A mayor removed from office: the postal-vote case that shook London
An English judge removed a sitting mayor from office for postal-vote fraud, bribery, and personation — and the case exposes exactly why voting outside a polling booth is the hardest problem in election security.
It is the morning of 23 April 2015, and in a courtroom in London, a judge is reading out a verdict that has not happened in British politics in living memory. Lutfur Rahman — the executive Mayor of the London Borough of Tower Hamlets, elected in May 2014 by more than 18,000 voters — is being removed from office. Not by an election. Not by a parliamentary vote. By a court.
The judgment in Erlam & Ors v Rahman & Anor [2015] EWHC 1215 (QB) runs to hundreds of paragraphs. Commissioner Richard Mawrey QC, sitting as an Election Court under the Representation of the People Act 1983, found the election tainted by corrupt and illegal practices committed by the Mayor personally and through his agents. The list is remarkable: personation, postal-vote fraud, bribery, treating, false statements, and undue spiritual influence — together with general corruption so extensively prevailing that it could reasonably be supposed to have affected the result.
Rahman was removed. The election was voided. A new vote was held.
And buried inside the judgment, if you read it carefully, is a lesson that has nothing to do with one borough in east London — and everything to do with how any democracy handles ballots that travel through the post.
The polling booth was built to solve exactly this problem
It helps to start from first principles.
The secret ballot — the envelope, the private booth, the unmarked paper — was not invented as a nicety. It was a security system. When Victoria came to the throne, voting in Britain was public: your choice was called aloud, written in a book, and the book was published. Landlords watched. Employers watched. Creditors watched. If you voted the wrong way, you knew what came next. The Ballot Act 1872 ended that. It replaced open voting with a sealed box and a private compartment — not to protect your feelings, but to destroy the coercer's ability to verify the transaction.
The mechanism is precise. A vote that cannot be observed or proven cannot be bought or coerced, because the buyer cannot confirm delivery. The whole market collapses when verification fails.
In-person voting at a supervised polling station preserves this guarantee. A stranger cannot stand over your shoulder as you mark your ballot. A party operative cannot collect your paper and check it before it goes in the box. The chain of custody — blank ballot in, sealed box out, opened in public at the count — makes personation difficult and manipulation auditable.
Now take the ballot out of that controlled environment. Post it to a home address. Let it sit on a kitchen table. And immediately the guarantee fractures in two separate places: who actually marked it, and who handled it before it arrived.
This is not a hypothetical concern. Tower Hamlets is the case study.
What the election court actually found
The Tower Hamlets judgment is worth reading in full — not for the political drama, but for the operational specificity. The court did not find that a computer was hacked or that the count was miscalculated. It found that the election was corrupted during the period before and during polling, through the mechanisms that remote voting uniquely enables.
Personation — casting someone else's vote — is extremely difficult at a supervised polling station. It is considerably easier when a ballot paper has been delivered to an address by post and the identity of the person marking it is verified by nothing more than a signature and date of birth on an envelope.
Postal-vote fraud, as found in the Tower Hamlets case, is the exploitation of that gap. The sealed environment of the polling booth is replaced by a private residence (or anywhere else a ballot might travel), and the chain of custody that the Ballot Act built — blank paper, private booth, sealed box, public count — is replaced by a paper trail that passes through hands the court cannot see and was not designed to watch.
The attack surface for remote voting is not the count. It is the custody.
North Carolina: the same mechanism, a different continent
Tower Hamlets is not an isolated curiosity. Consider what happened in North Carolina's 9th Congressional District in 2018.
After the election, the State Board of Elections declined to certify the apparent result. It investigated irregularities with mail-in absentee ballots. On 21 February 2019, the Board unanimously ordered a new election, finding what it called a "coordinated, unlawful and substantially resourced absentee ballot scheme" in Bladen and Robeson counties. The operative at the centre, McCrae Dowless, was later indicted on felony charges.
The mechanism was the same as Tower Hamlets, translated across an ocean and a different legal system: third parties collecting, handling, and in some cases altering other people's mail ballots. The ballot had left the controlled environment of the polling place, and without robust chain-of-custody checks, it became possible to interfere with it between the voter's hand and the sealed box.
In both cases, the only remedy was to void the election and run it again. There is no way to un-corrupt a ballot that has already been tampered with and counted. You cannot subtract fraud from a result; you can only start over.
Austria: what chain-of-custody means in practice
Here is a version of the same problem where no fraud was found at all — and the election was still annulled.
In the spring of 2016, Austria held a presidential run-off between Alexander Van der Bellen and Norbert Hofer. Van der Bellen won by roughly 30,000 votes out of nearly 4.6 million cast. Hofer's party challenged the result. On 1 July 2016, the Austrian Constitutional Court annulled the entire election — not because fraud was proven, but because postal-ballot handling rules had been broken.
The law required that absentee ballots be opened and counted only after 9 a.m. on the day after the election, by the district electoral authority, with required board members and witnesses present. In multiple districts, that did not happen. Envelopes were opened early, by unauthorised people, without witnesses. Roughly 77,000 votes were affected — a number exceeding the winning margin of approximately 30,000.
The court's logic was exact: the rules on who may handle ballots and when are not bureaucratic formalities. They are the mechanism that makes the result independently verifiable. When they are violated, even honestly, the chain of custody is broken. You cannot prove manipulation did not occur in the time and space where the safeguards were absent. A repeat run-off was held in December 2016.
