Self-Employed Income Fraud: Altered 1099s & P&L Statements

This article is a snapshot – content was accurate as of September 2026 (code examples tested against the API as of September 2026). The product evolves actively; specific counts, examples, and detection rules may have changed since publication – see the changelog for the current state.
A W-2 borrower’s income file has a spine running through it. There is an employer who can be phoned, a payroll platform that issued the paystub, a Verification of Employment the employer fills in, and an IRS record of the same wages filed by somebody other than the applicant.
A self-employed borrower’s file has none of that spine. There is no employer to call because the applicant is the employer. There is no payroll platform because the pay is a transfer between accounts. And the central income document – the profit and loss statement – is one the applicant wrote themselves, which is the documented, guideline-sanctioned way the file is supposed to work.
That is an awkward problem for anyone adding a document-integrity layer to underwriting: self-employed files are where document evidence carries the most weight, and where a naive file check produces the worst answers. Below: which documents a structural check can speak to, which ones it cannot, and how to route the results without treating every sole trader as a suspect.
What a Self-Employed Income File Is Made Of
Start with what the guidelines require, because the received wisdom that self-employed borrowers get less scrutiny is wrong. They get more.
Under Fannie Mae’s self-employed borrower standards (Selling Guide B3-3.2-01), the lender generally obtains a two-year history of prior earnings. A single year of returns is permitted only in a narrow case – the business has existed for five years, the borrower has held 25% or more ownership throughout, and the lender completes a cash flow analysis on Form 1084 or equivalent, with the five-year existence documented from an independent source such as an EIN confirmation letter, a business licence or articles of incorporation.
Other controls sit alongside the returns. The lender must verify, within 120 calendar days prior to the note date (B3-3.1-07), that the business exists – from a third party such as a CPA, a regulatory agency or the applicable licensing bureau, or by verifying a phone listing and address – and document the source. Where business assets fund the down payment or reserves, a business cash flow analysis is required. And the income analysis has to be written up using Form 1084; the lender may support the year-over-year trend with Form 1088, the Income Calculator, or any other method applying the same principles.
Then there is the profit and loss statement. Fannie Mae’s guidance on analysing P&L statements (B3-3.7-04) is explicit that the lender may use a P&L ‘audited or unaudited,’ and that a typical one has a format similar to Schedule C. A year-to-date statement is not universally required; it becomes a live question when the loan application is dated more than 120 days after the end of the business’s tax year, where the lender may choose to require one.
The whole routing problem hangs on that sentence. The guideline expressly contemplates an unaudited P&L. In practice that means a document the borrower produced in a spreadsheet, exported from bookkeeping software, or typed into a word processor. That is the sanctioned artefact.
The non-agency world leans harder still. Bank-statement loan programmes underwrite self-employed applicants on twelve or twenty-four months of deposits precisely because taxable income after allowable business deductions often understates the cash flow available to service a loan. There the borrower-supplied statement is not a supporting exhibit – it is the qualifying evidence.
Guideline citations here reflect the Fannie Mae Selling Guide and IRS guidance as published in August 2026; confirm against the current edition before relying on them.
Two Documents, Two Completely Different Provenances
A self-employed income file mixes two categories of document that look similar on screen and are forensically nothing alike.
Third-party issued. A 1099-NEC, 1099-MISC or 1099-K is produced by the payer, not the applicant. A platform, a client or a payment processor generated it, filed a copy with the IRS and sent one to the recipient. Business bank statements are the same class: a bank produced them. So are the CPA-prepared returns, the EIN letter, the invoices a client issued. Each has an issuing party with its own document pipeline, and therefore a baseline of what its files normally look like.
Self-authored. A P&L statement. A borrower-prepared income summary. A bookkeeping export. An engagement letter the applicant drafted. There is no issuer other than the applicant, and no external pipeline to compare against – because the applicant’s own laptop is the pipeline.
The distinction matters because a document-integrity check is an argument about provenance: whether a file bears structural evidence of having been written to after it was generated, and whether its origin matches what the document claims to be. On the second category, half of that collapses: a document with no issuer cannot deviate from an issuer’s baseline.
Any framing that skips this distinction and treats ‘self-employed income documents’ as one bucket will be wrong about roughly half the file.
