Advanced Electronic Signature in the FACTS Laboratory

Perhaps you’ve noticed a slight difference in the FACTS laboratory test reports. It’s a very subtle but very important change: we recently implemented an electronic signature system. This means that all test reports are now signed with an advanced electronic signature.

Why must test reports be signed?

ISO 17025:2017 requires test reports to be reviewed and authorised by an appropriate qualified person prior to their release, and also that the authorising party is identified. To satisfy these requirements, FACTS laboratory test reports are reviewed, approved and signed by a technical signatory (in the case of accredited methods). Our reports are electronically generated and sent by our Laboratory Information Management System (LIMS), therefore they must be signed by advanced digital means. This takes the form of a digital/electronic signature, which also enhances the security of the report.

What is an Electronic or Digital Signature?

This is the definition: a digital signature is a mathematical scheme for demonstrating the authenticity of a digital message or document. A valid digital signature gives a recipient reason to believe that the message was created by a known sender (authentication), that the sender cannot deny having sent the message (non-repudiation), and that the message was not altered in transit (integrity).

Public Key Infrastructure (PKI) technology, a cryptographic system that uses two digital keys, is used to create digital signatures. The first key is a private key that belongs to the signing party, and that should be kept secure and secret. The second is a public key available to all to validate the digital signature.

Why an advanced electronic signature?

In accordance with the Electronic Communications and Transaction Act, SANAS requires that advanced electronic signatures (AES) are used to sign electronic test reports. According to LawTrust, an accredited authentication service provider, an AES is a digital signature created with a digital certificate from an accredited authentication service provider, after following a face-to-face identification process with the subscriber.

How do I know the report is electronically signed?

It’s easy to see whether a test report has been electronically signed. When you open the PDF, you will notice a banner (the blue banner in the picture below) across the top of the report, bearing the words ‘Signed and all signatures are valid.’

You can also determine who signed the document by clicking on the ‘Signature Panel’ button. A Signatures panel will open on the left-hand side of the report, showing the details of the person who signed or authorised the report, as in the image below.

To determine the validity of signatures, click on the drop-down menu next to ‘Validate All’, and click on ‘Validate All Signatures’.

 

A box like the one in the example below will pop up, indicating that all signatures have been validated.

How do I know that the electronic signature is still intact?

If a test report was altered after it was signed, the banner at the top of the report will no longer state that all signatures are valid, as in this example:

This may indicate that it is not the original test report, or that some aspects of the report were altered after it was approved and signed by FACTS. If you validate the signatures, the banner will change and at the bottom of the Signatures panel a brief description of changes will be viewable, as in this example:

Please let us know if you have any questions, or need help validating our electronic signatures.