An audit trail is a tamper-evident, chronological record of every action and document tied to a mortgage file, and it's the first thing a regulator or insurer asks for during a review. It captures who did what, when, and why, from initial intake through funding. Brokers use it to prove retention and retrieval compliance, document the reasoning behind advice, and reconstruct events when fraud is suspected. Start by checking your current retention period and whether files can be pulled fast enough to meet a regulator's deadline.
TL;DR:
- Regulations require a minimum five-year retention period with a 30-day window for file retrieval during audits, with some provincial rules extending retention to seven years and maintaining records within the province.
- Audit trails must include detailed data points such as actor identity, timestamp, action type, document source and version, rationale, and device and role metadata to be considered trustworthy by regulators.
- Implementing tamper-evident controls like append-only logging, role-based access, encryption, and full export capabilities ensures the integrity and reproducibility of records during an investigation.
- Automating document intake, classification, and metadata capture reduces manual gaps and speeds up retrieval, making the audit trail more reliable and easier to maintain.
- Regularly sampling closed files for missing rationale, enforcing strict access controls upon agent departure, and working proactively to detect red flags such as timestamp anomalies and duplicate documents help prevent fraud and support compliance.
Table of Contents
- 1. What an audit trail must capture
- 2. Regulatory recordkeeping rules you need to map
- 3. Technical controls that make a trail tamper-evident
- 4. How to implement an audit-trail workflow in your brokerage
- 5. Using audit trails to catch fraud and support investigations
- 6. How automation closes the gaps in manual record keeping
- 7. Treat audit trails as supervision tools, not just paperwork
- How Autowrite helps you build audit-ready files faster
- Primary sources worth bookmarking
- Sources
- FAQ
1. What an audit trail must capture
A usable audit trail is built from five recurring data points on every entry: actor identity, timestamp, action type, the source document or its version, and the rationale behind the action. Missing any one of these turns a log into a list of events nobody can explain later.
The trail should cover more than the loan application itself. It needs to include information records collected at intake, the mortgage loan file itself, correspondence by email or text, notes on suitability, and receipts tied to fees or disbursements.
- Actor and timestamp: who touched the file and exactly when, down to the minute.
- Action type: whether the entry was a document upload, an edit, an approval, or a communication.
- Source and version: the specific document, its version number, and a checksum or hash confirming it hasn't changed.
- Rationale: a short note explaining why a recommendation or decision was made.
- Device and role metadata: the IP address, device type, and the user's role in the brokerage.
2. Regulatory recordkeeping rules you need to map
The federal floor is set by FINTRAC's recordkeeping guidance, which requires mortgage brokers to keep information records for at least five years and to produce them within 30 days of a request. That 30-day window is the number that should drive how your storage and retrieval process is built, not just how long you keep files.
Retention: 5 years minimum, retrieval: within 30 days of a request is the baseline set by FINTRAC, and it applies regardless of how small the brokerage is.
Provincial and sector rules often go further. FSRA's guidance on keeping good records stresses documenting the "advice journey," meaning the reasoning behind a recommendation, not just the paperwork that resulted from it. BCFSA's document retention guidance points to retention periods running up to seven years for certain brokerage records, along with residency requirements that keep some records within the province.
- Federal floor: five years retention, 30-day retrieval, per FINTRAC.
- Provincial layer: some records need up to seven years retention and in-province storage, per BCFSA.
- Regulator focus: examiners look for documented rationale behind suitability decisions, not just signed forms.
The practical takeaway is to identify the strictest rule that applies to your operating area and apply it brokerage-wide, rather than tracking different retention clocks for different file types.
3. Technical controls that make a trail tamper-evident
A log anyone can quietly edit isn't an audit trail, it's a liability. The controls below are what separates a record a regulator or investigator will trust from one they'll dismiss.
- Append-only logging: entries are added, never overwritten, and each one is sealed with a cryptographic hash so any alteration is detectable.
- Write-once storage: once a document lands in the system, it can't be edited in place, only superseded by a new version with its own timestamp.
- Role-based access control: permissions match job function, so an agent can add notes but can't alter a compliance officer's sign-off.
- Privilege and change monitoring: every access attempt and permission change is itself logged, closing the loop on who could have touched what.
- Encryption and data residency: files are encrypted in transit and at rest, and storage location matches whatever residency rules your province requires.
- Searchability and export: the system can produce a full, printable file on demand, satisfying BCFSA's rule that electronic records must be reproducible and stay under brokerage control.
Pro Tip: Ask any vendor to demonstrate a full file export, timestamps, hashes, and metadata included, before you sign a contract, not after your first audit.
4. How to implement an audit-trail workflow in your brokerage
Getting audit-ready isn't a single project, it's a sequence of decisions that need an owner at each step.
- Inventory every record type your brokerage currently generates, from intake forms to lender correspondence.
- Define retention periods for each type, using the strictest applicable rule as your floor.
- Choose storage and vendor controls that support append-only logging, encryption, and export on demand.
- Set access policies by role, then document who approved them.
- Run a retrieval test on a closed file to confirm the whole chain actually works.
Clear ownership prevents the checklist from stalling:
- The principal broker owns overall supervision and sign-off on retention policy.
- A compliance lead manages day-to-day file audits and vendor oversight.
