Guide

How to tell if a bank statement has been altered

Check the file before the figures. A statement downloaded from a bank is written once by the bank's software; an edited one is often saved again, produced by a general-purpose PDF tool, or carries dates that don't add up. Then check the math: the opening balance plus credits minus debits has to equal the printed closing balance.

LendPipe team

Start with the file, not the numbers

Altered statements are a known route to credit. In a 2024 federal wire fraud case in Florida, the bank statements submitted for a business line of credit had been altered to hide the account's real name and inflate its cash balances.

A PDF can record the product that created the document, the product that converted it to PDF, and when it was created and last modified; the PDF standard calls these Creator, Producer, CreationDate and ModDate. When a file is updated incrementally, the standard has the changes appended to the end of the file, leaving its original contents intact. None of this shows on the page, which is why an edit that looks perfect can still be caught.

File checks for an altered bank statement
CheckWhat to look for
Producing softwareA PDF library or HTML-to-PDF tool, such as pdf-lib, wkhtmltopdf, headless Chrome or ReportLab, instead of the bank's own export
Extra savesMore than one end-of-file marker, meaning the file was saved again after it was first written
DatesA modification date earlier than the creation date, or either date in the future
Missing metadataNo producer, creator or dates at all, which some tools strip on purpose
Unreadable fileA PDF that won't open cleanly

Then check the math

  1. Opening balance plus credits minus debits has to equal the printed closing balance, to the cent.
  2. Where the bank prints credit and debit totals and counts, the rows have to add up to them.
  3. Where the bank prints a running balance, each one has to equal the previous balance plus the rows between them. A changed amount breaks the chain at that row.
  4. Every transaction has to fall inside the statement period.
  5. Each statement's opening balance has to equal the previous statement's closing balance.
Example: a changed deposit breaks the running balance
DateDescriptionAmountPrinted balanceBalance by the math
Jun 3Opening balance$8,240.10$8,240.10
Jun 3CARD SETTLEMENT 0207$3,412.55$11,652.65$11,652.65
Jun 4CUSTOMER ACH PAYMENT$9,800.00$13,940.65$21,452.65
Jun 4KESTREL RIDGE CAP MERCH DEBIT−$289.00$13,651.65$21,163.65

The printed balances moved by $2,288.00 on Jun 4, but the deposit row says $9,800.00. Either the amount or the balances were edited, and the rows after it carry the difference.

What a flag means

A file check is a reason to look closer, not proof of fraud. Signing a PDF or opening and saving it in a viewer can add a save, and some banks produce statements with general-purpose tools. Weigh the checks together. Underly rates each PDF statement from the share of checks that raise a concern: Integrity OK, Low risk, Concerning or High risk. A date problem or a PDF-tool producer moves a Low risk rating up to Concerning, while one extra save on its own stays Low risk.

When a statement is flagged, ask the merchant for statements downloaded straight from the bank, or verify them with the bank directly.

What file checks can't see

  • CSV and Excel statements have no PDF history, so only the balance math applies to them.
  • A statement rebuilt from scratch, with balances that add up and metadata copied from a real file, can pass both checks. On a large advance, confirm the figures with the bank.
  • A statement without printed opening and closing balances can't be reconciled.

How Underly does it

Altered statement detectionPDF metadata and balance math checked on upload, so edited files are flagged before you fund.

Sources

FAQ

Common questions

Does an extra save mean the statement is fake?

No. Signing a PDF or saving it from a viewer can add one. On its own it rates Low risk in Underly; it matters more alongside other checks.

Can a statement be edited without leaving traces in the file?

Yes, which is why the balances are checked too. An edited amount that isn't carried through every later balance breaks the running balance.

Are CSV and Excel statements checked?

Their balances are reconciled like any statement, but the file checks need a PDF, so spreadsheets don't get an integrity rating.

Run your next file through Underly

The first 10 statements are free. No card.

Run a file free