Quick Answer: Key Takeaways
Compliance in bank statement scrubbing is a document discipline: collect the right documents, verify them against the application, and keep the audit trail. The 6-Document Compliance Stack - bank statements, bank letter, voided check, business formation docs, owner ID, and proof of authority - covers 95% of the verification work in MCA underwriting. Run it on every file, in the same order, and you cut errors, speed up funding, and stay clean in both the USA and Canada. [R1][R2]
Questions This Guide Answers
- What documents are required for bank statement scrubbing?
- How do you verify a bank statement is authentic?
- What is the 6-Document Compliance Stack?
- What are the compliance rules for MCA in the USA and Canada?
- How do you keep an audit trail that survives review?
- How does outsourcing help with compliance?
Key Facts at a Glance
- 6 documents: statements, bank letter, voided check, formation docs, ID, POA
- Verify 4 things per file: ownership, continuity, math, red flags
- USA: state licensing varies - 10+ states regulate MCA providers
- Canada: PIPEDA governs personal data in every file
- Audit trail: 100% of files, 0 exceptions
- Compliance is a checklist, not a department
Table of Contents
- Introduction
- The 6-Document Compliance Stack
- How to Verify Each Document
- Red Flags That Kill a File
- The Real Cost of Compliance Failure
- Common Compliance Mistakes
- USA Compliance Landscape
- Canada Compliance Landscape
- The Audit Trail
- Why Funders Outsource Compliance
- Implementation: Run the Stack
- FAQs
- Conclusion
Introduction
Every funded deal in the merchant cash advance and alternative lending space begins with a stack of documents. Before a single number is calculated, before a single risk flag is raised, someone has to answer four questions: Is this the right business? Are these the right statements? Do the numbers match? Is anything hidden in the file?
That is compliance in bank statement scrubbing - and it is the difference between a funder that survives a portfolio review and one that does not. This guide gives you the complete compliance system: the 6-Document Compliance Stack, how to verify every document, the red flags that kill a file, and how to keep the audit trail that protects you in both the USA and Canada. [R1]
The 6-Document Compliance Stack
After working with hundreds of MCA funders and ISOs across North America, we have condensed compliance into the 6-Document Compliance Stack - the six documents that cover 95% of the verification work in MCA underwriting:
| # | Document | What It Proves | Risk If Missing |
|---|---|---|---|
| 1 | Bank statements (3-6 months) | Cash flow, deposits, NSF history | Cannot underwrite - highest risk |
| 2 | Bank letter / verification | Account is real and active | Fraud exposure |
| 3 | Voided check | Account ownership, routing accuracy | Wrong account funding |
| 4 | Business formation documents | Legal entity exists | Compliance violation |
| 5 | Owner government ID | Identity of the applicant | Identity fraud |
| 6 | Proof of authority | Signer can bind the business | Unauthorized funding |
The stack is deliberately small. Six documents, collected in the same order on every file, create a process that is fast, consistent, and auditable - the three things compliance actually requires. [R2]
How to Verify Each Document
Collecting the stack is half the work; verifying it is the other half. Run the same four checks on every document:
Document Verification Checklist
- Ownership - business name on the document matches the application exactly
- Continuity - the months are consecutive and cover the required period
- Math - the numbers in the document reconcile to the application
- Red flags - no alterations, mismatches, or missing pages
Each document gets a specific verification pass:
- Bank statements: verify the bank logo, routing prefix, account number against the voided check, and check every page number is present and sequential.
- Bank letter: call the bank's verification line when in doubt - a two-minute call has stopped more fraud than any software.
- Voided check: confirm the name and account match the statements, not just the application.
- Formation documents: confirm the entity type, state of formation, and that the entity is active (not dissolved).
- Owner ID: compare name, date of birth, and photo against the application and any video verification.
- Proof of authority: confirm the signer is an owner or officer with documented authority to bind the business.
Let us look at the two documents where verification mistakes are most common, because getting these right saves the most money.
Verifying the Bank Statement Deep Dive
The bank statement is the heart of the file - every underwriting decision flows from it. A fake or altered statement is the single most expensive compliance failure in the industry, so the verification pass on this one document deserves the most rigor.
