Analysis · Sep 2026

How a doctored statement gives itself away

Underwriting rests on a document supplied by the party it describes. Almost all of them are honest, and the handful that are not are the expensive ones — which is why authenticity is checked the same way on every file rather than when something feels off. Two independent layers of evidence do the work: what the document says about itself, and what its numbers are obliged to add up to. Beating one is straightforward. Beating both, on the same file, is where forgeries fail.

  • Two independent layers, checked on every file
  • Metadata can be stripped; arithmetic cannot
  • A signal is a reason to look, never a verdict
Premise

Why the check runs on every file

Authenticity checking has a reputation problem: it sounds like an accusation. In practice it is the opposite of one. A check that runs only when a file feels wrong is a check driven by whatever the reader happens to be suspicious of that afternoon — and the merchants it lands on are the ones whose paperwork looks unfamiliar rather than the ones whose paperwork was edited.

Run on every file, the same forensics become boring, which is the goal. Most statements produce nothing. The ones that produce something produce it for a reason that can be named, shown, and argued with.

Layer one

What the document says about itself

A PDF carries a record of how it was made. None of these is proof on its own; together they describe a file that has been through more hands than a bank statement should.

  1. The tool that touched it

    Image editors, design tools, word processors and browser-based PDF editors leave their names in the document metadata or in its edit history. A bank statement generated by a bank does not pass through an image editor on its way to an underwriter.

  2. Timestamps that do not agree

    A modification date later than the creation date says the file was re-saved after it was produced. So does an incremental update — content appended to a PDF after it was first written — and so does a marker left behind when text is edited directly inside a PDF tool.

  3. Fonts that arrived separately

    When a page carries several embedded instances of the same underlying font, the text was not all laid down by one program. It is a quiet signal, and a specific one: it is what inserting a line into an existing page tends to leave behind.

  4. A history that is missing, or too generic

    Absent producer information, or a document produced by a general-purpose print-to-PDF engine rather than a statement generator, does not prove anything by itself. It does describe a file whose provenance cannot be read — which matters when the rest of the evidence has to carry more weight.

The countermeasure

Everything above can be erased in one step

Anyone who edits a document and then reads about metadata forensics arrives at the same idea within a few minutes: open the edited file, print it to a new PDF, and the entire first layer disappears. The new file was made by a printer driver, it has one creation date, no edit history, and a single consistent set of fonts.

Which is exactly why the first layer is not the check. It is the cheap half. A generic print engine on a document that claims to come from a bank is itself worth noticing, but the real work is done by the layer a re-print cannot touch, because it lives in the numbers rather than in the file.

Layer two

What the numbers are obliged to do

These survive any amount of re-printing, because they are properties of the content rather than of the container.

  1. The statement has to agree with itself

    Banks print their own totals: deposits in, withdrawals out, a balance at each end of the period. Those figures and the transaction rows are two descriptions of the same month, and they have to match. Changing a number without changing every place it feeds is the most common way a file breaks.

  2. The balance chain has to hold

    Where a statement prints a running balance on each row, every balance must follow from the one above it plus that row’s amount. Alter a single amount and the chain is broken from there to the end of the page — repairing it means rewriting every balance below, consistently, in a document that also has to keep agreeing with its own totals.

  3. Deposits behave like deposits

    Real inflows have texture. They carry cents, they vary, they cluster the way a business’s customers actually pay. A high share of perfectly round figures, or first digits that stray from the distribution genuine financial data tends to follow, is a reason to look more closely — never a conclusion on its own, since some perfectly honest businesses bill in round numbers on a regular cycle.

  4. The same deposit does not keep happening

    An identical amount from an identical payer, repeating across many different dates, is either a very unusual customer arrangement or a row that was copied to fill a month. Both are worth a question; only one of them has an answer the merchant can give.

Discipline

Signals, not verdicts — and an unknown is never a pass

Every one of these is reported as a signal with its own explanation, including what it might innocently be. A regular deposit pattern can fail a statistical test honestly. A bank’s own web portal can produce a file through a generic print engine. A merchant who scans and re-saves what their branch printed has a file with a history, and no intent behind it. Software is good at noticing; it is not entitled to conclude.

One rule matters more than the rest, and it is the same principle that runs through the rest of the report. There are three honest states, not two: checked and clean, checked and flagged, and not checked. A file where the forensics could not run is not quietly filed as verified. That distinction sounds academic until a list of merchants shows a column of green ticks, and some of them mean nothing was found while others mean nothing was looked at.

In practice

What to do with a flagged file

A flag is the start of a conversation, not the end of a deal. Most resolve immediately: the merchant downloaded a PDF from their banking portal, the broker combined pages into one file, a page was scanned because the online history only went back ninety days. Ask, and the answer usually arrives with the missing original attached.

When it does not resolve, the remedy is evidence rather than argument: the statement direct from the bank, a read-only connection to the account, or the months either side of the one in question. What should not happen is the flag quietly deciding the file on its own, in either direction — neither a decline on a signal nobody examined, nor an approval because the number underneath it looked fine.

FAQ

Common questions

How can you tell a bank statement PDF has been edited?

Through independent signals rather than one test: editing tools named in the document metadata or history, a modification timestamp after creation, content appended after the file was written, several embedded instances of the same font, and — separately from the file itself — totals that do not reconcile or a running balance that stops following from the row above.

Does printing to PDF hide an edit?

It removes the metadata layer, which is precisely why that layer is not the check. Re-printing cannot repair arithmetic: the statement still has to agree with its own printed totals and the balance chain still has to hold row by row.

What does it mean if deposits fail a statistical test?

That the inflows do not have the texture real deposits usually have — too many round figures, or first digits away from the usual distribution. It is a reason to look at the rows, not a conclusion. Some genuine businesses bill in round amounts on a fixed cycle and will fail it honestly.

Does a flag mean the statement is fraudulent?

No. Each signal is surfaced with what it is and what it could innocently be, and most flags resolve as soon as the merchant explains how the file was produced. The decision belongs to the underwriter, with the evidence in front of them.

What does "not checked" mean on a file?

That the forensics could not run on that document. It is reported as its own state rather than as a pass, because an unchecked file and a clean one are not the same thing and should never look the same in a list.

Keep exploring

Related

Check authenticity on every file, not on a hunch

Upload a statement and see the document signals and the arithmetic checks side by side.