Process

A perfect forgery
extracts perfectly.

A retouched document reads without effort: the fields come out clean, the amounts line up, nothing looks wrong on the page. Holofin checks what cannot be seen — the issuer's signature, the totals recomputed from scratch, and what the documents in a file say about each other.

Five independent levels, never melted into one scoreEvery signal explained, with the page it came from
CASE-2026-0914Lending
1 DOCUMENT AT RISK
Tax assessmentsealed
signature valid
Identity documentMRZ
check digits agree
Payslips3 months
net recomputed
Bank statement · March
3 signals
Recomputed closing balance ≠ printed balancestrong
Different font subset on the balance linemedium
PDF producer: consumer editorweak

A weak signal decides nothing on its own. What deserves a second look is three of them converging on the same document while every other document in the file checks out.

The problem

"Fake document"
means five different things.

They are not detected the same way, which is why a single check always lets something through. Someone reviewing a document by eye will catch one or two of these; the other three leave nothing to see on the page.

The fabricated document

Created from nothing, often by an online generator. The layout is plausible; it is the identifiers it carries that do not hold up.

Example: an invoice whose IBAN fails its mod-97 check digits and whose VAT number does not validate. Nobody recomputed either one.

The retouched document

A genuine document with exactly one value changed. Everything else on the page is authentic, the issuer's seal included.

Example: a bank statement whose closing balance went from 1,485.51 to 11,485.51 in a consumer PDF editor.

Someone else's document

A genuine document, untouched, whose seal verifies. Only the person is wrong.

Example: a sibling's bank statement, a parent's tax assessment, submitted as the applicant's own.

The expired or superseded document

The document was accurate on the day it was issued. It is not accurate today.

Example: a company registration extract from last year, a tax assessment for a superseded year, a certificate that has since been reissued.

The fictitious or inactive issuer

A company that never existed, or whose registration is no longer active. The document itself is perfectly well formed.

Example: a payslip whose named employer can confirm nothing, because it stopped trading eighteen months ago.

Only the second of these leaves a trace in the file itself. The third leaves no trace anywhere on the page — it is a true document, and nothing short of comparing it to the rest of the case will show it.

Documents controlled

Each kind of document
carries its own proof.

A sealed tax assessment is verified by the signature its issuer put on it. A bank statement is verified by its own totals. A company registration extract is verified by the check digits in its identifiers. The control cannot be the same for all of them, and a tool that applies one generic check to every document is really only checking the ones that happen to suit it.

Bank statement

Opening balance + credits − debits = closing balance. The running balance is recomputed line by line, and duplicated or out-of-order entries are flagged.

Payslip

Gross − deductions = net, recomputed from the lines the document itself prints. The named employer has to be the employer the rest of the case names.

Tax assessment

The most favourable case, when the issuer seals it: the signature is verified first, then every sealed value is compared to the value printed on the page.

Identity document

The machine-readable zone is validated for internal consistency: its own check digits have to agree with the names, dates and document number printed above them.

Company registration extract

Check digits on the registration number, agreement between the identifiers the extract carries, and how old the extract is. A generated forgery usually forgets the check digit.

Invoice

VAT arithmetic recomputed from the net and the rate, mod-97 check digits on the payment IBAN, and the issuing company checked against an official registry.

Steps

From a pile of documents
to signals you can argue with.

Five steps, always the same. Authenticity controls are not a separate pass: they run on the same case as the completeness controls, and they return a single verdict.

1

Intake and classification

The case arrives over the API, through an upload portal, over SFTP or in a dedicated mailbox. A bundled file is split into separate documents, then each document is recognised for what it is — which is what decides which controls apply to it. The filename plays no part in that decision.

2

Extraction

Every document returns its fields, each one with the region of the page the value was read from. Without this step there is nothing to recompute and nothing to compare: a fraud inconsistency is observed on values, not on a visual impression of the page.

3

Controls

The five levels run against the document and against the case: issuer verification, registry verification, recomputed internal consistency, cross-document consistency, file forensics. They are independent of one another, and that independence is exactly what makes it informative when several of them agree.

4

Signals and risk level

Failed controls become explained signals: what was compared, both values, the page each one came from. They are grouped by document and by level, then turned into a risk level — from a document whose signature verifies to one where several levels converge on the same value.

5

Decision

Yours. You set what passes unattended, what goes to review and what stops, according to what is at stake on the case. Holofin assembles the evidence; it does not issue the refusal.

