Document fraud is a supply chain attack and deserves the same defence
Forged certificates enter supply chains through the trusted receiving desk, so the defence is depth of review at the point of entry, on your own hardware, with every decision sealed.

Document fraud should be treated as a supply chain attack because it behaves like one: it enters through a trusted interface, exploits the assumption of good faith at the receiving desk, and propagates downstream into products, aircraft and infrastructure long before anyone notices. Documented cases, from forged aviation release certificates to falsified material test data, show that paperwork is an attack surface. The defence is the one networks learned decades ago, inspection in depth at the boundary, and it is work a sovereign AI system can now do without a single supplier document leaving your building.
Why should we treat document fraud as a supply chain attack?
Because it uses the same mechanics. A supply chain attack succeeds by compromising something you trust and letting your own processes carry it inside. A forged release certificate or falsified test report does exactly that. It arrives attached to a physical part, wearing the format your quality system expects, and your own receiving process escorts it into stores, onto the line or onto the wing. The attacker only needs a plausible document, and the record shows plausible documents pass.
What do the documented cases actually show?
They show fraud passing through professional receiving desks for years. The clearest recent example is AOG Technics, the parts distributor whose forged release certificates moved through the aviation supply chain between 2019 and 2023. AeroTime reported the FAA's September 2023 warning over parts supplied with falsified documents, and Simple Flying put the scale at more than 60,000 parts sold with forged certificates, touching more than 180 engines and grounding aircraft at major carriers. The fraud was not caught by a systematic control. It was caught when one engineer questioned a document's origins. Aviation is not alone. Kobe Steel admitted in 2017 that it had falsified strength and durability data on metal products supplied across the automotive, aerospace and rail industries, which meant downstream material certificates described metal that did not exist as certified.
Why does the receiving desk miss forged paperwork?
Because incoming inspection was designed for error, not adversaries. Most quality systems check that a certificate is present, legible and matches the purchase order, often on a sampling basis, because full depth on every document is beyond human capacity at commercial volume. A competent forger clears that bar easily, because the forger wrote the document to clear it. What the forgery cannot survive is depth: cross referencing against the claimed part history, sister documents from the same batch, prior paperwork from the same supplier, and the internal consistency of dates, signatures and serial numbers. Depth is what a time pressed inspector cannot give every line item, and exactly what a machine can.
What does depth of review at the point of entry look like?
It looks like treating every incoming document package as untrusted until it proves itself. Our document review capability reads the package as it arrives, cross references every certificate against the records behind it, drafts the receiving paperwork for items that reconcile, and holds every anomaly for a person to judge. In practice that means:
- Every certificate checked, not a sample, because machine patience does not run out at line item forty
- Cross referencing against purchase orders, claimed part histories, batch records and prior documents from the same supplier
- Internal consistency checks on dates, serial numbers, signatories and formats, the details forgeries tend to get subtly wrong
- Anomalies held at the receiving desk before the part enters stores, with the discrepancy stated in plain language
- A person, never the machine, deciding the disposition of every held item
- Every review and every decision sealed to a tamper evident record as it happens
Why does this review need to run on our own hardware?
Because the documents involved are among the most sensitive a manufacturer holds. Supplier certificates, part histories and test data describe your supply chain in detail, and in defence and dual use manufacturing they can carry export controlled technical data, which makes uploading them to a third party cloud service a question for your export control officer rather than a default. Mickai is a Sovereign Intelligence Operating System that runs entirely on hardware you own, on premise and air gapped. Nothing leaves the building: not the certificates, not the anomalies, not the questions the review asked. You get the depth of modern AI review without creating a second supply chain exposure in the act of defending against the first.
How does a sealed audit record change the outcome?
It turns receiving decisions into evidence. Every review the system performs and every disposition a person makes is sealed to the Open Audit Record, a cryptographically signed, post quantum, tamper evident record that is written before an action runs and remains verifiable offline years later. When a regulator, a customer or an investigator asks what your receiving desk knew and when, the answer is not a reconstruction. It is the sealed record showing the certificate that arrived, the checks that ran, the anomaly that was held and the person who cleared or rejected it.
“Machines are patient enough to check every certificate against the records behind it. People stay in charge of what happens next, and the record proves both.”
Paperwork fraud will not get harder to commit. Generative tools make plausible documents cheaper to produce every year, and supply chains are getting longer, not shorter. The organisations that stay ahead will stop treating documents as clerical objects and start treating them as an attack surface with a real control at the boundary: every document checked in depth, every anomaly held, every decision sealed. We build for that boundary, on your hardware, inside your walls, because a defence rented from someone else's cloud is one more link in the chain you are trying to secure.
Frequently asked questions
Does AI replace the quality inspector at receiving?
No. The system does the first pass in depth, reading packages and cross referencing certificates. Anomalies are held for the inspector, who keeps disposition and sign off. The machine adds patience and depth, the person keeps judgement and authority.
Can this work with scanned or paper certificates?
Yes. Supplier paperwork arrives in every format, and reading mixed document packages as they actually arrive is the job. The review works from what your receiving desk actually receives, not from an idealised data feed.
Why not use a cloud AI service to check certificates?
Because supplier documents are commercially sensitive and can carry export controlled technical data. Sending them to a third party service creates a new exposure while addressing an old one. On premise, air gapped review keeps every document inside your estate.
What happens when a certificate fails cross referencing?
The item is held before it enters stores, the discrepancy is described in plain language, and a person decides what happens next. The hold, the reasoning and the disposition are all sealed to the Open Audit Record, so the decision is provable long after the moment has passed.
Is document fraud really common enough to justify this?
The documented cases suggest that discovered fraud understates the problem. The AOG Technics forgeries circulated from 2019 to 2023 before one engineer's question unravelled them, and the falsified data Kobe Steel admitted to persisted across years and product lines. Controls that assume fraud is rare tend to find out otherwise late.
What is MICKAI?
MICKAI is a Sovereign Intelligence Operating System, a SIOS, that runs on the customer's own hardware, on premise and air gapped. Every consequential action is sealed to the Open Audit Record, a cryptographically signed, post quantum, tamper evident record verifiable offline, before that action runs. Mickai comprises 87 studios, with ten production ready at launch and 77 in development, and is protected by 104 filed UK patent applications across 2,340 claims, filed rather than granted.