Digital settlement

Signing a transfer without a pen: how digital signatures bind a firm

How a Queensland transfer is signed digitally: the certificate behind the signature, who in a firm may sign, what the signer certifies and when a signature can be disowned.

· 18 min read

Kooky
Written by
Kooky

Builder of Shaka, the payment router that pays every agent their commission on closing date.

About Kooky and Shaka →

On a paper transfer, the signature was the part everyone could see. The seller wrote a name in ink, a witness watched and signed beside it, and the page went to the titles office. On an electronic transfer there is nothing to look at. The document that changes the name on a Queensland title is signed by a person at a law practice or a lender, using a key held on that organisation's behalf, and the law treats the result as if the owner had executed a paper form.

That raises questions a careful owner is entitled to ask. What is the thing that signs? Who inside the firm is allowed to use it? What does that person promise when they sign? And if the signature turns out to have been made by the wrong hands, who is stuck with it?

This guide answers from three texts. The first is the Electronic Conveyancing National Law (Queensland), as published on the Queensland legislation website, chiefly sections 3, 9 and 12. The second is the Queensland Participation Rules version 7, published on 1 March 2024 and effective from 2 April 2024, which state on their face that they are the rules determined by the Registrar under section 23 of the national law. The third is the guidance of the Australian Registrars' National Electronic Conveyancing Council (ARNECC), in particular Guidance Note 3 on certifications and Guidance Note 8 on system security, both updated in August 2024. Where those texts explain the technology, the guide repeats their explanation in plain words. Where they stop, it stops.

Related readPaper or screen: the nine dealings Queensland lawyers must lodge online

What the law means by a digital signature

Section 3 of the national law gives the definition on which everything else rests. A digital signature is encrypted electronic data intended for the exclusive use of a particular person, as a means of identifying that person as the sender of an electronic communication or the signer of a document. To digitally sign is simply to create such a signature for the communication or document.

Two words in that definition carry the weight. "Encrypted" tells the reader that this is not a scanned image of handwriting or a name typed at the foot of an email. "Exclusive" tells the reader what the law expects of it: the data is meant to be usable by one person only, which is why it can stand as evidence of who signed.

Section 9 then states what a signature of this kind achieves. A registry instrument in a form that can be lodged electronically has the same effect as if it were a paper document. A registry instrument digitally signed by a subscriber in line with the participation rules has the same effect as a paper document executed by the subscriber or, where the subscriber signs under a client authorisation, by each person for whom the subscriber signs. The section adds that such an instrument is taken to be in writing for the purposes of every other Queensland law, and that the requirements of any other law about execution, signing, witnessing, attestation or sealing must be regarded as fully satisfied.

A subscriber, in the same section 3, is a person authorised under a participation agreement to use an electronic lodgment network to complete conveyancing transactions for someone else or for itself. In practice that is the law practice acting for a buyer or seller, or the lender taking or releasing a mortgage.

Related readQueensland without paper title deeds: what proves ownership now

The certificate behind the signature

The participation rules describe the machinery in their definitions, and they do it in a handful of short terms that fit together.

A key is a string of characters used with a cryptographic algorithm to encrypt and decrypt. A key pair is two such keys that work as partners: each one decrypts messages that were encrypted with the other. One of the two is the public key, which may be made public. The other is the private key, which, in the rules' words, has to be kept secret to ensure confidentiality, integrity, authenticity and non-repudiation.

A digital certificate is the document that ties a key pair to a person. The rules define it as an electronic certificate, itself digitally signed by a certification authority, which identifies a key holder, the business entity the key holder represents, or both, and binds the key holder to a key pair. A key holder is an individual who holds and uses keys and digital certificates on behalf of a subscriber.

Put together, the picture is this. The signer at a law practice holds a private key. A certificate, issued by an outside body, says whose key it is and which organisation that person signs for. Rule 7.5.1 requires documents lodged through a network to be digitally signed, where they need a signature, using a private key to create the subscriber's digital signature. The signature is the subscriber's, even though an individual's key made it. That point returns with force in section 12.

The rules do not explain the mathematics, and nor does ARNECC's guidance: Guidance Note 8 does not define a digital certificate, it deals with how one is looked after. This guide keeps to the same boundary.

