Demographic Verification
What is the purpose of the Demographic Verification against Signing Certificate feature, and why was it introduced?
Last updated
What is the purpose of the Demographic Verification against Signing Certificate feature, and why was it introduced?
Last updated
The Demographic Verification against Signing Certificate feature was introduced to strengthen the security and trustworthiness of the signing process by ensuring that the certificate used to sign a document genuinely belongs to the signatory.
This feature validates the signatory's Personally Identifiable Information (PII), admin-configured fields against the details embedded in the digital certificate used during signing. This validation is especially critical for external users, where identity verification cannot rely on internal user directories.
If there is a mismatch — for example, if the certificate does not belong to the actual signatory — the signing attempt will be rejected. The user will then have the option to retry with the correct certificate. The certificate details are also included in the Completion Certificate for audit and compliance purposes.
Additionally, administrators have the flexibility to:
Define which PII fields must be validated.
Set a threshold for name matching to allow minor variations or enforce strict matching.
Key Benefits:
Prevents misuse of certificates and unauthorized signatures.
Enhances PII accuracy for external users.
Offers configurable validation rules and name matching thresholds.
Use Cases:
Fraud Prevention: Ensures only valid users can sign with their own certificates.
High-Stakes Signing: Strengthens identity assurance in legal, financial, or regulatory document workflows.
This feature ultimately helps build trust and ensures accountability in digital transactions by tying the signatory’s identity tightly to their signing credential. Currently, the emSigner application supports the configuration for Aadhaar based signing and will be extended to other Signing certificates.
Below are the steps how the Super Admin can configure the Demographic validation settings.
Step 1: Navigate to the Admin Settings, where you will find the 'Demographic Verification' option listed under Settings.
Step 2: The Super Admin has to select the 'Signing Type' from the dropdown and the option from the 'Action' dropdown. Based on the option selected from the dropdown the signatory is either allowed or restriced the signing
The Action dropdown has the below options
Restrict Signing - Block signing if details mismatch, capture mismatched details in the log
Allow Signing - Proceed with signing, but capture mismatched details in the log
Once the certificate attributes are enabled, the admin has to click 'Save' to save the demographic verification settings.
When the Initiator is sending the document for signing to the external user, the option 'Verify Demographic Data' needs to be selected so that the Signatory's details will be verified with the Signing Certificate.
The details captured in the completion certificate shows if the Signatory details are matching or not.