Express Computer
Home  »  Guest Blogs  »  From identity to evidence: Why India’s next infrastructure needs to focus on digital trust

From identity to evidence: Why India’s next infrastructure needs to focus on digital trust

0 0

By Rupesh Kuche, Founder and MD, Digital Trust Infrastructure India (DTII)

Every statutory filing season, thousands of government officials, board of directors, HNIs, chartered accountants, company secretaries and tax practitioners across India hand their digital signature token to a colleague to meet a deadline. That quiet, routine handoff is easy to overlook. It’s also the clearest evidence of a shift India’s policymakers have already committed to, even if the infrastructure hasn’t caught up yet: governance is no longer measured by intention. It’s measured by whether you can prove, later, exactly what happened and who authorised it.

India is beginning to move from obtaining consent toward being able to demonstrate that consent occurred, especially in the light of Digital Personal Data Protection Act 2023 and rules there-under.
The Bharatiya Sakshya Adhiniyam, 2023 introduced a structured evidentiary standard for digital records in Indian courts.

Whether a particular person authorised a particular digital action, what was presented to them when authorisation was sought, what affirmative action was recorded, and whether that evidentiary history can still be independently examined years later.

Read individually, these look like routine regulatory updates. Read together, they point at the same underlying shift: India is moving from digitising transactions to demanding proof of how they occurred. But the infrastructure to support that shift hasn’t caught up as fast as the mandates have.

The next infrastructural challenge
India’s digital public infrastructure is, by most global comparisons, a genuine success. Aadhaar solved identity at population scale. UPI solved payments at population scale. DigiLocker and the Account Aggregator framework solved document access and consent-sharing at the same scale. Each layer answered a version of the same question: who is this person, and can they be verified quickly, effectively, and reliably.

But these identity or payment infrastructures were never built to answer a different, harder question: did this person authorise this specific action, at this specific moment, with full knowledge of what they were agreeing to.

That gap is easy to miss until it’s tested. And nowhere is it more visible than in digital signatures.

The law places control of the private key squarely on the subscriber. Section 42 of the Information Technology Act, 2000 requires subscribers to exercise reasonable care to retain control of their private keys and prevent disclosure; where a key is compromised, liability continues until the Certifying

Authority is informed. Yet operational practice often involves delegation of the very signing process for which the subscriber is expected to retain control.

The result is legal liability without operational control, and no verifiable record of consent if a signature is ever questioned later.

Why this is a scale problem, and not an outlier case
India generates well over 150 million digital-signature-based filings a year, across board of directors, chartered accountants, company secretaries, banks, NBFCs, and government processes. At that volume, disputes over who authorised what are not rare exceptions. They surface routinely, and they will continue to surface as digital transactions continue to multiply.

A solution that depends on reconstructing intent after the fact, whether it is emails, screenshots, memory, cannot operate at the scale India’s digital economy has already reached.

Whatever solution closes this gap must function as infrastructure, quietly underneath millions of transactions a day, the same way UPI or Aadhaar authentication already do. It cannot be a manual workaround applied case by case.

What the gap actually costs
Industry estimates put India’s digital signature market growing at well over 40% CAGR, expected to cross $1 billion in scale by the end of the decade.

A valid digital signature can establish important cryptographic facts about a signed record. It does not, by itself, preserve the complete evidentiary history surrounding the human and system action that produced it.

Why evidence must be infrastructure, not just policy
Policy can mandate consent and accountability. And India’s policymakers have spent the last few decades tightening the guardrails of accountability.

But policy alone cannot manufacture the infrastructure that makes accountability provable. That must be engineered, in the same way Aadhaar or UPI didn’t simply mandate real-time payments… it built the rails that made them possible.

Similarly, we need evidence infrastructure to authenticate who initiated an action, capture authorisation in real time, preserve a structured, tamper-evident record of it, and make that record independently verifiable years later. Often long after the person who created it is available to vouch for it themselves.

This isn’t something that can be bolted onto existing systems as a compliance layer. It must be present at the moment the action happens, not something that can be reconstructed years later.

Where the trust layer goes next
Let’s look at the example of the banking industry.

Consider a ₹100 crore bank loan. Years later, can the institution reconstruct not just whether an agreement was signed, but who authorised what, when, under which terms; and, independently verify that evidentiary history?

The evidence may exist across multiple systems; but the challenge is making those fragments tell one coherent, verifiable story. And that is the missing layer today.

If the first decade of India’s digital build was defined by making things fast and accessible at scale, the next one will be defined by making them provable at the same scale.
The next frontier of Digital India is not simply more digital actions. It is digital actions that can prove, verify and defend their own history.

Leave A Reply

Your email address will not be published.