Compliance

The audit trail question.

An examiner's request list keeps asking who touched the file and when. What a loan file audit trail records, what makes it trustworthy and how to test your own.

Updated September 15, 2026 · 8 min read · By the Prodeal team
Flat editorial illustration of scattered documents resolving into an ordered stack

The short answer

A commercial loan file audit trail shows who uploaded, viewed, changed, approved or shared each document, and when, in the order it happened. It also shows who had access to the file at each point. Examiners and auditors use it to confirm that required steps happened in sequence and that access to borrower information was controlled.

A trustworthy trail is recorded by the system as the work happens, kept complete for the life of the loan and exportable on request. A trail rebuilt from inboxes after the fact has gaps.

What question sits under an examiner's request list?

A request list looks like dozens of questions. Most of them ask about custody and sequence. Who uploaded the final title policy? Who accepted the insurance certificate, and on what date? Which version of the rent roll supported the credit decision? Who could see the borrower's financial statements?

Each answer proves a control worked. The FDIC's Risk Management Manual lists what loan reviews typically analyze, including the sufficiency of credit and collateral documentation, proper lien perfection, proper loan approval and compliance with internal policies. Every one of those depends on showing what happened and when.

A file full of correct documents still fails that test when it cannot say who did what, in which order.

What should a loan file audit trail record?

Each event in a useful trail carries the same fields.

Fields in a loan file audit trail event
FieldWhat it capturesWhy a reviewer needs it
ActorThe named user, internal or external, who took the actionTies each step to a person with a role
ActionUpload, view, download, edit, status change, approval, share, permission changeShows what happened, beyond who was copied on an email
ObjectThe document, checklist item or deal the action touchedLinks the event to the requirement it satisfied
TimestampDate and time, recorded by the systemProves sequence, such as appraisal review before approval
VersionWhich version of the document the action applied toShows which rent roll or report the decision relied on
Access stateWho could see the item when the event occurredDemonstrates controlled access to borrower information

What do examiners and auditors use the trail for?

  • Sequence
    The appraisal and its review came before the credit decision, and insurance was in force at funding.
  • Approval
    The person who approved the loan held the authority, and approved the terms that appear in the documents.
  • Completeness
    Every condition in the approval has a document that satisfied it and a record of who accepted that document.
  • Access
    Borrower financials and credit memos stayed with the people who needed them.
  • Consistency
    Files sampled from the portfolio follow the same standard, so the controls look the same on every loan.

Which events matter most in a loan file trail?

Reviewers read a small set of events closely. Make sure the system captures each one with the actor and the time.

High-value audit trail events
EventWhat it proves
Credit approval recordedWho approved, with what authority, and on which terms
Appraisal review completedThe value was reviewed before the credit decision
Condition acceptedA named person accepted the document that satisfied each condition
Insurance evidence acceptedConforming coverage existed on the funding date
External access grantedWhich outside party could see which items, and from when
Document replacedWhich version was current when a decision relied on it
Post-closing item receivedRecorded documents and the final title policy arrived and were reviewed

What makes an audit trail trustworthy?

A trustworthy trail is written by the system as the work happens. People doing the work have no way to edit or delete its entries, so the record carries weight with a reviewer who never met them.

It is complete. Every action on every document shows up, including views and permission changes, which are the events an email archive leaves out.

It is attached to the requirement. An event that says a document was uploaded against the insurance condition answers a reviewer's question directly, while an upload to a shared folder still needs someone to explain what it was for.

It is exportable. A reviewer asks for a report, and the lender produces it the same day in a format the reviewer can read.

How does an audit trail differ from a closing binder?

A closing binder shows what the loan file holds at the end: the executed documents, organized for reference. An audit trail shows how the file got there: every upload, review, acceptance and access change, in order.

Reviewers use both. The binder answers whether a document exists. The trail answers whether it arrived in time, who accepted it and who could see it. A binder with no trail leaves the sequence questions open, and a trail with no binder makes the final documents hard to find.

How long does the trail need to last?

The trail needs to last as long as the loan and the lender's record retention policy require. A reviewer may sample a loan years after closing, and participations, loan sales and litigation can all call for the history long after the closing team has moved on.

