← Todos os artigos

From your precinct to the TV chyron: the fragile pipeline behind election-night numbers

Your vote travels through a dozen hands and three different systems before it becomes a number on TV — and at least one of those handoffs has already brought down a presidential election.

It is the evening of August 8, 2017, and Kenya's national tallying centre is filling up with numbers. Polling stations across the country have closed. Presiding officers have counted ballots by hand, filled out a pink form called Form 34A, photographed it, and transmitted the image electronically to Nairobi. The law is explicit: every individual form must arrive this way, simultaneously, before the chairperson of the Independent Electoral and Boundaries Commission may declare a winner.

The numbers keep arriving. The chairperson announces a result. Incumbent Uhuru Kenyatta has won, he says, with 54.27 percent of the vote.

Twenty-four days later, the Supreme Court of Kenya threw the whole thing out.


The transmission that wasn't

The court's judgment in Raila Odinga & another v IEBC — Presidential Election Petition No. 1 of 2017, decided by a 4-2 majority on September 1 and explained in full on September 20, 2017 — identified a specific, concrete failure in the pipeline. Not all Forms 34A had been electronically and simultaneously transmitted to the national tallying centre as the law required. Result forms lacked consistent security features. The final national tally form bore no watermark or serial number. And the chairperson had announced the winner before he had even received all the underlying source documents.

No court found that the tallies were fabricated. No court found that votes were stolen inside the polling stations. What the court found was something structurally more revealing: the chain of custody between the local count and the national total had broken in enough places that the final number could not be independently verified against the raw evidence.

When you cannot check whether the number on the screen is the same number that came out of the polling stations, the number on the screen is not a result. It is an assertion.

The court ordered a new election within 60 days. Read the full judgment.


Count the hands before the chyron

Most people think of an election result as a single event: ballots go in, numbers come out, a winner is announced. The reality is a relay race with seven or eight distinct legs, each one a potential point of failure.

Here is what actually happens between your vote and the number that appears on television.

Leg 1: You mark a ballot. It goes into a box.

Leg 2: At close of polls, workers count those ballots by hand or run them through a scanner. The precinct total is written on a results tape or a paper form. A copy is often posted on the polling-station door.

Leg 3: That form is transported — physically or digitally — to a county canvassing office. In many systems, a human types the numbers into a computer. This is where Antrim County, Michigan, tripped in 2020: after a last-minute change to a local race, some tabulators were not correctly reprogrammed, and the unofficial compilation was wrong. The error was caught only because the result was so implausible — Biden winning one of Michigan's most reliably Republican counties — that it drew immediate scrutiny. A subtler error in a closer county might not have. And when Antrim conducted its hand audit in December, the final hand count still differed from the machine tabulation by about a dozen votes out of roughly 15,700 cast. Caught error, yes. Proof of perfection, no.

Leg 4: County totals are uploaded to a state results system. In many U.S. states, this is done over a network connection using removable media — a USB drive, a memory card, a laptop carried into a parking lot. Each handoff is a point at which a transcription error, a software misconfiguration, or a communication failure can insert a discrepancy.

Leg 5: The state results system compiles and publishes unofficial totals. These are what you see on election night. The U.S. Election Assistance Commission is explicit: election-night results are unofficial and never final. They change as mail, provisional, and overseas ballots are counted and the canvass is completed.

Leg 6: A canvass cross-checks the totals against source documents. This can take days or weeks.

Leg 7: Certification. Only now is the result official.

Leg 8, if required: An audit samples physical ballots against the tabulated result to give statistical confidence that Legs 2 through 4 did not introduce errors large enough to change the outcome.

That is at least eight handoffs, each one a place where an honest mistake, a software bug, or a deliberate alteration can insert a number that nobody will catch unless someone goes back to the source.


What Kenya and Antrim share

They are separated by 8,000 miles, a different legal system, and a different scale of election. But the structural problem is identical: a result that cannot be traced back, step by step, to tamper-evident source documents that anyone can independently check.

In Kenya, the source documents — the pink Form 34As — existed and were legally required to be transmitted. The transmission failed or was incomplete. Without the ability to compare the national total to the individual forms, the court could not determine whether the announced result reflected what actually happened in the polling stations.

In Antrim, the source documents existed — the printed tabulator tapes — and they did not match the published totals. The mismatch was visible, but only because someone went looking. Nothing in the system automatically raised an alarm before the wrong numbers were posted.

In both cases, the failure is not in the counting. It is in the compilation and transmission pipeline: the unglamorous infrastructure that connects the local count to the published result. That pipeline is the least-watched part of the process and, precisely because it is unwatched, the most vulnerable to both error and manipulation.


The clock at 2 a.m.

There is a common misconception that slow results are a sign of something going wrong. They are not. They are frequently a sign of the law working as designed.

Six U.S. states — Alabama, Mississippi, New Hampshire, Pennsylvania, West Virginia, and Wisconsin — may not begin processing mail ballots until Election Day. No state may release mail-ballot results before polls close. When an election ends with millions of unprocessed mail ballots, the official count takes days not because anything is being hidden, but because the law creates a physical bottleneck at midnight.

