How to Verify Voters in an Online Election

Friday, 25 September 2026, 8:56 am

vero_voting-blog-How-Election-Scrutineers-Work-with-Online-Voting
BlogElections

How to Verify Voters in an Online Election

An online election can make participation much easier. Members can vote from home, employees can participate remotely, and organisations can manage ballots without printing, posting and manually processing thousands of voting papers.

But convenience creates a practical governance question:

How do you know the person accessing the ballot is actually entitled to vote?

That is where voter verification comes in.

A well-designed online election should do more than send a voting link to an email address. It should establish that the person attempting to access the ballot matches an authorised voter record, apply an appropriate authentication step, prevent duplicate or unauthorised voting, and protect the personal information used during the process.

The right approach depends on the organisation, the type of election and the rules governing the vote. A board election, union ballot, strata vote and company AGM may have very different requirements.

This guide explains the practical principles behind online voter verification, including email verification, mobile verification and one-time passwords (OTPs).

What is voter verification?

Voter verification is the process of confirming that a person attempting to participate in an online election is an authorised voter for that particular election.

It is useful to distinguish this from proving someone’s legal identity.

For many organisational elections, the question is not:

“Can we prove exactly who this person is?”

Instead, it is:

“Can we establish that this person is the authorised participant associated with this voting entitlement?”

For example, an association may have a membership register containing a member’s name, membership number and registered email address. A company may maintain a shareholder register. A union may have an eligible voter list for a particular ballot.

The voting system can use the relevant information to determine whether the person requesting access corresponds with an eligible voter record.

That distinction matters because collecting more personal information than necessary can create additional privacy and security risks.

The Office of the Australian Information Commissioner (OAIC) says APP entities should only collect personal information that is reasonably necessary for their functions or activities and should take a data-minimisation approach.

Why voter verification matters in an online election

A paper ballot has physical controls built into the process. Someone may need to receive a ballot paper, have their eligibility checked against a roll, sign a declaration or return a ballot through a controlled process.

Online voting replaces those physical steps with digital controls.

A secure voting process should therefore address several questions:

Who is entitled to vote?
How is their entitlement confirmed?
How does the voter access the ballot?
How do you prevent someone from using another person’s credentials?
How do you prevent a voter from submitting multiple votes?
Can eligible voters recover access if they lose their invitation?
Can administrators intervene without compromising the ballot?
What information is recorded for audit purposes?
How is voter information protected?

The authentication process should support the election rules rather than become an afterthought.

For companies, the applicable voting rights and procedures can also depend on the Corporations Act, the company’s constitution and the particular type of vote. For example, section 250E of the Corporations Act sets out voting entitlements for members of companies under the relevant replaceable rules.

Other organisations may be governed by state or territory legislation, industrial legislation, constitutions, rules, enterprise agreements or other governing documents.

So the first step is always to establish who is eligible to vote.

Voter authentication and voter eligibility are different

This is one of the easiest concepts to get wrong.

Eligibility determines whether someone has a right to vote.

Authentication helps establish that the person accessing the ballot is the authorised participant associated with that entitlement.

For example:

Jane is a financial member and therefore eligible to vote in the association’s committee election.

The voting system then needs an appropriate mechanism to establish that the person accessing Jane’s voting entitlement is authorised to use it.

A system could use a combination of:

An authorised voter list
A unique voting invitation or credential
Email verification
SMS or mobile verification
A one-time password
Another authentication or recovery method appropriate to the risk

The exact combination should be proportionate to the election.

A low-risk internal poll may not require the same controls as a contested election involving significant governance decisions.

How OTP verification works for online voting

A one-time password, commonly called an OTP, is a temporary code used to verify access.

A typical process might look like this:

Step 1: Establish the voter record

The organisation provides the voting provider with an authorised voter list.

This may contain information such as a member number and registered contact details, depending on the organisation’s requirements and privacy arrangements.

