Authentic, Suspicious, Likely Tampered: How a Document Earns a Verdict

Estimated Reading Time: 6 minute(s)

6 minute read

Document fraud detection: Authentic, Suspicious, Likely Tampered verdicts

Key Takeaways

  • Every document on a fraud-enabled schema gets one of three verdicts: Authentic, Suspicious, or Likely Tampered.
  • One strong finding caps the score, so eight clean checks can’t average it back up to Authentic.
  • Each verdict comes with a plain-language summary, a breakdown of every check, and the page and region where the problem is.
  • Checks that can’t run on a document type are marked skipped and left out of the score. They are never counted as passed.
  • Likely Tampered sends the document to a person for review. It never rejects a claim automatically

Document fraud detection only helps if your claims team can act on it. “The system says this document is suspicious” is not actionable. A handler needs to know which check fired, what it found, and where on the page to look. Otherwise, the flag becomes one more queue nobody trusts. In our first post, we looked at why altered, duplicated and AI-generated documents slip past manual review, a pattern the Coalition Against Insurance Fraud has been tracking as generative tools spread. This post covers what happens next: how CoverGo IDP turns nine independent checks into one verdict, with the evidence attached.

See it run on a tampered invoice: Book a CoverGo IDP AI Agent demo.

Three document fraud detection verdicts, not a score to interpret

On a fraud-enabled schema, the CoverGo IDP AI Agent returns one of three verdicts for every document.

Authentic. No strong tampering signals were detected. The document proceeds through the normal workflow.

Suspicious. Signals fired, but not conclusively. The document is routed for manual review rather than held or refused.

Likely Tampered. There is strong evidence of tampering. What happens next is the insurer’s decision — escalate to the fraud team, request a resubmission, or hold pending investigation. It is a flag for human review, never an automatic rejection.

Handlers see a badge, not a number to calibrate against. Teams that want finer control can build routing rules on top of the verdict.

One strong signal is enough

You might expect a single check to be outvoted. That is the risk with any average. A weighted average across nine checks has an obvious weakness: a single decisive finding could be diluted by eight checks that found nothing. The pipeline handles this with override rules. When one check returns a strong, specific finding — the arithmetic does not reconcile, the visible text disagrees with the embedded text layer — that finding caps the document’s score, so it cannot be averaged back up into Authentic. A document with one unambiguous problem and eight clean checks still lands in review.

The reasoning travels with the verdict

Alongside the verdict, each document carries a detection summary in plain language, a per-check breakdown showing what every technique returned and why, and a list of flagged issues describing which check fired, what it detected, and where.

Where the evidence is visual — a retouched region, an altered digit — the flagged issue includes the page and a bounding box over the area. Where it is textual, such as a mismatch between what a PDF displays and what its text layer contains, the suspect text itself is surfaced instead. The execution log records which checks ran, which were skipped, and why.

Skipped is not the same as passed

Some checks only apply to some documents. Two of the most reliable checks read the internal structure of a PDF, so they cannot run on a photograph or scanned image of a receipt. Rather than scoring those as clean, the pipeline marks them skipped and excludes them from the calculation, so an absent check never inflates a verdict. A reviewer looking at the technique list sees exactly which checks were available for that document.

Why it matters

Document fraud detection fails in practice when handlers cannot see why something was flagged. A verdict with per-check reasoning, visible evidence, and an honest account of which checks could not run is something a claims team will act on, and something an auditor or regulator can follow after the fact.

See the per-check breakdown on your own claims documents. Book a CoverGo IDP AI Agent demo →

TL;DR

A fraud flag only helps if a claims handler can act on it. CoverGo IDP runs nine independent authenticity checks on each document and returns one of three verdicts: Authentic, Suspicious, or Likely Tampered. Each verdict shows which check fired, what it found, and where on the page to look. One strong finding is enough to cap a document’s score. Checks that can’t run are reported as skipped, not counted as passed. A Likely Tampered verdict sends the document for human review and never rejects the claim automatically.

Frequently Asked Questions

What verdicts does CoverGo IDP return on a claim document?

There are three: Authentic, Suspicious, and Likely Tampered. Authentic documents carry on through the normal workflow. Suspicious documents go to manual review. For Likely Tampered documents, the insurer decides the next step.

Does a Likely Tampered verdict reject the claim?

No. It flags the document for human review. Nothing in the pipeline refuses a claim, closes a case, or contacts the customer.

Can one failed check change the verdict if all the others pass?

Yes. A strong, specific finding, such as totals that don’t add up or a PDF whose visible text differs from its text layer, caps the score. The document can’t average back up to Authentic.

How does a handler see why a document was flagged?

Each verdict comes with a plain-language summary, a breakdown of what every check returned, and a list of flagged issues. Visual findings show the page and a box around the area. Text findings show the suspect text itself.

What happens when a check can’t run on a document?

It is marked skipped and left out of the score. For example, the PDF-structure checks can’t run on a photographed receipt. The reviewer can see exactly which checks were available.

Is document fraud detection on for every document?

No. It is off by default and turned on per document schema, which in practice means per document type.

For more information or an expert-led demo, reach out to a team member.

See the Per-Check Breakdown on
Your Own Documents

A fraud flag only helps if your team can act on it. Bring a claim document from your own book and see the CoverGo IDP AI Agent return its verdict: which check fired, what it found, and where on the page to look. If a check can’t run on that document type, you’ll see that too.

BOOK A DEMO

Share

Recommended resources

Want to know how we can help your business?

CoverGo’s Intelligent Document Processing AI Agent enhances Generali Hong Kong’s health claims automation