For three weeks the most disruptive shortage in most organisations has not been laptops or bandwidth. It has been signatures. Purchase orders waiting for a director who cannot reach the office. Contracts printed, signed, photographed and emailed back at an angle. Payment runs held because the second signatory is in another country. Human resources letters unsent because nobody can apply the company stamp. The conclusion being drawn everywhere this month is that digital signatures and remote approvals are about to become permanent. That is probably right, but the reasoning behind it is usually wrong, and the wrong reasoning produces the wrong system.
A signature is evidence, not a control
It is worth being precise about what a signature does, because organisations have been treating four distinct functions as one thing. It authenticates the person: this individual, not another. It evidences intent: they meant to approve, not merely to read. It fixes the document: this version, not the one edited afterwards. And occasionally it satisfies a legal form requirement: the law says this instrument must be signed, witnessed or notarised to be valid. Only the fourth of those genuinely needs paper, and it applies to a small and identifiable category of documents. The first three are all served better by a system than by ink. A workflow record showing who approved, when, from which authenticated session, against which version, with the supporting information visible at the time, is stronger evidence than a signature on a page that nobody can prove was the page the signer read. That inversion is the whole argument. We did not use paper because it was reliable. We used it because it was available.
Three tiers, three different problems
The organisations making a mess of this month are the ones buying a single tool and pointing it at everything. Internal approvals, which are the overwhelming majority by volume, do not need a signature at all. Purchase requisitions, purchase orders, expense claims, journal postings, credit limits, leave, payment release. These belong in the system that owns the transaction, enforced by role and limit, with an audit trail. Routing an internal purchase order through an e-signature product because the old process used a signature block is automation of a historical accident. Commercial documents that leave the organisation need a signed record with evidence: contracts, quotations, engagement letters, statements of work, amendments, non-disclosure agreements. This is what electronic signature platforms are for, and their value is not the image of the signature but the certificate behind it: identity method, timestamps, document hash, event sequence. Then there is a residual set that genuinely requires formality: certain real property transactions, powers of attorney, some court filings, negotiable instruments, some government submissions and employment documents in some jurisdictions. Identify that list for your own business, keep it short, and stop trying to solve it with software. Planning around a dozen genuinely physical documents is manageable. Pretending they do not exist is how a transaction fails in month four.
What the audit trail must contain
When this becomes permanent, and it will, the question auditors and counterparties ask is not whether you used an electronic signature. It is what you can produce two years later. A defensible record contains the identity verification method used, the timestamp with an unambiguous time zone, a hash of the exact document signed, the sequence of actions by each party, the delivery and access events, and the signer's acknowledgement of electronic execution. It is exportable in a form that survives you changing vendors, and it is retained with the contract rather than inside a subscription you might cancel. That last point deserves attention, because it is the mistake being made at scale this month. Contracts signed in a trial account, under someone's personal login, with the evidence held only in the platform, are contracts whose evidence disappears when that person leaves or the trial ends. Export the completed documents and certificates into your document repository on a schedule, from day one.
Delegation of authority is the real project
The reason approvals have jammed is not that signatures were physical. It is that authority was personal, undocumented and un-substituted. Most organisations have a delegation of authority matrix that exists as a document from several years ago, names individuals rather than roles, has no alternates, and does not match how the systems are configured. When a named individual becomes unreachable, the organisation discovers that authority cannot be delegated without a board resolution, and that the system's approval hierarchy was built by an implementation consultant who left in 2017. Rebuilding it is a fortnight of work and the highest-value thing your finance function can do this quarter: limits by transaction type, roles rather than names, a defined alternate for every role, escalation where an approver is unavailable for more than a stated period, and the system configuration reconciled to the document. Then test it by removing someone deliberately.
| Document category | Question to resolve |
|---|---|
| Internal authority record | Which role, limit and alternate authorise this step? |
| Commercial execution record | What identity, version and event evidence is retained? |
| Formal instrument or filing | What form, witnessing and acceptance rules apply? |
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
Practical Guidance for Approval Workflow Modernization
- Separate internal approvals from external signatures before buying anything. Internal authority belongs in the transaction system; e-signature platforms are for documents that leave the building.
- List the documents that genuinely require physical execution. Usually fewer than fifteen. Plan logistics around them and remove them from the software conversation entirely.
- Rebuild the delegation of authority matrix with roles, limits and named alternates. Then reconcile it against what the systems actually enforce, which will not match.
- Insist on exportable evidence and export it on a schedule. Completed document plus certificate, into your own repository, not left in the vendor's account.
