← All posts

'Verifiable' is a word politicians love. Here's what it actually has to mean.

Kenya's Supreme Court annulled a presidential election not because fraud was proven, but because no one—not a judge, not a journalist, not an ordinary voter—could independently check how the result was built.

It is the morning of September 1, 2017, and six judges in Nairobi have just split four to two on a question that will echo in courtrooms from Malawi to Germany to your living room: when you cannot trace a vote from the polling station to the national tally, do you have an election at all?

The declared winner of Kenya's August 8 presidential election was Uhuru Kenyatta, with about 54 percent of the vote. But the Supreme Court didn't throw out the result because the numbers were wrong. It threw out the result because no one could check whether the numbers were right. Form 34A — the polling-station-level result sheet that the constitution required to be electronically transmitted to the national tallying center — had not all arrived as required. The final tally form bore no watermark, no serial number. The chairperson of the electoral commission had declared a winner before receiving all the underlying documents. The chain from individual ballot to national total had broken links, and in a constitutional democracy, broken links are not a technical inconvenience. They are the whole problem.

"The election was not conducted in compliance with the Constitution," the majority wrote in its full reasons, issued September 20. The requirement: that voting be simple, accurate, verifiable, secure, accountable and transparent. Not trusting. Not certified. Verifiable.

That word — verifiable — is doing enormous work in that sentence. Politicians use it constantly, and almost never define it. Courts, it turns out, have to.


What a court means by 'verifiable'

The Kenyan Supreme Court was interpreting Article 86 of Kenya's constitution, which sets out those six properties as requirements — not aspirations, requirements. But the judgment's deeper contribution is what it implies about the word's content.

Verifiable is not the same as verified by someone you trust. It is not the same as our auditors checked it. It means: any person, not just an expert, can trace the essential steps — from the ballot in the box to the number on the tally — and confirm they match. An unbroken, independently checkable chain. Each link public, documented, tamper-evident.

The Kenyan system failed on multiple links simultaneously. Forms weren't transmitted as required. Forms that arrived lacked consistent security features. The final aggregation happened before the source documents it was supposed to reflect had been received. None of this means votes were stolen. The Court explicitly did not find that fraud occurred. But the structure of the count made fraud undetectable — and an undetectable error is indistinguishable from an undetectable fraud. That is the point.

A fresh election was ordered within 60 days. The runner-up, Raila Odinga, boycotted it. Kenyatta won again. Whether the underlying vote in August 2017 was accurate we genuinely do not know — and that is precisely the problem the Court named.


The German formulation: no specialist knowledge required

Four months before the Kenyan election was even held, a court on the other side of the world had drawn the same line, more sharply.

On March 3, 2009, the German Federal Constitutional Court invalidated the use of Nedap electronic voting machines in the 2005 federal election. The machines had been widely used. They had been certified. No one had found evidence of tampering. None of that mattered.

The Court's reasoning is worth memorizing word for word: the essential steps of voting and of the determination of the result must be examinable by the citizen reliably and without any specialist knowledge of the subject. This flows from the principle of the public nature of elections embedded in the Basic Law — the German constitution's foundational democratic requirement.

The machines stored votes only in electronic memory. No independent record existed that a voter could verify. No ordinary person could check the transition from "I pressed this button" to "this number appeared in the total." The Court called this a constitutional defect, full stop. It declined to annul the 2005 result — the election had happened, there was no evidence of malfunction, and the Court weighed that against the disruption of unseating a parliament — but it banned the machines going forward.

Two courts, two continents, two constitutional traditions. The same definition of verifiable. The chain from ballot to total must be checkable, by anyone, without needing to trust a technician's word for it.


What 'verifiable' is not

Here is where the concept gets sharpened by what it excludes.

