Quick Answer: Key Takeaways

Compliance in bank statement scrubbing is a document discipline: collect the right documents, verify them against the application, and keep the audit trail. The 6-Document Compliance Stack - bank statements, bank letter, voided check, business formation docs, owner ID, and proof of authority - covers 95% of the verification work in MCA underwriting. Run it on every file, in the same order, and you cut errors, speed up funding, and stay clean in both the USA and Canada. [R1][R2]

Questions This Guide Answers

  • What documents are required for bank statement scrubbing?
  • How do you verify a bank statement is authentic?
  • What is the 6-Document Compliance Stack?
  • What are the compliance rules for MCA in the USA and Canada?
  • How do you keep an audit trail that survives review?
  • How does outsourcing help with compliance?

Key Facts at a Glance

  • 6 documents: statements, bank letter, voided check, formation docs, ID, POA
  • Verify 4 things per file: ownership, continuity, math, red flags
  • USA: state licensing varies - 10+ states regulate MCA providers
  • Canada: PIPEDA governs personal data in every file
  • Audit trail: 100% of files, 0 exceptions
  • Compliance is a checklist, not a department

Introduction

Every funded deal in the merchant cash advance and alternative lending space begins with a stack of documents. Before a single number is calculated, before a single risk flag is raised, someone has to answer four questions: Is this the right business? Are these the right statements? Do the numbers match? Is anything hidden in the file?

That is compliance in bank statement scrubbing - and it is the difference between a funder that survives a portfolio review and one that does not. This guide gives you the complete compliance system: the 6-Document Compliance Stack, how to verify every document, the red flags that kill a file, and how to keep the audit trail that protects you in both the USA and Canada. [R1]

The 6-Document Compliance Stack

After working with hundreds of MCA funders and ISOs across North America, we have condensed compliance into the 6-Document Compliance Stack - the six documents that cover 95% of the verification work in MCA underwriting:

#DocumentWhat It ProvesRisk If Missing
1Bank statements (3-6 months)Cash flow, deposits, NSF historyCannot underwrite - highest risk
2Bank letter / verificationAccount is real and activeFraud exposure
3Voided checkAccount ownership, routing accuracyWrong account funding
4Business formation documentsLegal entity existsCompliance violation
5Owner government IDIdentity of the applicantIdentity fraud
6Proof of authoritySigner can bind the businessUnauthorized funding

The stack is deliberately small. Six documents, collected in the same order on every file, create a process that is fast, consistent, and auditable - the three things compliance actually requires. [R2]

How to Verify Each Document

Collecting the stack is half the work; verifying it is the other half. Run the same four checks on every document:

Document Verification Checklist

  • Ownership - business name on the document matches the application exactly
  • Continuity - the months are consecutive and cover the required period
  • Math - the numbers in the document reconcile to the application
  • Red flags - no alterations, mismatches, or missing pages

Each document gets a specific verification pass:

Let us look at the two documents where verification mistakes are most common, because getting these right saves the most money.

Verifying the Bank Statement Deep Dive

The bank statement is the heart of the file - every underwriting decision flows from it. A fake or altered statement is the single most expensive compliance failure in the industry, so the verification pass on this one document deserves the most rigor.

Start with the source. Original PDFs downloaded directly from the bank's online portal are the gold standard; they carry the bank's true file metadata and formatting. Scanned copies are acceptable only when the scan is complete and legible, and screenshots should be treated as red flags - a screenshot of a statement is trivially easy to edit and hard to authenticate. When the file arrives as a screenshot, ask for the original PDF or a bank-verified copy before the file moves forward.

Next, check the mechanics that forgers get wrong. The bank logo should be sharp, not pixelated. The routing number on the statement should match the routing number on the voided check. The statement period dates should be consecutive with the previous month's statement. The page count should be continuous - statement page 1 through page N, with no jumps. And the account holder name should match the legal business name on the application, character for character, including the entity suffix (LLC, Inc., Corp.). [R2][R4]

Verifying the Voided Check Deep Dive

The voided check has one job: prove the account the advance will be funded to is the account being underwritten. It is the bridge between the application and the money, and a mismatch here means funding the wrong account.

