How-to guideAug 28, 2026by Docurensic Team8 min read

A Document Verification Policy Worth Adopting (Template)

A copy-and-adapt policy with tiered checks, numeric thresholds instead of adjectives, a named escalation route and an incident procedure — written to be edited, and free of anything that depends on buying a product.

A Document Verification Policy Worth Adopting (Template)
In this guide
  1. Key takeaways
  2. Document Verification Policy — template
  3. Making it stick
  4. Frequently asked questions

Almost every organisation that gets hit by document fraud had a policy. It said something like "staff should verify documents where appropriate", and it was true, and it was useless, because at 4:40pm on a Friday with a customer on hold nobody has ever been helped by the phrase where appropriate.

A policy that works has a different shape. It removes the judgement call from the person under pressure, it names who decides when the answer is unclear, and it is short enough that somebody actually reads it.

Below is a template you can copy, adapt and adopt. It is written to be edited — the bracketed parts are yours to fill in — and it is deliberately free of anything specific to our product, because a policy that only works if you buy something is not a policy. Take it, change it, put your own name on it.

Key takeaways


Document Verification Policy — template

1. Purpose and scope

This policy sets out how [ORGANISATION] verifies documents received from customers, suppliers, applicants and third parties before relying on them.

It applies to every document that supports a decision to pay money, extend credit, release goods, employ a person, or accept a liability. It applies regardless of how the document arrives — email, portal, post, or in person.

It does not apply to [internal working documents / marketing material / list your exclusions], which are governed by [other policy].

2. Principles

  1. Verify at the source where a source exists. Confirmation from the issuing body outranks any analysis of the document itself.
  2. One signal rarely decides. A single anomaly prompts a closer look; a decision to decline requires corroboration from an independent direction.
  3. Authenticity and approval are separate questions. Whether a document appears genuine is a question about evidence. Whether to proceed is a business decision that includes risk appetite. Record them separately.
  4. Doubt escalates; it does not resolve itself. Nobody is expected to make a judgement call alone under time pressure.
  5. Genuine customers are the majority. Controls will be proportionate, and wrongly refusing a real customer is treated as a failure, not a safe outcome.

3. Verification tiers

Every in-scope document is handled at one of three tiers, determined by value and risk.

Tier 1 — Standard. Applies to [documents supporting transactions under $X] [routine documents from established counterparties].

Tier 2 — Enhanced. Applies to [transactions between $X and $Y], first-time counterparties, and any Tier 1 document where an anomaly was noted.

Tier 3 — Investigation. Applies to [transactions above $Y], any case where Tier 2 raised an unresolved concern, and any document type on the elevated-risk list at Appendix A.

Set the thresholds to real numbers before you publish this. A tier structure with adjectives in it is not a policy.

4. Mandatory checks that never depend on tier

These apply to every document, always:

5. Escalation

Anybody, at any level, may escalate a document they are uncomfortable with, without needing a reason they can articulate. Escalation goes to [named role or team] and is acknowledged within [timeframe].

No individual may waive a required check. [Named role] may authorise a documented exception, which must record: what was waived, why, who approved it, and the date. Exceptions are reviewed [monthly] by [role].

Escalating is never a performance issue. A person who escalates a genuine document has done their job correctly.

6. When a document is judged fraudulent

  1. Preserve the original file and the message that carried it, unmodified.
  2. Do not tell the sender what was detected or how. [Named role] handles all communication.
  3. Notify [named role] immediately; notify [insurer / legal / bank] per Appendix B.
  4. Check whether the same counterparty has supplied other documents, and re-examine them.
  5. Report externally per Appendix B.
  6. Record the case, the indicators and the outcome in [system], for the review at section 8.

Point 2 matters more than it looks. Telling a fraudster exactly which check caught them trains the next attempt.

7. Training and awareness

8. Review

This policy is reviewed [every six months] by [role]. The review must consider:

Appendix A — Elevated-risk document types [list yours: proof of funds, certificates of insurance, employment letters, bank statements from non-institutional sources…]

Appendix B — Escalation contacts and external reporting routes [see where to report document fraud]


Making it stick

Three things determine whether a policy like this survives contact with an operating business.

Numbers, not adjectives. Every bracketed threshold above should become a figure. The single most common failure in real policies is that they describe when to be careful in language that lets a person under pressure decide they are not in that situation.

A named owner with time. A policy owned by "the risk function" in the abstract is owned by nobody. Put a name on it and give that person the twice-yearly review as a real task.

Feed it your own incidents. The generic version above is a starting position. Six months of your own near misses will tell you which document types actually cause you problems, and the second version of this policy — the one shaped by your losses rather than by a template on the internet — is the one that earns its place.

If you adapt this for your organisation, you are welcome to use it however you like. A link back is appreciated but not required.

Frequently asked questions

What should a document verification policy include?

Scope, a small number of principles, tiered checks tied to numeric thresholds, a set of checks that apply regardless of tier, a named escalation route, an incident procedure, training obligations, and a scheduled review. Anything longer than a few pages will not be read.

How do you set verification thresholds?

Start from your own transaction distribution and incident history rather than from an industry number. Pick values that put a manageable proportion of volume into each tier, then adjust at the six-month review based on what the tiers actually caught and how many genuine customers they delayed.

Who should own document verification in a business?

A named individual with authority over the process — commonly a risk, finance or operations lead. Ownership by a committee or an unnamed function is the most reliable way for a policy to go stale.

Can we adapt this template for our organisation?

Yes. It is written to be copied and edited, and there is no restriction on using it. Replace every bracketed placeholder with a real value before publishing it internally, or it will read as advice rather than as policy.

Check the PDF you are holding

Run a free PDF X-Ray in your browser — it recovers text from the file’s earlier revisions, so you can see what a value was before it was changed. No account needed.

Open the free PDF X-Ray

Keep reading