← Back to Blog
Platform

How Meeting Attendees Sign the Opening/Closing Form Without a Certiva Account

2026-06-08 · 7 min read

The Signing Problem Every CB Faces

During an ISO certification audit, the opening meeting and the closing meeting are formal events. The auditor presents the audit scope, plan, and methodology at the opening; findings and recommendations at the closing. Both meetings are documented in a form — often called FR.225 or something similar — that must be signed by all attendees.

The attendees include the lead auditor, any team members, and several client-side participants: the management representative, the quality manager, department heads, and sometimes senior leadership. These client employees are not auditors. They are not CB staff. They will never log into the CB's certification management system. But their signatures are required on the meeting form.

This creates a practical problem that every CB has struggled with.

The Traditional Approach: Print, Sign, Scan

For decades, the process has looked like this: the auditor prints the meeting form, passes it around the table, everyone signs with a pen, the auditor scans the signed form (or photographs it with a phone), and uploads the image to whatever system the CB uses. Sometimes the scan is unreadable. Sometimes the form gets lost between the audit site and the office. Sometimes the auditor forgets to collect a signature and has to follow up weeks later by email.

This process is slow, error-prone, and produces documents of inconsistent quality. It also creates a weak audit trail — there is no system-level record of when each signature was applied, only the date printed on the form.

Why Account Creation Is Not the Answer

The obvious digital solution — give every meeting attendee a Certiva account — is impractical. Consider a typical audit: five client employees attend the opening meeting. They need to sign one form, once. Creating user accounts for all five means managing five sets of credentials for people who will use the system for thirty seconds and never return. It wastes the CB's user licenses, clutters the user database, and creates a terrible experience for the client employee who just wants to sign a form and get back to work.

Some platforms attempt this anyway, requiring every signer to create an account. The result is predictable: attendees refuse, the auditor collects signatures on paper anyway, and the digital workflow is abandoned.

How Certiva Handles It: Email Token With OTP Verification

Certiva takes a different approach. When the auditor initiates the opening or closing meeting form (FR.225), they enter the names and email addresses of the client-side attendees. Certiva then sends each attendee an email containing a unique link and a one-time password (OTP).

The process from the attendee's perspective:

  • 1. They receive an email with a link to the meeting form and a verification code.
  • 2. They click the link and are taken to a signing page in their browser — no app download, no account creation.
  • 3. They enter the OTP from the email to verify their identity.
  • 4. They review the form content — the meeting details, attendee list, and any notes the auditor has recorded.
  • 5. They sign in-browser using their finger on a touchscreen or their mouse/trackpad on a laptop. This is a visual signature — a drawn mark that represents their personal sign-off.
  • 6. The signature is captured along with their name, the timestamp, and their IP address. The form updates to show their signature as collected.

The entire process takes less than a minute. The attendee does not need to create an account, remember a password, or install anything.

What Gets Recorded

Each signature on the meeting form captures:

  • The signer's name as entered by the auditor and confirmed by the signer
  • The visual signature drawn by the signer in their browser
  • The timestamp of when the signature was applied, recorded by the server
  • The IP address of the device used to sign

This information is stored in Certiva's audit trail for that form. When all required signatures have been collected, the form is finalized and a PDF is generated with all visual signatures flattened into the document. The PDF is stored in the audit file and linked to the client's certification record.

Important: What This Is and What It Is Not

This signing mechanism is a visual signature with a verified identity and a timestamped record. It is not a cryptographic digital signature. It is not eIDAS-qualified. It does not use PKI certificates or cryptographic key pairs.

What it provides is:

  • Verification that the signer received the email at the address provided (they needed the OTP from that email to sign)
  • A visual representation of their signature on the document
  • A timestamped, IP-logged record of when the signature was applied
  • A tamper-proof PDF with signatures flattened into the document so they cannot be altered after generation

For the purpose of audit meeting documentation, this level of assurance is appropriate and practical. The accreditation body needs to see that the meeting was held, that attendees participated, and that they acknowledged the proceedings. A visual signature with identity verification and a full in-app record satisfies this requirement.

The Auditor's Perspective

For the auditor, the workflow eliminates a significant administrative burden. Instead of managing paper forms, chasing signatures, and scanning documents, the auditor:

  • 1. Opens the meeting form in Certiva during the meeting
  • 2. Enters attendee details (or selects them from previous audits if the organization has been audited before)
  • 3. Triggers the signing invitations
  • 4. Signs the form themselves
  • 5. Monitors the form status as attendee signatures come in

If an attendee's signature is still pending after the meeting, the auditor can trigger a reminder. The attendee clicks the same link, enters the OTP, and signs. No follow-up emails with PDF attachments, no printing and re-scanning.

Practical Considerations

A few details that matter in real-world use:

  • Attendees can sign on their phones. The signing page is mobile-responsive. During the meeting itself, attendees often sign on their smartphones immediately after receiving the email, while still in the room.
  • The OTP has a limited validity window. If the attendee does not sign within the window, a new OTP can be sent. This prevents stale links from being used weeks later.
  • The auditor controls the attendee list. Only the auditor can add attendees to the form. Client employees cannot self-add or modify the form content.

The result is a meeting form that is fully signed, properly recorded, and stored in the audit file — all without requiring anyone outside the CB to have a Certiva account.