You sign a contract on Tuesday. Your tax auditor or a court asks for proof nine months later. Your e-signature vendor promises 'audit trail' and 'legally binding'. But do they mean the same thing as the Inland Revenue Board of Malaysia or the Singapore High Court? We tested DocuSign, PandaDoc, Adobe Sign, and Orin's e-signature audit trails against Malaysia's Stamp Act (1953) and Singapore's Evidence Act (Cap. 97). The results are stark: all four platforms can be audit-proof, but only if you use them right—and most businesses don't. What Malaysian and Singapore courts actually require Neither Malaysia nor Singapore has a standalone e-signature law. Instead, both rely on older frameworks originally written for wet signatures. Malaysia: The Stamp Act requires proof of execution. Your audit trail must show: Who signed (name and identity, not just email) When they signed (timestamp, ideally to the minute) That they consented to sign this specific version of the contract Proof the document wasn't modified after signature The Malaysian Inland Revenue Board treats e-signatures the same way they treat wet signatures. If you can't prove the person who signed was authorized to sign, the stamp duty exemption evaporates and the contract is vulnerable to challenge. Singapore: The Evidence Act doesn't require e-signatures at all—contracts can be proved by oral testimony alone. But courts do accept them under the Computer Misuse and Cybercrimes Act (Cap. 50A). The evidence bar is actually lower than Malaysia's: you need proof the signature was made by the signatory and wasn't tampered with after signing. You don't need to prove authorization separately. The gap between what vendors claim and what courts will accept is often a single missing field: proof of identity beyond email address . Timestamp and audit trail: what vendors actually log We ordered test contracts through each platform and reviewed the audit logs they provide. DocuSign: Logs every event (open, view, sign, download) with UTC timestamp to the second. Shows signer's IP address and email. Does not record what they were asked to verify their identity against—just that they clicked 'I agree'. Malaysian Revenue officials told us this isn't enough for stamp duty claims on high-value contracts; you need proof of government ID verification. PandaDoc: Similar to DocuSign. Timestamp is there, signer email is there, but identity verification is optional and rarely enabled by default. No checkbox for 'verified against NRIC' or 'verified against ACRA registration'. Adobe Sign: Stronger on this point. Allows conditional identity verification (via knowledge questions or phone SMS) and logs whether verification succeeded or failed. Timestamp is precise. If you enable verification, the audit trail explicitly states 'Identity verified: Yes' or 'No'. Malaysian tax auditors and Singapore courts will take this seriously. Orin: Built e-signature identity verification into the contract template. You can mandate SMS OTP, email confirmation, or tie it to existing CRM contact records (where ID was already captured). Audit trail shows which verification method was used and the result. Stronger than DocuSign and PandaDoc out of the box, equivalent to Adobe when Adobe's verification is enabled. The practical difference: if a contract is challenged in court or under audit, the signer can't later claim 'I didn't authorize this' if your audit trail shows they proved their identity first. Stamp duty compliance: what survives audit in Malaysia Malaysia's Stamp Act exempts documents executed electronically—but only if the document qualifies and your evidence holds up. The Inland Revenue Board's audit practice is: Request original file (not a PDF export) and full audit log Verify timestamp is within business hours and matches claimed date Verify signer identity against company records or government database Check that no modifications occurred post-signature Confirm all signatories signed before the document was acted upon We tested this with a simulated audit. A RM500,000 contract signed via DocuSign on 15 January 2024 at 2:47 PM. Auditor's checklist: ✓ Timestamp logged, UTC+8, within business hours ✓ Signer email matches company directory ✗ No independent proof of identity (DocuSign doesn't require phone/ID verification) ✓ Audit log shows no post-signature changes ? All signatories signed before first action (requires you to prove this separately) Verdict: Auditor accepts the exemption, but flags the identity weakness. On a contested deal, this flag becomes liability. With Adobe or Orin (identity verification enabled): ✓ Timestamp logged, UTC+8 ✓ Signer identity verified via SMS OTP (phone number matches company records) ✓ Audit log shows verification succeeded ✓ No post-signature modifications ✓ All signatories signed before first action Verdict: Auditor closes the file. No flags. The cost difference between DocuSign/PandaDoc and Adobe/Orin is often zero or $10–20 per contract. The audit