A scanned signature can make a contract look complete in seconds. That does not mean it provides the evidence your business may need when a customer, employee, supplier or auditor later asks who signed, when they signed and whether the document changed afterwards. The practical difference in AES versus scanned signatures is not simply digital versus paper. It is the strength of the connection between a person, their approval and the final document.
For teams handling employment agreements, client contracts, financial approvals or recurring supplier paperwork, that difference affects risk, administration and the speed at which disputes can be resolved.
What counts as a scanned signature?
A scanned signature is usually an image of a handwritten signature inserted into a PDF, Word document or online form. It may have started life as a wet-ink signature on paper, or it may be a PNG file someone keeps in a folder and drops into documents when needed.
The image itself does not identify the person who placed it there. It does not reliably record the time of approval, show whether the signer saw the final version, or protect the document from later edits. An email trail, access controls and document history can strengthen the surrounding evidence, but these are separate controls rather than properties of the scanned image.
That does not automatically make a scanned signature invalid. In many routine commercial situations, parties can agree to use one. The real question is whether it is proportionate to the value, sensitivity and potential challenge involved. If a signer later says, “That image was copied” or “I did not approve that version”, the business must piece together evidence from several places.
What makes an Advanced Electronic Signature different?
AES means Advanced Electronic Signature. It should not be confused with encryption standards that happen to use the same abbreviation. Under eIDAS, an AES is an electronic signature that meets defined requirements designed to create a stronger evidential link between the signatory and the signed data.
In practical terms, an AES must be:
- uniquely linked to the signatory;
- capable of identifying the signatory;
- created using signature-creation data under the signatory’s sole control, with an appropriate level of confidence; and
- linked to the signed document so that later changes can be detected.
A properly designed AES workflow does more than place a visual mark on a page. It records the signing event and creates an audit trail that can include the signer’s email address, authentication steps, timestamps, IP information, consent to sign electronically and the document’s integrity record. The exact evidence depends on the provider’s workflow and the assurance level selected.
This is why an AES is generally better suited to documents where a business needs to demonstrate a reliable process, rather than merely show a signature-shaped image.
AES versus scanned signatures under eIDAS
eIDAS is the EU framework for electronic identification and trust services. It establishes that an electronic signature should not be denied legal effect or admissibility as evidence solely because it is electronic or does not meet the requirements for a qualified electronic signature.
That is helpful, but it is not a shortcut around good process. Legal validity and evidential weight are related, not identical. A scanned signature may be accepted by the parties and may be evidence of an agreement. Yet an AES ordinarily gives the organisation more persuasive, structured evidence if authenticity or document integrity is questioned.
For many business documents, an AES offers the sensible middle ground. It delivers stronger assurance than a simple image-based approach without making every signing task as formal as a qualified process. A Qualified Electronic Signature, or QES, has additional requirements and is recognised across EU member states as equivalent to a handwritten signature. It can be the right choice where legislation, the counterparty or the risk profile requires the highest level of assurance.
Always check whether a particular transaction has formal requirements. Real estate, court filings, company-law actions and country-specific documents may demand a particular form, witness arrangement or signature type. The right signature is determined by the document and jurisdiction, not by a preference for the most technically sophisticated option.
The evidence is where the difference shows
Consider an HR manager sending a contract to a new employee. With a scanned signature, the employee could print the document, sign it, scan it and email it back. The HR team then needs to ensure the returned file is the final version, store the email, manage revisions and establish who had access to the signed PDF.
With an AES workflow, the manager sends a controlled version through a signing platform. The signer receives an invitation, completes the selected authentication step, signs the document and both parties receive a completed copy with a tamper-evident audit trail. The document status is visible without chasing emails or comparing attachments.
Neither approach eliminates every possible dispute. A person can still allege that their email account was accessed by somebody else, for example. However, AES gives the business a clearer evidential starting point and makes the signing process easier to administer consistently.
Security and operational control
Scanned signatures create a quiet security problem: they are easy to reuse. Once an image file is saved on a laptop, shared drive or inbox, it may be copied into a different document without the named person seeing it. Even where everyone acts in good faith, staff can accidentally use an outdated version or attach the wrong completed copy.
An AES process can reduce these risks through controlled invitations, signing order, reminders, role-based access and tamper detection. It also creates a single source of truth for documents that are pending, completed, declined or expired. For finance and legal teams, this control often matters as much as the signature itself.
Data handling matters too. Businesses operating across Europe should know where signing data and documents are hosted, who can access them and how long they are retained. GDPR responsibilities do not disappear because a document is sent for signature. A provider with EU-only hosting and clear access controls can support a more straightforward compliance position.
Choosing the right approach for each document
The best choice is rarely “use AES for everything” or “scanned signatures are never acceptable”. Start with the consequences if the agreement is disputed, altered, delayed or signed by the wrong person.
A scanned signature may be adequate for low-risk internal acknowledgements, informal correspondence or documents where all parties already have a well-established relationship and the signature is not the main evidence of agreement. Even then, a controlled workflow can save considerable time.
AES is a strong fit for client agreements, supplier contracts, HR documents, approvals, policy acknowledgements and recurring operational paperwork. These documents benefit from reliable identity evidence, a clear timeline and proof that the final file has not been modified after signing.
QES should be considered where a legal rule specifically requires it, a counterparty insists on it, or the financial and legal consequences justify higher assurance. It is not automatically necessary for every contract. Using QES where AES is sufficient can add cost and friction without delivering a meaningful business benefit.
Make the signing process repeatable
Signature strength is only useful if people follow the process. Teams often lose control when each employee sends PDFs from their own inbox, stores signed files in separate folders and chooses a different method for every agreement.
Build a standard route for each document category. Define who prepares the document, who approves it before sending, which signature level applies, whether signers must act in sequence and where completed records are stored. Templates are especially useful for repeat documents such as service agreements, employee letters and supplier onboarding packs. They reduce manual errors and prevent teams from starting with an old version.
An electronic signature platform should support this operational discipline without creating enterprise-level overhead. For example, Asignu combines templates, signing sequences, tracking and document organisation with unlimited Advanced Electronic Signatures, helping teams apply a consistent AES process without treating each signature as a separate purchasing decision.
A practical standard for business teams
If your current method relies on pasted signature images and email attachments, do not begin by replacing every workflow at once. Identify the documents that create the greatest exposure or consume the most follow-up time. Contracts awaiting multiple signers, employment paperwork and approvals that need an audit trail are usually sensible first candidates.
Set a clear policy for when staff may accept a scanned signature, when they should use AES and when legal review or QES is required. Then make the approved route easier than the workaround. When signing is simple, traceable and properly recorded, people are far less likely to return to uncontrolled PDFs.
The most useful signing process is not the one with the longest feature list. It is the one that gives your team enough assurance for the document at hand, while making the right action the easiest action to take.
