A chain of trust is only as strong as its first document

Every passport, every diploma, every licence rests on an earlier document. If the first one is fake, everything built on top of it is fake too, and almost impossible to catch after the fact. The answer is to secure the document at the moment it is created.
Illustration of a chain of linked documents, from a bright, sealed origin document fading through progressively fainter identity documents, showing how trust in the first document carries through every document issued afterward
August 3, 2025

TL;DR

Every passport, diploma, or professional licence is only as trustworthy as the birth certificate, marriage certificate, or civil registration entry it was built on. If that first document, the breeder document, is forged, every later verification inherits the lie, and border checks that inspect only the document in front of them cannot see it. Regulation is now closing this gap by requiring verification at the moment a document is issued, as seen in eIDAS 2.0. TRUE anchors authenticity at that first, foundational document, so trust does not depend on catching a forgery years later.

Why is the first document the most dangerous one?

The first document is the most dangerous one because every document issued after it inherits its truth or its lie, and nobody checks it again once later documents exist. A forged birth certificate or driver's licence can produce a completely genuine passport, since the passport office trusts the document used to apply for it. Once that first document passes, the forgery becomes invisible, carried forward inside a document that is authentic in every physical sense.

In an undercover test, investigators from the U.S. Government Accountability Office set out to obtain passports under false identities. They did not forge the passports. They forged the documents behind them: counterfeit birth certificates and fake driver's licences. It was enough. The passport office issued five of the seven genuine U.S. passports they applied for. (GAO-10-922T)

Read that again. The passports were real. Issued by the state, printed on real stock, with every security feature intact. The lie was one layer down, in the paperwork nobody looked at closely.

This is the breeder document problem, and it is the single most important idea in identity security that almost no one outside the field talks about.

What is a breeder document?

A breeder document is a foundational record used to establish who you are so you can obtain something of higher value: a birth certificate, a marriage certificate, a civil registration entry. From that first document flows a chain. The birth certificate gets you a national ID. The ID gets you a passport. The passport gets you a bank account, a residence permit, a professional licence, a loan.

Each link in that chain is verified against the link before it. Which means the entire chain inherits the trust of the very first document. Secure that first link and the chain holds. Compromise it, and every genuine document built on top carries a lie forward, silently.

The European Commission put it plainly. Obtaining authentic documents on the basis of false breeder documents, it wrote, remains one of the biggest threats in document fraud, because it is very difficult to detect. Authentic documents established on a false identity are very hard to catch at a border crossing or inside a country. (COM(2016)790)

Why does verifying documents later not work?

Verifying documents later does not work because inspection only examines the physical document in front of the officer, not the paperwork used to obtain it years earlier. A forged birth certificate can produce a passport that is genuine in every physical sense, so no amount of scrutiny at the border reveals that its origin was false. The only way to catch the problem is to verify the source document at the moment it is issued, not the document built on top of it later.

The instinct is to inspect harder at the border. That is where most of the world's effort goes today. Interpol and Frontex run a shared system called FIELDS, launched in 2022, that gives border officers Quick Check Cards showing the security features to look for on a travel document. (Interpol)

This is good work, and it catches crude forgeries. But look at what it actually does: it inspects the physical document in front of the officer. It cannot see that a genuine passport was issued on a fake birth certificate three years earlier. You cannot inspect your way out of a document that is authentic in every physical sense and false only in its origin.

Document and identity fraud is not a niche problem. Europol calls it an enabler for most serious and organised crime. In 2023 alone, Frontex reported more than 22,000 fraudulent documents detected at Europe's borders. And detection is, by definition, only the fraud that got caught.