Step 2: The voter requests access

The voter follows their invitation or starts an approved verification process.

Step 3: The system checks the voter information

The information supplied is matched against the authorised voter record for the particular ballot.

Step 4: A one-time code is issued

The system sends a temporary authentication code to an approved email address or mobile number.

Step 5: The voter enters the code

The code is checked and, if valid, the voter can proceed.

Step 6: The voter receives access to the ballot

The voter can then cast their vote according to the election rules.

The key benefit of an OTP is that the code is intended for one-time use rather than functioning as a permanent password.

However, OTPs should not be treated as a magic security solution.

Australian Government cybersecurity guidance notes that SMS and email-based authentication codes can be more susceptible to compromise than phishing-resistant authentication methods.

For many organisational elections, email or SMS verification may still be a practical control, particularly when combined with an authorised voter register, unique voting access and controls preventing repeat voting. But the security requirements should be assessed according to the circumstances.

Email verification for online elections

Email is one of the most common ways to distribute voting invitations.

A basic process might involve sending each eligible voter a unique link to the ballot.

The strength of this method depends on what happens around the link.

Simply knowing an email address does not necessarily prove that the person accessing the ballot is the intended voter. Email accounts can be shared, compromised or accessed by someone other than the intended recipient.

A stronger process can combine:

an authorised voter record
a unique voting link
a controlled verification step
one-time authentication
a record that the voting entitlement has been used

The aim is to make unauthorised access difficult without creating unnecessary barriers for genuine voters.

Mobile and SMS verification

Mobile verification can provide another authentication factor by sending a temporary code to the voter’s registered mobile number.

For example:

Voter enters details → system checks voter record → OTP sent to registered mobile → voter enters OTP → ballot access granted.

This can be useful when email delivery is unreliable or when an organisation maintains verified mobile numbers for its members.

There is, however, an important security distinction.

SMS is a useful authentication mechanism in many real-world applications, but Australian Government cybersecurity guidance identifies SMS and other non-phishing-resistant methods as being more susceptible to compromise than phishing-resistant MFA.

That means organisations should avoid assuming that an SMS code makes an election automatically secure.

The authentication method should be considered alongside the voter register, access controls, ballot design, privacy protections and audit process.

What happens when a voter loses their voting email?

This is a surprisingly common operational problem.

A voter may:

delete the original invitation
have the message filtered into spam
use a corporate email system that blocks automated messages
change devices
have an outdated email address
simply be unable to find the invitation

The wrong response is to bypass verification completely.

For example, an administrator should be cautious about simply issuing a new voting link because someone phones and says:

“I’m John Smith. Please send me another link.”

A controlled recovery process is safer.

Depending on the election, recovery could involve matching information against the authorised voter record and then completing a one-time authentication step using an approved contact method.

This provides a practical balance: legitimate voters can regain access without creating an easy route around the election’s security controls.

Vero Voting has introduced a voter self-verification feature designed around this type of situation, allowing eligible participants to verify themselves against information already held in the authorised voter record and complete a configured authentication step.

How to prevent unauthorised voting

Voter verification is only one part of election security.

A properly designed online election should consider the complete voting journey.

1. Start with an accurate voter register

The quality of the voter list matters.

If former members remain on the list, eligible voters are missing, or contact information is incorrect, even a sophisticated voting platform cannot fix the underlying governance problem.

The organisation should establish:

who is eligible
the eligibility date
voting entitlements
relevant membership or shareholder categories
any weighted voting rights
proxy arrangements where applicable
whether joint members or representatives have special rules

For APP entities, the OAIC says reasonable steps should be taken to ensure personal information is accurate, up to date and complete.

2. Give each voter controlled access

Avoid shared credentials wherever possible.

A voting entitlement should be associated with the relevant voter record and controlled through a mechanism that makes it difficult for another person to use.

3. Use one-time authentication where appropriate

An OTP can provide an additional step beyond simply clicking a link.

