The state of fraud detection in lending
A public review of the technology sold to detect document, income and identity fraud in lending. It names the technologies in use, sets each against the published research and the statements of the authorities who regulate this field, and asks one plain question on the broker's behalf: what can actually be relied on? It names no product. Reviewed 11 September 2026.
Abstract
Lending has always run on documents a borrower supplies and a broker cannot readily check, and the market has an answer: software that promises to detect forgery, verify authenticity, and score the risk that a document is fake. Buying it looks like prudence, and against a careless forger it delivers. This paper examines that same software one level down, at the technology beneath the marketing. Grouped into families and set against the published research, the tools share a single property: each detects a known trace of manipulation, and a document generated cleanly leaves that trace absent. The authorities charged with fraud describe the same limit in their own words. The conclusion is narrow, and we think it matters. No available technology can support a claim to have proven a document genuine, or to have caught that it was machine-made. What a broker can prove is something else entirely, and the paper closes on it.
Why the market exists
The concern is real and current. Australia's largest lenders have publicly estimated fraudulent mortgages on their books in the billions, and in 2026 the financial-intelligence regulator put banks on notice over coordinated loan fraud. Generative tools have lowered the cost of a convincing forgery to almost nothing, and now produce whole sets of documents, a payslip, an employment letter, a tax return and a bank statement, that corroborate one another. Against that, a broker who wants a machine to catch the fake before the file is funded is being sensible, and the belief that such a machine exists is a reasonable one to hold.
That belief is what this paper tests. Demand for detection is understandable, and the tools that meet it are real products with real capabilities. The narrower question is whether those capabilities are the ones a broker takes them to be: of the technologies sold to catch the fake, which actually deliver what the buyer relies on them to deliver? Answering it means setting the marketing aside and reading the method.
The market sorts into five families, grouped by the question each puts to a document. Taken in turn, from the most familiar to the strongest, each answers a narrower question than a broker needs. The most familiar begins with the page itself.
Image forensics: built to catch edits, blind to clean fakes
The oldest family reads the image of a document for signs that it was altered. It includes metadata and file-structure analysis, error level analysis, JPEG "ghost" and double-compression tests, quantization-table and sensor-noise fingerprinting, and the newer machine-learning classifiers trained to segment a tampered region. Products built on these techniques promise to flag edits, splices and forgeries.
Within their design they work. Metadata analysis catches an editor who forgot to clear a revision history. Structural analysis finds text painted over other text. These are genuine tells, and a broker is better off with the check than without it.
The limits are documented by the people who built the methods. The researcher who introduced error level analysis writes in his own account of it that the technique identifies only that a change occurred, never that the change was malicious, and that high-contrast content confounds it. A payslip is high-contrast black text on white, the exact condition he names, so the method lights up the edges of a genuine document as readily as a forged one. The peer-reviewed compression tests carry their own stated conditions: they work only when the altered region is lower quality than its surroundings, and they fail on any document that has been emailed, resized or scanned, because those steps compress a file twice for innocent reasons.
The machine-learning classifiers are the current answer, and independent testing through 2026 has measured them directly. Asked to judge AI-generated forgeries rather than the human edits they were trained on, the strongest detectors fell close to chance. In one study, people shown a genuine receipt and a forged one side by side picked the fake barely more often than a coin toss, and the best software judge sat only a little above them. The reason is structural. Every technique in this family hunts for the boundary of an edit. A document generated cleanly in one pass, printed to PDF from a template carrying plausible figures, has no edited region, no revision history, no double compression and no sensor mismatch. There is nothing for the method to find, because nothing was altered.
AI-content detectors: the tools that cannot tell machine from human
A forensic tool can locate an edit, and a cleanly generated file has no edit to locate. The apparent remedy is a tool built to recognise the machine itself. That family tries to detect that content was produced by a machine: deepfake and synthetic-media classifiers for images, and AI-text detectors for writing. The text detectors use real, named methods, measures of perplexity and burstiness, probability-curvature tests, and statistical watermarks. They are deployed at scale, most visibly in education, where universities run them across student work.
