TL;DR: A screenshot of a bank statement is a picture of evidence, not the evidence. Flattening a native PDF to an image discards the Producer string, the text layer, the revision history, and any digital signature, which is most of what document fraud detection reads. Screenshots are still legitimate for mobile-only customers, so a blanket ban costs conversion. The FBI's 2025 Internet Crime Report logged 22,364 AI-related complaints and nearly $893 million in losses. Treat an image as lower-tier evidence, run the checks that survive flattening, and require a native export or a data connection above a materiality threshold.
What a screenshot actually is as evidence
A screenshot is a raster capture of whatever a display showed at one moment. The bank's server produced data, an app drew it, the phone painted it, and the screenshot tool sampled the result. Nothing in that chain carries the bank's identity forward. The PNG or JPEG that lands in the intake queue has one provable origin: the device that captured it.
Print to PDF and a scan of a printout belong to the same class. A print driver re-renders the page and writes a fresh PDF with its own Producer string, its own timestamp, and no relationship to the issuer's original object graph. A scanned printout adds a paper generation on top. Each path ends in a container that looks like a document and behaves, forensically, like a photograph.
Screenshots exist in intake for a good reason. Many banks and neobanks only expose account views inside an app, with no statement export. Fannie Mae's Selling Guide still accepts copies of bank statements, including online statements downloaded by the borrower, provided the document identifies the institution, the account holder, the period, the transactions, and the ending balance. The mainstream position is not that images are forbidden. The position is that they must identify their source, and that the lender is accountable for what it relied on.
That accountability is getting heavier. The FBI's 2025 Internet Crime Report tracked AI as a descriptor for the first time: 22,364 complaints and nearly $893 million in losses, with fake identification documents among the tactics. An image is a legitimate submission. It is also a loss of evidence, and the loss is not visible on the page.
What gets lost when a PDF becomes an image
The document information dictionary goes first. ISO 32000 PDFs carry Creator, Producer, CreationDate, and ModDate, and an issuer's reporting engine stamps its identity there. The tells that expose an AI-generated PDF live largely in these fields. After a screenshot, the Producer describes the phone or the print driver, and the CreationDate is the moment of capture.
The text layer and fonts go next. A native PDF stores text as positioned glyph runs, so a parser reads the exact characters the bank emitted along with the font subset that drew them. A screenshot stores pixels. Any text recovered later comes from OCR, which cannot tell an original glyph from a pasted one.
Incremental saves vanish. PDF editors append revisions to the end of the file, so an edited statement often contains the original bytes and the altered bytes side by side. Flattening collapses both into one image. The audit trail of the edit is gone, and so is the original it would have contradicted.
Digital signatures are the sharpest casualty. A signature is a cryptographic statement over the file's bytes, and a picture of a signed document carries no signature at all.
The Scientific Working Group on Digital Evidence states the principle in its Best Practices for Image Authentication: metadata may help identify the source and processing history of a file, but can be limited, absent, or altered. A screenshot is the case where it is absent by construction, not by tampering. The customer did nothing wrong. The evidence is thinner anyway.
Tells that still work on images, and the ones that don't
Image forensics is a real discipline, and several signal classes survive flattening. Recompression signals work on JPEGs and on screenshots that passed through messaging apps: a region edited and re-saved carries a different compression history from the rest of the frame. Resampling signals appear when part of an image was scaled or rotated to fit. Copy-move signals detect the same pixel block appearing twice, the visual equivalent of a duplicated transaction row. Text re-rendering signals look for characters whose anti-aliasing, baseline, or stroke weight do not match their neighbors.
None of those is a verdict. SWGDE's guidance notes that a thorough examination can conclude manipulation is unlikely, not that it is absent, and a phone screenshot's own capture path introduces resampling and compression that a detector has to treat as normal.
Visual review performs about the same on both formats, which is to say poorly against competent fakes. The practical tells on a fake bank statement a reviewer checks by eye carry over to an image without loss. The difference is what sits underneath the page.
How detection works on images vs. native PDFs
Document fraud detection runs six checks on any file: production method, timestamp trail, issuer matching, consistency, model artifacts, and recycled patterns. On an image, two largely stop working, two degrade, and two survive intact.
Production method largely stops working. The question is whether the issuer's known renderer, a consumer editor, a print driver, or a generative pipeline wrote the file. A screenshot answers "phone" for every legitimate customer and every fraudster alike.
