What is a Qualified Electronic Signature (QES)?

Certificate with a blue ribbon badge marked qualified electronic signature qes and the label qualified certificate | complycube

TL;DR: A Qualified Electronic Signature (QES) provides one of the highest levels of assurance for signature verification under the eIDAS regulation. It offers the same legal equivalent as a handwritten signature. For regulated industries, QES signatures can support stronger remote onboarding and secure identity assurance.

How Did Qualified Electronic Signatures Originate?

Before the European Union (EU) harmonized electronic signature rules, each member state had its own framework. This changed with Regulation (EU) No 910/2014 (eIDAS), which came into full force in July 2016. The eIDAS regulation defined common terms for electronic signatures, qualified electronic seals, trust services, and Qualified Trust Service Providers (QTSPs). It also established QES as the most secure and highest-assurance electronic form of signature under EU regulation.

The ecosystem has changed fast since then. The number of certified remote Qualified Signature Creation Device (QSCD) products increased from around five in 2016 to around 40 at the end of 2025. Some Italian public-sector services process about 577 million remote signatures monthly.

QES will also be further embedded in daily digital interactions through the EU Digital Identity Wallet (EUDI Wallet) framework. Implementing Regulation 2024/2979 requires wallet solutions to support qualified electronic signatures and to interface with QSCDs.

The Requirements for a Qualified Electronic Signature (QES)

A qualified electronic signature is a special, regulated type of digital signature and has the strongest legal effect under the eIDAS regulation. The term “qualified” is not a marketing label. Instead, signatures that satisfy all eIDAS requirements and possess a valid qualified certificate may use that term.

A QES must:

  • Be uniquely linked to the signatory and created under their sole control.
  • Be created using a QSCD, which protects the signature creation data and private key.
  • Be issued by a Qualified Trust Service Provider that is listed in national Trusted Lists.

QES signatures operate on three principles. Firstly, it has the same legal effect as a handwritten signature. Secondly, it supports non-repudiation, acting as irrefutable legal proof in the event of litigation. Third, its interoperability means it is mutually recognized across the EU. As such, EU member states must accept qualified electronic signatures as valid.

SES, AES, and QES Differences and Legal Implications

The eIDAS regulation divides electronic signatures into three main security levels: Simple Electronic Signatures (SES), Advanced Electronic Signatures (AES), and Qualified Electronic Signatures (QES). The use case for each signature type will largely depend on the level of identity assurance, security, and legal certainty a business needs.

Image has the title 3 levels of electronic signature under eidas  this is followed by a table that compares simple electronic signatures ses advanced electronic signatures aes and qualified electronic signatures qes | complycube

To simplify, SES typically indicate a customer’s intent to sign or approve something electronically. They do not require strong identity verification or cryptographic protection. Common use cases for SES include low-risk agreements, online acceptances, internal approvals, and basic contracts.

One level of assurance up is AES. These signatures uniquely link to the signer, identify the signer, and detect changes to the signed data. Organizations rely on AES for employment documents, business agreements, and financial transactions that require stronger evidence of identity and authenticity.

On the other hand, the QES offers the highest assurance. It uses a qualified digital certificate issued by a provider with qualified status, created using a QSCD. These QTSPs, which provide qualified trust services, are also subject to regulatory supervision. Regulated transactions or government services typically require a qualified electronic signature to ensure higher legal certainty.

SES vs QES: Does the Difference Matter?

Simple electronic signatures have fewer prescribed technical and identity-assurance requirements than the QES. It is important to note that eIDAS does not permit refusal of legal effect solely because the signatures do not meet the stricter requirements for a QES, meaning SES is still legally valid. SES is often enough when the risk present is low, and the main outcome is to record a person’s intent.

However, if someone disputes the signature, the company must rely on other supporting records, such as directly contacting the customer to establish who signed and their intent. QES strengthens this evidence by linking the signature to a verified signatory, a qualified certificate, and a regulated trust framework. In practice, SES serves low-risk transactions, while QES serves regulated, high-value, or legally sensitive processes.

AES vs QES: What Does QES Add?

