top of page
Image by LYCS Architecture

How Much Assurance Does Your E-Signature Need? Electronic Signature Risk Levels Explained

Quick Overview


The higher the cost of a disputed signature, the higher the assurance level your document needs. ISO/IEC 29115 defines four levels of confidence in the signer, from LoA1 to LoA4, while eIDAS distinguishes between Simple, Advanced and Qualified Electronic Signatures. Match the level to the document’s risk—not simply the cheapest option. SelfieSign closes the gap every audit trail leaves by recording what actually happened at signing.


What we'll cover


Most organizations pick one electronic signature level and apply it to everything they sign. That single decision costs them either customers or court cases, and usually they cannot tell which.


Electronic signatures have been legal in every major market for over twenty years. The US passed ESIGN in 2000. Taiwan's Electronic Signature Act followed in 2001. The EU replaced its first directive with eIDAS in 2014.


Taiwan then did something almost nobody else has. In 2024, it rewrote the act. Electronic documents now carry the same legal effect as paper outright; signers no longer need the counterparty's prior agreement, and government agencies lost the exemption route that let them opt out indefinitely.



But most countries still run their original twenty-year-old statute. They should follow Taiwan.


The difficulty is that a statute cannot be both future-proof and precise. Write it tightly, and it fossilises; write it broadly, and it leaves the hard questions unanswered.


woman walking while making e-signature on tablet and her face is being recorded on the tablet's camera

Where the law stops, and standards start


The moment a statute names an approved technology, it freezes the market in place. Mandate smart cards in 2006, and you are still carrying smart cards in 2026 while the rest of the world has moved on.


So, the law must stay broad, and something else has to supply the precision. Standards do that work.


Two of them matter here, and they measure different things.


eIDAS needs little introduction to anyone selling into Europe. It is widely adopted and grades the signature itself, sorting signatures into three tiers: Simple, Advanced, and Qualified.


A signature can be perfectly valid under the statute and still useless as evidence when challenged. The tiers give an organization a line to point at.


ISO/IEC 29115 grades your confidence in who the signer is, from LoA1 to LoA4.


Other frameworks grade identity too. NIST's guidelines are the best known, but they are written for US federal agencies. We use ISO/IEC 29115 here because it is neutral, belonging to no single government.


Vendors quote whichever of the two flatters them, which is why comparisons collapse.


A supplier leading with QES may have done almost no identity proofing. A supplier with rigorous proofing may produce a signature that is easy to alter afterwards.


You need a position on both.


Start with the signer. If you do not know who someone is, the quality of their signature is irrelevant. That is why ISO/IEC 29115 comes first.


What is ISO/IEC 29115?


ISO/IEC 29115 is an international standard for entity authentication assurance. It basically provides a framework for determining how confidently a digital system can establish that an online entity is who they claim to be.


It covers three phases.


Enrolment. Application, identity proofing, identity verification, and record-keeping. This is where you establish that the person exists and is who they claim.


Credential management. Creation, issuance, activation, storage, renewal, revocation, and destruction. The whole life of the credential.


Entity authentication. The moment the entity uses the credential to assert its identity, plus the record-keeping around it.


The standard states that the LoA achieved by an implementation is the level of the phase with the lowest LoA. Rigorous in-person proofing followed by sloppy credential storage does not average out to something respectable.


It scores as the weakest phase and nothing else.


Those three phases, judged against the risk of getting it wrong, produce four possible settings:


The four Levels of Assurance (LoA1 to LoA4)


LoA1: low assurance


Minimal confidence in the asserted identity. The system only needs to recognize that you are the same entity today that you were yesterday. Any authentication mechanism is acceptable. Cryptography is optional.


Used where minimum risk attaches to getting it wrong. A self-registered username and password is enough, provided the username is unique on that platform.


This is the whitepaper download. The newsletter signup. The free trial.


LoA2: medium assurance


Some confidence in the asserted identity, for transactions carrying moderate risk. You must prove control of your credential through a secure protocol, and the system must defend against eavesdropping and online guessing.


Single-factor authentication is permitted but hardened.


Proofing now has two objectives. The identity must be unique, and the person behind it must objectively exist, not fabricated. At least one authoritative source must confirm this. Pseudonyms are still permitted.


The standard example is an insurance customer changing their address of record.


LoA3: high assurance


High confidence in the asserted identity, where substantial risk is involved.


Multi-factor authentication is mandatory. Secrets exchanged during authentication must be cryptographically protected. General-purpose hardware is still sufficient for credentials; dedicated devices are not yet required.


Proofing deepens. You must verify the identity against authoritative sources, and you must confirm that the identity is active in other real-world contexts.


Then the standard draws a line most vendors walk straight past. All of that establishes the identity is real and in use. Whether the person at the keyboard is its rightful owner is a separate problem.


