← Back to blog
Business & Legal

CPR 32.19: What UK Courts Require to Prove a Document Is Authentic

By Provlyn·17 July 2026

When a document’s authenticity is challenged in UK court proceedings, the party relying on it must prove document authenticity to the court’s standard. Under CPR 32.19 of the Civil Procedure Rules, that standard is strict — and the evidence most businesses assume will be sufficient routinely falls short. Provlyn provides the independent, cryptographically anchored record that meets that standard. This post explains what the law requires, where standard document exchange falls short, and what an evidential record that holds up in court looks like.

Document Authenticity Disputes in UK Commercial Litigation

Document authenticity is a recurring issue in UK commercial litigation, and the stakes when it arises are high. Fieldfisher and iDS Europe noted in 2023 an increase in reliance on potentially false, fabricated, or doctored evidence in legal proceedings. The cases reaching the courts illustrate the point.

In Foglia v Family Officer Ltd [2021] EWHC 650 (Comm), fraudulent documents were used to procure the transfer of €15 million of a claimant’s offshore funds to the first defendant. The Commercial Court’s asset-tracing powers enabled recovery of €11.5 million relatively quickly, with summary judgment awarded for the remainder. The case is not a story of irreversible loss — the claimant largely prevailed — but it illustrates the scale of financial harm that disputed document authenticity can generate in commercial proceedings, and the forensic and legal resources required to address the dispute.

In 44 Wellfit Street Ltd v GMR Services Ltd [2017] EWHC 1841 (Ch), a disputed lease and option to purchase a commercial property involved competing versions of the same documents. The claimant served notices under CPR 32.19 in respect of the documents it wished to challenge. Because the defendant served no corresponding Notice to Prove, it was deemed to have admitted the authenticity of the claimant’s versions — so where competing versions of the same documents existed, the claimant’s were treated as authentic by default. The underlying case involved detailed forensic scrutiny of signatures, handwriting, and metadata, and the court found evidence of falsification. CPR 32.19 did not replace that scrutiny, but it determined which version each party bore the burden of proving.

The question these cases raise for any business that exchanges documents is straightforward: if the authenticity of a document you sent were challenged in proceedings, what independent evidence would you have that the version being relied upon is exactly the version that existed at the moment of exchange? Provlyn was built to answer that question before it arises — by creating a cryptographic record of any document at the moment of exchange, independently anchored and admissible in UK and EU jurisdictions.

What CPR 32.19 Requires and Why Standard Document Exchange Cannot Meet It

Under CPR 32.19, a party that receives a disclosed document is deemed to admit its authenticity unless they serve a formal Notice to Prove within the required timeframe. If they do serve that notice, the burden falls on the disclosing party to prove the document’s authenticity at trial — not merely its existence, but that it is the specific version being relied upon, in the form it was in, at the time it is said to have existed.

Standard document exchange does not produce that proof. An email attachment establishes that something was sent. It does not establish that the version now being relied upon is the one that was sent. Email metadata is editable. PDF properties can be altered. File system timestamps reflect activity on a specific device and can be changed by editing system settings or transferring a file to a different machine. A party’s own records are produced and held by the party with an interest in the outcome — courts treat them as partisan rather than independent.

In McGann v Bisping [2017] EWHC 2951 (Comm), drawing on Mumford v HMRC [2017] UKFTT 19 (TC), the trial judge confirmed that a party wishing to challenge a document’s authenticity cannot do so merely by pleading it in a Statement of Case — they must serve a formal Notice to Prove within the required timeframe. The obligation falls on the challenger to take the procedural step, not on the disclosing party to volunteer proof. The evidential consequence of that step is illustrated by 44 Wellfit Street itself: the Master found that the defendant’s version of the disputed emails had been tampered with, noting that the defendant had made no real effort to provide any metadata for them, while the claimant had offered access to its emails in native form so that the metadata could be checked. The absence of verifiable metadata on the defendant’s documents was the deciding factor.

What You Need to Prove Document Authenticity in a Dispute

CPR 32.19 imposes an evidential standard with three properties. The record must be independent — created by a third party with no stake in the outcome. It must be contemporaneous — made at or close to the time the document existed in the version being relied upon. And it must be verifiable — in a form that cannot be altered after the fact and can be checked by any party using independent tools.

A file timestamp produced by the disclosing party’s own system meets none of these criteria. An email header is independently produced but can be contested and is not legally qualified. A notarised document meets the criteria but is costly and impractical at any volume. Cryptographic timestamping — anchoring a document’s fingerprint to an independently maintained record at a specific moment — was designed for exactly this gap.

