A sample workplace safety training completion certificate stamped diagonally in red with the word "FAKE," illustrating certificate fraud

Counterfeit Safety Certificates Are a Real Business — Here's How to Verify Training

Published: July 22, 2026 · Last updated: July 27, 2026

In Brooklyn, a card printer was doing a brisk trade. For somewhere between $200 and $650, a construction worker could walk away with an OSHA safety card that looked exactly like the real thing — same layout, same stock, indistinguishable at a glance from a card earned over ten or thirty hours of actual training. The only difference was that no training had happened  — the card was a product of training fraud.

In April 2023, the Brooklyn District Attorney indicted three people over that scheme. Two of them were authorized OSHA trainers — the very people the system trusts to certify everyone else — who sold completion cards without a course being taken. A third produced counterfeit cards on a printer at her workplace. The operation surfaced only because a New York City Housing Authority employee happened to notice discrepancies in a contractor's card during a routine check. (Construction Dive)

That case is a few years old now, but the mechanism it exposed is very much current — and it isn't a New York problem, or even only a US one. In Canada, safety professionals have reported a recent surge in forged training certificates, including workers photocopying cards and using AI to complete online modules on their behalf. (Canadian Occupational Safety) The uncomfortable truth underneath both: a safety certificate is one of the easiest documents in your files to fake, and one of the hardest to verify.

Why a forged safety card sails through

Pull an OSHA card out of a new hire's wallet and try to confirm it's genuine. You hit a wall fast. OSHA is explicit that it "does not operate, maintain or acknowledge any national database" for verifying student completion cards. (OSHA) The official routes are to scan a QR code on a plastic card — which just points you back to the Education Center that processed it — or to phone the trainer who issued it, who is required to keep records for five years.

Remember who the forgers were in Brooklyn: authorized trainers. When the person you would call to verify a card is the same person who might have sold a fake one, the verification step is theater. The result is a credential that's trivial to counterfeit and effectively unauditable at the exact moment you need to trust it — a hire, a site check, a contractor walking onto your job.

The certificate proves less than you think

Even a genuine, trainer-issued card carries two blind spots, and forgery only widens them. The first is completion versus competence: a card says someone sat through a course, not that they can do the work safely. The second — the one the fraud turns on — is identity and integrity. Who actually did the training, and has the document been altered since it was issued? A laminated card and a downloaded PDF can both assert a name. Neither can prove the named person is the one who earned it, and neither resists a thirty-second edit to a date or a spelling.

For a safety or HR buyer, that gap isn't academic. The certificate on file is supposed to be your evidence of due diligence. It holds up right until it's tested — an incident investigation, an insurer's audit, a client's pre-qualification review — at which point "we had the cards on file" can turn out to mean far less than it looked like.

What actually closes the gap

You can't spot your way out of this. Good forgeries are built to pass a glance, and the Brooklyn cards did exactly that. The durable fix is structural: change what a certificate is, so that faking it stops working. Two pieces do that.

Verify the person, not just the paper

The first fix attacks the "who actually did it" question at the source — the moment of assessment. Instead of trusting that the account logged in belongs to the named learner, identity is confirmed in real time when the graded assessment is taken. Tools built for exactly this — like Asgard Authenticate — verify a learner's identity at the point of assessment and proctor that moment, so an impersonation is caught before any certificate is issued, without subjecting the whole course to surveillance. It's a light touch for the learner and a hard anchor for the record: the difference between a certificate that asserts a name and one that verifies it.

Make the record impossible to forge

The second fix attacks the document itself. A verifiable credential is a training record issued as tamper-evident, cryptographically signed data rather than a printable card — built on the open W3C Verifiable Credentials standard. Platforms like CredentialVault issue certificates this way, which changes three things at once:

It can't be silently altered. Change one character and the signature breaks, so a forged or edited record fails verification instead of passing as real.

Anyone can check it — without trusting the issuer's word. An auditor, a client, or a site supervisor verifies the credential against the issuer's signature on the spot, instead of phoning a trainer and hoping someone picks up.

A discredited issuer is visible. If an issuer is revoked, credentials tied to them can be flagged — so a card from a bad-actor trainer doesn't quietly keep passing.

Put together, the two fixes move proof out of a document that can be faked and into a system that can't. The Brooklyn scheme worked because a fake card and a real one were indistinguishable and no one could easily check either. A verified identity plus a verifiable credential is the version of that same paperwork where the fake simply doesn't verify.

Where Gardril fits

Gardril was built around this problem. Its training verifies identity at the point of assessment, so the person who earns the certificate is the person who did the work, and it issues the record as a CredentialVault verifiable credential rather than a static PDF — tamper-evident, tied to the verified learner, and checkable by anyone who needs to trust it. The point isn't that a platform makes anyone compliant; it's that when a record can be verified by anyone, the incentive to fake it collapses, because a hollow credential can't survive the first check. You can see how Gardril approaches verified, defensible safety training if you want the working example.

This is the same weakness now being prosecuted in trucking — see our look at what the federal CDL training crackdown means for every employer.

What to do before you trust the next certificate

You don't need a national registry to protect your own organization. A few practical steps:

  • Don't treat a card as proof on its own. For OSHA cards, scan the QR code and, for anything high-stakes, confirm with the issuing Education Center or trainer — and remember records only have to be kept for five years.
  • Ask vendors the two questions that matter. Does the record verify who actually completed the assessment, and is it issued as a verifiable credential a third party can check — or just a PDF you're asked to take on faith?
  • Demand competency over completion. A certificate that reflects a genuine assessment tied to the person's real duties tells you more than a completion screen ever will.

The certificate is the easy part — it always has been, which is exactly why it's so easy to fake. Proving the right person genuinely earned it, in a way someone else can check without taking your word for it, is the part that holds up when it counts.

Frequently asked questions

Can you verify an OSHA 10 or 30 card online?

Not through a public database. OSHA states that it doesn't operate or recognize any national lookup site for student completion cards. You verify a plastic card by scanning its QR code, which routes to the OSHA Training Institute Education Center that processed it, or by contacting the authorized trainer who issued it — trainers are required to keep records for five years.

How common is safety-certificate fraud?

Common enough to be prosecuted. In one New York case, three people were indicted for producing and selling counterfeit OSHA and Site Safety Training cards for $200–$650 each — two of them authorized trainers who certified workers without training them. In Canada, safety professionals have reported a recent surge in forged training certificates, including photocopied cards and AI used to complete online modules.

Why can't I just tell a fake certificate by looking at it?

Because modern forgeries are built to pass a glance — matching layout, fonts, and card stock. A static certificate, real or fake, can also be edited in seconds and can't prove the named person is the one who earned it. That's why verification has to come from the record itself, not the appearance of the document.

What is a verifiable credential, and how does it stop forgery?

A verifiable credential is a training record issued as tamper-evident, cryptographically signed data based on the W3C Verifiable Credentials standard, instead of a printable card or PDF. Any change breaks the signature, and anyone can verify it against the issuer without trusting a printout — so a forged or altered record fails verification instead of passing as real.

What should employers verify before accepting a safety certificate?

Confirm the record verifies who actually completed the assessment (identity), that it certifies demonstrated competency rather than mere completion, and that it's issued as a credential a third party can independently check. For traditional OSHA cards, use the QR code or the issuing trainer/Education Center rather than accepting the card at face value.