Evidence Law: Indian Evidence Act, 1872 / Bharatiya Sakshya Adhiniyam, 2023 (BSA)
Electronic Evidence Certificate under the Schedule
The Electronic Evidence Certificate under the Schedule to the Bharatiya Sakshya Adhiniyam, 2023: Form, Contents and Common Defects
The Indian Evidence Act prescribed no form for the certificate under Section 65B(4), and the consequence was two decades of litigation about what a certificate had to contain. The Adhiniyam supplies a form in the Schedule, divided into two Parts and requiring two signatures. Getting the form right is now largely a matter of care rather than of judgment, and the defects that defeat certificates are almost all avoidable.
1. Where the Form Comes From
Section 63(4), BSA — closing words ... and purporting to be signed by a person in charge of the computer or communication device or the management of the relevant activities (whichever is appropriate) and an expert shall be evidence of any matter stated in the certificate; and it shall be sufficient for a matter to be stated to the best of the knowledge and belief of the person stating it, and in the certificate specified in the Schedule. |
Three requirements are packed into these words, and all three are new as against Section 65B(4) of the Indian Evidence Act.
- Two signatures — a person in charge, and an expert. The earlier provision required one.
- A prescribed form — the certificate specified in the Schedule. The earlier provision prescribed none.
- Submission at each instance — the opening words of the sub-section require the certificate to accompany the record 'at each instance where it is being submitted for admission'.
The Schedule gives effect to the first two by dividing the certificate into Part A, completed by the party or the person in charge, and Part B, carrying the declaration of the expert.
2. Part A — What It Must Contain
Part A is the substantive part. It is completed by the party producing the record or by the person in charge of the computer or communication device or of the management of the relevant activities, and it covers five matters.
2.1 Identification of the electronic record
The record must be identified with enough particularity that there can be no doubt what is being certified. A description such as 'WhatsApp messages' or 'call records' is inadequate. What is required is the kind of record, the account or number to which it relates, the period covered, the number of pages or files, and the manner in which the record is being produced — as a printout, as a file on media, or otherwise.
Where the record is being produced as a file rather than on paper, the file name, the file size and the format should be stated, because these together with the hash value are what allow the record to be identified beyond dispute at a later stage.
2.2 The manner in which it was produced
Clause (a) of Section 63(4) requires the certificate to describe how the output was produced. This means the actual process — the record was exported from the application to a file and printed; the record was extracted using a specified forensic tool; the record was downloaded from a named portal after authentication; the record was generated by running a query against a database.
A statement that the record was 'taken from the computer' does not describe a manner of production. The court and the opposing party are entitled to know what was done, because the reliability of the output depends on it.
2.3 Particulars of the device
Clause (b) requires particulars of any device involved, 'as may be appropriate for the purpose of showing that the electronic record was produced by a computer or a communication device'. In practice this means the make and model, an identifying number where one exists — a serial number, an IMEI, an asset tag — the operating system, and where relevant the application and version from which the record came.
Where a system rather than a single device is involved, the particulars should describe the system: the server, its location, the software running on it, and how the output was drawn from it. Section 63(3) treats a combination of devices as a single device, so the certificate need not describe every machine in the chain, but it should describe the system sufficiently for the court to see what produced the record.
2.4 The matters relating to the conditions in Section 63(2)
Clause (c) requires the certificate to deal with the matters to which the four conditions relate. This is the heart of Part A, and each condition should be addressed distinctly rather than covered by a general assertion of compliance.
- Condition (a) — that the device was used regularly to create, store or process information for an activity regularly carried on, by a person having lawful control over its use.
- Condition (b) — that information of the kind contained in the record was regularly fed in, in the ordinary course of those activities.
- Condition (c) — that the device was operating properly during the material part of the period, or that any malfunction did not affect the record or the accuracy of its contents.
- Condition (d) — that the information in the record reproduces or is derived from what was fed in, in the ordinary course.
A certificate which recites that 'all the conditions of Section 63(2) are satisfied' without addressing them individually is formally compliant but evidentially thin, and it invites the objection that the deponent has not applied his mind to the matters he is certifying.
