Quick Answer: Key Takeaways

Compliance is a documentation discipline before it is a legal one. The execution standard is the 6 Document Pillars - consent, disclosure, verification, analysis, submission, and retention - each one collected, filed, and reviewable on demand. [R1][R2]

Questions This Guide Answers

  • What documents does a compliant MCA back office keep?
  • What are the 6 Document Pillars?
  • How do you build consent and disclosure trails?
  • What changes when work crosses the US-Canada border?
  • How do you stay audit-ready without an audit?
  • How do specialists keep documentation current?

Key Facts at a Glance

  • 6 Document Pillars: consent, disclosure, verification, analysis, submission, retention
  • Compliance is a habit with an owner, not a project
  • US and Canada rules differ; both require documented controls
  • Audit-readiness means any file, any time, full trail
  • Retention schedules turn storage into a policy
  • Specialist partners document controls and sign strict NDAs

Introduction

In alternative lending, compliance failures rarely start as legal problems - they start as documentation gaps. A missing signature, an unrecorded consent, an unfiled disclosure. The fix is not more lawyers; it is a documentation system that makes compliance automatic. [R1]

This guide lays out the documentation requirements that keep an MCA operation compliant - the pillars, the trails, and the habits - across the USA and Canada markets. [R1][R2]

Why Documentation Is the Backbone of Compliance

Regulators, funders, and auditors do not ask whether you were compliant - they ask whether you can prove it. Proof is documentation: what was collected, when, from whom, and what was done with it. [R1]

With DocumentationWithout Documentation
Audits are formalitiesAudits are fire drills
Funder questions answered in minutesFunder questions become deal delays
Consistency across the teamCompliance depends on who handled the file
Disputes resolved by the recordDisputes resolved by argument

Documentation turns compliance from a belief into a record. That record is what protects you when it matters. [R1][R3]

The 6 Document Pillars at a Glance

1. CONSENT Agreed purpose 2. DISCLOSURE Terms delivered 3. VERIFY Identity, docs 4. ANALYSIS Rulebook kept 5. SUBMIT Proof kept 6. RETAIN Scheduled
The 6 Document Pillars

Every file in your pipeline should be able to show all six pillars completed. If a pillar is missing, that file is a compliance gap - not a paperwork issue. [R1][R2]

Pillar 1: Consent

Consent documents what the merchant agreed to: the purpose of data collection, the use of their information, and the parties involved in the funding workflow. It is the foundation every other pillar stands on. [R1]

The Consent Trail

  • Signed consent captured before data collection begins
  • Purpose stated in plain language, not fine print
  • Third parties named - including outsourced processors
  • Timestamped record of when and how consent was given

In an outsourced model, consent flows down: your agreements with merchants, and your NDAs with partners, create the documented chain that compliance reviews look for. [R1][R4]

Pillar 2: Disclosure

Disclosure proves the merchant received the terms: rates, fees, payment structure, and rights. The document exists so that every party - and every future reviewer - can see exactly what was agreed. [R1]

Filed disclosures are what turn a he-said-she-said dispute into a closed file. The discipline is simple: deliver the disclosure, confirm delivery, and file the proof with the merchant's record. [R1][R3]

Pillar 3: Verification

Verification is the identity and document evidence behind the deal: merchant identification, business documents, and the bank statements that support the analysis. Each item is checked for authenticity and completeness at collection. [R1]

Verification failures are the most common finding in compliance reviews - and the most preventable with a checklist. [R1][R4]

Pillar 4: Analysis

The analysis pillar documents how the numbers were produced: the rulebook used, the calculations run, the risk flags raised, and the evidence behind each one. It makes the underwriting decision reviewable. [R1]

The Analysis Record

Every analysis follows the documented rulebook, and the record shows which rules applied to which figures - deposits, NSF events, negative days, and risk patterns - so any reviewer can reproduce the numbers from the file alone. [R1][R2]

Pillar 5: Submission

Submission documentation is proof of what was sent, where, and when: the portal or email, the documents attached, the recipient, and the confirmation. Submission without proof is submission that never happened, as far as a reviewer is concerned. [R1]

Submission RecordWhy It Matters
Funder and portal usedShows the file reached the right place
Documents attachedShows the package was complete
Timestamp and confirmationShows the SLA was met
Follow-up actionsShows the file was not abandoned

A submission log is also an operations tool - it reveals which funders respond fastest and where files stall. [R1][R5]

Pillar 6: Retention

Retention turns storage into a policy: what is kept, how long, where, and when it is destroyed. Without a schedule, files are either kept forever (a liability) or deleted arbitrarily (a risk). [R1]

A documented retention schedule is one of the cheapest, most visible signs of a mature compliance program. [R1][R4]

Cross-Border Compliance: USA and Canada

When work crosses the US-Canada border - and for any partner serving both markets - compliance must handle two rulebooks with one standard. [R1]

AreaUSACanada
Data protectionUS privacy framework, documented controlsStrict Canadian privacy expectations, consent-based
IdentityEIN / SSNSIN and business numbers
KYCUS AML postureCanadian AML expectations
DocumentsUS bank and ID formatsCanadian formats, bilingual norms

The winners run one documented standard that satisfies both - which is why cross-border funders rely on partners who already hold both standards. [R1][R5]

Audit-Readiness Without an Audit

Audit-readiness is a habit, not an event. The standard: any file, any time, full trail in minutes. Achieve it by making documentation part of the process instead of an afterthought. [R1]

Field Example - The Funder Who Passed an Audit by Accident

A funder with a sloppy documentation habit faced a surprise funder audit. Files were scattered across email, spreadsheets, and shared drives - the team spent a week reconstructing trails.

