Digital efficiency is valuable, but legal certainty is essential. Banks operate under strict regulatory supervision, and every document must be capable of standing up in court if required. This is exactly where being 'somehow digital' differs from being digitally compliant.

Every manual check, every scan and every missing signature costs time, money and trust. If the evidentiary value is insufficient, fines or even reversals may follow. Processes that are supposed to be digital become a cost trap.

Banks that establish evidentiary value correctly from the outset not only reduce audit effort, but also gain greater regulatory confidence and measurable efficiency improvements.

To meet the expectations of regulators, auditors and courts, use the key levers of eIDAS-compliant signatures, audit trails, qualified timestamps and an evidence-preserving archiving strategy.

Terminology in 20 Seconds

  • Digital original: created electronically, with signature + audit trail + timestamp.
  • EES / FES / QES: eIDAS signature levels; QES = equivalent to written form (documentary evidence).
  • Audit trail: Complete logs (who/what/when/with what/why) for internal and external audits.

Series: From Paper to Performance

What to expect in this article:

Principles of the Evidentiary Value of Digital Documents

Digital documents must have evidentiary value in order to be used in banks in a legally compliant manner. Only natively digital documents with a signature and audit trail meet the requirements of Sections 371a/b of the German Code of Civil Procedure (ZPO) and the eIDAS Regulation (EU 910/2014):

Integrity

  • The document must be stored unchanged and protected against tampering.
  • Changes must be traceable, for example through timestamps and hash values.

Authenticity / Signature

  • EES is the 'simple electronic signature'. It covers any electronic declaration used by a person to sign, for example click-to-sign, a typed name or a scanned signature.
  • FES, the 'advanced electronic signature', strengthens the link to the individual and the integrity of the data.
  • Individual electronic signatures (EES/FES) cover internal processes or simple approvals.
  • The qualified electronic signature (QES) additionally verifies the signer's identity and includes a qualified certificate.

Traceability / Audit Trail

  • Complete logging of actions throughout the workflow.
  • Audit-proof records for internal and external audits.

Timestamps & Evidence Preservation

  • The times of creation, approval and signature must be documented.
  • Essential for admissibility in court and regulatory compliance.

Scans & Evidentiary Value: A Look at Current Guidance

Federal Archives (guidance): 'Substitutive scanning' can replace paper, but additional measures are required for the evidentiary value to approach that of the original. A simple scan remains only a copy.

BSI TR-RESISCAN (TR-03138): The objective is to approximate the evidentiary value of the original; documentary evidence is not created automatically.

Legal assessment: Scanned private documents are generally subject to the court's free assessment of evidence under Section 286 ZPO; without QES, the evidentiary effect under Section 371a ZPO does not apply.

Scans are suitable for internal low-risk processes, but they do not replace QES in legally effective banking transactions.
Further Reading (Practice): PDF ≠ Digital: How Banks Turn PDFs into Structured, Verifiable Data

Distinction: Digital Original vs. Scanned Copy

Not every digital process starts with a genuine digital original. Scanned PDFs are initially only images of paper documents without timestamps or an audit trail. For legally secure banking workflows, documents must either be created digitally from the outset or be provided with a signature and a complete audit trail.

Scanned PDF Document vs. Digitally Signed Document

Document Type Integrity Signature Audit-Trail Evidentiary Value
PDF Scan low none incomplete limited
QES Document very high EES, FES, QES complete full

Legal Basis: Brief & Specific

Section 371a ZPO: Private electronic documents with QES enjoy the evidentiary effect of private documents; without QES, the court applies free assessment of evidence.
Section 371b ZPO: Special provision for scanned public documents, with a different framework from private documents.
eIDAS framework: QES verification pursuant to Article 32 eIDAS; in German law, the evidentiary effect as documentary evidence is based on Section 371a ZPO.

Anti-Pattern: Evidentiary Value of Digital Documents

Problem: Documents are scanned and stored as 'digital'.
Cause: no signature strategy and no end-to-end audit trail.
Consequence: limited evidentiary value, greater review effort and regulatory risks during audits or legal disputes.

Further Reading (Compliance): Evidentiary Value of Digital Documents in Banking: Signatures, Audit Trails and Auditability

Compliance Requirements in Digital Workflows

Digital workflows in banks must meet regulatory requirements. What does that mean? Every process step must be fully traceable, audit-proof and auditable.