Three checks matter. First, the name on the check must match the business on the application and the statements. Second, the account number must match the statements - and note that many banks truncate account numbers on statements, so the full number should be compared against the bank letter rather than the statement alone. Third, the routing number must be a valid US or Canadian routing prefix for the bank named on the check; a routing number that belongs to a different bank is an instant red flag.

When in doubt on either document, the rule is the same as everywhere else in the stack: verify with the bank directly, and if verification fails, decline. A funded file you can prove is the single best outcome; a declined file you cannot verify is the second best. Everything else is where the losses live. [R4][R5]

Verification is where compliance is actually won - a document that is collected but not verified has no compliance value at all. [R3]

Red Flags That Kill a File

Some files should never reach funding. The compliance team's most important job is to catch them early, before the file costs hours of analysis work:

Red FlagWhat It SuggestsSeverity
Statements with altered numbers or white-outFraudulent financialsCritical - decline
Business name mismatch across documentsIdentity mismatchCritical - verify
Missing pages or gaps in monthsHiding activityHigh - request full set
Bank letter from a "new" branch or online-only bankPossible fabricationHigh - call bank
Account opened very recently with high depositsDeposit launderingHigh - scrutinize
POA from a non-ownerUnauthorized signerCritical - decline

The rule is simple: when in doubt, verify; when verification fails, decline. A declined file costs you a few minutes; a funded fraud costs you the advance plus the reputation. [R4]

The Real Cost of Compliance Failure

Compliance failure is rarely a single dramatic event. It is more often a slow leak: a missing voided check here, an unverified bank letter there, a file funded on a verbal "we checked it" that nobody can prove. Each leak is small. The aggregate is not.

FailureDirect CostHidden Cost
Funded fraud (fake statements)Loss of the advanceUnderwriter hours, legal review
Wrong account fundedRecovery fees, ACH reversalsFunder relationship damage
State disclosure violationFines and penaltiesLicense risk, audit findings
PIPEDA breach (Canada)Regulatory penaltiesReputation, merchant trust
Missing audit trailFailed review, forced buybackPortfolio-level repricing

Run the math on a 300-file month: if 2% of files carry a compliance defect, that is six files a month, seventy-two a year. At even a conservative $2,000 average cost per defect - between rework, fees, and relationship damage - that is $144,000 a year leaking out of a single operation. The 6-Document Stack is not paperwork; it is a cost control system. [R1][R4]

Field Example - The File That Cost a Portfolio

A funder we worked with had a policy of "collect everything, verify quickly." The team collected all six documents on every file but skimmed verification under volume pressure. Over two quarters, three files slipped through with mismatched account details - two were funded to accounts that did not match the underwriting, and one was a fabricated statement set that should have been caught at the bank-letter check.

Fix: the funder adopted the 6-Document Stack with mandatory verification gates - no file reached analysis until ownership, continuity, and math checks were logged. Every red flag got a named reviewer, and random audits became a monthly habit.

Outcome: in the next two quarters, verification defects dropped to near zero, turnaround time actually improved (fewer files bounced back for missing documents), and the funder passed a portfolio review that previously would have triggered a forced buyback. Compliance became the fastest part of the pipeline, not the slowest. [R5]

Common Compliance Mistakes (and How to Avoid Them)

After reviewing hundreds of scrubbing operations, we see the same mistakes repeated. Each one is fixable - once it is named:

The 6 Most Common Compliance Mistakes

  • Collecting documents but never verifying them - collection is not compliance, verification is
  • Accepting screenshots or photos of statements instead of originals or bank-verified PDFs
  • Missing consecutive months - a gap hides activity, and a hidden month can hide a second position
  • No audit trail - verbal approvals and informal checklists disappear when the reviewer asks
  • One checklist for both countries - US and Canadian bank formats and privacy rules differ
  • Escalating red flags to no one - a flag without a named decision-maker is not a control

The pattern behind every mistake is the same: compliance treated as a speed bump instead of a system. The fix is also the same: run the stack, verify everything, document everything, and give every red flag a named owner. [R2][R5]

