Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
AI, Automation & Digital Finance
1AI Foundations
Artificial Intelligence in FinanceAlgorithmNeural Networks and Deep LearningMachine LearningArtificial Intelligence vs Machine…Computer Vision in FinanceTraining Data and LabelsNatural Language Processing in Finance
2Generative AI
Generative AIGenerative AI vs Predictive AILarge Language ModelsEmbeddingsHallucinationFine TuningPrompting vs Fine TuningThe PromptThe Context WindowTool CallingGroundingVector DatabasesRetrieval Augmented GenerationRAG vs Fine Tuning
3Automation and Workflow
Workflow AutomationAutomation vs AugmentationHow to Map a…Straight-Through Processing and Exception…Robotic Process AutomationRule EnginesMachine Learning vs Rule-Based…
4Document and Operations AI
Intelligent Document ProcessingBatch vs Real-Time vs…Document Classification vs Entity…Service Level AgreementsCase ManagementHow to Document Data…Reconciliation AutomationOptical Character Recognition and Data ExtractionConfidence Scores
5Customer Systems, Identity and Digital Assets
Digital IdentityConsent ManagementBlockchain and Distributed LedgerChatbots and Conversational AIFrom Use Case to ProductionDigital Assets and TokenisationDigital SignaturesData Sharing in FinanceElectronic KYC and Digital Onboarding
6Credit and Fraud Systems
The Fraud AlertCredit Decisioning SystemsHuman in the Loop…Adverse ActionAnomaly DetectionThe Decision ThresholdCredit Score vs Credit DecisionAlert Triage and EscalationFraud Detection and Transaction MonitoringFraud Model vs Credit ModelHow to Build Human…
7Governance, Data and Vendors
AI Governance and the AI PolicyHow to Create an…Explainability and Interpretability ComparedThe AI VendorBias and Fairness in Financial AIShadow AIAccess Control and Data MinimisationCloud Computing in FinanceData Lineage and Master DataData ResidencyThe AI Use Case Register and Model InventoryThe Model Owner
8Model Performance, Monitoring and Resilience
Model DriftFalse Positives and False NegativesClassification MetricsAdversarial AttacksModel TestingBias, Fairness and Explainability…Stopping an Automated SystemModel ValidationAI Governance vs Model Risk ManagementPrompt InjectionHow to Create an…

Digital Signatures: Proving Who Signed and That Nothing Changed

A signature is asked to establish four things: that a named holder of one private key signed, that they meant to sign, that nothing in the document changed afterwards, and that all of it can still be shown years later. A digital signature carries the first and third mechanically. The fourth is not a property of the signature at all. The record that survives is something somebody has to keep.

Consider the last thing anybody signed, and ask who the signature was actually for. The signer was there and the person across the table was there, so neither of them needed convincing. A signature is written for a stranger in the future. Somebody who was not in the room, who has no reason to take anybody's word for anything, and who is holding the document years later when the office has moved, the officer has retired and everybody's memory of that afternoon has gone soft. Every property a signature is asked to carry is a property that stranger needs. The subject gets much easier the moment the question stops being what a signature is and starts being what that person, on that later day, will actually be able to check.

What is a signature actually being asked to prove?

Four things, and they are worth pulling apart before any mechanism appears. A mechanism only carries some of them, and finding out which ones it quietly drops is the useful part.

No.The propertyThe question it answers for the stranger in the future
1IdentityWho signed this, and can that be tied to a named person rather than to a description of one?
2IntentDid they mean to sign, or did the signature happen as a side effect of something else they were doing?
3IntegrityIs this the same document that was signed, down to the last clause and the last figure?
4The record that survivesCan all of the above still be shown today, years after the signing, by somebody who was not there?

Read that fourth row again. The fourth row is doing something the other three are not. Properties 1, 2 and 3 are about the moment of signing. Property 4 is about every day after it. The first three are settled in an afternoon and the fourth is settled over a decade. An institution can get the first three perfectly right and still find itself unable to prove anything at all.

