← All posts

They found no fraud. They re-ran the election anyway.

Austria's highest court threw out a presidential election in 2016 — not because anyone cheated, but because no one could prove they hadn't.

Picture a locked room. Inside are the ballot papers that will decide who becomes president of Austria. The room has no log of who entered. No witnesses signed in. Some of the ballots inside were counted before the law permitted, by people who weren't authorized to touch them. When the Austrian Constitutional Court examined what happened, it found something striking: it could not say fraud had occurred. But it could not say fraud had not occurred. That distinction — subtle, procedural, almost bureaucratic — was enough to throw out a national presidential election.

That is the story this post is about.


A court annuls an election it could not prove was stolen

On May 22, 2016, Austrians voted in the run-off of their presidential election. Alexander Van der Bellen defeated Norbert Hofer by roughly 30,000 votes out of more than 4.5 million cast — a margin of less than one percent. Hofer's side challenged the result.

On July 1, 2016, the Verfassungsgerichtshof — Austria's Constitutional Court — handed down Decision W I 6/2016-125. It was 38,000 words long. Its conclusion was unequivocal.

Austrian law requires that all handling of postal ballots — the opening of outer envelopes, the removal of inner envelopes, the actual counting — must be conducted exclusively by the district electoral authority, with the required electoral-board members and witnesses present, and may not begin before 9:00 a.m. on the day after the election.

In district after district, those rules had been broken. Absentee ballot envelopes were opened early. They were opened by unauthorized persons. They were processed without the required witnesses present. The Court found that roughly 77,000 votes were affected by proven procedural violations — more than double the winning margin of 30,000.

Here is the part that matters most: the Court expressly found no evidence that a single vote had been altered, added, or destroyed. No one was found to have committed fraud. The irregularities appeared to be a mixture of overeager officials and sloppy administrative habits. And yet the election was annulled.

The repeat run-off was held on December 4, 2016. Van der Bellen won again.


Why annul an election you can't prove was rigged?

The Austrian Court's logic is worth sitting with, because it runs counter to how most of us instinctively think about the problem.

Most people assume the question is: did someone cheat? If the answer is no, then the result stands. The court said something more demanding: the question is whether the procedures were rigorous enough that we can affirmatively prove cheating could not have happened. When you open 77,000 ballot envelopes without witnesses, before the permitted time, you destroy the conditions under which that proof is possible. The chain of custody is broken. The result is not "probably fine." It is unverifiable.

"Unverifiable" is not a lesser problem than "fraudulent." In election law, it is often the same problem.

Think about what those postal-ballot rules actually do. The requirement that counting begin only after 9:00 a.m. the next day, only by authorized officials, only with witnesses present — each of those conditions isn't a formality. Each one is a link in a chain that, if intact, lets any observer reconstruct and confirm the handling of every ballot. Remove a link, and the chain no longer proves anything. The witnesses aren't there to watch for fraud; they're there so that the absence of fraud is observable and documented. When the witnesses aren't there, the documentation doesn't exist — and a count without documentation is, legally and democratically, a claim, not a proof.

The Austrian court understood something that gets lost in debates about election security: procedure is not bureaucratic overhead. Procedure is the verification mechanism.


The chain of custody problem is not uniquely Austrian

Austria's case is cleanest because the Court spelled out its reasoning with such precision. But the same underlying failure appears in different forms around the world.

In England's Tower Hamlets in 2014, an Election Court found actual postal-vote fraud — personation, ballot manipulation, and bribery — and voided the mayoral election. There, unlike Austria, fraud was proven. But the attack was only possible because the postal ballot chain of custody had gaps: ballots moving outside the controlled environment of a polling station are ballots that can be intercepted, pressured over, or falsified.

In North Carolina's 9th Congressional District in 2018, a coordinated absentee ballot scheme — described by the State Board of Elections as unlawful and substantially resourced — led to a new election. Again: the attack surface was mail-in ballots in transit, outside the custody of authorized officials.

In Malawi in 2020, result tally sheets were altered with correction fluid before entering the official count. The Supreme Court of Appeal's judgment voided the presidential election because the documentary chain — the source records of what voters decided — had been visibly compromised. No continuous, tamper-evident custody of the record. No verifiable result.

The pattern is consistent across jurisdictions, legal systems, and continents: when the physical chain of custody breaks, the result loses its claim to be trusted — even if, as in Austria, the break appears to be carelessness rather than malice.


The deeper principle: verification is not about catching fraud after the fact

Here is the uncomfortable implication that the Austrian case forces into view.

We tend to think about election security as a detection problem. Someone cheats, someone else catches it, the system corrects itself. Under this model, the question to ask after an election is: did the audits find anything suspicious?

But the Austrian court was applying a more rigorous standard. The question it asked was: could the integrity of this count be independently verified by a neutral observer, using the documentary and procedural record that exists? When the answer is no — not because fraud was found, but because the procedures were not followed — the result cannot be certified as clean.

A result no one can independently verify is not a "probably clean" result. It is an unresolved question.

This principle shows up in a different form in Kenya's 2017 Supreme Court decision (Odinga v. IEBC), which annulled a presidential election because result forms hadn't been transmitted as required by law and lacked consistent security features. Again: no proof of fraud. Annulment anyway, because the chain from polling station to national tally could not be independently verified.

And it is the same principle the German Federal Constitutional Court articulated in its 2009 judgment banning voting computers that didn't produce an independently checkable record: electronic vote-counting is only legitimate when ordinary citizens, not just experts, can verify each essential step. Not "probably fine." Verifiable by design.