Every manual check, every scan and every missing signature costs time, money and trust. If the evidentiary value is insufficient, fines or even reversals may follow. Processes that are supposed to be digital become a cost trap.

To reliably meet regulatory requirements such as MaRisk, BAIT or GDPR banks rely on eIDAS-compliant workflows.

Key requirements arise from:

  • MaRisk AT 7.2: Proper business organisation & ICS, with traceability of every action.
  • BAIT 2021 ff.: Requirements for IT operations and data management, including traceability of changes.
  • GDPR Articles 5 & 32: Integrity, confidentiality and availability of personal data.
  • GoBD: Audit-proof electronic archiving.
  • BSI TR-03125 (TR-ESOR): Technical guideline for evidence-preserving long-term storage.

For banks, this means: Legal certainty is not an end in itself. It reduces review effort, lowers OPEX (operational expenditure) and protects against regulatory pressure. Every automated piece of evidence replaces manual checks and creates measurable ROI in compliance operations.

Preserving Evidentiary Value: Technical Requirements

Valid on receipt: QES + timestamp + certificate chain/OCSP.

Valid over time: renewed timestamps/hash migration when algorithms or keys expire.

Exportable: auditable evidence record/audit package.

Applies to: Standardised banking processes with external legal effect, such as bank and securities account openings, loan agreements, powers of attorney or KYC-related documents where evidentiary value and traceability are required by regulation.

Does not apply to: Purely internal notes, working documents without decision-making or external effect, and historical scanned legacy files without subsequent signature or evidentiary enhancement.

Preserving Evidentiary Value in Practice

Even qualified electronically signed documents can lose evidentiary strength over time if the signature or hash algorithms used become obsolete. BSI guidelines such as TR-ESOR therefore provide for regular renewal of evidence objects (Evidence Records) and procedures for long-term signature validation (Long-Term Validation, LTV).

Practical context: Banks are increasingly implementing so-called archive gates. These verify signature status, generate evidence objects and automatically monitor renewal cycles.

Compliance Checklist:

Aspect Required Evidence Regulatory Reference Risk of Non-Compliance
Signature eIDAS-compliant (EES / FES / QES) eIDAS Art. 25 ff. Loss of evidentiary strength
Audit trail Complete logging MaRisk AT 7.2 / BAIT 8 Lack of traceability
Timestamp Qualified according to BSI TR-ESOR BSI TR-03125 Suspected tampering
Archive Audit-proof, GDPR-compliant GoBD / DSGVO Fines, reputational risks

Measurement framework: Period: 6-12 months Population: bank and securities account openings, loan files, KYC-relevant documents KPIs: number of audit findings / reviews rework time per case share of QES-protected documents OPEX per process (compliance & internal audit) Method: before/after comparison by document class Data sources: audit trail logs, archive systems, internal audit reports, ICS documentation Reporting: quarterly (median + outliers)

Mandatory technical measures: Validierung eingehender Signaturen und Zertifikate (OCSP/CRL-Belege). Automatische Erneuerung von Zeitstempeln (Hash-Migration). Archivsystem mit Audit-Package (Beweisobjekte + Validierungsprotokolle).

The technical requirement pays off commercially: less rework, shorter audit cycles and lower total costs per case. What was once seen purely as a compliance burden is now becoming an efficiency lever within the control system.

How Paperfly Preserves the Evidentiary Value of Digital Documents

Paperfly ensures that digital documents in banks are processed not only efficiently, but also in a way that preserves their evidentiary value over time. Signatures, timestamps, audit trails and archiving work together in one end-to-end workflow that is automated, verifiable and eIDAS-compliant.

Out-of-the-Box Features:

  • eIDAS-compliant EES, FES and QES signatures for each document class
  • Automatic validation of signatures, certificates and timestamps before archiving
  • Audit-proof storage with an exportable audit package
  • Seamless integration into DMS, core banking and archive systems
40-60% less audit rework through automated evidence management.

Best Practices & Pitfalls

The solution: Automated digital end-to-end workflows. They provide eIDAS-compliant signatures (EES/FES/QES), versioning and access control, an automated audit trail and audit-proof processing.