An everyday version, and it is exact rather than loose. Somewhere in most households there is a photograph of a wedding. Everybody in it can be named, so identity holds. Nobody has cut anything out of it or pasted anything into it, so integrityThe property that nothing in the document changed after it was signed, so the thing being read now is the thing that was agreed then. holds. Somebody meant to take it, so intentThe property that the signer meant to sign. No mechanism produces it on its own; it comes from the circumstances of the act. holds. Then a grandchild asks which year it was, and the room goes quiet. Nobody ever wrote it on the back. Nothing about the photograph has decayed. The one fact that decayed is the year, known to everybody in the room on the day and written down by nobody.

THREE PROPERTIES ARE SETTLED IN AN AFTERNOON. THE FOURTH IS SETTLED OVER A DECADE. THE MOMENT OF SIGNING YEARS LATER SETTLED ON THE DAY 1 IDENTITY produced by the mechanism 2 INTENT from the circumstances only 3 INTEGRITY produced by the mechanism All three are finished by the time the signer stands up. SETTLED EVERY DAY AFTERWARDS 4 THE RECORD THAT SURVIVES Not produced by the mechanism at all. Produced by what somebody chose to keep, and by whether they are still keeping it on the day the question is finally asked. WHAT PROPERTY 4 IS MADE OF The document as signed, the signature, the certificate as it stood on the day, and evidence of when the signing happened.
Identity, intent and integrity are all settled by the time the signer stands up, while the record that survives is settled by what somebody chose to keep and is still keeping years later.
Try it out

Which of the four properties is not settled at the moment of signing at all?

AI For Finance Bootcamp — Fin Maverick

Is a typed name at the bottom of an agreement a digital signature?

No, and the difference is not one of strength. A typed name and a digital signature are two different artefacts that answer different questions, and a reader who treats them as a weak version and a strong version of one thing will make the same mistake an institution makes when it buys the first and reports it as the second.

An electronic signatureA typed name, a tick box or an image of a signature, which carries intent at best and nothing mechanical about identity or integrity. is the broad category. A typed name at the foot of a printed sheet. A tick in a box beside the words I agree. A scanned image of a handwritten signature dropped into a file. The squiggle drawn with a fingertip on a delivery agent's handheld screen. Almost everybody has produced one and almost nobody would recognise their own.

The four questions can be put to that squiggle. Identity: the screen recorded a finger movement and has no way to attach a name to it, so it establishes nothing. Integrity: nothing either. The delivery note could be reprinted with different contents tomorrow and the squiggle would sit under it just as happily. Intent: this one it does carry, and honestly. The person knew they were accepting the parcel and meant to do it. An electronic signature carries property 2 at best, and carrying property 2 is not nothing. In an enormous number of ordinary situations intent is the only thing in dispute.

A digital signatureA private key operation over a fingerprint of a document, which stops matching the moment anything in the document changes. is a much narrower thing. The mark it leaves is a private key operation over a fingerprint of the document. A private key is set out under digital assets and tokenisation, where it does the job of controlling an asset. The same object does a completely different job here, producing a mark that only one holder could have produced and that is tied to one exact document. A mark of that construction carries properties 1 and 3 mechanically, meaning without anybody's memory, testimony or good faith being involved.

NOT A WEAK ONE AND A STRONG ONE. TWO ARTEFACTS CARRYING DIFFERENT PROPERTIES. THE PROPERTY BEING ASKED FOR ELECTRONIC SIGNATURE DIGITAL SIGNATURE 1 IDENTITY who signed it NOT CARRIED anybody at that keyboard could type it CARRIED, MECHANICALLY one key holder could produce it 2 INTENT they meant to sign CARRIED, AT BEST the act itself is the evidence CARRIED, AT BEST from the circumstances, not the maths 3 INTEGRITY nothing changed since NOT CARRIED the page above it can be replaced CARRIED, MECHANICALLY one changed word breaks the check 4 THE RECORD THAT SURVIVES still showable years later NOT CARRIED nothing in the artefact keeps itself NOT CARRIED an archive carries it or nobody does The strong artefact and the weak one agree on the bottom row: neither of them carries property 4, and that row is the whole of the rest of this guide.
A typed name carries intent at best and nothing about identity or integrity, while a private key operation carries identity and integrity mechanically, and neither artefact carries the fourth property.
Try it out

A customer types their name at the bottom of an agreement and ticks a box saying they agree. What has been established?

