← Back to blog
Business & Legal

CPR 32.19: What UK Courts Require to Prove a Document Is Authentic

By James A Snell·17 July 2026

When a document's authenticity is challenged in UK proceedings, the party relying on it must prove what that document contained and when — and most businesses exchanging documents have no independent evidence to produce.

Every commercial transaction generates documents. Contracts, amendments, notices, emails confirming agreed terms, settlement letters, board resolutions: each one has a version that was sent and a version that is later disputed. When those versions conflict, the question the court asks is not which party is telling the truth. The question is which party can produce independent evidence of what the document contained at the moment it was exchanged. Most cannot.

Under CPR 32.19 of the Civil Procedure Rules, a party that receives a disclosed document is deemed to admit its authenticity unless they serve a formal Notice to Prove within the required timeframe. If that notice is served, the burden falls on the disclosing party to prove — not assert but prove — that the document being relied upon is the specific version that existed at the time it is said to have existed. Three cases heard within a few years of each other show exactly what that standard requires and what the consequences are when a party falls short.

How CPR 32.19 Works — and What It Demands

CPR 32.19 is a procedural rule with substantive consequences. Its mechanics are straightforward: disclosure of a document carries a deemed admission of its authenticity unless the receiving party serves a Notice to Prove. If they do, the party who disclosed the document must prove its authenticity at trial. The rule does not define what proof requires, but the cases do.

The deadline for serving a Notice to Prove is the later of the final date for serving witness statements, or seven days from disclosure of the document. A party that misses that window is deemed to have admitted authenticity — including, critically, where competing versions of the same document exist.

In 44 Wellfit Street Ltd v GMR Services Ltd [2017] EWHC 1841 (Ch), the claimant served notices under CPR 32.19 in respect of documents it wished to challenge. Because the defendant served no corresponding Notice to Prove, it was deemed to have admitted the authenticity of the claimant's versions. Where competing versions of the same emails and documents existed, the claimants were treated as authentic by default.

The defendant's versions were not excluded from scrutiny — but the procedural starting point was determined before the evidence was heard.

Chief Master Marsh then conducted close forensic scrutiny of signatures, handwriting, and metadata. The court found evidence of falsification. The determinative factor was not handwriting expertise — it was the absence of verifiable metadata on the defendant's documents, contrasted with the claimant's willingness to provide its emails in native form so that the metadata could be independently checked. The party that could point to an independently verifiable record of what its documents contained prevailed. The party that could not was found to have falsified the material it had placed before the court.

In McGann v Bisping [2017] EWHC 2951 (Comm), citing Mumford v HMRC [2017] UKFTT 19 (TC), the trial judge confirmed that a party wishing to challenge a document's authenticity cannot do so by pleading the challenge in a Statement of Case. The procedural obligation is specific: a formal Notice to Prove must be served within the required period. Merely asserting a challenge does not satisfy the rule, and a court retains discretion under CPR 3.1(2)(m) and CPR 3.10 to dispense with the notice requirement in exceptional circumstances — but no party should plan to rely on that discretion.

What the Cases Reveal About the Standard of Proof

The 44 Wellfit Street judgment is the clearest working illustration of what document authenticity proof requires. The defendant's versions of disputed emails could not be verified through independent metadata — no system logs, no server records, no native-format export that would allow an independent check. The claimant's versions could withstand that check. That difference was determinative.

Foglia v Family Officer Ltd [2021] EWHC 650 (Comm), decided by Mrs Justice Cockerill, illustrates the financial scale at which document disputes operate. The claim arose from fraudulent payment instructions — spoofed communications that directed the transfer of €15 million from a Cayman account to a company controlled by the defendant. Upon discovering the fraud, the claimant applied for Worldwide Freezing Injunctions and non-party disclosure orders against banks. Those orders, and the technical evidence gathered through them, enabled recovery of approximately €11.5 million. Summary judgment was awarded for the outstanding balance of around €3.5 million.

The case is not a document version dispute in the 44 Wellfit Street sense, but it demonstrates the scale of financial harm that flows from disputed document provenance, and the forensic resources required to establish what was sent, by whom, and when — in circumstances where the answer was contested from the outset.

The thread running through all three cases is the same: the party that could produce independent, verifiable evidence of what a document contained and when it was in that form had a decisive advantage. The party that could not was either found to have falsified its documents or faced the full cost of reconstructing an evidentiary record from hostile disclosure.

Why Standard Document Exchange Cannot Meet the Standard

Standard document exchange — email, cloud storage, messaging platforms, direct file transfer — was built to move documents between parties. It was not built to produce evidence of those documents.

The structural problem is independence. An email header is produced by the sender's own mail server and by the recipients. Email metadata is editable by anyone with administrative access to either server, and headers can be forged.

File system timestamps reflect the specific machine on which the file was created or modified; they change when a file is transferred to a new machine, re-saved, or when system settings are altered. A party's own IT systems are infrastructure the party controls — courts treat records produced by such systems as partisan rather than independent. It is the same reason a court would not accept a defendant's own account of what a document said without corroboration.

In 44 Wellfit Street, the absence of independently verifiable metadata was the single most important factor in the court's assessment of the defendant's documents.

A further problem is contemporaneity. Metadata can in principle be reconstructed, and records of document exchange can in principle be assembled after the fact. The difficulty is that any record assembled after a dispute begins is created precisely when its creator has a motive to assemble it in a particular way. Courts are alert to this — and the 44 Wellfit Street judgment showed that a forensic expert can detect signs of after-the-fact creation. A record made at the time the document was exchanged, by a party with no stake in the outcome, is the record the evidential standard demands.

