Explainable Document Forensics: Why a Score Alone Fails Audit

Explainable document forensics shows where a file was altered, what it said before, and how the examiner knows. Why a fraud score alone fails audit.
Dean Uata, Founding GTM at Sphinx
Dean Uata

TL;DR: Explainable document forensics is the practice of showing where a file was altered, what it said before, and how the examiner knows, rather than returning a fraud probability. The DocForge-Bench study published in March 2026 found that tampered regions occupy only 0.27 to 4.17 percent of pixels in forged document images, which is why a whole-file score hides the one edit that matters. SR 11-7 expects model documentation a stranger can follow, and the CFPB has said twice that a black-box model is no excuse for a vague adverse action reason.

What Document Forensics Actually Is

Document forensics is the examination of a document to determine whether it is what it claims to be: issued by the stated party, on the stated date, and unchanged since. Its two branches share a name and little else.

Questioned-document examination works on paper. Examiners compare ink, paper stock, indentations, and handwriting against known exemplars and write an opinion a court can test.

Digital document forensics works on files. A PDF is not a picture of a page. It is a structured container of objects, fonts, image streams, cross-reference tables, and metadata, and every producer and editor leaves a characteristic pattern in that structure. The PDF Association's 2025 session on incremental saves calls version history one of the best ways to understand the intent behind an edit, because an incrementally saved file retains earlier states a full rewrite discards. Scanned or photographed documents add image forensics, where compression and texture inconsistencies around edited text are the evidence.

In both branches a forensic result is a set of findings a second examiner could reproduce. A number between 0 and 100 is not a finding. It is a summary of findings the system did not show.

Why a Score Alone Fails

A fraud score fails three people for three reasons, and none of them is that the score is wrong.

The analyst cannot act on it. A bank statement at 0.71 says nothing about what to do next. Is the closing balance edited, or did the applicant print to PDF from a browser? Same score, opposite dispositions. Without the located edit, the analyst either re-reviews the file by eye, the step the tool was meant to replace, or accepts the number.

The auditor cannot verify it. SR 11-7 expects model documentation "sufficiently detailed so that parties unfamiliar with a model can understand how the model operates, its limitations, and its key assumptions," and applies that to vendor models. A tool that outputs only a score leaves the institution validating a black box, the situation AML model validation requirements exist to prevent.

The applicant cannot be told why. When a document verdict feeds a credit decision, ECOA and Regulation B require a statement of the specific principal reasons for adverse action. The CFPB's Circular 2022-03 states that a creditor "cannot justify noncompliance" because its technology "is too complicated or opaque to understand," and Circular 2023-03 added that checking the closest box on a sample form does not count if it is not the actual reason. "Document failed fraud check" is a box. "Closing balance altered after the file was produced" is a reason.

Sphinx set out the broader principle in how every Sphinx decision is made auditable. Document forensics is its sharpest instance. The edit is in the file or it is not.

What a Defensible Verdict Contains

Diagram of a defensible document fraud verdict containing the score plus located edit, original value, producer, timestamps, and template match
A verdict an auditor can use pairs the score with the evidence that produced it.

A defensible document fraud verdict is a written finding a second reviewer can check against the file without rerunning the model. Five elements carry it.

Element Score-only output Evidence-backed output
The located edit "Manipulation likely" Page 2, row 14, deposit amount field, highlighted on the page
The original value Not available Prior revision shows $1,240.00; current shows $12,400.00
Producer and timestamp evidence Not available Created by the issuer's statement engine June 3; modified by a desktop editor June 19
The matched template Not available Layout matches issuer family X; font in the edited field does not
The reasoning Confidence 0.87 Value changed after issuance, by software the issuer does not use, in the eligibility field

The right-hand column is what a case note, a SAR narrative, and an adverse action reason need. A score can sit on top for triage. It cannot be the verdict.

How Six Checks Produce Evidence, Not a Number

Diagram of six document checks each producing an evidence item that feeds a single explained verdict
Each check contributes evidence, not just a weight; the verdict is the sum of things a reviewer can point to.

Each class of forensic signal answers a plain-language question. The check itself is the explanation.

Production method asks how the file was made. Issuer systems, office software, print-to-PDF drivers, and generative tools construct files differently, and the construction is visible in the object structure. The finding is a statement such as "produced by a browser print driver, not the issuer's statement engine."