That deployment is also the clearest evidence of their limits, because it is the best-resourced test of the technology there is. Independent evaluation has found reliable machine-versus-human text detection sitting close to zero, with false positives that flag genuine writing as machine-made, defeat by a light paraphrase, and a documented bias that falls hardest on people writing in a second language. The most telling admission is a vendor's own: one of the largest AI labs withdrew its own AI-text classifier in 2023, citing a low rate of accuracy.
This family matters most because AI-generated documents are the newest fraud vector, and this is the technology built specifically to catch them. If the sector with the strongest incentive and the largest scale cannot reliably tell machine text from human text, and a leading lab retired its own tool for the job, a broker cannot lean on an equivalent verdict about a payslip. The absence of an "AI-generated" flag establishes nothing about who, or what, wrote the document.
Provenance and "tamper-evident" records: a seal only the vendor can read
If the document cannot be read for the fake, the market's next answer is to stop reading it, and to wrap the record in a seal instead. This family, the fastest-growing, does not examine the document for fakery at all. It sells the wrapper as trust: content credentials and provenance manifests, digital signatures, AI watermarks, independent timestamps, blockchain anchoring, and "tamper-evident, append-only" storage. This is where the most confident language in the market lives, and where the least scrutiny has fallen.
Take the claims one at a time. Content credentials describe who produced or edited a file. The specification's own authors write that it "does not provide value judgments about the truth or falsehood" of the content, and the first independent security review of the standard concluded it "should not be relied upon for high-stakes uses such as financial disclosures." A digital signature proves that a file has not changed since it was signed and that a given key signed it. It says nothing about whether the contents are true, and in this market the documents a borrower holds are not signed at their source in any case, so there is no signature to check.
Watermarking is offered as the answer for AI content, and it has already been tested in public. A national standards body has reported that watermarking schemes are "consistently found vulnerable to removal," and a peer-reviewed proof, co-authored inside a major AI lab, holds that a strong, unremovable watermark cannot be built under ordinary assumptions. The live example is recent. In August 2026 one of the largest AI companies announced that its models would embed an invisible statistical watermark in their text. Within a day an open-source tool aimed at removing such marks appeared and quickly gathered thousands of stars. That tool reliably strips the surrounding metadata and hidden characters; whether it defeats the statistical watermark itself is unproven, and its authors say so. The lesson holds either way: the moment a marker is announced, the effort to erase it begins, and a marker that can be removed proves nothing by its absence.
The timing and integrity claims deserve the same scrutiny as the rest. "Independently timestamped" often means a clock the vendor itself controls, rather than a genuine third-party time source. "Tamper-evident" and "append-only" usually mean the vendor's own system will not let a record be overwritten, which is a property you can confirm only by asking the vendor, and one that ends when the vendor does. These are real engineering choices. But as sold, they are assurances about the vendor's own platform, not something an outside party could confirm without it. A claim of integrity that only its author can vouch for is closer to the detection claims above than it first appears.
Identity and database checks: matching the document, not the person
Those families all interrogate the document. The next looks past it, to a source that might vouch for what the document claims, and it is also where the authorities charged with detection describe, in their own words, where it ends. This family verifies against a source: biometric identity checks with liveness detection, register and licence lookups, watchlist screening, and matches against employer or government databases. These are useful, and some are strong. They are also narrower than they are read to be.
Australia's Document Verification Service is a good example, because it is the national rail and its scope is documented. It confirms that the details on an identity document match the issuing authority's records. It does not confirm that the person presenting the document is the person it describes, and it checks no biometric. It matches a document to a record, not a person to a document. A genuine credential in the wrong hands passes it.
