Fake surety bonds: how to verify a guarantee and prove what you received

A bid guarantee usually arrives as a PDF, often on the day the deadline closes. The letterhead belongs to an insurer you know, the wording follows the standard form, the signature block looks right. You open the supervisory register, find the company, move the file forward.

Three months later the bond is called and the insurer says it never issued it. The supplier says it sent a different document, a valid one, and that whatever you are holding never left its office. The question is no longer whether the bond was genuine. It is what you can show.

Checking a surety bond before you accept it is necessary, and on its own it is not enough. A check protects you only if it leaves a record you can produce later: which document was handed over, on what date, and what the official registers showed at the moment you looked. What follows covers both halves of the job, the verification and the evidence that it happened.

What makes a surety bond fake, and why procurement is the target

A fake surety bond is a guarantee that the named issuer never underwrote. The paper exists, the obligation behind it does not, and the beneficiary finds out only when the bond is called. That is a different problem from a bond that is merely invalid, where a real insurer issued a real policy that then fails on a formal requirement and can sometimes be cured. On 16 July 2026 IVASS, the Italian insurance supervisor, published three separate alerts in a single day about counterfeit surety policies circulating on the letterhead of Allianz Benelux SA/NV, Chaucer Insurance Company DAC and Tryg Forsikring A/S. All three are properly authorized insurers in the surety class. All three disowned the documents going around under their names (IVASS press releases).

Procurement attracts this kind of fraud because the guarantee is the one document in the file that nobody expects to use. It gets collected, filed and forgotten, and it is tested only when something has already gone wrong, often years after the award.

What supervisors have flagged in 2026

The 2026 alerts follow one pattern: counterfeit policies attributed to foreign insurers that are real, authorized and known, but that never issued the documents in circulation. On 12 February 2026 IVASS flagged counterfeit draft surety policies attributed to ADAC Versicherung AG, a German insurer, which disowned them. On 29 May it flagged counterfeit policies attributed to Industria Försäkringsaktiebolag, a Swedish insurer, which also disowned them. Then came the three alerts of 16 July. The choice of issuer is deliberate. Anyone who checks only whether the named company is authorized will find that it is, because it genuinely is, and will conclude the document is fine. The authorization check passes and the bond is still worthless.

Two distinct risks: a guarantee that never existed, and a document that was swapped

The counterfeit is the risk everyone talks about. It is not the only one.

The first risk is the guarantee that was never underwritten: a forged document, or one produced by an entity with no capacity to stand behind it. A variant of the same failure, documented across the European market, is the guarantee formally issued by an authorized entity that turns out to be unpayable when it is called. Tools that generate convincing forged documents have made the first category cheaper to produce and harder to catch by eye.

The second risk gets almost no attention, and in a dispute it is the harder one to unpick: the document you hold is not the document the other side says it sent. Files get replaced in transit, attachments get resent, versions multiply across a mailbox, and the argument turns into one word against another. It is the same dynamic as the invoice with a substituted IBAN, where everyone agrees an email was sent and nobody can prove what was attached to it. Verifying the issuer does nothing for you here, because the issuer was never the weak point.

How to verify a surety bond before you accept it

Three checks, in this order: confirm the issuer is authorized to write surety business, confirm whoever placed the bond is a registered intermediary, and confirm with the insurer itself, on contact details you found independently, that the policy exists. Anything the document tells you about itself is worth nothing, because a forger controls every character on the page.

Checking the issuer and the intermediary against official supervisory registers

Supervisory registers are the only starting point a counterfeiter cannot edit. A European insurance supervisor typically publishes four things that matter here: the list of authorized domestic insurers, the list of foreign insurers admitted to operate in the market, the specific list of insurers authorized in the surety class, and the register of insurance intermediaries. Next to those sits a running list of alerts about counterfeits, unauthorized firms and irregular intermediation websites. Appearing on the first list is not the same as appearing on the third: an insurer can be perfectly authorized and simply not write surety business, which is the gap the 2026 counterfeits exploited. Outside the euro area the equivalents are the U.S. Treasury listing of approved sureties and the FCA Financial Services Register in the United Kingdom.

Run the intermediary check separately. A bond placed by someone who is not on the register of intermediaries is a red flag on its own, whatever the letterhead says.

Registers are web pages, and web pages change. A consultation of a supervisory register can be certified with TrueScreen, which fixes the content of the page and the time of access, so that the page you consulted stays available as evidence instead of as a memory.

