India kept its voting machines — but tightened the paper check. Why?
India's Supreme Court refused to scrap its voting machines — then immediately ordered stronger paper seals and independent spot-checks. That tension tells you everything about what "trust" actually requires.
It is the morning of April 26, 2024, and somewhere in New Delhi, a two-judge bench of India's Supreme Court has just finished reading 102 pages of petitions asking it to do something dramatic: scrap the country's entire electronic voting system, or at minimum require that every single paper slip generated by every voting machine be counted by hand.
The petitioners — the Association for Democratic Reforms and others — were not conspiracy theorists. They were pointing at a genuine structural question: in an election involving roughly 970 million eligible voters across a country of continental scale, how much of the electronic count can any citizen independently verify?
The court said no to both demands.
And then it immediately ordered stronger paper seals, mandatory secured storage, and a new dispute-verification mechanism tied to the paper trail.
That combination — uphold the machines, tighten the paper check — is worth sitting with. Because it contains an argument that cuts across every democracy that has ever tried to run an election on a computer.
What India's machines actually do, and what the court actually said
India's Electronic Voting Machines (EVMs) are standalone, non-networked devices. They are not connected to the internet. They do not run commercial operating software. The Election Commission of India describes them as purpose-built, tamper-resistant units. Since 2013, the system has been paired with a Voter Verifiable Paper Audit Trail — a VVPAT — a small printer behind a glass window that displays, for seven seconds, a paper slip showing the party symbol and candidate name the machine recorded. The slip drops into a sealed box the voter cannot touch.
In Association for Democratic Reforms v. Election Commission of India (2024 INSC 341, judgment of 26 April 2024), the Supreme Court of India declined to order a return to paper ballots or a full 100% hand-count of VVPAT slips. The existing regime — mandatory hand-verification of VVPAT slips in five randomly selected polling stations per constituency — survived.
But the court did not simply say "we trust the Election Commission." It issued concrete directions:
- Symbol Loading Units (SLUs) — the devices used to load candidate and party symbols onto EVMs before an election — must be sealed and secured after the symbol-loading process and stored for a minimum of 45 days after results are declared.
- Candidates may, on payment of a fee, request verification of the burnt memory microcontroller in 5% of EVMs in a constituency, in the event of a dispute.
Read those two directives carefully. The court was not saying the machines are fine, trust us. It was saying: seal the devices that touch the machines before voting, keep them available for checking afterward, and give losing candidates a mechanism to challenge the count against physical hardware evidence.
Even a judgment that upheld the electronic system leaned, at every anxious moment, on the logic of independent, paper-and-hardware-based checkability.
That is the argument. Not India's argument — everyone's argument.
The question every court in every country eventually arrives at
In March 2009, eight judges in Karlsruhe, Germany reached what is now the clearest judicial statement of the core principle. The German Federal Constitutional Court, reviewing the use of Nedap voting computers in the 2005 Bundestag election, held that electronic voting is only legitimate when "the essential steps of the voting and of the determination of the result can be examined by the citizen reliably and without any specialist knowledge."
Not by a certified expert. Not by the election authority. By a citizen.
The machines stored votes only in electronic memory, with no independently verifiable record a voter could check. They failed the test. The Federal Voting Machines Ordinance was found unconstitutional.
India's Supreme Court in 2024 was wrestling with the same question at far greater scale, with a different machine architecture, and reached a different bottom line — but notice what it preserved in both directions: the paper slip the voter watches drop into the box, and the hardware record that a disputed constituency can now request to examine. The court drew a line between trusting a machine and having something to check the machine against.
That line is not India's invention. It is the irreducible minimum that every serious national court has eventually demanded.
What happens when there is nothing to check
The Sarasota County, Florida case from 2006 remains the clearest single example of what the absence of a paper trail actually costs you. Roughly 18,000 ballots in Florida's 13th Congressional District showed no recorded choice in the race — a 13% undervote rate on paperless ES&S iVotronic touchscreen machines. The race was decided by 369 votes. The GAO tested the systems and could not identify a machine malfunction, but noted that a voter-verified paper trail could have provided independent confirmation that the touchscreens recorded votes correctly.
There was nothing to recount. No slip in a box. No physical artifact the voter had watched produced. The machines said what they said, and there was no independent layer to interrogate.
A machine that leaves no checkable trace is not a counting system. It is a declaration.
India's VVPAT regime, whatever its limitations, is a structural rejection of that outcome. The paper slip exists. The question the Supreme Court was adjudicating was not whether to have a paper trail but how much of it must be verified by hand, and under what conditions the hardware beneath it can be examined.
That is a real argument worth having. It is not the same argument as whether to have any check at all.
Why the five-polling-station sample is a genuine tension, not a comfortable answer
The court retained the requirement that VVPAT slips be hand-counted in five randomly selected polling stations per constituency. India has thousands of constituencies. The sample is small.
Critics of the ruling — and the petitioners before the court — argued that a small random sample cannot provide the statistical confidence needed to certify a close result. That is a legitimate technical objection, not a fringe one.
Compare Colorado's approach: in 2017, Colorado became the first U.S. state to complete a statewide risk-limiting audit, a method that sizes its hand-check sample to the closeness of the race. A blowout needs a small sample to confirm. A near-tie requires many more ballots examined by hand. The RLA delivers a defined statistical confidence; a fixed five-station sample does not, and in a close race, the math matters.
The Indian court's answer is not that five stations is optimal. Its answer is that the architecture of dispute-resolution — sealed SLUs, stored for 45 days, with microcontroller verification available on request — provides a different layer of check that the five-station sample alone does not.
