Broker guide
Document Collection for Mortgage Broker Files 2026
To gather complete borrower evidence without email attachments, compare document collection software and portals for requests, review and tracking.
- Published
- Updated
Document collection for a mortgage broker file works best as one secure portal request for each client. Build that request from the lender’s document checklist, then check each upload before it reaches assessment. Email attachments leave copies of payslips and identity documents in inboxes, with no record of what was requested, replaced or accepted.
Start once the fact find is complete, because the request list comes from the client’s income, borrowing entity and loan purpose. You also need the target lender’s current document checklist and a portal that records each upload, reminder and review decision. The steps below suit a broker or broker assistant preparing a residential home loan file.
Turn Requirements Into Requests
Turn the fact find into a request list by matching each applicant’s income type, borrowing entity and loan purpose to the documents the target lender asks for. Give every requested item the lender condition it supports, so the client sends only what the file needs.
Lenders publish different lists. Westpac’s minimum required documents checklist for brokers, as at October 2026, starts with a section every application must complete. It then adds sections by income type, liabilities and loan purpose.
- Start with the documents every application needs. Westpac’s mandatory section asks for a signed privacy acknowledgement and consent form, identity verification and rates notices for properties it doesn’t already hold as security. It also asks for every tax file number to be removed from the documents.
- Add income documents for each applicant. A pay as you go (PAYG) employee, a casual worker and a self-employed borrower each need a different set, even when they apply together.
- Add entity documents. A trust or company borrower adds entity financial statements and details of every entity commitment. Westpac asks for a certified copy of the stamped trust deed when it can’t confirm the applicant as the trustee, or as a director and shareholder of the trustee company.
- Add documents for the loan purpose. A purchase needs the signed contract of sale, and a construction loan needs the building contract, plans, specifications and payment schedule.
- Set the evidence period for each item from the lender’s rule. Then choose the request date so the document is still current at the stage the lender measures it.
Evidence periods are measured from different events. Westpac wants PAYG payslips no more than two months old on the day of formal approval. Macquarie’s 10 September 2026 credit guidelines want the latest payslip no more than 60 days old and the oldest no more than four months old at submission.
A payslip that meets Macquarie’s rule at submission can still be too old for Westpac by formal approval. Ask for a newer payslip when approval runs late.
Financial-year timing changes the request too. Westpac requires the previous 30 June financials after 15 May. Macquarie requires prior-year financials for every self-employed applicant from 1 April, with a two-week grace period to 15 April.
Home Loan Application Checklist by Borrower Type
Each row links a document to the borrower it applies to, its evidence period and the lender condition behind it. The rows come from Westpac’s checklist unless a row names Macquarie.
| Document | Borrower type | Evidence period | Lender condition it supports |
|---|---|---|---|
| Identity verification certificate with certified copies of identification | New Westpac customers, and new mortgages outside Tasmania and the Northern Territory | Current identification | Westpac’s mandatory section |
| Signed privacy acknowledgement, consents and confirmation form | Every applicant, except existing loan increases | Signed for this application | Westpac’s mandatory section |
| Two consecutive payslips, or one year-to-date (YTD) payslip covering the last two pay cycles | PAYG base income | No more than two months old at formal approval | PAYG income verification |
| One YTD payslip covering at least six months, or two consecutive payslips plus a prior-year income document such as an Australian Taxation Office (ATO) income statement | Casual income | No more than two months old at formal approval | Casual income verification |
| Business and personal tax returns, business financial statements and notices of assessment | Fully verified self-employed | Last two years, including the previous 30 June financials after 15 May | Self-employed income verification |
| Rental agreement or property manager’s rental statement | Tenanted investment property | The most recent document held | Rental income verification |
| Account statements showing the board payments | Board paid by transfer | Two payment cycles | Ongoing board expense |
| Full signed contract of sale, including title details and annexures | Property purchase | Signed copy of the current contract | Property purchase |
| Building contract or tender signed by the applicant and builder, with plans, specifications and payment schedule | Construction | Contract dated less than 12 months ago | Building loan |
| Evidence of 5% genuine savings | Westpac: mortgage-insured loan with a base loan-to-value ratio (LVR) above 90%. Macquarie: LVR above 85% | As set by the lender’s accepted documents | Genuine savings |
Bulma’s Scenario Planner lists the conditions to meet and the documents to gather for each lender it checks. Each answer quotes the lender’s policy wording, which you can keep on file beside the request list.
Check the list before you send it. Every row needs a borrower, an evidence period and a lender condition. A row without a condition is personal information the file may not need.
Collect Through a Secure Portal
Collect documents through a secure document collection portal that gives each client their own request, limits which staff can open it and records the client’s consent. Email attachments leave copies in every inbox that sends, receives or forwards them, with no access control once they arrive.
