Supported document type
Detect tampered and deepfake Loan Statement
A loan statement is the lender's own account of what a borrower still owes and how reliably they pay. Applicants alter it to shrink the debt an underwriter sees, or to hide missed payments. Because principal, interest, and instalment follow from each other row by row, the edit that looks like one number has to be several, and the outstanding balance has to walk forward consistently down the payment history.
API slug: loan_statement
What a genuine loan statement contains
A loan statement names the lender, the borrower, and the loan account number, and gives the statement date, original principal, outstanding principal, interest rate, instalment amount, and next due date. Below sits a table of payments and charges, often with interest and principal split for each instalment, plus any late fees and an arrears position.
The table is a running calculation. Interest for a period is roughly the opening balance times the rate over the days elapsed, principal repaid is the instalment less interest, and the new balance is the old one less principal. A missed payment appears as arrears or a late fee. The account number, borrower name, and lender branding should stay identical across every page.
How loan statement forgeries are made
Outstanding balance reduction
The principal shown is cut so the applicant's liabilities look smaller. The history below it no longer supports the new figure, unless it is rewritten too, and rewritten rows lack the original page's rendering.
Removing arrears
Late fee and overdue lines are deleted to present a clean record. The instalment count, running balance, or interest accrual leaves a gap where the removed rows were.
Instalment understatement
The monthly payment is lowered to improve an affordability ratio. The rate, balance, and term no longer generate that payment, so the statement disagrees with its own terms.
Borrowed statements
A genuine statement from someone else's loan is relabelled with the applicant's name. The name block rarely matches the surrounding text's rendering, and the account details conflict with the applicant's bank debits.
What TamperCheck checks on a loan statement
TamperCheck runs 200+ forensic checks across three layers and returns a risk score from 0 to 100 with plain-English findings tied to specific regions of the document. These three carry the most weight on this document class.
Arithmetic reconciliation
Stated totals are recomputed from their components, and running or cumulative figures are checked for continuity across periods. A single edited value breaks the chain even when the page still looks right.
Table structure integrity
Inserted and deleted rows leave structural artifacts behind: inconsistent spacing, misaligned columns, and formatting the visible table no longer accounts for.
Letterhead, logo, and issuer plausibility
Issuer branding is checked for resolution and compression consistency against the body text it sits on. A logo lifted from a website carries the signature of its source, not of the document.
And many more checks
The three above are the layers that carry the most weight on a loan statement. Every upload runs the full suite of 200+ checks regardless of document class, spanning file structure and metadata, pixel-level forensics, font and text rendering, optical and print characteristics, provenance signals, AI-generation signatures, and many more checks.
Who verifies a loan statement, and why
Lenders, underwriters, and credit risk teams assessing existing debt. In each case the document is being used to unlock money, access, or a legal status, which is exactly what makes it worth forging.
How to verify a loan statement in 4 steps
Check the fields against each other
Read outstanding principal, payment history, and arrears and late fees together rather than one at a time. Forgers typically change one value and leave the rest of the document describing the original.
Inspect the file metadata
Open the document properties and look at the producer, creation date, and modification date. A document produced by a consumer PDF editor, or created long after the date printed on its face, is worth a closer look.
Ask for a second document
Request a corroborating document from the same issuer or an adjacent period. Forgery effort concentrates on one file, so inconsistencies surface as soon as there are two to compare.
Run a forensic check
Manual review catches obvious edits but not field-level pixel manipulation or synthetic generation. TamperCheck runs 200+ forensic checks on a loan statement and returns a risk score from 0 to 100 in about a minute, at $0.50 per document.
Frequently asked questions
How do underwriters detect an edited loan statement?
They test the statement against itself first: the balance progression, interest against rate, and instalment against terms. Then they compare the instalment with the debits on the applicant's bank statement. A forensic scan looks for figures that were inserted after the statement was produced.
How can I tell whether a loan statement is real?
Check that the lender, account number, and dates are consistent on every page, that the balance moves plausibly from payment to payment, and that the instalment matches the bank statement. Then confirm with the lender if the decision is material.
Why would someone alter a loan statement?
To qualify for new credit. Existing debt reduces borrowing capacity, and a history of arrears reduces approval odds, so the balance and the payment record are the two fields most often changed.
Is a loan statement the same as an amortization schedule?
No. A statement records what actually happened on the account up to a date. An amortization schedule is the plan for every future payment. Underwriters use both, but only the statement reflects prepayments, missed instalments, and rate changes.
TamperCheck analyses loan statement uploads with a hybrid forensic and AI pipeline tuned for this document class. Upload endpoints accept PDF and common image formats; class is inferred automatically. See the API documentation for authentication, async jobs, and webhooks.