Timestamp trail largely stops working. Without CreationDate, ModDate, and an incremental-save chain, the detector cannot see whether the document was edited after it was born. This is the check that most reliably separates an edited-real statement from a clean export, the case document fraud detection in banking most needs to catch, and it is the one flattening removes most completely.
Issuer matching degrades. Producer, fonts, and page geometry are gone, but the visual template survives: logo placement, column order, header chrome, date formatting. Matching against known-good views of the same bank's app still works, with less precision.
Consistency degrades but remains useful. Running totals and date ordering can be checked after OCR, with recognition error as noise.
Model artifacts survive. A page synthesized by a generative model carries frequency-domain regularities and background uniformity that a screenshot does not erase.
Recycled patterns survive. The same template, dummy transaction set, or layout fingerprint appearing across unrelated applicants is a visual property; seeing the same app view from fifty accounts at forty banks requires no metadata. FinCEN's November 2024 alert on deepfake media notes that institutions often catch GenAI content by re-reviewing account opening documents and examining an image's metadata.
What to do with a screenshot submission
The workable policy is tiered, not binary.
Accept with compensating controls. For low-value decisions, or for customers whose bank offers no export, take the image but run the checks that survive flattening: model artifacts, recycled patterns, template matching against known app views, and arithmetic after OCR. Pair the document with a signal that does not depend on it, such as a test deposit or a callback. Record that the evidence was an image and which checks ran.
Require a native export or a data connection above a threshold. When a single altered balance would be material, ask for the PDF the bank produced, or offer a permissioned account link that retrieves data directly from the institution. A genuine customer can usually produce a second export whose Producer and timestamps look like the first. A fraudster holding a flattened image often cannot.
Treat images as lower-tier evidence throughout. A screenshot should not carry the same weight as a native file that passed all six checks, and the record should say so. Identity documents already live under this rule: a photo of a driver's license is expected, and identity document verification for onboarding is built around image forensics plus liveness and data checks.
Keep the original bytes. Do not re-save, crop, or convert a submitted image before the forensic pass, and do not accept a re-scanned printout in place of the digital file the customer already has. If the queue receives PDFs, check a document in its native form before anything else touches it.
Where Sphinx fits
Sphinx Watchdoc scores the file on arrival, native PDF or image, and shows which of the six checks it could run and which the format made unavailable, so a screenshot that passes is reported as a screenshot that passed, not as a clean document. Across more than 1 million documents processed, Sphinx reports a 94.3% correct verdict, 2.8x more forgeries caught, and clean files cleared in under 28 seconds, at $0.45 per document with no seats and no platform fee. The Watchdoc playground is free for a first file, no email required, with a 50-document free tier. Run a native export and a screenshot of the same statement to see what flattening removes.
Frequently Asked Questions
Should compliance teams accept screenshots of bank statements?
Conditionally. Screenshots are legitimate for mobile-only customers and app-only banks, so a blanket ban costs conversion. Accept them as lower-tier evidence for low-exposure decisions, run the image-forensic checks that survive flattening, and require a native PDF or a permissioned data connection when an altered balance would be material.
What does a screenshot of a PDF lose compared to the original file?
A screenshot discards the document information dictionary, the text layer and embedded fonts, the incremental-save history that records edits after export, and any digital signature. What remains is a raster whose only provable origin is the capturing device.
Is a print-to-PDF of a bank statement the same as a screenshot?
Forensically, yes. Print to PDF re-renders the page and writes a new file with the print driver's Producer and a fresh timestamp, severing the link to the issuer's original object graph. A scan of a printout is the same class with an extra paper generation. Treat all three as images.
Can fraud detection still work on a screenshot?
Partly. Model-artifact detection and recycled-pattern matching survive flattening, and image forensics adds recompression, resampling, copy-move, and text re-rendering signals. Production-method and timestamp-trail checks largely do not work, so an edited-real statement is much harder to catch from an image.
What is the safest alternative to accepting a screenshot?
A permissioned data connection that retrieves account data directly from the institution, or the bank-produced PDF downloaded from the portal. Both preserve provenance a screenshot cannot. Where neither is available, pair the image with an independent signal such as a test deposit and record that the decision rested on image-tier evidence.

.png)