Counterfeit alerts and contacting the insurer directly

Read the supervisor’s alerts before you read the document. They are short, they name the companies whose letterhead is being abused, and they exist so that beneficiaries stop accepting what is in circulation.

Then call the insurer. The joint recommendation issued by the Italian supervisors on 28 May 2020 is still the clearest statement of the practical standard, and it holds anywhere: before accepting a guarantee, confirm the issuer is authorized, confirm the intermediary is on the official register, and contact the insurer directly using the contact details published in the supervisory register, never the ones printed on the document you received. That last clause is the whole point. Counterfeit bonds carry a phone number and an email address that reach the people who made them, and a courteous confirmation from that number proves nothing.

Other signals worth treating as stop conditions: a premium far below the market, issuance within hours with no underwriting questions, payment instructions pointing to an account not held in the insurer’s name, and a web domain that reproduces a known brand with a small alteration.

Which elements of the document to compare

Compare the document against independent sources, element by element, and record what you compared it against.

Element on the document Compare it against What a mismatch usually means
Issuer name and legal form Supervisory list of authorized insurers The entity does not exist as named, or the name imitates a real one
Authorization to write surety business Specific list of insurers authorized in the surety class The insurer is real but does not underwrite this class
Intermediary who placed the bond Register of insurance intermediaries The bond was placed outside any supervised channel
Contact details printed on the bond Contact details published in the register The confirmation you are about to seek reaches the counterfeiter
Policy number, issue date, expiry Direct confirmation from the insurer The reference does not exist in the insurer’s own records
Signatory and their powers Insurer’s confirmation of the signature and mandate The signature was copied or invented
Payment and premium instructions Account held in the insurer’s name Funds are being routed to a third party
Wording and standard form Form required by the tender documents The text was assembled rather than issued

None of these checks takes long. They get skipped because they land at the worst moment in the calendar, when the file has to close.

Why verification loses its value when nothing records it

Because verification is an event, and events leave nothing behind unless you capture them. The register page you consulted will look different next quarter. The document you approved sits in a shared folder with a system date anyone can change. The email that carried it lives in a mailbox that can be edited, moved or purged. Every piece of a careful check is perishable.

What happens when the other side denies sending that document

The dispute stops being about the guarantee and starts being about the file. Digital copies carry weight in most European jurisdictions until the other party disputes them, and once disputed, the burden swings back to whoever relies on the copy. If your only artifact is a PDF in a folder, you are asserting that this was the file you received and the other side is asserting it sent something else. Neither statement is evidence.

Capturing the transmission as it arrives changes that. Certifying the email that carried the document, attachments included, turns a claim about what was sent into a record of what was received. ISO/IEC 27037 sets out the internationally recognized requirements for identifying, collecting and preserving digital evidence, and the logic behind it applies to a tender file too: evidence is defined by how it was acquired, not by how convincing it looks later.

The difference between remembering you checked and being able to show it

Unlike a paper file, which stays stable unless someone alters it, a digital check is unstable from the start. The result of a verification exists only in the moment it is performed. A supervisory register is live content: a company can be added, suspended, struck off or moved between lists, and the state you saw on the day you looked cannot be reconstructed later from the public site. Six months on, an auditor asking whether the issuer was authorized at the time of the award gets an answer about today’s register, not about the one you consulted. Fixing content and time at the moment of the check, with a qualified timestamp, is what turns a private recollection into something a third party can examine.

What you check Where you check it What is normally left behind What makes it provable
Issuer authorized in the surety class Supervisory register, live web page A screenshot with no certain date Certified capture of the page, with time of access
Intermediary on the official register Register of intermediaries A note in the file Certified capture of the register entry
Confirmation from the insurer Phone call or email exchange An email in a mailbox Certified email with its attachments
The bond document itself Attachment received from the counterparty A PDF on a shared drive Certified copy of the file as received, with a qualified timestamp
Date of receipt Mail server metadata A date that can be altered Time fixed at capture, independent of your systems

Procurement teams and finance departments use TrueScreen to fix the date and the content of a document at the moment they receive it, before a dispute makes the sequence impossible to reconstruct.

What is at stake for whoever accepts a fake guarantee

The contract loses its security and the file loses its defensibility, in that order. A guarantee the named issuer never underwrote secures nothing: there is no obligation to call, and the exposure it was supposed to neutralize sits with the contracting authority.

