Fake Certificates of Good Standing in KYB Onboarding
How fraudsters forge Certificates of Good Standing and Articles of Incorporation to pass KYB checks in the US, and how compliance teams detect and stop it.

Summarize this article with
A fake Certificate of Good Standing (or a doctored set of Articles of Incorporation) is a state-issued business filing that has been edited, fabricated, or presented with a real entity number but substituted officer or registered-agent details, to pass a KYB onboarding check. The United States has no single national companies registry โ each of the 50 states runs its own filing office, disclosure rules, and lookup portal โ so fraudsters can exploit gaps between state systems more easily than they can forge a bank statement or a passport. This is the fraud-detection companion to our guide on how to verify a company registration certificate online: that article covers the legitimate lookup process, this one covers how the document gets faked.
This article is for informational purposes only and does not constitute legal, tax, or regulatory advice. Consult an attorney or compliance professional for guidance specific to your organization. Legislation and guidance referenced are current as of July 25, 2026.
What a Certificate of Good Standing Proves โ and the Fifty-Registry Problem
A Certificate of Good Standing (Certificate of Existence or Certificate of Status in some states) confirms an entity is validly formed and currently authorized to transact business in the issuing state, having filed its required reports and paid franchise or annual fees as of the date it was issued. Articles of Incorporation, by contrast, are a one-time formation document filed with the Secretary of State (Division of Corporations in Delaware, Department of State in New York); they are never updated, so a genuine 2019 filing remains genuine even if the company has since changed officers or been administratively dissolved. Neither document proves who currently controls the business or that it is still active โ a gap that matters more in the US than in most jurisdictions, since there is no free, universal, federal lookup to instantly confirm current status.
This fragmentation is itself a fraud vector specific to the US system. A fraudster incorporating a shell entity can shop for the state with the weakest disclosure regime: Delaware does not require officer or director names on its public Certificate of Incorporation, Nevada has historically marketed its privacy protections to entity formers, and Wyoming permits anonymous LLCs with only a registered agent's name on the public record. None of this is illegal โ states compete for incorporation revenue โ but a reviewer checking a Delaware entity often cannot see beneficial ownership through the state registry at all, only through a certificate the counterparty chooses to present. That gives the certificate more evidentiary weight in the US than in single-registry jurisdictions: a reviewer must know which office issued the document and go to that office's own search tool, treating anything unconfirmed as unverified by default. Delaware, notably, offers no free public entity search comparable to other states โ a certified status confirmation requires a paid request, raising the incentive to skip independent verification.
How Fraudsters Actually Forge These Documents
Editing a genuine downloaded PDF is the most common method: a fraudster obtains a real certificate โ sometimes their own, sometimes a stolen or purchased copy relating to an unrelated entity โ opens it in a PDF editor, and changes the entity name, file number, registered agent, or issue date.
Fabricating a document from scratch is less common but occurs, particularly where the target is a one-off visual check: recreating a state seal, signature block, and certificate wording in a design tool, or increasingly using generative AI to produce a convincing image-based certificate carrying a plausible-looking file number that either does not exist or belongs to an unrelated entity.
Corporate identity theft is the more dangerous variant: using a real, active entity's genuine file number and legal name, but substituting the officer names or registered-agent details. Because the file number checks out on a cursory search, this survives a reviewer who confirms "yes, that entity exists" without comparing every field against the state's own record. A related, fourth pattern is a stale certificate that quietly omits a recent administrative dissolution โ most states dissolve entities for failing to file an annual report or pay franchise tax, and the certificate may be genuine while omitting the status change the presenter has not disclosed.
Real Fraud Schemes This Enables
Business email compromise and vendor impersonation fraud are among the costliest categories the FBI's Internet Crime Complaint Center tracks: IC3 recorded $2.77 billion in reported BEC losses across 21,442 complaints in 2024, climbing to roughly $3.05 billion in 2025, with most stolen funds moved by wire transfer or ACH (FBI IC3, 2025 Internet Crime Report). A forged certificate frequently sits behind these schemes, used to convince accounts payable that a fraudulent vendor or a compromised supplier's "updated" banking details are legitimate.
