Fraud Detection
Document fraud detection that catches edited bank statements at intake.
About 1 in 5 bank statements submitted to lenders is flagged high risk for tampering. Kaaj checks 25+ forensic signals on every document in under 5 seconds, highlights exactly what was edited, and cross-checks the whole package, before anyone invests time in analysis.
Book a demoWhat Kaaj sees across live lender traffic Β· September 2026
Tampered statements are routine, not rare. Catching them is a forensics problem, not a skim.
1 in 5
bank statements submitted to lenders is flagged high risk for tampering signals
25+
forensic signals checked on every document
<5s
to run document forensics on a file
0.00
median fraud score: most files are clean, so underwriters only review the flagged minority
Measured on bank statement PDFs submitted to lenders using Kaaj over a trailing 30-day window (September 2026). Each statement is compared against a fingerprint of genuine statements from the same issuing bank and scored from 0 (matches the bank's baseline) to 1 (strong tampering indicators). "High risk" is a forensic verdict that routes the file to an underwriter; it is not a determination of fraud.
See exactly what was edited
Every flag comes with evidence. Kaaj overlays the original and the edited text on the page, lists each risk indicator, and gives a verdict an underwriter can act on in seconds.
- 01
Fingerprint the bank
Each statement is compared with genuine statements from the same issuing bank.
- 02
Run 25+ signals
Metadata, fonts, concealed text, structure, and balance math, in under 5 seconds.
- 03
Score and verdict
A 0-to-1 fraud score and a clear risk level: clean, low, medium, or high.
- 04
Show the evidence
Edited text is highlighted on the page and results sync to your CRM or LOS.
25+ forensic signals, grouped by what they catch
Bank-specific baselines cover about two-thirds of the statements lenders receive, and high-risk rates vary by more than 4x between issuing banks. Generic checks miss that; a fingerprint of each bank's genuine statements does not.
| Category | Signal | What it catches |
|---|---|---|
| Bank fingerprint | Baseline deviation | Statement differs from genuine statements issued by the same bank: layout, fonts, streams, page size, structure. |
| Producer & metadata | Unknown producer or creator | PDF was produced or re-saved by editing software the bank does not use. |
| Creation vs. modification dates | File was modified after the bank generated it. | |
| Missing metadata fields | Metadata stripped or rewritten to hide the editing tool. | |
| Edit-protection mismatch | Bank normally locks its PDFs; this copy is editable. | |
| Fonts & text | Unusual fonts | Typefaces the bank never uses, typical of retyped numbers. |
| Unusual font sizes | Digits or lines at sizes that do not match the template. | |
| Concealed or overlapping text | New values drawn over original ones (the classic white-box edit). | |
| Unusual encoding | Text encoded differently from the rest of the document. | |
| File structure | Internal structural anomaly | Object structure not found in the bank's genuine files. |
| Missing required stream types | Content streams a genuine statement always contains are absent. | |
| File size anomaly | File is far larger or smaller than the bank's norm. | |
| Non-standard page size | Page dimensions differ from the issuing bank's template. | |
| Math & content | Balance reconciliation | Beginning balance plus deposits minus withdrawals does not equal the ending balance. |
| Cross-document | Name and address mismatch | Business or owner details differ across application, Secretary of State, bank statement, and ID. |
| ID mismatch | Driver's license name, date of birth, address, or dates do not match the application. | |
| Revenue mismatch | Tax returns or financial statements disagree with bank deposits. | |
| Invoice vs. request | Invoice vendor, amount, or equipment does not match the loan request. | |
| Account mismatch | Voided check account or name differs from the bank statements. | |
| Cross-application | Duplicate submissions | Same applicant or EIN resubmitted under a slightly different name. |
| Shared identifiers | Same phone, address, or bank account across unconnected applications. | |
| MCA & debt | MCA stacking | Undisclosed merchant cash advance positions and recurring funder debits. |
| Business legitimacy | Web presence and domain age | No real footprint, a days-old domain, or a business that does not appear to operate. |
Every document in the package, not just bank statements
Fraudsters edit whatever the lender relies on. Kaaj checks each document and then checks the documents against each other and the application.
| Document | What Kaaj checks |
|---|---|
| Bank statements | Bank fingerprint, metadata, fonts, concealed text, file structure, balance math, deposit patterns, MCA and loan activity |
| Tax returns | PDF forensics; revenue and entity details checked against bank deposits and the application |
| Financial statements | PDF forensics; figures checked against tax returns and bank activity |
| Invoices | PDF forensics; vendor, amount, and equipment details checked against the loan request |
| Driver's licenses | Field extraction; name, date of birth, address, and issue and expiration dates checked against the application |
| Voided checks | Account holder and account details checked against bank statements and the application |
| Insurance certificates | PDF forensics; insured business details checked against the rest of the deal |
Kaaj's strongest model
MCA stacking, caught before funding
The most expensive fraud in small business lending is not a forged PDF; it is an undisclosed position. Kaaj identifies merchant cash advance funders, disbursements, and recurring remittances across every statement and account, and shows payment frequency and timing for each position.