Effects on the award and on the contract

Under EU procurement practice a bid guarantee is typically a small percentage of the estimated contract value, and a performance guarantee a larger one. Both are ordinarily issued by banks, by insurers authorized in the surety class, or by supervised financial intermediaries. When the instrument turns out to be counterfeit, the damage runs along two tracks. At bid stage the tenderer’s position is compromised and the award is open to challenge from the competitors ranked behind. During performance the authority discovers, usually at the worst possible moment, that the works or supplies it depends on are unsecured, and that recovering anything means suing the contractor directly. Keeping certified evidence throughout a digital procurement process is what lets the authority show which documents it received, and when, if the award is later contested.

Where responsibility lands when nobody documented the check

On whoever holds the file. Internal audit and external reviewers do not ask whether someone was careful, they ask what the record shows. A verification that produced no artifact is indistinguishable, six months later, from a verification that never happened, and the officer who ran a thorough check with nothing to show for it ends up in the same position as the one who ran none. That is why certifying digital evidence during a tender protects the people running the process, not just the process itself.

What evidence remains of the check you ran on a guarantee

TrueScreen certifies at source the register page you consulted, the document you received and the message that carried it, producing evidence with a qualified timestamp and a digital seal delivered by a QTSP integrated into the platform. Under eIDAS Regulation 910/2014, a qualified electronic timestamp enjoys the presumption of the accuracy of the date and time it indicates and of the integrity of the data linked to it, and a qualified electronic seal enjoys the presumption of integrity and of correct origin. Applied to a surety bond, that fixes three otherwise perishable objects at the moment of the check: the state of the supervisory register on the day you looked, the exact file that reached you, and the transmission it came with. As the Data Authenticity Platform, TrueScreen is built to capture and certify content at the point of acquisition rather than attest to files after the fact.

Take the scenario the alerts describe. A tender office receives a bid guarantee on the closing day, checks the supervisory list of insurers authorized in the surety class, finds the company, accepts the document. Four months later the bond is called, the insurer disowns it, and the contractor insists it transmitted a different and perfectly valid policy. The office has its folder of PDFs and nothing with a certain date: no proof of which file arrived that day, and no way to show what the register displayed when it was consulted.

Run the same day differently and the file looks nothing alike. The register page is captured as it appeared, the incoming policy is certified as received through certified email and attachment capture, and the record joins the tender documentation. The same approach covers the rest of the documentation certified for tenders and contracts and any document received in digital form that someone might later dispute. What the office produces is a dated record of what it was given, rather than an account of how carefully it worked.

Frequently asked questions

How do you spot a fake surety bond?

Not by looking at it. Counterfeit surety bonds reproduce the letterhead, wording and signature blocks of real insurers, and the 2026 IVASS alerts concern documents attributed to companies that are genuinely authorized. Detection comes from independent checks: the supervisory list of insurers authorized in the surety class, the register of intermediaries, and direct confirmation from the insurer on contact details found in the register.

How can you verify that a surety bond is authentic?

Three steps. Confirm the issuer appears on the supervisory list of insurers authorized in the surety class, not merely on the general list of authorized insurers. Confirm the intermediary who placed the bond is on the official register of insurance intermediaries. Then contact the insurer directly, using the contact details published by the supervisor and never those printed on the document you received.

Who is allowed to issue a surety bond?

In EU procurement practice, guarantees are ordinarily issued by banks, by insurance companies authorized in the surety class, or by supervised financial intermediaries. Authorization is class specific: an insurer may be fully authorized and still not write surety business, which is why the general register of authorized insurers does not prove that a given bond could have been issued.

What is the difference between a fake surety bond and an invalid one?

A fake bond was never underwritten by the issuer named on it, so no obligation exists behind the document and there is nothing to call. An invalid bond was genuinely issued by a real insurer but fails a formal or contractual requirement, which in some cases can be corrected. The first is a fraud, the second a defect in an existing guarantee.

How do you keep proof that you verified a surety bond?

By certifying the check while you run it. A screenshot saved in a folder has no certain date and its system metadata can be altered, so it does not establish what a register showed on a given day. To make the check provable you need a certified capture of the register page and of the document received, carrying a qualified timestamp and a digital seal: that is what TrueScreen produces.

What if the other party claims they sent you a different document?

Without a dated record of receipt, the matter reduces to one assertion against another, and the evidential weight of a digital copy in most European jurisdictions falls away once the other side disputes it. Certifying the document and its transmission on arrival, together with the hash that identifies the file, moves the question from who is right to what was delivered.

Certify what you receive, before anyone disputes it

TrueScreen fixes the content and the time of the documents, pages and messages your office receives, so that a check you ran months ago is still something you can show.

Start now
Request a demo

TrueScreen