Under Australian Privacy Principle (APP) 11, an organisation covered by the Privacy Act must take reasonable steps to protect the personal information it holds. The Office of the Australian Information Commissioner’s (OAIC) guide to securing personal information suggests limiting access to staff who need it for their job. It also covers multi-factor authentication for higher-risk access and audit logs that show who opened what.
Set up these protections for each request:
- Permissions. Give access to the client and to the staff working on the file, such as the broker and the assistant. Remove access when someone leaves the team or the file closes.
- Upload controls. Accept the file types the lender takes and scan each upload for malware. Westpac, as at October 2026, asks for every tax file number to be removed from the documents, so ask clients to cover it before they upload.
- Consent records. Keep a record of the privacy and consent form the client signed, with its version and signing date. Record any consent to a bank statement retrieval service separately.
- Access expiry. Close the client’s link when the request is complete, so an old link can’t reopen the file.
Show Clients What a Genuine Request Looks Like
Tell the client how your request will arrive before you send it, so a fake message stands out. A home loan document request is easy to imitate, and a scammer who copies it can collect a full identity set.
The Australian Cyber Security Centre’s scam guidance, as at October 2026, tells people to go direct to a trusted source instead of using links or contact details in a message. It also suggests checking what an organisation says it will and won’t ask for.
Agree these signs with the client at the first meeting, then compare any message against them.
| Sign | Genuine portal request | Unsafe message |
|---|---|---|
| Where it comes from | The portal you named, sent after the conversation you had | An unexpected email or text, even one that uses your name |
| What it asks for | The documents you discussed, uploaded into the portal | Documents by email reply, passwords or one-time codes |
| Deadline | The due date you agreed | A threat or a deadline within hours |
| Payment | No payment or bank detail requests | A request to pay a fee or change payment details |
| How to check | Call your office on the number the client already has | A phone number or link supplied in the message itself |
A short message to send at the first meeting:
Your document request will come from our client portal and list the payslips, statements and ID we discussed today. We never ask for documents by email or for passwords by text or phone. If a message looks different, call our office on the number you already have for us before you open anything.
Review What Arrives
Review every document before it enters assessment. Accept it only when it passes all six checks in the table below. Reject anything that fails, with a note telling the client exactly what to send instead.
| Check | What to confirm | Example of a document that fails |
|---|---|---|
| Identity | The applicant’s name is on the document, and statements show the account holder | A transaction listing that shows only an account number |
| Period | The dates fall inside the lender’s evidence period at the stage that counts | A payslip that will be too old by the stage the lender measures |
| Completeness | Every page is present, including annexures and the pages that show totals | A four-page statement with page three missing |
| Legibility | Every name, date and figure can be read | A phone photo with glare across the YTD figures |
| Consistency | The figures agree with the fact find and with each other | Net pay that doesn’t match the salary credits on the bank statement |
| Signs of alteration | Fonts, alignment and totals look the way the issuer produces them | A YTD total that doesn’t match the pay period amounts |
ASIC’s Regulatory Guide 209 (December 2019) explains the identity check for statements. A transaction listing has to be identifiable as the consumer’s. If it shows only an account number, get an earlier statement that names the account holder for the same account, or cross-check it against another document.
Westpac’s document standards, as at October 2026, ask that a payslip shows the applicant and employer, the period covered, gross and net pay, tax paid and YTD income. Use the target lender’s standard for the same check.
Treat signs of alteration as a reason for a question, not a finding of fraud. These checks catch documents that need explaining, but they can’t prove a document is fake. Pass the document to the broker and follow your licensee’s process before anything is lodged.
Track Replacement Documents
When a lender asks for a replacement document, tie it to the exact outstanding condition and record which document it supersedes. Mark the condition complete only when the assessor confirms they’ve accepted the new evidence. An upload alone doesn’t clear it.
This example register uses made-up documents and dates.
| Outstanding condition | Replacement document | Supersedes | Sent | Assessor accepted |
|---|---|---|---|---|
| Updated payslip within the lender’s required period | Payslip for the period ending 26 September 2026 | Payslip for the period ending 15 August 2026 | 30 September 2026 | Yes, lender email on 1 October 2026 |
| Full contract of sale with annexures | Contract including the special conditions annexure | Contract without the annexure | 29 September 2026 | Open |
Keep the superseded version on file with the date it was replaced. For the full sequence from lodgement to settlement, use the guide to applying for a mortgage.
Automate Follow-Up Carefully
Automate reminders only for items that are still outstanding, stop each one as soon as its item arrives and hand anything unresolved to a named person. Automation chases documents. A person decides whether the evidence is acceptable.
Explain the reminders when you take the client’s consent. Tell them which channels you’ll use, how often reminders come and when they stop, then record that they agreed. Keep document names and figures out of text messages, because a phone can show them on a locked screen.
