SOP Management & Workflow Documentation3 min readUpdated September 2026

Running Underwriting Exceptions Without Losing the Audit Trail

Underwriting checklists, closing conditions, and post-closing monitoring each have required steps that get compressed when a deal needs to fund by Friday. The exceptions accumulate, and by the time an examiner or an investor pulls a sample of files, the gap between the written policy and what actually happened is bigger than anyone realized.

Here is a workable approach to keeping the audit trail intact without becoming the reason a deal misses its funding date.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Step 1: Separate a hard stop from a documented exception

Not every underwriting step can bend under deadline pressure, but pretending none of them can is how a deal desk starts quietly skipping steps instead of documenting exceptions. Decide in advance which conditions are true hard stops, verified collateral value, for instance, and which can proceed with a documented, approved exception and a follow-up deadline. Build both paths into the checklist rather than leaving the exception path as an off-system workaround.

Step 2: Build the underwriting-to-close checklist with the exception path built in

A Process Street checklist that only has a single pass-or-fail path for each condition forces people to either wait or go around the system entirely. Add a branch: condition met, condition waived with documented approval and a cure deadline, or deal held. That third option, visible and tracked rather than informal, is what actually protects the file later. Give the exception path its own required fields, reason, approver, cure deadline, rather than a free-text comment box, so the resulting log is something you can filter and report on rather than a pile of notes someone has to read one by one before an exam.

Step 3: Put the underwriting policy itself in SweetProcess, not in the checklist

The checklist enforces sequence; it should not be where someone looks up what actually qualifies as acceptable collateral documentation or what threshold triggers a second-level review. Keep that policy content in a procedure library the checklist steps reference, so updating the policy does not mean rebuilding the checklist, and an underwriter working a live deal can pull up the current standard without leaving their workflow.

Step 4: Track post-closing monitoring as its own recurring checklist, not a one-time close-out step

Post-closing monitoring, the borrowing base certificates, the periodic field exam, the covenant compliance check, is where files drift furthest from policy, because the urgency of the closing deadline is gone and monitoring competes with new originations for attention. Run it as its own recurring checklist tied to a calendar, not a task someone remembers to revisit. A deal desk under origination pressure will always deprioritize monitoring in favor of new business unless the monitoring calendar runs independently of whoever is busiest that week.

Step 5: Build the exception log examiners and investors will actually want to see

Every documented exception, who approved it, why, and what the cure deadline was, should roll up into a single log an examiner can review without pulling individual files one at a time. This is the difference between a lender that looks like it manages exceptions deliberately and one that looks like it is hiding them, even when the underlying exception rate is identical. Review the log itself on a schedule too, not only when an exam is imminent. A rising exception rate on a specific condition is usually the first sign that condition needs to be reconsidered or that a specific originator needs closer supervision, and that signal is easy to miss if the log only gets pulled up once a year.

Each logged exception should capture these details:

  • The condition that was waived, and whether it was a hard stop or a condition allowed to proceed under a documented exception.
  • The named approver, recorded in the same system as the exception rather than in an email thread.
  • The reason the exception was granted, written clearly enough that an examiner does not have to ask why policy was not followed.
  • The cure deadline and the follow-up owner, so the exception is tracked to closure instead of forgotten after funding.

What this costs to run and who should own it

Median pay for an operations manager, often the role that ends up owning this kind of compliance system, runs $105,770 a year nationally1, a reasonable anchor when deciding whether to build this ownership into an existing credit-team role or budget for a dedicated hire. Either way, name the owner explicitly rather than leaving exception tracking as a shared responsibility that quietly becomes nobody's job during a busy quarter.

What a bad exception process looks like from the outside

An examiner who finds an undocumented deviation from stated underwriting policy treats it very differently depending on whether your file shows an approved, dated exception with a named approver, or shows nothing at all and forces them to ask why the policy was not followed. The gap between those two outcomes is almost entirely a matter of whether the exception was logged in the moment, which is why the logging step has to be built into the checklist itself rather than left as a task someone does later if they remember.

The same logic applies to post-closing monitoring gaps. A covenant check that ran two weeks late with a documented reason reads as a manageable operational hiccup. The same check that simply never happened, with no record either way, reads as a control failure, even if the underlying credit risk turned out fine.

Executive Capability Standard

What Good Looks Like

A well-run asset-based lender can produce a complete exception log for any examination period on request, showing every underwriting exception, its approval, and whether the cure condition was met.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Review a sample of recent files and identify how often an underwriting step was skipped versus formally waived.
2. Do Manually:Write down which conditions are hard stops and which can proceed with a documented exception, and start logging exceptions manually.
3. Delegate:Assign a credit operations lead to own the exception log and post-closing monitoring calendar.
4. Automate:Move the underwriting checklist into a tool with a built-in exception path and tie post-closing monitoring to a recurring schedule.
5. Buy:Run underwriting, exception tracking, and post-closing monitoring under one governed system with an examiner-ready audit trail.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Process Street

Use Process Street to run the underwriting-to-close checklist with a documented exception path built in.

Visit Process Street→
Every

Every can handle the lender's own back-office payroll and compliance administration, separate from the credit process itself.

Visit Every→

Frequently Asked Questions

Who should have authority to approve an underwriting exception?

Someone above the person originating the deal, typically a credit committee member or a designated second-level underwriter. Record the approval in the same system as the exception itself, not in a separate email thread that is easy to lose track of later. An independent approver is what makes the exception log credible to an examiner.

How far back should the exception log go for an examination?

Match the lookback period your regulator or investor states, typically 12 to 24 months. Keep the log exportable rather than only viewable inside the tool, since an examiner will usually want a file they can review independently instead of screen-sharing through your system. If the stated period is unclear, keep more history rather than less.

What is a hard stop in underwriting versus a documented exception?

A hard stop is a condition that cannot bend under deadline pressure, such as verified collateral value. A documented exception is a condition that can proceed with an approved waiver, a named approver, and a follow-up cure deadline. Deciding which is which in advance keeps a deal desk from quietly skipping steps.

How should post-closing monitoring be tracked?

Run it as its own recurring checklist tied to a calendar, not a one-time close-out step. Borrowing base certificates, periodic field exams, and covenant compliance checks are where files drift furthest from policy, because monitoring competes with new originations for attention once the closing deadline is gone.

Sources

Where we quote a benchmark, we show its source. Other figures in this guide are estimates or general guidance, so check them against your own numbers.

  1. Annual wage, General and Operations Managers (SOC 11-1021), US all industries. BLS OEWS May 2025, 2025.

Related Guides