← Back to blog

Source of Funds Verification: A Compliance Officer's Playbook

August 19, 2026
Source of Funds Verification: A Compliance Officer's Playbook

Source of funds (SoF) verification means confirming, with independent evidence, where the specific money in a transaction actually came from, distinct from source of wealth (SoW), which explains a client's overall net worth and how they built it over time. The compliance action is simple to state and harder to execute: SoF is transaction-specific, and when risk warrants it, you need independent corroboration, not just a client's word.

Bodies like the FATF, FINTRAC, and provincial law society rules all point to the same expectation: verify proportionately, and document why you did what you did.

For any transaction that trips a risk trigger, do three things immediately:

  • Identify the trigger. Name the specific reason the check is happening (high-risk client, large or unusual transfer, red flag from monitoring).
  • Request corroborating documents. Ask for evidence that explains the event and evidence that shows the money moving, not just one or the other.
  • Log the verification and rationale. Record what you received, what you concluded, and why, before the file closes.

Key Takeaways

Source of funds verification works when evidence is matched to risk, corroborated independently, and documented well enough that another analyst could reconstruct the decision.

PointDetails
Define SoF preciselyIt confirms the origin of a specific transaction's funds, separate from overall source of wealth.
Use the two-document patternPair a document explaining the event with one showing the funds actually moving.
Scale evidence to riskReserve multi-source independent corroboration for PEPs, offshore activity, and outsized transactions.
Log the rationale, not just the outcomeRecord triggers, documents, verification actions, and sign-off for every event-driven check.
Automate intake, not judgmentAutowrite classifies and extracts mortgage document data to speed evidence collection, while final risk decisions stay with the broker.

Table of Contents

When Source of Income Checks Are Required

Not every client needs a SoF check. It applies when risk crosses a threshold, and knowing where that threshold sits keeps your team from either under-checking dangerous files or over-checking routine ones.

The common triggers show up again and again across engagements:

  • Onboarding a politically exposed person (PEP) or a client with a complex or opaque ownership structure.
  • A transaction that is unusually large relative to the client's known profile or large in general.
  • Activity that doesn't match the stated purpose of the account or relationship.
  • A red flag surfaced by transaction monitoring, adverse media, or a sanctions screen.

FATF Recommendation 10 requires firms applying enhanced due diligence to take reasonable measures to establish both SoF and SoW for higher-risk customers. That obligation doesn't end at onboarding. A client who looked low-risk six months ago can generate a transactional trigger today, a sudden inheritance-sized deposit, an offshore wire, a change in stated occupation, and each of those events resets the clock on whether you need fresh evidence.

What Documentation Proves the Origin of Funds

The strongest SoF files follow a pattern: one document that explains the economic event, and a second that shows the money actually moving. A bank statement alone rarely cuts it. It proves the funds passed through an account; it doesn't prove where they came from in the first place, a limitation practitioner guidance on source of funds checks flags repeatedly.

Match the evidence to the scenario:

  • Employment income: payslips, an employment contract, or a letter from the employer, paired with the deposit history.
  • Property sale: the sale agreement or completion statement, paired with the bank receipt showing the proceeds landing.
  • Inheritance: a grant of probate or estate distribution letter, paired with the transfer record.
  • Loan proceeds: the signed loan agreement, paired with the disbursement showing up in the account.
  • Investment liquidation: brokerage statements showing the sale, paired with the settlement transfer.
  • Cryptocurrency: on-chain transaction history establishing provenance, paired with exchange records showing the fiat conversion.

Third-party gifts, trust distributions, and corporate dividends each need their own paper trail: a signed gift letter and the donor's own SoF for a gift, a trust deed and trustee resolution for a distribution, board minutes and dividend records for a corporate payout. Wherever possible, favor independent, official sources, land title registries, probate courts, exchange transaction histories, over documents the client typed up themselves. A registry entry can't be edited after the fact; a self-declared summary can.

Applying a Risk-Based Verification Standard

Not every client deserves the same scrutiny, and pretending otherwise wastes resources on low-risk files while under-checking the ones that matter. A standard check for a salaried client depositing a modest down payment might reasonably rely on a declaration plus one supporting document. A PEP moving funds through an offshore structure needs independent corroboration from multiple sources, tax filings, sale contracts, probate records, not a single form. FINTRAC guidance is explicit that client assertions alone aren't acceptable evidence once risk rises.

Three factors push a file from standard checks into Enhanced Due Diligence (EDD); adopting tailored, client-specific intake questions can reduce unnecessary document requests and surface risks earlier:

  • The plausibility gap. The declared funds don't square with the client's known income or wealth profile, often the single strongest risk signal in the file.
  • Jurisdictional exposure. Money is routing through, or originating from, a high-risk or sanctioned jurisdiction.
  • Transaction size or complexity. The amount or structure is disproportionate to the relationship you have on record.

Whenever you deviate from your baseline standard, in either direction, write down why. A supervisor or examiner reviewing the file six months later needs to see the judgment, not just the outcome.

Red Flags That Signal a Verification Problem

Certain patterns should slow you down every time you see them, regardless of how clean the rest of the file looks.