The levels stack

No single level
catches everything.

That is why
there are five.

The five controls are independent, and each one is blind to what the others see. A spotless file clears level 01 without raising anything; it is its signature that fails at 02. A genuine, untouched document passes the first four; it is the rest of the case that contradicts it at 05.

On the diagram, each document that is stopped carries the mark of its own defect, and the trail behind it shows every mesh it had already crossed. The tighter the mesh, the more the control proves: the issuer's signature and the registry let almost nothing past them, while an analysis of the file mostly opens a line of enquiry.

So the five levels are not equal. The next section re-orders them, strongest to weakest — and says which one spoke.

Documents inPasses cleanno signal01Structuraltext overlaid02Issuerseal unsigned03Contentbalance mismatch04Businessissuer inactive05Case fileholder differs

Controls

The five levels are not equal.
Here is which ones prove, and which ones indicate.

The framework presents them by scope, from the bytes of a file up to the whole case. In front of an alert that is not the useful question: what matters is the strength of the evidence. So here they are again, re-ordered from the most solid to the most fragile.

A tool that melts these five levels into a single score leaves you with no way of knowing whether the alert came from an invalid signature or from a harmless re-export. We keep them apart, and we say which one spoke.

Level 02

Verification at the source

Proof

The only control that depends neither on how the document looks nor on the honesty of whoever sent it. Where the issuer has sealed the document, you read the seal: it holds mathematically, not statistically.

  • Where a document is cryptographically sealed — a digitally signed PDF, or a signed barcode an issuer prints on the page — the signature is verified against the issuing certificate, and the file is checked for any change made after signing. A seal regenerated by a fraudster fails, because no issuer signed it.
  • Every sealed value is then compared to the value printed on the page. That second step is what catches the most frequent case of all: an amount retouched on top of a seal that itself remains perfectly valid. Where an issuer seals a document, you verify the signature rather than the appearance — and then you check that the two agree.
  • On identity documents, passports and residence permits, the machine-readable zone is validated for its internal consistency: its check digits have to agree with the names, dates and document number printed above them.
  • This is also the level where the issuer's fingerprint is compared: producer software, embedded font subsets, logo position, page geometry. A bank or a payroll system produces its documents the same way every time, and a statement that does not look like that issuer's own output is a signal even when nothing printed on it is wrong.
  • Some issuers operate a verification service of their own, where a reference printed on the document can be confirmed directly with them. That confirms the fields the service covers, and no others — which is worth knowing before treating it as a verdict on the whole document.
Level 04

Verification against official registries

Proof

A perfectly consistent document can describe a company that does not exist, has stopped trading, or is run by somebody else. No analysis of the file will tell you that: you have to leave the document and ask the source of record. This is our own ground — in France, enrichment runs on Origami Entreprises, our own registry built from the official sources and refreshed daily: we do not buy that data from a third party, we produce it. Elsewhere the same checks run against the official register for the jurisdiction, through our data partnerships.

  • Registration and status: the company registration exists, and it was active on the date the document claims. Legal form, incorporation date, activity, establishments, and the history of events declared to the register.
  • Officers and beneficial owners: compared to the names on the identity documents in the case. A signatory who appears nowhere in the register is a discrepancy, not an administrative detail.
  • Address check: the registered office and the establishments reconciled against the address printed on the document, allowing for spelling variants.
  • VAT number validated and consistent with the registration number the document carries.
  • This is the level that catches the fictitious or inactive issuer: a payslip from an employer that no longer exists, an invoice from a supplier that closed eighteen months ago.

Beyond France the same checks run against the official register for the jurisdiction, reached through our data partnerships — company registries, VAT validation and beneficial-owner sources, added per market as you need them. The checks are the fixed part; the source behind them is configurable, so a case file that mixes jurisdictions is verified company by company rather than held to whichever register happens to be connected.

Enrichment at Holofin · origami-entreprises.fr →

Level 03

Recomputed internal consistency

Strong

The document has to agree with itself. A fraudster who changes one figure then has to make everything that follows from it agree: the totals, the lines below, the check digits. They rarely do, and never all of it at once.

