← Todos os artigos

Announcing a winner is not the same as proving the count

The EU's observers watched an entire presidential election conclude in the Democratic Republic of the Congo—and couldn't trace a single result back to its source. That's not a minor oversight. It's the whole problem.

It is the evening of November 28, 2011, and polling stations across the Democratic Republic of the Congo are closing. Millions of people have stood in lines that sometimes stretched for hours. They have cast ballots in a country the size of Western Europe, with roads that dissolve in the rainy season and a communications infrastructure that has never fully recovered from decades of war. The votes exist. Somewhere, in schools and churches and makeshift counting centers, stacks of paper represent what Congolese citizens chose.

Then the results arrive — and the European Union Election Observation Mission, which has deployed observers across the country at considerable expense and risk, cannot trace them back to anything.

Not to precinct-level forms that observers could inspect. Not to a verifiable chain from local tally to national total. Not to a functioning court where disputes could be tested in the open. The mission's final report would later conclude that the electoral commission lacked transparency in the local and national compilation and publication of provisional results, and that the absence of a functioning Constitutional Court meant result disputes were handled without adequate, transparent adjudication. Observers were even denied access to the relevant court decisions.

A winner was declared. But a declaration and a proof are not the same thing.


When a number appears without a source record, it isn't a result — it's an assertion

Think about what a result actually is. It is a chain of smaller numbers: the count at each polling station, collected and compiled into a district total, then a provincial total, then a national total. Each link in that chain has to be visible — documented in a form that an observer, a losing candidate, a citizen, or a journalist can pull up and check against the previous link.

When that chain is not published — when the compilation happens in a room observers cannot enter, or on a server that produces totals without showing its working — what gets announced is not a verified count. It is a claim about what the count was.

The difference between a result and an assertion is the paper trail anyone can follow.

This is not a radical standard. Kenya's constitution, by the time of its 2017 presidential election, explicitly required that voting be "verifiable, secure, accountable and transparent." When the results system failed that test — when not all polling-station forms were electronically transmitted as required, and the final tally bore no watermark or serial number — the Supreme Court annulled the result entirely. The chairperson had declared a winner before receiving all the underlying source documents. The Court's majority found that was not good enough, and ordered a fresh election. The judgment makes the reasoning plain: you cannot verify the total if you cannot check the forms it was built from.

In the DRC in 2011, the mechanism failed earlier and more completely. The chain from individual ballot to national declaration never became publicly visible at all. There was no Kenyan-style transmission protocol to check against. There was no court willing or able to adjudicate challenges in the open. And so the winner was whoever the electoral commission said it was — which is precisely what "no transparency" means in practice.


The problem is not unique to fragile states

It is tempting to read the DRC's 2011 experience as a story about a specific place at a specific level of institutional development — something that could not happen in countries with more resources and longer democratic traditions. That would be a comfort. It is not accurate.

In Malawi in 2019, a presidential election was voided because official result sheets had been altered with correction fluid. The tabulation happened on paper, in a country with functioning courts — but the source documents, the tally forms that should have been the immutable record of what each station counted, turned out to be mutable after all. The Supreme Court of Appeal's judgment held that this destroyed the verifiability of the announced result. Correction fluid on a tally sheet is the low-tech version of the same problem: a number presented as a count, with no reliable chain back to what was actually recorded.

In Venezuela in 2017, the company that built and operated the voting machines — Smartmatic — publicly stated it knew "without any doubt" that the officially announced turnout had been manipulated by at least a million votes. The company's statement described a situation in which even the system's operator could not reconcile the official total with what the machines recorded. With no independent audit trail, no one else could either.

These are not all the same failure mode. But they share an architecture: a process that produces an announced total without publishing the source records that would let anyone independently reconstruct — and therefore contest or confirm — how it was reached.


Source documents are not a bureaucratic formality. They are the proof.

When Germany's Federal Constitutional Court banned electronic voting machines in 2009, the court's reasoning was precise. It held that the essential steps of voting and counting must be examinable by citizens "without any specialist knowledge." The judgment was not about whether the machines had cheated. It was about whether anyone other than an expert could verify that they had not. A process whose correctness depends on trusting the machine's internal records is not a verifiable process.

The same logic applies to result compilation, not just to the machines that do the counting. If the compilation of totals happens in a room the public cannot see into, using records the public cannot read, verified by a court the public cannot access, then the announced total is no more independently checkable than the output of a closed voting machine.

The Dutch government reached the same conclusion about its own voting computers in 2007. Its election commission's final report — Stemmen met vertrouwen, Voting with Confidence — stated bluntly that "there are no secrets in the election process" and that questions about the count must be "answerable and the answers checkable and verifiable." The Netherlands went back to paper ballots counted by hand in public. Not because computers are evil, but because the count must be checkable.

