[ Credit Risk ]
Two Kinds of Bank Statement Fraud, and Why Most Lenders Only Check for One
A forged PDF and a dressed account are different problems requiring different checks. The forensic tests, the behavioural signals, and why generic fraud rules fail across borrower segments.
7 min read · 20 August 2026

Contents
A borrower can defraud you with a bank statement in two entirely different ways.
They can hand you a document that is not what the bank issued — edited in a PDF tool, regenerated from a template, numbers changed. Or they can hand you a completely genuine statement, digitally signed, arithmetically perfect, of an account that was deliberately operated to look creditworthy for the six months before they applied.
These are different problems. They require different detection methods. Most fraud checking in Indian lending addresses the first and is blind to the second — which is unfortunate, because the second is more common, harder to reverse, and passes every test the first one fails.
Layer one: is the document authentic?
This is a forensic question about the file, and it is answerable before a single number reaches the credit team.
Digital signature validation. Bank-issued PDFs carry a cryptographic signature. If it validates, the document is authentic and the enquiry ends there — this is the only check that produces certainty rather than suspicion.
The important nuance runs the other way. A missing signature is not evidence of fraud. Borrowers routinely print statements to PDF, forward them through email clients that re-encode attachments, or download from a net banking portal that never signed them. All of these strip or invalidate the signature on a perfectly genuine statement. Treating absence of signature as a fraud flag generates enormous false-positive volume and trains your team to ignore the flag entirely.
Metadata anomalies. Producer and creator fields naming a consumer PDF editor rather than the bank's document system. Modification timestamps later than creation timestamps. Incremental save layers indicating the file was opened and re-saved. None of these is conclusive alone; the pattern is what matters.
Font and rendering inconsistency. Edited text is rarely re-rendered with the exact font, weight, kerning and baseline of the surrounding table. On a scanned statement the equivalent tell is a region whose compression artefacts or resolution differ from the page around it.
Balance trail arithmetic. The most reliable forensic check, and the one anyone can perform manually: the running balance must reconcile transaction by transaction across the entire period. Opening balance, plus credits, minus debits, must equal the stated closing balance at every row and every page boundary.
Someone editing a single credit amount to inflate turnover has to edit every subsequent balance on every subsequent page to keep the trail intact. Almost nobody does. The break shows up as an arithmetic discontinuity at a specific row, which is why a tampering verdict should always name the page and line rather than returning a score.
Layer two: is the account authentic?
Here the document is real. The signature validates, the arithmetic reconciles, the metadata is clean. The account behind it was managed.
This is account dressing, and it is the harder problem, because there is no artefact to examine. The evidence is behavioural, distributed across months, and visible only in the shape of the transactions.
Circular funding
The clearest signal is the same counterparty appearing on both the debit and credit side of an account. Money leaves, returns, and is counted as revenue on the way back in.
Run at scale between a promoter, a group entity and an operating account, this manufactures turnover from nothing. The account shows healthy throughput. The business generated none of it. Netting related-party and self-transfer flows to a single figure — rather than counting each leg — is the difference between reading cash generation and reading cash movement.
Round-figure credits
Real trade receipts are rarely round. They carry GST, they carry deductions, they carry the arithmetic of an actual invoice. A statement dense with credits at exactly ₹5,00,000 or ₹10,00,000 is describing transfers, not sales.
Throughput that contradicts the claim
Two signals that only appear when you compare months against each other rather than looking at aggregates: a fall in the number of transactions per month, and a fall in total monthly credit value. A business claiming stable operations while its transaction count declines month on month is describing an account that has been kept alive rather than used.
Mechanically implausible entries
Some transactions could not have happened as narrated. An RTGS entry below the ₹2 lakh floor. A transfer through a channel above that channel's daily cap. A cheque clearing or a cash deposit dated to a bank holiday.
These are rarely sophisticated forgery. They are usually someone fabricating entries without knowing the operational rules of the payment system they are imitating.
Timing patterns
Dressing has a calendar. Balances get parked before a statement period opens and withdrawn after it closes. Nil credits between the 20th of one month and the 5th of the next — a gap in what should be continuous trading activity — indicates an account being managed to a reporting boundary rather than operated.
For salaried borrowers the equivalent tell is a large debit immediately following the salary credit, month after month. The salary landed. It did not stay. Either it was borrowed for the purpose of appearing, or an obligation exists that is not on the bureau.
Why generic fraud rules produce noise
Every signal above is context-dependent, and applying one ruleset across all borrower types is why fraud flags get ignored.
A round-figure credit of ₹10,00,000 is unremarkable in a corporate account settling an inter-company balance. In a micro-enterprise account it is close to diagnostic.
