Reading a document is different from trusting it
A system can extract a number correctly from a manipulated statement. Resistant AI’s documentation describes fraud and manipulation checks for PDFs and images, including risk verdicts, metadata and indicator-level explanations. It positions these functions for workflows such as underwriting, identity and business verification, claims and investigations. These are vendor descriptions, not independent accuracy measurements. [1]
The financial task is broader than deciding whether a file changed. A genuine statement may contain nonrecurring income, an outdated address or information irrelevant to the requested service. Authenticity, factual accuracy and the final product decision require related but distinct evidence.
What the AI component is described as doing
The developer documentation lists detectors for editing tools, document reuse, template farms, metadata changes, pixel anomalies, digitally issued PDF authenticity and other manipulation patterns. It also describes policy mapping through adaptive decisioning. [1] These are documented product capabilities, not proof that every detector performs equally on every document type or that a verdict establishes fraud as a legal fact.
The public product page describes recommendations such as Trusted, Warning and High Risk and configurable treatment of document features. [2] A bank should obtain the specific indicator definitions and version behavior used in its deployment. The meaning of a verdict depends on the detection evidence and the policy applied to it, not just the color shown to an analyst.
The vendor’s loan-underwriting material positions the product as a way to identify suspicious financial documents within lending workflows. [3] That establishes the intended use case. It does not establish a validated credit-risk model or authorize the bank to substitute a fraud score for required credit analysis and explanations.
A changed file is not necessarily a fraudulent file
Analysis: legitimate documents are printed, scanned, annotated, translated and combined. A customer may obscure an irrelevant account number or use accessibility software. Those changes can alter metadata or structure without making the underlying financial information false. Conversely, a sophisticated fabricated document can be created cleanly rather than edited from a genuine original.
The correct response therefore depends on the signal and the use case. A low-quality image may require a better copy. An unsupported digital signature may require source verification. A repeated template across unrelated applicants may merit investigation. A bank should avoid treating all warnings as interchangeable automatic declines.
Preserve the original submitted file and the system’s result before converting it for display or OCR. Normalization can remove evidence or introduce artifacts. Record the submission time, document type, detector version and analyst disposition so later review can distinguish what the customer supplied from what internal processing changed.
A hypothetical underwriting workflow
Assume an applicant submits a PDF bank statement showing $6,000 of monthly deposits. OCR extracts the number correctly, but document forensics flags inconsistent structure around several deposit entries. A reviewer requests an independently obtained statement or another approved verification method. The discrepancy may be resolved as a benign conversion issue or confirmed as manipulation; the initial flag alone does not determine the outcome.
If a genuine statement is obtained, the lender still needs to classify the deposits. Transfers between the applicant’s own accounts, refunds and one-time proceeds are not necessarily recurring income. If manipulation is confirmed, the bank should apply its approved fraud and credit processes, preserve evidence and communicate as required. This example describes a proposed workflow, not a reported Resistant AI customer result.
The alternative verification route matters. Requiring an applicant to resubmit the same file repeatedly can create friction without resolving the question. Provide staff with specific reasons and a workable path to additional evidence. A human review step is useful only if reviewers have authority, training and information beyond the original warning label.
Evaluate with the documents the bank actually receives
Build a test set spanning native PDFs, scans, photographs, different issuers, languages and legitimate transformations. Include difficult authentic documents as well as known fraud. A benchmark dominated by obvious forgeries will overstate practical usefulness. Separate document-level performance from application-level outcomes when one applicant submits several files.
A hypothetical sample of 10,000 documents may include only 100 confirmed fraudulent ones. If a model flags 200 documents and 60 are confirmed fraud, precision is 30% and recall is 60%. These assumed values show why an impressive overall accuracy figure can obscure a large manual-review burden. Measure fraud dollars, review time and applicant resolution as well as classification metrics.
Hold out issuers or templates and later time periods to test robustness. Track whether fraudsters adapt after a new control is introduced. Feedback from analyst dispositions should be reviewed for consistency before it becomes training data; an unverified suspicion is not equivalent to confirmed manipulation.
Costs, privacy and implementation
Commercial cost is only one component. Include file ingestion, secure storage, integration with OCR and underwriting, analyst time, appeals and source-verification expense. The public sources reviewed do not establish a universal bank price or independently replicated net savings. Vendor accuracy and automation claims require their own definitions, populations and baselines.
The product’s focus on document structure should not be treated as a blanket privacy exemption. Files can contain sensitive financial and identity information regardless of which features a detector emphasizes. Review access, retention, processing locations, permitted training use and deletion behavior for the actual configuration. Maintain a reliable path when the service is unavailable.
Make verification work for the customer’s actual task
Analysis: in a mortgage application, a flagged pay or account statement can delay a time-sensitive decision. In business onboarding, an ambiguous document may delay access to a payment service. These are illustrative workflows, not named customer deployments. The institution needs an appropriate route to resolve the concern, such as obtaining a source document or another permitted form of verification.
A re-upload request should identify what usable evidence is needed without making an unsupported accusation of fraud. A file may have been compressed, combined or scanned for an ordinary reason. Evaluate difficult authentic documents as well as known manipulations, and distinguish inability to assess from a positive finding.
Review burden changes the value of a detector
Hypothetical extension of the earlier test: if 200 flagged documents each require 15 minutes of follow-up, initial review takes 50 hours. If 40 cases require another half hour, total effort rises to 70 hours. These assumptions are not Resistant AI results, and a lower case count would not establish better detection without checking missed fraud.
Measure time to acceptable evidence, repeated uploads, manual verification expense and completed customer decisions. Improving the presentation of a document indicator can be useful even without changing model accuracy if it helps reviewers reach a justified conclusion faster. That benefit should be measured separately from fraud loss avoided.
What would support a useful authenticity layer
Confidence increases when explanations are actionable, authentic documents are handled reliably and material manipulations are identified at a manageable cost. It decreases when an opaque verdict substitutes for the broader financial decision or customers cannot resolve a mistaken concern.
SR 26-2 provides a model-risk reference within its stated supervisory scope; it is not product certification. [4] The business case rests on reliable evidence and timely service, with the final decision appropriate to the customer and product.
Sources
- Resistant AI developer documentation, About Resistant Documents; reviewed September 27, 2026SourceBack to text: ↑1↑2
- Resistant AI, Documents product page; reviewed September 27, 2026; vendor claimsSourceBack to text: ↑
- Resistant AI, loan-underwriting use case; reviewed September 27, 2026; vendor claimsSourceBack to text: ↑
- Federal Reserve, SR 26-2, April 17, 2026Official sourceBack to text: ↑