A result that cannot be independently reconstructed from public source records is not a proven result. It is a claim made by whoever announced it.


The adjudication gap is as dangerous as the transparency gap

The EU Mission's finding about the DRC in 2011 had a second component that tends to get less attention: the absence of a functioning Constitutional Court to adjudicate disputes with transparency.

This matters for a specific reason. Even if results are published, disputes will arise. Some will be legitimate; some will be frivolous. The mechanism that distinguishes between them — the independent court or tribunal that examines evidence, hears argument, and publishes its reasoning — is itself part of the verifiability infrastructure.

When that mechanism is absent or inaccessible, a losing candidate has nowhere to go. And crucially, a winning candidate has no independent forum to prove the win was clean. Everyone is left trusting the authority that announced the result. That is not verification; it is deference.

Austria's Constitutional Court, when it annulled the 2016 presidential run-off, found that postal ballots had been handled by unauthorized persons before legally permitted, in numbers exceeding the winning margin. The court's decision found no evidence of fraud. But it annulled anyway, because the procedural chain of custody — the thing that would have made it possible to prove fraud had not happened — was broken. That is the standard an independent adjudicator should apply: not "did someone cheat?" but "can anyone prove they didn't?" When the answer is no, the result is unverifiable regardless of who won.

In the DRC in 2011, neither the source records nor the court were available to answer that question.


What "results transparency" actually requires

The phrase "results transparency" is sometimes used to mean publishing a final total on a website. That is a starting point, not the goal.

Real results transparency means a published, machine-readable record at every level of aggregation — polling station, district, province, national — with timestamps showing when each was entered and by whom. It means the underlying source forms (the paper or digital records from each counting location) are available to any observer who wants to check the arithmetic. It means the compilation process is conducted in the open, or at minimum in the presence of observers from all competing parties and independent monitors.

And it means an independent adjudicator who can — and must — publish its reasoning when a dispute is brought.

None of this requires extraordinary technology. What it requires is a commitment to the principle that the count belongs to the public, not to the authority conducting it. Kenya's court said this in 2017. Austria's court said it in 2016. Germany's said it in 2009. The Dutch commission said it in 2007. The EU Mission said it about the DRC in 2011.

The lesson is not complicated. Announcing a winner is one action. Proving the count is a different action, and it requires publicly visible source documents, a transparent compilation process, and an accessible independent adjudicator.

Skipping those steps and calling it an election is like filing a claim and calling it a verdict.


What would make it checkable — by anyone

Here is what a fully verifiable results process looks like, and what still falls short almost everywhere.

What works when it's present: Precinct-level result forms, signed by representatives of all parties, posted publicly before aggregation. Machine-readable export of every precinct total, downloadable in open formats, timestamped, with cumulative additions visible as they happen. (The U.S. Election Assistance Commission's own guidance urges exactly this, and some jurisdictions like Idaho already do it at the precinct level.) A risk-limiting audit or full hand count that checks machine totals against physical source ballots, as Colorado pioneered in 2017 and Georgia executed at scale in 2020. And a court or tribunal with the independence, access, and transparency to test disputed claims in public.

What still cannot be independently checked in most places: The software that compiles precinct totals into district and national figures. The chain of custody on digital transmission of results. The adjudication process when results are challenged behind closed doors. And — critically — whether the number a machine read from a ballot actually reflects what the voter marked, a gap the U.S. District Court in Curling v. Raffensperger identified when it found that Georgia's QR-code tabulation system produced a record voters cannot read and verify.

The DRC in 2011 failed at nearly every one of these points simultaneously. But failing at any single one of them leaves a gap that a bad actor — or honest error, or mechanical failure — can walk through silently.


The takeaway worth sharing

A government or electoral commission announcing a result is the beginning of a verification process, not the end of one. The announcement is a claim. What turns it into a proven result is the publicly visible chain from individual ballot to final total — source forms anyone can check, a compilation anyone can audit, a court anyone can watch.

"The results have been declared" and "the count has been proven" are not the same sentence. The distance between them is where elections are won and lost by manipulation, error, or the quiet absence of anyone who can check.

The technology to close that gap — machine-readable precinct-level reporting, tamper-evident source records, cryptographic audit trails — exists and is deployable now. What is missing in most places is not the tool. It is the commitment to treating verifiability as a non-negotiable requirement rather than an optional extra that officials can waive when it becomes inconvenient.

Until that changes, "we declared a winner" will keep being confused with "we proved the count." They are not the same thing. They have never been the same thing.

See how common this transparency gap is across elections worldwide →

Read the two-minute version of what verifiable results require →

Explore documented cases of results that couldn't be independently checked →


Sources