Audit readiness is created throughout the year, not in the week before the review. A reviewer needs to understand the business, select evidence, test controls and follow the trail from policy to decision. A structured preparation process reduces disruption and makes weaknesses easier to correct.
Start with the scope
Confirm the review period, applicable regulations, requested documents, sample method, deadlines and points of contact. Maintain one controlled request list and record who owns each response.
Test files before submission
Select a representative sample across risk levels, products, jurisdictions and lifecycle events. Check identification, beneficial ownership, purpose, source of funds or wealth where applicable, risk classification, approvals, monitoring and periodic-review evidence.
Reconcile governance evidence
Policies, organisational charts, mandates, training records, risk assessments, compliance reports and minutes should tell the same story. Record material changes and explain how the control framework was adapted.
Manage findings to closure
For each gap, document the root cause, immediate correction, broader population impact, owner, deadline and verification step. A closed action should have evidence that the fix works, not only a statement that it was completed.
| Readiness area | Evidence to assemble |
|---|---|
| Organisation | Roles, mandates, delegation and escalation |
| Client files | CDD, risk rating, approvals and review history |
| Monitoring | Alerts, investigations, decisions and reporting |
| Training | Attendance, content, testing and follow-up |
| Remediation | Finding log, owners, deadlines and validation |