14 — Comparison to Other Approaches
14.1 — Introduction
The United States has a layered system of election integrity measures. Some operate before the election, some on election day, some after. Some verify counting accuracy, some verify reporting accuracy, some verify procedural compliance. Some require government cooperation, some can be conducted independently.
Actual Vote is one tool in this landscape. It does one specific thing — independently verifies that precinct-level poll tape totals match officially reported results — and it does it at one specific layer: the reporting layer, between the poll tape and the public record (see the layer model in Conceptual Foundation). Understanding where AV sits relative to other approaches clarifies both what it contributes and what it doesn’t. It also reveals a structural gap in the existing landscape: the reporting layer is the least-checked segment of the chain from ballot to official result, and AV is the only approach that systematically verifies it from outside the government’s own infrastructure.
This section describes each major election integrity approach, explains what it checks and what it misses, and identifies its relationship to Actual Vote. The approaches are organized chronologically through the election lifecycle: pre-election measures, election day measures, and post-election measures.
A note on posture. This section is not an argument that other approaches are inadequate and AV is the solution. It is a map of the landscape. Most of these approaches are valuable and well-designed for their intended purpose. The problem is not that any individual approach fails — it is that the collection of approaches, taken together, leaves the reporting layer largely unchecked. AV fills that gap. A system with AV and all of these other approaches is strictly better than a system with only these other approaches.
14.2 — Part I: Pre-Election Measures
1. Federal Voting System Certification (EAC/VSTL Testing)
What it is. The Election Assistance Commission (EAC) runs a voluntary national certification program in which Voting System Test Laboratories (VSTLs) evaluate voting systems against the Voluntary Voting System Guidelines (VVSG). Testing covers functionality, accessibility, and security requirements. Manufacturers submit their systems for testing; laboratories conduct extensive evaluation against the VVSG standards; and the EAC issues a certification if the system meets all requirements.
What it checks. Whether the voting system, as manufactured and configured, meets federal standards for correctly reading ballots, accurately counting votes, providing accessible interfaces, and protecting data from unauthorized access. Certification also evaluates the system’s documentation, quality assurance processes, and configuration management.
What it misses. Certification tests the system as manufactured, not as deployed. The EAC’s own FAQ states explicitly that certification is “not a determination that a voting system, when fielded, will be operated in a way that ensures system integrity.” Field conditions introduce variables that certification cannot anticipate: local configurations, firmware versions, election definitions, peripheral hardware, operator errors, environmental conditions, and the cumulative effects of years of use on hardware that may have been certified a decade earlier.
Certification is also voluntary at the federal level. Although many states require EAC certification as a precondition for state approval, the federal program itself imposes no mandate. The EAC did not certify its first voting system until February 2009 — meaning that every voting system used in every American election before that date, including the disputed elections of 2000 and 2004, was deployed without the benefit of a completed federal certification.
Most importantly for our purposes, certification does not test the reporting chain. It tests whether the voting system produces correct outputs — correct poll tapes, correct memory card data, correct results files. It does not test whether those outputs are faithfully transmitted from precinct to county to state to public. A machine that passes every EAC test can still produce results that are lost in transit (Georgia 2020), double-counted during upload (Monmouth County 2022), or reformatted incorrectly during aggregation (Prince William County 2020).
Relationship to AV. AV operates entirely downstream of what certification tests. Certification verifies that the machine can count correctly; AV verifies that the machine’s output was correctly reported. These are different questions about different parts of the process, and both need answering. A certified machine whose results are mangled during the reporting process will produce exactly the kind of discrepancy AV is designed to detect — and certification, by design, does not and cannot catch it.
Sources: EAC Testing & Certification Program (eac.gov/election-technology/testing-certification-program-tc); EAC FAQ on Certification (eac.gov/voting-equipment/frequently-asked-questions); Brennan Center, “Voting System Failures: A Database Solution” (2010).
2. Logic and Accuracy Testing (L&A / LAT)
What it is. Pre-election testing required in most states, in which election officials run a set of pre-marked test ballots through every tabulator that will be used in the election. The tabulated results are compared against a known test script — a hand count of the test ballots establishing the correct answer. The test must produce an exact match for the equipment to be deployed. L&A testing is typically conducted publicly, often with party observers present, in the days or weeks before the election.
What it checks. Whether each specific tabulator, loaded with the specific election definition for the upcoming election, correctly reads and counts ballots. Unlike federal certification, which tests the system as a type, L&A testing verifies each individual machine in its actual deployed configuration. It confirms that ballot layouts are correct, that all contests and candidates appear as expected, that the machine correctly distinguishes between marked and unmarked ovals, and that the tabulated results match the predetermined script exactly.
L&A testing is, in a sense, the most practically relevant pre-election safeguard: it tests the exact machines that voters will use, with the exact software and election definitions that will be in place on election day. It catches configuration errors, ballot layout problems, and basic machine malfunctions before they can affect real votes.
What it misses. L&A tests the machine before election day, in a controlled environment, with a known and limited set of test ballots. It cannot detect problems that emerge only under election-day conditions: high volume, thousands of ballot scans in sequence, concurrent memory card operations, power fluctuations, operator errors during closing procedures, or software behaviors triggered by specific data patterns not present in the test script.
This last point deserves emphasis, because it is the central concern raised by election security researchers about L&A’s sufficiency as a standalone safeguard. A predetermined test script has a known structure. A sufficiently sophisticated attack that activated only for specific candidate names, specific ballot counts, or specific dates — election day rather than test day — would pass L&A and fail in production. This is not a hypothetical: it is the design premise of the “Fraction Magic” attack documented in our case study collection, in which the GEMS tabulation system could theoretically be configured to internally represent votes as fractions that round to whole numbers, producing results that look correct in small test batches but systematically shift large counts.