Breaking Into Quants Bootcamp — Fin Maverick

How does a private key operation show that nothing changed?

Signing is the one part of the subject where people expect mathematics, and there is none needed. Three steps, and all three fit on the back of an envelope.

Step one, a fingerprint of the document is computed. A fixed, published procedure reads every byte of the agreement and returns a short value. The important property is not that the value is short. The value is brittle in a very particular way: change one character anywhere in the document, add one space, alter a single digit in a figure, and the value that comes back is not slightly different, it is wholly different. There is no near miss. There is no partial match. A document that has moved by one comma produces a fingerprint that looks nothing like the original one.

Step two, the private key operation is applied to that fingerprint. Not to the document, to the fingerprint. That operation produces the mark that only the holder of that one key could have produced, and it is why a signature made this way is a fixed size whether the document runs to one sheet or four hundred.

Step three, and this is the step that does the work, anybody can repeat step one later. Running the same published procedure over the document handed over today produces a fingerprint. Taking the signature and, using the public counterpart of the signing key, recovering the fingerprint that was signed produces a second one. The two then sit side by side. If they match, the document in hand is the document that was signed, and it is the document that was signed by that key holder. If they do not match, something moved, and nothing says what moved or by whom, only that the two are no longer the same thing.

The check requires very little. The signer is not needed. The institution that arranged the signing is not needed. No records of the transaction are needed either, and no trust in the person handing the file over. A self contained check of that kind is exactly what carrying properties 1 and 3 mechanically means.

THE SIGNATURE IS MADE OVER A FINGERPRINT OF THE DOCUMENT, NOT OVER THE DOCUMENT ON THE DAY, SIGNING 1 THE AGREEMENT Every byte of it, read by a fixed published procedure that returns one short value. 2 THE FINGERPRINT Short, and brittle. One changed comma gives a wholly different value. 3 THE KEY OPERATION Applied to the fingerprint, producing a mark only that one holder could produce. YEARS LATER, CHECKING, WITH NOBODY FROM THAT DAY IN THE ROOM RUN IT AGAIN The same procedure over the document in hand. OPEN THE SIGNATURE Recover the fingerprint that was actually signed. PUT THE TWO SIDE BY SIDE THEY MATCH Same document, same key holder. THEY DO NOT MATCH Something moved. Nobody is told what moved, only that it did. One changed word does not produce a near miss. There is no near miss available.
A fingerprint of the document is computed, the private key operation is applied to that fingerprint, and anybody recomputing the fingerprint later sees immediately whether it still matches.
Try it out

One word of the agreement is changed after signing. What happens to the check?

So what is the signature actually asserting?

Three things, and it is worth saying plainly that this is the whole list. Everything else people believe a signature says is something they brought to it themselves.

Claim one, who signed. A mark that only one key holder could have produced sits on this document, and a certificate names that holder. Claim two, that nothing changed since. The document in hand is byte for byte the document that mark was made over. Claim three, when. Unlike the other two, the time is not contained in the signature at all. The time has to be supplied from outside, and everything difficult about old signatures follows from that.

Each claim has its own failure, and a claim that cannot be broken is a claim that is not understood.

Claim one fails when the key and the person come apart. The mechanism proves a key was used. The mechanism does not prove a person used it. When a colleague is handed a credential so they can finish something while the holder is travelling, every signature they make is mechanically perfect and attributed to the holder. The split between key and person is not hypothetical at Sumeru Bank Limited, an invented mid-sized Indian bank running a retail loan intake chain. Of the four numbered arrangements the bank considered for moving customer data, set out under data sharing in finance, arrangement 1 was refused at design and never used. Under arrangement 1 a customer hands over a credential and the recipient signs in as them, and after that nobody can tell the two apart in any record.

