In an era where digital tools allow individuals to manipulate PDFs in seconds, document forgery is a significant risk for financial institutions. Borrowers seeking higher loan limits or lower interest rates occasionally alter bank statements, salary slips, and tax files.
For underwriters, relying on visual inspection of loan application documents is no longer sufficient. Modern underwriting platforms like CreditCore Ten use automated fraud detection algorithms that look beneath the visible layout of a document. This guide explains how risk engines identify altered financial documents during credit underwriting.
1. Common Methods of Financial Document Forgery
Document tampering usually targets specific transaction items that influence capacity calculations:
- Transaction Amount Alteration: Borrowers change numbers—such as raising a salary credit from ₹30,000 to ₹80,000, or lowering a debt EMI debit from ₹15,000 to ₹1,500.
- Deleting Transaction Rows: Default charges, cheque bounce fees, or EMIs to other lenders are deleted entirely from the bank statement to make the cashflow look healthier.
- Fabricating Salary Slips: Borrowers generate fake salary slips using templates that do not match actual bank credits or tax records.
- Metadata Manipulation: Forgers use online editors to alter dates, names, or addresses, inadvertently leaving traces in the file parameters.
2. Technical PDF Structure & Metadata Checks
When a PDF is uploaded, automated risk engines analyze its source code. PDFs are structured files containing text streams, layout blocks, font descriptors, and metadata:
Metadata Analysis
Checks the PDF "Producer" and "Creator" keys. If a bank statement claims to be generated by a banking system but lists "Canva" or "iLovePDF" as the modification tool, it is flagged as altered.
Font Substitution
Banks use specific font packages (like Helvetica or Arial) compiled in their document generation systems. Injecting custom numbers introduces font mismatch signatures that alert risk engines.
Checksum Balances
The algorithm recalculates every line item in the ledger: `Opening Balance + Credits - Debits = Closing Balance`. Altering a single digit causes a checksum failure on that row.
3. Cross-Document Verification Techniques
Underwriters do not assess documents in isolation. They verify data points across different documents submitted in the same application:
Comparing Bank Statements & Salary Slips
The risk engine checks the exact credit amount and date in the bank statement against the "Net Pay" declared on the payslips. If a payslip shows a net salary of ₹75,000 but the bank credit is only ₹45,000, it triggers an instant rejection.
Verifying Tax Records (Form 16 / ITR)
Underwriters check that the total annual credits in bank statement salary deposits match the gross salary declared on Form 16 and ITR files submitted to the Income Tax Department. This identifies temporary cash infusions designed to skew eligibility.
4. Behavioral Fraud Risk Indicators
Besides physical alterations, underwriters look for behavioral risk indicators in the transaction flow:
- Circular Transactions: The borrower transfers money to a friend's account, and that friend transfers it back on a recurring basis to simulate salary credits or commercial cash inflows.
- Immediate Outflows: When major credits are deposited (such as a loan disbursement or business payment), the funds are immediately withdrawn in cash or transferred to private wallets. This suggests the borrower lacks stable operating capital.
- Hidden Peer-to-Peer Loans: Scans for frequent payments to small NBFC platforms or P2P lenders that have not been registered on the CIBIL profile yet.
Conclusion
Underwriting fraud detection has evolved into a highly automated, data-driven security model. CreditCore Ten leverages advanced checksum audits and PDF structure analyses to protect lenders from fraudulent document submissions. By ensuring that application documents are authentic, consistent, and unaltered, underwriters can evaluate risk accurately and maintain lending portfolio health.