A negative end-of-day balance on a single day is routine for an SME running an overdraft facility. For a salaried applicant it is a material conduct signal.
Same-counterparty-on-both-sides is expected in a corporate group with genuine inter-company trade. In a sole proprietorship it is the primary circular-funding indicator.
An NEFT or RTGS outflow exceeding twice the average monthly balance is normal in a business account with high velocity and low parked balance. In a salaried account it is anomalous.
The practical consequence is that fraud rules have to be tuned by segment, or the false positive rate makes them unusable. A credit team that has learned to dismiss the flags is in a worse position than one with no flags at all, because it now has the appearance of a control.
A flag is a trigger, not a verdict
None of these signals establishes fraud. Each establishes that a specific transaction or pattern requires explanation.
That distinction matters operationally and it matters legally. Indian lenders operate under fraud classification frameworks that require documented investigation and natural justice before an account or a borrower is declared fraudulent — a system output is an input to that process, never a substitute for it.
So the useful design is: flag with evidence attached, routed to a person, before the file reaches the credit decision rather than after. A flag that names the page, the line and the rule that fired can be resolved in a minute. A risk score with no provenance cannot be resolved at all, only argued about.
Two of the flags in this article have innocent explanations often enough to prove the point. Round-figure credits appear legitimately in advance payments and security deposits. A same-party debit and credit appears legitimately in a refund. The check is not there to convict. It is there to ensure someone asked.
Auditing your own process
Five questions worth putting to your current setup this week.
- Do you validate digital signatures at all, and what happens when one is absent? If absence triggers rejection, measure the false positive rate. If absence triggers nothing, you are not running the check.
- Does your tool reconcile the running balance across page boundaries? Many reconcile within a page and not across. Page breaks are exactly where a tamper is likely to survive.
- Are your fraud rules segmented by borrower type? If a salaried applicant and an SME are scored against the same ruleset, one of them is generating noise.
- When a flag fires, does it carry a page and line reference? If your analyst has to search the statement to find out what the alert is about, the alert costs more than it saves.
- Do the checks run before analysis or after? A tampering verdict delivered alongside a completed credit report has already allowed corrupted figures into the assessment.
The point about the second layer
Document forensics is a solved problem in the sense that the methods are known and mechanical. Any lender can implement a balance-trail reconciliation and a signature check.
Account dressing is not solved, and it is where the losses are. It requires reading months of behaviour against segment-appropriate expectations, netting circular flows, comparing months against each other rather than against an aggregate, and catching mechanical impossibilities that only make sense to someone who knows how the payment rails work.
It also requires the categorisation underneath to be correct in the first place. A circular flow cannot be netted if both legs were labelled "transfer" and never linked to the same counterparty. We measured how often that categorisation is wrong across 200,001 transactions — the error rate in counterparty identification is precisely what makes layer-two fraud invisible to most tools.
Frequently asked questions
How can you tell if a bank statement is fake? Validate the digital signature first — if it validates, the document is authentic. Then reconcile the running balance across every row and page boundary, since editing an amount breaks the arithmetic downstream. Then check PDF metadata for consumer editing software and modification timestamps, and check for font or rendering inconsistency in specific regions. A missing signature alone is not evidence of forgery.
What is account dressing? Deliberately operating a genuine bank account to appear creditworthy ahead of a loan application — circulating funds to inflate turnover, parking balances across statement period boundaries, and routing money through related parties so it is counted as revenue. The statement is authentic, so document forensics cannot detect it. Only behavioural analysis across months can.
What are FCU checks in lending? Fraud control checks run on a borrower file before it reaches underwriting. In bank statement analysis these typically cover document tampering, mechanically implausible transactions, and irregular behavioural patterns such as circular counterparty flows or round-figure credits. Effective rulesets are tuned separately for salaried, self-employed and SME borrowers.
Can a digitally signed bank statement still be misleading? Yes. A valid signature proves the bank issued the document. It says nothing about whether the account behind it was operated genuinely. Circular funding, parked balances and related-party turnover all appear in fully authentic, correctly signed statements.
Fiscus runs segment-specific fraud control checks on every statement before analysis begins, with each flag traceable to the page and line that triggered it. Book a parallel evaluation to run it against files your team has already cleared.
Written by
Zeus DhanbhooraZeus Dhanbhoora is the CEO of BridgeUp Tech, the company behind Fiscus. He previously co-founded Bacferim Technologies and was an associate at the law firm Bharucha & Partners. He writes the Fiscus credit desk blog on benchmarks, fraud detection and credit underwriting methods.