Claim two fails at the edge of the document. The check covers what was inside the fingerprint and nothing else. An annexure that was referred to but never attached, a rate table that lived on a separate screen, a term the customer read in one version of the wording and not another: none of that is inside the sealed bytes, so none of it is protected, and the check will pass happily on a document that is missing the very sheet the argument is about.

Claim three fails silently, and silence is what makes it the dangerous one. The other two failures are visible on inspection. A missing time is invisible on the day, invisible for years, and then arrives all at once on the afternoon somebody finally asks. Claim three is where the rest of the difficulty sits.

THREE CLAIMS, AND EACH ONE BREAKS IN ITS OWN WAY CLAIM 1: WHO SIGNED A mark only one key holder could have produced. CLAIM 2: NOTHING CHANGED Byte for byte the document that mark was made over. CLAIM 3: WHEN Not contained in the signature. It has to be supplied. FAILS WHEN The key and the person come apart. A borrowed credential produces a perfect signature under a name that is not theirs. FAILS WHEN The argument is about something outside the sealed bytes: a missing annexure, a table on another screen. FAILS WHEN Nobody preserved the moment. Invisible on the day, invisible for years, and then arrives all at once when somebody asks. The first two failures are findable by looking at the file. The third is findable only by trying to verify it, which nobody does until it matters.
A signature asserts who signed, that nothing changed since, and when, and each of those three claims has a distinct way of breaking that the other two do not share.

What does a signature never prove, however strong it is?

Three things, and every one of them is something people routinely assume it covers.

A signature does not prove the signer read the document. Nothing in a key operation touches a pair of eyes. A person who scrolled to the bottom in four seconds produces a signature that is byte for byte as strong as one produced by a person who spent an hour on it, and no examination of the artefact could ever separate the two.

A signature does not prove the signer understood the document. Understanding is a separate limit from reading, and worth keeping separate. A person can read every word of a term and still have no idea what it will do to them in month fourteen. The signature is silent about comprehension in exactly the way it is silent about reading.

A signature does not prove the signer had the authority to sign. A perfectly valid signature can be made by somebody with no standing to bind anybody. Permission to act is a separate layer altogether, layer 4 of the four identity layers set out under digital identity, and it lives in the institution's own records of who holds what mandate. The mechanism has no opinion on it whatsoever.

The consent record earns its keep here. Field 9 of its nine numbered fields, set out under consent management, records what was actually on the screen when the customer agreed. Field 9 exists because a signature answers who and what and never how it was presented, so an institution that wants any evidence at all about the second question has to capture it deliberately and separately. A signature and a record of what was shown are answers to two different questions, and holding a perfect one of the first kind says nothing about the second.

THE GAP BETWEEN WHAT IT SAYS AND WHAT PEOPLE HEAR WHAT THE ARTEFACT ASSERTS Who signed, being one named key holder. That nothing in the document changed since. When, and only if somebody preserved it. Three claims. That is the entire list. WHAT PEOPLE READ INTO IT That the signer read the document. That the signer understood it. That the signer had authority to sign. Silent on all three, at any strength. Evidence about the right hand list has to be captured deliberately and separately, which is the reason a record of what was on the screen exists at all.
The artefact asserts who signed, that nothing changed and when, while reading, understanding and authority sit outside it entirely and have to be evidenced some other way.
Try it out

A signed agreement is produced in a dispute and the customer says they never understood one of the terms. Does the signature settle that?

Why might a signature that verifies today fail to verify in five years?

Because of a small object sitting beside the signature that most people never think about at all: the certificateThe record naming the holder of a key. It has a life of its own, is issued for a period, and can lapse while the signatures made under it remain untouched..

The mark on the document proves that one particular key was used. On its own that is a statement about a key and not about a person, and a separate record naming the holder of that key is what turns the first into the second. The certificate is issued for a period, and it ends. Ending is not a fault, and it is not the result of anything going wrong: a record that never ended would be a record nobody could ever correct.

Here is the everyday version, and it is uncomfortably close. Somebody hands over a note and an identity card, and the card ran out four years ago. The note is genuine. The handwriting is theirs. Nothing about the note has changed. Nothing on the table answers whether the note was written while the card was still good, and the gap is not about honesty, it is about the absence of one small fact. If the note had a date somebody else had recorded, the whole difficulty would evaporate in a second.