L&A testing also does not test the reporting chain. It confirms that the tabulator produces correct poll tapes and correct memory card data in the testing environment. It does not test whether that data is correctly uploaded from the memory card to the county election management system, correctly reformatted for state reporting requirements, correctly aggregated with data from other precincts, and correctly published as official results. Every one of the reporting-layer failures documented in our case studies — Georgia’s memory card upload failures, Prince William County’s formatting incompatibility, Monmouth County’s double-counted flash drives — involved machines that had passed L&A testing.
Finally, after L&A testing is complete, machines are sealed and transported to polling places. This seal-and-transport process introduces a chain-of-custody gap that L&A testing itself does not address. The machine that arrives at the polling place is assumed to be the same machine that was tested — an assumption that depends entirely on the integrity of physical seals and transport procedures.
Relationship to AV. L&A testing and AV operate at different stages and different layers of the election process. L&A verifies the machine before the election; AV verifies the reporting chain after. L&A confirms the machine can produce correct outputs under test conditions; AV confirms those outputs were correctly reported under real conditions. They address different vulnerabilities, and a system with both is more robust than a system with either alone.
Sources: EAC, “Logic and Accuracy Testing Quick Start Guide” (eac.gov); Elections Group, “Logic and Accuracy Testing” (electionsgroup.com/resource/logic-and-accuracy-testing/); EAC, “Logic and Accuracy Testing Manual v1.4.”
3. Equipment Certification at the State Level
What it is. States conduct their own certification and testing of voting systems, independent of and often beyond the requirements of federal EAC certification. State certification may include additional functional testing, security review, source code analysis, and field testing. The scope and rigor vary enormously by state.
At the strong end, some states have conducted security reviews of historic depth and significance. California’s 2007 “top-to-bottom review” — commissioned by Secretary of State Debra Bowen — subjected every certified voting system in the state to independent source code review, red-team penetration testing, and accessibility evaluation. The review uncovered critical vulnerabilities in systems from all three major vendors, leading to the decertification of several systems and the imposition of stringent new conditions on others. Ohio’s 2007 “Project EVEREST” (Evaluation and Validation of Election-Related Equipment, Standards and Testing) conducted a parallel evaluation with similar findings. Both reviews found vulnerabilities that federal certification had not detected.
At the weak end, some states simply accept federal EAC certification without additional review, or conduct only minimal supplementary testing.
What it checks. At its best, state certification examines source code for vulnerabilities, attempts to exploit those vulnerabilities under realistic conditions, and evaluates the full system architecture — including the election management system, the tabulator software, the communication between components, and the physical security of the hardware. The strongest state reviews have produced the most comprehensive public assessments of voting system security available.
What it misses. The same structural limitation as federal certification applies: even the most rigorous state certification tests the system as designed and configured, not as deployed and operated in the field over years of use by hundreds of different jurisdictions. State certification also does not test the reporting chain from precinct-level tabulator output to official certified results. The upload, reformatting, and aggregation steps are outside the scope of system certification.
Additionally, the practical reach of state certification is limited by resources. Comprehensive reviews like California’s and Ohio’s are expensive, time-consuming, and politically contentious (vendors have resisted them, and some officials have argued they create unnecessary public anxiety about election security). Most states lack the budget, expertise, or political will to conduct reviews of comparable depth.
Relationship to AV. Same as federal certification — AV operates downstream of what state certification covers. State certification verifies the system; AV verifies the output of the system as actually reported. They are complementary at different stages of the process.
Sources: NCSL, “Voting System Standards, Testing and Certification” (ncsl.org); California Secretary of State, “Top-to-Bottom Review” (2007); Ohio Secretary of State, “Project EVEREST” (2007); Butler County 2008 case study (documents EVEREST’s findings in context).
14.3 — Part II: Election Day Measures
4. Poll Watchers and Election Observers
What they are. Individuals authorized to observe the voting process at polling places. Partisan poll watchers are appointed by parties or candidates to represent their interests. Nonpartisan observers may represent civic organizations, academic institutions, media, or international monitoring bodies. Rules governing observation vary significantly by state — who may observe, where they may stand, what they may see, what they may record, and what recourse they have if denied access.
The tradition of election observation is among the oldest in democratic governance, predating every other approach discussed in this section. The Carter Center, which has observed elections in more than 100 countries, published a comprehensive guide to election observation policies across all 50 U.S. states, documenting the wide variation in observer access and rights.
What they check. Procedural compliance: whether poll workers follow correct opening and closing procedures, whether ballot handling is proper, whether voters are treated fairly and without intimidation, whether the count is conducted as prescribed. In jurisdictions that require public posting of poll tapes, observers can also witness the printing and posting process and visually inspect the tapes.
Election observation serves a broader democratic function beyond any specific verification: it demonstrates that the election is being conducted in the open, under public scrutiny. This transparency function has value independent of any specific error it might catch.
What they miss. Observation is passive. An observer who sees a poll tape posted on the wall can note the numbers, but that observation does not create a permanent, independently-held, verifiable evidentiary record. It creates a human memory, a handwritten note, or perhaps a photograph — but not a systematic, archivable, comparable dataset. An observer’s contemporaneous notes are valuable testimony; they are not scalable verification infrastructure.
Observer access also does not extend to the central tabulation step in most jurisdictions. Observers can watch precinct-level closing procedures — the printing of poll tapes, the sealing of ballot containers, the shutdown of machines. But they typically cannot observe the aggregation of precinct results at the county election management system, which is where most reporting-layer errors actually occur. The crucial step — when precinct-level data is uploaded, reformatted, and aggregated into county totals — generally happens behind closed doors.
