Digital efficiency is valuable, but legal certainty is essential. Banks operate under strict regulatory supervision, and every document must be capable of standing up in court if required. This is exactly where being 'somehow digital' differs from being digitally compliant.
Banks that establish evidentiary value correctly from the outset not only reduce audit effort, but also gain greater regulatory confidence and measurable efficiency improvements.
To meet the expectations of regulators, auditors and courts, use the key levers of eIDAS-compliant signatures, audit trails, qualified timestamps and an evidence-preserving archiving strategy.
Terminology in 20 Seconds
- Digital original: created electronically, with signature + audit trail + timestamp.
- EES / FES / QES: eIDAS signature levels; QES = equivalent to written form (documentary evidence).
- Audit trail: Complete logs (who/what/when/with what/why) for internal and external audits.
Series: From Paper to Performance
-
Part 1/5 - From Paper to Performance: Why Banks Need End-to-End Digitalisation
Cost and risk drivers of paper-based processes, plus a roadmap for end-to-end workflows. -
Part 2/5 - PDF ≠ Digital: How Banks Can Finally Use PDFs Intelligently
Why 'saving a PDF' is not a process, and how PDFs can become structured, verifiable data. -
Part 3/5 - Evidentiary Value of Digital Documents: Legally Secure Digital Banking
Evidentiary value, audit trails and signatures: what really matters for auditability and regulatory resilience. -
Part 4/5 - Digital Competitiveness: How Banks Can Keep Pace in a Digital Market
The capabilities banks need now and the process metrics that make the difference measurable. -
Part 5/5 - Workflow Automation: Step by Step to a Paperless Process
How workflow automation creates a resilient process infrastructure: faster and compliant
What to expect in this article:
- Principles of Evidentiary Value
- Distinction: Digital Original vs. Scanned Copy
- Compliance Requirements in Digital Workflows
- Preserving Evidentiary Value in Practice
- Best Practices & Pitfalls
- Which Signature Level (EES/FES/QES) Is Right?
- Integration into Existing Processes
- Step-by-Step Guide to Preserving Evidentiary Value
- Automation and AI Potential
- Conclusion and Outlook
- Frequently Asked Questions (FAQ)
Principles of the Evidentiary Value of Digital Documents
Digital documents must have evidentiary value in order to be used in banks in a legally compliant manner. Only natively digital documents with a signature and audit trail meet the requirements of Sections 371a/b of the German Code of Civil Procedure (ZPO) and the eIDAS Regulation (EU 910/2014):
Integrity
- The document must be stored unchanged and protected against tampering.
- Changes must be traceable, for example through timestamps and hash values.
Authenticity / Signature
- EES is the 'simple electronic signature'. It covers any electronic declaration used by a person to sign, for example click-to-sign, a typed name or a scanned signature.
- FES, the 'advanced electronic signature', strengthens the link to the individual and the integrity of the data.
- Individual electronic signatures (EES/FES) cover internal processes or simple approvals.
- The qualified electronic signature (QES) additionally verifies the signer's identity and includes a qualified certificate.

Traceability / Audit Trail
- Complete logging of actions throughout the workflow.
- Audit-proof records for internal and external audits.
Timestamps & Evidence Preservation
- The times of creation, approval and signature must be documented.
- Essential for admissibility in court and regulatory compliance.
Scans & Evidentiary Value: A Look at Current Guidance
Federal Archives (guidance): 'Substitutive scanning' can replace paper, but additional measures are required for the evidentiary value to approach that of the original. A simple scan remains only a copy.
BSI TR-RESISCAN (TR-03138): The objective is to approximate the evidentiary value of the original; documentary evidence is not created automatically.
Legal assessment: Scanned private documents are generally subject to the court's free assessment of evidence under Section 286 ZPO; without QES, the evidentiary effect under Section 371a ZPO does not apply.
Scans are suitable for internal low-risk processes, but they do not replace QES in legally effective banking transactions.Further Reading (Practice): PDF ≠ Digital: How Banks Turn PDFs into Structured, Verifiable Data
Distinction: Digital Original vs. Scanned Copy
Not every digital process starts with a genuine digital original. Scanned PDFs are initially only images of paper documents without timestamps or an audit trail. For legally secure banking workflows, documents must either be created digitally from the outset or be provided with a signature and a complete audit trail.
