Document fraud: detecting fake documents and deepfakes
The digitalization of customer journeys has caused document fraud to explode: counterfeit identity documents, fabricated proof of residence, and now deepfake attacks capable of deceiving inadequately protected biometric verification. This guide describes current fraud techniques and detection methods to implement.
Regulatory stakes in fraud detection
Document fraud detection is not simply a best practice: it conditions the effectiveness of identity verification required by AML/CFT regulations and by the ANSSI's PVID framework. Accepting a false document amounts to failing to meet the obligation to verify the customer's identity, with a risk of liability in case of money laundering or identity theft. Identity fraud and use of false documents also constitute criminal offenses. The PVID framework imposes precise controls for document authenticity and liveness detection, specifically to resist presentation and injection attacks, including deepfakes.
To move from theory to practice, discover the Certyneo electronic signature solution and its offer dedicated to your sector — eIDAS compliant, no installation required.
- AML/CFT obligation to verify identity on the basis of a reliable probative document.
- ANSSI's PVID framework: requirements for resistance to presentation and injection attacks.
- Criminal Code: forgery and use of forgery (art. 441-1) and identity fraud (art. 226-4-1).
- GDPR: proportionate processing of biometric data used for detection.
Documents and fraud vectors to monitor
Steps for document fraud detection
- 1
Document authenticity analysis
Verification of visual security features, MRZ zone, font consistency, and if possible, reading the NFC chip.
- 2
Manipulation detection
Search for traces of retouching, metadata inconsistencies, and overlays revealing falsification.
- 3
Liveness check and biometrics
Liveness detection to rule out photos, screens and masks, and facial matching resistant to deepfakes.
- 4
Scoring and human review
Assignment of a risk score and escalation of questionable cases to an analyst for final traced decision.
Frequently asked questions
- What are the most common types of document fraud?
- We distinguish counterfeiting (entirely fabricated document), forgery (authentic document modified, for example photo replaced) and fraudulent use of an authentic stolen document. Remotely, presentation attacks and injection attacks are added.
- How to detect a deepfake during a verification?
- The defense relies on robust liveness detection and protection of the capture channel against video stream injection. The PVID reference framework requires proven resistance to these attacks, beyond simple face comparison.
- Does NFC reading protect against fraud?
- Yes, very effectively. Reading the NFC chip of the document makes it possible to cryptographically verify the authenticity of the data and photo, which makes visual forgery much harder to pass off.
- Can a proof of address be verified automatically?
- Partly: analysis can detect inconsistencies in layout, metadata or format. For high-stakes cases, cross-checking with third-party sources and human review strengthen reliability.
- Is human intervention always necessary?
- Automation handles the vast majority of cases, but human review of at-risk files remains recommended. It secures the decision, documents the reasoning, and reduces both false positives and false negatives.
Related guides and solutions
Explore the related resources from our electronic signature hub.