You reject a fake payslip, then spot the same unusual flaw in another applicant’s file. Document fraud incident response starts here: preserve originals and hashes, assign an owner, pause risky decisions proportionately and search for related submissions. Keep facts separate from hypotheses, control evidence access and record why each hold is widened or lifted.
Rejecting the first file doesn’t tell you whether you’ve stopped the problem. You need to know which other decisions depend on the same pattern. This first-24-hours playbook sets out who takes charge, what to search and when to widen or lift a hold.
Use the time blocks as checkpoints. They aren’t legal deadlines and you shouldn’t wait for one before taking urgent action.
A repeated fake document pattern changes the job
Suppose three applicants submit payslips that claim to come from different employers. The names and salary figures differ, but the files share the same unusual structure and the same issuer inconsistency.
Reviewing each case in isolation can tell you whether a document looks suspicious. It will not show how far the pattern has spread through your business.
Resistant AI describes document fraud templates as reusable files built to imitate official layouts, with personal data swapped to produce many variations. So repeatability is plausible. But a shared template doesn’t prove a shared operator.
Treat the repeat as a lead, not a verdict. Your initial incident statement might read: “Three submissions contain a matching forensic pattern inconsistent with the claimed issuers. Related exposure is unknown.”
That gives the next reviewer something to check. “We found an organized fraud ring” claims more than you know.
Which decisions, accounts and payments may depend on the same source? That’s the question to ask when the second or third document appears.
The first hour: preserve evidence before touching the cases
Before anyone starts marking up a suspicious PDF, preserve it. Do not edit the suspicious files, re-save them, add annotations inside them or replace them with screenshots. Those actions can change the evidence available for later analysis. NIST’s forensic evidence guidance recommends preserving file integrity, verifying copies with message digests and using read-only access where possible.
-
Save the original submission. Preserve the exact file received, its original filename, submission timestamp, channel and associated case identifier. Keep the document in access-controlled storage.
-
Calculate a cryptographic hash. Record a SHA-256 hash for each original file and compare it with any hash recorded at intake. A hash taken now provides a baseline for later checks, not proof that the file was unchanged before you received it or that its contents are genuine.
-
Capture the surrounding record. Preserve the forensic result, application data, communications already received and the decision state at detection time. Do not collect unrelated personal data “just in case.”
-
Protect the audit trail. Record who accessed, copied or exported the evidence and why. Use a working copy for analysis while keeping the original read-only.
-
Stop irreversible decisions where proportionate. Place the affected cases into manual review before another loan is disbursed, claim is paid, supplier bank detail is accepted or account is activated. Do not freeze every customer because three files look alike.
Preserve enough evidence to investigate without putting unrelated business on hold. NIST’s incident response guidance is written for cybersecurity, but its emphasis on preparation, detection, response and recovery is useful here too. Apply that discipline to the decisions and evidence in your document fraud response plan.
Assign an incident owner before the hour ends. That person controls the timeline, approves scope changes and keeps facts separate from assumptions.
Give the owner a named deputy and a route to whoever can approve payment holds. Otherwise, the team may agree on the risk while the next payment still goes out.
Hours one to four: scope exposure without contaminating evidence
Start your search with indicators from the suspicious submissions, then query the systems that hold applications, claims, vendors or accounts. A document forensics result can give you a starting point. You’ll also need evidence from your case platform, identity system and device-risk tools.
Work through these searches:
- Exact file match: Look for the same cryptographic hash, then verify the candidate files match. Do not use hash matching alone to search for template reuse: changed file contents should produce a different SHA-256 hash.
- Document pattern match: Search for the same claimed issuer, document type, template flag, structural anomaly or unusual producer information. Keep the criteria documented so somebody else can repeat the query.
- Data cross-reference: Compare applicant contact details, account numbers, employer names, addresses and payment destinations already lawfully held in your systems.
- Operational link analysis: Ask the relevant platform for shared devices, sessions or identity attributes if it collects them. Do not imply a PDF tool can see data it never received.
- Decision exposure: Identify which related submissions were rejected, approved, paid, activated or still pending.
Persona’s article on the new wave of document fraud explains how device history and shared identity attributes can reveal links between users. That is useful context, but it is a separate evidence source.
Document findings and device links answer different questions. Keep the source of each finding visible in the case record.
Set a time boundary for the first query, perhaps the current week or the period since the suspicious issuer format first appeared. Record why you chose it.
If credible matches appear near that boundary, widen the search and log the new criteria. A large match count means little if nobody can explain how the query found it.
This is also the moment to review previously approved cases. Our post on ongoing document monitoring explains why risk does not end at onboarding.
An old approval can still leave you exposed. Don’t leave it out of the search just because the case is closed.
By hour four: separate document fraud evidence from hypotheses
It’s easy for a suspicion to become an accepted fact as people hand a case over. Keep two lists and an evidence table so the next analyst can see what you’ve established and what you’re still testing.
The facts list should contain statements that another analyst can reproduce. These are illustrative examples, not findings from a real incident:
- Three original PDFs have different hashes but share a specified forensic indicator
- Two applications use the same payment account already held in the case system
- One related claim was paid and four applications remain pending
- The claimed issuer has not yet confirmed or denied the documents
The hypothesis list contains what those facts might mean:
- A reusable fraud template may have produced the PDFs
- The applicants may be connected
- A compromised broker, vendor or internal process may explain the cluster
- A legitimate document generator may produce the shared characteristic
For each hypothesis, record what would support it, what would weaken it and who owns the next check. Use a small evidence table like this:
| Observation | Possible explanation | Next check and owner |
|---|---|---|
| Different PDFs share an unusual structure | Reused fraud template or a common legitimate generator | Document analyst compares known genuine issuer files |
| Two applications name the same payment account | Shared destination, authorized joint account or data-entry error | Case reviewer checks account ownership through an approved channel |
| A matching claim was already paid | Possible loss, not yet confirmed | Claims lead reviews the evidence; finance assesses recovery options |
Do not add the same payment twice because two search rules found it. Use case and transaction IDs to count unique decisions, then keep suspected exposure separate from confirmed loss.