2.5 The hash value
The distinctive requirement of Part A is the disclosure of the hash value of the electronic record, obtained through one of the algorithms the Schedule specifies. The algorithms named are the standard families — SHA-1, SHA-256 and MD5 — and where a choice exists the stronger should be used.
The hash should be stated exactly as computed, with the algorithm identified. A hash value given without saying which algorithm produced it cannot be verified, and a hash for a different version of the file than the one produced defeats the purpose entirely.
⚠ The hash must relate to the record being tendered Where a party computed a hash at the time of seizure and afterwards produces a printout or an extract, the hash of the seized image and the hash of the extract are different values, and both may need to be stated — the first to establish that the source has not changed since seizure, the second to identify the output being tendered. A certificate disclosing one hash without saying what it is the hash of is a common and serious defect. |
3. Part B — The Expert's Declaration
Part B carries the declaration of the expert. It records that he has examined the electronic record and states his conclusion in relation to the matters the sub-section requires.
What the expert is certifying is not the same as what the person in charge certifies in Part A. The person in charge speaks to the system — how it was used, what was fed into it, whether it was working. The expert speaks to the record — that he has examined it, that the hash value is as stated, and that the output corresponds to what it purports to be.
The identity of the expert was the subject of a constitutional challenge, and the position is now settled.
📖 Pune Bar Assn. v. Union of India, 2026 SCC OnLine SC 1297 (decided 22 May 2026) Held: A three-Judge Bench upheld Section 63(4) and the Schedule. Electronic records are a species of evidence liable to continuous mutation, and the requirements of hash-value disclosure and expert certification bear a rational nexus with the object of securing authenticity and integrity. Reading Sections 39(1) and 39(2) harmoniously, the expert who signs Part B is not confined to an Examiner of Electronic Evidence notified under Section 79A of the Information Technology Act, 2000; any person possessing special skill and expertise in computer science or cyber forensics may sign, provided the court is satisfied of the credentials on unimpeachable material. Ratio: Part B may be signed by any competent cyber forensic examiner, but his credentials must be established rather than assumed. |
The practical consequence for the form is that the expert's credentials should appear. His qualifications, his training, his experience and the capacity in which he examined the record are matters the court will want, and putting them in the certificate — or annexing them to it — avoids an application to prove them later.
4. Who Signs What
Part A | Part B | |
|---|---|---|
Signed by | The party producing the record, or the person in charge of the device or of the management of the relevant activities | An expert in computer science or cyber forensics |
Speaks to | The system — regular use, regular feeding, proper operation, derivation; and the hash value | The record — that he has examined it and that it is as certified |
Standard of knowledge | To the best of his knowledge and belief, as Section 63(4) expressly permits | Based on his own examination |
Must the credentials be proved? | The capacity in which he signs should be stated | Yes — on unimpeachable material, following Pune Bar Assn. |
The words 'whichever is appropriate' in Section 63(4) give a genuine choice for Part A. Where a record comes from a large organisational system, the person in charge of the relevant activities may be better placed to certify than a technician who operates the machine; where it comes from a single device, the person in charge of the device is the natural signatory. The choice should be made deliberately, because the deponent may be examined on what he has certified.
5. Common Defects
Certificates fail for a small number of recurring reasons, and every one of them is avoidable.
- One signature instead of two. A certificate in the old Section 65B form, signed only by a person in charge, does not comply with Section 63(4).
- No hash value, or a hash value without the algorithm identified, or a hash that does not correspond to the record produced.
- A general recital of compliance with Section 63(2) instead of addressing the four conditions separately.
- No description of the manner of production, which clause (a) expressly requires.
- Inadequate identification of the record — a generic description that does not tie the certificate to what has been tendered.
- No particulars of the device, or particulars so vague that they show nothing.
- The expert's credentials not stated, so that Part B is signed by somebody the court has no basis to regard as an expert.
- The certificate not submitted with the record at the instance of tender, contrary to the express words of the sub-section.
- A single certificate used across multiple tenders, where the sub-section requires one at each instance.
