Auditing the voter register: purpose, impact, and where we are at the moment

The purpose of the audit is to determine, on the basis of evidence, whether the Unified Voter Register can be trusted — and to correct the problems it finds. It does this by testing both the accuracy of the data and the resilience of the system that maintains it, proceeding in sequence from first indications, through deeper checks, to findings and conclusions.
08.06.2026.
Latest update · 17 July 2026

Progress has been made in establishing the conditions to begin the substantive audit of the voter register.

1. Access to data. Commission members have been given access to the Unified Voter Register, including the history of changes. A secure technical environment to analyse it efficiently is still being set up.

2. Cross-checking with source records. Work with the Office for IT and eGovernment on cross-checking the register against source records - primarily civil registries, residence records and the citizenship register - is under way, with first results on the model for this cooperation expected during July.

3. Local audits. The audit of the parts of the register for the municipalities that held elections in March has begun; the first three are expected to be completed by the end of July.

A substantive audit can proceed only once the technical environment is in place and full access is confirmed in practice.

Voter register audit: 24 of 69 checks are now fully or partly possible as data access widens

CRTA's July 2026 assessment maps the full audit methodology against the data access granted to the Commission. Following an expansion of access, 12 checks can now be carried out in full and 12 more in part, while 45 remain blocked. Full access, required by Article 22j of the UVR Law, has still not been provided.

CRTA · July 2026 · crta.plus
Export

The four aims

AccuracyDo entries match the real, lawful situation?
ResilienceIs the system protected from error and abuse?
EfficiencyAre records kept and updated in time?
AccountabilityCan a fault be traced to its cause?

How the audit creates impact

Findings are not the end point. Each one feeds a step that changes the register and the system around it — and contributes to confidence-building in the UVR.

Findingserrors and weaknesses Correctfix, add, or remove entries Strengthenclose the gaps Accountwho, where, why Report to theAssembly & the public Confidence-buildingin the UVR enabled

The audit program at a glance

The structure of the methodology. Colours show whether the procedures in each phase/level can be performed with the current access granted; no phase or level is yet fully possible. Each box is clickable — select one to jump to that part of the detailed program below.

every procedure fully possible — not yet reached by any groupsome procedures possible or partialnone can run
Phase 1 · Find signals1 possible · 1 partial Phase 2 · Cross-check0 possible · 2 partial of 3 Phase 3 · Legal validation1 possible · 1 partial Phase 4 · Field verification0 of 2 procedures possible Level 1 · Central register1 possible · 1 partial of 3 Level 2 · Local updating1 of 6 procedures possible Level 3 · Source registers1 of 3 procedures possible Area 1Accuracy of data Area 2System resilience Audit of thevoter register
Phase 1 · Find signals2 of 2 available Phase 2 · Cross-check3 of 3 available Phase 3 · Legal validation2 of 2 available Phase 4 · Field verification2 of 2 available Level 1 · Central register3 of 3 available Level 2 · Local updating6 of 6 available Level 3 · Source registers3 of 3 available Area 1Accuracy of data Area 2System resilience Audit of thevoter register

The access story over time

Through the first half of 2026 the Commission's access stayed at record-by-record queries. In July it widened — some aggregate profiling and partial cross-checks became possible — but it still falls short of the full access the law provides, and the deadlines and reporting obligation continue to run. The graph shows the access actually provided against the full access the law mandates (dashed).

Click to enlarge Jan Feb Mar Apr May Jun Jul Aug Sep Oct today 28 Jan Commission established March 2 · work plan adopted 12 · individual UVR query 10 Apr · MDULS denies access 18 Apr · MUP/KITE assurances 29 Apr · civil-registry query 31 May deadline for full access 17 Jul access widened 30 Sep audit wrap-up 28 Oct report due to the Assembly Data access provided Full None the gap — access still short of what the law requires full access granted by UVR law (Art. 22j) limited — individual queries only partial — some aggregate & cross-checks
Select a point on the timeline for detail.

