Sign This, Dammit!

Live Free, Sign Hard

ad slot · header · set NEXT_PUBLIC_ADSENSE_CLIENT

2026-04-05

BankID qualified signing vs a simple e-signature: two different questions

BankID signing and a simple e-signature are not two brands for the same thing. The first is high-assurance identity, often QES. The second is a yes to a text, typically SES. You mix them when you think that without BankID the contract is air — and when you think that with BankID the wording can be sloppy.

Which question are you trying to answer?

If the question is 'could someone pretend to be the CEO', BankID and similar eID is the answer. Registry, high trust, boring and right for large sums and strangers.

If the question is 'do we have a trail that Lina saw the PDF and said yes on Tuesday', SES is the answer. Email, fields, time, maybe IP. That convinces an adult on most jobs. It will not convince a surety bank that wrote QES into policy.

Pick the question first. Tool second. Reverse that order and you buy QES for an internal lunch agreement.

A compromised inbox is the SES nightmare. A stolen eID is the QES nightmare. Different alarms. Different countermeasures. One security slogan does not hit both.

What does BankID do that a browser squiggle does not?

It ties the act to an identity banks and government already trust. Pretending to be someone else is heavy without stealing an eID. SES with an open link is easier to abuse if the inbox is compromised or the address was guessed.

That is why sane SES tools send personal links and sometimes a code. It raises the bar. It does not become QES. It becomes less embarrassing.

BankID grinds when the other side is a studio in Lisbon. Then 'we require Norwegian eID' is a business no dressed up as security.

International board members without BankID are a filter you must want. Otherwise you designed a Norway-only flow and called it governance.

What does PAdES do that BankID does not necessarily do?

PAdES sits in the PDF. Swap a paragraph later and the cryptographic check fails. BankID sessions can be logged at the provider without the PDF carrying a stamp Acrobat understands. Different layers.

You can have QES without understanding PAdES, and PAdES without QES. The latter is SES-level identity plus file maths. Acrobat may complain about the CA. The maths can still hold against that CA.

An honest product says: not qualified, not BankID, integrity against our issuer. Believe that. Do not upgrade it in your head to the national registry.

Do not let marketing write BankID-level about a drawing. That is the sentence that makes counsel stop trusting the rest of the text.

When is 'ordinary e-signature' irresponsible?

Unknown counterparty, painful sum, you can smell a dispute, or a regulation points at qualified level. Then SES is laziness, not pragmatism.

Also when you pretend SES is BankID in an email to the board. Then you have a governance problem, not a PDF problem.

For repeat relationships — the same translator, the same carpenter, the same agency — SES with a log is the adult move. You know who they are. You need the yes not to vanish in Slack.

Can you combine them in one company?

Yes. A one-page policy: QES/BankID for X, SES for Y. X is pledges, suretyship, what the board said, what the municipality demands. Y is NDAs, SOWs, three-page jobs.

Do not let every team pick in a panic. Then you get four tools and no archive. One SES track, one QES track, done.

Teach counterparties with one sentence in the send: 'this is not BankID; it is a yes to the PDF with a log'. People who need more will say so before they click, not after.

What should you say out loud, every time?

The level. SES or QES. Not 'secure signature'. The word secure means nothing.

What Acrobat will show. If the CA is unknown, say yellow triangle. If it is qualified and on the list, say that. Surprise is what feeds the myth that 'electronic does not count'.

Where the evidence lives. In the file, at the vendor, or both. If ads pay the wall, say the document is not the ad surface. People can stand honesty. They cannot stand being lured into a level they did not ask for.

How do you explain this to a board in ten minutes?

Draw two boxes. Identity. File. BankID fills the first when it is used as QES. PAdES can fill the second without touching the first. SES fills yes without filling the national registry.

Give one example they know: NDA with the agency down the street is SES. A pledge to the bank is whatever the bank says. No more.

If the board only hears risk, offer a sentence in the template: which level, what Acrobat shows, where the log lives. Risk with no specification is how you buy QES for lunch agreements and SES for the thing that actually hurts.

A practical middle step people forget: a video call where you scroll the PDF, then SES right after. Identity is I saw the face; the yes sits in the log. That is not QES. It is adult SES when the sum is ugly and eID is impossible. Write in the evidence that the meeting happened, with a date. Do not pretend Zoom is BankID.

FAQ

Is SES 'less valid' than BankID?

Not as a rule. eIDAS says electronic form must not be rejected for being electronic. QES has special effect where handwriting is required. The rest is evidence and interpretation.

Can I demand BankID from a client abroad?

You can demand it and lose the client. Without a Norwegian eID, BankID is a locked door. Use SES, or an eID that actually exists where they live.

Why offer 'crypto' if it is not BankID?

Because PDF integrity and personal identity are different. PAdES marks the file. BankID marks the person. You can have the first without the second. Say which you have.

BankID when identity is the question. SES when the text is the question. Mix them in language and you buy the wrong thing.

If you just need a PDF signed without a subscription, that’s what STD is built for.

Norsk