It is not "we counted it by hand." A hand count is a useful check, but it is not self-verifying. In Antrim County, Michigan, in 2020, election workers conducted a full hand audit of every presidential ballot after a machine-count error attracted scrutiny. The hand count differed from the corrected machine tabulation by about a dozen votes out of roughly 15,700 cast. Twelve votes. That is irreducible human error in a manual process — fatigue, judgment calls on ambiguous marks, a ballot briefly misplaced in the wrong pile. In a race decided by a handful of votes, a method that is itself off by a handful of votes cannot settle the question. "The hand count confirmed it" is a reassurance. It is not a proof.

It is not "we certified the system." Ireland bought a national e-voting system — Nedap/Powervote machines, 7,500 of them — and an independent commission concluded it simply could not recommend deployment with the "requisite degree of confidence." Not because fraud was found. Because accuracy and secrecy had not been proven to the commission's satisfaction. The machines sat in a warehouse for five years, then were scrapped. Certification is a claim. The commission's job was to test the claim. The claim failed.

It is not "a senior official said it was fine." In Venezuela in August 2017, Smartmatic — the company that had built and run the country's voting infrastructure for over a decade — issued a public statement saying it knew "without any doubt" that the announced turnout in the July 30 National Constituent Assembly election had been manipulated, differing from actual participation by at least a million votes. The official result had been declared. The vendor itself disowned it. When the people who built the machine cannot reconcile what the machine recorded with what was announced, and no independent check exists, there is nothing left for the public to stand on.

It is not even "our cryptographic proof is published." Swiss Post and its vendor Scytl published the full source code of their internet-voting system in 2019 precisely as a transparency gesture. Independent researchers Sarah Jamie Lewis, Olivier Pereira, and Vanessa Teague read the code and found a trapdoor in the mixnet's shuffle proof: someone who knew the trapdoor values could generate a verification transcript that passed every check while having silently altered votes. Swiss authorities suspended the system. The proof looked valid. The flaw was invisible until outside cryptographers with no stake in the result went looking for it. A verifiability claim is only meaningful if it survives adversarial outside scrutiny.


The five links in the chain

If 'verifiable by any ordinary person' is the constitutional standard, what does it actually require in practice? The Kenya case, read against the Germany case and the accumulating evidence from a dozen other countries, suggests five specific links that must all hold.

One: a tamper-evident record at the point of voting. The ballot — paper or its equivalent — must capture the voter's intent in a form neither the machine nor any subsequent handler can alter without detection. The QR-code ballot-marking devices reviewed in Curling v. Raffensperger in Georgia illustrate the failure mode: a federal court found the system "does not provide a verifiable and auditable ballot record because it relies on the QR code for vote tabulation and that code itself cannot be read and verified by the voter." The thing that gets counted must be the thing the voter can inspect. Those have to be the same artifact.

Two: a documented, signed chain of custody. In Austria's 2016 presidential run-off, postal ballots were opened and counted prematurely, by unauthorized people, without required witnesses. The Austrian Constitutional Court annulled the result — 77,000 affected votes exceeded the 30,000-vote margin — even though it found no evidence of fraud. The procedural chain existed precisely to make manipulation detectable. Once the chain is broken, you cannot distinguish a procedural irregularity from a covered-up fraud. The result becomes legally indefensible not because it is wrong but because it is unverifiable.

Three: a public record at every aggregation step. In Kenya, the constitutional requirement was real-time electronic transmission of Form 34A from every polling station. That requirement existed specifically so that anyone — a journalist, a party agent, a private citizen — could compare the bottom-up sum with the top-down announcement. When that doesn't happen, the national total floats free of its source documents. In Malawi in 2019, electoral officials used correction fluid on official tally sheets before entering them into the count. The Constitutional Court nullified the election. You cannot verify a number that someone has already erased and rewritten. Tamper-evident source records are not bureaucratic pedantry; they are the evidence base that any subsequent audit depends on.