To start, AES already offers strong security controls. The AES must be uniquely linked to the signatory, using their signature creation data under control, with high confidence. However, a QES signature satisfies several additional criteria. A qualified electronic signature must use a qualified certificate from a certified provider, and a QSCD must generate it.

This added regulatory layer is a key difference. EU member states recognize only QES as having the same legal effect as a handwritten signature. While AES can provide strong technical evidence of identity and integrity, QES adds a formally regulated trust framework across the EU.

AI, Deepfakes, and the Role of QES in Fraud Prevention

Generative AI has made it easier to create false IDs, selfies, documents, deepfakes, and even voice calls at scale. In 2025, scammers using sophisticated AI tools stole at least £1.3 billion. As such, it paints a problematic picture in which visual proof is becoming easier to fake.

Individuals can mass-produce a pasted signature image in seconds

QES helps reduce that risk by linking a signature to a verified identity, offering stronger signer authentication and cryptographic evidence of document integrity. As such, it reduces reliance on weaker trust signals, making account takeover and fake documents more difficult to carry out.

For example, take a deal worth $10 million. With a basic SES, a signer might claim that someone accessed their email account and approved the agreement. AES provides stronger evidence of identity and document integrity by linking a signature to the verified owner and detecting signs of tampering. With QES, you add another layer of compliance. To put it simply:

SES: “Do you have evidence of this person’s intent to sign?”
AES: “Can we prove beyond doubt who signed and that no one changed the submitted document?”
QES: “Can all the above be done with an EU-regulated trust framework and offer statutory handwritten-signature equivalence?”

Harry Varatharasan, ComplyCube’s Chief Product Officer, notes that individuals can mass-produce a pasted signature image in seconds. He adds, “This is exactly why the cryptographic backbone of QES can be a non-negotiable for building a critical defense layer.” However, QES signatures are not the one-all to stopping deepfake or AI fraud attacks. Instead, their value lies in lessening reliance on trust signals that are increasingly easy to fake.

When Do You Need a Qualified Electronic Signature?

A QES signature may not be necessary for every single agreement. Instead, compliance teams should collaborate with legal and information security to define exactly when SES, AES, and QES are appropriate. Matching the security level of each electronic signature to the risk of the transaction or relationship helps businesses achieve a risk-based framework.

Common questions to consider when designing a signature process include regulatory requirements, formal requirements, and risk appetite:

  • Regulatory Expectations: Leading regulators, including the Financial Action Task Force (FATF), the Monetary Authority of Singapore (MAS), and the U.S. Financial Crimes Enforcement Network (FinCEN), expect higher identity assurance where the risk of financial crime is high. These scenarios include transactions involving Politically Exposed Persons (PEPs) or complex ownership structures.
  • Formal Requirements: Certain supervisory bodies require QES signatures for legal compliance. For example, the European Commission requires documents submitted electronically in certain competition proceedings to be signed using at least one QES signature compliant with eIDAS.
  • Internal Risk Appetite: Many organizations choose to use QES signatures to meet internal risk management and compliance standards. Although not required by law, these businesses choose qualified electronic signatures for scenarios involving multiple documents containing sensitive information, high-value transactions, or corporate actions such as board resolutions.

Additionally, to establish a strong governance framework, businesses should document all electronic signature decisions and supporting evidence in internal records. This includes defining when AES versus QES is required, aligning signature requirements with the organization’s risk assessment and Anti-Money Laundering (AML) policies, recording exceptions and the rationale behind them, and maintaining sufficient evidence to demonstrate these decisions to regulators or auditors.

Common Documents and Scenarios for Using QES

Furthermore, organizations can apply a qualified electronic signature at specific control points in Know Your Customer (KYC) processes, rather than every interaction. This allows businesses to strengthen identity assurance for higher-risk or legally significant documents while keeping the wider signing journey user-friendly, reducing unnecessary face-to-face checks, and decreasing friction for customers.

Infographic outlining when to use a qualified electronic signature qes with a central qes badge and six use case boxes | complycube

Common documents and scenarios that may warrant QES signatures include tenancy agreements with a significant rental value, cross-border property purchases, sensitive internal documents, loan agreements involving complex financing arrangements, and major changes to account mandates.