A lapseThe moment a certificate stops being current. Signatures made before it are untouched, but showing they were made before it now needs a preserved time. does not reach back and spoil a signature that was made while the certificate was current. A lapse removes the ability to show it. Losing the proof is not the same as losing the fact, and it feels identical to whoever is holding the file.

So whether an old signature still stands comes down to two questions asked in order, and the second only matters because of the first.

TWO QUESTIONS IN ORDER, AND THE SECOND ONLY MATTERS BECAUSE OF THE FIRST QUESTION 1 Is the certificate still current? YES IT VERIFIES ON ITS OWN Nobody has to know when the signing happened. Nobody asks. NO, IT HAS LAPSED QUESTION 2 Was the moment of signing preserved? YES IT STILL STANDS The preserved time shows it was made while the certificate held. NO NOTHING CAN ESTABLISH IT, AND THIS IS WHERE THE SIX SAT The signature is untouched. The document is untouched. The key holder was named. What is missing is one fact that everybody in the room knew on the day, and there is now no way at all to put it back.
Is the certificate still current, and if not, is there preserved evidence of when the signing happened: a no to both is exactly where the six failures sat.
Try it out

A signature was valid when it was made, and the certificate naming the key holder has since lapsed. What is needed for the signature to still stand?

What happened when the invented bank pulled 500 old agreements?

Everything above this line is craft. Here is what it looked like when somebody actually tested it.

At month 12, before the annual re-approval, Neelima Rao in the risk function ran the independent validation of the intake chain at Sumeru Bank Limited. She did not build any part of it, and building none of it is what makes a validation independent. Among a great many other things she pulled 500 signed agreements out of the archive and tried to verify each one.

Six of the 500 could not be verified, being 1.2 per cent. Not six that were forged. Not six where a clause had been altered. Six where the signing certificate had lapsed and no timestamp of the moment of signing had been preserved, so nothing in the file could establish that the signature had been made while the certificate was still current.

Sit with what that means for a second. The shape of it is unusual. In all six, properties 1, 2 and 3 held. The signatures were valid when they were made. The key holders were named. The documents were intact, byte for byte, exactly as they had been on the day. Property 4, the record that survives, is the one that broke, and it broke without anybody doing anything wrong at the moment of signing.

Scaled to a month, 1.2 per cent of the invented bank's signed agreements is about 59. The month's signed agreements are a floor of 4,902, being the count of applications the scoring model accepted with nobody touching the file, and it is a floor rather than a total because the outcomes of the 3,010 files routed to a person are not recorded anywhere in this case. So the honest sentence is: at least 4,902 signed agreements in the month, of which about 59 would already fail this test after a year.

WHAT ONE OF THE SIX FILES ACTUALLY LOOKS LIKE ONE SIGNED AGREEMENT, PULLED FROM THE ARCHIVE THE AGREEMENT Present, and intact byte for byte. Property 3 holds. THE SIGNATURE Present, and valid when it was made. Property 1 holds. THE CERTIFICATE Present, and it has lapsed. Which was always going to happen. WHEN THE SIGNING HAPPENED Empty. Never captured. Cannot be added now. 6 OF 500 PULLED 1.2 per cent, at the month 12 independent validation. WHAT THE SIX ARE NOT Not forgeries. Not altered documents. Not disputed by anybody. Just undateable, for good.
Six of 500 agreements could not be re-verified because the certificate had lapsed and no timestamp of the signing moment had been kept, while the document and the signature themselves were untouched.
Try it out

How would a firm find out whether its own old signatures still verify?

What does a failure rate of about one in a hundred a year do over ten years?

Care matters at this step. The invented bank measured one hand check at one moment: 6 of 500, being 1.2 per cent. The bank did not measure a trend, and nobody has watched this rate over a decade. A measured point and a projected curve are two very different objects, so the 1.2 per cent a year is carried forward as an assumption and labelled as an assumption every time it is used.