Where the IRS Cross-Check Runs Out
The strongest control on the 1099 side is the one that goes around the applicant entirely. Form 4506-C authorises an Income Verification Express Service participant to pull transcripts straight from the IRS, and the wage and income transcript it produces shows data from information returns including the 1099 series. When that transcript comes back showing the same totals the applicant supplied, the income is corroborated by a party the applicant never touched. Where the path is open, use it. That path has a hard boundary, and on self-employed files it bites unusually deep.
Information return data for a tax year generally does not appear on the IRS record until the following calendar year, once payers have filed, and the record is not complete the moment filing season opens – it fills in over the months that follow. A 1099 issued for the year in progress is not on the record at all, and neither is the return that would report it. For a salaried applicant that matters less: a VOE reaches the employer directly and the pay is regular enough to project. For an applicant whose income is a stack of client payments across the current year, the documents describing that income are the only evidence of it.
The transcript has a second ceiling: the IRS caps how many income documents it carries and warns that it may not reflect every information return issued to a taxpayer – a real limit for someone with many payers, the ordinary shape of gig income. An IVES request also takes time to come back, and pre-approvals get issued in that window on the documents already in hand.
So the third-party side has a strong control with a coverage hole over current-year income. The self-authored side has no equivalent control at all, because there is no third party to ask.
What a Structural Check Actually Reads
A PDF carries an internal account of its own assembly – which software wrote it, how many times it has been written to, whether a signature covers the bytes, whether pages arrived from different sources. Editing a genuine file and saving it generally leaves traces there, independent of whether the visible numbers reconcile.
Reconciliation is what a careful forger optimises for. Someone editing a 1099 knows the file will be read against the P&L, the bank deposits and the application, and can make the arithmetic agree across all of it. What they are not editing is the file’s own record of its assembly – that record is not on the page.
HTPBE? reads that structure and returns one of three verdicts.
intact — no structural evidence of post-creation modification, with an origin consistent with an institutional export. This is the absence of evidence of change.
modified — the file carries structural evidence of having been written to after it was first generated. Named modification markers describe what was found. On income documents the ones that matter most are HTPBE_EDITING_TOOL_FINGERPRINT (traces of a known PDF editing tool on a document that should not have passed through one), HTPBE_MULTIPLE_REVISION_LAYERS (the document carries revision layers added after it was created), HTPBE_DATES_DISAGREE (the file’s own timestamps do not agree) and HTPBE_CHARACTER_OVERLAY_EDIT (targeted character-level overlays added by a desktop editor).
inconclusive — the file’s origin is consumer software, an online editor or a scanner, leaving no institutional baseline to check integrity against. This is a statement about origin, not a failure to analyse.
The Routing Problem, Stated Honestly
Here is where a self-employed file breaks a workflow designed around W-2 documents.
A self-prepared P&L should typically come back inconclusive, and that is the correct answer. It was written in a spreadsheet or a bookkeeping tool by the applicant, and consumer software is what the guideline permits. An inconclusive verdict there tells you nothing about the applicant – it restates a format you already knew about.
If you route inconclusive to enhanced review, and self-employed files generate inconclusive more often than W-2 files purely because of their document mix, you have built a system that flags people for being self-employed. That is a bad outcome on every axis: it is unfair, it buries reviewers in noise that resolves to nothing, and after a few weeks of empty escalations the team stops trusting the signal for the files where it does mean something.
The rule that makes this work is that a verdict is only interpretable against the document’s claimed source.
| Document | Claimed source | inconclusive means |
|---|---|---|
| Borrower-prepared P&L | The applicant | Expected. The format, restated. No signal. |
| Bookkeeping-software income summary | The applicant’s tool | Expected. No signal. |
| P&L presented as CPA-prepared | A firm, but no pipeline | Expected. Confirm the preparer by other means; the verdict cannot speak to it. |
| 1099 issued by a platform or payer | A third-party payer | Worth a question. It should have an issuer’s pipeline behind it. |
| Business bank statement | A bank | Worth a question. Resolve it with an issuer-direct download. |
| CPA-prepared return, transcript copy | A firm or the IRS | Worth a question. |
On the bottom three rows, an inconclusive verdict is a reason to ask for a copy pulled directly from the issuer’s portal, or to order the 4506-C the document was standing in for. Note the CPA-prepared P&L row: a statement prepared by an accountant has a claimed third-party preparer but no institutional pipeline behind it, because the accountant’s desktop is a desktop. Scanning is likewise a common innocent explanation for an inconclusive verdict on a bank statement – resolve it with the issuer-direct file rather than the applicant’s account of how they handled it.
