Article · September 11, 2026

How to check a bank statement exhibit you did not prepare

Two hashes, two different claims

Every exhibit carries two numbers that are easy to confuse. The findings hash is printed on the cover and in the footer of every page. It is computed over the SHA-256 of each input file as received, each file's declared source, every row as exported, the method version, and the reviewer's screen parameters. It is not computed over the matter name, the reviewer's name or the file names, so a rerun under different labels still reproduces it, and it is the same on any build of the engine. It answers one question: were these figures produced from these files by this method.

The file hash is the SHA-256 of the exhibit PDF itself. It is the same only on the same build of the engine, with the same preparation date and the same rendering mode, all three of which are printed on the cover; the preparation date is printed in UTC and sits deliberately outside the findings hash, so that a rerun on a later day reproduces every figure without pretending it was prepared that day. It answers a narrower question: is this file the one that was produced.

What you need

The procedure

  1. Note the method version, the engine line, the preparation date, the output mode and the findings hash on the cover.
  2. Run shasum -a 256 over the PDF and compare with the file hash recorded at download. A match proves the file is the one produced. A mismatch means the file changed after it was produced, or it was produced on a different day, build or mode; the cover says which of those it was.
  3. Compute the SHA-256 of each source file and compare with the register. A file that does not match is not the file the exhibit was built from, and nothing further needs checking until that is resolved.
  4. Open a matter, add the files in the register's order with the register's sources, set the same key date and keywords, apply the same hand edits, and run it. Name the matter and the reviewer as you like; neither enters the hash.
  5. Compare the findings hash on screen with the one on the cover. A match proves every number in the exhibit is reproduced from those files by that method. If you also match the engine build, preparation date and rendering mode, the new PDF's SHA-256 matches too, byte for byte.

Where a page was read by OCR

A scanned page is a picture, and a different reader of a picture is a different engine. So when OCR ran, the OCR engine and the identity of its training data are part of the findings hash, and both are printed in the engine line on the cover. Two runs on different OCR builds can legitimately differ on a scanned matter, and the cover is what tells you whether that is what happened.

Try it on the sample before a real matter

The sample exhibit on this site is built from synthetic statements of a fictional bank, and the files are downloadable as a zip with a README that lists the order and the sources. Drop them into a free matter, under any matter name and any reviewer name, and the hash on screen must read the one on the sample's cover. If it does not, something in the procedure was not followed, and the README says which step to check.

What a match does not say

Reproduction proves the figures, not the documents. It shows that the rows, the proof and the notes follow from the files by a published method. Whether a statement is genuine, whether a transfer had a purpose, and what a note means for the matter are the examiner's calls, and the exhibit's basis of preparation says so in as many words. The method page lists every check by name, and it also lists what is not checked, which is the part an opposing expert reads first.

The register and the proof are free on screen, no account needed for the first matter. Start a matter · Read the sample exhibit

All articles