Related readRequisitions at Titles Queensland: when a lodged dealing is sent back

Who issues a certificate

A firm does not make its own. The rules define a certification authority as a Gatekeeper accredited service provider that issues digital certificates signed with the certification authority's own private key. Gatekeeper is defined as the Commonwealth government strategy to develop public key infrastructure to facilitate government online service delivery. Public key infrastructure, in turn, is Gatekeeper compliant technology, policies and procedures, based on public key cryptography, used to create, validate, manage, store, distribute and revoke digital certificates.

So the chain of trust has three links: a Commonwealth framework, a provider accredited under it, and a certificate which that provider signs. The participation rules attach duties to the subscriber at each point where it touches that chain.

Rule 7.5.2 requires a subscriber to obtain at least one digital certificate and to keep it valid. Rule 7.5.4 requires that all information given to a certification authority, a registration authority or a network operator for the purpose of obtaining a certificate be correct, complete and not false or misleading. A certificate is only as good as the facts on which it was issued, and the rules make the applicant answerable for those facts.

Rule 7.5.5

One certificate, one signer

A subscriber has to take reasonable steps to ensure a digital certificate is used to sign only by the signer to whom it is allocated. ARNECC's Guidance Note 8 puts the reason bluntly: using a digital signature that belongs to another person can be likened to forging a signature on paper.

Who in a firm may be a signer

The rules build the role in two layers. A user is an individual who is a principal, officer, employee, agent or contractor of the subscriber and is authorised by it to access and use a network on its behalf. A signer is a user authorised by the subscriber to digitally sign electronic registry instruments and other electronic documents on behalf of the subscriber.

Related readVerification of identity: the check before a Queensland e-settlement

The definition turns on authorisation by the subscriber. It does not name a job title, and the provisions of rule 7.5 read for this guide do not add one: rule 7.5.3 says only that the subscriber has to take reasonable steps to ensure that nobody but a signer digitally signs. Who a practice chooses is therefore its own decision, made inside the checks the rules impose and whatever the laws governing legal practice separately require, which are outside this guide.

Those checks are specific. Under rule 6.5.1, a subscriber has to take reasonable steps to verify the identity of each of its signers before a digital certificate is first allocated to that signer. Rule 6.5.4 relieves it of repeating the exercise where it complied within the previous two years. Under rule 7.2.3(b), a police background check has to be carried out before the first allocation of a certificate to a signer.

The general screening of rule 7.2.3(a) applies as well, since a signer is a user: the subscriber has to take reasonable steps to ensure its users have no insolvency event in the last five years, no conviction for fraud or dishonesty of the kinds the rule lists, and no current restriction on their right to access a network.

Before a person signs for a firmQueensland Participation Rules version 7
  1. Identity is verifiedThe subscriber takes reasonable steps to verify the signer's identity before a certificate is first allocated. Rule 6.5.1.
  2. A police check is runA police background check is conducted before that first allocation. Rule 7.2.3(b).
  3. The certificate is allocatedIt is issued by a certification authority and used by that signer alone. Rules 7.5.4 and 7.5.5.

Guidance Note 8 fills in how ARNECC reads these duties. A police check carried out earlier, before the certificate was first allocated, satisfies the rule. Where a signer faces a pending charge, the note leaves it to the subscriber's judgement whether the person should continue in the role while the outcome is awaited; on conviction, the subscriber has to revoke the person's ability to sign at once. As an example of a breach, the note offers the case of a subscriber that allocates a certificate and signing rights to a person known to have been involved in property fraud.

Related readThe client authorisation: the form that lets a lawyer sign for you

The same note explains the standard that runs through all of this. Reasonable steps are those an ordinarily prudent subscriber would have taken in the circumstances and in the ordinary course of business, and what they are is a question of fact in each case.

What the signer certifies

A digital signature on a registry instrument is never a bare signature. Rule 7.10 requires the subscriber to give those of the certifications in the certification rules that are required whenever it digitally signs. The certification rules are Schedule 3 of the participation rules, and the party giving them is called the certifier, defined as the subscriber providing the certifications.

Schedule 3 holds six statements. Five of them concern Queensland transactions; ARNECC's Guidance Note 3 says the sixth, about retrieving and destroying duplicate certificates of title, is given in Victoria only.