Four: independent audit with statistical teeth. A check by the same institution that produced the number is not independent. Colorado, in 2017, ran the first statewide risk-limiting audit in the United States — a procedure that examines enough hand-counted paper ballots to give a mathematically defined confidence level that the machine total is correct. It works only because durable paper ballots exist and can be physically compared against machine output. The audit's logic is adversarial: it is designed to catch a wrong outcome with high probability, not to rubber-stamp the announced winner. That is what an independent check looks like.

Five: results published at the lowest level, instantly, in machine-readable form. The Kenyan constitution's Form 34A requirement was the right idea for this reason: bottom-up transparency at the polling-station level makes aggregation errors immediately visible, because anyone can add up the forms and compare. The U.S. Election Assistance Commission urges officials to publish precinct-level results in downloadable machine-readable formats so citizens can reconcile the count themselves. That is verifiability made practical — not "we posted a PDF," but "here is the raw data; check our arithmetic."

All five links must hold. One broken link is enough to make the chain unverifiable. Kenya's chain broke at links three and five simultaneously. Austria's broke at link two. Malawi's broke at link three. That is why results announced confidently in all three cases were still legally unsound.


Trust is not the same as verifiability — and the difference matters

There is a version of this argument that feels uncomfortable, because it seems to cast doubt on elections that most observers believe were honestly run. That discomfort is worth sitting with.

The point is not that Kenya 2017 or Austria 2016 were fraudulent. Courts in both cases declined to find fraud. The point is that an honest result produced by an unverifiable process is indistinguishable, to the public, from a dishonest result produced by the same process. Trust that happens to be warranted is still trust. It is not verifiability. And trust — in officials, in vendors, in a Secretary of State's press release — is exactly what coercion, corruption, and sophisticated technical manipulation exploit.

The Netherlands understood this in 2007 when its advisory commission published a report called "Voting with Confidence" and then recommended abandoning electronic voting. Its logic: there are "no secrets in the election process," and "questions must be answerable and the answers checkable and verifiable." It returned to paper and hand counts — not because the machines were proven compromised, but because transparency and checkability were treated as non-negotiable, regardless of how trustworthy the current operators happened to be.

That is the architecture worth building toward. Not systems you trust. Systems you can check. Systems whose results anyone can verify independently, without needing access to proprietary code, classified logs, or a vendor's assurances. Where the proof is public, adversarially tested, and does not depend on believing the person who produced it.

Because the next government may not be as honest as this one. The next vendor may not be as careful. The next election may not be decided by a margin obvious enough to catch an error. The constitutional requirement is not "verifiable when we're paying close attention." It is verifiable by design, by anyone, as a matter of course.


What is still not checkable — and what would make it so

Here is what the Kenya ruling, the Germany ruling, and the full body of evidence above leave unresolved:

In most democracies, you still cannot, as an ordinary citizen, independently confirm that the number reported from your polling station matches what was recorded in the machine. You cannot verify that the aggregation from station to precinct to county to national total was done correctly. You cannot check whether the software that tabulated your ballot contains the code that was certified, or a later version that does not. You cannot compare the QR code on your ballot-marked paper with the human-readable text you thought you were choosing — because the scanner reads the barcode, not the text.

These are not hypothetical gaps. Courts have named them. Researchers have exploited them. Election authorities have, in some cases, fixed them — and in many cases have not.

What would make them checkable? Published, signed, polling-station-level results the moment they are final. Voter-marked paper ballots whose human-readable text is what gets scanned. Open-source tabulation software that independent experts can read, test, and re-test — not once at certification, but continuously. Routine, adversarial, public audits tied to a stated confidence level, not a fixed percentage. And a chain of custody documented at every step, with tamper-evident seals that can be physically inspected after the fact by anyone with standing to look.

None of that requires trusting a government, a vendor, or a Secretary of State. That is the point.

An election result you cannot independently verify is not, in the constitutional sense, a result at all. It is an announcement.

See where this gap appears across the world →

Read the two-minute version →

Explore specific country cases →


Sources