Observer programs also depend on the cooperation of election officials, and cooperation is not always forthcoming. In Warren County, Ohio (2004), officials locked down the county administration building on election night and barred all reporters and observers from watching the vote count, citing a terrorist threat that the FBI said it had no information about. Emails later obtained through public records requests showed the lockdown had been planned more than a week before the election. In Baldwin County, Alabama (2002), the opposing party’s county chair was told the courthouse was closing and was sent home, after which officials reopened the building and continued counting.
Finally, observer coverage is inherently incomplete. No party or organization has the resources to station trained observers at every precinct in every jurisdiction. Coverage tends to concentrate in high-profile, contested, or historically problematic locations — which means that precincts in lower-profile races, smaller jurisdictions, and less contentious political environments receive the least scrutiny, despite being just as susceptible to error.
Relationship to AV. AV transforms observation from passive witnessing into active evidence production. An AV user who records a poll tape creates a permanent, video-based, GPS-stamped, timestamped evidentiary record that exists in a public archive maintained independently of any government system. That record can be transcribed, compared against official results, investigated for discrepancies, and cited in formal analyses — months or years after the election. A traditional observer’s memory cannot survive in this way.
AV also extends the evidentiary power of observation beyond the precinct. By comparing tape totals against official results, AV checks the central tabulation step that observers typically cannot see. The observer’s role ends at the precinct; AV’s verification begins there and follows the data through the reporting chain.
In a sense, AV is what election observation becomes when it is paired with systematic, permanent, independently-held evidence capture.
Sources: EAC, “Poll Watchers” (eac.gov/election-officials/poll-watchers); Carter Center, “Guide to Election Observer Policies in the United States”; NCSL, “Policies for Election Observers” (ncsl.org).
5. Parallel Testing
What it is. Election-day testing in which randomly selected voting machines are pulled from service (or excess machines are used) and fed known test ballots during the hours that polls are open, under conditions designed to mimic real election-day operation. The idea is to catch software that behaves differently on election day than during pre-election L&A testing — a time-activated or condition-activated attack that activates only under election-day conditions.
Parallel testing addresses a specific and important vulnerability: the possibility that a compromised machine could be programmed to behave correctly during pre-election testing (when it “knows” it is being tested) and incorrectly during the actual election. By testing under real election-day conditions — same date, same time window, same power environment — parallel testing narrows this window of opportunity.
What it checks. Whether tabulators produce correct results under real election-day conditions as opposed to the artificial conditions of pre-election testing. Parallel testing is specifically designed to detect the most sophisticated class of counting-layer attacks: those that can distinguish between test mode and election mode.
What it misses. Parallel testing verifies the counting layer, not the reporting layer. It confirms that the tabulator counts correctly and prints a correct tape under election-day conditions. It does not test what happens to those counts after they leave the precinct — the upload, aggregation, reformatting, and publication steps where reporting-layer errors occur.
Parallel testing is also rare in practice. The logistical requirements are significant: machines must be selected at the last possible moment to prevent gaming, operated under realistic conditions for the full duration of polls being open, and the results compared against the known test script afterward. This requires trained personnel, dedicated equipment, and hours of sustained operation — resources that most election offices struggle to allocate on a day when they are already managing the election itself. Professor Douglas Jones of the University of Iowa, a leading voting systems researcher, has documented the practical challenges of making parallel testing both effective and operationally feasible.
Security researchers have also debated whether parallel testing can be made truly undetectable to the software being tested. A sufficiently sophisticated attack could potentially detect parallel testing conditions by recognizing test ballot patterns, atypical vote distributions, the absence of a voter check-in sequence, or other environmental signals that distinguish a test from a real election. This is a theoretical concern — no documented case of a voting machine detecting and evading parallel testing has been established — but it illustrates the arms-race dynamic inherent in adversarial testing.
Relationship to AV. Parallel testing and AV are complementary and non-overlapping. They verify different layers with zero functional redundancy. Parallel testing verifies the counting layer: did the machine count correctly under election-day conditions? AV verifies the reporting layer: were the machine’s counts correctly reported? A jurisdiction that conducts both parallel testing and AV verification has covered both layers independently. Neither alone provides what both together provide.
Sources: Douglas Jones, University of Iowa, “Testing Voting Systems” (homepage.divms.uiowa.edu/~jones/voting/testing/); Elections Group, “Systems Check: A Guide to Testing Election Technology.”
14.4 — Part III: Post-Election Measures
6. The Canvass
What it is. The official post-election process in which election officials reconcile all ballot materials, verify that the number of ballots cast matches the number of voters who checked in, resolve provisional and challenged ballots, incorporate late-arriving absentee ballots (where permitted by law), and produce the official certified results. The canvass is required by law in virtually every state and typically takes one to three weeks after election day. It is the process through which preliminary election-night results become official certified results.
The canvass is often invisible to the public — few voters are aware that the results reported on election night are preliminary and that a multi-week reconciliation process follows. But the canvass is where the official results are actually produced, and it serves critical administrative functions that no other process duplicates.
What it checks. Ballot reconciliation: does the number of ballots counted match the number of voters who checked in at the polls? This is a fundamental integrity check. A precinct that issued 500 ballots but counted 550 has an unexplained discrepancy that must be investigated. The canvass also resolves provisional ballots (voters whose eligibility was questioned at the polls), processes absentee and mail-in ballots that arrived within the legal window, and aggregates precinct-level results into county and state totals.
The canvass does catch some reporting errors. A precinct that reported zero votes — as happened in Gaston County, North Carolina (1998) when faulty data cartridges caused a third of precincts to report zeros — will be noticed during canvass because the ballot reconciliation will fail. A county whose precinct totals do not sum to the reported county total will also be caught.
What it misses. The canvass is conducted by the same officials who ran the election. It is an internal quality assurance process, not an independent verification. There is no external check on whether the canvass itself is conducted correctly, and the public has limited visibility into the process.