  • Bank statement: opening balance + credits − debits = closing balance. The continuity of the running balance, the ordering of the dates and duplicated entries are checked line by line.
  • Payslip: a net that does not follow from the gross and the deductions printed above it is a signal, not a rounding error.
  • Identifiers: IBAN check digits (ISO 13616, mod-97), the Luhn algorithm on identifiers that carry a Luhn check, and VAT arithmetic recomputed from the net and the rate. These are calculations, not estimates — a retouched IBAN does not survive the arithmetic.
  • Dates and periods: a period that does not match the year the document announces, an extract older than the freshness rule the case applies.
Level 05

Consistency between the documents in the case

Strong

The only control that catches the fraud in which every document is genuine: somebody else's document. It leaves no trace in the file, no failed calculation and no invalid signature. It gives itself away purely through what the documents say about each other.

  • The account holder on the bank statement is the person on the identity document.
  • The employer on the payslip is the employer on the employment contract, and the declared salary is the salary the payslips actually show.
  • The tax assessment covers the applicant and not another household, and the declared address is the address on the proof of address.
  • Every discrepancy is reported with both of the values compared and the document each one came from — not a bare "inconsistency detected".
Level 01

Analysis of the file itself

The analysis that does not read the document but the way it was built: metadata, revision history, font tables, internal structure, image statistics. Deterministic detectors spread across independent forensic domains. It is the one level that needs no issuer seal, no registry and no second document — so it runs first, and it runs on everything.

It is also the weakest of the five as proof, and that is precisely why the levels are kept apart. A re-scan, a print-to-PDF or a legitimate re-export rewrites the metadata and erases the revision history, and a consumer PDF producer never proved anything about anybody — plenty of honest applicants re-export a statement before sending it. So this level opens a line of enquiry and localises it on the page; it never refuses a case on its own. What it is uniquely good at is reach: it is the only control still available on a document whose issuer seals nothing and whose company appears in no register.

  • Content integrity: traces of text overlaid, rewritten or inserted after the document was created — including text laid on top of a masking rectangle, which hides the old value on screen while leaving both of them in the file.
  • Typography: a font subset or a letter spacing that changes on the line carrying an amount, while the rest of the page stays homogeneous. Mixed subsets on one line are a fingerprint of text that was typed in a second time.
  • Metadata and structure: incremental saves and the revision history they leave behind, the producer and creator chain, an impossible timeline between the creation date and the modification date, hidden layers, multiple content streams, unusual complexity.
  • Images and digital signatures: cloned or resampled image regions, a recomposed photograph, a fabricated image, and any modification made after an electronic signature was applied.

Worked example

A lending case
where one figure moved.

Four documents, all genuine but one. On the March bank statement the closing balance went from 1,485.51 to 11,485.51: a single "1" inserted in front. To the eye the page is flawless, and it extracts flawlessly too.

What the document says, and what its own figures say

Opening balance1,240.18 EUR
Total credits+ 3,186.40 EUR
Total debits− 2,941.07 EUR
Closing balance, recomputed1,485.51 EUR
Closing balance, as printed11,485.51 EUR

Whoever did this corrected the closing balance but not the three numbers it follows from — nor the running balances on the lines above it, which stay on the old trajectory. The gap is exactly 10,000.00: the signature of an inserted digit.

The signals, and what each one is worth

Stronginternal consistency

The accounting equation does not hold

A calculation, not an estimate. A genuine statement cannot fail this control: the bank produced all three of the numbers it is built from.

Stronginternal consistency

The running balance is broken

The balance on the last line does not lead to the closing balance shown. Two independent controls point at the same value.

Mediumtypography

Different font subset on the balance line

Corroborating: it puts the retouch on the exact line the two previous controls had already called into question.

Weakmetadata

PDF producer: consumer editor

Worth nothing on its own. Thousands of honest customers re-export their statements. Here it adds a detail of context and no more.

Contextrest of the case

The other three documents check out

The tax assessment's signature is valid and its sealed values match the printed ones, the identity document's machine-readable zone is consistent, and the payslips' net recomputes from the gross. The suspect document is isolated, and that is what makes the report precise.

What a reviewer receives is a named document, a sum to check and a page to open — not an overall score they would then have to interpret.

Decision

Holofin reports and explains.
The decision stays with your teams.

A fraud signal is not an accusation, and an engine has no business drawing the consequences on your behalf. You set the thresholds: what passes unattended, what goes to review, what stops — and those thresholds depend on what is at stake on the case, not on the technology.

Nothing is refused automatically on your behalf

The GDPR regulates decisions based solely on automated processing that produce legal effects concerning a person, or similarly significantly affect them: that is its article 22. Refusing credit or declining a claim falls squarely inside that perimeter. The verdict prepares the decision; it does not take it.