Durability tests the storage choice. A trail kept in individual mailboxes shrinks every time an employee leaves or an archive policy runs. A trail kept in the system that holds the deal stays with the loan.

Is the system holding the file in scope?

Yes. Federal banking agencies issued final interagency guidance in June 2023 on managing risks from third-party relationships, including relationships with financial technology companies. A platform that stores loan files and their audit trail is one of those relationships.

Two artifacts settle most questions. The provider's SOC 2 report, kept in the vendor file before anyone asks for it, and a tested export path that produces the full record independently of the vendor's interface.

Prodeal holds a SOC 2 report, encrypts data with TLS 1.2 in transit and AES-256 at rest, stores each customer's files in a separate bucket with its own key, and exports activity logs as CSV for security monitoring tools.

Why does an email archive leave gaps in the trail?

Email records messages. It shows who sent an attachment to whom, and it holds no record of who opened a document, which version became final or when a document was accepted. A single deal's history spreads across every participant's mailbox, and the lender controls only its own.

Reconstructing a trail from email becomes a project each time a reviewer asks, and projects built from partial evidence produce partial answers.

Who should have access to the audit trail?

Compliance, internal audit and credit administration need the full trail for any loan. Deal team members need the trail for their own deals. Outside parties, such as borrower's counsel or a title company, generally see only their own activity.

Examiners receive exports. Producing a clean report per sampled loan keeps the conversation on the evidence and away from walkthroughs of internal systems.

How do you test your own audit trail?

Pick a loan that closed more than a year ago and give yourself ten minutes. Answer who accepted the insurance certificate and when, which rent roll version supported the credit memo, and who had access to the sponsor's financial statements during the closing.

Answers that come from a report mean the trail works. Answers that need three mailbox searches and a phone call mean the trail lives in people, and it leaves when they do. Run the same test on a sample of files each quarter and fix what it finds.

How do teams build the trail without extra work?

They close on one record. Documents arrive against checklist lines, statuses change inside the system, approvals happen where the documents live, and outside parties work in the same room under scoped permissions. The trail accumulates as a byproduct.

Prodeal logs each action with the actor and time, ties documents to checklist items, and produces an activity report on request. TruStone Financial cut daily servicing email by 75% after moving its commercial closings onto that model.

75%
less daily servicing email

TruStone Financial, Prodeal case study.

Questions lenders ask

What is an audit trail in commercial lending?
An audit trail is the time-stamped record of every action taken on a loan file: who uploaded, viewed, changed, approved or shared each document, and who had access at each point. Examiners and auditors use it to confirm that required steps happened in order and that access was controlled.
What do examiners look for in a loan file audit trail?
They look for proof of sequence, such as appraisal review before approval; proof of approval authority; a document and acceptance record for each condition; controlled access to borrower information; and consistency across the sample of files they pull.
Why is email a weak audit trail?
Email records who sent a message to whom. It holds no record of who viewed a document, which version became final or when a document was accepted, and each deal's history spreads across many mailboxes, including ones the lender does not control.
How long should a loan audit trail be kept?
Keep it for the life of the loan and as long as the lender's record retention policy requires after payoff. Reviewers sample older loans, and participations, loan sales and disputes can require the history years after closing.
Does a lender need its software vendor's SOC 2 report?
Lenders manage the software that holds loan files as a third-party relationship, and interagency guidance issued in 2023 covers that risk. Keeping the vendor's SOC 2 report in the vendor file answers the most common questions about the platform's controls.
What makes an audit trail tamper-resistant?
The system records each event automatically as it happens, and users cannot edit or delete entries. That design gives the record weight with reviewers who never met the people doing the work.
How can a lender check whether its audit trail works?
Take a loan that closed more than a year ago and try to answer, in ten minutes, who accepted a specific document, which version supported the credit decision and who had access during the closing. If the answers come from a report, the trail works.
The Prodeal team
Written by the team behind Prodeal, the closing platform commercial lenders have run for ten years and 56,000 deals. This library is drawn from that record: what actually holds up closings, and what examiners and auditors actually ask for.
Keep reading
Ready when you are

See your deals in real time.

Send us one live deal. We will build the room on your own checklist.