Timestamp trail asks what happened after creation. Edited-after-creation files, the most common competent forgery in lending and onboarding, carry revision evidence: save events after the stated issue date, a modifying application that differs from the creator, or a prior revision that still holds the original value. Where that prior state is recoverable, the verdict shows before and after.

Issuer matching asks whether the file resembles what that issuer actually produces. A layout that matches a known issuer family while one field uses a font the family never uses is a located finding.

Consistency asks whether the numbers agree. A statement whose transactions do not sum to its closing balance is wrong on its face, and the arithmetic is the evidence. It is corroboration, not proof. Generated fakes agree with themselves by construction, which is why detecting an AI-generated PDF needs the other five checks.

Model artifacts asks whether the page carries traces of generative production. On scanned or photographed documents this is image forensics: texture, compression, and rendering inconsistencies in the changed region.

Recycled patterns asks whether this file, or a near copy, has been seen before. The evidence is the matched prior case and the fields that differ.

DocForge-Bench found that none of the 14 detection methods it tested worked reliably out of the box, mostly because of threshold calibration. Showing the located region lets the reviewer see whether a flag is real. A score hides that question.

What the Analyst Still Has to Judge

Explainable forensics narrows the analyst's job without removing it. Three judgments stay human.

Intent is the first. An incremental save after issuance proves the file changed. It does not prove fraud. A borrower who flattened a statement in a free PDF tool, a broker who redacted an account number, and a forger who raised a balance all leave revision evidence. Materiality is the second. An edit to a footer and an edit to the closing balance are both edits. Only one changes eligibility. The output should show the change and the changed value so the analyst can settle both questions.

The hard cases are the third: a scan of a genuine letter, a bilingual registry extract, an issuer that rebranded last quarter. FinCEN's November 2024 deepfake alert makes the same point about GenAI indicators: no single red flag is necessarily indicative, and institutions should weigh the surrounding facts. Evidence lets the analyst reach that judgment. A score forces a guess.

What to Do With a Verdict

An evidence-backed verdict is reusable wherever a document decision has to be defended.

To see a located verdict on a real file, check a document in the Watchdoc playground and compare the x-ray view against the current case note.

Where Sphinx Fits

Sphinx Watchdoc is the product expression of explainable document forensics. Every file runs through the six checks above, and the verdict comes back as an x-ray view: the edit highlighted on the page, the recovered original value where the file history holds it, the producer and timestamp trail, and the matched issuer template. The verdict is correct 94.3 percent of the time, catches 2.8 times more forgeries than a visual baseline, and clears clean files in under 28 seconds. Pricing is $0.45 per document, no seats, no platform fee. The Watchdoc playground is free for the first file, no email required, then a 50-document free tier.

Watchdoc does not decide the case. It hands the analyst the evidence and leaves intent and materiality to the person who owns the outcome. See also document fraud in banking and generative AI document fraud as a compliance risk.

Frequently Asked Questions

What is explainable document forensics?

Explainable document forensics is document authentication that returns evidence rather than only a score: where the file was altered, what the original value was, which software touched it and when, and which issuer template it matches. A second reviewer can verify the finding against the file.

Why is a document fraud score not enough for an audit?

Examiners working under SR 11-7 expect documentation that lets someone unfamiliar with a model understand how it operates and what its limits are. A score with no supporting evidence cannot be challenged, reproduced, or tied to a fact in the file, so the institution ends up defending a number it cannot explain.

Can a document fraud verdict be used in an adverse action notice?

Only if it is specific. ECOA and Regulation B require the principal reasons for adverse action to accurately describe the factors actually considered, and the CFPB has stated that complex or opaque models do not relax that requirement. A located edit with the original and changed values is a specific reason. A score is not.

What is the difference between digital document forensics and questioned-document examination?

Questioned-document examination analyzes physical documents: ink, paper, printing characteristics, and handwriting compared against known exemplars. Digital document forensics analyzes the file itself, including object structure, fonts, image streams, producer metadata, and revision history. Both aim for reproducible findings about whether a document is genuine and unaltered.

What does a fraud analyst still have to decide when the tool explains its verdict?

Intent, materiality, and the hard cases. Forensic evidence can prove a file changed after issuance and show which field changed, but not why. The analyst decides whether the edit matters, whether an innocent explanation fits, and what disposition, SAR, or adverse action follows.

Get Your Free AI Compliance Handbook

What compliance leaders need to know about AI-driven fraud, autonomous laundering, and how your team can
fight back.
Submit
Thank you! Your submission has been received!
Something went wrong while submitting the form. Please try again.