  • Unexplained payments from a third party with no stated relationship to the client.
  • Circular fund movement, money that leaves and returns through related accounts with no clear commercial purpose.
  • A sudden large deposit with no prior transaction history to match it.
  • Vague explanations like "savings" or "investments" with nothing behind them.
  • Income that doesn't come close to supporting the transaction size.
  • Funds routed through high-risk jurisdictions, or crypto transfers passed through a mixing service to obscure origin.

When you spot one of these, ask a targeted follow-up question rather than reaching for a generic template. Request the specific document that would resolve the gap: a contract, a probate filing, a brokerage statement. If a sanctions screen returns a hit at any point, freeze the transaction and escalate immediately; that step doesn't wait for the rest of the file to be finished.

Building an Audit-Ready Documentation Trail

Examiners don't just want the right answer, they want to see how you got there. FINTRAC guidance calls for a record of the documents received, the verification actions taken, any red flags identified, and the rationale behind the final decision.

Capture these fields for every verification event: date, trigger, client's stated explanation, documents obtained (type and source), verification action performed, inconsistencies or red flags noted, reconciliation to SoW, analyst name, sign-off level, and retention period. A vague label like "savings" is fine as a starting point, but the file needs to show how you resolved it, or why you judged the explanation sufficient without further digging.

FieldWhat to record
Trigger and dateWhat prompted the check and when it occurred
Documents obtainedType, source, and whether independently verified
Verification actionHow each document was checked (registry, third-party confirmation)
Rationale and sign-offWhy the file was approved, escalated, or declined, and by whom

Name files consistently, by client ID and event date, and cross-reference registry lookups so a reviewer can retrace your steps without asking you to reconstruct them from memory. Retain records per your jurisdiction's minimum period, and escalate to senior compliance or the MLRO the moment a file exceeds your authority to sign off.

Pro Tip: Structure each file so the sequence of judgment, not just the final conclusion, is visible: what you asked for first, what came back, what that triggered next. An inspector should be able to follow your thinking without a single follow-up question.

When You Cannot Verify the Source of Funds

Sometimes the evidence just doesn't add up, and pretending otherwise creates more risk than the transaction itself.

  • Request additional clarifying evidence before assuming the worst; a client may simply have submitted the wrong document.
  • If the gap persists, limit or place a hold on the transaction while the file is reviewed further.
  • Escalate to senior compliance or the MLRO, and consider whether the relationship should be restricted or declined outright.
  • Check your jurisdiction's reporting obligations. FINTRAC and comparable regulators elsewhere require specific reports once certain thresholds or suspicions are met.
  • Whatever you decide, write it down, with the reasoning intact, so the file holds up under later review.

How Document Automation Speeds Up Defensible Checks

For mortgage brokers specifically, SoF verification often means chasing down payslips, sale statements, and gift letters across a dozen email threads. A workflow built on document intelligence changes the sequence: incoming files get classified automatically, key data (amounts, dates, counterparties) gets extracted without manual re-typing, and the system checks that data against available registries before flagging a plausibility score for human review.

The payoff shows up in three places:

  • Evidence collection that used to take hours compresses into minutes.
  • Risk tiers get applied consistently across every file, not just the ones a senior analyst happens to catch.
  • The resulting audit trail is searchable and reconstructible on demand, instead of scattered across inboxes.

Automation speeds up the mechanics. It doesn't replace judgment. The decision to approve, escalate, or apply EDD still belongs to a trained compliance professional who understands the specific client and transaction in front of them.

A compliance officer's real-world calculus

Hands examining documents under magnifying glass

Experienced analysts spend less time chasing paperwork and more time interrogating the plausibility gap, because that gap, not the document count, is usually where the risk actually lives. Treat every SoF review as event-driven and built for audit, not as a box to check once and forget.

Autowrite Turns Document Chaos Into an Audit-Ready File

For mortgage brokers, SoF verification lives or dies on how fast you can turn a client's scattered documents into a coherent file, and how well that file holds up when a lender or regulator asks questions later. Autowrite is built specifically for that problem: it automatically classifies incoming documents, extracts the data that matters (income figures, transaction dates, counterparty names), and assembles it into a compliance package ready for underwriting and audit.

Autowrite

That means less time spent manually cross-checking payslips against bank statements, and a file structure that already matches what an examiner expects to see. Brokers still make the final call on risk and sign-off, Autowrite handles the paperwork that used to eat the hours between client meetings. If your current process still runs on spreadsheets and email chains, start a trial with Autowrite and see how quickly a SoF file comes together.

Where to Read the Original Regulatory Guidance

Frequently Asked Questions

What's the difference between source of funds and source of wealth? Source of funds verification confirms where the money in one specific transaction came from. Source of wealth explains how a client built their overall net worth over time, a broader, ongoing assessment rather than a single-transaction check.

Is a bank statement enough to verify source of funds? Usually not on its own. A bank statement shows that money moved through an account, not the economic event that generated it. Pair it with a document like a sale contract, probate grant, or employment letter that explains where the money originated.

When does a file need Enhanced Due Diligence instead of a standard check? When the plausibility gap between declared funds and known profile is significant, when jurisdictional risk is elevated, or when the transaction's size or complexity exceeds what the client relationship would normally justify.

What should we do if a client can't produce adequate evidence? Ask for clarifying documentation first. If the gap persists, hold or limit the transaction, escalate to senior compliance or the MLRO, and evaluate whether a regulatory report is required under your jurisdiction's rules.

Frequently Asked Questions — overview diagram

This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.

Sources