Fraud signal list
The following signals may be detected during document analysis:Most common signals
The three most frequently triggered signals are:- Unreconciled balances: Running totals don’t add up when recalculated from individual transactions
- Unusual document source: The PDF producer or creator doesn’t match known bank output
- Editing software detected: The document metadata references editing tools
Document support
Fraud analysis is only available for bank statements. Void cheques are processed for data extraction only.
Understanding false positives
Not every fraud signal indicates actual fraud. Some legitimate user behaviors can trigger signals.Print-to-PDF (common false positive)
When users print their bank statement to PDF instead of downloading the original file, the resulting document may trigger fraud signals. Common print-to-PDF producers include:- PDFium (Chrome’s built-in PDF printer)
- Microsoft Print to PDF (Windows)
- macOS Quartz PDFContext (macOS print dialog)
Actual fraud indicators
The following editing tools in document metadata are stronger indicators of manipulation:- PDF Filler
- Sejda
- iLovePDF
- Adobe Acrobat Pro (when used for editing, not just viewing)
- Other general-purpose PDF editing tools
Best practices
- Don’t auto-reject on a single signal. A single fraud signal (especially “unusual document source” alone) may be a false positive. Look for combinations of signals.
- Prioritize balance reconciliation. Unreconciled balances combined with dollar amount edits is a strong indicator of tampering.
- Review the document source. Check whether the PDF producer is a known print-to-PDF tool or a dedicated editing tool.
- Use the fraud verdict. Flinks provides an overall fraud verdict, Trust, Normal, Warning, or High Risk, that considers the combination of signals. Use this as your primary decision point.
Accessing fraud data
Fraud signals are available through:- The Fraud Analysis API endpoint
- The Flinks Dashboard (visual review)
- Webhook notifications (if configured)