What matters for legal purposes is not merely that a timestamp exists, but that it is issued by a qualified party under a recognised standard. Under RFC 3161, an accredited Trust Service Provider creates a cryptographically signed record of a document’s fingerprint at a specific moment. Under eIDAS Article 41, a qualified electronic timestamp issued by an accredited Qualified Trust Service Provider carries a legal presumption of accuracy in EU member states and is treated as strong electronic evidence under UK law. Anchoring the same fingerprint on the Bitcoin blockchain via the OpenTimestamps protocol adds a permanent, publicly verifiable layer that does not depend on any single party’s continued operation.

How Provlyn Lets You Prove Document Authenticity: The Deposit Process

A Provlyn vault deposit produces all three evidential properties — independence, contemporaneity, and verifiability — for any digital document, in under a minute. The deposit works as follows:

  • SHA-256 hash generated — a unique cryptographic fingerprint of the exact file at that moment. A single character change anywhere in the document produces an entirely different fingerprint. The fingerprint cannot be reverse-engineered to reveal the document’s contents.
  • RFC 3161 timestamp applied — the fingerprint is timestamped by an accredited Trust Service Provider, creating a cryptographically signed record of the exact moment that version of the document existed.
  • eIDAS Article 41 qualification — the timestamp is qualified by an accredited Qualified Trust Service Provider (QTSP), giving the resulting vault certificate a legal presumption of accuracy in EU member states and strong electronic evidence status under UK law.
  • Bitcoin blockchain anchoring — the fingerprint is anchored on the Bitcoin blockchain through the OpenTimestamps protocol, creating a permanent public record that does not depend on Provlyn’s continued operation to remain verifiable.
  • Vault certificate issued — a downloadable PDF recording the file name, the SHA-256 fingerprint, the qualified eIDAS timestamp, and the blockchain anchor. Independently verifiable by any court, regulator, or counterparty using public tools.

Provlyn’s versioning capability extends this across an entire document exchange. Each iteration of a document through a negotiation — initial draft, revised version, final version — can be deposited independently, building an anchored document history in which each version is independently dated and verifiable. A fuller technical walkthrough is at www.provlyn.com/how-it-works.

The Practical Position for Any Business That Exchanges Documents

The cases that turn on document authenticity share a common thread. In 44 Wellfit Street, the defendant’s failure to serve its own Notice to Prove meant that where competing document versions existed, the claimant’s versions were treated as authentic by default. The procedural mechanism of CPR 32.19 determined the evidential starting point before the merits of the dispute were even reached, and the absence of verifiable metadata on the defendant’s side did the rest. The underlying merits became secondary once the evidential position was clear.

Knowingly falsifying documents in UK legal proceedings may constitute a criminal offence under the Fraud Act 2006, carrying a maximum sentence of ten years’ imprisonment. Relying on false evidence in court can also give rise to contempt proceedings — which require the permission of the court to bring and carry a maximum sentence of two years’ imprisonment. But the more common risk for most businesses is not deliberate falsification — it is the absence of any independent record of what a document contained at the moment it was exchanged, which leaves a legitimate version dispute impossible to resolve on its merits.

Establishing a cryptographic record before a document leaves your hands costs nothing beyond a seven-day free trial. A document authenticity challenge in the Commercial Court costs considerably more — and the outcome turns on evidence that most businesses do not have.

Establish prior proof of document version integrity for your business

Provlyn provides cryptographic prior proof of ownership for any digital artefact. Each deposit is hashed with SHA-256, timestamped by an accredited Trust Service Provider under RFC 3161, qualified under eIDAS Article 41, and anchored on the Bitcoin blockchain. The vault certificate carries a legal presumption of accuracy under the EU eIDAS Regulation, is admissible evidence in UK and EU jurisdictions, and remains valid permanently, independently of Provlyn’s continued operation. Start your free seven-day trial at www.provlyn.com. No credit card required.

This post provides general information about the role of cryptographic evidence. It is not legal advice. For advice on a specific matter, consult a qualified lawyer in your jurisdiction.

Related Reading

False Evidence: Questioning Document Authenticity in UK Court Proceedings — Fieldfisher / iDS Europe

CPR 32.19 — Civil Procedure Rules, Part 32

How to Prove You Created Something: A Practical Guide for Anyone Who Makes Original Work

Protect your work with Provlyn

Blockchain-anchored timestamps and court-admissible certificates. Prove it. Permanently.

Get started free