Qualified Electronic Signature

Product overview

Qualified Electronic Signature (QES) lets clients sign formal or legal documents electronically with a high level of assurance about the signer's identity. Under the eIDAS Regulation, a QES has the same legal effect as a handwritten signature.

A QES is created using a qualified electronic certificate, which can only be issued by a Qualified Trust Service Provider (QTSP) after the client's identity has been verified to the required standard. Identity verification is performed through Fourthline Identity Verification.

From August 2026, you can use Fourthline as the QTSP for Identity Verification and QES workflows. To get started, contact your Fourthline success manager, or get in touch.

Important

QES standalone workflows continue to work with third-party QTSPs as before. Support for Fourthline’s QTSP will be added at a later date.

Our QES solution complies with EU regulation No. 910/2014 (eIDAS Regulation) for electronic transactions within Europe, and with European Telecommunications Standards Institute (ETSI) standards.

Use QES with your Identity Verification solution to build compliant onboarding flows for supported markets, such as France, Portugal, and Germany.

How it works

The first diagram shows the Fourthline QTSP flow, and the second shows a third-party QTSP flow.

Fourthline QTSP flow
Third-party QTSP flow

Initial eligibility checks

The client enters the signature flow and Fourthline performs the following initial checks to confirm the client is eligible for a signature:

CheckDescriptionRequired
Client IDWe check if the clientId exists and there is a pending or successful Identity Verification case for the client.Required
ID documentWe check if the client's ID document is still valid and that you still support that document type.Required
Client enters signature flow

Introduction screen


Additional eligibility checks

Fourthline performs the following further eligibility checks:

CheckDescriptionRequired
Device modelIf the related Identity Verification case is less than 24 hours old, we check if the client is still using the same device model.Required
GeolocationWe check if the client's current geolocation is in a prohibited country.Optional
ID documentIf last checked more than 24 hours ago, we re-check if the client's ID document is still valid and that you still support the document type.Required
SanctionsIf last checked more than 24 hours ago, we re-check if there are any sanctions hits for the client.Optional
SelfieWe ask for a new selfie to confirm the client is the same person as in the related Identity Verification case if the case was completed:
More than 24 hours ago, or
Less than 24 hours ago and the client is using a different device model
Required
Client shares their geolocation

Geolocation check (optional)

Client provides a new selfie

Selfie check (if required)

More information

For the complete list of supported countries and territories, request our CDD Policy from your Fourthline delivery manager.


Document approval and signature confirmation

The client views and approves the documents to sign. They can preview, download, and share the documents by selecting the Preview icon.

The client accepts the applicable QTSP legal terms and conditions.

There is no limit to the number of documents that the client can sign in a single signature flow.


Fourthline QTSP signature confirmation

To confirm the signature, the client selects Sign. This confirms that they have reviewed the documents and consent to signing them electronically using a QES with Fourthline as the QTSP.

Unlike the third-party QTSP flow, the Fourthline QTSP flow does not require a one-time passcode.

Client approves document(s) to sign and accepts legal agreements

Fourthline QTSP document approval and signature confirmation

Third-party QTSP signature confirmation

When Fourthline uses a third-party QTSP, the QTSP issues the qualified electronic certificate using the client's first and last names and ID document number, and shares the certificate with Fourthline.

The client receives an SMS with a one-time passcode, which they must enter in the signature flow to confirm signing.

Client approves document(s) to sign and accepts legal agreements

Third-party QTSP document approval and signature confirmation


Document signing

Fourthline applies the signature to the documents and notifies you via a webhook when they are ready to download.

You are responsible for sharing the signed document with the client. For reliable signature validation, we recommend that the client opens the signed document using Adobe Acrobat Reader, which is the most widely used application for validating digitally signed PDF documents.

Some PDF viewers, such as web browser PDF viewers or macOS Preview, do not fully support electronic signature verification. In these viewers, the document may appear digitally signed but can display a warning such as: Signature not verified. This warning does not necessarily mean the signature is invalid. It usually occurs because the viewer does not fully support the certificate validation process.

Signature validation in Adobe Acrobat Reader

The following instructions can be shared with the client to validate the signature.

To validate the signature:

  1. Open the signed PDF in Adobe Acrobat Reader.
  2. In the top notification bar, click Signature Panel or View Signed Version.
  3. Select the signature displayed in the panel.
  4. Click Signature Properties.
  5. Review the Signature Validation Status to confirm that the signature is valid.
  6. Optionally, click Show Signer’s Certificate to view certificate and trust details.

If the signature is valid, Adobe Acrobat Reader displays a message such as Signature is valid.


FAQ

Why does my PDF signature appear as unverified?

The PDF viewer you are using may not support the signature-validation capabilities required to verify the document.

A signature appearing as unverified does not by itself mean that the signature is invalid or that the document has been modified.

How can I verify the signature?

Open the PDF in Adobe Acrobat or Adobe Acrobat Reader and check the signature status there.

Can I verify the signature in a browser or macOS Preview?

No. Use Adobe Acrobat or Adobe Acrobat Reader to verify Fourthline PDF signatures. Chrome, Firefox, Safari, and macOS Preview can display the PDF, but do not provide the signature-validation information available in Acrobat or Reader.

What do your clients need to know?

Ask your clients to open the PDF in Adobe Acrobat Reader to verify its digital signature. They should not use a web browser or macOS Preview for signature verification.

Why doesn't Adobe Acrobat recognize a newly approved QTSP?

Adobe Acrobat does not check the live EU Trusted Lists when validating a signature. Instead, it uses a local snapshot of qualified trust providers derived from the EU Trusted Lists and updated periodically by Adobe.

As a result, a newly approved Qualified Trust Service Provider (QTSP) may not be recognized in Acrobat immediately after being added to a Member State Trusted List.

How long can it take for Adobe Acrobat to recognize a new QTSP?

Adobe typically publishes an updated EUTL-derived trust snapshot once a month, usually during the first week of the month.

It can take up to approximately 30 days for a change to a Member State Trusted List to be reflected in Adobe's trust data. After Adobe publishes the update, an Acrobat installation may take up to an additional 14 days to download the updated trust data.

What contact details are required for QES?

When using Fourthline as the QTSP, you must provide either the client's phone number or email address. We recommend providing a phone number whenever possible because it is supported by a wider range of QTSPs.

For API integrations, provide the client's contact details before the client reaches the contact details screen. If the contact details have already been provided, the SDK skips this screen.


Next steps

Learn how to include Qualified Electronic Signature in your Identity Verification solution.

For a standalone use case, see the Integration Guide.


Get in touch