The code should be temporary and controlled, with appropriate protections against repeated attempts or abuse.

4. Prevent duplicate voting

The system should track whether a voting entitlement has already been used.

The exact implementation depends on the ballot design, particularly where a secret ballot is required.

The goal is to prevent a voter from submitting multiple votes while preserving the required level of ballot secrecy.

5. Separate authentication from ballot secrecy

This is crucial.

An organisation may need to know that a particular member is entitled to vote without knowing how that member voted.

Authentication and ballot secrecy should therefore be designed as separate parts of the election process where a secret ballot is required.

Vero Voting describes its AGM voting service as confirming voter eligibility while keeping voter identity anonymous during the voting process.

6. Control administrator access

Election administrators can themselves become a security risk if access is poorly controlled.

Administrative accounts should have appropriate access controls, authentication and logging.

Australian Government cybersecurity guidance recommends multi-factor authentication and increasingly emphasises phishing-resistant methods such as passkeys and security keys for stronger protection.

7. Maintain an audit trail

A defensible election should leave an appropriate record of the process.

That can include records relating to:

voter eligibility
invitations issued
access or verification events
voting status
administrative actions
ballot closing
counting
results

The precise information retained should depend on the election and applicable privacy and record-keeping requirements.

Vero Voting says its platform produces an audit trail covering activities including registrations, revocations and voting.

Privacy matters as much as authentication

Verification requires information about voters.

That might include names, membership numbers, email addresses, mobile numbers or other information used to match an authorised voter record.

For organisations covered by the Australian Privacy Principles, privacy needs to be considered throughout the voting process.

The OAIC’s current APP guidance emphasises data minimisation when collecting personal information. APP 11 also requires APP entities to take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, and to destroy or de-identify information when it is no longer needed, subject to the relevant exceptions.

That has some practical consequences for election organisers.

Don’t collect identity documents simply because they are available.

Don’t retain voter information indefinitely without a reason.

Don’t expose one voter’s information while helping another voter recover access.

And make sure voters are appropriately informed about the collection and handling of their personal information. APP 5 includes requirements concerning notification about matters such as the purpose of collection and usual disclosures.

Privacy obligations can vary depending on the organisation and circumstances, so organisations should obtain specific advice where required.

Common mistakes with online voter verification

Mistake 1: Treating a voting email as proof of identity

An email invitation is useful, but possession of an email account does not necessarily establish the person’s legal identity.

Consider what level of authentication the election actually requires.

Mistake 2: Making verification too complicated

Security controls that genuine voters cannot navigate create their own governance problem.

If members repeatedly cannot access the ballot, administrators may start bypassing the controls manually.

A simpler, well-designed process is often safer than a complicated one that staff routinely override.

Mistake 3: Letting administrators manually bypass authentication

An administrator should not be able to casually replace a security control with a phone conversation.

If manual recovery is required, establish a documented process before voting opens.

Mistake 4: Forgetting about duplicate voting

Authentication alone does not necessarily prevent a person from voting twice.

The voting platform needs to associate the completed ballot with the relevant voting entitlement and enforce the election’s rules around repeat voting.

Mistake 5: Ignoring ballot secrecy

Knowing who is eligible to vote and knowing how that person voted are different things.

Where a secret ballot is required, the technical design needs to preserve that separation.

Mistake 6: Collecting too much personal information

More data does not automatically mean more secure voting.

The OAIC’s guidance supports collecting only information that is reasonably necessary for the relevant function or activity.

Mistake 7: Choosing the technology before understanding the rules

The software should fit the election.

Before selecting a voting system, establish the voting rights, eligibility requirements, ballot type, secrecy requirements, counting method and relevant governing documents.

Then assess whether the technology can support them.

A practical online voter verification checklist

Before launching an online election, ask:

Eligibility

Is the voter register current?
Has the eligibility cut-off date been established?
Are voting entitlements correct?
Have special membership or voting classes been accounted for?

