Still Using a Scanned Signature? Here's the Risk Most Businesses Overlook
20 Juli 2026
Ask your legal or finance team: on the last contract they signed, was the signature actually digital, or just a scanned image pasted into the PDF?
If the answer is the latter, you are not alone. This is still common practice across many Indonesian companies, especially those still transitioning from manual to digital processes.
The reason is simple: it feels fast, requires no new application, and appears to already be paperless.
The problem is, a scanned signature only moves the visual shape of a signature from paper to an image file. It does not change its legal standing or its level of security. This is exactly where the risk begins, and it usually only becomes visible once the document is disputed, not when it was created.
Imagine a contract worth billions of rupiah being disputed years later.
The first question raised usually isn't:
"Is there a signature image on the document?"
But rather:
1. Who actually signed it?
2. When was it signed?
3. Has the document been altered after signing?
4. Did the signatory genuinely consent to the document's content?
The Risks That Are Often Overlooked
1. Not necessarily recognized as strong legal evidence. Under Law No. 11 of 2008 on Electronic Information and Transactions (as amended by Law No. 1 of 2024), certified electronic signatures issued by a PSrE (Electronic Certification Provider) carry a significantly stronger level of proof, authentication, and non-repudiation compared to a scanned signature or an uncertified electronic signature.
As a result, a scanned signature image manually pasted into a document tends not to automatically meet this standard. When a dispute arises, its validity can be challenged, making the burden of proof more difficult and time-consuming.
2. Vulnerable to forgery and duplication. A scanned signature is essentially just an image file. Images can be copied, pasted onto other documents, or edited without leaving any easily detectable trace.
There is no cryptographic mechanism binding the signature uniquely to a specific document. This is different from a certified electronic signature, which uses a digital certificate and encryption, so any change made to the document after signing can be detected.
3. No accountable audit trail. Who signed, when, from which device, and whether the document was later altered, none of this is recorded with an ordinary scanned signature.
For tightly regulated industries such as financial services, healthcare, or anything tied to legal proceedings, the absence of an audit trail becomes a compliance issue, not merely a technical one.
4. A process that looks digital but is still half manual. Print, wet-ink signature, scan, resend by email, this remains a long chain of steps at many companies even though the document is technically already "in PDF form."
The efficiency gained from digitalization ends up limited, because the bottleneck still sits in a physical step.
5. Digital transformation does not only change the way companies work, it also changes how regulators view electronic transactions. Regulations in Indonesia increasingly emphasize the importance of identity authentication, document integrity, electronic transaction security, and the ability to audit and trace digital activity.
The Electronic Information and Transactions Law (UU ITE) and its derivative regulations have established the legal basis for the use of Electronic Signatures in digital transactions in Indonesia. Across tightly regulated sectors such as financial services, healthcare, and public services, the need for accountable digital transactions continues to grow.
In this context, the use of scanned signatures increasingly faces limitations, as it does not provide the identity verification mechanism, document integrity protection, or audit trail required in a modern business environment.
[ Want to know whether your digital signature already complies with applicable law? Read the full article here! Click to Read ]
Scanned Signature vs. Certified Electronic Signature
Aspect | Scanned Signature | Certified Electronic Signature |
| Legal basis | Does not automatically meet UU ITE requirements | Stronger level compared to a scanned signature or an uncertified electronic signature |
| Security | Image-based, easy to copy | Based on digital certificate and encryption |
| Audit trail | Generally none | Recorded and traceable |
| Document tampering detection | Not detected | Automatically detected |
| Sector compliance | At risk of non-compliance | Aligned with guidance from OJK, BI, and the Ministry of Health |
It's Not About Switching Tools, It's About Reducing Weak Points in Your Business Process
The point of this discussion is not to push everyone to rush into switching tools. What matters more is understanding where the real risk sits before a critical document, a vendor contract, a partnership agreement, a financial record, becomes the subject of a dispute.
If your company still relies on scanned signatures for important documents, it is worth mapping this out first: which documents carry the highest risk if their validity is challenged, and which processes lose the most time because they still depend on a physical step.
If an important document were disputed tomorrow morning, could your company prove:
1. who signed it,
2. when it was signed,
3. that its content has not been altered,
4. and that the signatory genuinely gave their consent?
If the answer isn't certain, the problem may not lie in the document itself.
But in how the organization builds trust into its digital transactions.
Indocyber Global Teknologi helps companies map this out and connects them with a certified electronic signature solution suited to their business needs.
Discuss your certified electronic signature needs with Indocyber's professional team. Free, no commitment.
[ Click -> Certified Digital Signature ]


