Supported document type
Detect tampered and deepfake Direct Debit Mandate
A direct debit mandate is the signed authority that lets a creditor pull money from a bank account. Its fraud comes in two forms: a mandate signed by someone who does not own the account, and one whose amount or creditor was changed after signing. The document is small and mostly boxes, so what carries the evidence is the account number, the signature, and whether the form fields were filled at one sitting.
API slug: direct_debit_mandate
What a genuine direct debit mandate contains
A mandate identifies the debtor by name and address, gives the bank and account details (an IBAN, or an account and routing number), and names the creditor with an identifier and a mandate reference. It states the scheme, such as SEPA, ACH, or NACH, whether the mandate is one-off or recurring, the amount or its maximum, and the frequency. The debtor signs with a date and place, and a bank section may be stamped.
Account numbers carry check digits: an IBAN passes a modulus test and many national formats have their own rules, so a mistyped or invented number can fail. The debtor's name should match the account holder, the creditor identifier should follow its scheme's format, and the signature should resemble the debtor's on other documents. Electronic mandates have no wet signature and are judged on their audit trail instead.
How direct debit mandate forgeries are made
Signature forgery
An account holder's signature is drawn or pasted onto a mandate they never signed. Identical stroke geometry across documents, or a signature with a different resolution from the form, is a signal.
Account swap
The account number is changed so funds are drawn from a different person. The edited digits stand apart from the printed form, and the account may fail its format check.
Limit and frequency edits
The amount ceiling or the frequency is raised after signing. The changed field's rendering differs from fields filled originally.
Creditor replacement
A mandate for one biller is repurposed for another by changing the creditor block. The identifier and reference formats then fail to match the stated scheme.
What TamperCheck checks on a direct debit mandate
TamperCheck runs 200+ forensic checks across three layers and returns a risk score from 0 to 100 with plain-English findings tied to specific regions of the document. These three carry the most weight on this document class.
Arithmetic reconciliation
Stated totals are recomputed from their components, and running or cumulative figures are checked for continuity across periods. A single edited value breaks the chain even when the page still looks right.
Stamp authenticity and placement
Stamps are assessed for whether the ink was impressed onto the page or printed as part of it, and for whether the impression was placed digitally after the fact.
Signature forgery analysis
Signature regions are assessed for ink consistency and for how the stroke sits on the page, which distinguishes a genuine pen stroke from a pasted image of one.
And many more checks
The three above are the layers that carry the most weight on a direct debit mandate. Every upload runs the full suite of 200+ checks regardless of document class, spanning file structure and metadata, pixel-level forensics, font and text rendering, optical and print characteristics, provenance signals, AI-generation signatures, and many more checks.
Who verifies a direct debit mandate, and why
Banks, billers, payment processors, and lenders collecting by debit. In each case the document is being used to unlock money, access, or a legal status, which is exactly what makes it worth forging.
How to verify a direct debit mandate in 4 steps
Check the fields against each other
Read account number or IBAN, signature, and creditor and amount together rather than one at a time. Forgers typically change one value and leave the rest of the document describing the original.
Inspect the file metadata
Open the document properties and look at the producer, creation date, and modification date. A document produced by a consumer PDF editor, or created long after the date printed on its face, is worth a closer look.
Ask for a second document
Request a corroborating document from the same issuer or an adjacent period. Forgery effort concentrates on one file, so inconsistencies surface as soon as there are two to compare.
Run a forensic check
Manual review catches obvious edits but not field-level pixel manipulation or synthetic generation. TamperCheck runs 200+ forensic checks on a direct debit mandate and returns a risk score from 0 to 100 in about a minute, at $0.50 per document.
Frequently asked questions
How do billers verify a direct debit mandate?
They validate the account number format, confirm the creditor identifier and reference, and compare the signature with samples on file. Forensic analysis of a scanned or digital mandate tests whether any field was altered after signing.
Can a direct debit mandate signature be forged?
Yes. A signature is a small graphic and can be traced or pasted. What is hard to fake is consistency: the same stroke shape on unrelated documents, or a signature at a different resolution from the printed form, stands out in analysis.
What is the difference between SEPA, ACH, and NACH mandates?
They are regional schemes for authorising debits: SEPA in Europe, ACH in the United States, and NACH in India. Each has its own form fields and identifier formats, which is why a mandate that mixes conventions is suspicious.
Does a direct debit mandate always need a wet signature?
No. Many schemes accept electronic mandates authorised online, in which case the record is a digital consent trail. A paper mandate, however, should carry a real signature and date, and a blank or pasted-looking one is worth flagging.
TamperCheck analyses direct debit mandate uploads with a hybrid forensic and AI pipeline tuned for this document class. Upload endpoints accept PDF and common image formats; class is inferred automatically. See the API documentation for authentication, async jobs, and webhooks.