The certifications given at signingSchedule 3, in plain words
No.What the certifier statesHow ARNECC says it is shown
1. IdentityIt has taken reasonable steps to verify the identity of the party, or of the party's administrator or attorney.Evidence of the identity check that was carried out.
2. AuthorityIt holds a properly completed client authorisation covering this document.The completed authorisation, obtained from the client.
3. EvidenceIt has retained the evidence supporting the document.The supporting file, kept for at least seven years from lodgment.
4. CorrectnessIt has taken reasonable steps to ensure the document is correct and complies with relevant law and any prescribed requirement.No single record; prudent conveyancing practice is the measure.
5. MortgageeThe mortgagee has taken reasonable steps to verify the mortgagor's identity and holds a mortgage on the same terms.The mortgage granted by the borrower, and the identity evidence.

Sources: Queensland Participation Rules version 7, Schedule 3; ARNECC Guidance Note 3, Certifications, updated August 2024.

Guidance Note 3 describes what these statements are. They are representations by the subscriber to the Registrar that the instrument lodged complies with the law, the participation rules and any prescribed requirements. They are given by the subscriber in its own right, whether it acts for itself or for a client. And they are not typed in by the signer: the note calls them system driven, set by the land registry's business rules and displayed in the document when it is presented for signature.

Which statements appear depends on the document and on whose behalf the subscriber signs. For a transfer signed for a buyer or a seller, the note lists certifications 1 to 4. For a mortgage signed for a lender, it lists 1 to 5. For a release of mortgage signed for a lender, 1 to 4. Where a subscriber signs for itself, for example a lender releasing its own mortgage, only the evidence and correctness certifications are listed, and a lender signing its own mortgage adds the fifth. A priority notice carries the evidence and correctness certifications in either case.

Related readCyber security duties of firms and lenders on a settlement network

Reading the certifications closely

Each statement has limits that the guidance takes care to mark.

The evidence certification does not ask for more paper than conveyancing asked for before. The note says the evidence is the same as would support a paper instrument, with the client authorisation and the identity evidence added, and that a subscriber is not required to seek additional supporting evidence beyond that. Titles Queensland's eConveyancing questions and answers describe the consequence at the registry counter: supporting documents that would ordinarily be deposited with a paper instrument are generally not deposited with an electronic one, because the subscriber holds them under the participation rules.

The correctness certification is the broadest and the least mechanical. ARNECC says no specific piece of evidence proves it, and that a failure to follow prudent conveyancing practice would suggest it was not met. "Compliant with relevant law" refers to the instrument, not to everything the parties do. But the note adds that a subscriber which knows of a legal problem affecting the transaction and proceeds anyway would have difficulty saying the certification was correctly given.

The mortgagee certification turns on the words "on the same terms". According to the note, small differences in formatting or in the execution clause do not matter, but a lodged mortgage that merely refers to terms set out in another document signed by the borrower does not meet the test: the lodged mortgage has to carry the terms in full.

On what happens when a certification is wrong, the guidance is brief. The subscriber is responsible for everything certified being correct. If the transaction completes, the consequences depend on its outcome for each party and on the legislation and other law that applies. And if a subscriber cannot give the certifications in good faith, the note says the transaction should not go ahead until it can.

Section 12: the signature binds

Section 12 of the national law is headed "Reliance on, and repudiation of, digital signatures". Its first subsection sets a default in four parts, which apply whenever a subscriber's digital signature is created for a registry instrument or another document in connection with a conveyancing transaction.

First, unless the subscriber repudiates the signature, the document is taken to be signed by that subscriber. Second, on the same condition, the signature is binding on the subscriber and on all other persons for whom the subscriber acts under a client authorisation in that transaction. Third, the signature is binding for the benefit of a list of people who rely on it. Fourth, the subscriber cannot repudiate the signature except in the circumstances the section itself sets out.

Who a digital signature binds, and who may rely on itSection 12(1), Electronic Conveyancing National Law (Queensland)
PositionWho
Bound by itThe subscriber whose signature it is.
Bound by itEvery person the subscriber acts for under a client authorisation in the transaction.
May rely on itEach party to the transaction, and anyone claiming through or under a party.
May rely on itEach subscriber acting under a client authorisation in the transaction.
May rely on itEach operator whose network is used in the transaction.
May rely on itThe Registrar, once the document is lodged electronically.
May rely on itFor a direction to pay money, each financial institution that pays or receives under it.

