Paris 21:19
New York 15:19
London 20:19
Blogkyc

Document check: how to verify a document and what forensics adds

Vasco Alexandre

Vasco Alexandre

August 25, 2026

Document check: how to verify a document and what forensics adds

What is a document check?

A document check establishes that a document is genuine, current and consistent with the case. You confirm its type and validity, read its data, compare it with what you already hold and inspect the file for tampering; document forensics, or digital forensic document analysis, is that last step: it analyses the file itself, its metadata, fonts, pixels and structure, to find documents that were edited, generated or reused.

Forensics is a triage signal, not a verdict. Over the past year on Dotfile, 15% of the documents analysed by forensics scored high risk. When an analyst decided on one, they rejected it 1 time in 5, against 1 time in 19 for documents scored trusted. The score tells you which file to read first. It does not read it for you.

Which documents does a KYC or KYB file need?

Two families, with different risks.

  • Identity documents: passports, national ID cards, residence permits, driving licences. Their authenticity rests on physical security features and the machine-readable zone (MRZ). Article 22(6)(a), Regulation (EU) 2024/1624 (the AMLR, applicable from 10 July 2027) names them as the default means to verify a customer's identity. Our guide to identity verification services covers the remote options, and our explainer on automated document verification covers the identity flow end to end.
  • Supporting documents: proof of address, bank statements, registration certificates, articles of association, shareholder registers, source of funds evidence. Most arrive as PDFs or phone photos, with no security feature at all. They prove the information listed in Article 22(1): the usual place of residence of a person, the registered office and legal representatives of a company.

Proof of address alone made up 46% of the documents run through forensics on Dotfile over the past year. It is the document most often asked for and the easiest to edit.

How do you check a document, step by step?

StepWhat you checkSource of the rule
1. Type and acceptabilityIs it the document you asked for, from an issuer you accept?Your policy
2. ValidityExpiry date, issue date, "less than 3 months old" for a proof of addressYour policy
3. Data extractionName, address, dates, numbers, read by OCR and checked for accuracyEBA/GL/2022/15, paragraph 34
4. Data comparisonDoes the extracted data match the case and the other documents?Directive Article 13(1); AMLR Article 22 from 2027
5. AuthenticitySecurity features, MRZ checksum, template, signs of a screen replayEBA/GL/2022/15, paragraphs 33 and 36
6. ForensicsMetadata, pixel structure, fonts, document reuse, known templatesYour policy; EBA/GL/2022/15 paragraph 33 by analogy
7. Decision and recordApprove, reject with a reason, keep a copy and set an expiryDirective Article 40; AMLR Article 77 from 2027

For identity documents, the EBA Guidelines on remote customer onboarding (EBA/GL/2022/15) are specific. Where you accept a reproduction rather than the original, paragraph 33 asks you to check the security features and the document's specifications "by comparing them with official databases, such as PRADO", that personal data and the photo were not altered, that the MRZ is consistent and that the reproduction "has not been displayed on a screen". PRADO is the EU's public register of authentic identity and travel documents.

The record matters as much as the decision. Today, Article 40(1)(a), Directive (EU) 2015/849 requires a copy of the documents obtained during due diligence; from 10 July 2027, Article 77(1), Regulation (EU) 2024/1624 adds that records must not be redacted.

What is document forensics, and what does it detect?

Document forensics is the automated analysis of a digital file for evidence of manipulation. Where an identity card has holograms, a PDF bank statement has only its own structure, and that structure leaves traces when someone edits it.

  • Metadata: the software that produced the file, creation and modification dates. A bank statement last saved by an online PDF editor is a question.
  • Structure and fonts: text layers added on top of the original, a font that differs on one figure, objects inserted after creation.
  • Pixels: copy and paste, cloning, compression that differs across one area of the image.
  • Templates and generation: documents produced by template farms or generative AI, which look perfect and match a known fake.
  • Reuse: the same file, or the same image, submitted for different people.
  • Issuer match: whether a digital PDF matches the structure that genuine documents from the same issuer have.

Each signal raises or lowers trust; none proves fraud alone. A legitimate customer who compresses a scan or merges two pages with a free tool will trip a metadata indicator. That is why a high-risk score should send a document to a person, never straight to a rejection.

Worked example: a proof of address that edits itself

A fictional EMI onboards a sole trader, Marc, who uploads a utility bill as his proof of address. The AI analysis reads the name, the address and the date, finds the bill 6 weeks old and the address identical to the one declared. Every rule passes.

Forensics scores the file high risk. Two indicators fire: the file was produced by the utility's billing system and modified 4 days ago with an online PDF editor, and the address block uses a different font from the rest of the page. Automatic approval is overridden and the check goes to review.

The analyst does not reject on the score. She asks Marc for the bill downloaded directly from his account. The second file matches the issuer's structure and shows a different street number: Marc had moved and edited the old bill rather than wait for a new one. Same person, wrong address: a policy question rather than a fraud case. The score did its job: it put the right file in front of the right person.

For company documents, the strongest control comes before forensics. A registration certificate ordered directly from the registry cannot have been edited by the customer.

What the data says about document forensics

Based on documents analysed by document forensics on Dotfile over the past year; aggregates only.

  • Forensic verdicts: 28% trusted, 38% normal, 19% warning, 15% high risk (about 1 in 7).
  • Of high-risk documents an analyst decided on, 1 in 5 was rejected. For trusted documents, 1 in 19.
  • Proof of address was 46% of the documents analysed.

Frequently asked questions

What is the difference between a document check and document verification?

They are used interchangeably. Strictly, verification is the checking part; a document check also covers collecting the document, deciding on it and tracking its expiry.

Can AI verify documents on its own?

AI reads and compares data well, and forensics finds manipulation humans miss. The decision on a flagged document should stay with a person, because most flags have an innocent explanation.

How do you detect a fake proof of address?

Check the date and the name against the case, then the file: editing software in the metadata, mismatched fonts, altered pixels. When in doubt, ask for the document downloaded from the issuer's portal.

Do identity documents need forensics too?

They need authenticity checks: security features, MRZ, template, photo substitution, screen replay. A live capture with liveness detection covers most of it; see our guide to liveness detection and deepfakes.

Where Dotfile fits

The document check collects documents through the client portal or the API, tracks expiry and keeps the review history. AI document analysis extracts and validates the data and compares it with the case, and document forensics checks each file in over 500 ways; a high-risk indicator overrides automatic approval and routes the check to review. For companies, document orders fetch official extracts from the registry. The full process sits within the KYB process.

Ready for Anywhere?

Verify any business, enter any market, defend every decision. Every signal orchestrated, every decision traceable, from one platform.

Book a demo