Validating Source of Funds When Documents Can't Be Trusted

Any payslip, sale contract, or bank letter can be generated in minutes, and source of funds is where EDD programs fail exams. This framework lays out five checks (identity alignment, document type, amount plausibility, counterparty verification, and forensic authenticity) that separate real provenance from fabricated evidence, and where a human still has to decide.
Alexandre Berkovic
Validating Source of Funds When Documents Can't Be Trusted
Validating Source of Funds When Documents Can't Be Trusted

Alexandre Berkovic and Chrisjan Wüst · Sphinx Frameworks · 2026

TL;DR: Source of funds and source of wealth are different questions, and exams fail where firms blur them or accept a document they cannot test. A payslip, a sale contract, or a bank letter can be generated in minutes. Five gates, asked in order, separate real provenance from a file that only looks like it.

Funds and wealth are different questions

FATF draws the line in its guidance on politically exposed persons. Source of wealth is the origin of the customer's entire body of wealth. Source of funds is the origin of the particular funds in the relationship or the transaction (FATF, 2013). The EBA adds the operative detail: source of funds includes both the activity that generated the funds and the means through which they were transferred (EBA, 2021). The FCA Financial Crime Guide lists, as poor practice, a firm that does not distinguish the two (FCA, FCG 3.2).

The two questions call for different proof. Source of wealth is a narrative about a life, corroborated where the sums are material. Source of funds is a chain of custody for a specific amount: the sale that produced it, the salary that accumulated it, the loan that advanced it, the account it moved through. HMRC puts the last point in one line: it is not enough to know the money came from a UK bank account (HMRC, AMLG11630). The remitting account is the last link. Source of funds is about the first.

A bank statement shows the money arriving. That establishes the means of transfer, which is half of the regulatory definition. The other half, the activity that generated the funds, needs a different document. Most source-of-funds files still open with the statement and stop there.

The enforcement record is a list of provenance gaps. The FCA's 2025 notice against Monzo found that the failure to collect occupation, purpose, source of wealth, and source of funds undermined any later assessment of whether transactions were suspicious, and that the PEP procedure allowed those details to be obtained after the customer had begun transacting. The penalty was £21,091,300 (FCA, 2025). Barclays was fined £39,314,700 the same year after it failed to obtain sufficient information on source of wealth and source of funds for a corporate customer whose low risk rating was never revisited. Starling paid £28,959,426 in 2024. The FCA's April 2026 multi-firm review found firms that failed to evidence the enhanced due diligence they claimed to have done. The HKMA's December 2025 guidance reported overreliance on customer representations, without challenging whether the story was reasonable or obtaining corroboration. Monitoring that cannot see this gap is described in behavioral transaction monitoring: if the expected activity was never collected, the alert has nothing to deviate from.

The document is the attack surface

The documents that carry a source-of-funds case are the documents fraud tooling has industrialized. Inscribe's 2026 report found that roughly 1 in 16 documents processed on its network in 2025 showed signs of fraud, that 91.2 percent of flagged documents carried altered financial details, and that 85.6 percent of the fraud and risk leaders it surveyed named bank statements as their top concern (Inscribe, 2026). Resistant AI reported that 1 in 3 documents it analysed showed structural tampering, and that editable fraudulent templates sell for an average of $28.29 (Resistant AI, 2026).

Generation has joined editing. Sumsub recorded that 2 percent of fake documents detected in 2025 were produced with general-purpose AI tools, a category that did not exist on its platform before April 2025 (Sumsub, 2025). Inscribe measured a roughly fivefold rise in monthly AI-generated document fraud between May and December 2025. Entrust put digital forgeries at 35 percent of document fraud in 2025, against a 29 percent average for 2022–2024. FinCEN's November 2024 alert confirmed the supervisory view: BSA reporting shows criminals using generative AI to create falsified documents to defeat customer identification and due diligence (FinCEN, FIN-2024-Alert004). A payslip has no hologram, no chip, and no issuer database. When it could only be forged by hand, the low quality of most forgeries was the control. That control is gone. Document fraud detection is the control that replaces it, and how to spot a fake bank statement is the practical version of the last gate.

Five gates, in order

An unstructured review asks someone to look at a document and decide whether it is satisfactory. That single judgment hides five separate ones, and when it goes wrong nobody can say which failed. Each gate ends in pass, manual review, or reject. Manual review is a designed state. Collapsing it into pass waves partial matches through. Collapsing it into reject refuses a hyphenated surname or a rescanned file. A review rate near zero usually means the gate is not looking hard enough.

Five-gate source of funds flow: identity, document type, amount, counterparty, and authenticity.

Each gate produces pass, manual review, or reject. Authenticity runs last because it is the costliest check.

