Key takeaways
- →Reviews are generally triggered one of three ways: a routine cyclical examination, a complaint-driven investigation, or a random file sample — and the first two look very different from a broker's perspective.
- →A regulator doesn't usually ask for “everything” — it asks for a defined sample of files and expects the full record for each one, producible on a set timeline.
- →The most common finding in a review is a documentation gap, not misconduct — disclosure that happened but wasn't recorded, a suitability rationale that lived only in the broker's memory.
- →Being ready for a review is mostly a matter of running your own version of it before the regulator does, on a schedule rather than reactively.
“Compliance audit” sounds like an event that happens to unlucky brokerages. In practice, every licensed mortgage professional in Canada operates under a regulator that can, and does, ask to see files — the only real variable is whether the request finds a well-organized file or a reconstruction project.
Here's the general shape of what that request typically looks like, framed as a practitioner playbook rather than a claim about any single regulator's exact internal checklist, since the specifics differ by province and by the nature of the review.
01 · What actually triggers a compliance review?
Three broad triggers cover most reviews: a routine, cyclical examination that isn't tied to any specific concern; a complaint or tip that prompts a targeted look at a specific broker, file, or practice; and a random or risk-based sample pulled as part of the regulator's ongoing supervision of the sector.
The first and third feel procedural — a request for files, a deadline to respond, no accusation attached. A complaint-driven review is different in tone from the start, because it's already anchored to a specific concern rather than a general spot check.
02 · Does a regulator actually ask for every file you've ever handled?
Almost never. A typical review asks for a defined sample — a set number of files from a given period, sometimes selected at random and sometimes targeted toward a particular product type or risk category. The expectation for each file in the sample, though, is the complete record: application, disclosure, suitability rationale, identification and beneficial ownership documentation where applicable, and the communications connected to the file.
This is where the record-keeping obligations covered in our piece on record retention actually get tested — a file that can be produced complete and on time reads very differently to a reviewer than one assembled under time pressure with visible gaps.
03 · What does a reviewer actually check for in a sampled file?
Across the provincial frameworks, the categories a review typically checks are consistent even where the specific rules differ:
- →Whether required disclosures were made, in writing, and on time — not just that a form exists somewhere in the file.
- →Whether the suitability rationale for the product recommended is documented, not just implied by the outcome.
- →Whether client and, where applicable, beneficial ownership identification was completed and recorded using an accepted method.
- →Whether any conflicts of interest — ownership ties, referral relationships, related-party involvement — were disclosed in writing before the client committed.
- →Whether supervision requirements were met — evidence that a Principal Broker or equivalent actually reviewed the file, not just that a supervisory role technically exists.
04 · What kinds of things actually show up as findings?
The recurring pattern across compliance reviews generally isn't misconduct — it's a documentation gap. A disclosure that was genuinely given verbally but never recorded. A suitability decision that was reasonable but exists only in the broker's memory rather than on the file. A record that technically exists but takes days to locate rather than minutes.
That distinction matters practically: the broker who made the right call but didn't document it is in a materially worse position during a review than one might expect, because a reviewer can only evaluate what's actually on the file.
05 · How do you actually get ready for a review before it happens?
Run your own version of the review, on a schedule, rather than waiting to find out what a regulator would ask for. Our brokerage file audit checklist walks through the same categories a real review checks, applied to a self-selected sample of your own recent files. Pairing that with a standing compliance calendar keeps the habit from lapsing once the initial setup is done.
Files ready before anyone asks
Run your own review before a regulator runs theirs.
Treadstone's fulfillment associates build the documentation a review actually checks into the file from day one — disclosure, suitability, identification, all dated and retrievable. Talk to us about what that looks like.
06 · What typically happens after a review turns up a gap?
Most regulators distinguish between minor, correctable gaps and more serious conduct issues, and respond proportionately — a corrective action plan and a follow-up timeline for the former, more formal discipline for the latter. The distinction usually comes down to whether the underlying conduct was sound and only the documentation was missing, or whether the conduct itself was the problem — which is exactly why the file notes and disclosure habits covered elsewhere in this series matter as much for what they prove later as for what they accomplish at the time.
Frequently asked questions
This article is general information to help you scale — not a substitute for tailored advice on your specific business, licensing, or compliance obligations. All figures are illustrative examples for planning purposes; actual costs vary by province, market, and brokerage.