Regulation 7 August 2026 10 min read

Electronic Signatures in Laboratory Reports: Law and Practice

Qualified electronic certificates, time stamps and ISO/IEC 17025 report approval: the legal basis for electronic signatures on test reports and where they sit in the laboratory workflow.

WL

WiseLIMS Team

Laboratory Digitalization Experts

The signature at the bottom of a test report is the laboratory vouching for that result. On paper the process was simple: print the report, have the technical manager sign it, stamp it, file it. Moving to electronic reports raises questions: is a scanned signature pasted into a PDF valid? Does typing a name next to “approved by” count as a signature? Will it hold up in an assessment?

The short answer is no. A scanned signature image is not a signature in law; it is simply a picture. This article covers the legal basis for electronic signatures on laboratory reports, which signature type does what, and how the whole thing should sit within the laboratory workflow.

Note on scope: the legal references below are those applicable in Türkiye. The underlying concepts — qualified certificates, time stamps and the equivalence of a qualified electronic signature to a handwritten one — follow the same logic as the EU eIDAS framework, so the practical guidance applies broadly. Always confirm the requirements of your own jurisdiction and of the authority receiving your reports.

The Legal Basis: Electronic Signature Law No. 5070

In Türkiye the framework is set by the Electronic Signature Law No. 5070, dated 2004. Its central provision is this: a secure electronic signature produces the same legal effect as a handwritten signature. A test report signed properly with an electronic signature is therefore equivalent to a wet-signed report.

Not everything called an “electronic signature” carries that force, however. What the law requires is a signature based on a qualified electronic certificate, issued by an Electronic Certificate Service Provider (ESHS) authorised by the national regulator. The certificate establishes the signatory’s identity, and the signature is created using means under that person’s sole control.

Signature types you will encounter in a laboratory

  • Qualified electronic signature: Personal, based on a certificate issued by an authorised provider. Legally equivalent to a handwritten signature. This is the type to use for approving test and calibration reports.
  • Mobile signature: Carries the same legal force; the certificate is held on the SIM card and the signature is confirmed from the phone. Practical for staff working in the field.
  • Organisational (electronic) seal: Applied on behalf of the legal entity, representing the organisation rather than an individual. Useful for bulk document approval, but it does not replace the signature of the person taking technical responsibility for the report.
  • Scanned signature image: Not a signature in law. It can be copied, pasted onto another document, and offers no mechanism to prove the document was not altered.
  • In-system approval flag: An “approved” marker in the software; valuable for internal workflow, but on its own it does not give the released report legal standing.

A common mistake: converting the report to PDF and pasting in a signature image. The document looks wet-signed from the outside, yet there is no way to tell whether it was altered afterwards. The real function of an electronic signature is not to display an identity but to prove the document has not changed since it was signed.

Time Stamps: Answering “When Was It Signed?”

An electronic signature shows who signed and that the document has not changed; on its own, it does not prove when the signature was applied. That is the role of a time stamp. Under Law No. 5070, a time stamp is defined as a record, verified by an authorised provider with an electronic signature, establishing the time at which electronic data was produced, modified or stored.

For laboratories this matters. If a dispute raises the question “was this report approved before or after the test date?”, the time stamp answers it. It is also the mechanism that allows you to show a signature was valid at the time it was applied, even after the certificate itself has expired.

What to Consider When Signing an ISO/IEC 17025 Report

ISO/IEC 17025:2017 defines what reports must contain and who must approve them in clause 7.8. The standard does not state whether the signature must be wet or electronic; it does require the report to be reviewed and authorised by designated personnel, and any amendment after issue to be clearly identified. An electronic signature maps directly onto both requirements.

What an electronically signed report should provide

  • Identity and authority of the signatory: The name, role and the fact that the person was authorised for that activity should be visible in the system.
  • Time of signature: Supported by a time stamp and consistent with the report date.
  • Immutability: If a single character is added after signing, the signature should become invalid — this is the defining property of an electronic signature.
  • Means of verification: The customer or assessor receiving the report should be able to verify the signature independently. A QR code or verification link is the common solution.
  • Revision trail: If an issued report is corrected, the earlier version must not be deleted; it should be retained with its revision number and rationale.
  • Archive accessibility: The signed report must remain openable and verifiable for the full retention period, which directly affects your choice of file format and archive infrastructure.

Who should sign?

