We should block garage reimbursement and warranty top-ups unless MOT certificate PDFs carry cryptographic hashes that match DVLA’s issue log—because Trading Standards casework this September still shows duplicate paperwork unlocking payouts when the vehicle never crossed a test bay.

Where the loophole lives

DVLA already records pass/fail outcomes when authorised testers submit results electronically. Insurers and extended-warranty administrators, however, often accept emailed PDF scans from garages or motorists without verifying that the file’s content hash equals the record DVLA issued. Fraud investigators in the West Midlands described cases where the same certificate serial appeared on two registrations; garages collected admin fees while DVSA audit trails showed only one live test.

Hashes are not exotic. DVSA’s contractor pipeline could expose a daily lookup API returning a SHA-256 of the signed certificate payload insurers query before releasing funds. Today that check is optional—so honest garages compete with operators who photocopy last year’s pass.

Strongest objection

Independent workshops argue hash APIs add latency at claim desks and disadvantage rural garages with poor broadband. Latency is solvable with batch overnight verification for sub-£200 claims and real-time checks above that threshold. Rural connectivity is a infrastructure problem; it should not excuse paying on forged PDFs.

Garage trade groups also warn that insurers will use failed hash matches to deny legitimate claims when DVLA’s log lags testers by hours. Build a grace window and audit the lag—do not keep paying on trust.

Who must act

DVSA should mandate hash publication for every certificate issued after 1 January 2027 and require Motor Ombudsman members to verify before arbitration awards. The Financial Conduct Authority should treat hash-less MOT payouts in motor finance add-ons as unfair contract performance when evidence of duplicate serials emerges.

Insurers can move faster: add a hash field to FNOL portals this quarter without waiting for statute. Trading Standards should publish anonymised duplicate-serial counts quarterly so boards see the scale.

What we are not saying

This is not a call to nationalise MOT testing or ban paper certificates for motorists who want a glove-box copy. It is not a claim every disputed payout is fraud—clerical errors happen. It is a demand that money leaving insurer treasuries traces to a DVLA-anchored file, not a convincing scan.

We are also not asking drivers to understand cryptography—only that back-office systems stop treating PDFs as proof when DVLA already holds the authoritative bits.

Mechanism in the kicker

Appropriations for DVSA’s digital MOT programme should include insurer-facing verification endpoints, not just consumer history websites. Until hashes gate payouts, September’s duplicate paperwork cases will remain the cheap fraud—not the sophisticated cyber heist headlines prefer.

Consumer-facing check

Motorists already use the free MOT history service before buying used cars; insurers could reuse that UX with a hash match indicator on claim portals. The technology is not the barrier—contractual willingness to deny payouts when PDFs fail verification is. Until hashes gate money, honest testers subsidise fraud through higher collective premiums.

Parliament’s transport committee should schedule one evidence session on certificate integrity before the next insurance renewal season—hashes are cheaper than another national fraud taskforce that only counts losses after the fact.