Beyond the Happy Path: A Safety-Critical Audit Methodology for Estonia’s I-Voting Processing Application

Tarvo Treier · IEEE Access · 2025

Auditing an Internet voting (i-voting) system can be viewed as a specialised form of software testing: the auditor acts as the tester, the goal is legal assurance rather than product release, and success depends on providing independently verifiable evidence. While Estonia’s legally binding i-voting platform includes procedural checks, it currently lacks a systematic, test-driven audit methodology—particularly for the vote-processing stage, where integrity checks and anonymisation are critical. This study presents a structured, evidence-based audit methodology for that stage. It identifies 37 potential fault scenarios—from duplicate votes to silent manipulations—maps them to 19 functional requirements, and highlights where targeted tests are missing. A requirement–risk matrix is used to reveal these coverage gaps. To enable reproducible audits, the paper introduces a GDPR-compliant synthetic dataset: one reference ballot box and a set of fault-seeded variants designed to expose critical risks, including a manipulation undetected by the previously used integrity-check tool. The examples illustrate how such faults can be detected automatically and how auditors could use measurable coverage metrics to track improvements over time. The methodology is designed to allow qualified observers to replicate the same tests on the synthetic data without compromising ballot secrecy. The requirements list, fault catalogue, and dataset guidelines have been shared with-on an independent basis-the National Election Service for possible consideration in preparation for the 2025 local elections. These results indicate that safety-critical testing principles can be adapted to strengthen the practical auditability of the i-voting processing stage.

Read the paper · More papers on PaperTik