How much of the audit can be performed

Data access
17% 17% 65%
12checks performable in full
12partially performable
45cannot be performed (of 69)
100%
69checks performable in full
0partially performable
0cannot be performed (of 69)

Select a bar segment or a figure above to list the checks it covers.

12 checks that can be performed in full
  • Aggregate profile of the register by category
  • Outlier rate of changes per individual voter
  • Identification of missing data
  • Logical-consistency checks
  • Arithmetic-consistency checks
  • Field syntax and meaning checks
  • Referential-integrity checks
  • Preliminary examination of a complaint’s data
  • Legal validity of the decisions underlying register changes
  • Full review of laws, by-laws, arrangements and controls governing the register
  • Full review of competences, deadlines, remedies, decision trails and controls in updating
  • Full review of the normative framework governing source registers
12 checks that are partially possible
  • Outlier number of voters per address / household
  • Outlier permanent-residence changes
  • Outlier temporary-residence changes
  • Consistency with residence records
  • Consistency with civil registries
  • Consistency with the citizenship register
  • Legal basis for establishing residence, incl. naturalised citizens
  • Process of public display by polling station
  • Pre-election closing of the register
  • Consistency of displayed data with the register
  • Consistency of extracts used with the register
  • All current and historical data, by period
45 checks that cannot be performed
  • Aggregate profile of civil, residence and other registers
  • Outlier passivisation changes
  • Outlier citizenship changes
  • Outlier border-police data
  • Outlier civil-registry data
  • Consistency with the IDP register
  • Consistency with legal-capacity, sanctions and military-service records
  • Consistency of changes, register vs source
  • Statistical analysis of mismatches
  • Consistency with census data (SORS)
  • Consistency with other central-registry data
  • Addresses vs the Address Register (RGA / Post)
  • Consistency with household data from other records
  • Consistency with other relevant registers
  • Spatial clustering of mismatches
  • Verify register entries against citizens’ real circumstances
  • Verify citizens’ real circumstances against the register
  • Access management
  • Change controls
  • Action logging and audit trail
  • Data integrity and quality
  • Stability, availability and continuity
  • Change and maintenance management
  • Legal and organisational maintenance framework
  • General security and data protection
  • Map of entry / deletion / amendment rights by authorisation
  • Quality of access-log security during updating
  • Legal review of officials’ authorisations
  • Process of receiving changes, drafting and forwarding decisions
  • Quality of training vs required competences
  • Material and financial resources for updating and how they are used
  • Recruitment and engagement of officials who maintain the register
  • The inspection process and follow-up on ordered measures
  • Access management
  • Protection against unauthorised changes
  • Action logging and traceability
  • Data integrity and quality
  • Stability and continuity
  • Change and maintenance management
  • Legal and organisational maintenance framework
  • General security and data protection
  • Recording life-fact changes into source registers
  • Recording residence changes
  • Dual-citizenship acquisition process
  • Data exchange with competent authorities
Progress has been made in establishing the conditions to begin the substantive audit of the voter register. Following the expansion of access, 12 of the 69 checks can now be carried out in full — the three legal reviews, the intake of citizen complaints, the legality of entry and deletion decisions, and most of the whole-register quality scan. A further 12 can be done in part, chiefly the cross-checks against source registers and the review of register extracts and historical displays. The remaining 45 — everything that needs the register’s full change history, the deep cross-referencing against other registers, the field sample, and the security of the IT systems — still cannot be performed.
With the full access the law provides (Art. 22j), all 69 checks across the 21 procedures could be carried out — the audit could be completed as the methodology designed.

The audit program and its coverage

The methodology defines 69 individual checks under 21 procedures. Each row shows the evidence a procedure requires and whether that evidence has been made available. Select any row to see the checks within it.

