Client experience · 3 minute read
How to collect mortgage documents securely
A mortgage client onboarding checklist for clear requests, controlled access and review. Make secure document collection practical for clients and colleagues.
The useful bit
A secure upload route is one part of document collection. The request, access permissions, review step and retention arrangements need an owner too.
Who this is for: Mortgage firms reviewing how clients provide identity, income and case documents, including clients who need help with digital services.
Start with a real task
Morgan receives a general request for financial documents but is unsure which dates to include. Sam sends a precise list using the firm's approved route, explains who will review it and offers help if Morgan cannot use the portal. This example focuses on the process around a file, because technology alone does not establish whether collection is appropriate or access is controlled.
A routine you can adapt
-
Adviser or case manager
Request only what the case needs
Explain the document, period and purpose in plain language. Confirm requirements with the relevant case process before sending a generic checklist. Review the mortgage fact find process so information already provided is not requested again without a reason.
Keep: The specific request, its purpose and any agreed support.
-
Person sending the request
Check the route and the recipient
Use the firm's approved channel and confirm that the intended client can access it. Review how users sign in, how access is removed and who within the team can view files. Avoid putting sensitive document details in an unrestricted shared tracking list.
Keep: A record of the approved route and the people responsible for access reviews.
-
Reviewer
Separate upload from acceptance
Acknowledge receipt without implying the file has been approved. Check completeness, relevance and readability, then record the review outcome. If a replacement is needed, explain the precise gap and how to provide it.
Keep: Receipt, reviewer, date, outcome and any follow-up request.
-
Firm owner
Apply your retention and incident process
Decide which record is authoritative and manage working copies under your firm's retention schedule. Establish who handles a wrongly shared file or suspected breach. Review access after staff changes and periodically test whether the documented process works.
Keep: An approved retention schedule, access review and incident contact.
Filled example · fictional data
A mortgage client onboarding checklist
| Checkpoint | Practical question | Evidence to retain |
|---|---|---|
| Clear request | Does Morgan know which document and period are needed? | The request and any support agreed |
| Controlled access | Can only the intended people reach the file? | Access setup and review record |
| Review complete | Has someone checked the document, not just received it? | Named reviewer, outcome and next action |
The ICO's data security guidance describes technical and organisational measures appropriate to the risk. A portal can support your process, but it does not remove the need to assess access, staff practice and incident handling.
Free tools · no sign-up
Take it into your next review
Start with the completed example, or use the blank version with your firm's own information. CSV files open in Excel and other spreadsheet apps. Store any live case data in your firm's approved location.
One next step
Put it to work
Send a fictional request through your current route and ask a colleague to act as the client. Check the wording, permissions, support option and review handover before changing the live process.
Explore the Achos mortgage client portalThe product walkthrough illustrates the workflow. Your firm remains responsible for its advice, controls and decisions.
Request a demo