Banking and Insurance - Laws and Practice · Digital Banking
Acceptance of Digital Signature Certificate under Section 41
Updated 11 October 2026 · Fact-checked
Under Section 41 of the IT Act, 2000, a subscriber is deemed to have accepted a Digital Signature Certificate if he publishes it, authorises its publication, or otherwise shows approval. By accepting, he certifies to all who reasonably rely on it that he holds the private key and that the information and representations are true.
Understand Acceptance of Digital Signature Certificate
A Digital Signature Certificate is issued by a Certifying Authority to a subscriber. It links the subscriber to a public key. The subscriber holds the matching private key. Section 41 answers one question: when does the subscriber become bound by the certificate?
The answer is acceptance. The Act does not require a signed acceptance form. Acceptance is deemed if the subscriber publishes the certificate or authorises its publication to one or more persons, or in a repository. It is also deemed if he otherwise demonstrates his approval in any manner. So conduct can amount to acceptance.
Acceptance has legal consequences. Under Section 41(2), the subscriber certifies to all who reasonably rely on the certificate three things. First, he holds the private key matching the public key listed, and is entitled to hold it. Second, all his representations to the Certifying Authority, and all material relevant to the information in the certificate, are true. Third, all information in the certificate that is within his knowledge is true.
Note who is protected: those who reasonably rely. This matters in digital banking. A bank accepting an e-signed mandate or loan document relies on the certificate. If the subscriber's statements were false, he cannot say he never took the certificate.
Section 41 sits within a chain. The Certifying Authority certifies facts at issue (Section 36). The subscriber certifies facts on acceptance (Section 41). The subscriber must then keep the private key safe (Section 42).
Key rules to remember
- Deemed acceptance (Section 41(1))
- Acceptance = publishes OR authorises publication (to one or more persons / in a repository) OR otherwise demonstrates approval in any manner
- Any one route is enough. No formal written acceptance is required.
- Certification by subscriber (Section 41(2))
- (a) holds the private key and is entitled to it; (b) all representations to the CA and all material facts are true; (c) all information in the certificate within his knowledge is true
- Made to all who reasonably rely on the certificate.
- Related duty: control of private key (Section 42)
- Reasonable care to retain control of private key; on compromise, inform the CA without delay; liable until he informs the CA
- Follows from acceptance; use it as the next step in your answer.
- Related penalty (Section 73)
- Publishing a certificate knowing the subscriber has not accepted it: imprisonment up to 2 years, or fine up to ₹1,00,000, or both
- Also covers knowledge that the CA did not issue it, or that it is revoked or suspended (unless publishing is to verify an earlier signature).
How to solve Acceptance of Digital Signature Certificate questions
Use this method for any case-based question on acceptance of a Digital Signature Certificate.
- 1Identify the parties: Certifying Authority, subscriber, and the person relying on the certificate.
- 2Ask whether the subscriber accepted. Look for publication, authorised publication to persons or a repository, or any conduct showing approval.
- 3State Section 41(1) in plain words and apply it to the facts.
- 4If accepted, list the three certifications under Section 41(2) and test each against the facts.
- 5Check whether the person relying did so reasonably.
- 6Add related duties: control of private key and prompt reporting of compromise (Section 42), and the Section 73 penalty if someone published a certificate not accepted.
- 7Conclude clearly: accepted or not, who is bound, and what follows.
Quickest way: Trigger-and-three method
When to use it: When time is short and the question asks whether a subscriber is bound by a certificate.
- Find the trigger: published, authorised publication, or approval shown by conduct.
- Write: deemed accepted under Section 41(1).
- Write the three certifications in one line each: key held and entitled; representations true; own-knowledge information true.
- Link to facts: which statement was false, or which person relied.
- Close with the Section 42 duty if a key issue appears.
Common mistakes in Acceptance of Digital Signature Certificate
Saying acceptance needs a written, signed acknowledgement.
Students assume contracts need formal acceptance.
Fix: Section 41(1) deems acceptance from publication, authorised publication or approval shown in any manner.
Mixing up what the Certifying Authority certifies with what the subscriber certifies.
Sections 36 and 41 read alike.