For income, the gap is plainer still. Lenders cannot check a payslip or a tax return against the tax office, because that data is walled off by statute, which is why the industry is lobbying to open it. There is no authoritative source for the income documents a borrower holds, so they are taken on trust. And on the identity side, the regulators are unusually direct about the limits. The United States Federal Reserve, studying synthetic identity fraud, wrote that such identities "may not be flagged as suspicious using traditional fraud detection models," and that the risk persists "even when financial institutions have strong customer identification programs and can verify an applicant in person." A government audit office found that synthetic identities "can go unnoticed for years," and that because there is often no defrauded person, "there may not be a victim to report a crime." Europe's law-enforcement agency, examining a common attack on identity documents, concluded flatly that "there is no reliable way to detect this kind of attack." These are the bodies whose job is detection, describing where it ends.
Transaction and behavioural signals: stronger, and still not the document
Matching a document to a record still leaves the record standing in for the truth. The stronger move leaves the document behind and pulls the data live from its source. This family steps off the document entirely and reads behaviour: bank data pulled from the source through open banking, transaction categorisation, device and network signals, and shared fraud-consortium data. Pulling data from the bank raises the bar, because it is harder to fabricate a live feed than a PDF, and this is the hardest of these families to fool.
It also answers a different question than the one a file has to answer. A bank feed validates net amounts, not the gross pay, tax and year-to-date figures a serviceability assessment turns on. The consent behind it commonly expires within a year, while the lending record must be kept for seven. And a large share of applications still arrive as a re-typed statement that no one seals. Behavioural scoring, in turn, produces an inferred judgement about a session, not a proven fact about a document. It is worth having. It does not close the gap that the document families leave open.
The numbers on the box: accuracy with no denominator
Strong and weak alike, every one of these families reaches the broker wearing the same badge, a headline accuracy figure, and that figure deserves its own examination. Across them all runs a claim form worth naming on its own: the performance figure. "Ninety-nine per cent accurate." "Three times more fraud caught." "Two hundred times faster than manual review." These arrive without the one thing that would let anyone check them: the population they were measured on, the base rate of fraud within it, and the count of false alarms.
That omission is not a detail. Fraud is a rare event, and against a rare event a high headline accuracy is easy and close to meaningless: a tool that simply passes everything is right almost every time. What the figure hides is the false-positive rate, and in a lending file a false positive is an accusation against a real applicant. The disciplines that certify measuring instruments will not issue a pass-or-fail against a threshold without a stated uncertainty and a documented decision rule. None of these fraud scores publish one. A verdict that never states what it cannot see is not an engineering result. It is a marketing number.
What all of this adds up to: detection cannot be claimed
Set the families side by side and the same shape appears in each. Every technique detects a known trace of manipulation. None can certify that a document is genuine, because that is a claim about the absence of tampering, and absence is the one thing a document cannot demonstrate about itself. A cleanly generated file has consistent metadata, a single font, no double compression, no sensor to mismatch, no signature to fail and no watermark to strip, and numbers that read plausibly on their face. It presents the whole detection stack with nothing to catch.
There is an ordinary operation that produces exactly this document. Flattening a PDF, or printing any file to a fresh PDF, is a one-click action people perform for innocent reasons every day. It merges every layer into a single image-like page and discards the metadata, the revision history, the embedded provenance and any embedded watermark along with it. What comes out is a clean, ordinary-looking document that carries no trace of editing and no sign of a machine. One routine step, available in any office application, erases the evidence that every detection and provenance tool described here depends on.
This is not our opinion alone; it is the settled position of every serious field that touches the question. Forensic science treats integrity and authenticity as different properties, one never implying the other. The content-provenance standard states that it makes no judgement about truth. The transparency logs that underpin web security are built to detect misissuance after the fact, never to prevent it, and their designers say so. When the disciplines that invented these tools describe them, they describe detection, not proof. The regulators quoted above describe the same limit from the other side. And the one place a legislature tried to force the issue, by mandating that AI content be watermarked, the law qualified itself in the same sentence, requiring the marking only "as far as this is technically feasible" given "the generally acknowledged state of the art."
So the finding is plain. No available technology, and no legal mandate resting on one, can support a claim to have detected that a document is fake or machine-made. A "clear" result from any of these tools is not evidence that a document is genuine. It is the absence of a caught mistake, on a method that catches only what it already knows to look for.
