
One question under all the requests
An examiner's document request list looks like many questions. It is mostly one, asked repeatedly: who touched this file, and when? Who uploaded the final title policy, who accepted the insurance certificate and on what date, which version of the rent roll the credit decision relied on, who had access to the borrower's financials. Every line is a variation on custody and sequence.
That reframing matters because it tells you what actually gets tested at an exam, and it is not the quality of any single document. It is whether your operation can prove its own history. A file full of correct documents that cannot say who did what and when has not answered the question the examiner is really asking.
Why email structurally cannot answer it
Email feels like a record because it is chronological and searchable, which is exactly why it fools teams into relying on it. But email answers what was sent, not what was done. It cannot tell you who viewed a document, only who was copied on it. It fragments a single deal's history across every participant's inbox, so no one holds the whole record. And it has no concept of a document's status changing, so accepted and received look identical in a thread.
The result is that reconstructing the audit trail from email is a forensic project every time, and forensic projects produce gaps. The honest test: pick a loan that closed eighteen months ago and try to answer, in ten minutes, who accepted the insurance certificate and when. If the answer is a search across three inboxes and a phone call, the record is the inbox, and the inbox leaves when its owner does.
What a kept record looks like
A record that answers the question is not a heavier version of email; it is a different kind of thing. Every document lives against its checklist line. Every action, viewed, uploaded, edited, status changed, is logged with the actor and the timestamp as it happens. Access is scoped by party, so who could see what is demonstrable, not asserted. And the whole thing exports on demand, so producing it is a report rather than an archaeology dig.
The crucial property is that this record is built during the closing, as a byproduct of doing the work, not assembled for the exam. That is the difference between teams that spend a week per cycle reconstructing and teams that export. Prodeal logs every action across ten years and 56,000 deals for exactly this reason: the answer to who touched the file should already exist the moment it is asked.
Prodeal has logged every action across ten years and 56,000 commercial closings.
The system holding the file is in scope too
There is a second audit-trail question that has grown teeth: where does the record itself live, and can you get it out. Examiners increasingly treat the platform holding loan files as a third party subject to review, so the audit trail extends to the vendor's own controls and to your ability to export your record independently of them.
Two artifacts settle it. The provider's SOC 2 report, in the vendor file before anyone asks, since Prodeal is SOC 2 audited annually and its Type II report is available to customers. And a tested export path, because a record you cannot extract in usable form is a record you do not fully control. The audit-trail question, in the end, is a question about whether your operation remembers what it did, and remembering is a property of how you close, not a task you perform under deadline.
Questions lenders ask
- What is the audit-trail question examiners are really asking?
- Who touched the file and when: who uploaded, viewed, accepted, and approved each document, in what sequence. Most of a document request list is variations on custody and sequence, which is why the real test is whether an operation can prove its own history, not the quality of any single document.
- Why can't email answer it?
- Because email records what was sent, not what was done. It cannot show who viewed a document, it fragments one deal's history across every inbox, and it treats received and accepted as identical. Reconstructing an audit trail from email is a forensic project that produces gaps, and the record leaves when its owner does.
- How do you keep an audit trail that answers on demand?
- Build it during the closing: every document against its checklist line, every action logged with actor and timestamp, access scoped by party, and the whole record exportable. Then keep the provider's SOC 2 report on file and test the export path, since the platform holding the record is in scope too.
Sources and further reading
- The post-closing audit trailThe full guide to what examiners ask for.
- Security at ProdealSOC 2 Type II and the controls in detail.
- Prodeal's SOC 2 Type II report is availableHow to get the report for your review.
- Glossary: lender due diligenceThe review the record has to survive.
- What lenders check in a closing binderThe executed file, organized for the reader.