Organisations should move sensitive signing journeys toward passkeys, especially where password, OTP, or knowledge-based methods create friction and weak assurance. Passkeys let users authenticate with device-level biometrics or a PIN, reduce failed sign-ins, and remove phishing-prone secrets from the flow. For eSignature, that improves both customer experience and confidence that the right person is accessing the agreement.
Modernising signer authentication without making the journey feel heavier
The practical shift is to treat signer authentication as a trust problem, not a password problem. For sensitive agreements, the goal is to raise assurance while removing the repeated challenges that slow users down, which is why passkeys are a strong fit. They bind authentication to the user’s device and local verification, so the experience is faster, less error-prone, and less exposed to phishing than OTP or password recovery flows.
That matters most where the signing event is high value, time sensitive, or likely to be accessed on a mobile device. In those cases, the friction people feel is often caused by weak control design, not by the agreement itself. If the authenticator is easy to steal or reuse, the organisation ends up adding more steps later, for example extra challenge screens, helpdesk verification, or manual review, which usually creates more drag than a modern passwordless flow.
Passkeys also shift the assurance model in a useful way because they reduce reliance on shared or reusable secrets. The user still authenticates, but the proving method is tied to possession of the enrolled device and a local gesture such as biometrics or a PIN. For eSignature workflows, that lets organisations strengthen confidence in the signer’s access without turning the signing page into a high-friction identity exercise.
Where the user experience improves and where controls still need to be deliberate
Passkeys work best when the signing journey is designed around actual user behaviour. People typically open an agreement once, review it quickly, and sign from a device they already trust. A modern signer flow should therefore make authentication feel like a natural step in the transaction, not a separate security ceremony. If the policy requires repeated knowledge checks or one-time codes at every touchpoint, the organisation is paying a usability cost for assurance that is often weaker than it appears.
That does not mean every signing event should be treated the same. Higher-risk agreements may still need step-up checks, especially when the transaction value, legal consequence, or anomalous access pattern justifies it. The design choice is to apply stronger authentication selectively, rather than forcing the same heavy process on every signer and every document. That preserves convenience for routine use while reserving extra friction for genuinely sensitive cases.
For practitioners, the most important implementation detail is recovery. A passwordless experience can fail badly if account recovery, device replacement, or fallback routing is poorly governed. The signing flow should work smoothly for the legitimate signer, but it should not become easy to bypass through weak recovery questions or overly permissive helpdesk processes.
Risk and Threat Considerations
Older signer authentication methods create a predictable mix of phishing exposure, credential reuse, and support burden. If the organisation still depends on passwords or OTP, attackers have more opportunities to intercept or replay the login step, and users have more opportunities to fail the flow and request exceptions. The result is often a system that looks controlled on paper but leaks assurance in practice.
Failure mechanism: Weak or reusable authenticators can be phished, replayed, reset through social engineering, or bypassed through recovery paths that were added to reduce friction. That erodes confidence in who actually accessed the agreement and can open the door to unauthorized signing or disputed execution.
Impact: Sensitive agreements may be signed under false pretences, disputes become harder to resolve, and the organisation may compensate with manual verification steps that slow down legitimate signers even more.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC — Access Control | Signer authentication is an access control problem for agreement access. |
| Recommendation — Apply access control to ensure only the intended signer can open and approve the agreement. | ||
| NIST SP 800-63 | IAL/AAL/FAL — Identity Assurance Levels / Authenticator Assurance Levels / Federation Assurance Levels | Passkeys change signer assurance requirements and authentication strength. |
| Recommendation — Set the required assurance level for signing based on agreement sensitivity and fraud impact. | ||
| CIS Controls v8 | 5 — Account Management | Modern signer authentication depends on governed account and recovery handling. |
| Recommendation — Harden account lifecycle and recovery so passwordless sign-in is not weakened by fallback abuse. | ||
| OWASP Agentic AI Top 10 | A1 — Agent Goal Hijacking | No direct material mapping to the question's primary subject, omitted. |
Practitioner Guidance
What to prioritise: Start with the signing journeys that combine sensitivity and high user volume. Those are usually the places where passkeys deliver the biggest reduction in friction without weakening assurance.
What to verify: Confirm that the recovery path is as strong as the primary login path. A well-designed passkey flow can still be undermined if device reset, support desk escalation, or fallback authentication is easier to abuse than the main channel.
Decision rule: If a signing event can create legal, financial, or customer-impacting consequences, keep a step-up option for exceptions, but make the normal path passwordless and phishing-resistant.
Practitioner takeaway: The best modernisation pattern is to remove the weak authenticator from the default signing path, not to bolt extra checks onto a fragile one; that is how organisations improve both trust and completion rates.
Related resources from NHI Mgmt Group
- How should organisations implement two-factor authentication in high-risk digital services without creating unnecessary user friction?
- How should organisations reduce completion delays in digital agreement workflows without adding friction for signers?
- How should organisations implement passive authentication in biometric onboarding without adding friction for users who may struggle with active challenges?
- How should organisations design customer identity so digital experiences stay secure without adding unnecessary friction?