Examples include filing confidential patent information, trading through an online brokerage account, and an executive approving a routine corporate wire.


LoA4: very high assurance


Very high confidence, for high-risk transactions. Everything in LoA3, plus two additions.


Identity proofing must be witnessed in person for human entities, to protect against impersonation. All secret and private cryptographic keys must be stored in tamper-resistant hardware. PII and other sensitive data in authentication protocols must be cryptographically protected.


Proofing now demands multiple authoritative sources and must be performed locally. Enrolment must happen in person.


The standard reaches for a pharmacist dispensing controlled medication, and an executive moving a significant sum out of company accounts.


Knowing the levels is not the same as using them. So, the next step is to look at what’s at stake.


How to choose an e-signature assurance level for your documents?


Sort your documents by what a challenge would cost, assign a level to each type, then make your decision.


Four questions do most of the work in practice.


What is the financial exposure if this signature is repudiated? A €40 subscription and a €4m facility agreement do not belong at the same level.


Will a regulator ask to see the evidence? If yes, raise the level and confirm the record exports in a form somebody else can read.


How long must this stay defensible? Three years and thirty years are different engineering problems.


How plausible is honest confusion? Some disputes involve fraud. Most involve a signer who did not understand what they agreed to.


Set the bar too high and completion collapses. Every extra verification step in a remote flow loses signers, and you lose the impatient ones first. Requiring witnessed in-person proofing for a change-of-address form keeps the paper form alive forever.


Set it too low, and the signature is legally valid and evidentially useless. You carry the liability of a digital process with none of the protection.


The standard supplies six impact categories. Assess the transaction against each and take the highest level that any single one demands.


Potential Risk Impact Category

LoA 1

LoA 2

LoA 3

LoA 4

Inconvenience, disruption, or reputational damage

Minor

Moderate

Significant

High

Financial loss or legal liability 

Minor

Moderate

Significant

High

Harm to individuals, programs, or public interests 

None

Minor

Moderate

High

Exposure or leakage of sensitive personal information/data 

None

Moderate

Significant

High

Personal safety 

None

None

Low–Moderate

High

Violation of civil or criminal laws/regulations 

None

Minor

Significant

High


This is only half the problem. The other half is the signature they leave behind. That is the territory eIDAS covers.


What are SES, AES, and QES under eIDAS?


Everything above grades the person. eIDAS grades the artefact.


Simple Electronic Signature (SES) covers any data attached to a document and used to sign. A scanned squiggle qualifies. A tick box qualifies.


Advanced Electronic Signature (AES) must meet four conditions:


  1. Uniquely linked to the signer

  2. Capable of identifying the signer

  3. Created using data the signer controls with a high level of confidence

  4. Linked to the signed document so any later change is detectable


Qualified Electronic Signature (QES) must be created by a qualified signature creation device, and it must rest on a qualified certificate issued by a trust service provider on an EU member state trusted list.


Only QES gets automatic legal equivalence to a handwritten signature across every member state. SES and AES are admissible and cannot be rejected purely for being electronic, but their weight is argued case by case.


The catch is, eIDAS tiers look clean on paper. The product catalog does not.


What most e-signature platforms record, and what they don't


The major e-signature platforms are not weak on assurance.


Docusign, Adobe Sign, and their peers reach from click-to-sign at the bottom up to QES through partnerships with qualified trust service providers, and most sell identity verification as a premium add-on.


The problem is commercial.


Assurance arrives as a series of purchases. Base signing, then ID verification, then a certificate through a partner provider, each with its own contract and its own per-transaction cost.


Organizations respond exactly as you would expect. They buy the add-ons for the documents where the risk is loudest and leave everything else at the bottom of the scale.


This is how a company ends up with excellent proofing on its loan agreements and a tick box on the personal guarantee that backs them.


The deeper problem is evidentiary.


Look at what the record contains. A certificate of completion logs timestamps, IP addresses, email trails, the authentication method used, and a hash of the final document. Every fact concerns the account and the file.


None of them concern the person.


That distinction sits idle until a signature is challenged, at which point it becomes the entire dispute.


A signer who admits the credential was theirs, admits the timestamp is correct, and testifies that their son-in-law filled the form in while they were in hospital has contradicted nothing in the audit trail.


The log confirms a session happened. The argument is about what happened during it.


How SelfieSign records the signing session


SelfieSign is a video-based electronic signature platform that records the signing session as it happens.


Instead of reducing a signing event to a timestamp and a completed document, it captures the event itself. Video and audio of the signer, handwriting trajectory, GPS position, timestamp, and other transaction data are packaged into a single tamper-evident file, which is the .SVS file.


Not every transaction needs the same level of scrutiny, so SelfieSign lets organizations match the evidence to the risk.


Routine document? Use a standard electronic signature.


High-stakes document? Record the signing session.


Same platform. Same workflow. Different depths of evidence.


