Ten Training Scenarios for Catching Document Fraud
Ten fifteen-minute scenarios with a defensible wrong answer in each, built to be read aloud and argued about — free to adapt, brand and use in your own training, no attribution required.

Fraud awareness training has a measurable effect and an unfortunate reputation, and both are deserved. The reputation comes from the format: forty slides of statistics, a five-question quiz, an annual completion certificate, and no observable change in behaviour. The effect comes from something else entirely — putting people in the situation, letting them get it wrong in a room where getting it wrong is free, and then talking about why.
These are ten scenarios built for that second thing. Each one runs in about fifteen minutes with a group of any size. They are free to use, adapt and put your own logo on; no attribution required, though a link back is always welcome.
The format is the same throughout: read the situation aloud, ask what the group would do, let the discussion run before revealing the second half, then debrief on the decision, not the answer.
Key takeaways
- Train the moment of pressure, not the taxonomy of fraud. Nobody fails because they could not define business email compromise.
- Every scenario should have a defensible wrong answer, or the group learns nothing from the discussion.
- Debrief on process — "what would have made this decision easy?" — rather than on whether people spotted the trick.
- Run these quarterly in fifteen-minute slots. It works better than an annual hour, by a wide margin.
How to run them
Small groups, spoken aloud. Reading beats video; discussion beats reading. Six to twelve people is ideal.
Do not reveal the twist first. Let people commit to a position. Someone confidently choosing the wrong course is the most valuable thing that will happen in the session, and they must not be punished for it — the whole point is that this is the safe room.
Debrief on the process. The useful question is never "did you spot it?" It is "what would have made this decision obvious, and do we have that?" Half the time the answer is a policy change, and you have just found it for free.
Keep a tally of what your own people find hard. After four sessions you will know exactly which control needs the work.
1. The Friday afternoon bank change
A supplier you have worked with for six years emails at 4:15pm on a Friday. Their letterhead, their signature block, their account manager's name. The bank details have changed due to "a group treasury restructure". An invoice for £48,000 is due Monday. The email is a reply within an existing thread that contains three months of genuine correspondence.
Ask: what do you do before Monday?
Reveal: the thread is genuine — the supplier's mailbox was compromised weeks ago and the attacker has been reading it. Nothing in the message is inconsistent, because the attacker knows everything you know.
Debrief: no amount of scrutiny of the email helps here. Only an out-of-band callback to a number already on file does. Does your policy require one? Does the person who received this know that? Do they have the number?
2. The perfect pay stub
A rental applicant supplies a pay stub. Employer, dates and format are all plausible. The gross-to-net arithmetic is correct to the penny. The PDF metadata says it was produced by a common payroll platform.
Ask: does this pass?
Reveal: the file has been saved twice, and an earlier revision inside it shows a lower salary figure. The arithmetic is right because the fraudster recalculated it.
Debrief: correct arithmetic is evidence of care, not honesty. What would you have to look at to see the earlier version, and would anyone here have looked?
3. The certificate that verifies itself
A contractor sends a certificate of insurance. It carries a QR code labelled "verify this certificate". You scan it; a clean, professional page confirms the policy is active.
Ask: are you satisfied?
Reveal: the domain behind the QR code was registered five weeks ago and is controlled by the contractor.
Debrief: the check felt like diligence and validated nothing. What is the rule? (Never use contact details or links printed on the document you are verifying.) Is that rule written down anywhere in your organisation?
4. The screenshot at the loading dock
A buyer is at the dock. They show a phone: a banking app confirming a transfer of the full amount, timestamped six minutes ago, with your invoice reference. The driver has another collection booked.
Ask: load or hold?
Reveal: the transfer was initiated and cancelled ninety seconds after the screenshot.
Debrief: the useful question is not "how would you spot a fake screenshot" but "who in this company is allowed to release goods before settlement?" If the answer is "whoever is at the dock", that is the finding.
5. The candidate who is somebody else
A remote developer interviews well, provides ID that passes checks, and is hired. Two months in, their camera is always off, their working hours are odd, and their code style differs sharply between commits.
Ask: what do you do?
Reveal: the person interviewed is not the person working. The ID was genuine; the individual attached to it was a stand-in.
Debrief: identity was verified once, at onboarding, and never again. Where else do you verify once and then assume forever?
6. The doctored delivery note
A supplier's delivery note says 240 units. Your warehouse counted 200 and noted it. The supplier sends the "original" scanned note showing 240, and it looks entirely ordinary.