More importantly, the canvass checks ballot-level reconciliation — total ballots cast versus total voters checked in — but does not systematically compare candidate-level precinct totals from poll tapes against the candidate-level totals in the official results. A precinct whose tape shows 542 votes for Candidate A but whose official results show 530 will not necessarily be caught by canvass reconciliation, because the total ballots cast may still reconcile correctly. The missing 12 votes might be offset by a corresponding over-count for another candidate, or might simply be too small to trigger any flag in a process focused on ballot-level totals rather than candidate-level accuracy.
The Washington County, North Carolina duplication — in which an outdated tabulator duplicated all mail-in ballot data — was caught during the canvass of the NC Supreme Court 2020 race. But this was because the duplication was large enough to create an obvious ballot-count discrepancy. Smaller or more subtle reporting errors, especially those that affect candidate-level allocations without changing the total ballot count, can pass through the canvass undetected.
Relationship to AV. AV provides the independent external check that the canvass lacks. Where the canvass asks “do the ballot counts reconcile?”, AV asks “do the candidate-level poll tape totals match the official results?” These are different questions. A canvass that finds perfect ballot reconciliation does not mean the candidate-level totals are correct. An AV analysis that finds the candidate-level totals are correct does not mean the ballot counts reconcile. Both checks matter, and both should be done. They are complementary.
Sources: EAC, “Election Results, Canvass, and Certification” (eac.gov); Bipartisan Policy Center, “Behind the Curtain of Post-Election Canvassing.”
7. Traditional Fixed-Percentage Audits
What they are. Post-election audits required by many states, in which a fixed percentage of precincts, machines, or ballot batches (typically 1%–5%) is selected for hand recount and compared against the machine tabulation. The selection may be random, predetermined by regulation, or based on specific criteria such as precinct size or contest closeness.
Traditional audits predate risk-limiting audits (discussed in the next section) and remain the most common form of post-election verification nationwide. Many states that have adopted RLAs still also require traditional audits in some form.
What they check. Whether the machine tabulation in the selected precincts matches a human hand count of the same ballots. This verifies counting accuracy: did the machines and humans arrive at the same numbers when reading the same ballots?
What they miss. Fixed-percentage audits check a small, predetermined fraction of precincts regardless of the margin. A 1% audit of a state with 3,000 precincts checks approximately 30. If the reporting error is in any of the other 2,970 precincts, the audit will not detect it. Unlike risk-limiting audits, traditional audits do not expand the sample in response to close margins or found discrepancies — the percentage is fixed by regulation, not by statistical need.
Traditional audits also typically check counting accuracy rather than reporting accuracy. An audit that hand-counts ballots and compares them to the machine tape confirms that the machine counted correctly. It does not check whether the machine’s totals were correctly reported upstream — uploaded to the county system, reformatted for state reporting, aggregated with other precincts, and published. The gap between “the machine counted right” and “the right numbers were published” is exactly the gap where reporting-layer errors occur.
The audit is also conducted by or under the supervision of the same officials who ran the election. It is a government checking its own work — valuable as an internal quality assurance process, but not equivalent to independent verification.
Relationship to AV. AV differs from traditional audits in three structural ways. First, AV covers every precinct where a recording is made, not a statistical sample — there is no 2,970-precinct blind spot. Second, AV checks the reporting layer specifically, which is the layer traditional audits typically do not examine. Third, AV’s evidence is captured and held independently, outside the government’s chain of custody. A jurisdiction with both a traditional audit and AV coverage has counting accuracy checked (by the audit, at sampled precincts) and reporting accuracy checked (by AV, at all covered precincts). Neither alone provides both.
Sources: MIT Election Data + Science Lab, “Post-Election Audits” (electionlab.mit.edu); Verified Voting, “Risk-Limiting Audits” (verifiedvoting.org/audits/whatisrla/) (includes comparison to traditional audits).
8. Risk-Limiting Audits (RLAs)
What they are. Statistically rigorous post-election audits designed to provide a quantifiable confidence level that the reported winner is the correct winner. Developed by UC Berkeley statistician Philip Stark, RLAs draw random samples of paper ballots, hand-count them, and compare the hand count to the machine tabulation. If discrepancies exceed a statistical threshold, the sample is expanded — potentially all the way to a full hand count. The key innovation is that the sample size adjusts dynamically: a race won by a large margin requires fewer sampled ballots to confirm the outcome; a close race requires more. This is both more efficient and more rigorous than checking a fixed percentage.
Colorado became the first state to adopt RLAs statewide in 2017. Georgia, Pennsylvania, Rhode Island, Virginia, and other states have since conducted or piloted RLAs to varying degrees. RLAs have strong support from the election security research community and are widely regarded as the gold standard for verifying vote counting.
What they check. Whether the reported winner is correct, with a quantifiable risk limit. For example, a 5% risk limit means there is at most a 5% chance that an incorrect winner would survive the audit without triggering escalation to a larger sample or full hand count. RLAs are optimized for the outcome question: did the right person win?
What they miss. Five structural limitations are relevant to the AV comparison.
First, RLAs verify counting accuracy, not reporting accuracy. An RLA compares hand-counted ballots against machine tabulation. It confirms that machines read ballots correctly. It does not check whether the machine’s totals were correctly transmitted from precinct to county to state to public. In Prince William County, Virginia (2020), a ~4,000-vote reporting error survived certification and a statewide risk-limiting audit that confirmed the counting layer with 99%+ confidence — because the error was in the reporting layer, which that audit did not check.
Second, RLAs are optimized for the winner, not the margin. An RLA can confirm that Candidate A beat Candidate B without precisely confirming the margin. A 4,000-vote reporting error in a race won by 60,000 votes does not threaten the outcome and would not trigger RLA escalation — but it still means the official results are wrong by 4,000 votes. For AV’s purposes, any discrepancy between a poll tape and the official results is significant, regardless of whether it threatens the outcome. Accuracy is the standard, not merely a correct winner.