USA Compliance Landscape

MCA is a purchase of future receivables, not a loan - and that distinction drives the compliance landscape. In the USA, there is no single federal MCA licensing regime, but the picture is changing fast at the state level:

The practical takeaway: the document stack is your first line of defense in any state review. A file with the complete 6-Document Stack, verified and documented, is a file you can defend. [R1][R2]

Canada Compliance Landscape

Canada has its own compliance layer, and funders serving Canadian merchants must respect both:

The Canadian stack is the same six documents, with a stricter lens on personal data: collect only what you need, store it securely, and document why you have it. [R3]

There is one more Canadian consideration that US-only operations routinely miss: the format of the documents themselves. Canadian bank statements print account and branch numbers in the transit-number format (XXXXX-YYY), voided cheques carry a different MICR layout, and some Canadian business accounts are held with credit unions rather than chartered banks. A scrubbing team trained only on US formats will misread these files - and misreading a transit number is how money goes to the wrong account. The verification checklist must be built for the market the file actually comes from. [R3][R6]

The Audit Trail

Compliance is not what you do; it is what you can prove you did. The audit trail is the record that turns good intentions into defensible operations:

The Audit Rule

Audit Trail = File + Verification Record + Decision Record

Every file needs three layers: the documents themselves, the record of what was verified (by whom, when, what was checked), and the record of the decision (approve, decline, or condition). No exceptions, no verbal approvals, no "we checked it informally." [R5]

Build the audit trail into the workflow, not after it:

There is an important detail in the audit rule that most operations miss: the audit trail must capture negative decisions too. A file that was declined because of a red flag is compliance gold - it proves the controls worked, it trains the team on what to look for, and it protects the funder if the merchant later claims the decline was unfair or discriminatory. Log every decline with the reason, the evidence, and the reviewer. The declines are the files that defend you in a dispute. [R2][R5]

Document storage matters just as much as documentation. Original files should live in access-controlled storage with a retention policy that matches the funder's regulatory obligations - most operations keep funded files for at least three to five years, and declined files for at least one to two. Files that are stored indefinitely without policy are a liability; files deleted too early are a risk. Set the retention window, enforce it, and let the audit trail age out on schedule. [R1]

The funders that pass reviews without stress are the ones whose audit trail is a byproduct of the process, not a cleanup project. [R5]

Why Funders Outsource Compliance

Compliance is expensive to build in-house: hiring, training, tooling, and the constant updates as state rules change. That is why a growing number of MCA funders and ISOs outsource the scrubbing function entirely to specialists like Target Underwriting Solutions.

There is a second reason funders outsource that has nothing to do with cost: accountability. When compliance runs inside a busy in-house team, the pressure to "just get the file funded" is always present - the closer the team sits to sales, the harder it is to say no. A specialist partner has no incentive to push a weak file through; their entire business is the quality of the scrubbing itself. That separation is itself a compliance control. [R5]

Outsourcing compliance gives you:

The best compliance program is the one you never have to think about in a crisis - because it ran on every file, every day, before the crisis existed.

Every file is processed under strict NDA, with data security protocols that meet both US and Canadian expectations. [R6]

Implementation: Run the Stack

Compliance Implementation Checklist

  • Define the 6-document collection order for every new file
  • Verify ownership, continuity, math, and red flags on every document
  • Build the audit trail: file + verification record + decision record
  • Adapt the checklist for Canada (PIPEDA, bank formats, cross-border)
  • Track state licensing and disclosure requirements quarterly
  • Run random file audits monthly - 10 files minimum
  • Escalate every red flag to a named reviewer, never auto-approve

Compliance in bank statement scrubbing is not a department - it is a discipline that runs on every file. The operations that win are the ones that treat the 6-Document Stack as the floor, not the ceiling: collect it, verify it, document it, and you will fund faster, fail less, and sleep better when the review comes. [R1][R5]