There is a trap folded inside that, and it is the part that reaches the broker directly. A clear result invites you to stop. That is what it is for. Having relied on it, you cross-check the document less, and you keep less of your own record of having looked. If the clear was wrong, you carry the liability with less evidence of your own diligence than if the tool had never been in the file. Reliance on a detection you cannot verify leaves you more exposed, not less.
The second cost: the data leaves your hands
The failure of detection is only the first cost the broker carries. There is a further problem that has nothing to do with accuracy. To run these checks, most of these tools take the client's most sensitive financial documents off the broker's own system and process them on the vendor's, by methods the broker cannot see, and return a score or a result the broker cannot open up. Three consequences follow, and each one lands on the broker.
The result is not something you can stand behind. You did not perform the check, you cannot explain the principles it rests on, and you cannot judge whether the method is even valid for the purpose it was used for. The box reports a verdict without a denominator and without a window onto its own method, so there is no way for you to know whether it scans to the standard its marketing implies or well below it; you are asked to take the quality of the check on the same trust the check was meant to replace. You have outsourced a judgement and kept the responsibility for it. Second, the record it hands back is verifiable, if at all, only by going back to the vendor, which means your evidence depends on a company staying in business and staying cooperative. Third, you have disclosed your client's data to a third party, and the obligations that attach to that data stay with you. Reliance on the tool has reduced your visibility and left your exposure where it was.
Two honest caveats belong here, because a careful reader will raise them. Reconciling documents against each other and against the application is real, mature work, and some lender-side systems do it well; the point is not that reconciliation is new. And a form of proof-of-diligence already exists at national scale, as a buyer's-assurance scheme that reduces a lender's exposure when diligence is done its way. But that scheme validates data and stops short of the professional judgement, which is exactly where the line should sit. Judgement is the part that cannot be handed to a machine or a scheme, and should not be.
This is not only a lending problem
Before this comes home to the file in front of you, one temptation has to be closed off: to treat it as a quirk of lending that a broker might wait out. The pattern is not confined to mortgages. The same technologies, and the same overreach, appear across every field that has tried to automate trust. Identity and anti-money-laundering screening treats a passed check as a settled fact. Pre-employment and credential vetting seals a qualification the issuing registrar never confirmed. Insurance runs the same document forensics on claims. Academic-integrity tools produce the AI-text-detection problem in its purest and most-studied form, where a false positive is an accusation against a student. In each, a tool that can only ever flag a known trace is sold as if it could certify the truth. Lending is where the consequence is most expensive, but the flaw is category-wide. And in a lending file, that cost has a single bearer.
What this means for you, and what you can prove
For a broker, this arrives at a hard place. The documents can no longer be trusted on their face, the tools sold to check them cannot prove what they imply, and the liability for a file that later turns out to be fraudulent lands on you. Two layers of cover a broker leans on both stop short of this. Professional indemnity is third-party liability insurance, so it can answer a claim by a lender, not only a client, where a loss flows from the broker's own negligence. What it is not built to carry are the losses that sit in its standard exclusions: the broker's own dishonesty, the clawback of commission already paid, the indemnity or warranty a broker gives an aggregator or lender by contract, and, in many wordings, any claim arising from certifying or verifying the documents behind a loan application. A fabricated document a broker passed on in good faith tends to land in those exclusions rather than in cover, and wordings vary, so your own policy is what settles it. This is also how the loss reaches you in the first place: rather than carry a fraud loss itself, a lender recovers it from the broker under that agreement, the mechanism that moves the loss down the chain to whoever introduced the file. Cyber cover does not reach it either, because cyber responds to a data breach, a hack, or your own funds being redirected by deception, and a fabricated document sitting in a loan file is none of those. So the event most likely to follow a false clear is often the one neither policy will meet, and a broker today can be cut loose over a file they had no hand in falsifying, on association alone.
