TL;DR: KYB document fraud detection is the check on whether certificates of incorporation, registry extracts, and proof of address are genuine files, not whether a company name exists in a registry. FinCEN's November 2024 alert documented a rise in SARs describing GenAI media used to circumvent identity verification. Visual review of KYB packs fails against edited-after-creation PDFs that still look like issuer output.
The Registry Record Is Not the File

KYB document fraud detection is the review of the paperwork a business submits at onboarding: whether those files were issued as claimed, left unaltered, and unique to that application. It is not a definition of what KYB is, and it is not a speed problem. Registry lookup, UBO mapping, and sanctions screening can all pass while the PDF is a template, an edit, or a reuse.
Business onboarding binds documents to each other, not to a face. A certificate of incorporation has no liveness check. A registry extract has no biometric. Reviewers trained on KYC IDs look for holograms and font kerning. Those tells were built for plastic cards, not native PDFs emailed from a formation agent.
The joint FATF-Egmont Group study on concealment of beneficial ownership found shell companies in more than half of 106 laundering cases, averaging over USD 500 million per case. That is entity risk. File risk sits one layer down: the papers that make a shell look established travel as attachments, not as live registry sessions. FinCEN's guidance on shell companies still holds that most shells are legitimate. The intake question is narrower. Did this applicant submit the issuer's file, an edited copy, or a generated stand-in that agrees with itself?
What a Fake KYB Document Actually Is
A fake KYB document is any file presented as an official business record that was never issued in that form, or that was issued and then changed. Two production methods dominate, and they leave different residue.
Edited-after-creation files start as real issuer output: a formation-agent PDF, a secretary-of-state or Companies House extract, a utility bill. Someone then changes a name, number, date, address, or director. Layout and most fonts stay genuine because they were genuine. Surface review sees a familiar template. The file history does not.
Generated-from-scratch files never touched an issuer system. A model or a template farm produces a certificate that looks like Delaware, Singapore, or BVI output. Internal consistency is often better than a real pack, because real businesses carry typos and legacy addresses. A generated pack agrees with itself by construction, which is why matching the certificate to the proof of address, without inspecting how each file was made, is a weak test.
The KYB pack is the unit of fraud, not a single page. Typical contents:
A reviewer who accepts the certificate because the company number matches a public search has not tested the file. Public records confirm that some entity exists. They do not confirm that the PDF is that entity's document, or that the address page was not reused last week. This is the corporate subset of document fraud in banking: formation papers, extracts, and address evidence used to open merchant, banking, or lending relationships.
Tells That Still Work, and the Ones That Don't
Some visual tells still catch amateur work. Competent KYB fraud does not leave those tells. Treat the table as a triage aid, not a clearance standard.
Serial reuse is the KYB-specific pattern visual review almost never sees. The same certificate, registry PDF, or proof of address appears in multiple applications with small field changes, or none at all when a ring is cycling shelf entities. One file in isolation looks ordinary. The pattern only appears when intake compares files to other files, not just to a registry API. Registered-agent addresses are legal; shell company red flags belong in the entity decision. On the document, the question is whether the bill or lease was issued to this applicant and not copied from a prior case.
Do not treat a matching company number as authenticity. Matching means the forger read the registry. It does not mean the PDF came from the registry.
How Detection Actually Reads the File
Detection that works on KYB packs reads the file's story, not the reviewer's impression of the page. Six classes of signal cover the usual production methods. Each is a question a reviewer should be able to answer in writing, not a recipe for beating the check.
Production method asks how the file was made. Issuer systems and formation platforms leave different construction patterns than a generative model or a filled template. Timestamp trail asks what happened after creation. Edited-after-creation fraud lives here: revision counts, save times that do not match the stated issue date, software the claimed issuer does not use. A clean visual page with a messy history is the typical KYB miss.
Issuer matching asks whether the file resembles what that issuer actually produces. Template resemblance is not proof of issuance. Divergence from the issuer family is a reason to stop. Consistency asks whether names, dates, and addresses agree inside the file, across the pack, and with the registry row. Use it as corroboration. Generated packs pass consistency on purpose.
Model artifacts ask whether the page carries traces of generative production, not a font an analyst was trained to circle. FinCEN's deepfake alert was written around identity media, but the same GenAI tooling now produces formation papers that never existed in a filing office. Recycled patterns ask whether this file, or a near copy, has appeared before. Serial reuse of certificates and proof of address is invisible in a single-application review.
Human judgment still sits on the hard cases: a scan of a real extract, a bilingual registry, a recently rebranded issuer template. The system should present the evidence, not an unexplained score. A reject with no file story is as weak in an exam as a clear with no file story.
What to Do With a Suspect KYB File
A suspect file is not yet a SAR and not yet an automatic decline. Sequence the response so the team does not spend an hour on a file that fails in seconds, and does not rubber-stamp a file that only looks clean.
A break-test is useful when the team is unsure whether current controls would catch a known-bad pack. Run a forged certificate, an edited extract, and a reused proof of address through the live applicant path. If those files clear, the process is measuring pack completeness, not authenticity.
When the team needs an independent read on a specific PDF, check a document in the Watchdoc playground. Use the file history and highlighted manipulation to request a fresh issuance, decline, or file. The playground does not replace registry lookup or UBO work.
Where Sphinx Fits
Sphinx Watchdoc scores the KYB file at intake on those six checks. Clean files clear in under 28 seconds. The verdict is correct 94.3 percent of the time, and the same checks catch 2.8 times more forgeries than a visual-plus-template baseline. Pricing is $0.45 per document, no seats, no platform fee, with 1 million documents processed to date. The Watchdoc playground is free for the first file, no email required, then a 50-document free tier.
Watchdoc does not replace a KYB platform. It sits on the documents that platform already collects, so a company that exists in the registry cannot complete onboarding on an edited certificate or a recycled bill. Keep entity screening and ownership mapping in the systems built for those jobs. The formation PDF itself is covered in how to spot a fake certificate of incorporation.
Frequently Asked Questions
What is KYB document fraud detection?
KYB document fraud detection is the authenticity review of business files submitted at onboarding, including certificates of incorporation, registry extracts, and proof of address. It asks whether each file was issued as claimed and left unaltered. Registry existence and UBO screening are separate controls and can pass while the PDF is still a fake.
How is this different from a company registry lookup?
A registry lookup confirms that an entity with a given name or number appears in a public or licensed database. KYB document fraud detection inspects the file the applicant uploaded. A forger can copy a real registry row onto a generated or edited certificate. Matching fields therefore do not prove the PDF came from the issuer.
Which KYB documents are most often faked?
Certificates of incorporation, registry extracts, and proof of address are the usual targets because they sit in almost every onboarding pack and have no biometric check. Share registers and beneficial ownership declarations are forged when the goal is to hide control rather than invent the entity. Serial reuse of the same address file across applications shows up once intake can compare cases.
Can an analyst catch a fake certificate by looking at it?
Analysts catch crude templates, wrong seals, and obvious screenshots. They miss edited-after-creation PDFs, because the layout was real, and they miss generated packs built to look consistent. FinCEN has already warned that GenAI media is used to get around verification that still assumes a human can see the fake.
What should a team do with a suspect KYB file?
Hold the application, keep the native file, reconcile fields to the registry, and inspect how the file was produced and whether it has appeared before. Request a fresh issuance from the source if the file cannot be explained. Escalate or decline with the evidence attached rather than asking the applicant to re-upload the same PDF.

.png)