Third, RLAs require government cooperation. They are conducted by or under the authority of election officials. An independent citizen cannot conduct an RLA — the process requires access to physical ballots, which are in government custody. This means RLAs depend on the institutional cooperation of the same officials whose work is being checked. In most cases, this works perfectly well: election officials are professionals who want to get the results right. But in the rare cases where cooperation breaks down — as in Warren County, Ohio (2004), where officials physically excluded observers from the count, or in Baldwin County, Alabama (2002), where the opposing party was sent home — RLAs provide no independent safeguard.
Fourth, RLAs audit specific contests, not the full ballot. A jurisdiction may RLA the presidential race but not downballot contests. Reporting errors affecting unaudited contests go undetected. The Monmouth County 2022 double-count affected a school board race — exactly the kind of low-profile contest that is often not selected for an RLA. The wrong candidate took office and served for two months.
Fifth, RLAs require voter-verified paper ballots. Jurisdictions using paperless direct-recording electronic (DRE) voting machines cannot conduct RLAs because there is no paper trail to audit. While paperless DREs are declining in use, they have not been fully eliminated from American elections.
Relationship to AV. RLAs and AV are the most natural complements in the election integrity landscape. They verify different layers (counting vs. reporting), they answer different questions (is the winner correct? vs. are the reported totals accurate?), and they operate under different authority (government-conducted vs. citizen-conducted). A jurisdiction with both an RLA and comprehensive AV coverage has the strongest available assurance: the RLA confirms that machines counted correctly, and AV confirms that the machine counts were correctly reported.
The complementarity is not merely theoretical. The Prince William County case is the canonical illustration: the RLA passed because it checked counting; AV would have caught the reporting error because it checks reporting. Together, they would have caught everything. Apart, each misses what the other catches.
Sources: Philip Stark, “Risk-Limiting Post-Election Audits: Why and How” (stat.berkeley.edu/~stark/); Verified Voting, “What Is an RLA?” (verifiedvoting.org/audits/whatisrla/); NCSL, “Risk-Limiting Audits” (ncsl.org); Carter Center, “Risk-Limiting Audits: A Guide for Election Observation Efforts”; Colorado Secretary of State, “RLA FAQs” (sos.state.co.us).
9. Full Hand Recounts
What they are. Complete hand counts of all paper ballots in a jurisdiction or contest, typically triggered automatically by close margins (most states define recount thresholds, often around 0.5% or narrower), by candidate petition, or by court order. In rare cases, a jurisdiction may conduct a full hand count proactively — as Georgia did for the 2020 presidential race, when Secretary of State Brad Raffensperger ordered a full hand tally of nearly five million ballots.
Full hand recounts are the most comprehensive check on counting accuracy available in American elections. They are also the most expensive, the most time-consuming, and the most logistically demanding.
What they check. Whether the machine tabulation matches a human interpretation of every ballot. Where an RLA samples and infers, a full hand recount examines everything. Every ballot is reviewed by human counters — typically in bipartisan pairs — and the human count is compared to the machine count. This catches counting errors at every precinct, for every contest, on every ballot.
What they miss. Full hand recounts verify counting accuracy, not reporting accuracy. A hand recount confirms what the physical ballots say. It does not systematically check whether the official results match the precinct-level machine totals that were transmitted through the reporting chain. The Georgia 2020 hand tally discovered memory card upload failures — reporting-layer errors in four counties totaling nearly 5,800 votes — but this was a side effect of checking counting accuracy, not a direct check of the reporting chain. The hand counters did not set out to find reporting errors; they found them because the hand count produced different totals from the reported results, and the investigation into the discrepancy traced it back to unfiled memory cards.
Full hand recounts are triggered only in exceptional circumstances. The vast majority of elections — including every uncontested race, every landslide, and most mid-margin contests — will never undergo a full hand recount. The Georgia 2020 hand tally happened only because the presidential race margin fell within the state’s recount threshold. If the margin had been wider by a few thousand votes, the upload failures would never have been discovered.
Hand counts also have their own error rate. The NC Supreme Court 2020 hand-to-eye recount of a random 3% sample illustrates this: bipartisan teams counting the same ballots produced results that differed from the machine count by small but nonzero amounts, due to differences in human interpretation of ambiguous marks, overvotes, and partially filled ovals. A full hand recount is not a perfect oracle — it is a different counting method with its own sources of error. In most contexts, the machine count and the hand count will agree closely, with discrepancies attributable to human interpretation rather than to machine or reporting errors.
Hand recounts are also conducted by officials under the authority of the same government that conducted the election. They are an internal re-checking process, not independent verification in the way AV is independent.
Relationship to AV. AV is not a recount and does not substitute for one. AV checks the reporting layer; recounts check the counting layer. But the two interact in several ways. AV can provide evidence that informs or motivates a recount: a large AV-detected reporting discrepancy might provide grounds for a recount petition, and AV’s precinct-level data can direct attention to the specific precincts where the discrepancy is concentrated — potentially making the recount more efficient or more targeted. Conversely, a recount that discovers reporting-layer errors (as Georgia’s did) validates the kind of check that AV performs systematically.
The NC Supreme Court 2020 case illustrates the gap that persists even after multiple recounts. Four separate counts — the original tabulation, the canvass, the full machine recount, and the hand-to-eye sample — verified counting accuracy from multiple angles. None systematically checked the 2,662-precinct reporting chain. A jurisdiction with both a recount and AV coverage has checked both layers.
Sources: NCSL, “Post-Election Processes: Recounts” (ncsl.org); NC Supreme Court 2020 case study; Georgia 2020 case study.