Subsection (2) is the sentence that gives the section its character. The default applies regardless of who created the subscriber's digital signature, and regardless of the circumstances in which it was created. Fraud is named in the text as one of those circumstances.

One further subsection keeps an ordinary working step available. Section 12 does not prevent the unsigning of a registry instrument or other document. A signature can be withdrawn inside the system by the party that gave it; that is a different thing from disowning it afterwards.

The narrow grounds to repudiate

Subsection (4) is the only way out, and the burden sits on the subscriber. It can repudiate its digital signature on a document only if it establishes each of three matters.

The first is that the signature was not created by the subscriber.

The second is that it was not created by a person who, at the time, was an employee, agent, contractor or officer of the subscriber and had the subscriber's express or implied authority to create its digital signature for any document or documents. Subsection (5) tightens this: it does not matter whether that authority was general, or limited to documents of a particular class, to a particular document, or in any other way. A signer who was authorised to sign one kind of document and signed another is still a person with authority for the purposes of this test.

The third is that the signature was not made possible by a failure, by the subscriber or any of its employees, agents, contractors or officers, either to comply fully with the participation rules or to take reasonable care.

The three matters are cumulative. A firm whose own staff member misused a certificate fails at the second. A firm whose certificate was used by an outsider, but only because a rule had been neglected or ordinary care was not taken, fails at the third. What remains is the case in which a stranger created the signature and nothing the subscriber did or omitted opened the way.

The rules on who may hold a certificate and how it is guarded are the working side of section 12: a firm that neglects them has also given up its only defence.

How the rules and the section fit together

Read side by side, the participation rules look like a list of the things a subscriber would later need to prove.

Rule 7.5.5 requires reasonable steps so that a certificate is used only by the signer to whom it was allocated, and so that signers do not let any other person use their access credentials and certificates. Rule 7.8.1 requires signing rights to be revoked promptly when a person is no longer to be a signer, with a request to the certification authority to revoke the certificate where appropriate.

Rule 7.9 covers the moment something goes wrong. In the rules, "compromised" means lost or stolen, or reproduced, modified, disclosed or used without proper authority. If a certificate has been or is likely to be compromised, the subscriber has to revoke the user's access immediately, check every electronic workspace in which the private key was used to sign, and unsign the documents concerned. Where it becomes aware or suspects that a private key has been used to sign without its authorisation, it has to unsign immediately where that is possible. Guidance Note 8 adds that, where unsigning is not possible, the operator has to be notified at once, and that the certification authority is to be told promptly so the certificate can be revoked or cancelled.

Unsigning, then, is the tool for the period before a transaction completes. Repudiation is the question that arises afterwards, and section 12 shows how seldom it will be answered in the subscriber's favour.

What this means for the name on the title

For a buyer or seller, four consequences follow from the texts.

The owner's signature is on the client authorisation and nowhere else. Section 9 gives the transfer the effect of a paper document executed by each person for whom the subscriber signs under that authorisation. The owner is treated as having executed a document they may never have seen on a screen.

The owner is bound with the firm. Section 12(1)(b) names, next to the subscriber, all persons for whom it acts under a client authorisation. The other side of the same rule is the benefit: the buyer relies on the seller's representative's signature, and the seller on the buyer's, in exactly the same way, as does each lender and the Registrar.

The right to repudiate belongs to the subscriber. Subsection (4) speaks only of what a subscriber can establish. The section gives the client no separate route to disown a signature made under the authorisation. What other remedies a person might have in a given case, against whom and under which law, is not something section 12 deals with, and it is a matter for advice on the particular facts.

The protections for the owner are therefore placed earlier in the chain. They are the identity check before the firm acts, the client authorisation that defines what the firm may sign, the screening of the individuals who hold certificates, the rule that a certificate is used by one signer only, and the certifications the firm gives to the Registrar each time it signs. A client who wants to understand how their own transfer will be signed can reasonably ask the practice who its signers are and what the authorisation covers.

ARNECC's guidance notes say of themselves that they are not legal advice and do not override the national law, the participation rules or a Registrar's requirements. The same holds here: this guide describes the general rules, and a particular transaction turns on its own documents.

Kooky, from Shaka

Kooky edits Queensland Estate and builds Shaka, the payment router he made for Queensland property professionals. One payment comes in, and every agent, agency and party in the deal receives their signed share on closing date.