Authentication

How will voters access the ballot?
Is email verification sufficient?
Should SMS/mobile verification be used?
Would stronger MFA be appropriate?
Is there a secure recovery process?

Voting controls

Can a voting entitlement be used more than once?
Can administrators alter a voter’s status?
Is ballot secrecy preserved where required?
Are proxies handled correctly?

Privacy

What personal information is being collected?
Is each field necessary?
Have voters been appropriately informed?
How is the information protected?
How long does it need to be retained?

Audit and governance

Are relevant events logged?
Can the organisation demonstrate how the result was produced?
Who has administrative access?
Is there a documented incident and recovery process?

These questions are often more useful than asking simply whether a platform is “secure”.

How Vero Voting can assist

Vero Voting provides online voting and election services for organisations conducting AGMs, board and committee elections, member ballots, enterprise agreement votes and other voting events. Its voting services can incorporate eligibility controls, online authentication, real-time voting and reporting, with the specific process configured around the election requirements.

For organisations dealing with voters who have lost or cannot locate their original invitation, Vero’s voter self-verification feature provides an additional access pathway based on the authorised voter record and configured one-time authentication.

The broader benefit is not simply sending ballots electronically. A properly managed election should give the organisation confidence that eligible voters can participate while unauthorised access and duplicate voting are controlled.

For complex elections, it is also useful to involve the voting provider early — before the voter list is finalised and invitations are issued.

Key takeaways

Good online voter verification does not mean making voters jump through as many security hoops as possible.

It means putting the right controls in the right places.

A strong process generally starts with an accurate voter register, establishes eligibility, uses an appropriate authentication method, controls ballot access, prevents duplicate voting and protects voter information.

Email and SMS OTPs can be useful tools, but they should be considered as part of the overall security design rather than as a guarantee of election integrity. Australian Government cybersecurity guidance increasingly recommends phishing-resistant MFA where stronger authentication is required.

For organisations running an online election, the practical objective is straightforward:

Make it easy for the right people to vote — and difficult for anyone else to do so.

If you’re planning an AGM, committee election, member ballot or other online election and want to discuss voter verification options, contact Vero Voting or request a demonstration of how the process can work for your organisation.

8. Sources

The following are the principal authoritative sources used to verify the Australian privacy, cybersecurity and governance points in this article:

Vero Voting references used for product-specific descriptions:


Frequently Asked Questions

What is voter verification in an online election?

Voter verification is the process of confirming that the person trying to access an online ballot is associated with an authorised voter record. It can involve unique voting credentials, email verification, SMS/mobile verification or a one-time password.

Is an OTP enough to secure an online election?

Not necessarily. An OTP can be one layer of authentication, but election security also depends on the accuracy of the voter register, access controls, duplicate-vote prevention, ballot secrecy, administrator controls and appropriate audit records. Australian Government guidance also notes that SMS and email authentication codes are more susceptible to compromise than phishing-resistant authentication methods.

Can voters verify themselves if they lose their voting email?

Yes, provided the election system has a secure recovery process. A controlled process can match the voter against the authorised voter record and require an additional authentication step rather than simply issuing an unrestricted replacement voting link. Vero Voting offers a self-verification process designed for this situation.

How can an online election prevent someone from voting twice?

The voting system should associate the ballot with the relevant voting entitlement and record whether that entitlement has already been used. The exact mechanism depends on the election rules and whether the ballot must remain secret.

Should voter verification collect a driver’s licence or passport?

Not automatically. Collecting identity documents creates additional personal information that must be handled appropriately. Where an organisation is subject to the Australian Privacy Principles, the OAIC’s guidance supports collecting personal information that is reasonably necessary for the organisation’s functions or activities.

Need support with your next Elections?

Contact Us

Subscribe to our blog

Stay up to date on the latest topics for voting solutions

[stc-subscribe]



    Subscribe

    If you want to personalise your subscription, click here