There is a longer tail to this than most brokers assume. You keep a file for seven years, because that is how long the law requires you to hold your records. Many treat that as the point where the file closes and the exposure ends with it. Fraud liability keeps its own clock. Where fraud is involved, the time to bring a claim can pause, and in some cases only begins, when the fraud is discovered or could reasonably have been discovered, so a loan written on false information may sit quiet for years and then start the clock from the day it surfaces rather than the day it settled. The outer limit runs to decades, thirty years in New South Wales. And this is already in motion: through 2026, regulators put lenders on notice over coordinated mortgage fraud, banks began combing back through their loan books, and hundreds of brokers were referred to authorities, many for no more than being the name attached to a file, because the reviews look for the same brokers, accountants and firms recurring across many applications and read that recurrence as a professional enabler network rather than a set of isolated files. On that footing a broker can be drawn in indirectly, and the fraud that draws the attention need not sit on their own file, or in the same year. A seven-year retention habit protects your compliance record. It does not cap how far back a fraud claim can reach, and a file you disposed of on schedule is a file you can no longer speak to.
Put those two together and the exposure takes a definite shape: it outlasts the records you are required to keep, it falls outside the cover you carry, and it rests on documents no tool could certify in the first place. That is the position the scan was sold to solve, and the position it leaves untouched.
The way through runs in the opposite direction to the scan. Stop trying to prove the document is genuine, which no one can do, and prove what you did about it, which you can. Your own conduct, the steps you took, the figures you reconciled across the file, and when you did it, is provable in a way the innocence of a PDF never will be, because it is a positive claim about your own work rather than a negative claim about someone else's. Two things make such a record protection rather than paperwork. It has to be made at the time you acted, under the rules that applied then, because a record built after a question is asked carries less weight in a dispute, not more; the law reserves its strongest presumptions for records kept in the ordinary course. And it has to be genuinely yours, held and controlled by you rather than living in a platform someone else can change or close, and kept for as long as it might be needed rather than only as long as the rules require.
A fairness point sits inside this. The law asks a broker for reasonable steps, and what is reasonable is bounded by what a broker can actually do in the ordinary course of a file. The genuinely capable detection systems, the ones running vast fraud-signature databases, are built and priced for institutions, not for a practice testing one file at a time, and even inside an institution they cannot certify that a document is genuine. So the reasonable standard cannot be a tool a broker cannot reach and that could not settle the question anyway. It is the diligence a broker can perform, and record.
That is also where the December change points. From 10 December 2026, privacy reform requires disclosure of the kinds of personal information a computer program uses when it substantially helps make a decision about a person. Your best-interests duty already asks for reasonable steps and a contemporaneous record of them, and that duty is personal to you: no aggregator, and no vendor, can discharge it on your behalf. The direction of travel is from trusting the machine to explaining it, and a record you own and can produce is how you meet it.
We publish this in the open because the limits described here belong to everyone, and a broker is entitled to know them before buying a tool that depends on them going unmentioned. A scan is worth running for what it can do, which is to catch the clumsy. What it cannot do is make a document prove its own innocence, and it should never talk you out of your own diligence. The record that protects you is the one that shows what you did, made when you did it, and owned by you.
Notes and sources
This paper names technologies and cites public authorities; it does not reproduce or link the academic research behind our own analysis. The statements attributed to authorities are drawn from their own publications and can be verified independently: the United States Federal Reserve on synthetic identity fraud (2019); a United States government audit office on the same; Europe's law-enforcement agency on morphing attacks against identity documents (2022); the European Union's AI Act, Article 50, on marking AI-generated content; a national standards body on the removability of watermarks; the content-provenance standard's own trust model and the first independent security review of it; and Australia's Document Verification Service scope. Performance figures quoted from the market are the vendors' own. Where the paper refers to independent testing of detection accuracy, it refers to peer-reviewed evaluation published through 2024 to 2026.
General information about the state of a technology market. Not personal credit, financial, tax or legal advice. A product of Aubelia Enterprise Pty Ltd trading as AeFin, an Australian Credit Representative (CR 464548) of Finsure Finance and Investment Pty Ltd (ACL 384704).