Scanned PDF Document vs. Digitally Signed Document
| Document Type | Integrity | Signature | Audit-Trail | Evidentiary Value |
|---|---|---|---|---|
| PDF Scan | low | none | incomplete | limited |
| QES Document | very high | EES, FES, QES | complete | full |
Legal Basis: Brief & Specific
Section 371a ZPO: Private electronic documents with QES enjoy the evidentiary effect of private documents; without QES, the court applies free assessment of evidence.
Section 371b ZPO: Special provision for scanned public documents, with a different framework from private documents.
eIDAS framework: QES verification pursuant to Article 32 eIDAS; in German law, the evidentiary effect as documentary evidence is based on Section 371a ZPO.
Anti-Pattern: Evidentiary Value of Digital Documents
Problem: Documents are scanned and stored as 'digital'.
Cause: no signature strategy and no end-to-end audit trail.
Consequence: limited evidentiary value, greater review effort and regulatory risks during audits or legal disputes.
Compliance Requirements in Digital Workflows
Digital workflows in banks must meet regulatory requirements. What does that mean? Every process step must be fully traceable, audit-proof and auditable.
To reliably meet regulatory requirements such as MaRisk, BAIT or GDPR banks rely on eIDAS-compliant workflows.
Key requirements arise from:
- MaRisk AT 7.2: Proper business organisation & ICS, with traceability of every action.
- BAIT 2021 ff.: Requirements for IT operations and data management, including traceability of changes.
- GDPR Articles 5 & 32: Integrity, confidentiality and availability of personal data.
- GoBD: Audit-proof electronic archiving.
- BSI TR-03125 (TR-ESOR): Technical guideline for evidence-preserving long-term storage.
For banks, this means: Legal certainty is not an end in itself. It reduces review effort, lowers OPEX (operational expenditure) and protects against regulatory pressure. Every automated piece of evidence replaces manual checks and creates measurable ROI in compliance operations.

Preserving Evidentiary Value: Technical Requirements
Valid on receipt: QES + timestamp + certificate chain/OCSP.
Valid over time: renewed timestamps/hash migration when algorithms or keys expire.
Exportable: auditable evidence record/audit package.
Applies to: Standardised banking processes with external legal effect, such as bank and securities account openings, loan agreements, powers of attorney or KYC-related documents where evidentiary value and traceability are required by regulation.
Does not apply to: Purely internal notes, working documents without decision-making or external effect, and historical scanned legacy files without subsequent signature or evidentiary enhancement.
Preserving Evidentiary Value in Practice
Even qualified electronically signed documents can lose evidentiary strength over time if the signature or hash algorithms used become obsolete. BSI guidelines such as TR-ESOR therefore provide for regular renewal of evidence objects (Evidence Records) and procedures for long-term signature validation (Long-Term Validation, LTV).
Compliance Checklist:
| Aspect | Required Evidence | Regulatory Reference | Risk of Non-Compliance |
|---|---|---|---|
| Signature | eIDAS-compliant (EES / FES / QES) | eIDAS Art. 25 ff. | Loss of evidentiary strength |
| Audit trail | Complete logging | MaRisk AT 7.2 / BAIT 8 | Lack of traceability |
| Timestamp | Qualified according to BSI TR-ESOR | BSI TR-03125 | Suspected tampering |
| Archive | Audit-proof, GDPR-compliant | GoBD / DSGVO | Fines, reputational risks |
Measurement framework: Period: 6-12 months Population: bank and securities account openings, loan files, KYC-relevant documents KPIs: number of audit findings / reviews rework time per case share of QES-protected documents OPEX per process (compliance & internal audit) Method: before/after comparison by document class Data sources: audit trail logs, archive systems, internal audit reports, ICS documentation Reporting: quarterly (median + outliers)
The technical requirement pays off commercially: less rework, shorter audit cycles and lower total costs per case. What was once seen purely as a compliance burden is now becoming an efficiency lever within the control system.