A signal is not a legal finding

Whether a document is a forgery, and what should follow from that, is a matter for a court under whichever law applies where you operate. Calling it is not an engine's job. What we produce is the material evidence: a calculation that fails, a signature that does not verify, two values that contradict each other and the page each one came from.

An ambiguous case is escalated, never filed in silence

A married name against a birth name, a company that has since been renamed, a re-exported document whose metadata was rewritten on the way: these go to review with their reason attached. A control that cannot conclude has to say so, rather than decide in place of the person handling the case.

Every signal is contestable because it is explicit

The level that fired, the values compared, the page they came from. A reviewer who disagrees has to be able to demonstrate it — and a customer who challenges the outcome has to be able to receive an answer other than "the algorithm said so".

What is kept behind every signal

Level that fired
issuer, registry, internal consistency, case or file
Values compared
both of them, with the document and page of origin
Seal verification result
issuing certificate and signature validity
Control engine version
hololang 4.2
Date the controls were frozen
2026-10-02
Decisions and reclassifications
kept append-only

A case challenged a year later can be re-read with the controls that applied at the time, and every signal traced back to the value and the page that produced it. That is what makes the decision defensible — in front of an auditor as much as in front of the customer.

Integration

The signal arrives
before the case moves on.

A fraud alert is no use at all once the funds have been released. The controls plug in where documents already enter your chain, and the signals go back out into the tool your teams actually work in.

REST API

You post the document or the whole case, you read back the signals. Extracted fields, control results and pages of origin in the same response.

Webhooks

A signal surfaces as soon as a document lands or a value is corrected; you are told without polling in a loop.

SFTP

Batch drop and collect, for chains that already run overnight — including re-checking a back catalogue of cases that were decided before the controls existed.

Document management

Documents go back filed, with the recognised type and the control results attached: the audit trail stays where the documents are archived.

Upload portal

The control runs at the moment of upload. This is the most useful point in the whole chain: an unreadable or inconsistent document can be asked for again before the case is ever opened.

Frequently asked

On document fraud detection

Analysis of the file itself needs no content at all: it works on properties of construction — metadata, font tables, revision history, internal structure, image statistics. The consistency controls do need content, because comparing the account holder on a statement to the name on an identity document means knowing both names; those run on the fields already extracted from the case. Both families of signal arrive in the same verdict.
Those that carry a proof placed on them by their issuer. Where a document is cryptographically sealed — a digitally signed PDF, or a signed barcode printed on the page — the signature is verified against the issuing certificate, the file is checked for any change made after signing, and the sealed values are then compared to the printed ones. Identity documents, passports and residence permits expose a machine-readable zone whose internal consistency is validated. Several countries also run national schemes that add a signed barcode to tax, utility or payroll documents, and where one applies the same two steps run on it. The detail is on the authenticity verification page.
Yes, but by other means. With no proof from the issuer, verification rests on what the document owes to itself and to the rest of the case: the accounting equation of a bank statement, the net that has to follow from the gross, the mod-97 check digits of an IBAN, the account holder who has to be the person on the identity document. A fraudster who changes one amount then has to make everything else agree, and that is rarely the case.
It counts, but it does not decide on its own. A re-scan, a print-to-PDF or a legitimate re-export rewrites the metadata and erases the revision history, and plenty of people scan their paperwork in complete good faith. That is exactly why there are five levels: analysis of the file opens the line of enquiry, and the issuer's signature, the recomputed totals and the rest of the case are what confirm it.
No. Holofin raises signals, explains them and ranks them; the thresholds and the decision belong to your teams. The GDPR regulates decisions based solely on automated processing that produce legal effects concerning a person (article 22). Calling a document a forgery is a matter for a court, not for an engine.
This is the case that no analysis of the file can catch: the document is true, it has not been retouched, and its signature verifies. What reveals it is the comparison with the rest of the case — the account holder on the bank statement is not the person on the identity document, the tax assessment covers another household, the employer on the payslip is not the employer on the contract. The discrepancy is reported with both values compared and the document each one came from. The case completeness control checks the same thing, on the same case.

Run Holofin on your own cases

Send us a handful of real cases, and above all the frauds you have already identified: it is the only honest way to judge this. We give you the signals back document by document, with the level that spoke — and what we did not see.

GDPR compliant European hosting French software vendor
Holofin