Understanding electronic signature compliance in Ideagen Quality Management Core
Who is this article for?Administrators evaluating electronic signature compliance requirements.
Document module access is required to configure password verification.
If your organisation needs to confirm whether Ideagen Quality Management Core's electronic signature functionality meets specific compliance or regulatory requirements, this article explains how the feature works and clarifies its alignment with federal cryptographic standards.
Understanding how electronic signatures work
Ideagen Quality Management Core supports password-based electronic signatures through a folder-level setting called password verification. When enabled, users must re-enter their Ideagen Quality Management Core login credentials at the point of document approval. This authentication step is treated as a legally valid electronic signature, establishing accountability and traceability for who approved a document and when.
Enabling password verification
To enable password verification for a folder:
- Navigate to the folder containing the relevant documents.
- Open Folder Properties.
- Go to the General tab.
- Select the Require password verification checkbox.
- Click Save.
Once enabled, password verification will be required starting with the next approval process for documents in that folder.
Reviewing compliance with specific FIPS standards
Some organisations — particularly federal agencies and regulated industries — need to confirm that electronic signature functionality complies with specific Federal Information Processing Standards (FIPS), such as those governing cryptographic modules and digital signature algorithms.
Important: Ideagen Quality Management Core's electronic signature feature is legally valid and secure for general document and training approval purposes. However, it does not fully adhere to the following specific FIPS standards:
- FIPS 140-3 (cryptographic module certification)
- FIPS 180-4 (secure hash standards)
- FIPS 186-5 (digital signature standards)
If your organisation's electronic signature policy requires explicit certification against these specific standards, Ideagen Quality Management Core's current implementation does not meet that requirement, even though the underlying authentication process is secure and produces a legally valid signature for general compliance purposes.
| Requirement | Status |
|---|---|
| Legally valid electronic signature for document and training approval | Supported |
| User authentication via login credentials at point of approval | Supported |
| Accountability and traceability of who approved a document | Supported |
| Certified cryptographic module compliance (FIPS 140-3) | Not currently supported |
| Secure hash standard compliance (FIPS 180-4) | Not currently supported |
| Digital signature standard compliance (FIPS 186-5) | Not currently supported |
Raising FIPS-level certification requirements
If your organisation's policy specifically mandates compliance with FIPS 140-3, FIPS 180-4, or FIPS 186-5, raise this with your Account Manager or Ideagen Support. This allows your specific requirement to be reviewed against the product roadmap and gives Ideagen visibility into demand for stricter cryptographic certification, which may inform future development priorities.
Note: There is currently no configuration option within Ideagen Quality Management Core that brings the existing password verification feature into alignment with these specific FIPS standards. This is a product-level limitation rather than a setup or configuration issue.
Tip: When raising a compliance requirement of this kind, reference the specific standards by number (for example, FIPS 140-3) and the regulatory or policy document that mandates them. This allows your request to be assessed accurately against the precise requirement, rather than against a general description of electronic signature compliance.