Whether that layer is sufficient is a technical question the judgment does not fully resolve. That unresolved question is not a flaw in this piece's argument — it is precisely the question that gives the ruling its tension.
The court upheld the machines. It added hardware-level dispute checks. It did not provide a mathematical guarantee of statistical confidence in close races. Those three things are simultaneously true, and anyone who tells you only one of them is telling you a comfortable story.
The deeper problem: what "verified" actually means on a seven-second window
Here is the part that the court's ruling leaves genuinely open, and that is worth naming plainly.
The VVPAT slip appears behind a glass window for seven seconds. The voter watches it. Then it drops into a sealed box.
What the voter verified is that the slip printed correctly. They did not verify that the machine tabulated that slip correctly. The slip goes into a sealed box that is hand-counted only in the sampled stations.
In the United States, a federal court in Atlanta made a structurally similar observation in 2020. In Curling v. Raffensperger, reviewing Georgia's Dominion ballot-marking devices, the court found the system "does not provide a verifiable and auditable ballot record because it relies on the QR code for vote tabulation and that code itself cannot be read and verified by the voter." The paper printout existed. The tabulation artifact — the QR code — was not human-readable.
India's situation is different in architecture: the VVPAT slip is human-readable, and the tabulation happens on the EVM itself rather than being encoded in a barcode. But the structural question is the same: the artifact the voter verifies and the artifact that determines the count must be the same artifact, and the connection between them must be independently checkable.
The Indian court's new microcontroller-verification mechanism is a step toward making that connection checkable in disputed cases. It is not a general public verification mechanism available to any citizen as a matter of course.
That gap — between what a court can order as a remedy and what a system should provide as a default — is where the real design argument lives.
What a system built for verifiability would look like
The Indian ruling, the German constitutional standard, and the Dutch government's 2007 commission report (which returned the Netherlands to paper ballots on the explicit grounds that elections must be transparent and checkable) all point toward the same specification.
A trustworthy count requires:
- A human-readable, voter-verified physical record — not a seven-second window, but a durable artifact the voter confirms and the system retains.
- A public audit protocol that is statistically designed to catch wrong outcomes, sized to the margin, not to convenience.
- Hardware and software custody chains that are sealed, logged, and independently verifiable — not just by candidates who pay a fee, but as a matter of transparent public record.
- Instant, precinct-level publication of results in machine-readable formats that anyone can download and reconcile against the paper.
None of those four things requires abandoning electronic voting. India's court did not say abandon it. Germany's court did not say abandon it — it said make it checkable by ordinary citizens. The Dutch commission did not say technology is wrong — it said transparency and checkability are non-negotiable, and paper currently delivers them better.
The throughline across every jurisdiction is not a preference for paper over silicon. It is a demand that the system produce evidence the public can examine independently — evidence that does not ask anyone to trust the authority declaring the winner.
Brazil runs official public adversarial security tests on its urnas, inviting anyone whose test plan is approved to try to break the system. Los Angeles County built an open-source publicly owned tally system specifically so outsiders could inspect the code. Colorado designed its audit to deliver statistical confidence, not just optics.
None of those are "paper ballots are magic." All of them are "here is the evidence; come check it yourself."
What is still unresolved — and what would make it checkable
India's April 2024 ruling is a significant data point, not a settled conclusion.
Here is what remains genuinely open:
- The five-station VVPAT sample has not been shown to provide sufficient statistical confidence in a close constituency race. No Indian court or election authority has published a mathematical analysis demonstrating what false-outcome risk the current sample accepts.
- The microcontroller-verification mechanism is available only to candidates, only in disputed cases, only on payment, and only in 5% of EVMs. It is a legal remedy, not a transparent public audit.
- The SLU sealing requirement is a chain-of-custody improvement. Whether the seals are independently logged, who has custody of the logs, and how a discrepancy would be surfaced and adjudicated is not publicly specified in the judgment.
- The EVM software remains closed. No independent researcher has published a peer-reviewed security analysis of current Indian EVMs comparable to the Princeton team's 2006 analysis of the Diebold AccuVote-TS, or the Estonian i-voting analysis that identified undetectable manipulation risks.
What would make any of this independently checkable?
Publish the sample-size calculations. Publish the seal custody logs. Open the EVM firmware to independent cryptographic analysis. Require that every constituency's VVPAT slip count be published against its EVM total at the polling-station level, in a machine-readable format any citizen can download and verify.
The court moved the dial. The dial is not yet at "anyone can check."
That is not an accusation. It is a design specification — and it is the same specification Germany articulated in 2009, the same one Kenya's Supreme Court enforced in 2017 when it annulled a presidential election because the results chain could not be independently traced, and the same one that makes the difference between an election you can verify and an election you are asked to trust.
Trust is not the goal. Verifiability is. They are not the same thing.
See where this gap shows up in elections around the world · Read the two-minute version · Explore the full case archive
Sources
- Supreme Court of India — Association for Democratic Reforms v. Election Commission of India, 2024 INSC 341 (26 April 2024)
- Bundesverfassungsgericht, Judgment of 3 March 2009, 2 BvC 3/07 and 2 BvC 4/07 (English translation)
- U.S. GAO (GAO-08-97T) — Testing of Voting Systems in Florida's 13th Congressional District
- Curling v. Raffensperger, No. 1:17-cv-2989-AT, Opinion and Order (N.D. Ga. Oct. 11, 2020)
- Colorado Secretary of State — A new kind of election audit: Colorado is first to complete it
- Adviescommissie inrichting verkiezingsproces, 'Stemmen met vertrouwen', 27 September 2007
- Supreme Court of Kenya, Presidential Election Petition No. 1 of 2017 (Odinga v IEBC), Judgment of 20 September 2017