All posts
Deepfake Detection6 min read

We Invented a Student, a School, and a Report Card. Here's Why It's Fake.

No student, no school, no exam ever produced this mark sheet - we generated it ourselves to test our own detector. It's clean, consistent, and unremarkable to look at. That's exactly why it's a useful example of what an AI fake document detection check needs to catch.

View as Markdown
check if a document is ai generatedai fake document detectiondocument fraud detectiondeepfake detection kycdetect fraudulent documents in kycai kycai for kyc automationautomated document verificationautomated document tampering detectiondocument ai amlai-powered kyc checkfake kyc
We Invented a Student, a School, and a Report Card. Here's Why It's Fake. — TamperCheck.ai blog cover
We Invented a Student, a School, and a Report Card. Here's Why It's Fake. — TamperCheck.ai blog cover

We build our own fake documents. Not for fraud - to test the thing we built to catch fraud. Before we ship a change to TamperCheck's detection pipeline, we run it against a library of documents we invented ourselves, so we know exactly what's fake and can check whether the tool agrees.

Here's one of them: a higher-secondary mark sheet for a student who doesn't exist, from a school that doesn't exist, for an exam that never happened.

A completely AI-generated higher-secondary mark sheet showing invented subjects, marks, and an aggregate percentage, with no security background, stamp, or signature
Every number on this mark sheet was invented for a test suite. No student, no school, and no exam board are behind it.

Look at it for a few seconds. There's nothing obviously wrong. The subjects are ordinary. The marks are believable - nobody scores a suspicious 100 across the board. The maths even checks out: 92 + 88 + 79 + 85 + 74 + 96 + 81 comes to 595, and 595 out of 700 is exactly 85%, exactly what the sheet claims. If you handed this to a person for a quick sanity check, or ran it through a tool that just reads the text and confirms the numbers add up, it would pass without a second look.

0
real students, schools, or exams behind this document - all invented
595/700
aggregate marks - the arithmetic is exactly consistent
1
prompt: this document was never printed, scanned, or photographed

So why does it count as fake?

Because nothing about it happened. A genuine mark sheet has a physical life before it ever reaches you: a school prints it, someone stamps or signs it, and it gets scanned or photographed to be emailed or uploaded. That trip leaves marks of its own - a bit of paper texture, a slight tilt, uneven lighting, the soft blur of a phone camera, sometimes a security pattern printed right into the page.

This one skipped all of that. It went straight from a prompt to a finished image. There's no stamp, no signature, no watermark, and no trace of ever having been a physical object. It's not that it looks bad - it's that it looks too clean, in a way a document that has actually been through a printer and a camera almost never does.

A document that reads perfectly and adds up perfectly hasn't earned your trust yet - it's just told you it's internally consistent. A generated document is consistent by construction, because there was never a real original for the numbers to disagree with. Consistency and authenticity are two different questions.

Why automated document verification and AI KYC checks miss it

Nobody spends much time scrutinising a mark sheet, a payslip, or a utility bill the way they'd scrutinise a passport. These are the supporting documents - proof of education, proof of income, proof of address - that back up a bigger claim, and most onboarding and KYC flows treat them as a formality once the primary ID has cleared.

That's exactly what makes them a useful target. Generating one now costs almost nothing and takes a few minutes, and the result is good enough to pass a human glance or a basic automated document verification step that only confirms the text reads correctly and the fields are all present. If your AI KYC stack stops at "does this look like the right kind of document," a fabricated mark sheet like this one has no reason to ever get flagged.

That gap matters more as KYC and AML workflows lean harder on AI for KYC automation. An AI-powered KYC check that only validates structure - are the right fields there, does the format match, does the maths reconcile - is validating the story the document tells, not whether the document itself is real. Detecting fraudulent documents in KYC increasingly means asking a different question entirely: did this file ever exist as a physical thing, or was it rendered whole, invented top to bottom?

What a document fraud detection tool actually checks for

"Document fraud detection" gets used as one label for two different jobs. Automated document tampering detection looks for edits made to something that was originally real - a pasted-in signature, a changed figure, a spliced photo, a region that was copied and pasted from elsewhere on the same page. It compares a document against what a genuine version of it should look like internally.

AI-generation detection asks a different question first: did this file ever exist as a real object at all? The mark sheet above was never tampered with in the traditional sense - there's no genuine original it diverges from, nothing pasted onto anything. It needs the second kind of check, not the first, and a lot of document fraud detection tooling was built for the first case alone.

If you're evaluating a document fraud detection tool for your own onboarding or AML pipeline, it's worth asking directly whether it tests for wholesale fabrication as a separate case from tampering - not just whether it can find a splice.

See what your pipeline would have missed

Upload a document - real or one you're testing with - and get back a plain verdict on whether it was ever a physical original. $5 in free credits, no contract.

Test a fake document

FAQ

How do I check if a document is AI-generated?

Start by asking whether the document shows any sign of having existed physically - paper texture, uneven lighting, a slight tilt or blur from being photographed, a stamp or signature that sits naturally on the page. A document that's flawlessly flat, evenly lit, and free of any capture imperfections deserves a closer look, not automatic trust. For anything beyond a visual check, a dedicated forensic tool looks at the image itself rather than just what it says.

Can I just eyeball a document to tell if it's AI-generated?

Sometimes, but less and less reliably. Early AI-generated documents had obvious tells - garbled text, warped logos, mismatched fonts. Current tools produce results clean enough that a fabricated mark sheet, payslip, or utility bill can look completely ordinary at a glance, which is exactly the case in the example above. That's the reason detection has to look past what a document says and check whether it was ever a real, physical thing.

Why would someone fake a mark sheet or payslip instead of an ID?

Because it gets far less scrutiny. Passports and driver's licences are the documents everyone is trained to inspect closely; supporting evidence - proof of education, proof of income, proof of address - is usually treated as a formality once the primary ID has cleared. A synthetic identity built from a convincing invented address, payslip, and mark sheet can be more effective than a single forged ID, precisely because none of the individual pieces look suspicious.

Is this the same as deepfake detection for KYC?

It's the same underlying question - was this produced by a generative model instead of captured from something real - just applied to a different kind of document. Deepfake detection in KYC most often refers to identity documents and face imagery; the same idea applies just as well to a mark sheet, a payslip, or a bill. For the identity-document version of this problem, see our guide to deepfake document fraud in KYC.

What are the best alternatives to Veriff for catching AI-generated documents?

It depends what you're missing. Veriff and similar platforms are built around an owned identity session - guided capture, liveness, face match - and are strong at that. They're not built as a dedicated forensic layer for documents submitted outside that session, such as uploaded, emailed, or collected through your own forms, which is exactly where invented supporting documents tend to slip through unnoticed. TamperCheck is a focused document-forensics API that runs alongside an existing IDV stack rather than replacing it. See the full comparison in Veriff vs TamperCheck.ai.


Add AI-generation detection to your document fraud detection stack

TamperCheck.ai checks whether a document was ever a real, physical original - alongside its automated document tampering detection and forgery checks - on every document you send it. Works alongside Onfido, Jumio, Persona, Veriff, Sumsub, or any existing AI KYC / AML stack.

Think you can spot a fake?

Upload a suspicious document and let TamperCheck do the forensics - a clear verdict in about a minute. $5 in free credits, no contract.