Treadstone Associates
Article · 12 min read

How do you collect documents from clients?

Generate one request list from the file rather than asking for things as you notice they are missing, send it through a channel you control, and let the reminders escalate on their own. The chasing is genuinely automatable. What is not is deciding what to ask for, verifying identity, and deciding what may be uploaded to a tool — because under TRESA confidential client information does not reach a third party without written consent, and an AI vendor is a third party.

Treadstone Associates · Updated 2026

Key takeaways

  • • Ask once, from a list generated by the file. Piecemeal requests are the main reason document collection drags.
  • • Identity verification has prescribed methods and prescribed fields; capture them as a form at the time, not from a photo later.
  • • FINTRAC expressly contemplates remote verification with document-authentication technology and a live or selfie comparison.
  • • PIPEDA limits collection to what is necessary, requires meaningful consent, and requires safeguards proportionate to sensitivity.
  • • Under designated representation, support staff must not pass client information to agents who are not designated representatives.

Document collection fails in a predictable way. The list is never written down, so it is discovered in fragments; each fragment arrives by a different channel; and by closing nobody can say with confidence what is held or where. Fixing the first problem fixes most of the rest.

Generate the list from the file

The request list is derivable. The transaction type tells you which identity records are needed. The agreement tells you which conditions depend on a document. The client type tells you whether corporate records are required — FINTRAC requires, where the client is a corporation, a copy of the part of the official corporate records containing the provisions relating to the power to bind the corporation for the transaction, which is a thing to ask for on day one, not the week of closing. The extraction step that produces most of this is described in reviewing the agreement of purchase and sale.

What a good request looks like

One list, one link, one deadline per item. Each item names why it is needed, which converts a chore into a reason.

A channel the brokerage controls. Not a personal email thread, and not a consumer file-sharing link nobody can revoke.

Escalating reminders tied to the dependency, the same way condition deadlines work in the deadline register.

A completeness view. What is received, what is outstanding, what was rejected and why.

A retention decision recorded at intake, so the disposal date is computed rather than debated later.

Identity documents are a special case

Identity verification is not document collection; it is a regulated procedure with prescribed methods. Under the government-issued photo identification method, FINTRAC requires you to record the person’s name, the date you verified their identity, the type of document, its unique identifying number, the issuing province or state and country, and the expiry date where it appears, and requires the document to be authentic, valid and current. The credit file method and the dual-process method each prescribe their own recorded fields.

Remote verification is permitted and the regulator describes how. FINTRAC allows the photo identification method where the person is not physically present, provided you have a process to authenticate the document — for example technology that compares its security features such as holograms, barcodes and watermarks — and a process to satisfy yourself the document is valid and current and that the name and photo belong to the person, such as a live video comparison or applying facial-recognition comparison to a selfie. Note what that is and is not: the technology authenticates and compares. A person is still satisfying themselves, and the record is written in their name. Our sister law firm explains why the same client is asked to verify identity again on the legal side of the transaction, which saves an awkward conversation.

Privacy sets the limits on what you ask for

PIPEDA governs personal information collected in the course of commercial activity, and the Office of the Privacy Commissioner summarises the obligations: obtain consent when you collect, use or disclose personal information, collect it by fair and lawful means, and only for purposes that a reasonable person would consider appropriate in the circumstances. The OPC’s consent guidance sets a practical bar — consent is only meaningful if individuals understand what they are agreeing to, which means highlighting what is collected, who it is shared with, and the residual risk of harm. And its safeguards guidance requires protection appropriate to the sensitivity of the information, through physical, organisational and technological measures. A driver’s licence and a mortgage approval are at the sensitive end.

Two design consequences follow. Do not collect what the file does not need — a full credit report where a name and date of birth would do is a liability, not diligence. And do not leave collected documents in the channel they arrived through; move them into the file, then remove them from the inbox.

Who inside the brokerage may see the file

This is where TRESA is stricter than most brokerages assume. Under designated representation, RECO states that only the designated representatives named in the agreement may access confidential information about the clients they represent, that the designated representative must not disclose it to any other agent employed by the same brokerage or to any other person unless authorised by the client or required by law, and that the brokerage must ensure administrative or support staff with access to client files do not share client information with agents who are not designated representatives. The duty also does not end with the file: even after the client relationship ends, brokerages and agents must continue to protect and safeguard the client’s information. Access permissions in a document system are therefore a compliance control, not an IT preference.

What may be uploaded to a tool

The threshold question, and the one to settle before a pilot rather than during it. Under TRESA, confidential client information may not be disclosed to a third party without the client’s written consent unless disclosure is required by law, and RECO specifies that the consent must identify what will be disclosed, who receives it, the purpose, and who benefits. BCFSA states the operating rule for licensees: always ensure you have acquired your clients’ informed consent before using their information in an AI tool, and unless you are certain a tool does not store or utilise user data, avoid entering any confidential or personal information into it. It also warns against relying on anonymisation, because data from different sources can be matched to identify an individual.

CREA gives the vendor questionnaire: how the system collects, uses and discloses personal information, whether it is stored in Canada, whether uploaded content is disclosed to third parties or used to train the system for other users, who owns uploaded and generated data, and what warranties and indemnities the contract carries. Canada’s privacy commissioners have also published joint principles for responsible, trustworthy and privacy-protective generative AI that are worth reading alongside it.

In practice the safe pattern is narrow: classification and completeness checking on documents inside a system the brokerage controls, with no client-identifying content leaving it, and no general-purpose consumer chatbot in the path.

A worked example

The following is illustrative — a composite of how the workflow is usually assembled, not a measured result.

A file opens. The system generates a request list of nine items from the transaction type, the agreement and the client type, each with a reason line and a due date derived from the condition it supports. The client receives one link. Uploaded documents are classified on arrival, checked for legibility and for the presence of expected fields, and either accepted into the file or bounced back with a specific reason.

Identity verification runs as its own step: the document is authenticated, a live comparison is done, and six named fields are written to the identity record by the person conducting it. Nothing about that step is inferred from an image after the fact.

Three days before any condition deadline that depends on an outstanding document, the reminder escalates from the client to the agent to the transaction coordinator. At closing, a retention rule computes a disposal date per document type from its stored start event, and the inbox copies are removed.

Common questions

Can we use a consumer file-sharing link for client documents?

It is the wrong shape for the obligation. The OPC expects safeguards appropriate to the sensitivity of the information, and a link that cannot be revoked, audited or scoped to named recipients is difficult to defend for identity documents and financial records. Use something the brokerage administers.

May an assistant chase documents on a designated-representation file?

They may perform administrative tasks with access to the file, but the sharing constraint stands: support staff must not share the client’s information with any agent employed by the brokerage who is not a designated representative for that client. Configure the permissions to match the representation agreement, and revisit them when a team changes — see onboarding an agent.

How long do we keep everything?

Per document type, from a stored start event. FINTRAC records are generally kept five years, with the start point depending on the record, while income tax records run six years from the end of the last taxation year to which they relate. The detail is in FINTRAC record keeping for real estate and commission tracking.

See where AI pays off first in your business.

A 30-minute call is enough to tell you whether AI pays for itself here.