← Back to resources

Compliance & GDPR · 14 Jun 2026 · Clear Fact Team

Building an FCA-ready audit trail for client documents

From upload to approval, mortgage firms need a defensible record of client interactions. Here is how case-level history, retention controls, and DSAR exports support compliance.

“We have the file somewhere” is not an audit trail

FCA Consumer Duty and GDPR both push firms toward demonstrable outcomes: fair treatment, clear communications, and controlled handling of personal data. For mortgage and financial advisers, client documents are where theory meets evidence.

What a useful audit trail includes

  • Client actions — portal activation, uploads, fact-find submission, e-signatures.
  • Adviser actions — document approval, rejection with reason, case notes, and reassignments.
  • Timestamps — when items moved between pending, uploaded, and approved states.

Retention and erasure

Define how long cases and documents are kept at firm level, and handle client erasure requests through a review workflow rather than ad-hoc folder deletes. DSAR exports should bundle case data and documents in a controlled package — not a manual scramble across shared drives.

Portal-first firms answer faster

When activity is logged against the client and case, compliance queries and internal file reviews take hours instead of days. That is not just efficiency — it is the operational proof that your client journey matches your policies.