Identity alignment. Is this document about this customer? The gate reads the name and identifiers on the page and compares them with the customer on file, with tolerance for the ordinary mess of real names: order, diacritics, a middle name present on one side. A full match proceeds. A mismatch stops. A partial match, including a document in a family member's name, goes to a person with the relationship to be documented. A gift letter from a parent is legitimate provenance and will always fail a strict identity check. The framework should expect that, rather than widening tolerances for everyone. Corporate customers and joint funds are where a two-field check runs out, and the gate should say so instead of forcing a person-shaped answer.

Document type. Can this kind of document evidence the origin of funds at all? Primary evidence records the activity that generated the funds and is issued by a party other than the customer: a payslip, a tax return, a completion statement from the acting lawyer, a grant of probate, a loan offer from a regulated lender. AMLA's draft standards under the EU Anti-Money Laundering Regulation list that family and add the condition that the information meet "criteria of reliability and independence" (AMLA, draft RTS Article 27). Bank statements, screenshots, and the customer's own affidavit fail the test for different reasons. A statement corroborates that the salary landed. It does not record the salary. A screenshot may be honest, and the response is to ask for the original file. Rejecting a document type is a request for the right document, not a refusal of the customer.

Amount and plausibility. Does the figure cover the money, and does the money make sense for this customer? A genuine payslip that shows a tenth of the deposit has not explained the deposit. The gate finds the number that matters on a page full of numbers, compares it with the transaction, and tests it against what the institution already knows: occupation, stated income, the pattern of the account. Evidence that covers most but not all of the amount is a manual-review case with a documented explanation for the remainder. Evidence that covers a fraction has not done its job.

Counterparty verification. Does the bank, employer, broker, or buyer named in the document exist, and do they hold the status the document implies? Fabricated institutions are cheaper than fabricated documents. Public registries differ by region: company registers, bank license lists, land registries, professional rolls. Where the registry is thin, a digital footprint can supplement it. It cannot replace it. Outcomes are verified, unverifiable, or adverse. Unverifiable is a review, not a pass.

Authenticity. Has the file been altered or generated? Edited-after-creation and generated-from-scratch leave different evidence. Compositional analysis reads the rendered page: alignment, fonts, totals that do not add, a logo that does not match the issuer. Metadata analysis reads what the file says about itself. Info-dictionary fields are optional and editable, and a clean metadata result does not prove a document is genuine (PDF Association, 2025). Rescans, stripped metadata, and a file rebuilt by a converter arrive clean. Forensic checks raise suspicion reliably. They clear documents only weakly. Confirmation with the issuer or a registry is the conclusive test. This gate runs last because it is the most expensive, and because the earlier gates have often already rejected the file.

What the record has to contain

An examiner should be able to reconstruct the case from the record alone: which gate ran, what it extracted, which outcome it produced, and who changed that outcome. Wolfsberg is explicit that source of wealth and source of funds should not be treated as a documentary exercise. Corroboration means information from a source independent of the customer (Wolfsberg Group, 2020).

Sphinx runs the five gates as separately evidenced decisions, then hands the indeterminate cases to three agents. A Prosecutor argues that the provenance does not hold. A Defender argues the innocent reading, including the partial match and the document type that is corroboration rather than proof. A Judge writes the outcome under the institution's policy. The pattern is the Interpretable Agentic Framework. Humans stay on the middle tier: partial identity, an unverifiable counterparty, an indeterminate forensic result, and any case where the numbers are plausible but the story is thin. Pass and reject, when the evidence is complete, do not need a person to re-read the page. The same expectation, that a model earns autonomy and does not start with it, is the argument of Financial Crime in the Age of AI.

Frequently asked questions

Is a bank statement ever acceptable as source-of-funds evidence?

As corroboration, yes. It confirms that the salary or the sale proceeds arrived. As primary evidence, no. It records the transfer, not the activity that generated the funds, which is what the FCA and EBA definitions require.

Does a clean metadata result prove a document is genuine?

No. Metadata is optional and editable, and a printed-and-rescanned file arrives clean. Forensic checks raise suspicion reliably and clear documents only weakly. Confirmation with the issuer is the conclusive test.

How should a document in a family member's name be treated?

As a partial match routed to manual review, with the relationship documented. A gift letter from a parent is legitimate provenance and will fail a strict identity check. The framework should expect that, rather than widening tolerances for every customer.

Read the handbook

The taxonomy of accepted documents, the plausibility checks, and the forensic limits are in Validating Source of Funds When Documents Can't Be Trusted. Where the same document is attached to a payment rather than an onboarding file, it is one of the six lenses in behavioral transaction monitoring.

Get Your Free AI Compliance Handbook

What compliance leaders need to know about AI-driven fraud, autonomous laundering, and how your team can
fight back.
Submit
Thank you! Your submission has been received!
Something went wrong while submitting the form. Please try again.