Summary

  • According to Yinuo Technology, the online system used in the PKR polls was effective in securely and transparently documenting and tallying votes.

  • The audit finds no credible evidence of misconduct or irregularities, but recommends some improvements.


The independent auditor tasked with evaluating PKR divisional and branch-level polls has reported that the e-voting system functioned effectively, though with certain shortcomings requiring enhancement.

In its digital audit and forensic investigation report's executive summary, Yinuo Technology indicated that its assessment examined the system's architecture, security, protocols, and operational reliability, particularly focusing on the electronic Know Your Customer (e-KYC), voting app, and blockchain backend elements.

"An audit of the full voting process and stakeholder behaviour found no credible evidence of misconduct or irregularities. Internal audit procedures were also reviewed and deemed satisfactorily conducted.

"Several minor anomalies, such as issues with candidate sequence number display, application message confusion, and timing discrepancies, were identified and analysed.

“However, these issues were primarily related to front-end display bugs or user interface clarity and did not affect the core vote-counting logic or historical vote results," the firm said.

It noted that system developers provided root cause analyses and implemented prompt solutions.

Yinuo Technology said the e-voting system effectively accomplished its fundamental objective of securely and transparently documenting and tallying votes.

Despite certain aspects of user-facing components and internal consistency warranting improvement, the system exhibited considerable resilience and integrity, it added.

Rafizi’s recommendations

In a statement today, PKR deputy president Rafizi Ramli made several recommendations for improving the system, in time for the upcoming central polls.

These are:

  • Confirming the number of one-time password (OTPs) issued compared to the number of e-KYCs, votes on the S3 (Simple Storage Service) server and final votes recorded on the blockchain, to identify how many votes were lost due to system weaknesses.

  • Protecting the original version of the source code uploaded to the cloud server, ensuring the correct and same version is used throughout the election process, checking the entire source code for each uploaded version, to ensure no different code is processing the voting.

  • Protecting and controlling the source code deployment by checking the deployment logs before, during and after the voting process, to ensure system integrity is guaranteed.

PKR deputy president Rafizi Ramli

"The Central Election Committee is responsible for ensuring the central election process - including the validity and technical capability of the system runs smoothly, to avoid prolonged controversy after the central election is completed," Rafizi said.

He also attached links in his statement to the audit report and a post-audit analysis highlighting alleged discrepancies in the digital voting system.

Rafizi’s camp hit hard in divisional polls

Many who were known to be Rafizi's allies had lost to ordinary members in the divisional polls which were held between April 11 and April 20.

Among them were PKR vice-president Nik Nazmi Nik Ahmad, who lost the Setiawangsa divisional chief position, Johor Bahru MP Akmal Nasrullah Nasir (Johor Bahru) and Ampang MP Rodziah Ismail (Shah Alam).

Rawang assemblyperson Chua Wei Kiat (Selayang) and Sabah state minister Christina Liew (Kota Kinabalu) also lost.

This led to the Central Election Committee receiving multiple appeal applications.

However, following a meeting on May 4, during which the audit findings were presented, these objections appeared to have largely subsided.

The PKR central leadership committee decided to accept the results, paving the way for the central party election on May 23.

What's being challenged in post-audit report

Following the audit analysis, an independent technical review identified a list of alleged discrepancies in the e-voting system.

The report was commissioned by Anbarasan Murugesu, an unsuccessful Puchong PKR candidate.

The technical evaluation was conducted by IT experts Tham Chin Seng and Tan Tung Ai, both with relevant industry credentials.

"Our assessment has revealed a number of significant discrepancies and omissions in the execution and reporting of the official audit.

“Several high-priority items within the original audit checklist such as end-to-end process validation, source code review, server deployment log analysis, database integrity checks, and vote data reconciliation, were either only partially executed or entirely omitted.

"Additionally, the audit failed to provide supporting evidence for critical system behaviours, such as crash analytics, sampling methods, and user acceptance testing outcomes. These shortcomings raise substantial concerns over the reliability and completeness of the audit's findings,” they said.

"Moreover, certain risks that could materially impact the fairness, transparency, and accuracy of the voting process, such as OTP delivery failures, application crashes, and user interface confusion, were either understated or not thoroughly investigated," the duo added.

They asserted that a minority report had previously highlighted these issues and advocated for more thorough scrutiny, contending that the official audit had minimised their significance without sufficient evidence or justification.

In their conclusions, Tham and Tan also recommended a focused re-audit of the system, whilst cautioning that should this supplementary examination fail to confirm systemic integrity, a complete revote might be necessary.