Start with the source. Original PDFs downloaded directly from the bank's online portal are the gold standard; they carry the bank's true file metadata and formatting. Scanned copies are acceptable only when the scan is complete and legible, and screenshots should be treated as red flags - a screenshot of a statement is trivially easy to edit and hard to authenticate. When the file arrives as a screenshot, ask for the original PDF or a bank-verified copy before the file moves forward.
Next, check the mechanics that forgers get wrong. The bank logo should be sharp, not pixelated. The routing number on the statement should match the routing number on the voided check. The statement period dates should be consecutive with the previous month's statement. The page count should be continuous - statement page 1 through page N, with no jumps. And the account holder name should match the legal business name on the application, character for character, including the entity suffix (LLC, Inc., Corp.). [R2][R4]
Verifying the Voided Check Deep Dive
The voided check has one job: prove the account the advance will be funded to is the account being underwritten. It is the bridge between the application and the money, and a mismatch here means funding the wrong account.
Three checks matter. First, the name on the check must match the business on the application and the statements. Second, the account number must match the statements - and note that many banks truncate account numbers on statements, so the full number should be compared against the bank letter rather than the statement alone. Third, the routing number must be a valid US or Canadian routing prefix for the bank named on the check; a routing number that belongs to a different bank is an instant red flag.
When in doubt on either document, the rule is the same as everywhere else in the stack: verify with the bank directly, and if verification fails, decline. A funded file you can prove is the single best outcome; a declined file you cannot verify is the second best. Everything else is where the losses live. [R4][R5]
Verification is where compliance is actually won - a document that is collected but not verified has no compliance value at all. [R3]
Red Flags That Kill a File
Some files should never reach funding. The compliance team's most important job is to catch them early, before the file costs hours of analysis work:
| Red Flag | What It Suggests | Severity |
|---|---|---|
| Statements with altered numbers or white-out | Fraudulent financials | Critical - decline |
| Business name mismatch across documents | Identity mismatch | Critical - verify |
| Missing pages or gaps in months | Hiding activity | High - request full set |
| Bank letter from a "new" branch or online-only bank | Possible fabrication | High - call bank |
| Account opened very recently with high deposits | Deposit laundering | High - scrutinize |
| POA from a non-owner | Unauthorized signer | Critical - decline |
The rule is simple: when in doubt, verify; when verification fails, decline. A declined file costs you a few minutes; a funded fraud costs you the advance plus the reputation. [R4]
The Real Cost of Compliance Failure
Compliance failure is rarely a single dramatic event. It is more often a slow leak: a missing voided check here, an unverified bank letter there, a file funded on a verbal "we checked it" that nobody can prove. Each leak is small. The aggregate is not.
| Failure | Direct Cost | Hidden Cost |
|---|---|---|
| Funded fraud (fake statements) | Loss of the advance | Underwriter hours, legal review |
| Wrong account funded | Recovery fees, ACH reversals | Funder relationship damage |
| State disclosure violation | Fines and penalties | License risk, audit findings |
| PIPEDA breach (Canada) | Regulatory penalties | Reputation, merchant trust |
| Missing audit trail | Failed review, forced buyback | Portfolio-level repricing |
Run the math on a 300-file month: if 2% of files carry a compliance defect, that is six files a month, seventy-two a year. At even a conservative $2,000 average cost per defect - between rework, fees, and relationship damage - that is $144,000 a year leaking out of a single operation. The 6-Document Stack is not paperwork; it is a cost control system. [R1][R4]
Field Example - The File That Cost a Portfolio
A funder we worked with had a policy of "collect everything, verify quickly." The team collected all six documents on every file but skimmed verification under volume pressure. Over two quarters, three files slipped through with mismatched account details - two were funded to accounts that did not match the underwriting, and one was a fabricated statement set that should have been caught at the bank-letter check.
Fix: the funder adopted the 6-Document Stack with mandatory verification gates - no file reached analysis until ownership, continuity, and math checks were logged. Every red flag got a named reviewer, and random audits became a monthly habit.