The fix: they adopted the 6 pillars: one place per file, consent and disclosure filed at intake, verification and analysis recorded, submission proof logged, and a retention schedule applied.

The result: the next audit took hours, not weeks - and the funder's audit rating improved.

The lesson: audit-readiness is a documentation system, and the system pays for itself in the first audit. [R5]

The quarterly habit: pick five random files, run the 6-pillar check, and fix what is missing. Five files a quarter keeps the whole operation honest. [R1][R4]

The Bottom Line

Compliance is documentation with a schedule and an owner. The 6 Document Pillars - consent, disclosure, verification, analysis, submission, and retention - make compliance a system instead of a hope. [R1]

If it is not documented, it did not happen.

Build the pillars, run the quarterly five-file check, and keep the standard current across both markets. The operation that proves compliance is the one that never has to argue about it. [R1][R5]

Frequently Asked Questions

What documents does a compliant MCA back office keep?
Six pillars: consent (what the merchant agreed to), disclosure (terms delivered), verification (identity and document evidence), analysis (the rulebook and calculations), submission (proof of what was sent), and retention (scheduled storage and destruction). Every file should show all six completed.
What are the 6 Document Pillars?
1) Consent - signed, timestamped, purpose stated, third parties named. 2) Disclosure - terms delivered and filed. 3) Verification - identity and documents checked at collection. 4) Analysis - rulebook and calculations recorded. 5) Submission - proof of send. 6) Retention - scheduled storage and destruction.
How do you build consent and disclosure trails?
Capture signed consent before data collection with the purpose in plain language and third parties named - including outsourced processors. Deliver disclosures, confirm delivery, and file the proof with the merchant record. The chain of agreements and NDAs creates the documented trail reviewers look for.
What changes when work crosses the US-Canada border?
Two rulebooks, one standard. Data protection expectations differ (both strict), identity documents differ (EIN/SSN vs SIN and business numbers), KYC posture differs, and document formats differ. Cross-border funders need partners who already hold both standards.
How do you stay audit-ready without an audit?
Make documentation part of the process, not an afterthought, and run the quarterly five-file check: pick five random files, verify the 6 pillars, fix what is missing. Audit-readiness means any file, any time, full trail in minutes.
How do specialists keep documentation current?
Specialist partners document their controls, follow the same 6-pillar standard on every file, keep retention schedules, and sign strict NDAs. Documentation discipline is part of the service - which is why their clients pass audits in hours, not weeks.

Conclusion

Compliance and documentation are the same discipline: proof. The 6 Document Pillars - consent, disclosure, verification, analysis, submission, and retention - turn compliance from a belief into a record any reviewer can follow. [R1]

Build the pillars into the process, run the quarterly check, and keep the standard current across the USA and Canada. With a specialist partner like Target Underwriting Solutions - documented controls, strict NDAs, cross-border fluency - the record is already in place the day you start. [R1][R5]

If it is not documented, it did not happen. Document everything that matters, and compliance stops being a risk. [R1]

BPO & OutsourcingComplianceDocumentationMCALendingAudit
EJ

About the Author: Eddie Jones

Eddie Jones is the Operations Director at Target Underwriting Solutions, bringing over 15 years of experience in MCA underwriting, bank statement analysis, and back-office operations across the US and Canadian markets. Connect on LinkedIn →

Why You Can Trust This Guide

This article is written by an operations practitioner, not a content writer. The frameworks and field examples come from live production work at Target Underwriting Solutions. Claims are cited to public sources ([R1]-[R6]) and our internal production experience. For client-specific questions, contact us for a confidential assessment.

References

  1. [R1] Deloitte Global Outsourcing Survey 2026 — www.deloitte.com
  2. [R2] SBA Office of Advocacy — Financial Services BPO Report — www.sba.gov
  3. [R3] Small Business Finance Association Report 2026 — www.sbfa.org
  4. [R4] IBISWorld BPO Industry Outlook — www.ibisworld.com
  5. [R5] Target Underwriting Solutions Case Studies — www.targetunderwriting.com
  6. [R6] BLS Occupational Outlook for Financial Underwriters — www.bls.gov

Ready to Outsource Your Underwriting & Back-Office Work?

Target Underwriting Solutions serves MCA funders, ISOs, and business lenders across the USA and Canada - the 6 Document Pillars on every file, documented controls, strict NDA, 48-hour onboarding.

Get a Free Consultation →

📚 Topical Authority Hub: Financial BPO & Operations Outsourcing Hub

This article is part of our structured knowledge base on Financial BPO & Operations Outsourcing Hub.

🏛️ Master Hub: BPO and Business Process Outsourcing: Best Pr 📖 Guide: BPO Services for Financial Companies: Be 📖 Guide: BPO Services Explained: Front-Office vs. 📖 Guide: Benefits of Outsourcing for Lending Comp
Related Articles in this Cluster (136)
External Authority Reference: Harvard Business Review Operations Strategy | Gartner BPO & Technology Reports