How Paperfly Preserves the Evidentiary Value of Digital Documents
Paperfly ensures that digital documents in banks are processed not only efficiently, but also in a way that preserves their evidentiary value over time. Signatures, timestamps, audit trails and archiving work together in one end-to-end workflow that is automated, verifiable and eIDAS-compliant.
Out-of-the-Box Features:
- eIDAS-compliant EES, FES and QES signatures for each document class
- Automatic validation of signatures, certificates and timestamps before archiving
- Audit-proof storage with an exportable audit package
- Seamless integration into DMS, core banking and archive systems
40-60% less audit rework through automated evidence management.
Best Practices & Pitfalls
The solution: Automated digital end-to-end workflows. They provide eIDAS-compliant signatures (EES/FES/QES), versioning and access control, an automated audit trail and audit-proof processing.
Typical Errors & Avoidable Risks
- Simple PDF scan: No legally compliant documentation, limited evidentiary value
- Missing audit trail: No complete traceability of process steps, compliance risks
- Versioning issues: Unclear which document version is valid, errors during updates
- Manual review: Time-consuming, error-prone and resource-intensive
Which Signature Level (EES/FES/QES) Is Right?
Not every process requires QES, but some cannot do without it. The following quick picker helps identify the appropriate level in seconds:
- Does a written-form requirement apply (law/contract)? → QES (equivalent to written form).
- No written-form requirement, but external effect for a customer/partner?
- Low to medium risk → EES (alternatively FES depending on policy/threshold).
- High risk / amounts above threshold / PEP / sanctions exposure → FES/QES.
- Internal process only (no external effect) → EES/FES according to ICS policy.
- Uncertainty / borderline case → choose the next higher level (secure default).
Integration into Existing Processes
For banks: Digital workflows must integrate seamlessly into existing systems. This enables an end-to-end, auditable process flow without media breaks, from DMS and core banking systems through to CRM and HR solutions.
Seamless Workflow Integration
Further Reading (Strategy): Digital Competitiveness in Banking: Capabilities, KPI Set and RoadmapBy combining structured data capture, digital signatures and audit-proof archiving, smart PDF workflows meet key requirements from MaRisk AT 7.2, BAIT Chapter 8.1 and the Internal Control System (ICS).
This creates an end-to-end traceable evidence process that is both eIDAS-compliant and auditable under GoBD.
Step-by-Step Guide to Preserving Evidentiary Value
Your goal: Make document workflows audit-proof, auditable and legally reliable.
These 6 steps are required:
- Scope & prioritisation: Identify critical document classes (bank/securities account opening, loan files, KYC).
- Legal check: Determine the required signature types (EES/FES/QES) for each document class.
- Technical baseline: Check whether the digital workflow system supports signatures, timestamps and audit trails.
- Automated validation: Enforce validation rules (mandatory fields, signature status, completeness) before storage.
- Audit and archiving strategy: Define GoBD/GDPR-compliant long-term archiving.
- Rollout & change: Processes, roles, training, monitoring (KPIs).
Automation and AI Potential
Banks generate thousands of documents every day. The greater the volume, the more important automated controls and intelligent verification mechanisms become.
According to the KYC Trend Report Germany 2023, banks spend an average of up to 28 hours per new customer onboarding, with manual document checks and follow-up requests accounting for the largest share of the time.
Automated validation and workflow intelligence can reduce this time by 30-50% while improving data quality.
Legal certainty is the foundation, but what matters is how quickly and cost-effectively it can be achieved. Modern eIDAS workflows combine evidentiary value, efficiency and audit readiness in a single process, turning compliance into a competitive advantage.
Conclusion and Outlook
Digitalisation in banking requires a legally secure foundation. Only when integrity, authenticity, traceability and long-term evidence preservation are ensured can a document remain legally binding in digital form over time.
Update 2026 - 2027: eIDAS 2.0 & EUDI Wallet
The eIDAS 2 framework is in force. By 2027, every Member State is expected to offer at least one EUDI Wallet.
For banks, this means: Wallet-based identification and signatures replace manual KYC processes, while attribute-based credentials such as residence or corporate role and integrated signatures accelerate onboarding and contract processes. Status: 12/2025
Frequently Asked Questions (FAQ)
What does the evidentiary value of digital documents mean in banking?