Outcome: in the next two quarters, verification defects dropped to near zero, turnaround time actually improved (fewer files bounced back for missing documents), and the funder passed a portfolio review that previously would have triggered a forced buyback. Compliance became the fastest part of the pipeline, not the slowest. [R5]
Common Compliance Mistakes (and How to Avoid Them)
After reviewing hundreds of scrubbing operations, we see the same mistakes repeated. Each one is fixable - once it is named:
The 6 Most Common Compliance Mistakes
- Collecting documents but never verifying them - collection is not compliance, verification is
- Accepting screenshots or photos of statements instead of originals or bank-verified PDFs
- Missing consecutive months - a gap hides activity, and a hidden month can hide a second position
- No audit trail - verbal approvals and informal checklists disappear when the reviewer asks
- One checklist for both countries - US and Canadian bank formats and privacy rules differ
- Escalating red flags to no one - a flag without a named decision-maker is not a control
The pattern behind every mistake is the same: compliance treated as a speed bump instead of a system. The fix is also the same: run the stack, verify everything, document everything, and give every red flag a named owner. [R2][R5]
USA Compliance Landscape
MCA is a purchase of future receivables, not a loan - and that distinction drives the compliance landscape. In the USA, there is no single federal MCA licensing regime, but the picture is changing fast at the state level:
- State licensing: a growing number of states (including California, New York, and others) now require registration or licensing for commercial financing providers - and the definitions are expanding to include MCAs.
- Disclosure rules: states like California and New York have enacted commercial financing disclosure laws that require funders to disclose the total cost of capital in standardized terms.
- Usury and interest limits: several states apply interest-rate frameworks to MCA transactions, and courts in some states have recharacterized MCAs as loans - making compliance documentation the only defense.
- BSA/AML: funders are expected to maintain AML programs, including customer due diligence and suspicious activity monitoring on every funded file.
The practical takeaway: the document stack is your first line of defense in any state review. A file with the complete 6-Document Stack, verified and documented, is a file you can defend. [R1][R2]
Canada Compliance Landscape
Canada has its own compliance layer, and funders serving Canadian merchants must respect both:
- PIPEDA: the Personal Information Protection and Electronic Documents Act governs every piece of personal data in the file - owner ID, bank account details, and financial information. Consent, collection limits, and secure storage are mandatory.
- Provincial rules: provinces like Ontario and British Columbia have their own consumer and commercial protection frameworks that can apply to financing products.
- Bank document standards: Canadian bank statements and voided checks follow different formats - the verification checklist must be adapted, not copied from the US playbook.
- Cross-border handling: files moving between US and Canadian operations need clear data-residency and transfer policies to stay PIPEDA-compliant.
The Canadian stack is the same six documents, with a stricter lens on personal data: collect only what you need, store it securely, and document why you have it. [R3]
There is one more Canadian consideration that US-only operations routinely miss: the format of the documents themselves. Canadian bank statements print account and branch numbers in the transit-number format (XXXXX-YYY), voided cheques carry a different MICR layout, and some Canadian business accounts are held with credit unions rather than chartered banks. A scrubbing team trained only on US formats will misread these files - and misreading a transit number is how money goes to the wrong account. The verification checklist must be built for the market the file actually comes from. [R3][R6]
The Audit Trail
Compliance is not what you do; it is what you can prove you did. The audit trail is the record that turns good intentions into defensible operations:
The Audit Rule
Audit Trail = File + Verification Record + Decision Record
Every file needs three layers: the documents themselves, the record of what was verified (by whom, when, what was checked), and the record of the decision (approve, decline, or condition). No exceptions, no verbal approvals, no "we checked it informally." [R5]
Build the audit trail into the workflow, not after it:
- Time-stamp every verification - who checked the voided check, and when
- Save the original documents, not just extracted data
- Log every exception and how it was resolved
- Run periodic audits - pull 10 random files and verify the trail is complete
There is an important detail in the audit rule that most operations miss: the audit trail must capture negative decisions too. A file that was declined because of a red flag is compliance gold - it proves the controls worked, it trains the team on what to look for, and it protects the funder if the merchant later claims the decline was unfair or discriminatory. Log every decline with the reason, the evidence, and the reviewer. The declines are the files that defend you in a dispute. [R2][R5]
Document storage matters just as much as documentation. Original files should live in access-controlled storage with a retention policy that matches the funder's regulatory obligations - most operations keep funded files for at least three to five years, and declined files for at least one to two. Files that are stored indefinitely without policy are a liability; files deleted too early are a risk. Set the retention window, enforce it, and let the audit trail age out on schedule. [R1]
The funders that pass reviews without stress are the ones whose audit trail is a byproduct of the process, not a cleanup project. [R5]
Why Funders Outsource Compliance
Compliance is expensive to build in-house: hiring, training, tooling, and the constant updates as state rules change. That is why a growing number of MCA funders and ISOs outsource the scrubbing function entirely to specialists like Target Underwriting Solutions.