The lesson is uncomfortable because it applies even when everyone is acting in good faith. The Austrian officials were not accused of fraud. They were accused of making the result impossible to verify. In a close election, that is enough.
Why postal voting is structurally different
Think concretely about what happens at a polling station. You walk in. Your name is checked against a register. You receive a ballot — one ballot, for you. You take it to a private booth. You mark it, fold it, and drop it in a sealed box. Nobody saw what you wrote. Nobody handed you a pre-marked paper. Nobody watched you leave.
Now think about what happens with a postal ballot. A paper arrives in the post, addressed to a name. Anyone in the household can open the envelope. There is no supervision of who marks it. A party agent can sit at the table. A family member can stand over the shoulder. A community leader can collect the form. The identity check — typically a signature and a date of birth — is checked only later, after the envelope is returned, and is checked against a record that was compiled before the election.
The identity check is retrospective. The opportunity for influence is contemporaneous.
This is not an argument against postal voting as such. It is an argument for understanding exactly what postal voting requires that polling-place voting does not: robust identity verification at the point of application, tamper-evident sealed custody from the moment the ballot leaves the voter's hand, and an auditable record of every step in between.
Without those things, the Ballot Act's protection evaporates. The vote can be observed. The vote can be coerced. The vote can be replaced.
The deeper problem: when verification stops being possible
The Tower Hamlets and North Carolina cases were caught. A court investigated, heard evidence, and voided the results. That is the system working — slowly, expensively, and only after the damage was done.
But the mechanism of detection depended on the fraud being substantial enough to generate evidence: witnesses, patterns in the data, testimony from people who saw what happened. Small-scale postal-vote fraud, conducted carefully across a large number of ballots, might leave no such signature.
This is the gap that matters for election integrity broadly. Not the dramatic case that ends in a courtroom, but the quiet manipulation that never reaches one.
Consider the Austrian case again. The court found procedural violations and annulled the election. But the court also found no evidence of actual fraud. The problem was that it could not disprove fraud, because the conditions that would make fraud detectable — a complete, witnessed, timestamped chain of custody — had been broken. A rigorous chain of custody does not just detect manipulation. It makes manipulation impossible to conceal, which is why the chain exists.
The same logic applies to any remote-voting system. The question is not simply "was fraud committed?" The question is "is the system designed so that fraud, if committed, would leave a detectable, independently verifiable trace?"
If the answer is no — if the only people who can confirm the integrity of the postal ballot are the officials handling the ballots themselves — then "no fraud was found" is a reassurance, not a proof. And in a system built on trust rather than verifiability, the incentive to manipulate is never truly removed. It is only hoped not to be acted on.
What "verifiable custody" would actually look like
This is where the argument turns from diagnosis to architecture.
The postal ballot's chain-of-custody problem has a known shape. The solution has a known shape too — it just requires building it deliberately, rather than assuming it exists.
Verifiable custody of a remote ballot requires three things that currently exist only in fragments:
First, identity verification at the point of ballot receipt, not just application. Checking a signature retrospectively against a database is a weak control. Cryptographic verification tied to a unique, voter-held credential — issued before the election and usable once — would make personation structurally difficult rather than merely illegal.
Second, a tamper-evident chain from the moment the voter marks the paper to the moment it is counted. This means sealed, logged custody at every transfer point, with an auditable record that any independent party could check against the count — not a record that only officials can access.
Third, a result that anyone can verify without trusting the official who declares it. The German Constitutional Court put the principle in constitutional terms when it struck down electronic voting computers in 2009: essential steps in the voting and the determination of the result must be examinable by the citizen reliably and without specialist knowledge. That standard applies just as sharply to postal voting. A result whose chain of custody only officials can reconstruct fails it.
None of this requires abandoning remote voting. It requires building the infrastructure that remote voting lacks by default — the same infrastructure the polling station provides physically and procedurally.
The question the officials cannot answer for you
On 23 April 2015, after the Tower Hamlets judgment, a mayor was removed. A new election was ordered. Observers said the system had worked.
And in a narrow sense, it had. The fraud was caught. The result was voided. Democracy corrected itself.
But here is what the official account cannot tell you: how much of the postal-vote fraud was not caught? The court found what the evidence before it supported. It found the corruption was extensive enough to void the election. It did not — could not — reconstruct every manipulated ballot, every personated vote, every collected envelope. Courts work with what reaches them.
The cases that reach courts are the ones that generate enough evidence to bring. The cases that never reach courts are invisible by definition.
This is the argument for building verifiability into the system before the election, not relying on litigation to reconstruct it after. A postal ballot whose custody is cryptographically logged, whose identity check is independently auditable, and whose place in the count any citizen can verify without calling a solicitor — that ballot does not require you to trust the election official who handled it, or the court that retrospectively reviewed the process, or the Secretary of State who says everything was fine.
It requires you to check the record. And the record is there.
That is what we build. See how common the custody gap is across the world — or read the two-minute version of this problem.
Sources
- Election Court judgment — Erlam & Ors v Rahman & Anor [2015] EWHC 1215 (QB) (BAILII)
- NC State Board of Elections — State Board Unanimously Orders New Election in 9th Congressional District
- Verfassungsgerichtshof, Decision W I 6/2016-125, 1 July 2016 (official English translation)
- UK primary legislation — Ballot Act 1872 (35 & 36 Vict. c. 33), legislation.gov.uk
- Bundesverfassungsgericht, Judgment of 3 March 2009, 2 BvC 3/07 and 2 BvC 4/07 (English translation)