The evidentiary value of digital documents describes their legal usability before regulators, auditors and courts. It arises when a document is created digitally from the outset, signed in compliance with eIDAS, timestamped and archived in a traceable manner with a complete audit trail. Only then does it qualify as legally compliant evidence.
What qualifies as a document with full evidentiary value?
A document has full evidentiary value when it is created digitally from the outset or digitised and subsequently signed with an eIDAS-compliant qualified electronic signature (QES). In Germany, this establishes documentary evidentiary effect under Section 371a ZPO. Qualified timestamps and a complete audit trail provide additional traceability.
Is a PDF scan sufficient as evidence?
No. Without an electronic signature and audit trail, a PDF scan is merely a digital copy. It lacks proof of authenticity and integrity, meaning it is generally subject only to the court's free assessment of evidence. Legally secure banking processes require signed documents with timestamps and a complete audit trail. Source: Gesetze im Internet
How can I verify the evidentiary value of digital documents?
Using three characteristics:
Signatur: qualified or advanced under eIDAS
Timestamp: proves the time of creation
Audit trail: documents changes and access
Tools such as Paperfly automatically verify and log this evidence.
What advantages does a signed workflow offer over paper-based processes?
50% shorter processing time through automated approvals
30% lower OPEX (operational expenditure) by eliminating printing, postage and rework. Efficiency, legal certainty and clear ROI benefits.
Can I integrate existing DMS or core banking systems?
Yes. API interfaces can be used to integrate Paperfly, for example, into DMS, CRM or HR systems. Existing processes remain in place while signature and audit functions are added automatically.
How is evidentiary value preserved over the long term?
The evidentiary value of digital documents is preserved over the long term when signatures and timestamps are renewed regularly and validation evidence is stored. Under BSI TR-03125 (TR-ESOR), Evidence Records, OCSP/CRL evidence and hash and timestamp migrations ensure long-term verifiability even when certificates or algorithms expire. Source: BSI
What benefits do eIDAS 2/EUDI bring to banks?
eIDAS 2.0 and the EUDI Wallet enable government-recognised digital identities and attribute credentials that can be used across banking. Wallet-based identification, strong customer authentication (SCA) and integrated signatures significantly shorten onboarding and contract processes, increase evidentiary value and reduce manual KYC and review effort. EU-wide rollout is planned for 2026/2027. Source: European Commission (Digital Identity)
Back to the series: From Paper to Performance: End-to-End Digitalisation in Banking (Overview & Introduction)Mini Glossary: Key Terms for the Evidentiary Value of Digital Documents
Evidentiary value = Legal usability of a document before regulators, auditors and courts; dependent on integrity, authenticity, traceability and long-term evidence preservation.
Digital original = A document created electronically from the outset, provided with an electronic signature, timestamp and audit trail, and not originating from a scan.
QES (Qualified Electronic Signature) = The highest eIDAS signature level with a qualified certificate; in Germany, it has the evidentiary effect of written-form private documents under Section 371a ZPO.
Audit trail = Complete, audit-proof logging of all process and document actions (who, what, when, with what, why) throughout the entire lifecycle.
Qualified timestamp = Cryptographic proof of a specific point in time that makes tampering detectable and is essential for evidence that can withstand legal scrutiny.
Long-term evidence preservation (LTV) = Procedure for permanently preserving evidentiary value through Evidence Records, OCSP/CRL evidence and regular renewal of timestamps and hash algorithms in accordance with BSI TR-03125 (TR-ESOR).
Head of Compliance = defines signature levels, evidentiary-value policies and audit paths.
Internal Audit = assesses traceability, audit trails and long-term evidence.
IT Governance = is responsible for integrations, archiving strategy and system controls.
Sources:
https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr03138/ersetzendes-scannentr-resiscan.htmlhttps://resources.fenergo.com/de/aktuelle-nachrichten/kyc-trend-report-2023-detutschland
https://digital-strategy.ec.europa.eu/en/policies/eudi-regulation
https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/TechnischeRichtlinien/TR03125/BSI_TR_03125_V1_3.pdf
https://www.gesetze-im-internet.de/zpo/__371a.html