The postal ballot is the hardest link in the chain to protect

It is worth being precise about why postal ballots create a structurally different verification challenge.

When you vote in a polling station, you are inside a controlled environment. Officials are present. Observers are permitted. The ballot box is sealed in front of witnesses. The chain of custody begins the moment your ballot leaves your hand.

A postal ballot begins its journey at your kitchen table, or wherever you happen to be. There is no observer. There is no seal applied in front of witnesses. The ballot travels through a postal system, arrives at an elections office, and must be processed by officials before it joins the count. Every one of those steps is an opportunity for the chain to break — not necessarily through fraud, but through the same kind of administrative looseness that the Austrian court documented.

The rules that Austria's officials violated — the time restrictions, the witness requirements, the authorization checks — exist precisely because the postal ballot's journey introduces custody gaps that in-person voting eliminates by design. Those rules are not procedural formalities. They are the substitute for the polling station's controlled environment.

When they are followed, the chain is intact. When they are skipped — even by well-meaning officials who are running behind schedule on a long day — the chain is broken. And a broken chain cannot be mended retrospectively. The Austrian court had no mechanism to go back and reconstruct, with confidence, what had happened to 77,000 ballots. So it annulled.


What "the audit confirmed it" actually means — and doesn't

At this point, a reasonable reader might say: but what if an audit is conducted afterward? Doesn't that restore confidence?

Let's be precise about what an audit can and cannot do.

Georgia's 2020 full hand recount of approximately 5 million ballots — documented by Georgia Public Broadcasting and NPR — confirmed the machine tally to within about a tenth of one percent. That is a remarkable result and a genuine demonstration that a physical, voter-marked paper record allows independent verification of a machine count. It works because the paper ballots themselves constitute an unbroken chain from the voter's hand to the recount table.

But notice what that audit is actually auditing: the paper record. The paper record is only trustworthy if its own chain of custody is intact — if we know those ballots are the same ones voters marked, in the same condition, unaltered between the counting and the recounting.

An audit cannot reconstruct chain-of-custody gaps that occurred upstream of the paper record itself. If 77,000 postal ballot envelopes were opened by unauthorized people without witnesses, a subsequent hand count of the same ballots cannot tell you whether those ballots were the original ones, or whether they were handled in a way that permitted substitution or removal. The audit counts what's there. It cannot count what might have been removed, or verify what it cannot see.

This is also why a hand count is not the last word in a close race. Antrim County, Michigan's December 2020 hand audit — a meticulous, ordered review of approximately 15,700 ballots — still produced a tally that differed from the machine count by about a dozen votes. That isn't an indictment of hand-counting; human miscounts, ambiguous marks, and judgment calls in adjudication are real and irreducible. But in a race decided by a margin within that range of error, "the hand count confirmed it" is a reassurance — not a proof. A method that is itself off by a dozen votes cannot settle a question decided by a dozen votes.

The answer is not to abandon audits. The answer is to build systems where the chain of custody is so documented, transparent, and tamper-evident that no gap ever needs to be reconstructed after the fact.


Procedures rigorous enough to prove fraud could not have happened

The standard the Austrian court was applying has a name in the broader literature of election integrity: end-to-end verifiability. The idea is that every step in the electoral process — from the moment a voter marks a ballot to the moment a result is certified — should be documented in a way that any independent observer can reconstruct and check.

This is not about whether you trust the officials. The Austrian officials who opened those envelopes early were, as far as the court could determine, not committing fraud. The problem was that their deviation from procedure made the result unverifiable — and unverifiable by anyone, including the officials themselves. They had inadvertently made it impossible to give the public, or a court, the proof it needed.

The Dutch government's Election Process Advisory Commission reached the same conclusion in its 2007 report "Stemmen met vertrouwen" (Voting with Confidence): there are no secrets in the election process, and questions must be answerable and the answers checkable and verifiable. The Netherlands subsequently abandoned electronic voting and returned to hand-marked paper ballots counted manually — not because machines had been found to cheat, but because their operation could not be verified to the commission's standard.

The lesson from Austria, the Netherlands, Kenya, and Malawi is the same lesson, stated different ways: it is not enough that the process probably worked correctly. The process must work in a way that anyone can independently confirm it worked correctly.


What would make any of this checkable?

Here is what the Austrian case leaves unresolved — and what it demands.

The Constitutional Court annulled 77,000 votes and ordered a re-run. That is the legal remedy. But it is a remedy of last resort, expensive and destabilizing, requiring an entire election to be run twice because administrative procedures failed the first time.

The better fix is upstream: design postal ballot procedures with a chain of custody so documented, timestamped, and witnessed that a gap would be immediately apparent — not discovered six weeks later in a court challenge. Every envelope opened should be logged. Every witness should sign. Every stage should produce a record independent of the official doing the counting.

Beyond postal ballots, the broader principle applies to every part of the process: results should be published at the precinct level, instantly, in machine-readable formats that anyone can download and reconcile. Not because officials are untrustworthy, but because trust in any individual or institution is fragile, and verifiability is durable. See how common this chain-of-custody gap is across the world.

What is still not verifiable after Austria 2016, or any of the cases above, is the handling of ballots that move outside official custody before the count — postal ballots in transit, absentee envelopes before the authorized opening time. No court, no audit, no official statement can reconstruct what happened to ballots that were handled without witnesses. That gap can only be closed prospectively, by procedures rigorous enough that the gap never opens.

The goal is not an election where officials confirm everything was fine. The goal is an election where anyone can independently check that it was.

Read the 2-minute version of this problem | See the full gap tracker


Sources