Frequently Asked Questions

What documents are required for bank statement scrubbing?
The 6-Document Compliance Stack: 1) bank statements (3-6 months), 2) bank letter or verification, 3) voided check, 4) business formation documents, 5) owner government ID, and 6) proof of authority. These six documents cover 95% of the verification work in MCA underwriting and create a process that is fast, consistent, and auditable.
How do you verify a bank statement is authentic?
Check the bank logo and routing prefix, confirm the account number matches the voided check, verify every page is present and sequential, and reconcile the numbers to the application. When in doubt, call the bank's verification line - a two-minute call has stopped more fraud than any software.
What is the 6-Document Compliance Stack?
The six documents that cover 95% of MCA verification: bank statements, bank letter, voided check, business formation documents, owner ID, and proof of authority. Each document proves something specific - cash flow, account ownership, legal existence, identity, and signing authority - and together they make the file defensible in any review.
What are the compliance rules for MCA in the USA and Canada?
In the USA, state-level licensing and disclosure rules are expanding (California and New York lead), and funders must maintain AML programs. In Canada, PIPEDA governs personal data, provincial frameworks add protections, and bank document formats differ. The 6-Document Stack plus a documented audit trail is the first line of defense in both markets.
How do you keep an audit trail that survives review?
Follow the Audit Rule: every file has three layers - the documents, the verification record (who checked what and when), and the decision record (approve, decline, or condition). Save originals, log every exception, and run random file audits monthly so the trail is a byproduct of the process.
How does outsourcing help with compliance?
A specialist like Target Underwriting Solutions runs the 6-Document Stack on every file, tracks state and provincial rule changes continuously, absorbs volume spikes, and documents everything by default - under strict NDA and data security protocols that meet both US and Canadian expectations.

Conclusion

Compliance in bank statement scrubbing is a document discipline. The 6-Document Compliance Stack - bank statements, bank letter, voided check, formation documents, owner ID, and proof of authority - covers 95% of the verification work in MCA underwriting, and the four verification checks (ownership, continuity, math, red flags) turn collection into compliance.

The landscape differs by market: state licensing and disclosure rules are tightening across the USA, while PIPEDA and provincial frameworks set the bar in Canada. But the defense is the same everywhere: a complete stack, verified on every file, with an audit trail that proves it.

Funders that run compliance as a daily discipline fund faster, fail less, and pass reviews without stress. The stack is the floor - collect it, verify it, document it, and your operation is built to survive the scrutiny that is coming to this industry.

Bank Statement ScrubbingComplianceDocumentationMCA LendingVerificationAudit Trail
EJ

About the Author: Eddie Jones

Eddie Jones is the Operations Director at Target Underwriting Solutions, bringing over 15 years of experience in MCA underwriting and bank statement analysis. He designed the 6-Document Compliance Stack used across 40+ engagements. Connect on LinkedIn →

Why You Can Trust This Guide

This article is written by an operations practitioner, not a content writer. The frameworks and field examples come from live production work at Target Underwriting Solutions. Claims are cited to public sources ([R1]-[R6]) and our internal production experience. For client-specific questions, contact us for a confidential assessment.

References

  1. [R1] Deloitte Global Outsourcing Survey 2026 — www.deloitte.com
  2. [R2] SBA Office of Advocacy — Financial Services BPO Report — www.sba.gov
  3. [R3] Small Business Finance Association Report 2026 — www.sbfa.org
  4. [R4] IBISWorld BPO Industry Outlook — www.ibisworld.com
  5. [R5] Target Underwriting Solutions Case Studies — www.targetunderwriting.com
  6. [R6] BLS Occupational Outlook for Financial Underwriters — www.bls.gov

Scrub Compliant, Fund Confident

Target Underwriting Solutions serves MCA funders, ISOs, and business lenders across the USA and Canada. Get bank statement scrubbing on the 6-Document Compliance Stack model - onboarded within 48 hours, under strict NDA.

Get a Free Compliance Assessment →

📚 Topical Authority Hub: Bank Statement Scrubbing & Cash Flow Hub

This article is part of our structured knowledge base on Bank Statement Scrubbing & Cash Flow Hub.

🏛️ Master Hub: Cash Flow Analysis for Business Lenders: Best 📖 Guide: How to Analyze Business Bank Statements: 📖 Guide: Bank Statement Scrubbing Canada Market O
Related Articles in this Cluster (74)
External Authority Reference: CFPB Consumer Financial Protection Rules