Document Fraud
Pronunciation: DOK-yuh-ment FRAWD
Definition
Document Fraud is the creation, alteration, theft, substitution, or misuse of a document to misrepresent identity, authority, ownership, eligibility, a transaction, or another material fact. It includes forged documents and genuine documents used by an unauthorized person or in a deceptive context. Controls should assess document source, integrity, security features, data consistency, issuer verification, liveness and holder linkage where relevant, duplicate use, metadata, sanctions and identity context, manual escalation, and retention of evidence and reviewer decisions.
Overview
Document Fraud is the creation, alteration, theft, substitution, or misuse of a document to misrepresent identity, authority, ownership, eligibility, a transaction, or another material fact. The control exists to prevent deceptive or unauthorized transactions, reduce customer and merchant loss, and preserve evidence for recovery, dispute handling, and investigation. It includes forged documents and genuine documents used by an unauthorized person or in a deceptive context. It should be interpreted alongside Business Verification because the concepts can affect the same decision without representing the same control, event, or risk.
The workflow combines identity, device, behavior, communication, beneficiary, transaction, and historical signals before and after payment. High-risk changes or instructions should be verified through a trusted independent channel, and controls should not rely on information supplied inside the potentially compromised message or session. In this context, controls should assess document source, integrity, security features, data consistency, issuer verification, liveness and holder linkage where relevant, duplicate use, metadata, sanctions and identity context, manual escalation, and retention of evidence and reviewer decisions.
It should connect the term to Invoice Fraud where that relationship changes access, transaction treatment, investigation, communication, or recovery.
Records should preserve the original request, account and device events, approvals, beneficiary changes, transaction identifiers, communications, authentication results, review notes, and recovery actions. Teams should connect related attempts without exposing unnecessary personal or credential data.
Useful measures include attempted and confirmed loss, prevented value, false-positive rate, review time, recovery rate, beneficiary-change exceptions, customer complaints, repeat attacks, and control-bypass findings.
The relationship with Deepfake Fraud should be documented where it affects residual risk or control ownership.
Key Takeaway
Controls should assess document source, integrity, security features, data consistency, issuer verification, liveness and holder linkage where relevant, duplicate use, metadata, sanctions and identity context, manual escalation, and retention of evidence and reviewer decisions.
Sources
- Business Email Compromise — FBI Internet Crime Complaint Center (2026-08-03)
- Recognize and Report Phishing — Cybersecurity and Infrastructure Security Agency (2026-08-03)
- Security and Privacy Controls for Information Systems and Organizations, SP 800-53 Rev. 5 — NIST (2026-08-03)