- Agents are responsible for logging file notes and the rationale behind their recommendations at the time a decision is made.
Build in recurring routines too: periodic integrity checks on stored files, clear versioning rules so nobody overwrites a prior document, and locked-down offboarding steps that cut a departing agent's access without losing their historical entries. A documented intake workflow makes the inventory step in this checklist far less painful.
5. Using audit trails to catch fraud and support investigations
A solid audit trail turns a fraud investigation from weeks of guesswork into a matter of pulling the right log. Certain patterns should trigger a closer look before a file ever reaches a regulator's desk.
- Timestamp anomalies, such as a signature dated before the document that authorized it existed.
- Duplicate or altered documents with mismatched checksums.
- Metadata that doesn't match the claimed actor, like a broker's login from an unfamiliar device at an odd hour.
- Approval cycles that move faster than the file's complexity would reasonably allow.
- Missing suitability rationale on a file that otherwise looks complete.
When something looks wrong, investigators typically start with the transaction bundle: the application, lender correspondence, and signed disclosures, alongside the narrative explaining why the recommendation was made. Preserve evidence by working from isolated snapshots rather than the live file, keep a chain-of-custody note for anything pulled for review, and never edit a record in place once an investigation starts. A rundown of common mortgage fraud red flags is worth keeping on hand for training.
Pro Tip: Export a hash-verified copy the moment you suspect a problem, before anyone else touches the file.
6. How automation closes the gaps in manual record keeping

Manual audit trails fail for a predictable reason: busy brokers skip the rationale field when they're rushing to close a deal. Document intelligence software fixes this by classifying incoming files, capturing metadata automatically, and locking version history the moment a document lands, so the trail builds itself instead of depending on someone remembering to fill it in later.
Autowrite applies this approach to Canadian mortgage files specifically, automating document intake and classification, autofilling underwriting forms, and assembling compliance packages while keeping data within Canadian residency requirements.
- Continuous logging replaces after-the-fact note-taking, closing the most common gap examiners flag.
- Automated metadata capture removes the manual step where rationale notes get skipped under deadline pressure.
- Faster document assembly shortens the time needed to produce a full file when a retrieval request lands.
| Operational need | Manual process | Automated approach |
|---|---|---|
| Metadata capture | Entered by hand, often incomplete | Captured automatically at intake |
| Version control | Tracked in file names or folders | Locked and hashed on save |
| Compliance package assembly | Compiled manually before submission | Assembled automatically from classified documents |
7. Treat audit trails as supervision tools, not just paperwork
The brokers who stay out of trouble use their audit trail proactively, not just when a regulator calls. Principal brokers should sample closed files regularly, looking specifically for missing rationale, since that's the gap examiners flag most often. Mandate a short rationale template for every recommendation, as detailed in Independent Broker Tactics for Life Insurance With Multiple Sclerosis, and lock down access the day an agent leaves, not the week after. An audit trail reviewed only during a crisis has already missed its best use: catching a training gap before it becomes a finding.
— Anant Bawa
How Autowrite helps you build audit-ready files faster
Every control described above, append-only logs, metadata capture, rationale documentation, retrieval on demand, is easier to sustain when the system does the capturing for you instead of relying on an agent to remember it mid-deal. Autowrite automates document intake and classification, autofills underwriting forms, and assembles compliance packages built for Canadian brokers, with Canadian data residency built into the platform.

If your brokerage is still assembling audit trails by hand across scattered folders and email threads, that's the gap worth closing first. Autowrite's plans start at $149 per month for Starter, with Pro at $269 and Legend at $499, plus a $20 fee per additional deal beyond plan limits, all detailed on the Autowrite pricing page. Visit the Autowrite product page to see how the platform handles compliance packages before your next file review.
Primary sources worth bookmarking
Keep these close at hand when you're setting or reviewing retention policy.
- FINTRAC's recordkeeping guidance for the federal retention and retrieval baseline.
- FSRA's guidance on keeping good records and its sector supervision plan for advice-journey expectations.
- BCFSA's document retention guidance for provincial residency and retention rules.
Sources
- Record-keeping obligations (FINTRAC)
- Keep good records to protect your reputation | Financial Services Regulatory Authority of Ontario
- Document Retention Information | BCFSA
- Mortgage brokering sector supervision plan 2023-24 | FSRA
FAQ
How much does a mortgage broker make on a $500,000 mortgage?
Broker compensation varies by lender, product, and province, and no fixed public rate applies to every deal. Brokers should check individual lender compensation agreements rather than relying on a general figure.
What not to say to a mortgage broker?
Avoid withholding financial details or providing inconsistent information across conversations, since gaps like these are exactly what create documentation problems later. Clear, consistent answers about income, debts, and intent help a broker build accurate suitability notes from the start.
How much trail commission do mortgage brokers get?
Trail commission structures differ by lender and are set out in individual broker compensation agreements rather than a single published rate. Brokers should confirm the specific trail terms with each lender they work with.
What are red flags on a mortgage application?
Common red flags include timestamp anomalies, duplicate or altered documents, mismatched metadata between a stated actor and the device used, and approval cycles that move faster than the file's complexity would suggest. Missing suitability rationale on an otherwise complete file is another pattern that tends to draw closer scrutiny.