10. Cast Vote Record (CVR) Review
What it is. Analysis of the digital record of each ballot’s interpretation as produced by the scanner. When a scanner reads a ballot, it creates a cast vote record — a digital file recording how it interpreted each mark on each contest. The CVR shows, for every ballot, which candidates the scanner believed were selected, whether any contests were overvoted or undervoted, and in some systems, a confidence score for ambiguous marks. Some jurisdictions publish CVRs; others provide them through public records requests; others do not disclose them at all.
CVR review is a relatively recent addition to the election integrity toolkit, enabled by the increasing digitization of the scanning process. NIST published the first formal CVR data standard (NIST SP 1500-103) in 2019, providing a common format for CVR data — but adoption of the standard is not yet universal.
What it checks. Whether individual ballot interpretations are consistent with the reported totals, and whether there are patterns suggesting systematic misinterpretation. CVR analysis can reveal that a machine consistently misread marks for one candidate, that a batch of ballots was processed anomalously, or that the aggregate CVR totals do not match the reported results. Independent researchers and civic organizations have used CVR data to conduct large-scale analyses of counting accuracy, searching for statistical anomalies that might indicate machine error or manipulation.
What it misses. CVR analysis checks counting accuracy at the individual ballot level. It can reveal that a machine misread specific marks, or that a batch of ballots was processed anomalously. But it does not check whether the aggregated totals derived from those CVRs were correctly transmitted through the reporting chain to the official results. A CVR analysis might confirm that the scanner correctly interpreted 10,000 ballots — and the official results might still be wrong if the totals from those 10,000 ballots were incorrectly uploaded, reformatted, or aggregated.
CVR availability varies enormously by jurisdiction, and access can be contentious. Some jurisdictions publish CVRs proactively as a transparency measure. Others require formal public records requests, which may take weeks or months. Others argue that CVRs are exempt from disclosure, citing ballot secrecy concerns (even though CVRs do not contain voter-identifying information). The unevenness of access means that CVR review, however valuable in principle, is not a systematically available check across all jurisdictions.
There is also a deeper structural limitation: CVRs are produced by the same machine whose output they would be used to verify. If the machine’s software is compromised in a way that affects both the tabulation and the CVR — counting one way while recording another — the CVR will confirm the compromised count. A CVR is a second digital artifact of the same process, not an independent physical record. A poll tape, by contrast, is printed on paper at the precinct and can be photographed by an independent observer. It provides evidence from a different medium, not just a different file from the same computer.
Relationship to AV. CVR review and AV are complementary at different layers and through different mechanisms. CVR review provides ballot-level transparency into the counting process — how did the machine interpret each individual ballot? AV provides precinct-level transparency into the reporting process — were the machine’s totals correctly reported? A jurisdiction that publishes CVRs and has AV coverage provides the public with the most complete evidentiary picture available: ballot-level evidence of how machines counted, and precinct-level evidence of how counts were reported.
The key additional distinction is independence. CVRs are produced by and obtained from the government’s systems. AV’s evidence — the video recording of the poll tape — is captured independently by citizens and held in a public archive outside any government’s custody. For situations where the integrity of government-held records is itself the question, this independence matters.
Sources: NIST SP 1500-103, “Cast Vote Records Common Data Format Specification”; Votebeat, “What Is a Cast Vote Record, and Why Does It Matter?” (2022).
11. Ballot Image Audits
What they are. Review of the digital images of physical ballots produced by some scanning systems. When certain models of scanners process a ballot, they capture a high-resolution image of the paper — a photograph of exactly what the scanner saw. These images can be reviewed by humans or analyzed by independent software to check whether the scanner’s interpretation of each ballot was correct.
Ballot image audits represent a relatively new frontier in election transparency. The images themselves have been captured by scanners for years, but the idea of making them publicly available for independent review has gained traction only recently, driven by transparency advocates and academic researchers.
What they check. Whether the scanner’s interpretation of each ballot matches what a human reviewer sees on the ballot image. Ballot image audits can catch counting errors that even poll tape verification would miss: a mark that the scanner misread as an overvote, a ballot that the scanner skipped entirely, a systematic calibration error that caused a scanner to misinterpret marks in a specific position on the ballot. Because the images show the actual marks on the paper, they provide the closest available digital approximation of what a hand recount would find — without the logistical demands of physically handling millions of ballots.
What they miss. Ballot image audits verify counting, not reporting. They confirm that the scanner read each ballot correctly. They do not check whether the scanner’s totals — however accurate at the counting level — were correctly transmitted to official results through the reporting chain. This is the same structural limitation shared by every counting-layer verification approach in this section.
Ballot image availability is even more restricted than CVR availability. Most jurisdictions do not make ballot images publicly available. Access typically requires litigation, and some states have laws that expressly prohibit disclosure of ballot images, treating them as equivalent to the ballots themselves for secrecy purposes. Where access has been obtained, it has often required years of sustained advocacy and legal action.
Like CVRs, ballot images are produced by the scanner itself. If a scanner were compromised in a way that affected both its tabulation and the images it captured — showing marks differently than they appeared on the physical paper — the images would confirm the compromised count. This is a theoretical concern; no documented case of ballot image manipulation has been established. But the structural point stands: ballot images are a product of the system being audited, not an independent record from outside that system.
Relationship to AV. Ballot image audits and AV are deeply complementary, and the complementarity runs in both directions. Ballot image audits can catch counting errors that AV cannot detect: if a scanner misreads a ballot, the poll tape will reflect the miscount, and AV — which compares the tape to the official results — will not flag it because both the tape and the results will show the same wrong number. AV catches reporting errors that ballot image audits cannot detect: if the scanner counted correctly but the results were misreported during aggregation, the ballot images will confirm the correct count but will not show the downstream reporting error.
