Fake Bills of Lading and Certificate of Origin Fraud Detection
How US compliance teams detect fake bills of lading and forged certificates of origin, including AI-generated forgeries, inside KYB and AML controls.

Summarize this article with
This article is provided for informational purposes only and does not constitute legal or regulatory advice. Legislative and regulatory references are accurate as of the publication date. Consult a qualified professional for guidance tailored to your situation.
Editorial disclosure: CheckFile provides document fraud detection solutions. Internal analyses and benchmarks cited in this article come from CheckFile platform data and are identified as such.
A fake bill of lading is a shipping document that looks genuine but describes a cargo, vessel or voyage that does not exist, or that misstates weight, value or origin to support a fraudulent payment. A forged certificate of origin performs the same trick for country-of-origin claims, letting sanctioned or tariff-restricted goods cross a border under a false flag. Both are detected the same way: by cross-checking the document against independent third-party records โ vessel tracking data, customs valuation history, chamber of commerce registries โ rather than reviewing the PDF on its own.
What a bill of lading and a certificate of origin actually do
A bill of lading performs three legal functions simultaneously: it is a receipt confirming goods were loaded onto a named vessel, evidence of the contract of carriage between shipper and carrier, and, in its negotiable form, a document of title that lets ownership of the cargo transfer by endorsement before the goods physically arrive. In the US, that document-of-title function is governed by state commercial law under Article 7 of the Uniform Commercial Code, while the customs treatment of the underlying shipment is federal. A certificate of origin (CoO) is a separate document, typically issued or certified by a local chamber of commerce or, for USMCA-qualifying goods, self-certified by the importer, exporter or producer, attesting the country where goods were produced, manufactured or substantially transformed. Banks financing the transaction, US Customs and Border Protection (CBP) assessing duty, and buyers claiming preferential tariff treatment under a trade agreement each rely on these two documents independently corroborating the same shipment.
Every imported article entering the United States must carry accurate country-of-origin information, and CBP's marking regulations at 19 CFR Part 134 require that origin be conspicuous, legible and sufficient for the ultimate purchaser to identify where the goods were made (eCFR, 19 CFR Part 134 โ Country of Origin Marking). For goods claiming USMCA preference, separate rules-of-origin regulations determine whether non-originating components underwent enough transformation to qualify. When the certificate or self-certification backing that claim is fabricated rather than genuine, the importer, the bank financing the deal and CBP granting the tariff concession are all exposed โ often without knowing it until an audit, a duty-evasion investigation or a sanctions screening flags the shipment.
How trade document fraud works in practice
Trade-based money laundering (TBML) moves value through the trade system itself rather than through a bank account, and forged shipping documents are what makes the mechanism function. The FATF's report Trade-Based Money Laundering: Trends and Developments sets out the core techniques compliance teams still see today: over- and under-invoicing, over- and under-shipment, multiple invoicing of the same cargo, and falsely described goods or shipments (FATF, Trade-Based Money Laundering: Trends and Developments). As a FATF member, the US implements this through FinCEN's own advisory guidance rather than a separate national typology framework.
In practice this breaks down into a handful of repeatable patterns. A phantom bill of lading references a container or vessel voyage that never took place, used to draw down a letter of credit or justify a cross-border payment against a shipment that does not exist. Over- or under-invoicing shifts value between counterparties by pricing goods far outside their normal range, a discrepancy that only surfaces when the invoice is cross-checked against the declared weight, volume or unit count on the bill of lading and packing list. Falsified certificates of origin misstate where goods were actually made, either to dodge antidumping or countervailing duties (AD/CVD) tied to a specific country of manufacture or, more seriously, to disguise the true origin of goods produced in a sanctioned jurisdiction. Counterfeit chamber-of-commerce stamps and signatures โ copied from a genuine certificate and reused on unrelated shipments โ are the common thread linking most of these schemes together.
FinCEN's foundational advisory on the subject lists inconsistencies between the description, quantity or value of goods across trade and shipping documents, along with shipments routed through jurisdictions with no apparent business rationale, among the clearest red flags financial institutions are trained to look for when filing a Suspicious Activity Report (FinCEN Advisory FIN-2010-A001, Guidance to Financial Institutions on Filing Suspicious Activity Reports Regarding Trade-Based Money Laundering). A single mismatched figure rarely proves fraud on its own, but a pattern of mismatches across a supplier's transaction history is what typically triggers escalation.
