
Every passport, diploma, or professional licence is only as trustworthy as the birth certificate, marriage certificate, or civil registration entry it was built on. If that first document, the breeder document, is forged, every later verification inherits the lie, and border checks that inspect only the document in front of them cannot see it. Regulation is now closing this gap by requiring verification at the moment a document is issued, as seen in eIDAS 2.0. TRUE anchors authenticity at that first, foundational document, so trust does not depend on catching a forgery years later.
The first document is the most dangerous one because every document issued after it inherits its truth or its lie, and nobody checks it again once later documents exist. A forged birth certificate or driver's licence can produce a completely genuine passport, since the passport office trusts the document used to apply for it. Once that first document passes, the forgery becomes invisible, carried forward inside a document that is authentic in every physical sense.
In an undercover test, investigators from the U.S. Government Accountability Office set out to obtain passports under false identities. They did not forge the passports. They forged the documents behind them: counterfeit birth certificates and fake driver's licences. It was enough. The passport office issued five of the seven genuine U.S. passports they applied for. (GAO-10-922T)
Read that again. The passports were real. Issued by the state, printed on real stock, with every security feature intact. The lie was one layer down, in the paperwork nobody looked at closely.
This is the breeder document problem, and it is the single most important idea in identity security that almost no one outside the field talks about.
A breeder document is a foundational record used to establish who you are so you can obtain something of higher value: a birth certificate, a marriage certificate, a civil registration entry. From that first document flows a chain. The birth certificate gets you a national ID. The ID gets you a passport. The passport gets you a bank account, a residence permit, a professional licence, a loan.
Each link in that chain is verified against the link before it. Which means the entire chain inherits the trust of the very first document. Secure that first link and the chain holds. Compromise it, and every genuine document built on top carries a lie forward, silently.
The European Commission put it plainly. Obtaining authentic documents on the basis of false breeder documents, it wrote, remains one of the biggest threats in document fraud, because it is very difficult to detect. Authentic documents established on a false identity are very hard to catch at a border crossing or inside a country. (COM(2016)790)
Verifying documents later does not work because inspection only examines the physical document in front of the officer, not the paperwork used to obtain it years earlier. A forged birth certificate can produce a passport that is genuine in every physical sense, so no amount of scrutiny at the border reveals that its origin was false. The only way to catch the problem is to verify the source document at the moment it is issued, not the document built on top of it later.
The instinct is to inspect harder at the border. That is where most of the world's effort goes today. Interpol and Frontex run a shared system called FIELDS, launched in 2022, that gives border officers Quick Check Cards showing the security features to look for on a travel document. (Interpol)
This is good work, and it catches crude forgeries. But look at what it actually does: it inspects the physical document in front of the officer. It cannot see that a genuine passport was issued on a fake birth certificate three years earlier. You cannot inspect your way out of a document that is authentic in every physical sense and false only in its origin.
Document and identity fraud is not a niche problem. Europol calls it an enabler for most serious and organised crime. In 2023 alone, Frontex reported more than 22,000 fraudulent documents detected at Europe's borders. And detection is, by definition, only the fraud that got caught.
The two approaches, side by side:
| Dimension | Checking after the fact (today) | Authenticity at the source (eIDAS 2.0) |
|---|---|---|
| When the check happens | At the border or on receipt, often years after issuance | At issuance, once |
| What gets checked | The document's physical security features | Who issued it, and that nothing has changed |
| Catches a forged breeder document | No, the document on top is genuine in every respect | Yes, the chain breaks at the source |
| Who can check | A trained officer with the right equipment | Anyone, in seconds |
| Example | FIELDS Quick Check Cards (Interpol/Frontex) | Trusted issuers, eIDAS 2.0 Art. 45e/45f |
Sweden's 2021 Skatteverket pilot on strategic addresses found around 500 addresses linked to undeclared work, money laundering, tax crime, fraud, and sham marriages, covering more than 1,500 people and turning up 150 suspected cases of exploited identities. Because Swedish identity runs through the folkbokföring population register rather than a birth certificate, that register is itself the first document in the chain, and it has already shown signs of exploitation at scale.
Sweden feels insulated from this because identity here runs through folkbokföring, the population register, rather than a physical birth certificate. But the register is exactly the first link in the chain, and the Swedish Tax Agency has been sounding the alarm about it.