Fraudulent subcontractor onboarding is common in construction, where a forged or borrowed certificate lets a non-compliant subcontractor pass a general contractor's paperwork check before work begins. Shell companies formed to launder money or clear a lender's onboarding threshold pair a genuine or lightly altered certificate with fabricated financial statements, echoing the tactics in our analysis of fake financial statements in business lending fraud. In each scheme, the certificate is rarely the fraud itself โ it is the credential that gets the fraudster past the door.
Ready to automate your checks?
Free pilot with your own documents. Results in 48h.
Request a free pilotDetection Techniques That Actually Work
The single most effective control is going directly to the Secretary of State's business entity search for the specific state of incorporation named on the document, rather than trusting the PDF a counterparty has sent โ Delaware's Division of Corporations for a Delaware entity, the Texas Comptroller's Taxable Entity Search for a Texas one, not a generic multi-state aggregator. Any mismatch between what the state's own system shows and what the document claims is the clearest signal of tampering.
Requesting a certificate issued within the last 30 to 90 days is a practical control against stale or dissolution-concealing filings, since most states will not issue a fresh certificate for a delinquent or dissolved entity. Cross-checking the registered agent is a second, underused check โ its name and address are public record in nearly every state, and a mismatch is a strong indicator of substitution. PDF metadata analysis is a further layer: creation software and timestamps can reveal that a "2021 certificate" was last saved in an image editor a few weeks ago. Where the entity is a foreign reporting company subject to beneficial ownership reporting, checking FinCEN's BOI filings adds a further cross-reference โ though, as covered below, this now applies to a narrower slice of entities than originally intended.
| Red flag | Verification method | What it reveals |
|---|---|---|
| File number matches, but officer or registered-agent names differ | Search the file number on the Secretary of State's portal | Corporate identity theft โ real entity, fabricated control details |
| Certificate over 90 days old, no other current filing accompanies it | Request a fresh Certificate of Good Standing from the state | Possible dissolution or delinquency being concealed |
| Certificate presented as current for a dissolved entity | Check current status with the Secretary of State | Stale filing concealing dissolution or revocation |
| PDF creation date inconsistent with the claimed certificate date | Inspect file metadata (software, save history) | Document edited or fabricated after its claimed date |
| Seal, signature block, or wording differs from the genuine template | Compare against a certificate ordered directly from the state | Wholesale fabrication rather than an edited filing |
| Registered agent does not match the state's public record | Search the registered agent field on the state registry | Document altered to obscure who receives legal notices |
What Compliance Teams Are Actually Asking
Compliance and fintech practitioners on forums like r/compliance and r/fintech often ask which state's registry to trust when a counterparty is incorporated in Delaware or Nevada but operates elsewhere, since the "home" registry often shows little beyond entity status and registered agent. Most experienced reviewers answer that the state of incorporation controls for legal existence and good standing, but a foreign qualification filing where the business actually operates often surfaces more current information worth checking as a secondary source.
A second recurring question, closer to r/banking discussions of onboarding friction, is whether one discrepancy โ a registered-agent name that does not match the state record โ justifies rejecting a customer outright. In practice, one inconsistency should trigger a direct registry check and a request for an explanation, but two or more on the same document, particularly involving officer identity or entity status, is treated as grounds to pause onboarding pending verification with the Secretary of State directly.
The Corporate Transparency Act โ What Actually Applies in 2026
The Corporate Transparency Act (CTA), enacted in 2021, originally required most US corporations, LLCs, and similar entities to report beneficial ownership information (BOI) to FinCEN. That scope has since been substantially narrowed. On March 21, 2025, FinCEN issued an interim final rule exempting all entities created in the United States, and their beneficial owners, from BOI reporting entirely. "Reporting company" now covers only entities formed under foreign law and registered to do business in a US state or tribal jurisdiction โ and even those no longer report beneficial owners who are US persons (FinCEN, Beneficial Ownership Information Reporting). FinCEN intends to finalize this interim rule, so the scope could shift again, but as of mid-2026 US-formed entities have no BOI filing obligation at all.