Typical Errors & Avoidable Risks

  • Simple PDF scan: No legally compliant documentation, limited evidentiary value
  • Missing audit trail: No complete traceability of process steps, compliance risks
  • Versioning issues: Unclear which document version is valid, errors during updates
  • Manual review: Time-consuming, error-prone and resource-intensive

Which Signature Level (EES/FES/QES) Is Right?

Not every process requires QES, but some cannot do without it. The following quick picker helps identify the appropriate level in seconds:

  • Does a written-form requirement apply (law/contract)?QES (equivalent to written form).
  • No written-form requirement, but external effect for a customer/partner?
    • Low to medium riskEES (alternatively FES depending on policy/threshold).
    • High risk / amounts above threshold / PEP / sanctions exposureFES/QES.
  • Internal process only (no external effect) → EES/FES according to ICS policy.
  • Uncertainty / borderline case → choose the next higher level (secure default).
Always required in addition, regardless of level: Audit-Trail (wer/was/wann/womit/warum), Zeitstempel, Signatur-/Zertifikats-Validierung vor Archiv, wiederauffindbare Ablage, definierte Lösch-Trigger.

Integration into Existing Processes

For banks: Digital workflows must integrate seamlessly into existing systems. This enables an end-to-end, auditable process flow without media breaks, from DMS and core banking systems through to CRM and HR solutions.

Seamless Workflow Integration

  • DMS integration: Signed documents are stored directly in an audit-proof manner. No more manual post-archiving.
  • HR systems: Contracts, evidence and personnel documents can be signed and stored automatically while preserving evidentiary value.
  • CRM & core banking systems: Customer data, applications and approvals run through a single digital process.
Further Reading (Strategy): Digital Competitiveness in Banking: Capabilities, KPI Set and Roadmap

By combining structured data capture, digital signatures and audit-proof archiving, smart PDF workflows meet key requirements from MaRisk AT 7.2, BAIT Chapter 8.1 and the Internal Control System (ICS).

Every signature, change and forwarding action is automatically documented in the audit trail; the integrity of the document can be verified at any time using hash values and timestamps.
This creates an end-to-end traceable evidence process that is both eIDAS-compliant and auditable under GoBD.

Step-by-Step Guide to Preserving Evidentiary Value

Your goal: Make document workflows audit-proof, auditable and legally reliable.

These 6 steps are required:

  1. Scope & prioritisation: Identify critical document classes (bank/securities account opening, loan files, KYC).
  2. Legal check: Determine the required signature types (EES/FES/QES) for each document class.
  3. Technical baseline: Check whether the digital workflow system supports signatures, timestamps and audit trails.
  4. Automated validation: Enforce validation rules (mandatory fields, signature status, completeness) before storage.
  5. Audit and archiving strategy: Define GoBD/GDPR-compliant long-term archiving.
  6. Rollout & change: Processes, roles, training, monitoring (KPIs).

Automation and AI Potential

Banks generate thousands of documents every day. The greater the volume, the more important automated controls and intelligent verification mechanisms become.

Modern AI-based systems now perform key tasks that were previously manual and error-prone, such as checking document authenticity, comparing information with master data or detecting irregularities in the audit trail.

According to the KYC Trend Report Germany 2023, banks spend an average of up to 28 hours per new customer onboarding, with manual document checks and follow-up requests accounting for the largest share of the time.

Automated validation and workflow intelligence can reduce this time by 30-50% while improving data quality.

Legal certainty is the foundation, but what matters is how quickly and cost-effectively it can be achieved. Modern eIDAS workflows combine evidentiary value, efficiency and audit readiness in a single process, turning compliance into a competitive advantage.

Conclusion and Outlook

Digitalisation in banking requires a legally secure foundation. Only when integrity, authenticity, traceability and long-term evidence preservation are ensured can a document remain legally binding in digital form over time.

The next step is to digitalise existing processes in a targeted way and consider evidentiary value from the outset.

Update 2026 - 2027: eIDAS 2.0 & EUDI Wallet

The eIDAS 2 framework is in force. By 2027, every Member State is expected to offer at least one EUDI Wallet.

For banks, this means: Wallet-based identification and signatures replace manual KYC processes, while attribute-based credentials such as residence or corporate role and integrated signatures accelerate onboarding and contract processes. Status: 12/2025

Practical note: Define policy mapping (EES/FES/QES) today, prepare wallet integration for PID/attributes and relying-party processes, and establish long-term preservation of evidentiary value in the archive using OCSP/CRL evidence, qualified timestamps and renewal cycles in accordance with BSI TR-03125/TR-ESOR.

