Inspection sign off
What does inspection sign off mean, and what is actually being signed
An inspection sign off is the act of a named, authorised person attaching their identity to an inspection record and stating what they will stand behind, whether that is that the work was carried out or that a defined condition was met.
What is the signer attesting to?
ISO/IEC 17020:2012 is unusually clear on this, and it splits the question into two separate required elements. Every inspection report or certificate must carry a "signature or other indication of approval, by authorized personnel", and separately must carry "a statement of conformity where applicable". Those are two different assertions, and the standard lists them apart on purpose. ISO/IEC 17020 was revised in 2026, so check which edition an accredited body is assessed against before quoting a clause number.
The signature says a competent, authorised person approved the issue of this document. The statement of conformity says the item meets, or fails to meet, a stated requirement. A report can carry the first without the second. That happens whenever an inspection reports findings without judging them against a pass criterion.
Signing that a task was done versus signing that a condition was met
Almost every dispute about a sign off comes down to which of these two the signer thought they were doing.
A completion attestation says: the specified steps were carried out, at this time, by this person. It is a statement about activity. The signer is exposed if the steps were not actually performed, and only if that.
A conformity attestation says: I examined this and it meets the standard. It is a statement about the world. The signer is exposed if the asset later turns out not to have met the standard, whether or not every prescribed step was followed.
The practical consequence: a technician can honestly sign that a 40 point check was completed on a vehicle and still be wrong to sign that the vehicle is roadworthy, because the check does not cover everything roadworthiness requires. Templates that end with a single tick box labelled "Complete" collapse the two, and the organisation only discovers which one it relied on when somebody asks. Give the two attestations separate fields, separate wording and, where competence differs, separate signers.
Whose name goes on it
Attribution requirements in regulated inspection are specific, and they are worth copying even where they do not legally apply. Schedule 1 of the UK Lifting Operations and Lifting Equipment Regulations 1998 requires the report to give the name, address and qualifications of the person making it, whether that person is self-employed or, if employed, the name and address of their employer, and separately the name and address of whoever authenticates the report.
Three facts, then: who did the work, what standing they had, and who authenticated the document. ISO/IEC 17020 adds a fourth requirement in the same direction, that the report or certificate must be internally traceable to the inspector who performed the inspection, even where that inspector is not the person who signs the issue.
That traceability requirement is the one shared logins destroy. An account called "workshop1" satisfies nothing. Identity has to be individual, which is a role based access question before it is a signature question.
Inspection sign off: a worked example
An apprentice technician carries out a multi point check and records twelve findings with photographs. The apprentice signs the completion attestation: these checks were performed, by me, on this vehicle, at this time. The shop foreman reviews the evidence and signs the conformity attestation, including the two items graded as requiring immediate work.
Two names, two different claims, one record. If the vehicle comes back with a fault in a checked area, the file shows exactly who asserted what. Under a single "signed by" field it would show neither.
What makes a sign off hold up when challenged
- Individual identity, verified at the moment of signing. Not a shared device left logged in on a bench all day.
- The record fixed at the point of signature. If the evidence can change after signing, the signature covers nothing in particular.
- What was on screen. The strongest challenge to any sign off is that the signer never saw the material. Capture which version of the record was presented.
- An audit trail around it. Who reviewed, when, what changed after, and any countersignature.
- Legal footing for the electronic form. Under the EU eIDAS Regulation (No 910/2014), Article 25, an electronic signature cannot be denied legal effect or admissibility solely because it is electronic or does not meet the requirements for a qualified electronic signature, and a qualified electronic signature has the equivalent legal effect of a handwritten one. Which tier you need depends on what is being attested.
The property that all of this is aiming at is non-repudiation: the signer cannot credibly claim afterwards that it was not them, or that they were shown something else. The mechanics sit under cryptographic signature, and the document being signed is covered under inspection report.
Try Venta Capture on your own process
Build one flow for your highest-volume case type. Free, no credit card.