← All posts

A supreme court threw out a presidential election because no one could check the numbers

Kenya's Supreme Court didn't just overturn an election — it ruled that a result no one can independently trace from polling station to national tally is not a result at all.

It is the morning of September 1, 2017, and the Supreme Court of Kenya has just done something no court in African history had done before: thrown out a presidential election.

Not because of a coup. Not because of violence at the polls. Because the numbers could not be traced.

Raila Odinga had lost to incumbent Uhuru Kenyatta by roughly 1.4 million votes — a margin wide enough, you might think, to speak for itself. But the court didn't agree. By a 4-2 majority, it annulled the result entirely and ordered a fresh election within sixty days. The full reasons, issued on September 20, 2017, are worth sitting with. The court held that the Independent Electoral and Boundaries Commission had failed to meet the constitutional requirement that voting be simple, accurate, verifiable, secure, accountable and transparent. Not one of those words — every one of them.

The margin wasn't the point. The chain was.


The chain that broke

Kenya's system was, on paper, a model of modern election administration. Each of the country's roughly 40,000 polling stations was supposed to complete a Form 34A — a tamper-evident results sheet capturing the tally at that station. That form was supposed to be electronically and simultaneously transmitted to the national tallying centre, and a physical copy was supposed to travel up through constituency and county tiers on Forms 34B and 34C.

The idea was elegant: every number at the top should be reconstructable from the numbers at the bottom. Any citizen with access to the raw forms could, in principle, add them up and check the national total independently.

But the court found that not all Forms 34A had been transmitted as required by law. It found that the result forms lacked consistent security features. The final tally form — the document announcing who would be president — bore no watermark and no serial number. And the IEBC chairperson had declared Kenyatta the winner before all the underlying forms had even arrived.

Think about what that means physically. Somewhere in Nairobi, an official stood in front of cameras and announced the winner of a presidential election while a stack of forms — the very evidence on which that announcement rested — was still in transit. The top of the chain had been declared before the bottom of it was assembled.

That is not a count. That is an assertion.


Why the margin didn't save it

The most common objection you will hear to the Kenya ruling is: 1.4 million votes. If the fraud or error needed to flip the election would have required falsifying more than a million ballots, isn't the result obviously right regardless of the paperwork?

This is the wrong question. It is the question of a person who trusts the number. The court was asking a different question: how do we know what the number is?

An election result is not self-certifying. The announced total is only as reliable as the process that produced it. If the Forms 34A were not all transmitted, if security features were inconsistent, if the final tally document had no serial number — then the announced total is not a verified sum. It is a figure that emerged from an opaque process and was declared correct by the authority whose job it was to declare things correct.

This is the distinction that separates a trustworthy election from a trusting one. A trustworthy election lets you check. A trusting one asks you to believe.

The Kenyan court was not accusing the IEBC of fraud. It was saying something more fundamental: the process was not designed so that fraud was impossible to hide. And an election that cannot prove the absence of fraud is not, in any meaningful sense, proven.


This is not just an African story

Courts in other democracies have reached the same conclusion by a different route, and it is worth being precise about what connects them — because the connection is not about corruption, or developing democracies, or any of the comfortable othering we reach for when a story like Kenya's makes us uncomfortable.

In 2009, Germany's Federal Constitutional Court struck down the use of electronic voting machines in the 2005 Bundestag election. The machines stored votes in electronic memory with no independent record a voter could check. The court held that the essential steps of voting and of the determination of the result must be examinable by the citizen reliably and without any specialist knowledge. Not by experts. Not by the government. By the citizen. The machines failed that test, and the ordinance permitting them was declared unconstitutional.

In 2016, Austria's Constitutional Court annulled a presidential run-off — one with a margin of roughly 30,000 votes — not because fraud was found, but because the rules governing who could handle postal ballots and when had been broken in enough places that roughly 77,000 votes were affected. The court made its reasoning explicit: the safeguards against manipulation had been violated in numbers capable of affecting the result. Not that manipulation had happened. That it could not be ruled out.

Same logic. Different countries. Different technologies. The same fundamental requirement: a result no one can independently verify is not a result that can be trusted.

In Malawi in 2020, courts voided a presidential election after official tally sheets were found to have been altered with correction fluid — whiteout applied to the figures on documents that were supposed to be tamper-evident. If the source documents can be quietly rewritten, there is no source. The announced total becomes whatever the last person with a bottle of Tipp-Ex decided it should be.


