Compliance & GDPR · 14 Jun 2026 · Clear Fact Team
Building an FCA-ready audit trail for client documents
From upload to approval, mortgage firms need a defensible record of client interactions. Here is how case-level history, retention controls, and DSAR exports support compliance.
“We have the file somewhere” is not an audit trail
FCA Consumer Duty and GDPR both push firms toward demonstrable outcomes: fair treatment, clear communications, and controlled handling of personal data. For mortgage and financial advisers, client documents are where theory meets evidence.
What a useful audit trail includes
- Client actions — portal activation, uploads, fact-find submission, e-signatures.
- Adviser actions — document approval, rejection with reason, case notes, and reassignments.
- Timestamps — when items moved between pending, uploaded, and approved states.
Retention and erasure
Define how long cases and documents are kept at firm level, and handle client erasure requests through a review workflow rather than ad-hoc folder deletes. DSAR exports should bundle case data and documents in a controlled package — not a manual scramble across shared drives.
Portal-first firms answer faster
When activity is logged against the client and case, compliance queries and internal file reviews take hours instead of days. That is not just efficiency — it is the operational proof that your client journey matches your policies.