Fix: Section 36 is the CA's representations at issue. Section 41(2) is the subscriber's certification on acceptance.
Forgetting that the certification runs to those who reasonably rely.
Students focus only on the CA and subscriber.
Fix: State that the certification is made to all who reasonably rely on the certificate, and test the reliance.
Dropping one of the three certifications, usually entitlement to the private key.
Students memorise only 'information is true'.
Fix: Remember: key and entitlement, representations and material facts, own-knowledge information.
Confusing Section 41 with Section 73 penalty.
Both mention acceptance by subscriber.
Fix: Section 41 deems acceptance. Section 73 punishes publishing a certificate with knowledge that the subscriber has not accepted it.
Worked examples
Example 1
Meera Iyer obtains a Digital Signature Certificate and emails it to her bank, Shree Sahakari Bank, so that it can verify her signatures on loan documents. She never signs any acceptance form. Later she says she never accepted the certificate. Advise.
Show the solution
- Section 41(1) deems a subscriber to have accepted a certificate if she publishes it or authorises its publication to one or more persons.
- Meera sent the certificate to the bank for verification. This is publication to a person, or at least conduct showing approval.
- The absence of a signed form does not matter, because acceptance can be shown in any manner.
- So she is deemed to have accepted, and the Section 41(2) certifications apply to the bank, which reasonably relies on the certificate.
Answer: Meera is deemed to have accepted the certificate under Section 41(1). Her denial fails, and she is taken to certify the facts in Section 41(2) to those who reasonably rely.
Example 2
Rohan Desai gave false information to the Certifying Authority to get a certificate and accepted it. A bank relied on it to process a payment instruction. State his position under Section 41.
Show the solution
- Rohan accepted the certificate, for example by using it or having it published, so Section 41(2) applies.
- By accepting, he certified that all representations made to the Certifying Authority were true. Here they were false.
- He also certified that information in the certificate within his knowledge was true.
- The bank relied on it in the ordinary course, so it is a person who reasonably relied.
- Further, under Section 38(2)(a) the Certifying Authority may revoke a certificate if a material fact in it is false or concealed, after giving him a hearing (Section 38(3)).
Answer: Rohan breached his Section 41(2) certification to the bank, and the Certifying Authority may revoke the certificate after hearing him.
Exam tips
- Quote the trigger words of Section 41(1): publishes, authorises publication, or otherwise demonstrates approval.
- List all three certifications in Section 41(2) and tie each to a fact in the case.
- Always mention 'reasonably rely' when naming who is protected.
- Link to Section 42 and Section 73 briefly for a complete answer.
Practice questions from Digital Banking
- A wallet operator, designated by the RBI under the Payment and Settlement Systems Act, 2007, collects customer funds and is later wound up. …
- A fintech payment system operator functions wholly within an International Financial Services Centre (IFSC) set up under the Special Economi…
- Rahul Mehta's Certifying Authority suspended his DSC in public interest on its own opinion, without any request from him. Under the Informat…
- A hacker in Jaipur steals Rs 8 lakh from customers of Bharat Gramin Bank. The Adjudicating Officer under the IT Act has already awarded comp…
- A State Government department accepts licence applications only in a particular manner under its law. It now wants to accept such applicatio…
Acceptance of Digital Signature Certificate in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Acceptance of Digital Signature Certificate: frequently asked questions
When is a Digital Signature Certificate deemed accepted under Section 41?
It is deemed accepted when the subscriber publishes it or authorises its publication to one or more persons or in a repository. It is also deemed accepted if he otherwise demonstrates his approval in any manner.
What does a subscriber certify on accepting the certificate?
He certifies to all who reasonably rely on it that he holds the matching private key and is entitled to it. He also certifies that his representations and material facts given to the Certifying Authority are true, and that information in the certificate within his knowledge is true.
What are the subscriber's duties after acceptance?
Section 42 requires him to take reasonable care to retain control of the private key and prevent its disclosure. If the key is compromised, he must inform the Certifying Authority without delay. He remains liable until he does so.
What is the difference between Section 36 and Section 41?
Section 36 lists what the Certifying Authority certifies when issuing the certificate. Section 41 lists what the subscriber certifies by accepting it.