Together, they cover both layers. A jurisdiction that makes ballot images publicly available and has AV coverage gives the public the ability to independently verify both that ballots were counted correctly (through the images) and that the counts were correctly reported (through AV). Neither alone provides what both together provide.
The practical challenge is that ballot image access is far more restricted than poll tape access, making ballot image audits harder to conduct. Poll tapes are posted publicly on election night in many states; ballot images are almost never available without formal requests or litigation. This difference in accessibility is one reason AV focuses on poll tapes rather than ballot images — the evidentiary material is more widely and more immediately available.
Sources: Verified Voting, ballot image research and advocacy; Section 13.5 of this manual.
12. FOIA and Public Records Campaigns
What they are. Organized efforts to obtain election records — cast vote records, ballot images, poll tapes, tabulator logs, election management system reports, internal communications, chain-of-custody documents — through the federal Freedom of Information Act or state-level public records laws. FOIA campaigns are not a verification method themselves; they are the mechanism through which verification becomes possible. The records obtained can support RLAs, CVR analysis, ballot image review, independent retabulation, and AV-style poll tape comparison.
Election transparency organizations, academic researchers, investigative journalists, and individual citizens have used public records laws to obtain election data for decades. Some of the most significant discoveries in election integrity — including the Shelby County software bug, the Butler County irregularities, and the Prince William County reporting errors — were made possible by public records access.
What they check. FOIA campaigns do not check anything directly. They obtain the raw material that enables checking. The value of a FOIA campaign depends entirely on what is done with the records after they are obtained — who analyzes them, using what methods, and how the findings are communicated.
What they miss. Speed. FOIA requests are slow. Response times range from days to months, and jurisdictions that resist disclosure can delay through exemption claims, fee demands, redaction disputes, and appeals. For analyses intended to produce findings before certification — typically two to four weeks after election day — FOIA is often too slow. The Shelby County poll tape discrepancy was discovered because Bennie Smith photographed the tape on election night. Had he instead filed a FOIA request for the tapes, the response might have arrived weeks or months later — well after the certification window had closed.
Access is also not guaranteed. Jurisdictions may deny requests, claim exemptions, redact records, or charge prohibitive copying fees. Some states have laws that restrict access to specific election records. Litigation may be required, adding months or years of delay. And even when records are eventually produced, they have been in government custody since the election — meaning their integrity depends on the chain of custody maintained by the officials from whom they were obtained. In Ohio 2004, 56 of 88 counties destroyed their election records despite a federal preservation order and a pending federal lawsuit. FOIA cannot produce records that no longer exist.
Relationship to AV. FOIA is one of AV’s access methods. AV users in non-posting states can obtain poll tapes through public records requests when other access methods — election-night recording of publicly posted tapes, poll observer access, or in-person inspection at election offices — are not available.
But AV’s preferred access methods produce evidence that has three advantages over FOIA-obtained records. First, timeliness: a poll tape recorded on election night is available immediately, not weeks or months later. Second, independence: a tape photographed or recorded by a citizen at the polling place has never been in government custody — its chain of custody begins with the AV user, not with the officials whose work is being checked. Third, permanence: an AV recording in the public archive cannot be lost, destroyed, or withheld through FOIA exemptions.
AV complements FOIA campaigns rather than replacing them. FOIA can obtain records that AV users cannot access — tabulator logs, EMS reports, internal communications, chain-of-custody documents. AV produces one specific piece of evidence — the poll tape total — with greater speed, independence, and evidentiary security than FOIA can typically provide. Organizations that conduct FOIA-based election analysis and organizations that use AV are natural allies.
Sources: Section 7 (Access Methods) of this manual; Reporters Committee for Freedom of the Press, “Open Government Guide” (various state entries on election records).
14.5 — Part IV: The Structural Gap
The layer nobody systematically checks
The twelve approaches described above constitute the most comprehensive system of election integrity safeguards in the world. American elections are observed, tested, audited, recounted, and scrutinized at a level unmatched by any other democracy. This is not a system in failure — it is a system with a specific, identifiable gap.
The gap becomes visible when we ask a simple question of each approach: does it verify that the numbers printed on precinct-level poll tapes match the numbers in the official certified results?
Federal certification does not. It tests the machine as manufactured, not the reporting chain as operated. State certification does not, for the same reason. Logic and accuracy testing verifies that machines produce correct outputs under test conditions, but does not follow those outputs through the reporting chain. Poll watchers observe procedures but do not systematically record and compare data. Parallel testing verifies counting under election-day conditions but does not check reporting. The canvass reconciles ballot counts but does not systematically compare candidate-level tape totals to official results. Traditional audits check counting at sampled precincts. Risk-limiting audits confirm the winner with statistical rigor but do not verify the margin or the reporting chain. Full hand recounts verify counting comprehensively but check reporting only incidentally. CVR review and ballot image audits provide ballot-level counting transparency but do not track totals through the reporting process. FOIA campaigns obtain records but depend on government cooperation and government custody.
Every one of these approaches — with the partial exception of the canvass — focuses on the counting layer: did the machines read the ballots correctly? This is an important question, and the fact that so many approaches address it reflects appropriate concern about counting accuracy.
But there is another question that matters just as much: were the machine’s counts correctly reported? Were the numbers that the tabulators printed on their poll tapes faithfully transmitted — uploaded from memory cards, reformatted for reporting systems, aggregated across precincts, reconciled across counties, and published as official certified results — without error, omission, or alteration?
This is the reporting layer, and almost nothing systematically checks it.
The consequences of this gap are documented throughout the case study collection:
Prince William County, Virginia (2020). A ~4,000-vote reporting error survived certification and a statewide risk-limiting audit that confirmed the counting layer with 99%+ confidence — because the error was in the reporting layer, which that audit did not check. Nobody caught it for over a year.