Three Jurisdictions, One Evidential Requirement

CPR 32.19 is a rule of English civil procedure. The underlying evidential requirement it reflects — prove what the document contained and when — is not unique to England and Wales.

In US federal proceedings, the authentication requirement under Federal Rule of Evidence 901 requires the proponent of a document to produce evidence sufficient to support a finding that the document is what the proponent claims. Federal Rules of Evidence 902(13) and 902(14), added in the 2017 amendments, provide a self-authentication route for records generated by electronic processes or copied from electronic devices — provided the accuracy of the process is established through a certification by a qualified person. A cryptographic hash, independently timestamped and verifiable by any party using public tools, is precisely the kind of record those rules were designed to accommodate.

In EU member states, the eIDAS Regulation (EU) 910/2014 establishes the qualified electronic timestamp as a legally recognised instrument. Under Article 41 of the Regulation, a qualified timestamp issued by an accredited Qualified Trust Service Provider carries a legal presumption of accuracy as to its date and as to the integrity of the data to which it relates. That presumption applies across all EU member states; no court may discount a qualified timestamp on the basis that it is electronic rather than paper. The United Kingdom retained this framework domestically after leaving the EU; qualified timestamps from accredited providers are treated as strong electronic evidence under UK law.

The jurisdictional coverage matters because commercial document disputes rarely stay within a single legal system. A contract signed between a UK business and a EU counterparty, or a US business and its UK subsidiary, may be litigated in any of those jurisdictions. A document authenticity record that meets the standard in all three removes the jurisdictional question from the dispute entirely.

What an Evidential Record of Document Version Integrity Requires

An evidential record that can withstand a Notice to Prove or its equivalent in any major jurisdiction has three properties. It is independent — made by a third party with no stake in the outcome, not held on infrastructure either party controls. It is contemporaneous — made at or close to the moment the document existed in the version being relied upon, not assembled after the dispute began. And it is verifiable — in a form that any party, court, or expert can check using independent tools, producing a mathematical result that cannot be disputed.

Cryptographic prior proof at the qualified standard delivers all three:

  • SHA-256 hash generated — a unique cryptographic fingerprint of the exact file at that moment. Change a single character anywhere in the document and the fingerprint changes entirely. The fingerprint cannot be reverse engineered to reveal the document's contents.
  • RFC 3161 timestamp applied — the fingerprint is timestamped by an accredited Trust Service Provider, creating a cryptographically signed record of the exact moment that version of the document existed.
  • eIDAS Article 41 qualification — the timestamp is qualified by an accredited Qualified Trust Service Provider (QTSP), giving the resulting certificate a legal presumption of accuracy in EU member states and strong electronic evidence status under UK law, and supporting authentication under FRE 901/902 in the United States.
  • Bitcoin blockchain anchoring — the fingerprint is anchored via OpenTimestamps, creating a permanent, publicly verifiable record that does not depend on any single provider's continued operation.

This approach can be applied to every version of a document through a negotiation. Each iteration — initial draft, counter-draft, revised version, final form — is deposited independently, building an anchored version history in which each document is independently dated and verifiable. In a dispute about which version was the agreed final form, or about whether an amendment was made after signature, that version history is the evidence the court will demand. In 44 Wellfit Street it was the absence of any equivalent record on the defendant's side that proved fatal.

The Practical Stakes

The criminal and contempt law framework surrounding document falsification in UK proceedings sets the floor of the risk, not its typical expression. Falsifying a document for use in court proceedings constitutes perverting the course of justice at common law — a common law offence tried in the Crown Court carrying an unlimited maximum sentence. It may also constitute fraud by false representation under section 2 of the Fraud Act 2006, carrying a maximum of ten years' imprisonment on indictment. Contempt of court — which includes knowingly putting false evidence before the court — carries a maximum custodial sentence of two years under the Contempt of Court Act 1981, and judicial sentencing guidance confirms that immediate custody is appropriate in serious cases.

The criminal framework sets the outer limit of risk. The more immediate exposure for most businesses is the civil position created by the absence of any independent record of what a document contained at the moment of exchange.

When CPR 32.19 notice is served, the disclosing party must prove authenticity. If the only records available are from systems the disclosing party controls, the evidential contest has already started badly. In 44 Wellfit Street, one version of events was authenticated, and one was not — and the difference was a single verifiable property: independently checkable metadata. The practical consequence was that a property dispute was decided not on the underlying commercial merits but on which party had produced an evidential record that could be independently verified.

Establishing that record at the time each document is created or exchanged costs a fraction of what a commercial court claim costs to defend. The asymmetry in 44 Wellfit Street was not between sophisticated parties and unsophisticated ones — both parties had legal representation and a forensic expert. The asymmetry was between one set of documents that could be checked and one set that could not.

Related Reading

False Evidence: Questioning Document Authenticity in UK Court Proceedings — Fieldfisher / iDS Europe

CPR 32.19 — Civil Procedure Rules

44 Wellfit Street Ltd v GMR Services Ltd [2017] EWHC 1841 (Ch) — BAILII

Sending a Pre-Release Track: How to Prove Who Received a File and When

This post provides general information about the role of cryptographic evidence. It is not legal advice. For advice on a specific matter, consult a qualified lawyer in your jurisdiction.

James Snell is the founder of Provlyn, a platform providing cryptographic prior proof of IP ownership. provlyn.com