Detail Show
Area 1 — Is the data accurate?From the first signal of an inaccuracy to a confirmed or dismissed conclusion.
Phase 1 · Find the signals
2.1.2Whole-register quality scanPartially 8
2.4.3Handling citizen complaintsCan be performed 1
Phase 2 · Cross-check the registers
2.3.2Quality scan of the source registersPartially 7
2.3.5Match register against source recordsPartially 7
2.3.6Verify against census, address and other registriesCannot be performed 6
Phase 3 · Legal validation
2.2.3Legality of entry and deletion decisionsCan be performed 1
2.3.3Legality of the residence basisPartially 1
Phase 4 · Field verification (the final step)
2.4.1Field check — register to citizensCannot be performed 1
2.4.2Field check — citizens to registerCannot be performed 1
Area 2 — Is the system resilient?Whether the legal, organisational and IT framework prevents, detects and corrects error and abuse.
Level 1 · The central register
2.1.1Legal review — central-register frameworkCan be performed 1
2.1.4Security of the central IT environmentCannot be performed 8
2.1.3Verify register extracts and historical displaysPartially 5
Level 2 · Local updating
2.2.1Legal review — local-update frameworkCan be performed 1
2.2.2Abuse risk in change authorisationCannot be performed 2
2.2.5Officials’ authority and trainingCannot be performed 3
2.2.6Resources for updatingCannot be performed 1
2.2.7Integrity of hiringCannot be performed 1
2.2.4Review of inspection supervisionCannot be performed 1
Level 3 · The source registers
2.3.1Legal review — source-register frameworkCan be performed 1
2.3.7Security of the source-register ITCannot be performed 8
2.3.4Officials’ conduct in residence and civil changesCannot be performed 4

What this means

Partial scope — analysis can begin

With the wider access now granted, the audit can begin substantive work: the legal framework can be reviewed in full and the register can be profiled as a whole. But on the evidence available it still cannot reach a firm conclusion on the accuracy or integrity of the register — the deep cross-checks, the full history of changes and a representative field sample remain out of reach. The scope is now partial rather than blocked.

What can be done now

  • Legal review of the rules governing the register, at all three levels
  • A quality scan of the register as a whole — profiling, consistency and integrity checks
  • Intake and review of citizen complaints, and the legality of entry and deletion decisions
  • Partial cross-checks against residence, civil and citizenship records

What is still missing

  • The full history of changes — basis, date, official, decision number
  • Deep cross-referencing against source and check registers (IDP, legal capacity, sanctions, census, address)
  • System logs and security configuration
  • A statistically representative field sample
The methodology’s own threshold. Data from any single register are not sufficient grounds for a conclusion where cross-checking with another register is technically possible. The access now available therefore cannot, on its own, meet the standard the Commission set for a finding — it can frame the work and begin the analysis, not complete it.

Annex — data access on record

View = can be seen, one record at a time. Aggregate = can be analysed across the register. Verify = can be independently confirmed. Following the July expansion, limited aggregate access has been granted for some categories (marked Partial); full aggregate analysis and independent verification remain unavailable. Cells marked Partial reflect the July expansion and are provisional, pending confirmation of the Commission’s current access record.

Data / recordViewAggregateVerify
Unified Voter Register
Individual current voter data (name, JMBG, residence, polling station, passivisation, IDP)YesPartialNo
Record of changes (basis, date, official, decision number)PartialNoNo
Legacy reporting module (missing / incorrect data)NoNoNo
ICT system logs (traces of unauthorised access)NoNoNo
Source registers
Current residence — permanent and temporaryYesPartialNo
Previous residence; passivisation of addressesPartialNoNo
Civil registries — births, deaths, marriagesYesPartialNo
Citizenship — yes/no search by JMBGYesPartialNo
Citizenship — full records; IDP; legal capacity; prison sanctionsNoNoNo
Cross-check registers
Inspection reports; statistics (SORS); address register; pension; health; tax; ID and passportNoNoNo

Sources. Adopted Act on the Audit Procedure (methodology of the Commission for the Revision, Verification and Control of the Accuracy and Updating of the Voter Register); Commission data-access record. The 69 checks counted here are the sub-procedures enumerated in the methodology, grouped under 21 procedures. Access status reflects Article 22j of the Law on the Unified Voter Register and the Commission’s recorded access as provided (updated July 2026).

Export

Last updated: 17 July 2026

Related Articles

CRTA.Plus is part of CRTA’s work to document developments related to democracy, the rule of law, and accountability in Serbia.
Crta @ 2026. All rights reserved.