Why generative AI has raised the bar for document review
Generative AI tools let a fraudster produce a bill of lading with a plausible carrier letterhead, a correctly formatted IMO vessel number and a chamber-of-commerce stamp that visually matches the genuine article, in minutes rather than the hours a manual template edit used to take. Image generation and inpainting models can now replicate embossed stamps, watermarks and signature textures well enough to defeat a visual check by someone working through a stack of PDFs at speed. The tells that used to give away a forgery โ mismatched fonts, pixelated logos, an obviously copy-pasted signature โ are becoming less reliable as the tooling improves.
What generative AI cannot do is fabricate an entry in a vessel-tracking database, a chamber of commerce's own issuance register, or a carrier's internal booking system. A document can look flawless and still fail the moment it is checked against a source the fraudster does not control. That is why cross-referencing against independent third-party records remains the most reliable control, with AI-generation signals functioning as a complement to existing controls rather than a replacement for them โ a distinction worth keeping in mind when evaluating any vendor claim, including ours.
Ready to automate your checks?
Free pilot with your own documents. Results in 48h.
Request a free pilotDetection signals compliance teams should check first
A handful of checks catch a disproportionate share of forged trade documents, and none of them require exotic tooling. Cross-document consistency comes first: does the cargo description, weight and value on the bill of lading match the commercial invoice, packing list and certificate of origin, field for field. Transit-time plausibility follows: a bill of lading claiming a ten-day Pacific crossing for a vessel whose typical schedule takes sixteen is worth a second look. The vessel's IMO number should resolve to a real, active ship when checked against a public vessel-tracking source such as MarineTraffic or Equasis โ a document referencing a vessel that was scrapped, renamed or simply never existed under that IMO number is an immediate red flag. The issuing chamber of commerce on a certificate of origin should be traceable through the local chamber network; a stamp attributed to a chamber that cannot be found, or that denies issuing the document when contacted, is close to conclusive. PDF metadata โ creation software, author fields, edit timestamps inconsistent with the claimed issue date โ often survives casual tampering even when the visible content has been altered. Finally, stamps or signatures that appear identical, pixel for pixel, across documents purportedly issued by different companies or on different dates point to a template being reused across multiple fraudulent filings.
Manual review alone catches a limited share of this activity: the ACFE's 2024 Report to the Nations found that internal controls detect only 37% of occupational fraud cases, with an average detection delay of 87 days โ a lag most trade finance transactions, typically settled within weeks, cannot absorb before the funds have moved.
| Document | Common red flag | What it may indicate | How to check it |
|---|---|---|---|
| Bill of lading | Vessel or voyage not found in AIS/IMO records | Phantom shipment | Cross-reference the IMO number against MarineTraffic or Equasis |
| Bill of lading | Transit time inconsistent with the vessel's known schedule | Fabricated or altered document | Compare against the carrier's published routing and historical voyage data |
| Commercial invoice | Unit price well outside the 12-month range for the commodity and route | Over- or under-invoicing (TBML) | Benchmark against customs valuation data and historical supplier pricing |
| Commercial invoice | Weight, volume or unit count differs from the bill of lading and packing list | Value or quantity mismatch | Field-by-field cross-check across all three documents |
| Certificate of origin | Chamber of commerce stamp or self-certification not traceable to a verifiable issuer | Counterfeit certificate | Contact the issuing chamber or verify against USMCA self-certification data elements |
| Certificate of origin | Declared origin inconsistent with the exporting country's known manufacturing base | Origin-washing to evade AD/CVD duties or sanctions | Cross-reference against CBP rules-of-origin criteria and OFAC's Specially Designated Nationals (SDN) list |
Fitting document verification into a KYB and Know Your Supplier workflow
Trade document checks work best when they sit inside onboarding and ongoing monitoring rather than as a one-off review triggered by suspicion. At onboarding, a supplier or counterparty's registered activity, jurisdiction and historical trade patterns should be established as a baseline โ the Know Your Supplier discipline exists precisely to catch a mismatch between what a company claims to trade and what its filings and shipping history actually show. Ongoing monitoring then applies the same cross-document checks transaction by transaction, flagging deviations from that baseline rather than treating every shipment as a fresh, unconnected review.
For US banks and financial institutions financing trade, this sits within the customer due diligence obligations set out under the Bank Secrecy Act (31 USC ยง5311) and FinCEN's Customer Due Diligence Rule, which require institutions to understand a customer relationship well enough to detect activity that deviates from it. Trade finance regulation also runs on a federal-plus-state structure: a US importer or intermediary may face state money-transmitter licensing or UCC filing requirements layered on top of the federal BSA and customs regime. Where the true origin or destination of goods is in question, OFAC's sanctions guidance for the maritime industry sets out the due diligence expected before a shipment proceeds, including screening every party named on a bill of lading against the SDN list (OFAC, Sanctions Guidance for the Maritime Shipping Industry). On the customs side, CBP's Enforce and Protect Act (EAPA) process lets an interested party file an allegation that an importer is evading antidumping or countervailing duties through misdeclared origin (CBP, Enforce and Protect Act (EAPA)). Several of the mechanics described above map directly onto the broader money laundering typologies that US regulated firms must screen against under existing BSA/AML obligations.