The two approaches, side by side:

DimensionChecking after the fact (today)Authenticity at the source (eIDAS 2.0)
When the check happensAt the border or on receipt, often years after issuanceAt issuance, once
What gets checkedThe document's physical security featuresWho issued it, and that nothing has changed
Catches a forged breeder documentNo, the document on top is genuine in every respectYes, the chain breaks at the source
Who can checkA trained officer with the right equipmentAnyone, in seconds
ExampleFIELDS Quick Check Cards (Interpol/Frontex)Trusted issuers, eIDAS 2.0 Art. 45e/45f

How big is the problem in Sweden?

Sweden's 2021 Skatteverket pilot on strategic addresses found around 500 addresses linked to undeclared work, money laundering, tax crime, fraud, and sham marriages, covering more than 1,500 people and turning up 150 suspected cases of exploited identities. Because Swedish identity runs through the folkbokföring population register rather than a birth certificate, that register is itself the first document in the chain, and it has already shown signs of exploitation at scale.

Sweden feels insulated from this because identity here runs through folkbokföring, the population register, rather than a physical birth certificate. But the register is exactly the first link in the chain, and the Swedish Tax Agency has been sounding the alarm about it.

In 2021, Skatteverket ran pilot controls on what it called strategic addresses. The findings were stark: around 500 addresses tied to undeclared work, money laundering, tax crime, fraud and sham marriages. The investigations covered 675 people registered with personal identity numbers and 904 with coordination numbers, and turned up 150 suspected cases of exploited identities. The agency's own conclusion was direct: secure and unique identities are necessary, and the question of biometric data tied to identity must be examined without delay. (Skatteverket, Strategiska adresser)

That conclusion set off a wave of legislation that is still moving. A government inquiry on population registration and coordination numbers (SOU 2021:57). A mandate to examine whether the Tax Agency may store biometric data to stop one person from holding several registered identities (dir. 2023:134, later SOU 2025:75). A proposed new criminal offence targeting the trade in false addresses that feed the register. And in April 2026, a proposal that the Tax Agency and the Migration Agency be allowed to collect and store fingerprints and facial images during identity checks, to prevent a single person from being registered under multiple identities. (regeringen.se)

Every one of these measures is aimed at the same thing: making the first document, the register entry itself, trustworthy at the point it is created. Sweden is converging on the breeder document insight from its own hard experience.

What does the law say about document verification?

Under the EU's eIDAS 2.0 regulation, trusted issuers must sign digital identities and documents cryptographically at the moment of issuance, and Article 45e and Article 45f require verification against authentic public sources instead of inspection after the fact. The regulation entered into force in May 2024, making verification at the source a legal requirement across the EU, not just a best practice.

Here is what makes this the right moment rather than an abstract worry. The regulatory direction in Europe has already turned toward securing authenticity at the source.

The EU Digital Identity Framework Regulation, eIDAS 2.0, entered into force in May 2024. Under it, trusted issuers, public or private, sign digital identity and digital documents cryptographically straight into a citizen's wallet. Authenticity is established at the moment of issuance, not reconstructed later by a border officer with a magnifying glass. Trust lists tell any relying party which issuers are genuine, and issuers can verify each wallet they interact with. (European Commission, Wallet for Issuers)

The regulation goes further and makes verification at the source a legal requirement. Article 45e requires member states to let qualified providers verify attributes against authentic public sources. Article 45f requires public bodies that hold those authentic sources to provide an interface to the wallets. (Regulation (EU) 2024/1183). The same qualified-trust machinery is what makes a qualified electronic seal or timestamp legally recognized EU-wide in the first place.

The principle that a document should prove its own authenticity from birth, rather than be judged genuine or fake years later, is no longer a philosophy. It is becoming European law.

How do you secure the first link in the chain?

The lesson from the GAO test, from the European Commission, from Skatteverket's own files, and now from eIDAS 2.0 all point the same way. You do not defend a chain of documents by inspecting the last link harder. You defend it by making the first link impossible to forge, and provable as genuine by anyone, at any time, without having to trust the piece of paper in front of them.

That is the model TRUE is built for: authenticity anchored at the source, at the moment a document is issued, carried forward so every document downstream can prove where it truly came from. Secure the first document, and you secure the whole chain. See how TRUE anchors authenticity at the source.