- Standardise identity verification by document value. Email link for low-value routine documents; additional verification for anything material. Decide the threshold rather than defaulting to the weakest option.
- Set an authority for the platform itself. Who can send for signature, from which accounts, using whose templates. An e-signature account with open access is a contract-execution capability granted to everyone.
- Run a validation sweep on everything signed since March. Correct signatory, correct entity, correct version, evidence retained. Fix the ones that matter now, not at renewal.
- Write the policy while the crisis is still visible. Which documents may be executed electronically, by whom, with what verification, and which may not. Six months from now nobody will agree on what happened.
The Regional Angle
Four points matter here, and the first surprises people. The legislation has not been the obstacle. Electronic transactions law has recognised electronic signatures in this region since the mid-2000s, with the familiar list of exclusions, and the financial free zones have their own regimes. Nothing that has happened this month made electronic execution lawful; it was already lawful. What changed is institutional practice, and that means the blocker was never your legal department's opinion. It was the counterparty's accounts clerk, the bank's branch procedure and the ministry's submission form. Second, and most commonly misunderstood, your internal workflow does not determine who may bind the company. Signing authority here is external and registered: it sits in the trade licence, the memorandum, the board resolution and the signatory card lodged with the bank and the licensing authority. You can configure any approval hierarchy you like, and a supplier or bank will still check whether the individual appears on the authorised signatory record. If the crisis has pushed authority down to whoever is available, update the registered record as well, or you will have a well-documented internal approval attached to an unenforceable commitment. Third, acceptance runs on a chain that is still partly physical. Banks, courts, ministries, landlords and free zone authorities each have their own position, and documents intended for official use often require attestation or notarisation that historically meant appearing in person. Some courts and notarial services in the region have extended remote and video-based notarisation in the past weeks, which is a genuinely useful development worth checking for your emirate and document type. Until it is universal, the practical approach is a short matrix: counterparty, document type, what they accept today, and who to call when they refuse. Fourth, the corporate stamp remains a commercial reality even where it carries no legal weight. A purchase order without a seal will be queried by a counterparty's finance team regardless of what the contract says, and arguing about it costs more than accommodating it. Most e-signature deployments here end up applying a sealed image alongside the certified signature, which is fine as long as everyone understands which of the two is the evidence.
The objection worth taking seriously
The strongest objection is that this month is creating a legal mess rather than a modernisation. Signatures are being applied by whoever has access to a mailbox. Verification is a click on a link sent to an address nobody confirmed. Documents are being executed by people who are not authorised signatories, on behalf of entities that are not the contracting party, in versions that differ from what was negotiated. When a dispute arises in 2022, the question will not be whether electronic signatures are valid in principle. It will be whether this particular person was authorised and whether this particular document is the one that was agreed. The second objection is that permanence is being declared prematurely. Organisations revert. When offices reopen, the counterparties who insisted on originals will insist again, the finance manager who prefers a physical file will rebuild it, and the e-signature subscription bought in a panic will lapse quietly at renewal. Both are fair, and they point at the same remedy rather than at caution. Run the validation sweep now, while the documents are recent and the people involved remember; re-execute the material ones properly. And understand what will actually make this permanent, which is not preference. It is that the counterparties who accepted electronic execution this month have now seen it work, and that the cost of a courier, a printer, a notary appointment and three days of elapsed time is now visible as a cost rather than assumed as a fact of life. Things that become visible as costs tend not to come back.
Common Questions
Is a scanned signature on a PDF good enough?
For low-value internal documents, often yes. For anything material it is the weakest available option: it proves nothing about who applied it or whether the document changed afterwards. Use a platform with a certificate for commercial documents.
Do we need the most formal type of electronic signature?
Rarely, and it carries real cost and friction. Match the assurance level to the value and risk of the document, and reserve the highest tier for the small number of instruments that require it.
Where should signed contracts live?
In your contract repository, with the evidence certificate attached, not in the signing platform. The platform is a process tool, not an archive.
What should we expect over the next twelve months?
Expect counterparties to stop asking for originals as a default, and to keep asking for them for a narrow set of registrations and official filings. Expect banks and authorities in the region to extend remote submission and verification services introduced under pressure, because the queue reduction is worth more to them than to you. Expect a wave of contract validation work in the second half of the year as legal teams audit what was signed in the spring. And expect delegation of authority, not signature technology, to be the thing organisations are still fixing at the end of it.
Approval Workflow Modernization — we separate the approvals that belong in your systems from the documents that need real signatures, rebuild the authority matrix behind both, and make the evidence survive the vendor.