What "verifiable" actually requires

These cases, read together, spell out a precise technical requirement that is easy to state and hard to meet.

Verifiability means three things simultaneously:

First, every vote must produce a durable, tamper-evident record at the point it is cast — a Form 34A, a paper ballot, a sealed box with a chain of custody.

Second, that record must be transmitted or transferred to the next level of aggregation in a way that is independently checkable — electronically and simultaneously, with consistent security features, not in a process that can be interrupted or altered between the polling station and the tally centre.

Third, the final total must be reconstructable from the source records by anyone — not by the election authority, not by a hired auditor, but by any person with the time and the data.

Kenya's system had the concept right. It required Forms 34A to be electronically and simultaneously transmitted precisely so that the public could check the arithmetic. What it lacked was enforcement of that requirement, and — critically — a technical architecture that made non-compliance visible in real time rather than discoverable only in court weeks later.

That gap is the story.


The gap between design and verification

Here is the harder version of this argument, the one that goes beyond Kenya.

A results-transmission system that works correctly produces numbers anyone can verify. A results-transmission system that fails silently — or that can be bypassed by an official who declares the winner before all the forms arrive — produces numbers that look identical but aren't checkable.

From the outside, you cannot tell which one you are looking at.

This is why "the election authority says the results are correct" cannot be the end of the analysis. The IEBC said the results were correct. The Kenyan Supreme Court found it could not verify that claim from the underlying documents. Not because it found fraud — the court did not find fraud. Because the documents that should have made the claim checkable were missing, inconsistent, or arrived after the fact.

The same logic applies every time an official or a press release tells you an audit confirmed the result. An audit that audits a transmission chain that was already broken is not an audit of the election — it is a review of whatever made it to the tally centre. Whether that is all of the votes, or most of them, or a curated selection, is exactly what the chain of custody is supposed to prove.

Brazil offers a counterpoint worth noting: its election authority runs an annual public adversarial test of its voting machines, inviting any qualified citizen to try to break the system before real ballots are at stake. That is not a press release. That is a structural commitment to scrutiny by outsiders. The gap between that approach and "we declare the results certified" is the gap between verifiability and trust.


What would have made Kenya's result checkable

The Kenyan system's design was not wrong. The constitutional requirement — simultaneous electronic transmission of Forms 34A from every polling station — was exactly the right idea. What was missing was the public enforceability of that requirement.

Imagine instead a system where every Form 34A, the moment it is signed and scanned at a polling station, is published to a public, append-only log — timestamped, cryptographically hashed, and available for download. Any candidate's agent, any journalist, any voter with a laptop can sum those forms continuously as they arrive. The moment the published national total diverges from the sum of the published forms, the discrepancy is visible to everyone simultaneously.

In that architecture, the chairperson cannot declare a winner before all the forms arrive — because the declaration and the underlying evidence are both public and one is provably inconsistent with the other. The problem the Kenyan court had to reconstruct after weeks of litigation would have been visible in real time to anyone with a spreadsheet.

This is not a fantasy. Precinct-level, machine-readable results are already published in real time in a number of democracies. The U.S. Election Assistance Commission's own guidance urges officials to make results downloadable in common formats so they can be independently reconciled. The architecture exists. What varies is whether any given jurisdiction has committed to it.


The takeaway no official will put in a press release

The Kenyan Supreme Court's ruling is, at bottom, a judicial articulation of a principle that every election system should be built around from day one: a result no one can independently check is not a result — it is an announcement.

The difference between an announcement and a result is verifiability. Not the assurance of verifiability. Not the claimed existence of an audit trail. Actual, public, independently checkable verifiability: source documents that are tamper-evident by design, transmitted in a way that makes non-transmission immediately visible, and published in a form that any person can use to reconstruct the total without asking for permission.

Two justices dissented in the Kenyan case, finding the evidentiary burden had not been met. That dissent is not irrelevant — it tells you how close the court came to accepting the official result on faith rather than insisting it be proven. In a different court, on a different day, with a different evidentiary standard, the same unverifiable process might have been waved through.

That is the version of this story that should keep you up at night. Not the case where the court caught it.

The version where nobody did.


What is still not checkable: whether your own country's results-transmission architecture would survive the test the Kenyan court applied. Does every polling station's result produce a public, timestamped, cryptographically tamper-evident record the moment it is compiled? Can any citizen independently sum those records and reproduce the national total? If you cannot answer yes to both, the architecture is asking you to trust — not to verify.

See how common this gap is across the world · Read the 2-minute version · Explore this specific gap


Sources