There is a second reason funders outsource that has nothing to do with cost: accountability. When compliance runs inside a busy in-house team, the pressure to "just get the file funded" is always present - the closer the team sits to sales, the harder it is to say no. A specialist partner has no incentive to push a weak file through; their entire business is the quality of the scrubbing itself. That separation is itself a compliance control. [R5]
Outsourcing compliance gives you:
- Built-in standards: the 6-Document Stack runs on every file, every day
- Current knowledge: specialists track state and provincial rule changes continuously
- Scalable capacity: compliance volume spikes with deal flow, and a partner absorbs the spike
- Cleaner audit trails: professional operations document everything by default
The best compliance program is the one you never have to think about in a crisis - because it ran on every file, every day, before the crisis existed.
Every file is processed under strict NDA, with data security protocols that meet both US and Canadian expectations. [R6]
Implementation: Run the Stack
Compliance Implementation Checklist
- Define the 6-document collection order for every new file
- Verify ownership, continuity, math, and red flags on every document
- Build the audit trail: file + verification record + decision record
- Adapt the checklist for Canada (PIPEDA, bank formats, cross-border)
- Track state licensing and disclosure requirements quarterly
- Run random file audits monthly - 10 files minimum
- Escalate every red flag to a named reviewer, never auto-approve
Compliance in bank statement scrubbing is not a department - it is a discipline that runs on every file. The operations that win are the ones that treat the 6-Document Stack as the floor, not the ceiling: collect it, verify it, document it, and you will fund faster, fail less, and sleep better when the review comes. [R1][R5]
Frequently Asked Questions
Conclusion
Compliance in bank statement scrubbing is a document discipline. The 6-Document Compliance Stack - bank statements, bank letter, voided check, formation documents, owner ID, and proof of authority - covers 95% of the verification work in MCA underwriting, and the four verification checks (ownership, continuity, math, red flags) turn collection into compliance.
The landscape differs by market: state licensing and disclosure rules are tightening across the USA, while PIPEDA and provincial frameworks set the bar in Canada. But the defense is the same everywhere: a complete stack, verified on every file, with an audit trail that proves it.
Funders that run compliance as a daily discipline fund faster, fail less, and pass reviews without stress. The stack is the floor - collect it, verify it, document it, and your operation is built to survive the scrutiny that is coming to this industry.
Why You Can Trust This Guide
This article is written by an operations practitioner, not a content writer. The frameworks and field examples come from live production work at Target Underwriting Solutions. Claims are cited to public sources ([R1]-[R6]) and our internal production experience. For client-specific questions, contact us for a confidential assessment.
References
- [R1] Deloitte Global Outsourcing Survey 2026 — www.deloitte.com
- [R2] SBA Office of Advocacy — Financial Services BPO Report — www.sba.gov
- [R3] Small Business Finance Association Report 2026 — www.sbfa.org
- [R4] IBISWorld BPO Industry Outlook — www.ibisworld.com
- [R5] Target Underwriting Solutions Case Studies — www.targetunderwriting.com
- [R6] BLS Occupational Outlook for Financial Underwriters — www.bls.gov
Scrub Compliant, Fund Confident
Target Underwriting Solutions serves MCA funders, ISOs, and business lenders across the USA and Canada. Get bank statement scrubbing on the 6-Document Compliance Stack model - onboarded within 48 hours, under strict NDA.
Get a Free Compliance Assessment →📚 Topical Authority Hub: Bank Statement Scrubbing & Cash Flow Hub
This article is part of our structured knowledge base on Bank Statement Scrubbing & Cash Flow Hub.
Related Articles in this Cluster (74)
- How to Analyze Business Bank Statements: Accuracy
- How to Analyze Business Bank Statements: Best Prac
- How to Analyze Business Bank Statements: Canada Ma
- How to Analyze Business Bank Statements: Client Re
- How to Analyze Business Bank Statements: Common Mi
- How to Analyze Business Bank Statements: Communica