If I recall correctly, the signatures are only used to verify the actual packages (ie RPMs) prior to installation. Once installed, the package signatures serve no further use as the packages are discarded.
Verification of the files installed by various packages takes place against RPM's local database of all installed files -- but that can't tell you if the original package was trustworthy or not.