For KYB purposes, FinCEN's BOI database is no longer a meaningful cross-check for most US-formed counterparties โ a material change from the CTA's original design. Verification weight has shifted back toward the state-level Certificate of Good Standing and registered-agent record as the primary, and often only, independent source of truth for domestic entities.
Legal Framework and Liability
Presenting a forged or manipulated certificate to induce a lending, vendor, or banking decision typically implicates wire fraud under 18 U.S.C. ยง1343 where any interstate wire or electronic transmission is involved, carrying up to 20 years' imprisonment (Cornell Law School, Legal Information Institute, 18 U.S.C. ยง1343). Most states separately maintain their own forgery statutes covering falsified corporate documents.
For regulated financial institutions, the obligation to scrutinize business documentation as part of KYB sits within the Bank Secrecy Act, codified at 31 U.S.C. ยง5311, which requires recordkeeping designed to prevent money laundering and requires institutions to know who they are doing business with (Cornell Law School, Legal Information Institute, 31 U.S.C. ยง5311). Knowingly structuring proceeds through a shell entity built on fraudulent formation documents can trigger liability under the Money Laundering Control Act, 18 U.S.C. ยง1956. A financial institution that onboards on an unchecked, forged certificate is not merely exposed to the underlying fraud โ it risks its own BSA/AML compliance position.
A Layered Approach to Detection
Manual detection methods, including routine visual review of documents, catch only around 37% of occupational fraud cases, with a median delay of 87 days before detection (ACFE, 2024 Report to the Nations). That gap exists because a well-edited PDF can pass a five-second glance every time; it only fails when checked against an independent source, which is why state-registry cross-checking has to be a standing step in onboarding, not a discretionary one used only when something already looks wrong.
CheckFile's approach layers structural analysis, metadata checks, and cross-document validation, built to cover 3,200+ document types and 32 jurisdictions. CheckFile also deploys an AI-generation detection layer as a complementary signal, not a replacement for cross-checking the official state registry. A forged Certificate of Good Standing still has to be checked against the issuing Secretary of State's own record โ no amount of document-level analysis substitutes for that step.
For teams refining a full KYB workflow, our complete guide to business entity verification covers the wider process, and our industry verification guide sets out sector-specific checks across financing, construction, and regulated services. CheckFile's platform is also used in equipment financing and leasing, where a forged registration document paired with fabricated financials recurs โ see our security page, pricing, and homepage for more.
If your onboarding process still relies on a visual read of a PDF a counterparty has sent, CheckFile's AI-generated document detection adds AI-generation signals as a complement to your existing controls โ not a guarantee of catching every forgery, but a useful layer alongside state-registry cross-checks and registered-agent verification.
Frequently Asked Questions
Can a fake Certificate of Good Standing use a real entity file number?
Yes โ this is corporate identity theft, the most dangerous variant. The file number and entity name are genuine and pass a superficial search, but the officer or registered-agent details have been substituted. Catching it requires comparing every field against the state's own registry record, not just confirming the file number exists.
Which state's registry should I check if a company is incorporated in Delaware but operates elsewhere?
Check the state of incorporation first, since it controls legal existence and good-standing status. Then check whether the entity has filed a foreign qualification where it actually operates, since that filing often exposes more current information than the home-state registry provides.
Does the Corporate Transparency Act still require most US companies to report beneficial ownership to FinCEN?
No, not since March 2025. FinCEN's interim final rule exempted all US-formed entities and their beneficial owners from BOI reporting, narrowing the requirement to foreign entities registered to do business here โ and even those no longer report US-person beneficial owners. A final rule confirming this scope was still pending as of mid-2026.
What is the fastest way to check if a Certificate of Good Standing is genuine?
Go directly to the Secretary of State's business entity search for the state named on the certificate and compare the entity name, status, file number, and registered agent against the document presented. This is more reliable than any visual inspection of the PDF, though some states charge a fee for certified confirmations.
Is presenting a forged business certificate a criminal offense in the United States?
Yes. Where an interstate wire or electronic transmission is part of the scheme, it typically falls under wire fraud, 18 U.S.C. ยง1343, carrying up to 20 years' imprisonment. Most states additionally prosecute forgery of a corporate or government-issued document under their own statutes.
Stay informed
Get our compliance insights and practical guides delivered to your inbox.