Monmouth County, New Jersey (2022). The official post-election audit reported “tabulation accuracy was 100%.” The wrong candidate was certified as winner of a school board race and took office. Votes on six flash drives had been counted twice — a reporting-layer failure invisible to counting-layer verification. A citizen who noticed 311 phantom votes was told he was comparing “apples to oranges.” It took two months to identify the error and a court order to correct the result.
Georgia (2020). Memory cards from scanners in four counties were never uploaded to election management systems. Nearly 5,800 votes were missing from official results. Every scanner had counted correctly. Every tape had printed correctly. Every paper ballot was intact. The only failure was the transmission of results from precinct to county — and the only reason anyone found out was that an extraordinary statewide hand recount happened to be triggered by a close margin.
Shelby County, Tennessee (2015). 1,001 votes were dropped between poll tape and official results — all from areas with large concentrations of Black voters. The county had stopped comparing poll tapes to official results years earlier to save money. One person with one photograph of one poll tape uncovered the discrepancy, exposed a systemic bug, and changed the trajectory of elections in the county.
North Carolina Supreme Court (2020). The closest statewide race in North Carolina history — 401 votes out of 5.4 million. Four separate counts verified counting accuracy from multiple angles. None systematically checked the 2,662-precinct reporting chain.
In every case, the existing safeguards checked counting accuracy and missed reporting accuracy. In every case, AV — which checks reporting accuracy — would have flagged the discrepancy.
What AV uniquely provides
Actual Vote is the only approach in the current election integrity landscape that:
-
Operates at the reporting layer specifically. AV does not verify counting. It verifies that the counting output — the poll tape — was correctly transmitted to official results. This is its purpose, and this is the gap it fills.
-
Covers every precinct where a recording is made. AV is not a statistical sample. It does not check 1% or 3% or even 10% of precincts and infer the rest. It produces evidence for every precinct where an AV user records a tape. More coverage means more verification.
-
Produces evidence held independently of the government. AV recordings are captured by citizens and stored in a public archive that no election official controls. This evidence cannot be lost through negligence, destroyed by policy, or withheld through exemption claims. It exists outside the government’s chain of custody — which is the entire point when the question is whether the government’s reported results match its own precinct-level evidence.
-
Can be conducted by citizens without government cooperation (in states that require public posting of poll tapes). In posting states, the evidence is physically available on the wall of the polling place after polls close. No permission is needed. No FOIA request is required. No cooperation from election officials is necessary.
-
Creates a permanent, publicly accessible evidentiary record. AV recordings — video with embedded GPS coordinates, timestamps, and device metadata — are archived permanently and made available for public inspection. This evidence can be revisited, reanalyzed, and cited years after the election.
-
Operates on election night. AV evidence is captured when the poll tape is printed — the same night the election occurs. This is days or weeks before certification, months before FOIA responses, and often before the canvass is complete. Early evidence is more valuable than late evidence: it enables challenges within the certification window, informs canvass decisions, and prevents the normalization of unchecked results.
None of these properties is shared by any other approach in the landscape. Some approaches share one or two — poll watchers operate on election night, FOIA campaigns produce independent evidence, RLAs provide rigorous verification. But no other approach combines all six. AV’s design reflects a deliberate attempt to fill the specific gap that the existing landscape leaves open.
Not competition — completion
It is important to conclude this section with a point about posture. AV is not in competition with any of the approaches described above. It does not replace RLAs, audits, recounts, certification programs, observer programs, or FOIA campaigns. It does not argue that those approaches are failing. It does not claim to be sufficient on its own.
What AV provides is the missing piece. A system with RLAs and AV is more robust than a system with only RLAs. A system with observer programs and AV produces more durable evidence than a system with only observers. A system with FOIA access and AV has both government-held records and independently-held records — two sources that can be compared against each other.
The analogy from the manual’s philosophy section bears repeating: publicly traded companies submit their own financial reports, and independent auditing firms verify them. Nobody argues that independent audits are adversarial to the companies — they are a structural safeguard that makes the entire system more trustworthy. AV is the independent audit of vote reporting. Its existence strengthens confidence in the system, whether or not it finds discrepancies.
14.6 — Summary Table
| Approach | Layer Checked | Timing | Authority | Coverage | Checks Reporting? |
|---|---|---|---|---|---|
| Federal certification (EAC) | System design | Pre-election | Government | All certified systems | No |
| State certification | System design | Pre-election | Government | Varies by state | No |
| Logic & accuracy testing | Counting | Pre-election | Government | All deployed machines | No |
| Poll watchers / observers | Procedures | Election day | Mixed | Incomplete | No |
| Parallel testing | Counting | Election day | Government | Rare / minimal | No |
| Canvass | Reconciliation | Post-election | Government | All precincts | Incidentally |
| Traditional audit (fixed %) | Counting | Post-election | Government | 1–5% sample | No |
| Risk-limiting audit | Counting (outcome) | Post-election | Government | Statistical sample | No |
| Full hand recount | Counting | Post-election | Government | All ballots | Incidentally |
| CVR review | Counting (ballot-level) | Post-election | Mixed | Where published | No |
| Ballot image audit | Counting (ballot-level) | Post-election | Mixed | Where available | No |
| FOIA campaigns | (Obtains evidence) | Post-election | Independent | Varies | Enables it |
| Actual Vote | Reporting | Election night | Independent | All covered precincts | Yes |
The structural gap: Every approach in this table except Actual Vote focuses primarily on the counting layer — whether machines read ballots correctly. None systematically verifies the reporting layer — whether the machine’s correct counts were correctly transmitted to official results. AV is the only approach that fills this gap, operating independently, on election night, at every precinct where a citizen makes a recording.