Frequently asked questions

What is a breeder document?

A breeder document is a foundational record used to establish someone's identity so they can obtain something of higher value: a birth certificate, a marriage certificate, or a civil registration entry. From that first document a chain follows: it gets you a national ID, the ID gets you a passport, and the passport gets you a bank account, a residence permit, a professional licence, or a loan. Each later document is only as trustworthy as the breeder document it was verified against.

Why can't border checks catch a fake breeder document?

Border inspection, including systems like Interpol and Frontex's FIELDS with its Quick Check Cards, examines the physical document in front of the officer: its printing, security features, and layout. It cannot see that a genuine passport was issued years earlier on a fake birth certificate or driver's licence. A document that is authentic in every physical sense but false only in its origin passes inspection every time.

How big is the breeder document problem, really?

In a GAO undercover test, investigators used counterfeit birth certificates and driver's licences to apply for U.S. passports under false identities, and five of the seven genuine passports were issued. The European Commission has called obtaining authentic documents on the basis of false breeder documents one of the biggest threats in document fraud, because it is very difficult to detect. Frontex reported more than 22,000 fraudulent documents detected at Europe's borders in 2023 alone, and detection only counts the fraud that got caught.

What is Sweden doing about breeder document fraud?

Skatteverket's 2021 pilot controls on strategic addresses found around 500 addresses tied to undeclared work, money laundering, tax crime, fraud, and sham marriages, covering 675 people with personal identity numbers and 904 with coordination numbers, with 150 suspected cases of exploited identities. That finding set off a wave of legislation, including a government inquiry on population registration and coordination numbers (SOU 2021:57), a mandate to examine biometric data storage to stop multiple registered identities (dir. 2023:134, later SOU 2025:75), a proposed new criminal offence against trading false addresses, and an April 2026 proposal letting the Tax Agency and Migration Agency collect fingerprints and facial images during identity checks.

How does eIDAS 2.0 change this?

eIDAS 2.0, the EU Digital Identity Framework Regulation, entered into force in May 2024. It has trusted issuers sign digital identity and documents cryptographically into a citizen's wallet at the moment of issuance, with trust lists showing which issuers are genuine. Article 45e requires member states to let qualified providers verify attributes against authentic public sources, and Article 45f requires the bodies holding those sources to provide an interface to the wallets. Verification at the source, rather than inspection years later, is becoming a legal requirement across the EU.

Sources

  • U.S. GAO, GAO-10-922T, passport fraud undercover test (five of seven genuine passports issued on counterfeit breeder documents).
  • European Commission, COM(2016)790, Action Plan on travel document fraud ("one of the biggest threats... very difficult to detect").
  • Interpol / Frontex, FIELDS document system and Quick Check Cards (launched 2022).
  • Europol, SOCTA 2021 (document fraud as an enabler of organised crime); Frontex document fraud figures, 2023.
  • Skatteverket, Strategiska adresser pilot controls, 2021 (500 addresses, 675 personal ID numbers, 904 coordination numbers, 150 suspected exploited identities).
  • Swedish government: SOU 2021:57; dir. 2023:134; SOU 2025:75; government proposals, 2025-2026 (new folkbokföring offence, biometric storage).
  • European Commission, EU Digital Identity Wallet "Wallet for Issuers"; Regulation (EU) 2024/1183 (eIDAS 2.0), Articles 45e and 45f.

Get started with TRUE

Save time, increase traffic and insights and build trust, by upgrading to blockchain secured diplomas and course certificates, which are loved by recipients and always verifiably authentic.

Book a demo

More insights

Not sure where to start? Let us help!

You have questions, we have answers. Fill out the form to speak to our experts.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Hand holding smartphone with glowing floating digital document overlay symbolizing mobile document verification against blurred background

Trusted by leading organisations worldwide