A Document Verification Policy Worth Adopting (Template)
A copy-and-adapt policy with tiered checks, numeric thresholds instead of adjectives, a named escalation route and an incident procedure — written to be edited, and free of anything that depends on buying a product.

Almost every organisation that gets hit by document fraud had a policy. It said something like "staff should verify documents where appropriate", and it was true, and it was useless, because at 4:40pm on a Friday with a customer on hold nobody has ever been helped by the phrase where appropriate.
A policy that works has a different shape. It removes the judgement call from the person under pressure, it names who decides when the answer is unclear, and it is short enough that somebody actually reads it.
Below is a template you can copy, adapt and adopt. It is written to be edited — the bracketed parts are yours to fill in — and it is deliberately free of anything specific to our product, because a policy that only works if you buy something is not a policy. Take it, change it, put your own name on it.
Key takeaways
- Write thresholds as numbers, not adjectives. "High value" is not a threshold; "over $10,000" is.
- Name the person who can override, and require the override to be written down. Unrecorded overrides are where fraud lives.
- The escalation path matters more than the check list. Most losses happen when somebody knew something was odd and had nowhere to take it.
- Review it against your actual incidents twice a year, or it becomes fiction.
Document Verification Policy — template
1. Purpose and scope
This policy sets out how [ORGANISATION] verifies documents received from customers, suppliers, applicants and third parties before relying on them.
It applies to every document that supports a decision to pay money, extend credit, release goods, employ a person, or accept a liability. It applies regardless of how the document arrives — email, portal, post, or in person.
It does not apply to [internal working documents / marketing material / list your exclusions], which are governed by [other policy].
2. Principles
- Verify at the source where a source exists. Confirmation from the issuing body outranks any analysis of the document itself.
- One signal rarely decides. A single anomaly prompts a closer look; a decision to decline requires corroboration from an independent direction.
- Authenticity and approval are separate questions. Whether a document appears genuine is a question about evidence. Whether to proceed is a business decision that includes risk appetite. Record them separately.
- Doubt escalates; it does not resolve itself. Nobody is expected to make a judgement call alone under time pressure.
- Genuine customers are the majority. Controls will be proportionate, and wrongly refusing a real customer is treated as a failure, not a safe outcome.
3. Verification tiers
Every in-scope document is handled at one of three tiers, determined by value and risk.
Tier 1 — Standard. Applies to [documents supporting transactions under $X] [routine documents from established counterparties].
- Confirm the document type is the one requested and the period is current.
- Confirm the named party matches the party of record, exactly.
- Confirm internal arithmetic where applicable — totals, balances, subtotals.
- Record the document and the checks in [system].
Tier 2 — Enhanced. Applies to [transactions between $X and $Y], first-time counterparties, and any Tier 1 document where an anomaly was noted.
- Everything in Tier 1, plus:
- Verify the issuer against an independent source: [registry / licence board / issuer contact obtained independently].
- Cross-check at least two facts against other documents held for the same party — bank details, address, tax identifier, dates.
- Run the document through [document analysis process or tool].
- Second person reviews before the decision is recorded.
Tier 3 — Investigation. Applies to [transactions above $Y], any case where Tier 2 raised an unresolved concern, and any document type on the elevated-risk list at Appendix A.
- Everything in Tier 2, plus:
- Direct confirmation from the issuing organisation, using contact details obtained independently of the document.
- Full forensic analysis, retained with the file.
- Approval by [named role] before proceeding, recorded in writing with reasons.
Set the thresholds to real numbers before you publish this. A tier structure with adjectives in it is not a policy.
4. Mandatory checks that never depend on tier
These apply to every document, always:
- Contact details are never taken from the document being verified. Phone numbers, email addresses, URLs and QR codes printed on a document under review are not used to verify it. Details are obtained independently.
- Bank account changes are verified by callback to a number already on file, to a known contact, and never in the same channel the request arrived in. This applies even when the request comes from a familiar person. See vendor bank account change requests.
- Nothing is released against evidence of payment. Goods, funds and services are released on settlement in [ORGANISATION]'s own account. A screenshot, reference number or confirmation document is not settlement. See fake proof of payment.