On that assumption, 98.8 per cent of a month's agreements survive the first year. Then 98.8 per cent of what is left survives the second, and so on. Compounding on a shrinking base is what makes this a curve rather than a straight line. Multiplying 0.988 by itself ten times gives 0.886. So after ten years about 88.6 per cent of that month still re-verifies and 11.4 per cent does not.

Everybody nods at 1.2 per cent. Almost nobody predicts 11.4 per cent. The gap between the two reactions is the whole of the difficulty, and it is the same shape as the interest on a small recurring debt that nobody servicing it ever quite sees coming.

A RATE NOBODY WOULD ACT ON IN YEAR ONE, DRAWN OUT TO TWENTY 100 95 90 85 80 75 PER CENT 0 5 10 15 20 YEARS SINCE SIGNING WITH A PRESERVED TIMESTAMP: FLAT, EVERY YEAR The space between the lines is the share nobody can prove. READINGS MARKED ON THE CURVE After 1 year 98.8 per cent After 5 years 94.1 per cent After 10 years 88.6 per cent After 20 years 78.5 per cent
At an assumed 1.2 per cent a year, 98.8 per cent of a month of agreements still verifies after one year and 88.6 per cent after ten, while a preserved timestamp holds the line flat.
Try it out

Before the control below is moved: 1.2 per cent of signed agreements fail to re-verify in a year. On the same assumption, what share still verifies after ten years?

Play with it

Move the years, and watch the space between the two lines open up

One control: the number of years since signing, from 0 to 20. Two consequences are drawn together. The curve is the share of one month of signed agreements that still re-verifies, and the flat line above it is what the same month does when a timestamp of the signing moment was preserved. Beneath them the same month is drawn as one bar splitting into what can still be proved and what cannot. At the default of 10 years, 88.6 per cent still re-verify, being 4,344 of a floor of 4,902 signed agreements, and about 558 do not. The assumption of 1.2 per cent a year comes from one hand check of 500 agreements at the month 12 validation, in which 6 could not be verified.

THE SHARE OF ONE MONTH OF SIGNED AGREEMENTS THAT STILL RE-VERIFIES 100 95 90 85 80 75 PER CENT 0 5 10 15 20 YEARS SINCE SIGNING PRESERVED TIMESTAMP: 4,902 EVERY YEAR 88.6 THE SAME MONTH AS ONE BAR: A FLOOR OF 4,902 SIGNED AGREEMENTS 4,344 still re-verify 558 no longer do A floor rather than a total, because the outcomes of the 3,010 files routed to a person are not recorded in this case.

Years since signing: 10.0. The assumed failure rate is held at 1.2 per cent a year throughout.

Still re-verify
4,344
Share still verifying
88.6
No longer provable
558

Educational illustration. Figures are the invented bank's own and describe one deployment. Assumptions held on screen: a floor of 4,902 signed agreements in the month; a failure rate of 1.2 per cent a year, taken from one hand check of 500 agreements in which 6 could not be verified and carried forward as an assumption rather than as a measured trend; compounding, so the share is 0.988 raised to the number of years; and a flat line assuming a preserved timestamp at signing. The flat line holds at 4,902 because the failure being drawn cannot happen once the signing moment is recorded. Counts of agreements still re-verifying are rounded down to whole agreements, so the count that can no longer be proved is never understated.

Financial Analyst Program Bootcamp — Fin Maverick

How many agreements is that, and against what base?

Percentages are easy to nod at, so put the same month in front of yourself twice.

On the day they were made, a floor of 4,902 signed agreements all verify. Every one of them. Ten years later, on the assumption above, about 4,344 of them still verify and about 558 do not. Nothing was done to those 558 in the intervening decade. Nobody edited them, lost them, mishandled them or disputed them. The 558 sat in the archive being perfectly correct, and the ability to prove them drained away underneath.

The gap between the same month read at two moments is the entire subject of property 4, and no measurement taken on the day of signing can see it.