Set these stop rules in the portal:
- Stop a reminder when its item arrives. As at October 2026, Content Snare sends reminders only for outstanding items and stops them once the client completes the request.
- Restart a reminder only when you reject an item, and include the reason in the rejection note.
- Stop every reminder when the client asks, the application is withdrawn or the file closes.
- Cap the number of automatic reminders, then escalate.
Give every request a responsible person, usually the broker or assistant who owns the file. When the reminder cap is reached or a due date passes, that person calls the client and records the outcome.
Send missing or contradictory evidence to human review instead of another reminder. If net pay on a payslip doesn’t match the salary credits on a statement, a reminder can’t resolve it. The responsible person asks the client, records the explanation and decides whether the file needs another document.
Example Reminder Schedule
In this example schedule, the documents are made up.
| Day | Action | Who acts |
|---|---|---|
| 0 | Request sent for a driver licence, two payslips, recent account statements and the contract of sale | Portal |
| 2 | Email reminder listing only the items not yet uploaded | Portal |
| 4 | Text message reminder with a link to the portal and no document details | Portal |
| 6 | Phone call about the remaining items | Broker assistant |
| 8 | File review to decide whether to pause or proceed | Broker |
On day 5, the same request shows each item’s review status and reminder state.
| Item | Review status | Reminder |
|---|---|---|
| Driver licence | Accepted | Stopped |
| Payslip 1 | Accepted | Stopped |
| Payslip 2 | Rejected because the YTD figures are cut off | Restarted with the rejection note |
| Account statements | Received and in review | Paused |
| Contract of sale | Not received | Active, with a call due on day 6 |
Choose Document Collection Software
Pick the document collection software that leaves a record you can defend later. It needs version history for replaced documents, a complete export, retention you control and an audit trail showing what the client sent, when it arrived and who accepted it.
ASIC’s Regulatory Guide 273 (June 2020) expects brokers to keep records of how they met the best interests duty. Those records include the information given to the lender during the application. Regulatory Guide 209 notes that a consumer can ask for a written copy of the assessment up to seven years after credit assistance.
APP 11 also requires reasonable steps to destroy or de-identify personal information once it’s no longer needed, unless a law requires you to keep it. The software therefore needs retention you can set to cover your record-keeping obligations, followed by deletion.
This comparison shows each provider’s published information as at October 2026.
| Factor | BrokerEngine FinanceVault | Content Snare | FileInvite |
|---|---|---|---|
| Built for | Client portal inside BrokerEngine’s broker customer relationship management (CRM) software, included at no extra cost | General client document collection, with mortgage brokers among its stated users | Document collection for lenders, priced around commercial loan volume |
| Permissions | Permissions set who can see, create, edit and download data | Role-based access, with two-factor authentication an administrator can enforce | Roles and permissions, multi-factor authentication and single sign-on |
| Security and encryption | Data encrypted in transit and at rest | ISO 27001 certified, with encryption in transit and at rest, and each company’s data encrypted separately | SOC 2 Type II audited, with encryption in transit and at rest |
| Retention | Full data export on cancellation, then deletion from BrokerEngine’s system | A client’s link closes when the request is completed or archived | Data removed on deletion or when the administrator’s retention period ends |
| Export | Full export of deals and data on cancellation | Each request downloads as one package, or files push to Google Drive, Dropbox, OneDrive or SharePoint | Sync to OneDrive, Google Drive and Box, with SharePoint on Enterprise |
| Audit history | Not described on its features page | Approved items lock and show as checked | Audit trails listed in the plan comparison |
| Data location | Australia-based Amazon Web Services hosting | Amazon Web Services in the United States | Amazon Web Services, with a choice of data region on Enterprise |
| Australian presence | Used by Australian brokers and works with any aggregator | Office in Fortitude Valley, Queensland | Offices in Colorado and Auckland |
| Pricing basis | Per user each month, with a one-time onboarding fee and no free trial | Plans set by active requests, users and storage | Annual plans set by yearly loan volume |
For a brokerage choosing a CRM, a built-in portal such as BrokerEngine’s FinanceVault keeps documents with the deal and hosts them in Australia. BrokerEngine also connects to Connective Mercury and illion BankStatements.
Content Snare suits a brokerage that wants a separate portal beside its current CRM. Its confidential fields hide sensitive answers after entry and can be left out of exports. Its data sits in the United States, so weigh that against APP 8, which sets the steps an organisation takes before disclosing personal information overseas.
FileInvite’s published plans target lenders managing commercial loans, so its pricing fits a lender’s volume more than a broker’s pipeline. Whichever portal you choose, export the accepted documents and their replacement history into the file before handing the application to your loan origination software.