Introduction

An Advanced Electronic Signature, often shortened to AES, is an electronic signature that meets the higher-assurance requirements in eIDAS Article 26. It must connect the signature to the signer, help identify that signer, rely on data under the signer's control, and show if the signed data changes later.

For business teams, AES is not a slogan or a vendor badge. It is a signing evidence model. The practical question is whether your workflow can prove who signed, what they signed, how they were authenticated, and whether the final record stayed intact.

What an Advanced Electronic Signature means under eIDAS

Under the EU eIDAS framework, an advanced electronic signature is a signature type that satisfies the Article 26 requirements in the consolidated eIDAS Regulation text. That makes AES more evidence-heavy than a simple electronic signature, but different from a qualified electronic signature, which adds qualified certificates and qualified trust service provider requirements.

This distinction matters in procurement. A team should not ask only whether a platform can collect a signature image or click-to-sign acceptance. It should ask whether the platform can preserve signer identity evidence, authentication records, timestamps, certificate or integrity evidence where relevant, and an audit record that reviewers can actually use.

The four AES requirements

Linked uniquely to the signer

The signature should be connected to a specific signer, not merely to a shared inbox, a downloaded file, or an anonymous approval action. In practice, this means the workflow should record the signer's email, phone, account, certificate route, identity check, or other authentication signal that ties the action to one person or organization.

Capable of identifying the signer

AES does not require the same identity process in every situation. A low-risk internal approval may use a different identity route from a regulated cross-border agreement. The key is that the evidence should be strong enough for the document type, signer region, counterparty expectations, and legal review path.

Created under the signer's control

The signing process should reduce the risk that someone else can trigger the signature without the signer. Access codes, email OTP, SMS OTP, account verification, SSO, certificate checks, or stronger identity routes can all support this requirement when configured appropriately.

Linked to the signed data so changes can be detected

AES requires a connection between the signature and the signed content. If the agreement changes after signing, reviewers should be able to detect that change or rely on a final signed record that preserves the version, timestamp, audit record, and integrity evidence.

AES vs SES vs QES

CriteriaSESAESQES
Main purposeCapture electronic consent or approvalCapture stronger signer identity and integrity evidenceMeet the qualified signature route under applicable eIDAS rules
Typical evidenceSignature action, email, timestamp, basic recordSigner identification, authentication, control, tamper evidence, audit recordQualified certificate, qualified trust service provider route, stronger legal presumption in the EU
Common business fitLow-risk approvals, acknowledgements, simple workflowsB2B agreements, procurement approvals, HR documents, higher-value cross-border workflowsHigh-assurance documents where law, recipient policy, or risk review requires QES
Buyer checkIs simple consent enough?Can the workflow prove signer identity and document integrity?Does the document need a qualified certificate and qualified trust route?

The important point is not that AES is always better. The right level depends on the document, the signer, the receiving party, and the evidence burden your team may face later.

When AES is enough for business agreements

AES often fits business agreements where the team needs stronger evidence than a simple approval but does not need the QES route. Examples include procurement approvals, vendor agreements, HR confirmations, sales operations documents, internal policy acknowledgements, and cross-border commercial workflows where identity evidence and signed record retention matter.

AES is usually worth evaluating when the agreement has one or more of these traits:

  • the signer is external to your organization.
  • the agreement value is high enough to justify stronger evidence.
  • the signer region or receiving party expects more than a signature image.
  • the workflow needs audit records, authentication logs, and signed record retention.
  • the team may need to export records for legal, finance, HR, or compliance review.

What evidence an AES workflow should capture

Use this checklist before calling a workflow AES-ready:

Evidence itemWhy it matters
Signer identity evidenceShows who performed the signing action and how identity was checked.
Authentication recordHelps prove that the signer, not an unrelated user, accessed the signing session.
Signature control evidenceShows the signer acted through a controlled route such as account verification, OTP, SSO, certificate, or identity check.
Timestamp and event historyReconstructs the sequence of sending, viewing, signing, completion, and download.
Document integrity evidenceHelps detect whether the signed content changed after signature.
Audit record exportGives legal, compliance, HR, finance, or procurement teams a reviewable record.
Signed record retentionKeeps the final signed agreement accessible for the retention period your business needs.

Nota Sign is a global eSignature and agreement-workflow platform with APAC compliance expertise for teams operating across APAC, Europe, and the United States. It supports agreement workflows that need signer identity evidence, audit records, signed record retention, trusted signing routes, and regional rollout planning.

For AES-style workflows, the value is not simply collecting a signature. The value is designing the signing route so that the final record can answer practical reviewer questions: who signed, what identity evidence was captured, what version was signed, what happened during the session, and where the signed record is retained.

Teams comparing AES, QES, and other signature levels can also review Nota Sign's related guide to trusted digital signatures and AATL and evaluate platform controls through the Nota Sign Trust Center.

Final Recommendation

Use AES when the agreement needs stronger signer identity and integrity evidence than a simple electronic signature, but the document does not clearly require QES. Before changing platforms or signature levels, map the document type, signer regions, authentication method, audit record, signed record retention, and receiving-party expectations.

For a signing-level workflow review, talk to Nota Sign sales with your document categories, signer regions, identity requirements, audit needs, and retention rules.