Skip to main content
DTI

TILAKA · DTI PREFERRED PARTNER

Certified Digital Signatures for Banking

Accelerate customer onboarding, account opening, and credit agreements with certified electronic signatures from Tilaka — a KOMDIGI-certified PSrE. DTI guides the integration into your core banking and loan origination systems, from flow design through production.

KOMDIGI-Certified PSrEUU ITE & GR 71/2019POJK 11/2022PDP Law 27/2022

Discuss your deployment

Free initial consultation — we'll map your needs, integration, and compliance.

Are you inquiring for an organization or yourself?*

Reply within 1 business day · Your data is protected (UU PDP)

Digital signatures in banking are no longer a mere efficiency initiative — they are foundational to digital banking services. Account opening, credit agreements, restructuring documents, and treasury paperwork are now expected to close in minutes without a branch visit, while the legal standing of every document must still hold up before auditors, regulators, and the courts.

The legal framework is mature. Indonesia's Electronic Information and Transactions Law (UU ITE, as most recently amended by Law 1/2024) recognizes electronic signatures as legally valid provided they meet statutory requirements, and Government Regulation 71/2019 distinguishes certified electronic signatures — created using the services of an Indonesian Certification Authority (PSrE) — from uncertified ones. For banks, this distinction is material: certified signatures carry far stronger evidentiary weight because the signer's identity is verified and document integrity is cryptographically assured.

Tilaka is a KOMDIGI-certified PSrE and a sister company of DTI. As its preferred partner, DTI brings Tilaka into banking environments the way banks expect: API integration with systems already in production, e-KYC flows aligned with AML/CFT provisions, and audit trails that are ready for inspection — without forcing you to replace your core banking system.

Why conventional signing workflows hold banks back

Onboarding and credit agreements move too slowly

Physical documents must be printed, couriered, wet-signed, and archived — a process that takes days and pushes prospective customers to drop off mid-journey.

Scanned signatures are easy to dispute

A signature image pasted into a PDF verifies neither the signer's identity nor the document's integrity, leaving the bank in a weak position in disputes or fraud cases.

A heavy burden of proof and audit

Internal auditors, OJK, and legal teams need evidence of who signed what, when, and whether the document changed afterward — paper archives and plain PDFs struggle to answer this systematically.

Legacy integration is never trivial

A bank's LOS, core banking, and mobile channels are already complex; signing solutions without mature APIs and local implementation support turn into drawn-out projects.

Tilaka + DTI: certified electronic signatures built for banking

Electronic certificates from a KOMDIGI-certified PSrE

Every signature is backed by an electronic certificate issued by Tilaka, an Indonesian PSrE certified by KOMDIGI, meeting the criteria for certified electronic signatures under GR 71/2019.

e-KYC with biometric verification against population data

Customer identity is verified through facial biometric matching against national population data (Dukcapil) with liveness detection — supporting electronic CDD within Indonesia's AML/CFT framework for the financial sector.

APIs and SDKs for core banking, LOS, and digital channels

Signing is embedded directly into your account-opening, loan-application, or mobile-banking flows via REST APIs — customers never have to leave your application.

Verifiable audit trails and signature validity

Every document carries a timestamp, a cryptographic hash, and a verifiable certificate status — checkable via the official tte.komdigi.go.id validator — as proof of integrity in audits and disputes.

Implementation guided by DTI

DTI's team supports you from use-case mapping through sandbox, production, and operations — a single local point of accountability, aligned with the IT governance expectations of POJK 11/2022.

Tilaka has been implemented in institutional document-signing workflows across heavily regulated sectors, with DTI guiding each engagement from integration through production operations.

How implementation works

1

Use-case and document flow mapping

DTI works with your team to map priority documents — account opening, credit agreements, internal forms — and their integration points in the LOS, core banking, or digital channels, including compliance and archiving requirements.

2

API integration in a sandbox environment

Your engineers connect to the Tilaka sandbox with full API documentation and direct DTI support; certificate issuance, signing, and callback flows are tested end-to-end before anything touches production.

3

Customer activation: e-KYC and certificate issuance

Customers complete a one-time electronic identity verification (biometrics plus population-data matching), after which an electronic certificate is issued in their name — ready for signing from any device.

4

Go-live, monitoring, and audit trail

The flow runs in production under continuous monitoring; every signing event is fully recorded — verified identity, timestamp, and document integrity — ready to present to auditors and regulators.

Frequently asked questions

Are digital signatures legally valid for banking documents in Indonesia?

Yes. Article 11 of the Electronic Information and Transactions Law (UU ITE) recognizes electronic signatures as having valid legal force and effect provided they meet statutory requirements, including that the signature-creation data is controlled solely by the signer and any alteration is detectable. Certified electronic signatures from a PSrE such as Tilaka are designed to meet those requirements technically and administratively.

What is the difference between certified and uncertified electronic signatures?

Government Regulation 71/2019 distinguishes the two: certified signatures are created using the services of an Indonesian PSrE and evidenced by an electronic certificate, while uncertified signatures are created without them. For banks, the certified variant carries substantially stronger evidentiary standing because the signer's identity has been verified and document integrity is cryptographically assured.

Are banks required to use certified electronic signatures?

No regulation mandates that every bank document be signed with a certified electronic signature. For legally high-risk documents, however — credit agreements, contracts, customer consents — many banks choose certified signatures because they offer the strongest evidentiary position and align with the risk-management expectations of the POJK 11/2022 framework.

How does e-KYC and customer identity verification work?

Before a certificate is issued, the customer's identity is verified electronically through facial biometric matching against national population data (Dukcapil) with liveness detection. This supports electronic customer due diligence within Indonesia's AML/CFT provisions for the financial sector, and only needs to be completed once per customer.

How does integration with our core banking or loan origination system work?

Tilaka provides REST APIs and SDKs so signing embeds directly into your application flows — LOS, mobile banking, or internal portals — without replacing core systems. DTI supports your technical team from sandbox through end-to-end testing, go-live, and ongoing operations.

How is customers' personal data protected in this service?

Customer identity data is processed within the framework of Indonesia's Personal Data Protection Law (Law 27/2022), with a clear legal basis and processing limited to verification and certificate issuance purposes. As a certified PSrE, Tilaka is additionally subject to security and governance requirements supervised by KOMDIGI.

TILAKA · DTI PREFERRED PARTNER

Discuss your bank's digital signing workflow

Tell us your use case — onboarding, credit agreements, or internal documents — and DTI's team will prepare an integration architecture recommendation with concrete implementation steps. No commitment at the consultation stage.

Chat via WhatsApp