⚠ A defective certificate and an absent certificate are attacked differently Where no certificate is furnished, the objection goes to admissibility and the record cannot be received — the position under Anvar P.V. and Arjun Panditrao. Where a certificate is furnished but imperfect, the objection is more naturally one of mode of proof, which on the authority of R.V.E. Venkatachala Gounder v. Arulmigu Viswesaraswami and V.P. Temple, (2003) 8 SCC 752 must be taken when the record is tendered so that the defect may be cured, and is waived if not taken then. A party tendering should treat every defect as fatal; a party objecting should take the point at tender and identify precisely what is missing. |
6. Practical Drafting
A certificate that will withstand scrutiny is built from six components, and preparing them is a matter of sequence rather than of drafting skill.
First, establish whether a certificate is needed at all. If the output falls within an Explanation to Section 57 — multiple files, proper custody undisputed, simultaneous video recording, automated storage including temporary files — it is primary evidence and Section 63 does not operate. If the original device can be produced, no certificate is required on the authority of Arjun Panditrao. In practice, obtain one anyway where the record matters, because Explanation 4 depends on the opponent not disputing the record.
Second, compute and record the hash at the earliest moment — at seizure, at imaging, at download — and record it in the seizure memo, panchnama or file note so that its provenance is independent of the certificate itself.
Third, identify the correct signatory for Part A, choosing between the person in charge of the device and the person in charge of the relevant activities according to what the record is.
Fourth, retain the expert for Part B and gather the material establishing his credentials before the certificate is drawn, not after the objection is taken.
Fifth, address each of the four conditions separately in Part A, in terms that reflect what the deponent actually knows.
Sixth, annex what is needed — a copy of the record certified, the hash computation, the expert's qualifications — so that the certificate stands as a complete document.
7. What the Certificate Does Not Do
The form is prescribed, and a properly completed certificate answers the objection it exists to answer. It answers nothing else, and three limits should be kept in view.
It does not prove that the contents are true. Section 63(1) admits the output as evidence of a fact only 'of which direct evidence would be admissible'. A statement that would be hearsay from a witness remains hearsay in a computer output, and becomes evidence of its truth only under a provision that makes it so — most often as an admission under Section 15.
It does not establish attribution. That a message came from an account or a device is one thing; who was operating it is another. No provision addresses this, and Section 90 expressly declines to presume who sent an electronic message.
It does not answer completeness or meaning. Whether enough of a record has been produced for its meaning to be understood is governed by Section 33; what a fragment signifies is a matter for expert opinion under Section 39(2). A certified record may be perfectly admissible and entirely uninformative.
8. The Position Stated Shortly
- The Schedule prescribes the form, which the Indian Evidence Act did not, and divides it into two Parts.
- Part A is completed by the party or the person in charge, and covers identification, manner of production, particulars of the device, the four conditions, and the hash value.
- Part B carries the expert's declaration, and the expert need not be a notified Examiner — Pune Bar Assn.
- Two signatures are required. A certificate in the old single-signature form does not comply.
- The four conditions should be addressed separately, not covered by a general recital of compliance.
- The hash value must identify the algorithm and must correspond to the record actually tendered.
- The certificate accompanies the record at each instance of tender, as the sub-section expressly requires.
- An absent certificate goes to admissibility; a defective one goes to mode of proof and must be objected to at tender.
9. Related Topics and Provisions
Topic or provision | Connection |
|---|---|
Section 63 Certificate — Complete Note | The requirement, its timing and when it is not needed |
Role of the Expert in the Section 63 Certificate | Who may sign Part B and what the expert actually does |
Hash Value and Integrity of Electronic Evidence | What the hash establishes and how it is computed and verified |
Conditions for Admissibility of Computer Output | Section 63(2), addressed in Part A |
Electronic or Digital Record as Primary Evidence | The Explanations to Section 57, where no certificate is needed |
Section 33, BSA | How much of a record must be produced for its meaning to be understood |
Section 90, BSA | Presumption as to electronic messages, and the express refusal to presume the sender |