Identity proofing
Define acceptable ID sources, credential analysis, and knowledge-based or document-based proofing procedures to uniquely link a signer to an identity.
A written policy reduces legal and operational risk by standardizing signer identity, consent, and record-retention processes. It preserves enforceability under ESIGN/UETA, ensures consistent audit trails for dispute resolution, and supports industry rules such as HIPAA and 21 CFR Part 11 when higher assurance is required.
Typical users include departments that issue, sign, or store legally binding documents across industries.
The policy should be accessible to signers, administrators, compliance officers, and any third parties required to verify signatures.
Define acceptable ID sources, credential analysis, and knowledge-based or document-based proofing procedures to uniquely link a signer to an identity.
Specify required authentication levels (email link, SMS code, one-time passcode, or stronger) for each document class based on risk and legal requirements.
Require timestamped logs, IP addresses, signer actions, and certificate-of-completion records to support attribution and non-repudiation in disputes.
Mandate encrypted at-rest storage (AES-256) and integrity checks so executed records cannot be altered without detection.
Define signer order, delegated authority, and approver roles so only authorized individuals can execute specified documents.
Describe when in-person notarization or remote online notarization is required and how recordings, journals, and retention are handled.
| Field | Configuration |
|---|---|
| Signer Authentication | Email link by default; SMS OTP or KBA for high-risk records |
| RON Settings | Audio-video recording enabled; ID credential analysis required |
| Audit Trail | Timestamps, IP logging, and certificate of completion retained |
| Access Controls | Role-based permissions and SSO for administrators |
Specify supported file formats, integrations, and minimum security controls required of a signing platform.
Platform choices should support audit trails, role-based access, optional RON, SOC 2/ISO 27001 compliance, and HIPAA BAAs where required by the workflow.
Obtain per ESIGN Act (15 U.S.C. §7001) before electronic delivery
Effective or execution date triggers retention schedules
Retain audio-video per state rules, commonly 5–10 years
Provide forms to recipients by statutory deadlines
Define period to request re-execution or amendment
Define scope, roles, and acceptable authentication levels.
Enable integrations, logging, and retention settings.
Run test transactions and verify audit evidence.
Open production use and monitor compliance metrics.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Trial available | Trial available | Trial available | Trial available |
| Bulk Send | Yes | Yes | Yes | Yes | Yes |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
Tim Martin, founder, moved lease execution online to avoid in-person signings and speed closings
John Butler, founder, required robust PHI controls and rapid patient consent collection