- The original file is retained as received, unmodified, for [retention period].
5. Escalation
Anybody, at any level, may escalate a document they are uncomfortable with, without needing a reason they can articulate. Escalation goes to [named role or team] and is acknowledged within [timeframe].
No individual may waive a required check. [Named role] may authorise a documented exception, which must record: what was waived, why, who approved it, and the date. Exceptions are reviewed [monthly] by [role].
Escalating is never a performance issue. A person who escalates a genuine document has done their job correctly.
6. When a document is judged fraudulent
- Preserve the original file and the message that carried it, unmodified.
- Do not tell the sender what was detected or how. [Named role] handles all communication.
- Notify [named role] immediately; notify [insurer / legal / bank] per Appendix B.
- Check whether the same counterparty has supplied other documents, and re-examine them.
- Report externally per Appendix B.
- Record the case, the indicators and the outcome in [system], for the review at section 8.
Point 2 matters more than it looks. Telling a fraudster exactly which check caught them trains the next attempt.
7. Training and awareness
- All staff handling in-scope documents complete verification training within [30 days] of starting and annually thereafter.
- Training uses real, anonymised examples from [ORGANISATION]'s own incidents wherever possible.
- [Quarterly], [role] circulates a short brief on current patterns seen in the business.
8. Review
This policy is reviewed [every six months] by [role]. The review must consider:
- Every incident since the last review, and whether this policy would have caught it.
- The false-positive load: how many genuine counterparties were delayed, and whether that is acceptable.
- Whether the thresholds still match current transaction values.
- Whether the elevated-risk list at Appendix A still reflects reality.
Appendix A — Elevated-risk document types [list yours: proof of funds, certificates of insurance, employment letters, bank statements from non-institutional sources…]
Appendix B — Escalation contacts and external reporting routes [see where to report document fraud]
Making it stick
Three things determine whether a policy like this survives contact with an operating business.
Numbers, not adjectives. Every bracketed threshold above should become a figure. The single most common failure in real policies is that they describe when to be careful in language that lets a person under pressure decide they are not in that situation.
A named owner with time. A policy owned by "the risk function" in the abstract is owned by nobody. Put a name on it and give that person the twice-yearly review as a real task.
Feed it your own incidents. The generic version above is a starting position. Six months of your own near misses will tell you which document types actually cause you problems, and the second version of this policy — the one shaped by your losses rather than by a template on the internet — is the one that earns its place.
If you adapt this for your organisation, you are welcome to use it however you like. A link back is appreciated but not required.
Frequently asked questions
What should a document verification policy include?
Scope, a small number of principles, tiered checks tied to numeric thresholds, a set of checks that apply regardless of tier, a named escalation route, an incident procedure, training obligations, and a scheduled review. Anything longer than a few pages will not be read.
How do you set verification thresholds?
Start from your own transaction distribution and incident history rather than from an industry number. Pick values that put a manageable proportion of volume into each tier, then adjust at the six-month review based on what the tiers actually caught and how many genuine customers they delayed.
Who should own document verification in a business?
A named individual with authority over the process — commonly a risk, finance or operations lead. Ownership by a committee or an unnamed function is the most reliable way for a policy to go stale.
Can we adapt this template for our organisation?
Yes. It is written to be copied and edited, and there is no restriction on using it. Replace every bracketed placeholder with a real value before publishing it internally, or it will read as advice rather than as policy.
Check the PDF you are holding
Run a free PDF X-Ray in your browser — it recovers text from the file’s earlier revisions, so you can see what a value was before it was changed. No account needed.
Keep reading
Apostille vs. Legalization: Verifying Documents Across Borders
International documents carry authentication chains most reviewers have never been taught to read. How apostilles and consular legalization work — and how both get faked.
Chain of Custody for Digital Documents: Making Evidence Hold Up
A forensic finding is only as strong as the custody story behind the file. Hashes, handling, and documentation — how to keep digital document evidence defensible.
The Two-Invoice Trade: Customs Undervaluation and the Paper That Hides It
Undervalued commercial invoices dodge duties, launder value, and expose importers to seizure. How the double-invoice game works and how compliance teams catch it in the paper.