Ask: whose record wins?
Reveal: the scan shows a slightly different font weight on the quantity, and the page has been re-scanned to hide the edit.
Debrief: this is the scenario where the group usually splits, and that is the point. When your record disagrees with theirs, what is the process? Does anyone have the authority to hold payment while it is resolved?
7. The urgent legal letter
A letter arrives on a law firm's letterhead demanding payment of a disputed invoice within five days, referencing a real case number and threatening enforcement. The firm exists and is well known.
Ask: what is the first step?
Reveal: the letterhead was copied from a PDF on the firm's own website. The firm has never heard of the matter.
Debrief: the emotional response — urgency, fear of legal consequences — is the payload. Who in your organisation is allowed to receive a demand like this and not act immediately?
8. The invoice from one character away
An invoice arrives from your regular supplier. Same format, same contact name, same signature. The domain is supplier-co.com; your supplier's domain is supplierco.com.
Ask: what would catch this?
Reveal: nothing in the document is wrong. The only anomaly is a single hyphen in the sending address, on a screen where most clients show only the display name.
Debrief: human vigilance is the wrong control here — people read display names, not addresses, and always will. This is a job for tooling: external-sender warnings, domain-similarity checks, and payment details that come from your master record rather than from the invoice. See lookalike domains.
9. The claim photo from last year
An insurance claim arrives for storm damage, with clear photographs. The images are sharp and the damage matches the description.
Ask: what would you check beyond the visible damage?
Reveal: the capture dates in the image metadata are fourteen months old, and the GPS coordinates are two hundred miles away.
Debrief: the photographs are truthful pictures of real damage — just not this damage. What does your process currently do with the invisible half of an image? See EXIF data.
10. The document nobody wanted to question
A long-standing client, personally known to your managing director, submits accounts to support a credit increase. Something in the year-on-year figures does not sit right with the analyst reviewing them. The MD has already indicated the increase should go through.
Ask: what does the analyst do?
Reveal: there is no twist. This scenario is about whether your escalation route works when the pressure is internal.
Debrief: run this one last, and run it every time. Every organisation has a version of it, and it is the scenario that most reliably explains real losses. If the honest answer in the room is "they'd let it go", you have learned something more valuable than the other nine put together.
Building your own
After a few rounds, replace these with your own. The recipe is simple: take a real incident or near miss from your business, strip the identifying details, stop the story at the moment of decision, and make sure a reasonable person could get it wrong.
Scenarios drawn from your own history land differently. People recognise the customer type, the system, the time of day. And the debrief stops being abstract, because everyone in the room knows it happened here.
Pair the sessions with a written verification policy — the training teaches people to notice, the policy tells them what to do about it, and neither works well alone.
Frequently asked questions
How often should fraud awareness training be run?
Short and frequent beats long and annual. A fifteen-minute scenario each quarter keeps the material live and gives you four data points a year on which controls your people find hardest, which an annual session cannot.
Do these scenarios work for non-finance teams?
Yes, and they should be used that way. Warehouse, reception, HR and customer service staff are routinely the first point of contact for document fraud, and they usually receive the least training on it.
Should we tell people they got it wrong?
Not as a judgement. The value is in the discussion, and a session where people fear being wrong produces silence and no learning. Frame incorrect answers as evidence that a control is missing rather than that a person is careless.
Can we use these scenarios commercially?
Yes — adapt them, brand them, put them in your own training programme. No attribution is required, though a link back is appreciated if you publish them publicly.
Check the PDF you are holding
Run a free PDF X-Ray in your browser — it recovers text from the file’s earlier revisions, so you can see what a value was before it was changed. No account needed.
Keep reading
The Two-Invoice Trade: Customs Undervaluation and the Paper That Hides It
Undervalued commercial invoices dodge duties, launder value, and expose importers to seizure. How the double-invoice game works and how compliance teams catch it in the paper.
Fake Audit Reports: Borrowing a Big Four Signature
Fabricated audit opinions and doctored financial statements borrow credibility no fraudster earned. How fake audits are built, famous ways they unravel, and how to verify one.
Gig Onboarding Fraud: Fake Drivers, Rented Accounts, Borrowed Faces
Gig platforms onboard workers with document checks — and fraudsters attack exactly there. Fake licenses, rented accounts, and synthetic profiles, plus the checks that hold.