Say the base carefully. An institution quietly overstates itself right here. The 4,902 is a floor and not a total. The figure counts applications in month 6 that the scoring model accepted with nobody touching the file, being 57.0 per cent of the 8,600 that completed onboarding and reached the decision engine. Files routed to a person can also end in a signed agreement, and this case records no outcome for those 3,010, so the true monthly count is higher by an amount nobody here can state. Which means the 558 is a floor too. Where a case records a floor, every number built on it stays a floor, and an account that quietly promotes one to a total has invented a figure.

ONE MONTH OF AGREEMENTS, READ AT TWO MOMENTS ON THE DAY 4,902 signed agreements, every one of them verifying 558 TEN YEARS LATER 4,344 still verifying no longer Nothing was done to those 558 in the intervening decade. They were not edited, lost or disputed. The ability to prove them drained away underneath while they sat in the archive being correct. Both counts are floors rather than totals, on an assumed 1.2 per cent a year.
A floor of 4,902 signed agreements all verify on the day they are made, and about 558 of them no longer verify ten years later on the assumed rate.
Breaking Into VC Bootcamp — Fin Maverick

What has to be preserved at the moment of signing?

Four things, and the list is short enough to be slightly embarrassing when set beside what its absence costs.

Keep the document exactly as it was signed, down to the byte. A reformatted copy is a different document to the check even when it is the same agreement to a reader. Keep the signature. Keep the certificate as it stood on the day, rather than assuming somebody else will still be publishing it in a decade. And keep evidence of when the signing happened, recorded by something other than the signer. The moment then survives the certificate that named them.

The fourth item is the preserved timestampEvidence of when a signing happened, recorded at the time and kept separately, so the moment outlives the certificate that named the key holder., and it is the whole of the fix. With it, re-verificationChecking an old signature again years later. It is the only test that exercises the fourth property, and nothing else reveals whether it holds. ten years later asks a question that can be answered: was this made while the certificate was current, yes, here is the record of when. A preserved timestamp at signing holds the line flat at the full 4,902 for as long as anybody cares to ask, and the invented bank did not specify one.

KEEP THESE FOUR AND PROPERTY 4 HOLDS. THE BANK KEPT THREE. WHAT THE ARCHIVE HAS TO HOLD 1 THE DOCUMENT, EXACTLY AS SIGNED A reformatted copy is a different document to the check. 2 THE SIGNATURE The mark itself, stored beside the document. 3 THE CERTIFICATE AS IT STOOD Kept, rather than assumed to still be published later. 4 WHEN THE SIGNING HAPPENED Recorded by something other than the signer. Not specified. WITH ALL FOUR The line stays flat. A month of agreements re-verifies in year one and in year twenty alike, because the question can still be answered. WITH THE FIRST THREE ONLY The record decays quietly, at no visible moment, and it cannot be repaired afterwards, because the missing fact no longer exists.
Keep the document, the signature, the certificate as it stood and evidence of when the signing happened, and the fourth property holds indefinitely.
Bond Pricing and Yield Mechanics — free micro-course from Fin Maverick

What does holding the line actually cost?

The cost is the part that stings. The intake chain at the invented bank cost Rs 2,40,00,000/- to build once and Rs 65,00,000/- a year to run, and both figures are the bank's own. Against those, a preserved timestamp is not a system. A preserved timestamp is a line in a specification saying what the archive keeps, and this case records no separate cost for it at all.

But it has a deadline, and the deadline is brutal in a way most controls are not. Almost everything else in this sequence can be fixed late. A second route for wrongly refused applicants can be built in month 9 and it helps everybody who arrives in month 10. A missing consent field can be added to the record and every consent captured afterwards carries it. A preserved timestamp cannot be added to a signature that has already been made. The fact it preserves stopped existing the moment nobody wrote it down.

So every agreement signed before the specification is corrected is permanently outside the fix. The bank can hold the line flat from tomorrow, and it can do nothing whatsoever about the months already in the archive. A deadline like that is a very unusual property for a control that costs nothing, and it is why a preserved timestamp belongs in a specification rather than in a plan to improve things later. The omission is the same class as item 7 of the eight numbered data requirement items, the item asking what may be retained and for how long: nobody had written down what happens after the day, so nothing happened after the day.

Try it out

The fix is a preserved timestamp at signing. When does it have to be specified?