modified behaves differently. Structural evidence that a file was written to after it was generated is meaningful on a third-party document – a 1099 edited after the payer produced it is the same finding it would be on any file. On a self-authored P&L it is weaker: an author editing and re-saving their own statement is a normal thing to do.
One thing worth saying plainly, because the vertical invites the opposite framing. Nothing here says self-employed applicants are more likely to commit fraud, and we have no data that would support such a claim. What is true is narrower and purely mechanical: the automated verification paths that remove the document from the process cover self-employed income badly, so more of these files come down to what the applicant uploaded. That is a statement about the coverage of verification infrastructure, not about the people it fails to cover.
What This Layer Cannot Do
Three limits.
It cannot see a fabricated P&L. A P&L typed from scratch with invented revenue has no modification event to find, because structurally nothing happened to it. It is an honestly produced file containing dishonest numbers. That case belongs to the controls built for it: the business bank statements the revenue should appear in, the deposit analysis, the Form 1084 cash flow work, the verification that the business exists at all. A structural check contributes nothing there.
It says nothing about whether numbers are true. An intact verdict on a 1099 means only that the file shows no evidence of post-creation change. The payer could have issued it for the wrong amount, or a friendly client could have issued a real 1099 for work never done. Content review and source verification stay in the process.
It is not a decision about a person. A verdict is a reason to go back to the source – request the document from the issuing platform, order the transcript, escalate to someone who will. It should not by itself decline an application, and it does not verify identity, confirm that a business is real, or satisfy any agency documentation requirement.
Wiring It Into a Self-Employed File Review
For a one-off document, the file is all that is needed. Register and upload a 1099 or a business statement for a verdict in a few seconds; new accounts come with five checks, after which it is pay-per-check.
At origination volume it belongs at intake, before a human reads anything. The integration is two calls against the API: one to submit the document URL, one to fetch the verdict and named modification markers as structured data. A test key returns deterministic synthetic results for a fixed set of test URLs, so you can build and regression-test the routing logic below before spending a credit.
Route on document type, not on verdict alone:
- Tag each document on the way in as third-party-issued or self-authored. This is the field that makes the rest work, and your document taxonomy usually implies it already.
modifiedon a third-party document → manual review, plus a request for a fresh copy from the issuing platform or bank. This is the case the layer exists for.modifiedon a self-authored document → note it against the file; do not escalate on it alone.inconclusiveon a self-authored document → record it and move on. Do not surface it. This single decision determines whether the layer is useful or hated.inconclusiveon a third-party document → ask for the issuer-direct copy, or order the 4506-C.intact→ continue to the cash flow analysis, deposit review and business verification, which are doing the work this layer does not.- A human makes the credit decision. Where a document finding contributes to adverse action, the reasons given must be the lender’s own verified findings, not a verdict string – and the applicant must be able to supply a replacement document from the issuer and have it re-reviewed.
The lender, not a vendor, is the creditor for ECOA and Regulation B purposes. Any routing scheme built on document-type tagging should be tested and monitored by the lender for disparate impact on a prohibited basis; nothing here substitutes for that testing.
Keep the check identifier against the loan record so the outcome is retrievable if the decision is ever reviewed. The document-type walkthrough for the 1099 itself is on the fake 1099 detection page, and the adjacent income-document cases are covered in altered paystubs and W-2s and fake tax return and transcript fraud. What the third verdict means in general is unpacked in what inconclusive actually means.
Self-employed underwriting is not short of diligence – it has more required documents, more analysis forms and more independent verification steps than a salaried file. What it is short of is any control reaching past the applicant’s uploaded PDF to the party that issued it – for the current tax year that party either cannot be reached yet, or does not exist separately from the applicant. On the documents that do have an issuer, asking whether the file is the one that issuer produced is a cheap question with a real answer. On the ones that do not, the honest thing is to say so and leave them alone.