Signature Modules
Where & How Clients Sign
rSign supports every banking scenario with four specialised modules.
The right choice depends on signing location and
how the client is identified.
On-site, In-App or Remote
One platform, four powerful modules — all accessible through a single, clean API.
rSign PAES
Advanced Electronic Signature on signature pads at bank counters and service desks. Biometric handwriting capture with face-to-face identification by the bank clerk.
- Signing location: Branch / counter
- Identification: Bank clerk (face-to-face)
- Biometric data embedded in the signature
- Qualified timestamp included
rSign OQES
One-time Qualified Digital Certificate issued on the spot by a QTSP. Full eIDAS QES at the counter without any signature-pad hardware.
- Signing location: Branch / counter
- Identification: Bank clerk (face-to-face)
- True Qualified Electronic Signature
- Zero CAPEX on signature devices
rSign IQES
Full Qualified Electronic Signature inside the banking app for already authenticated customers. Bank acts as Registration Authority; QTSP issues a short-lived one-time certificate.
- Signing location: Inside the banking app
- Identification: App authentication (SCA)
- Highest legal strength without branch visit
- Reuses existing KYC + strong customer authentication
rSign RQES
Fully remote Qualified Electronic Signature via web or mobile. Identification through trusted cloud identity providers, national eID schemes or QTSP remote methods.
- Signing location: Anywhere (home / remote)
- Identification: Cloud / eID / remote providers
- No branch visit and no banking-app session required
- Multiple identity providers supported
Signing location & client identification
The two dimensions that determine which module fits each use case.
PAES — On-site pads
Location: Bank branch / service desk.
Identification: Performed by the bank clerk face-to-face.
Signature captured on a dedicated signature pad with biometric data.
OQES — On-site one-time QES
Location: Bank branch / service desk.
Identification: Bank clerk face-to-face (same KYC/AML process).
QTSP issues a short-lived one-time Qualified Digital Certificate — no pad needed.
IQES — In-app QES
Location: Inside the customer’s banking (or partner) app.
Identification: Existing strong customer authentication (SCA) of the app.
Bank acts as RA; QTSP issues one-time QDC for the session.
RQES — Fully remote QES
Location: Any location (home, mobile, web).
Identification: Trusted cloud identity providers, national eID or QTSP remote identification.
No clerk and no requirement to be inside a specific banking app.
Which module for which situation?
Quick guidance based on where the customer is and how they can be identified.
Customer is in the branch and you already use pads
Keep the familiar biometric pad experience while adding qualified timestamps and full auditability.
→ Recommend PAES
Customer is in the branch and you want full QES without hardware
Eliminate signature-pad fleets. Clerk identifies the customer face-to-face; QTSP issues a one-time certificate.
→ Recommend OQES
Customer is already logged into your banking app
Offer the highest legal strength (QES) for in-app documents without forcing a branch visit or extra ID steps.
→ Recommend IQES
Customer is completely remote and has a cloud / eID identity
Enable signing from home using existing trusted remote identities and QTSPs.
→ Recommend RQES
One API. All four modules.
Integrate once and support every combination of location and identification method your bank needs —
on-site, in-app or fully remote.