Our own review method rests on structural checks, metadata inspection and cross-document validation across several fields per document, rather than a read of any single PDF in isolation, with an additional layer of AI-generation signals, deployed according to client configuration, that complements these structural checks rather than replacing them. CheckFile's platform is built to handle verification across more than 3,200 document types and 32 jurisdictions, which in a trade context means bills of lading, certificates of origin, commercial invoices and packing lists can be checked against each other inside the same workflow used for standard KYC document verification in banking. Document handling for trade files, which often carry commercially sensitive pricing and counterparty data, runs under the same controls described on our security page. For a broader view of how document checks fit across a compliance program, our document compliance guide covers the wider set of obligations beyond trade finance specifically. Pricing for teams evaluating a trade-document workflow is set out on our plans page.
What compliance teams actually ask about this
Compliance professionals on specialized trade finance and AML forums tend to ask narrower, more practical questions than the regulatory literature covers. A recurring one: how do you verify a bill of lading without simply calling the carrier every time, given the volume most trade finance desks process. Another: is under-invoicing always a laundering signal, or can it reflect a legitimate transfer-pricing arrangement between related entities โ the honest answer is that price alone is rarely conclusive, and it is the combination with other indicators (unusual routing, a counterparty with no verifiable trading history, payment structured to stay under a reporting threshold) that moves a file from anomaly to a Suspicious Activity Report. A third, increasingly common question centers on whether AI-generated forgeries can pass a visual check convincingly enough to fool an experienced document reviewer โ the practitioner consensus is that they increasingly can, which is precisely why cross-referencing against external, fraudster-independent records has become the control that matters most.
Frequently Asked Questions
How can I verify a bill of lading is genuine without contacting the carrier every time?
Start by checking the vessel's IMO number and stated voyage against a public AIS tracking source such as MarineTraffic or Equasis, and compare the transit time against the carrier's known routing. If those checks are consistent, cross-reference the cargo description and weight against the commercial invoice and packing list before escalating to a direct carrier confirmation, which should be reserved for files that fail the earlier checks or carry other risk indicators.
Is under-invoicing always a sign of money laundering?
No. Price alone can reflect a legitimate volume discount, a related-party transfer-pricing arrangement, or normal commercial negotiation, and treating every low invoice as suspicious would overwhelm a compliance team with false positives. It becomes a red flag when combined with other indicators โ a counterparty with no verifiable trading history, routing that adds unexplained transit points, or payment structured to sit just under a reporting threshold.
Can generative AI produce a certificate of origin that passes a visual check?
Increasingly, yes. Current image generation and editing tools can replicate embossed stamps, watermarks and signature textures well enough to defeat a visual review carried out at normal processing speed. That is why verification against an external source the fraudster does not control โ the issuing chamber of commerce's own register, or the CBP-facing rules-of-origin data behind a USMCA self-certification, in the case of a certificate of origin โ remains more reliable than inspecting the document's appearance alone.
Where should US firms report suspected trade document fraud?
Suspicious activity connected to money laundering, including forged trade documents, should be reported by covered financial institutions as a Suspicious Activity Report (SAR) filed with FinCEN under the Bank Secrecy Act, consistent with the reporting framework FinCEN's trade-based money laundering advisory sets out. Suspected customs fraud, duty evasion or a fraudulent certificate of origin tied to an import entry can separately be reported to CBP through its e-Allegations program or, where antidumping or countervailing duty evasion is suspected, through an EAPA allegation.
Does checking a vessel's IMO number against AIS data actually catch fraud?
It catches a specific and common category: bills of lading referencing a voyage, vessel or shipping window that never happened. It will not catch a forgery built around a real vessel and a real, legitimate voyage used to cover a mispriced or misdescribed cargo, which is why the check needs to sit alongside invoice benchmarking and certificate-of-origin verification rather than standing in for them.
Forged bills of lading and certificates of origin are built to survive a quick visual check, not a cross-reference against records the person who forged them does not control. Building that cross-referencing into a KYB and trade finance workflow, rather than treating each document as a standalone review, is what turns an occasional catch into a repeatable control. If AI-generated forgeries are a growing concern in your onboarding or trade finance pipeline, our AI-generated document and deepfake detection capability is designed to sit alongside your existing checks โ offering AI-generation signals as a complement to your existing controls, not a replacement for the cross-document and third-party verification described above.
Stay informed
Get our compliance insights and practical guides delivered to your inbox.