Document fraud almost always surfaces late: after the candidate is hired, or after the file has been submitted to the regulator. It surfaces late because the usual check — a human looks at the PDF and it "seems fine" — verifies nothing. It validates the look of a document, not its authenticity.
This guide walks through the red flags that give away a manipulated diploma or passport, and how Booka's Verifier Agent catches them automatically before a file moves forward.
Why visual review fails
A forged document competes against a reviewer who sees dozens of files a day, in formats from more than 30 countries. Nobody remembers which seal a specific university uses or how an apostille issued in another country is structured. Visual review catches the crude forgeries; the careful ones pass.
The alternative is not to look harder. It is to read the document and compare it against what it should contain — which takes three pieces: data extraction (OCR), a registry of requirements per country and profession, and rules that compare the two.
Red flag 1 — The passport check digits don't add up
The MRZ band (the two lines of characters at the bottom of a passport) is not decorative: it follows the ICAO 9303 standard and carries mathematical check digits, computed with a 7-3-1 weighting over each field — document number, date of birth, expiry date.
That enables two things:
- Recomputing the digits. If the passport number doesn't match its check digit, there is either a transcription error or a manipulation. A passport with a tampered MRZ gives itself away: the digits stop adding up.
- Making the validated number authoritative. When the digits check out, the machine-read number overrides the visual reading. No more duplicate records because an O was mistaken for a 0.
Measure your corridor's timelines with a pilot before committing volume.
Red flag 2 — An impossible date
An apostille certifies the signature on a document that already exists. An apostille dated before the degree was issued is materially impossible. It is one of the most common inconsistencies in recomposed documents: a legitimate apostille block is reused on an altered diploma, and the dates stop lining up.
If you're unsure whether your corridor needs an apostille or consular legalization, this guide covers which applies where.
Red flag 3 — The missing authenticity feature
Every document type has expected features: the issuing authority's seal, the apostille block, the MRZ band, color. A police clearance in grayscale when the issuer produces it in color, or a diploma without the university's seal, doesn't prove fraud on its own — but it is exactly the kind of absence an automated system should flag as suspicious for human review.
Red flag 4 — The metadata betrays the edit
A PDF or an image carries metadata: which software produced it, when it was created, when it was modified. A diploma "issued in 2019" whose file was modified with an image editor years after its creation deserves a second look. Metadata alone doesn't convict a document — legitimate scans get processed too — but combined with another signal, it trips the alarm.
The architecture: extraction observes, rules decide
Booka's document brain deliberately separates three layers:
- 1The Model.
A structured registry of what each country × profession requires: stages, documents per stage, fees, and who verifies each step.
- 2The Extraction.
An OCR engine reads each document and returns data (name, number, dates) and features (color? seal? apostille? MRZ?), each with a confidence level. It observes; it doesn't decide.
- 3The Rules.
They turn the extraction into a verdict against the registry: valid, incomplete, or suspicious.
Separating what is read from what is concluded prevents false positives: no single layer condemns a document, and a suspicious verdict always goes through a human.
Where source verification fits
Catching manipulation is half the job. The other half is Primary Source Verification: confirming the credential against the institution that issued it. The Verifier Agent does this against more than 1,200 institutions in 30 countries, in 2-3 business days. A document can be flawlessly forged and still collapse the moment someone asks the source. Which verification each procedure requires is set by the regulator of the receiving country.
Conclusion
You don't catch a fake diploma by staring at the PDF harder. You catch it by recomputing what is mathematical (the MRZ check digits), checking what is verifiable (the document's features against the requirements registry, the degree against its university) and flagging what is inconsistent (impossible dates, editing metadata). Everything else is faith — and faith doesn't survive an audit.