The standard requires the person approving the report to be authorised for the relevant activity. In practice the technical manager or test supervisor signs. The critical point is that this authorisation is documented and current: assessors regularly ask “was the person who signed this report authorised for this test?” and expect the answer to be shown from competence records.

Another frequent error is using an absent colleague’s credentials to sign. An electronic signature certificate is personal; applying someone else’s signature on their behalf is a serious nonconformity, both legally and in accreditation terms.

What if the report changes?

If an issued report requires correction, ISO/IEC 17025 requires the amendment to be clearly identified and the original to remain traceable. In an electronic environment the correct approach is to produce and sign a new revision while retaining the earlier version, flagged as superseded. Overwriting is unacceptable, both under the standard and from a data integrity standpoint.

Friction Points When Moving from Paper

The obstacles most often encountered

  • “Our customer wants a wet signature”: Many recipients, public bodies included, now accept electronically signed reports. Most of the resistance comes from not knowing how to verify them; adding a verification link largely removes the objection.
  • Signature order and workflow: Does the report pass technical review before or after signing? In an electronic workflow this sequence must be defined in the system, otherwise you end up needing to intervene in an already-signed report.
  • Certificate validity: Qualified certificates are issued for a fixed term. An expired certificate cannot sign; without renewal tracking, report delivery stalls.
  • Signing in the field: During sampling or on-site inspection, staff are not at their desk. A mobile signature is the practical answer.
  • Archive format: For long-term retention, an archival PDF format should be used together with a time stamp so the signature remains verifiable.

Frequently Asked Questions

My customer insists on a wet signature — what should I do?

First understand the reason. Usually the issue is practical rather than legal: the recipient does not know how to check the authenticity of the PDF. Adding a verification link or QR code, together with a brief note that the signature carries the same legal effect as a handwritten one, generally resolves it.

Some buyers may still require a wet signature contractually. In that case the electronically signed original can be retained in the archive while a printed copy is provided — but the electronic version remains the record of reference.

What is the difference between an electronic signature and an electronic seal?

An electronic signature belongs to a natural person and carries that person’s declaration. A seal belongs to the legal entity and carries the organisation’s declaration. A test report requires the signature of the person taking technical responsibility; a seal does not replace it, though it can be used for correspondence or bulk document approval.

Will I be able to verify a signed report ten years from now?

A time stamp is essential to demonstrate that the signature was valid at the time of signing once the certificate has expired. For long-term archiving, the signature and time stamp are retained together and a PDF format suited to long-term validation should be preferred.

Can the same person enter the result and sign the report?

ISO/IEC 17025 requires review and authorisation to be carried out by designated personnel; in small laboratories the same person may both perform the analysis and approve it. What matters is that the authorisation is defined in writing and that the person is designated for that activity. Where feasible, separating analysis from approval presents a stronger picture during assessment.

How Electronic Signatures Fit into Laboratory Software

An electronic signature is not a standalone product; it is the final link in a workflow. If the system does not track which data the report was generated from, who reviewed it and which version was issued, the signature may hold legal force but you will have no story to tell during an assessment.

Report approval and signing in WiseLIMS

  • Template-based generation: Reports are produced from result data, eliminating errors introduced by manual copying.
  • Review and approval steps: Result entry, technical review and approval are separate steps; who performed each and when is recorded.
  • Electronic signature support: Approved reports are signed electronically and the signed version is retained in the system.
  • Barcode/QR verification: The code added to the report lets the recipient confirm the authenticity of the document in hand.
  • Revision management: Corrected reports are issued as new versions while earlier versions remain accessible.
  • Authority control: Report approval is restricted to personnel designated for that activity, with competence records held on the personnel card.

Conclusion

Electronic signatures on laboratory reports are no longer a matter of keeping up with digitalization. The law treats a qualified electronic signature as equivalent to a handwritten one; ISO/IEC 17025 requires reports to be authorised by designated personnel and amendments to remain traceable. An electronic signature satisfies both at once.

Scanned signature images nonetheless remain widespread, and many laboratories are unaware that they carry no legal weight. When reviewing your own system, ask: “How would we prove that the report we sent yesterday has not been altered since delivery?” If the answer is “because we produced the PDF”, it is time to revisit your signing infrastructure.

Manage Reports with Electronic Signatures

Generate reports from templates, have them approved by designated personnel, sign them electronically and make them verifiable with a QR code.