That means organizations can scale signing without forcing every transaction into the most expensive or cumbersome process.


SelfieSign biometric e-signature

Reaching LoA3 and LoA4


LoA3 is the level most regulated businesses run today, and it has one firm requirement.


You have to know who your customer really is, checked against a trustworthy record. A government ID database, or the KYC file a bank or insurer already builds when it opens an account.


Do it once at onboarding, and that identity carries forward.


But knowing who the customer is doesn't by itself show the person signing today is its rightful owner. That is what SelfieSign works on. Every signing session is recorded, so staff can compare the signer against the identity already on file, or against a previously verified session used as the reference.


For a new loan, a guarantee, an account change, an insurance claim, or any high-value agreement, that means fewer repeat checks, faster approvals, smoother manual verification, and a stronger record if the transaction is ever disputed.


LoA4 sets the bar even higher.


It needs a protected cryptographic key, AND the customer's identity confirmed face to face, with a member of staff present. SelfieSign fits here too.


The key does its job, but narrowly. It proves that a particular credential was used to sign. It doesn't tell you who was holding it when the signature happened.


A stolen key still signs perfectly.


What SelfieSign adds is the person, the intent, and the moment the key was never meant to capture.


The QES wall


QES is the gold standard for e-signatures, but gold is expensive to mine.


Every signer needs a qualified certificate first, through a national eID, a smart card, or a registration step with an approved provider.


Fine if your customer already has that. A wall if they are a supplier three countries away whose eID you have never heard of.


So most cross-border deals tend to happen at AES.


However, since AES earns no automatic recognition, when someone disputes it, a court weighs it as any other evidence and a thin record loses.


SelfieSign gives you the strongest record available. The signing session itself, recorded and sealed, showing who signed and how it happened, tying the act of signing to the person who performed it.


Whether the deal is local or cross-border, the principle is the same: the record must match the risk.


Match the level to the risk, not the budget


The mistake is almost always the same. One level, applied to everything, chosen by what was cheap or convenient rather than what each document is worth in a dispute.


Two frameworks tell you how to do better. ISO/IEC 29115 grades how sure you are of the signer. eIDAS grades the signature they leave behind.


Strong on one and weak on the other is not a position; it is an exposure.


Do the boring part first. List your document types, run each against what a challenge would cost, and assign a level to each. A newsletter signup and a mortgage should not sign the same way.


Then make sure the record you keep can carry the weight you have assigned it.


Contact SelfieSign for a free consultation.



People Also Ask


What are the risks of using one e-signature level for everything?

A newsletter signup and a €4m facility agreement carry very different risks. Set the bar too high and you lose customers to friction; set it too low, and your signature is legally valid but evidentially useless. SelfieSign lets you match the evidence depth to the risk—standard signatures for routine documents, video-recorded sessions for high-stakes ones.

ISO/IEC 29115 grades how confident you are in the signer's identity (LoA1 to LoA4). eIDAS grades the signature (SES, AES, QES). You need a position on both. A vendor may offer QES without rigorous identity proofing, or strong proofing with a signature that's easy to alter. Strong on one and weak on the other is exposure.

Traditional e-signature platforms like DocuSign record timestamps, IP addresses, and document hashes. Every fact concerns the account and the file; none of it concerns the person. SelfieSign records the signing session itself—video, audio, handwriting trajectory, and GPS—so if a signer later disputes having signed, you have evidence of who was actually at the keyboard.

Not necessarily. QES is ideal legally, but it requires every counterparty to hold a qualified certificate recognized in an EU member state. For international suppliers without national eIDs or smart cards, that requirement becomes a barrier.


Most cross-border B2B deals use AES, strengthened by additional evidence such as a video-backed agreement from SelfieSign.

LoA3 requires high confidence in who is signing. SelfieSign records every session, letting your staff compare the signer against the identity on file or a previously verified session.


For LoA4, which demands in-person proofing and tamper-resistant hardware, SelfieSign adds what the key cannot: proof of who was holding the credential, their intent, and the moment the signature happened.

Start by listing all your document types, estimating what a challenge would cost for each, and assigning an appropriate assurance level. Use the risk impact categories in ISO/IEC 29115—financial loss, reputational damage, regulatory exposure—and take the highest level any single category demands. Then make sure your record can carry that weight. Not sure where to start? Talk to the SelfieSign team for a free consultation.

About SelfieSign


SelfieSign is a dynamic biometric signature platform built for high-stakes agreements. Our patented selfie video signing technology (.SVS) captures face, voice, handwriting, geolocation, IP address, and timestamp at the moment of signing and cryptographically binds it to the document.


Trusted by over 80% of hospitals in Taiwan, processing 3 million documents every month, SelfieSign is fully compliant with eIDAS 2.0 AES, GDPR, and ISO 27001.


Comments


bottom of page