Frequently Asked Questions (FAQ)

What does the evidentiary value of digital documents mean in banking?

The evidentiary value of digital documents describes their legal usability before regulators, auditors and courts. It arises when a document is created digitally from the outset, signed in compliance with eIDAS, timestamped and archived in a traceable manner with a complete audit trail. Only then does it qualify as legally compliant evidence.

What qualifies as a document with full evidentiary value?

A document has full evidentiary value when it is created digitally from the outset or digitised and subsequently signed with an eIDAS-compliant qualified electronic signature (QES). In Germany, this establishes documentary evidentiary effect under Section 371a ZPO. Qualified timestamps and a complete audit trail provide additional traceability.

Is a PDF scan sufficient as evidence?

No. Without an electronic signature and audit trail, a PDF scan is merely a digital copy. It lacks proof of authenticity and integrity, meaning it is generally subject only to the court's free assessment of evidence. Legally secure banking processes require signed documents with timestamps and a complete audit trail. Source: Gesetze im Internet

How can I verify the evidentiary value of digital documents?

Using three characteristics:
Signatur:
qualified or advanced under eIDAS
Timestamp: proves the time of creation
Audit trail: documents changes and access
Tools such as Paperfly automatically verify and log this evidence.

What advantages does a signed workflow offer over paper-based processes?

50% shorter processing time through automated approvals
30% lower OPEX (operational expenditure) by eliminating printing, postage and rework. Efficiency, legal certainty and clear ROI benefits.

Can I integrate existing DMS or core banking systems?

Yes. API interfaces can be used to integrate Paperfly, for example, into DMS, CRM or HR systems. Existing processes remain in place while signature and audit functions are added automatically.

How is evidentiary value preserved over the long term?

The evidentiary value of digital documents is preserved over the long term when signatures and timestamps are renewed regularly and validation evidence is stored. Under BSI TR-03125 (TR-ESOR), Evidence Records, OCSP/CRL evidence and hash and timestamp migrations ensure long-term verifiability even when certificates or algorithms expire. Source: BSI

What benefits do eIDAS 2/EUDI bring to banks?

eIDAS 2.0 and the EUDI Wallet enable government-recognised digital identities and attribute credentials that can be used across banking. Wallet-based identification, strong customer authentication (SCA) and integrated signatures significantly shorten onboarding and contract processes, increase evidentiary value and reduce manual KYC and review effort. EU-wide rollout is planned for 2026/2027. Source: European Commission (Digital Identity)

Back to the series: From Paper to Performance: End-to-End Digitalisation in Banking (Overview & Introduction)

Mini Glossary: Key Terms for the Evidentiary Value of Digital Documents

Evidentiary value = Legal usability of a document before regulators, auditors and courts; dependent on integrity, authenticity, traceability and long-term evidence preservation.

Digital original = A document created electronically from the outset, provided with an electronic signature, timestamp and audit trail, and not originating from a scan.

QES (Qualified Electronic Signature) = The highest eIDAS signature level with a qualified certificate; in Germany, it has the evidentiary effect of written-form private documents under Section 371a ZPO.

Audit trail = Complete, audit-proof logging of all process and document actions (who, what, when, with what, why) throughout the entire lifecycle.

Qualified timestamp = Cryptographic proof of a specific point in time that makes tampering detectable and is essential for evidence that can withstand legal scrutiny.

Long-term evidence preservation (LTV) = Procedure for permanently preserving evidentiary value through Evidence Records, OCSP/CRL evidence and regular renewal of timestamps and hash algorithms in accordance with BSI TR-03125 (TR-ESOR).

Head of Compliance = defines signature levels, evidentiary-value policies and audit paths.

Internal Audit = assesses traceability, audit trails and long-term evidence.

IT Governance = is responsible for integrations, archiving strategy and system controls.

Sources:

https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr03138/ersetzendes-scannentr-resiscan.html

https://resources.fenergo.com/de/aktuelle-nachrichten/kyc-trend-report-2023-detutschland

https://digital-strategy.ec.europa.eu/en/policies/eudi-regulation

https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/TechnischeRichtlinien/TR03125/BSI_TR_03125_V1_3.pdf

https://www.gesetze-im-internet.de/zpo/__371a.html