How this gets used by somebody who is not building anything

Somebody in a control or audit function has one move here and it is not reading a policy. Pull a sample of old signed agreements and try to verify each one. The first three properties are checked constantly by ordinary use and the fourth is checked by nobody until the afternoon it is needed, so pulling that sample is the only test that exercises property 4. The invented bank found its six because Neelima Rao did exactly that at month 12, and nothing else in the annual review would have surfaced them.

Somebody assessing an arrangement from outside asks two questions instead of one. Everybody asks which signing method is being used, and the answer settles properties 1 and 3. Ask instead what is preserved at the moment of signing, and ask how long the agreement has to stand up against how long the certificate lives. A loan running twenty years and a certificate issued for a period measured in a couple of years are on very different clocks, and the mismatch between those two clocks is the whole risk in one sentence.

And there is something a household can use directly. When something is signed electronically, the document is not the only thing worth saving. Save whatever acknowledgement came back carrying a time on it, from somebody other than the signer: the message, the receipt, the reference number with a date attached. The acknowledgement belongs with the agreement rather than in a mailbox that will be cleared out. Keeping it is the household version of the same four item list, and it costs nothing but the decision.

The error that gets made, and what it costs

The specification for the intake chain said how agreements would be signed. The specification was detailed, it was reviewed, and on the mechanism it was right: properties 1 and 3 were carried, and the invented bank could show who had signed and that nothing had changed. The specification never said what the archive should keep afterwards, and nobody noticed the omission because nothing about it produces a symptom on the day.

An error of this kind has no incident, no alert and no unhappy customer at the moment it is made, and that is precisely why it survives every review that looks for problems rather than for absences. A control that fires when something goes wrong announces itself. A record nobody kept announces nothing at all, for years.

The cost, stated in the invented bank's own figures and on its own assumption of 1.2 per cent a year: about 59 agreements from a single month already fail this test after one year, on a floor of 4,902 signed agreements. By year ten it is about 558 from that one month, and every later month is stacking its own share behind it. Not one of those agreements is faulty. Every one of them was signed properly by a named person who meant to sign, over a document that has not moved by a comma since. The 558 are simply agreements nobody can now attach a time to, and no amount of money spent afterwards buys that time back.

Who sets expectations on a deployer here

Named, and to be read at the source

The Reserve Bank of India at rbi.org.in states what a signature is worth for a lender, sets out the recognised routes for signing, and says what a regulated lender is expected to retain and for how long. Where the institution is a market intermediary rather than a lender, the equivalent expectations sit with the Securities and Exchange Board of India at sebi.gov.in. Where the question is what a board is accountable for in keeping the records of a company, that sits with the Ministry of Corporate Affairs at mca.gov.in. The international standards that national expectations on record keeping descend from are published by the Bank for International Settlements at bis.org, and what India actually does is stated by the Indian authorities rather than by the standard. No authority publishes those four properties as a single definition, and the words used for them differ from one rule to the next. Every one of those must be read at the source named, on the day it matters.

Covered elsewhere. The authorities named above set what a firm is required to obtain a signature for and which routes are recognised, and both are covered separately. The consent record, its nine numbered fields and why the record of what was on the screen exists are set out under consent management. Private keys used to control an asset are set out under digital assets and tokenisation, where the same object does a different job. How any learned component is fitted, validated or evaluated is established elsewhere.

A preserved timestamp is a line, not a system. See what the signature holds.

Sources

SourceDocumentSite
Reserve Bank of IndiaExpectations on a regulated lender covering record keeping, digital lending and the retention of customer documentationrbi.org.in
Securities and Exchange Board of IndiaEquivalent expectations where the institution taking the signature is a market intermediarysebi.gov.in
Ministry of Corporate AffairsMaterial on what a board is accountable for in maintaining the records of a companymca.gov.in
Bank for International SettlementsInternational material on record keeping and operational resilience that national expectations descend frombis.org

Sumeru Bank Limited, its retail loan intake chain and Neelima Rao are invented.
Educational material. Not advice on any investment, tax, budget or market position.

← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.