In 2021, Skatteverket ran pilot controls on what it called strategic addresses. The findings were stark: around 500 addresses tied to undeclared work, money laundering, tax crime, fraud and sham marriages. The investigations covered 675 people registered with personal identity numbers and 904 with coordination numbers, and turned up 150 suspected cases of exploited identities. The agency's own conclusion was direct: secure and unique identities are necessary, and the question of biometric data tied to identity must be examined without delay. (Skatteverket, Strategiska adresser)
That conclusion set off a wave of legislation that is still moving. A government inquiry on population registration and coordination numbers (SOU 2021:57). A mandate to examine whether the Tax Agency may store biometric data to stop one person from holding several registered identities (dir. 2023:134, later SOU 2025:75). A proposed new criminal offence targeting the trade in false addresses that feed the register. And in April 2026, a proposal that the Tax Agency and the Migration Agency be allowed to collect and store fingerprints and facial images during identity checks, to prevent a single person from being registered under multiple identities. (regeringen.se)
Every one of these measures is aimed at the same thing: making the first document, the register entry itself, trustworthy at the point it is created. Sweden is converging on the breeder document insight from its own hard experience.
Under the EU's eIDAS 2.0 regulation, trusted issuers must sign digital identities and documents cryptographically at the moment of issuance, and Article 45e and Article 45f require verification against authentic public sources instead of inspection after the fact. The regulation entered into force in May 2024, making verification at the source a legal requirement across the EU, not just a best practice.
Here is what makes this the right moment rather than an abstract worry. The regulatory direction in Europe has already turned toward securing authenticity at the source.
The EU Digital Identity Framework Regulation, eIDAS 2.0, entered into force in May 2024. Under it, trusted issuers, public or private, sign digital identity and digital documents cryptographically straight into a citizen's wallet. Authenticity is established at the moment of issuance, not reconstructed later by a border officer with a magnifying glass. Trust lists tell any relying party which issuers are genuine, and issuers can verify each wallet they interact with. (European Commission, Wallet for Issuers)
The regulation goes further and makes verification at the source a legal requirement. Article 45e requires member states to let qualified providers verify attributes against authentic public sources. Article 45f requires public bodies that hold those authentic sources to provide an interface to the wallets. (Regulation (EU) 2024/1183). The same qualified-trust machinery is what makes a qualified electronic seal or timestamp legally recognized EU-wide in the first place.
The principle that a document should prove its own authenticity from birth, rather than be judged genuine or fake years later, is no longer a philosophy. It is becoming European law.
The lesson from the GAO test, from the European Commission, from Skatteverket's own files, and now from eIDAS 2.0 all point the same way. You do not defend a chain of documents by inspecting the last link harder. You defend it by making the first link impossible to forge, and provable as genuine by anyone, at any time, without having to trust the piece of paper in front of them.
That is the model TRUE is built for: authenticity anchored at the source, at the moment a document is issued, carried forward so every document downstream can prove where it truly came from. Secure the first document, and you secure the whole chain. See how TRUE anchors authenticity at the source.
A breeder document is a foundational record used to establish someone's identity so they can obtain something of higher value: a birth certificate, a marriage certificate, or a civil registration entry. From that first document a chain follows: it gets you a national ID, the ID gets you a passport, and the passport gets you a bank account, a residence permit, a professional licence, or a loan. Each later document is only as trustworthy as the breeder document it was verified against.
Border inspection, including systems like Interpol and Frontex's FIELDS with its Quick Check Cards, examines the physical document in front of the officer: its printing, security features, and layout. It cannot see that a genuine passport was issued years earlier on a fake birth certificate or driver's licence. A document that is authentic in every physical sense but false only in its origin passes inspection every time.
In a GAO undercover test, investigators used counterfeit birth certificates and driver's licences to apply for U.S. passports under false identities, and five of the seven genuine passports were issued. The European Commission has called obtaining authentic documents on the basis of false breeder documents one of the biggest threats in document fraud, because it is very difficult to detect. Frontex reported more than 22,000 fraudulent documents detected at Europe's borders in 2023 alone, and detection only counts the fraud that got caught.
Skatteverket's 2021 pilot controls on strategic addresses found around 500 addresses tied to undeclared work, money laundering, tax crime, fraud, and sham marriages, covering 675 people with personal identity numbers and 904 with coordination numbers, with 150 suspected cases of exploited identities. That finding set off a wave of legislation, including a government inquiry on population registration and coordination numbers (SOU 2021:57), a mandate to examine biometric data storage to stop multiple registered identities (dir. 2023:134, later SOU 2025:75), a proposed new criminal offence against trading false addresses, and an April 2026 proposal letting the Tax Agency and Migration Agency collect fingerprints and facial images during identity checks.
eIDAS 2.0, the EU Digital Identity Framework Regulation, entered into force in May 2024. It has trusted issuers sign digital identity and documents cryptographically into a citizen's wallet at the moment of issuance, with trust lists showing which issuers are genuine. Article 45e requires member states to let qualified providers verify attributes against authentic public sources, and Article 45f requires the bodies holding those sources to provide an interface to the wallets. Verification at the source, rather than inspection years later, is becoming a legal requirement across the EU.
Save time, increase traffic and insights and build trust, by upgrading to blockchain secured diplomas and course certificates, which are loved by recipients and always verifiably authentic.
Book a demoNot sure where to start? Let us help!

Trusted by leading organisations worldwide