Document fraud detection: how to spot a fake document

September 29, 2026
Blog Image

A fake tax notice, altered bank details, a doctored payslip, a printed ID card: document fraud is now within anyone's reach. Websites sell ready-to-fill templates, and generative AI produces convincing documents in seconds. Document fraud detection can no longer rely on an analyst's eye. Here are the types of forgery, the signals that give them away and the detection methods that work.

The four forms of document fraud

  • Complete forgery: a document fabricated from scratch, often from a template found online or generated by AI.
  • Falsification: a genuine document with one part altered — an amount, a name, a date, an IBAN. This is the most common form, and the hardest to see.
  • Counterfeiting: the reproduction of a secure official document, such as an ID card or residence permit.
  • Fraudulent use of a genuine document: an authentic document used by someone other than its holder. Here the document is real; it is the identity that is stolen.

Each form calls for a different check. A solution that only verifies document authenticity will miss identity theft; a solution that only does biometrics will miss falsified bank details.

The most commonly forged documents

  • ID documents: national ID cards, passports, residence permits, driving licences.
  • Proof of income: payslips, tax notices, employment contracts.
  • Banking documents: bank details (IBAN) and account statements.
  • Proof of address: energy and phone bills, rent receipts.
  • Company documents: registration extracts, articles of association, certificates.

How to detect a fake document: the signals

Visual inconsistencies

A font that changes on a single field, misaligned text, irregular spacing, an area sharper or blurrier than the rest, a pixelated logo, a non-uniform background around a figure: falsification almost always leaves a local trace.

Internal inconsistencies

A document must be consistent with itself. On a payslip, net pay must follow from gross pay and contributions. On an ID document, the MRZ encodes the printed information and includes calculated check digits: an MRZ that does not match the visible fields is a strong signal. An IBAN also has a check key.

File metadata

A PDF keeps a record of its history: creation software, creation and modification dates, number of versions, embedded fonts. A payslip "issued by payroll software" but edited in a PDF editor the day before it was sent deserves a second look. Note: the absence of suspicious metadata proves nothing, and a screenshot or scan wipes this information.

Inconsistencies between documents

This is often where fraud shows most clearly. Does the name on the bank details match the ID? The address on the tax notice match the proof of address? The salary on the payslip match declared income? Does the employer actually exist in the business register? Fraudsters rarely take the same care with every document.

Verification at the source

The most reliable check is not to trust the document and to query the issuer or a register instead:

  • the 2D-Doc, a signed barcode found on many French supporting documents (energy bills, tax notices, administrative documents), lets you verify that the data has not been changed;
  • a tax notice can be verified with the tax authorities;
  • a company registration extract can be compared with business register data;
  • an IBAN can be matched against its account holder.

Why the human eye is no longer enough

An experienced analyst spots crude forgeries. They cannot see a change of a few pixels, cannot read metadata on every file, and cannot cross-check five documents in thirty seconds. At high volume, fatigue does the rest.

Generative AI has changed the game: it produces documents without the classic visual defects, as well as convincing ID images. Detection must therefore combine several layers — image analysis, metadata, internal consistency, cross-document consistency and source verification — rather than rely on a single signal.

Building an effective fight against document fraud

  • Check every document in the file, not just the ID.
  • Prefer the original file over a photo or scan whenever possible: it contains more usable information.
  • Systematically cross-check information between documents and against official sources.
  • Link the document to the person: biometric verification with liveness detection rules out the use of a stolen document.
  • Record every check: the reason for a rejection must be explainable to the customer and to the supervisor.
  • Keep humans for ambiguous cases, with the detected signals in front of them.

Document fraud detection with Dataleon

Dataleon's document fraud module analyzes every document uploaded — ID, company registration, bank details, payslips, supporting documents — combining visual analysis, metadata, internal consistency and cross-document checks. Every alert is explained: your analysts see why a document is suspicious, and no longer waste time on clean files. To choose a tool, see also our guide document fraud software: selection criteria.

FAQ

How can you tell if a PDF has been modified?

Metadata (creation software, modification dates, successive versions) and analysis of the file structure provide clues. But a re-scanned or photographed file loses this information: you then have to rely on visual analysis and cross-checking.

Can an AI-generated fake document be detected?

Yes, but rarely through a single check. Generated documents often reveal content inconsistencies (invalid numbers, wrong calculations, data that matches no register) rather than visual defects.

Is using a fake document a criminal offence?

Yes. In France, forgery and use of forged documents are punishable under the Criminal Code (Article 441-1). For an obliged entity, a detected forgery may also justify a suspicious activity report.

Request a demo to test detection on your own documents.

Auteur
Dataleon

Autres blogs connexes

No items found.

Frequently Asked Questions

Does Dataleon provide support?
Yes. Every client receives dedicated support, including technical assistance via email and video conferencing, comprehensive documentation, and code samples for integrating our APIs. Our engineers help you define your KYC and KYB workflows, complete the integration, and go live without service interruption. A dedicated point of contact remains available afterward to monitor your volumes, adjust your control rules, and answer your business and technical questions.
Are my files deleted after processing?
Yes. Your documents are encrypted in transit and at rest, processed, and then automatically deleted after the retention period you define. You remain the sole owner of the data transmitted: it is neither resold nor used for any purpose other than performing your checks. You can also trigger the immediate deletion of a file from the interface or via the API, keeping only the analysis results necessary for your compliance obligations.
Can Dataleon be integrated into our tools via API?
Yes. Dataleon connects to your information system via a documented REST API, real-time webhooks, and connectors for your existing tools, such as CRM, core banking, DMS, or electronic signature solutions. Verification flows, scoring rules, risk thresholds, and validation workflows are fully customizable to align with your internal procedures. Our teams can also develop custom processes if your specific use case requires it.
Can I test Dataleon before committing?
Yes. You can enjoy a 15-day free trial, with no obligation, to verify your own identity documents, proof of address, and business documents, and to evaluate the quality of our extraction and KYC/KYB checks. During these 15 days, you will have access to the interface and test API keys to validate your end-to-end technical integration. We also offer a personalized demo with an expert to help you build a workflow tailored to your business.
Are you GDPR compliant with servers located in France?
Yes. Dataleon is GDPR compliant, and all data processing and storage are carried out in France on the infrastructure of Scaleway, a sovereign French hosting provider. We implement encryption for data in transit and at rest, data minimization, granular access control, and full audit trails for all operations. A Data Processing Agreement (DPA) and our security documentation are provided to facilitate your internal and regulatory audits.

Automation that makes compliance invisible.

Dataleon, the missing link between your compliance and your growth. KYC, KYB, and AML-CFT, finally all in one place.