Small Business Application Requirements – part 1

by Guest Contributor 6 min read January 25, 2012

By: Joel Pruis

Small Business Application Requirements

The debate on what constitutes a small business application is probably second only to the ongoing debate around centralized vs. decentralized loan authority (but we will get to that topic in a couple of blogs later). We have a couple of topics that need to be considered in this discussion, namely:

1.     When is an application an application?

2.     Do you process an incomplete application?

When is an application an application?

Any request by a small business with annual sales of $1,000,000 or less falls under Reg B.  As we all know because of this regulation we have to maintain proper records of when we received an application and when a decision on the application was made as well as communicated to the client. To keep yourself out of trouble, I recommend that there be a small business application form (paper or electronic) and that you have clearly stated the information required for a completed application in your small business application procedures. The form removes ambiguities in the application process and helps with the compliance documentation.

One thing is for certain – when you request a personal credit bureau on the small business owner(s)/guarantor(s) and you currently do not have any credit exposure to the individual(s) – you have received an application and to this there is no debate.

Bottom line is that you need to define your application and do so using objective criteria. Subjective criteria leaves room for interpretation and individual interpretation leaves doubt in the compliance area.

Information requirements

Whether or not you use a generic or custom small business scorecard or no scorecard at all, there are some baseline data segments that are important to collect on the small business applicant:

·         Requested amount and purpose for the funds

·         Collateral (if necessary based upon the product terms and conditions)

·         General demographics on the business

o    Name and location

o    Business Entity type (corporation, llc, partnership, etc.)

o    Product and/or service provided

o    Length of time in business

o    Current banking relationship

·         General demographics on the owners/guarantors

o    Names and addresses

o    Current banking relationship

o    Length of time with the business

·         External data reports on the business and/or guarantors

o    Business Report

o    Personal Credit Bureau on the owners/guarantors

·         Financial Statements (?) – we’ll talk about that in part II of this post.

The demographics and the existing banking relationship are likely not causing any issues with anyone and the requested amount and use of funds is elementary to the process. Probably the greatest debate is around the collection of financial information and we are going to save that debate for the next post.

The non-financial information noted above provides sufficient data to pull personal credit bureaus on the owners/guarantors and the business bureau on the actual borrower. We have even noted some additional data informing us the length of time the business has been in existence and where the banking relationship is currently held for both the business and the owners. But what additional information should be requested or should I say required?

We have to remember that the application is not only to support the ability to render a decision but also supports the ability to document the loan and maybe even serve as a portion of the loan documentation. 

We need to consider the following:

·         How standardized are the products we offer?

·         Do we allow for customization of collateral to be offered?

·         Do we have standard loan/fee pricing?

·         Is automatic debit for the loan payments required? Optional? Not available?

·         Are personal guarantees required? Optional?

We again go back to the 80/20 rule. Product standardization is beneficial and optimal when we have high volumes and low dollars. The smaller the dollar size of the request/relationship the more standardized we need to have our products and as a result our application can be more streamlined. When we do not negotiate rate, we do not need to have a space to note requested rate. When we do not negotiate on personal guarantees we always require the personal financial information be collected on all owners of the business (some exceptions for very small ownership interests). Auto-debit for the loan payments means we always need to have some form of a DDA account with our institution. I think you get the point that for the highest volume of applications we standardize and thus streamline the process through the removal of ambiguity.

Do you process an incomplete application?

The most common argument for processing an incomplete application is that if we know we are going to decline the application based upon information on the personal credit bureau, why go through the effort of collecting and spreading the financial information. Two significant factors make this argument moot:   customer satisfaction and fair lending regulation.

Customer satisfaction

This is based upon the ease of doing business with the financial institution. More specifically the number of contact points or information requests that are required during the process. Ideally the number of contact points that are required once the applicant has decided to make a financing request should be minimal the information requirements clearly communicated up front and fully collected prior to rendering a decision. The idea that a quick no is preferable to submitting a full application actually is working to make the declination process more efficient than the actual approval process. So in other words we are making the process more efficient and palatable for those clients we do NOT consider acceptable versus those clients that ARE acceptable. Secondly, if we accept and process incomplete applications, we are actually mis-prioritizing the application volume. Incomplete applications should never be processed ahead of completed packages yet under the quick no objective, the incomplete application is processed ahead of completed applications simply based upon date and time of submission. Consequently we are actually incenting and fostering the submission of incomplete applications by our lenders. Bluntly this is a backward approach that only serves to make the life of the relationship manager more efficient and not the client.

Fair lending regulation

This perspective poses a potential issue when it comes to consistency.  In my 10 years working with hundreds of financial institutions, only a very small minority of times have I encountered a financial institution that is willing to state with absolute certainty that a particular characteristic will cause an application to e declined 100% of the time. As a result, I wish to present this scenario:

·         Applicant A provides an incomplete application (missing financial statements, for example).

o    Application is processed in an incomplete status with personal and business bureaus pulled.

o    Personal credit bureau has blemishes which causes the financial institution to decline the application

o    Process is complete

·         Applicant B provides a completed application package with financial statements

o    Application is processed with personal and business bureaus pulled, financial statements spread and analysis performed

o    Personal credit bureau has the same blemishes as Applicant A

o    Financial performance prompts the underwriter or lender to pursue an explanation of why the blemishes occurred and the response is acceptable to the lender/underwriter.