Key Takeaways

  • Qualified Electronic Signatures have the same legal effect as a handwritten signature in the EU.

  • eIDAS regulates the criteria that QES signatures and Qualified Trust Service Providers must meet.

  • The EU framework regards the legal evidentiary value of a QES signature as very high.

  • A QES is essential in regulated industries that require high-level document integrity and assurance.

  • A Simple Electronic Signature offers the lowest level of identity assurance, followed by AES, and QES.

Strengthen Assurance with Qualified Electronic Signature Verification

A QES signature eliminates reliance on physical document printing and accelerates contract execution. It provides legal equivalence, strong identity assurance, document integrity protection, and strengthens operational efficiency. Because the eIDAS regulation recognizes it, businesses can obtain approvals, agreements, and consent within a single trust framework rather than rely on country-by-country paper-based processes.

Most importantly, QES should complement, rather than replace, AML/KYC controls. While an advanced electronic signature can provide strong evidence of the signer’s identity and safeguard the integrity of a document, it cannot verify other information, such as the source of funds, the source of wealth, beneficial ownership, or sanctions status.

ComplyCube offers a secure and trusted end-to-end AML platform, equipped with three levels of electronic signatures that are fully compliant with the EU eIDAS framework. Reduce customer friction while strengthening trust in remote transactions. Get started by speaking with one of our experts today.

Blue hero banner with the complycube logo and the line  | complycube'Start a conversation today to learn more about our solutions.'

Frequently Asked Questions

Can an Qualified Electronic Signature (QES) expire?

Not necessarily. A Qualified Electronic Signature (QES) does not automatically become invalid just because a document or certificate expires. Instead, its validity will be assessed at the point of signing. Businesses use qualified timestamps or long-term validation evidence to prove that the certificate was valid when the QES was created.

Can you mix QES and AES signatures on a single document?

Yes, a single document may contain both Qualified Electronic Signatures (QES) and Advanced Electronic Signatures (AES). Each signed documents will retain its own validity, however whether the document is legally binding depends on the law and the formal signature requirements that apply.

Are QES recognized outside the EU?

Qualified Electronic Signatures (QES) are automatically recognized across the EU under the eIDAS framework. However, this does not necessarily apply outside the EU. Recognition in non-EU jurisdictions will depend on local laws and any applicable international or mutual-recognition arrangements.

What is the difference between digital signatures versus electronic signatures?

While digital signatures and electronic signatures may be used interchangeably, they are different terms. To put simply, digital signatures uses cryptographic technology to authenticate a signer and protect the integrity of signed data. An electronic signature is a broad legal concept under eIDAS that indicate agreement or intent to sign.

How does ComplyCube’s QES signatures meet regulatory requirements?

ComplyCube’s electronic signature solutions supports SES, AES, and QES assurance levels around the requirements of the eIDAS framework. Its unified AML platform combines verified identity, cryptographic protection, and QES-level signing within the same customer journey. It supports non-repudiation and maintains tamper-evident and timestamped records.

Table of Contents

More posts

U S Treasury seal beside a stack of gold coins and an american flag symbolizing federal finance | complycube

FinCEN Exposes Digital Asset Investment Scam Network

FinCEN linked approximately $12.7B to digital asset investment scams run through overseas scam centers. See how these networks move illicit funds and what the findings mean for KYC, AML, and ongoing monitoring....
Visual showing a checked contractor and a different worker on site highlighting why businesses must verify contractor identity when the person doing the work changes | complycube

The Ultimate Guide for Right to Work Checks for Contractors in 2026

Understand how UK businesses should classify contractor relationships, apply Right to Work checks, manage evidence and substitutes, and prepare for the expanded contractor rules taking effect from 1 October 2026. more confidently....
Western union logo on a white rounded card with an australia flag badge and a magnifying glass on a light blue background | complycube

Western Union Ongoing AUSTRAC Investigation

AUSTRAC has launched an enforcement investigation into Western Union, putting its AML programme, transaction monitoring, and governance under scrutiny. In July 2025, the firm faced similar scrutiny over its compliance processes....