Audit readiness is created throughout the year, not in the week before the review. A reviewer needs to understand the business, select evidence, test controls and follow the trail from policy to decision. A structured preparation process reduces disruption and makes weaknesses easier to correct.

Start with the scope

Confirm the review period, applicable regulations, requested documents, sample method, deadlines and points of contact. Maintain one controlled request list and record who owns each response.

Test files before submission

Select a representative sample across risk levels, products, jurisdictions and lifecycle events. Check identification, beneficial ownership, purpose, source of funds or wealth where applicable, risk classification, approvals, monitoring and periodic-review evidence.

Reconcile governance evidence

Policies, organisational charts, mandates, training records, risk assessments, compliance reports and minutes should tell the same story. Record material changes and explain how the control framework was adapted.

Manage findings to closure

For each gap, document the root cause, immediate correction, broader population impact, owner, deadline and verification step. A closed action should have evidence that the fix works, not only a statement that it was completed.

Readiness areaEvidence to assemble
OrganisationRoles, mandates, delegation and escalation
Client filesCDD, risk rating, approvals and review history
MonitoringAlerts, investigations, decisions and reporting
TrainingAttendance, content, testing and follow-up
RemediationFinding log, owners, deadlines and validation

Official sources