This is not a defense of opacity.

It is an argument that the bottleneck needs to be visible. If you want the public to accept that a result changing over several days reflects legitimate counting under the rules — and not the quiet insertion of false numbers into the pipeline — the answer is not to ask people to trust officials and wait. The answer is to publish every precinct's results the moment they are final, in a machine-readable format anyone can download, verify, and reconcile against the state total themselves.

The EAC's own guidance urges officials to make results downloadable in common formats like .csv and .xml and to specify which ballot types each report includes. Idaho's official portal already publishes precinct-level results with downloadable raw data. The NCSL reports that most states already report at the precinct level.

Most states. Not all. And "reports at the precinct level" does not mean "publishes machine-readable files the moment results are certified." There is a wide gap between a PDF you can read and a .csv you can audit.


The pipeline is only as strong as its weakest handoff

Consider what it would take to introduce a wrong number at Leg 4 — the upload from county to state — in a way that a standard canvass would not catch.

The canvass compares the total reported by each county to the county's own records. If the upload introduces an error that is internally consistent with a doctored county record, the canvass finds nothing. The error propagates to certification. It gets announced as the result.

This is not a hypothetical attack vector. This is the exact structure that Kenya's Supreme Court identified as a live weakness. The Forms 34A were supposed to make the pipeline auditable: a photographed, transmitted source document at each polling station that any observer could, in principle, compare to the national total. When those transmissions were incomplete or inconsistent, the auditing function collapsed.

The fix is not better officials. The fix is a system that publishes the source documents — precinct by precinct, in machine-readable form, with a cryptographic timestamp — the moment they are finalized. Any journalist, any candidate's observer, any independent researcher can then reconstruct the national total from the precinct-level files and compare it to the announced result. If they match, the pipeline is verified. If they don't, the discrepancy is visible to everyone simultaneously, not just to an official who may or may not choose to investigate.

Germany's Federal Constitutional Court put this principle into constitutional doctrine in 2009: voting is legitimate only when ordinary citizens, without specialist knowledge, can independently examine the essential steps of the count. The German judgment was about voting machines. The principle applies with equal force to the transmission and compilation pipeline.


The audit doesn't fix a broken pipeline

Risk-limiting audits — Colorado ran the first statewide one in 2017 — are a powerful tool for confirming that a machine count is accurate. Georgia's 2020 statewide hand count of roughly 5 million ballots confirmed the machine tally to within about a tenth of one percent.

But an audit is only as useful as the records it audits against.

If the pipeline between the polling station and the audit sample is opaque — if there is no independently verifiable record linking each physical ballot to a precinct total to a county total to a state total — then an audit confirms the internal consistency of the system rather than its connection to the ballots voters actually cast. It checks whether the total matches the sample. It cannot check whether the total was correctly assembled from the precincts in the first place.

In Kenya, an audit of the nationally announced result against a sample of precincts would have confirmed nothing, because the pipeline between those precincts and the national total was the part that had broken.

A trustworthy system needs both: paper records that survive as physical evidence of voter intent, and a transmission and compilation pipeline that is so transparent that anyone can verify each step without trusting the officials who ran it.

Those two things are not substitutes for each other. They are both required.


What would actually make this checkable

Here is what an independently verifiable pipeline looks like.

The moment a precinct completes its count, it publishes a signed results file — precinct name, ballot type, candidate totals, timestamp, cryptographic signature — to a public repository. The file is human-readable and machine-parsable. The signature makes it tamper-evident: any change to the file breaks the signature, which any member of the public can verify with free tools.

County and state totals are computed from those files, not entered manually. The arithmetic is public. Anyone can check the addition.

The paper ballots remain as a fallback: if a precinct's electronic results are disputed, the physical ballots are there to count again, and the hand count can be compared to the signed file.

This is not a utopian design. The EAC already asks officials to publish .csv and .xml. Cryptographic signing of government files is routine technology. The gap is political will and standardization, not technical capability.

Until that gap closes, every election night involves trusting a pipeline whose most critical handoffs — the compilation and upload stages — are invisible to everyone except the officials running them.

Kenya's Supreme Court found out the hard way what happens when that trust is misplaced. The court could order a new election. Nobody can give Kenyans back the weeks of uncertainty, the violence, or the legal cost of discovering that the pipeline had broken.

The people who designed that pipeline trusted that the forms would arrive. They didn't build a system that proved it.

That is the difference between trust and verifiability. Trust requires nothing of the system. Verifiability requires the system to prove itself, to anyone, at any time, without asking for permission.

One of those is an election you can defend in court. The other is an election you can only defend by asking people to take your word for it.


The gaps in results transparency are mapped across every state and dozens of countries at TrustVoting's Gaps tracker. The Kenya case and the Antrim case both appear in the Atlas of Election Integrity cases. For the two-minute version of why instant precinct-level reporting matters, see /simple.


Sources