Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What happens when an IPEN session is completed…
Governance, Ownership & Risk

What happens when an IPEN session is completed without retaining the audit trail and eJournal?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Governance, Ownership & Risk

If the audit trail and eJournal are not retained, the notarization may still be completed, but the supporting evidence becomes much harder to defend later. Teams lose a detailed record of identity verification, timestamps, notary actions, and signer actions. That weakens internal review, dispute handling, and recordkeeping confidence for the notarized document.

What the missing audit trail changes in an IPEN session

An IPEN session can still conclude, but the evidentiary value drops sharply when the audit trail and eJournal are not preserved. The practical loss is not the notarization action itself, it is the ability to prove what happened, when it happened, and who performed each step. That turns a completed session into a weaker record for later scrutiny, dispute handling, and governance.

Without the retained record, the organisation loses the chain of events that makes the session defensible. The eJournal is what ties together identity checks, timestamps, signer actions, and notary actions into a coherent transaction history. If that history is absent, later reviewers can no longer validate the sequence with the same confidence, even if the document was otherwise completed.

This is why the issue matters most after the session is over. At the point of completion, the operational workflow may appear successful. The failure emerges later, when someone asks for proof of how the notarization was carried out and the supporting evidence is incomplete or missing.

Why retention matters for review, dispute handling, and recordkeeping

The retained audit trail is the difference between a notarization that is merely finished and one that can be reconstructed. In practice, teams need to show that the signer was present, the identity checks were performed, the notary acted at the right time, and the session was not altered after the fact. Retention supports that reconstruction.

That makes retention a recordkeeping control as much as a workflow control. If the audit trail and eJournal are discarded too early, internal reviewers lose the ability to test the integrity of the session, legal or compliance teams lose supporting evidence for challenges, and operations teams lose a reliable source for incident follow-up. The result is a weaker institutional memory around a high-trust event.

For practitioners, the key point is that completion and defensibility are not the same outcome. A session can complete successfully while still leaving the organisation exposed to downstream questions it cannot answer well.

What to verify before you treat an IPEN completion as closed

Before closing the record, verify that the retained artefacts are complete, readable, and associated with the correct notarization event. Teams should confirm that the eJournal entry matches the session, that timestamps are present, and that the evidence is retained in the system or repository that will actually be used for later review. If the retention path is unclear, the control has not really been exercised.

The most common operational mistake is assuming the notarized document is enough on its own. It usually is not. The document is the outcome, while the audit trail is the proof of process. When those are separated, teams should treat the process record as a first-class artefact and not as optional metadata.

For governance teams, the useful question is whether a later reviewer could reconstruct the session without relying on memory, screenshots, or informal notes. If the answer is no, the retention model is too weak for a defensible notarization workflow. NHIMG’s Ultimate Guide to NHIs, Regulatory and Audit Perspectives is a useful broader reference on why audit evidence and governance records matter when identities and access events must be defensible. SOC 2 Trust Services Criteria is also relevant when the organisation wants a formal assurance lens on record integrity and traceability.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AU-11 — Audit Record RetentionIPEN evidence depends on keeping the session record and journal available later.
Recommendation — Retain notarization audit records long enough to support review, dispute handling, and compliance evidence.
ISO/IEC 27001:2022A.5.33 — Protection of recordsThe audit trail and eJournal are records whose integrity and availability must be preserved.
Recommendation — Protect and retain notarization records so they remain usable for later verification.
SOC 2 (AICPA)CC7.2 — Change, Incident, and Access MonitoringRetained eJournal evidence supports traceability and detection of irregular session activity.
Recommendation — Keep session evidence available for monitoring, investigation, and audit support.

Practitioner Guidance

What to prioritise: Treat retention as part of the notarization outcome, not a post-processing convenience. If the audit trail or eJournal cannot be retrieved for review, the session should be considered operationally weaker even if the notarization itself completed.

What to verify: Confirm that the retained record ties the signer, notary actions, and timestamps to one transaction and that the record is stored where your review, legal, or compliance teams can actually access it later. If that linkage is missing, the record is not yet fit for defence.

Practitioner takeaway: The real control is not just completing the IPEN session, it is preserving enough evidence that the session can still be explained, challenged, and trusted after the fact.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org