Minimum Accountability Procedures for Optical Scan Voting Systems
Archive record — page as published on ballotintegrity.org, October 2004. Procedures credited by the original page to VotersUnite!.

This was the most technically substantial page on the 2004 site. It set out a list of minimum accountability procedures for counties using optical-scan voting equipment — that is, systems in which voters mark a paper ballot by hand and a scanner reads it. The original page credited the procedures to the group VotersUnite!, and that credit is preserved. The material is summarised and attributed here rather than reproduced, since it was another organisation's work.
Why optical scan was the focus
Most public argument in 2004 concerned direct-recording electronic machines, where a vote existed only as an electronic record. Optical scan was widely regarded as the safe alternative, because the voter's own marked paper ballot survives the count and can be examined afterwards. The procedures on this page start from a sharper observation: a paper ballot only helps if something in the process actually depends on it. If the reported result comes from a scanner and an aggregation system, and the paper is never consulted, then the paper is a reassurance rather than a control.
That is the same argument made more generally on the statement of purpose and applied to central tabulation on the parallel accounting page. Here it was worked into specific operational recommendations, in three parts.
Part one: counting and posting
The first recommendations concerned what happened at the close of polls. In summary, the procedures asked that federal contests be hand counted in public view at the polling place before any results were transmitted; that all precinct totals be posted at the polling place; that electronic accumulation of totals be permitted to run alongside; and that where the hand count and the machine count disagreed, the hand count should control.
Each element does distinct work. Counting before transmission removes the transport and communication stage from the chain of custody for the number that first enters the public record. Posting at the precinct creates a record held by observers and passers-by rather than only by the system. Permitting electronic accumulation in parallel keeps the fast, convenient reporting that election night requires. And making the hand count controlling is what converts the paper from a reassurance into an actual control — it is the clause that gives every other clause its force.
Part two: election transparency
The second group of recommendations concerned observation. The procedures asked that all parts of the process — pre-election testing, tabulation and any auditing — be open to observers, and that observers wear identification showing both their name and who they were there on behalf of.
The second half of that is worth pausing on, because it cuts against the reflex reading of a 2004 activist document. The procedures asked observers to identify their own affiliation, not merely to be admitted. A rule that opens a process to observation while requiring observers to declare who sent them is a rule designed to be acceptable to the people running the process, and it is consistent with the procedural, non-accusatory register described on the plan page.
Part three: software and ballot definition data
The third group was the most technical and, judged from a modern standpoint, the most far-sighted. It concerned ballot definition — the data file that tells a scanner what is on the ballot, which mark position corresponds to which contest and candidate, and how to record each result. A scanner is not intelligent; it counts marks in positions according to that file. An error in ballot definition produces a confident, fast, entirely wrong count, and it is the single most common source of serious tabulation error in real elections.
The recommendations were, in summary: that ballot programming be prepared by county officials rather than by the equipment vendor; that logic-and-accuracy test decks be prepared by the county rather than supplied with the system; that those decks cover every ballot style in use and deliberately include overvotes, undervotes, blank ballots and poorly marked ballots rather than only clean ones; that observers be permitted to add their own test ballots to a deck; and that pre-election testing be conducted publicly.
The reasoning is straightforward and does not depend on suspecting anyone of anything. A test deck supplied by the same party that supplied the system tests only what that party thought to test. A deck built independently, including the awkward cases, tests the system against the ballots that actually arrive. And allowing an observer to insert an unpredictable ballot is the difference between a demonstration and a test.

In context: how this is handled today
Almost every element of the third section is now standard practice, arrived at independently and codified far more thoroughly than this page proposed. Pre-election logic and accuracy testing is required by law in the great majority of states, generally with statutory requirements about notice, public access and the retention of test materials; the National Conference of State Legislatures maintains comparative summaries of state standards, testing and certification law. Public observation of testing and canvassing is likewise governed by state statute rather than by negotiation.
At the federal level, the system-level questions the page raised are handled through a published certification process administered by the Election Assistance Commission, under which systems are tested against the Voluntary Voting System Guidelines by laboratories accredited for the purpose, with the technical basis for the guidelines developed through the NIST voting programme. The results are not confidential: the commission publishes a register of certified voting systems together with the associated test reports and any subsequent modifications. That register, and the process behind it, is described in more detail on the certification background page.
The one recommendation that did not become universal practice is the first: hand counting federal contests at every precinct as the controlling count. The function it was meant to serve — an independent check of machine totals against paper — is instead performed after the fact by post-election and risk-limiting audits, which achieve comparable assurance for a small fraction of the labour. That trade-off, between counting everything imperfectly and sampling rigorously, is the substantive difference between 2004 practice and current practice.
About this archive
This page is part of an archival restoration of ballotintegrity.org, the website of the National Ballot Integrity Project, a volunteer citizen coalition that was active in the United States between roughly 2004 and 2006. The organisation is no longer operating. Everything described here in the past tense is a historical record of what the project published or proposed at the time. Positions taken by the project are reported as its own contemporaneous positions and are not endorsed here.
Nothing on this site is a current campaign, a current call to action, or a statement about any election, candidate, official or organisation after 2006. Personal names, contact details, petition and sign-up material, and third-party articles that appeared on the original pages are not reproduced. The National Ballot Integrity Project was a separate and unrelated body from any similarly named organisation operating today.