Define confidence in plain language too. “Confirmed fake” should require your agreed evidence threshold. Our document fraud false-positive review workflow covers routine thresholds and review queues. Here, use those rules to resolve cases inside the incident, not to assume every match is fraud.
“Related” should mean a documented link, not that two applicants live in the same city. If a forensic flag is the only connection, say so.
What document checks can and cannot settle
At VerifyPDF, we inspect PDFs for structural and metadata inconsistencies and return risk findings. Our document fraud detection software page shows the checks and dashboard/API options. Use it to plan a test on genuine and known fake files, then assess whether the warnings give your reviewers useful evidence.
A document warning does not establish who submitted a file or whether several applicants share an operator. Device and identity links must come from other systems. Your team still owns issuer checks, payment holds and the final decision. Wider holds may reduce exposure, but they also delay legitimate customers. Test false positives as well as detected fakes before expanding a rule.
Hours four to eight: contain decisions without tipping off the wrong people
You don’t need a dramatic shutdown. You need targeted controls to prevent avoidable loss while you establish the facts.
Move matching pending submissions to a restricted review queue. Require a second reviewer for releases, approvals or bank-detail changes connected to the incident. If an automated rule is approving the affected document type or issuer pattern, suspend that rule or add a temporary hold, but leave unrelated flows alone.
Avoid accusations before the evidence supports them. Before contacting an applicant, assess the risk of alerting other people involved, losing access to evidence or accusing a legitimate customer caught by a false match.
Continue normal communications where possible and use neutral language such as “additional review is required.” Your legal or compliance team should approve customer-facing wording for your jurisdiction and process.
Tell the people who need to act and keep access on a need-to-know basis. Depending on the incident, that may include:
- The fraud operations lead who controls the investigation
- The business owner for lending, claims, onboarding or payments
- Information security when account compromise or system abuse is plausible
- Privacy, compliance or legal advisers when personal data, employee conduct or external reporting questions arise
- Finance or treasury when money may still be stopped or recovered
Don’t guess at a regulatory deadline or assume this checklist determines your reporting duties.
Ask legal or compliance to assess those duties promptly, not at the end of the 24-hour checklist. Give them the known facts and detection times so they can decide whether a reporting duty applies and record any deadline.
Protect the people named in the files too. Limit exports, avoid emailing evidence bundles around and redact unnecessary personal details from status updates. You don’t want careless handling of personal data to create a second incident.
By the end of day: document fraud exposure and decisions
Before 24 hours pass, write a short incident brief. A senior fraud lead should be able to read it and understand what happened, what remains unknown and why the current controls are proportionate.
Include these fields:
-
Trigger and timeline. State which submission started the review, when the repeated pattern was recognized and which actions followed.
-
Evidence preserved. List original files, hashes, forensic outputs and the systems where related records are held. Do not paste sensitive data into the brief when identifiers will do.
-
Current scope. Count confirmed fake documents, suspected matches, affected products, pending decisions and completed decisions. Keep those categories separate.
-
Loss and exposure. Distinguish money already lost from money merely at risk. Include non-financial exposure such as activated accounts or accepted vendors.
-
Containment in force. Record temporary holds, review requirements, access restrictions and their owners. Every temporary control needs a review date.
-
Facts, hypotheses and confidence. Link each important conclusion to evidence. Mark contradictions rather than smoothing them away.
-
Next decisions. Name what must happen after the first day, who owns it and when the incident will be reassessed.
Your decision log is just as important as the brief. Record the time, decision, decision-maker, evidence considered and expected impact.
The log should explain why cases linked to one issuer were held while others stayed open. If the search window grew from seven days to six months, record the evidence that justified that change.
Why did you let that payment go ahead? When an auditor asks or a real applicant challenges a false positive, you need the reasoning recorded at the time. Reconstructing it afterwards is a poor substitute.
Widen or close the document fraud incident response deliberately
Widen the incident when evidence suggests your current search boundary could hide related exposure. A nervous team isn’t enough reason on its own.
Widen the incident when:
- Credible matches appear at the edge of the date range, product or geography searched
- A shared payment destination, identity attribute or device signal connects additional cases
- The same forensic pattern appears under another claimed issuer or document type
- A paid or activated case matches the incident indicators
- Evidence suggests an intermediary, vendor account or internal control may be involved
Narrow the scope when evidence clears a group of cases. Before closing the incident, check that:
- The scoped search is complete and repeatable, with no credible matches outside the contained set
- Each suspected anomaly has a recorded outcome: confirmed fraud, a legitimate explanation or an unresolved issue assigned for follow-up
- Competing explanations have been tested rather than ignored
- Affected decisions have been reviewed and permanent controls have owners
- Evidence retention, customer remediation and any required follow-up have been agreed with the appropriate internal teams
Closing the incident does not mean deleting the pattern. Keep a lawful, proportionate record of the forensic indicator and lessons learned so future submissions can be assessed consistently.
Review false positives too. A control that catches fraud but repeatedly blocks genuine customers is still a bad control.
You won’t solve every serial document fraud investigation in 24 hours. You should finish the day with intact evidence, a defined search scope and targeted holds. Assign an owner to every gap that remains.
Contact VerifyPDF sales to discuss a dashboard or API evaluation using a representative set of genuine and known fake documents. Use the results to decide where PDF checks belong in your response plan. Rejecting the first fake is a start. Your response plan has to account for the next one.