Tender Fraud: When the Winning Bid Is a Forgery
A tender is decided almost entirely on paperwork — certificates, accounts, references, insurance. Most of it is scored once, by someone with forty other submissions to read, and never checked again.

Procurement is one of the few processes in business where the decision is made almost entirely on documents. Nobody visits the factory. Nobody meets the reference. A panel reads a submission pack, scores it against criteria, and awards a contract that may run for years.
The pack is large — certificates, audited accounts, insurance, references, CVs, method statements, health-and-safety records — and it arrives alongside dozens of others, at a deadline, to be assessed by people who have a day job. The volume is the vulnerability.
Key takeaways
- Qualification documents are the fraud target, because they are pass/fail gates scored once and rarely re-verified after award.
- Reference letters are the weakest artifact in a tender pack: unverifiable by design, and frequently written by the bidder.
- Collusion leaves document traces — shared metadata, shared templates, complementary pricing — that are invisible per-submission and obvious across a set.
- Verifying at award instead of at submission is the single change that catches most of it, because it moves the check to the one bid that matters.
What actually gets forged
Certifications and accreditations. ISO standards, industry-specific approvals, environmental and quality marks. These are usually hard gates — no certificate, no bid — which makes them the highest-value forgery in the pack. Real certificates are registrable; every serious certification body maintains a searchable register, and almost nobody searches it.
Insurance certificates. Employers' liability, public liability, professional indemnity, at specified minimum levels. A certificate of insurance is a summary document produced from a policy, it looks broadly the same across the market, and it is easy to alter. The variants are worse than outright forgery: a real certificate with the limits inflated, a policy that was cancelled the week after issue, or coverage whose scope excludes exactly the work being tendered for. We went through the mechanics in fake certificates of insurance.
Financial statements. Turnover thresholds and solvency ratios are common gates. Filed accounts are public in most jurisdictions, which makes the fabricated version straightforwardly checkable — and makes an unfiled set, presented as "management accounts", the more common approach.
References. The weakest link by a wide margin, and the one that decides scored sections. A reference letter is a document with no issuing authority, on letterhead anyone can produce, from a contact whose phone number the bidder supplied. A meaningful proportion are written by the bidder and signed by a friendly contact; a smaller but real proportion are written by the bidder and signed by nobody at all.
CVs and named personnel. Tenders often score the specific people assigned. Qualifications get inflated, projects get borrowed, and the named senior engineer turns out to be on three other contracts. Credential fraud in this context is the same problem as in hiring — see how to verify a degree — but with a contract attached.
Past performance evidence. Project lists, case studies, completion certificates. Easy to embellish, hard to disprove, and rarely checked because verification means contacting a third party who has no obligation to reply.
The collusion layer
Beyond individual forgery, there is a second category that only becomes visible across submissions: bidders coordinating so that a predetermined one wins.
The classic patterns are well documented — cover bidding, where competitors submit deliberately uncompetitive prices; bid rotation, where the same set of firms take turns; and market allocation by geography or client (oecd.org). What is less discussed is that collusion leaves document traces, and they are the easiest part to detect if anyone looks.
Shared metadata. Two "independent" bids whose files carry the same author, the same company field, or the same producer software with the same unusual configuration. This is the single most common tell, and it survives because people edit content and forget the properties.
Shared structure. Identical formatting quirks, the same template, the same paragraph appearing verbatim in two submissions. Sometimes the same typo.
Complementary pricing. Prices that differ by a suspiciously consistent percentage, or a losing bid that is a clean multiple of the winner's.
Sequential submission. Bids uploaded minutes apart, from the same network, at the end of the window.
One bidder withdrawing late in a way that leaves a single compliant bid.
None of these are visible when you assess one submission at a time. All of them are obvious when you compare the set — which is an argument for treating the tender round, not the individual bid, as the unit of analysis.
Where the process makes it easy
Some of this is procedural rather than criminal, and worth naming plainly.
Evaluation is compressed. A panel receives thirty packs of two hundred pages each with three weeks to score them. Nobody reads it all, and everybody knows nobody reads it all.
Qualification is treated as a checkbox. Someone confirms the certificate is present, not that it is valid. The distinction sounds pedantic until you notice it is the entire control.
Verification is postponed and then forgotten. "We'll check at award" becomes "we awarded" and the pack is filed.
And the same documents are reused across tenders for years, so a certificate that was accepted in 2023 gets accepted again in 2026 because it is in the folder.
Controls that fit the constraints
The realistic goal is not to verify everything. It is to verify the right things at the right moment.
Verify at award, not at submission. Thirty packs is impossible. One is not. Make full verification of the winning bidder a mandatory pre-award step, and say so in the tender documents — announcing it changes behaviour before anyone submits.
Check registers, not documents. For anything with a register — certifications, insurance, company status, professional licences — the certificate is a convenience and the register is the truth. Look up the register entry rather than examining the PDF.
Verify references through the organisation, not the contact. Call the switchboard of the referring company and ask for the named person. A referee who only exists on the phone number the bidder provided is not a referee.
Compare across the set, not just within a bid. Run every submission's document properties together and look for shared authors, producers and templates. This costs almost nothing and it is the only way collusion becomes visible.
Give the evaluation panel a way to escalate. Assessors often notice something odd and have no mechanism to raise it that does not sound like an accusation. A simple "flag for verification" route surfaces a lot.
Re-verify on a cycle for long contracts. Insurance lapses. Certifications expire. A three-year contract awarded on a valid certificate can spend two of those years uninsured.
Where document analysis earns its place
Register checks answer the certification questions. What they cannot answer is whether the document in front of you is the one the register describes, or whether two bids came out of the same office.
That part is structural. Document properties, producer strings, embedded fonts, revision history and template fingerprints are all generated by the act of creating a file, and they are consistent in ways content is not. Two independent companies do not produce documents with the same author field by coincidence.
Our free PDF X-Ray reads that structure for a single file, without an account. For a tender round, the useful version is the same analysis across every submission at once, which is what our metadata comparison across a document set is for. Either way, the question is the same: does the paperwork's provenance match the story the submission is telling?
In procurement, that question is worth asking before the contract is signed rather than during the dispute.
Frequently asked questions
What is the most commonly forged document in a tender?
Reference letters, because they have no issuing authority and no register. Insurance certificates and certification documents are close behind, and both are checkable against a register that reviewers rarely consult.
How do you detect bid rigging from documents?
Compare submissions against each other rather than individually. Shared document authors, identical templates and formatting quirks, complementary pricing patterns and near-simultaneous submission are all traces that only appear across the set.
Should we verify every bidder's documents?
Rarely practical. Verify presence and format at submission, then fully verify the winning bidder before award — and state in the tender that you will. The announcement does much of the deterrent work.
How often should certifications be re-checked on a long contract?
At least annually, and on any renewal date the certificate itself carries. Insurance and certification both lapse quietly, and a contract awarded on valid cover can run for years without it.
Put it to the test
Scan a document and get a plain-English verdict in seconds. Free to start.
Keep reading
Fake Portfolio Statements: Wealth That Only Renders
A portfolio statement is a claim about money you cannot see, issued by an institution you may not be able to contact, in a format nobody standardised. That is a lot of room to work in.
The Fake Employment Letter: Anatomy of a 20-Minute Forgery
An employment verification letter is a salary claim on a letterhead. Why this document is the easiest fake in the file, and the source-check that defeats every version of it.
Trust Seals and Badges: The Cheapest Credibility Online
A trust seal is a picture. Copying a picture takes one right-click. Yet a row of badges in a website footer still moves purchase decisions more than almost anything else on the page.