- Funder names recognized from research-backed data, not static keyword lists
- Disbursements separated from operating revenue
- Recurring remittances with frequency and first and latest payment dates
- Stacking visible across multiple accounts and statement months
Document fraud vs. identity fraud tools vs. manual review
Identity platforms verify people and payments. Kaaj verifies the documents in the credit file. Most lenders need both; few need another manual checklist.
| Kaaj | Identity & transaction fraud tools | Manual review | |
|---|---|---|---|
| What it verifies | Documents and the application package | People, devices, and payments | Whatever the reviewer has time for |
| Edited bank statements | 25+ forensic signals with the edits highlighted | Not the focus | Font and formatting eyeballing |
| Documents covered | Statements, tax returns, financials, invoices, IDs, voided checks, insurance certificates | ID documents and identity data | Varies by reviewer |
| MCA stacking | Detected across accounts and months | Not covered | Manual pattern spotting |
| Speed | Forensics in under 5 seconds, at intake | Real-time identity checks | Minutes to hours per file |
| Output | Risk level, indicators, and evidence in your CRM or LOS | Identity risk scores | Notes in the file |
Document tampering detection
Altered bank statements, modified PDFs, inconsistent metadata. Forensic checks at the file level.
Name & address mismatches
Business name on the application vs. SOS records vs. bank statements vs. driver's license. Cross-checked and flagged.
Duplicate submissions
Same applicant, slightly different entity name, submitted to multiple departments. Detected and consolidated.
Suspicious web presence
No website, 2-day-old domain, no reviews, fake-looking business. Web presence signals scored and surfaced.
Document inconsistency
Invoice doesn't match equipment title. Tax return shows different revenue than bank statements. Flagged.
Pattern detection
Same phone, address, or bank account appearing across multiple unconnected applications. Surfaced as risk signal.
Cross-document signal scanner
3 signals need reviewWhy fraud slips through
Fraud investigations often begin only after credit analysis has already consumed time. By then, the team has spent 30β60 minutes reviewing documents that should have been flagged at intake. Kaaj moves fraud detection to the front of the workflow, before anyone opens a bank statement.
0 minutes
Time spent on deals that should've been flagged. Fraud detection runs before any human touches a file.
Fraud detection FAQ
How does Kaaj detect edited or fake bank statements?
Kaaj compares each statement against a fingerprint of genuine statements from the same issuing bank and checks 25+ forensic signals: producer and metadata, fonts and encoding, concealed or overlapping text, file structure, and whether balances actually add up. Edited values are highlighted on the page so an underwriter can see exactly what changed.
How common are tampered bank statements in lending?
Across live lender traffic in September 2026, 1 in 5 bank statements submitted to lenders was flagged high risk for tampering signals, and about 2% contained concealed or overlapping text edits. High-risk rates also vary by more than 4x between issuing banks, which is why bank-specific baselines matter.
Which documents does Kaaj check for fraud?
Bank statements, tax returns, financial statements, invoices, driver's licenses, voided checks, and insurance certificates. Each document gets forensic checks and is cross-checked against the rest of the package and the application.
How fast is Kaaj's fraud detection?
Document forensics run in under 5 seconds per file, at intake, before an analyst opens the deal.
Can Kaaj detect MCA stacking?
Yes. MCA detection is one of Kaaj's strongest models: it identifies merchant cash advance funders, disbursements, and recurring remittances across statements and accounts, surfacing undisclosed positions and stacking before funding.
Does Kaaj produce a lot of false positives?
Most statements are clean: the median fraud score is 0.00. Bank-specific baselines, which cover about two-thirds of statements lenders receive, keep normal bank formatting from being flagged, and every flag shows its evidence so reviewers can clear benign issues quickly.
Is Kaaj a replacement for identity verification tools like Alloy or Socure?
No. Identity and transaction-fraud platforms verify people and monitor payments. Kaaj focuses on document and application-package fraud in the credit file, and it works alongside identity tools.
Where do fraud results show up?
In the Kaaj fraud report with a risk level, the specific indicators, and the edited text highlighted on the document, and alongside the application in your CRM or LOS such as Salesforce.