The short answer
An audit trail is the log an e-signature service keeps for each document: when it was sent and to whom, when each person opened it and signed, from which IP address, and how they confirmed who they were. It usually comes as a certificate of completion attached to the signed PDF, which is sealed so that any later change shows.
What an audit trail records
- who sent the document, and when;
- each signer's name and email address, and the order they signed in;
- when each person was sent the link, opened the document and signed it, to the second;
- the IP address and device each step came from;
- how each signer was asked to confirm who they were, such as a one-time code sent to their email;
- declines, reminders, changes of recipient and anything else that happened along the way.
The certificate of completion
The audit trail is usually handed over as a certificate of completion: a page or a separate PDF that lists every signer and every step. With bSign, each signed document comes with one, named after the document (for example Lease - Certificate.pdf), and both are sealed.
Why it matters
If a signature is ever questioned, the signature image proves little on its own. The audit trail shows who signed, that they meant to, and when; the seal shows the document hasn't changed since. Some rules ask for this record directly: the CRA, for example, asks for a date and time stamp on certain electronically signed forms (more on the T183).
What to keep
- Keep the signed PDF and its certificate together, for as long as you keep the document itself.
- Download both before you leave an e-signature service: documents already signed stay valid, but the record lives with the copy you keep.
- Don't edit the signed PDF. To change something, send a new version for signature.
More on why intent and evidence matter more than how a signature looks.
This guide is general information, not legal advice; for a particular document, ask a lawyer. Published 2026-10-04 by Binarium, the Ontario IT services company behind bSign.