Assuming Applicant A had similar financial performance, we have a case of inconsistency due to a portion of the information that we “state” is required for an application to be complete yet was not received prior to rendering the decision. Bottom line the approach causes doubt with respect to inconsistent treatment and we need to avoid any potential doubt in the minds of our regulators.

Let’s go back to the question of financial statements. Check back Thursday for my follow-up post, or part II, where we’ll cover the topic in greater detail.

Related Posts

The Email Address as Your Most Powerful Identity Signal

The why behind Experian's acquisition of AtData What happens when a comprehensive email intelligence database joins a global leader in data, analytics and fraud prevention? The acquisition of AtData adds 25+ years of building a complete view of email as an identity signal. Financial institutions can recognize, engage and protect customers unlocking a new standard for the way their teams work and the customer experience. That's what Experian's acquisition of AtData delivers. How we got here Not all email addresses tell the same story. Some are newly created. Some exhibit bot-like patterns. Some are inconsistent with every other signal you have about that person. Imagine a real customer. You have a job. You shop online. You have a primary email from your employer, a personal Gmail you've used for 15 years, and an old Yahoo address you still use for shopping because you've been using it since college. You're an engaged customer who interacts with brands, makes purchases and pays bills on time. But each system sees a different version of you. When you apply for credit, the lender sees one email. When you shop, the retailer sees another. When you sign up for a service, you might use the third. For financial institutions: You slow down the approval process to manually verify identity or approve applicants without the full picture. For retailers: You can't tell which version of "customer" is the most engaged, so you either over-mail or under-serve. For fraud systems: Sees a new account created under one email and flags it as suspicious because it doesn't have the history. This was the original problem AtData was built to solve in 1999. Twenty-five years later, that problem didn’t go away, it became more complex. Email fragmentation and device sharing are more common, and identity theft is more sophisticated. Capabilities that now work together Experian has built sophisticated identity and fraud solutions backed by consumer data resources and decades of expertise in credit and risk. AtData brought the ability to assess whether an email address is trustworthy, reachable and consistent—at scale, in real time. Experian is now making email intelligence foundational, not optional. This matters for: Fraud prevention and risk management: Distinguishing a returning customer from a new threat. Knowing whether an email is newly created, exhibiting bot-like patterns or inconsistent with other identities is crucial. Compliance: Building audit trails that can explain identity decisions. Email data history and behavioral signals create the documentation needed to defend your decisions. Credit: Verifying identity in a world where traditional signals are shifting. Email signals provide a persistent, durable identifier that confirms who someone actually is. Marketing: Reaching the right person across email, mail and digital channels. Email intelligence reveals which addresses are actively engaged and reachable. Research shows email remains one of the highest-ROI marketing channels outperforming paid search and social advertising1. The problem every marketer faces: You end up burning budget on addresses that bounce, are unmonitored or are associated with users who never open mail. For credit marketing specifically, email enables faster, more targeted delivery of firm offers across channels, something that's increasingly important in a post-cookie world. "Email is a persistent identifier in a fragmented world. It's what connects a person's postal address, phones, devices, behaviors—the full picture of who they are. By embedding that into our infrastructure, we're not just adding another data point. We're fundamentally improving how businesses understand who their customers are."- Ashley Knight, Senior Vice President, Financial Services and Data Why now? AI is reshaping how decisions are made in every industry. Models are getting faster, more automated and more embedded in core workflows. But AI is only as effective as the data behind it. Fragmented data + fast models = faster, larger-scale misclassifications. In an era of synthetic identities, AI agents, deepfakes and AI-generated activity, the value of durable, persistent, real-world data signals has increased dramatically. Deloitte’s Center for Financial Services projects that generative AI could drive fraud losses in the U.S. up to $40 billion by 2027, a 32% growth rate since 2023. And email sits at the center of it with business email compromise already being one of the most common and costly fraud types. People change phones, move homes and swap devices, but they often hold onto their email for years. That's the signal that protects your business, and the one we've built into the core of how we help you make decisions with confidence. View the press release here

August 6, 2026 by Zohreen Ismail
Building Financial Opportunity Through Purpose-Driven Partnership

Discover how the National Urban League and Experian partner to expand financial literacy and create economic opportunity.

August 6, 2026 by Scarlet Nickel
2026 U.S. Identity and Fraud Report 

Explore key findings and insights from our newly released 2026 U.S. Identity and Fraud Report. Read more now!

August 5, 2026 by Laura Burrows

Subscribe to our Newsletter

Enter your name and email for the latest updates.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Subscribe to our Newsletter

Don't miss out on the latest industry trends and insights!
Subscribe