Audit-ready compliance: How to evidence your financial crime controls
Written by Iain Armstrong
Written by Iain Armstrong
A recap of the latest session in our Compliance Edge webinar series, hosted by Iain Armstrong, Executive Director of Financial Crime Compliance (FCC) Strategy at ComplyAdvantage.
This session started with a poll.
Around 28% of attendees had never been through a compliance audit, while 45% had been audited and identified areas for improvement.
Whichever group you sit in, you’ll agree on one thing: work in FinCrime compliance long enough, and an audit will eventually find you. The firms that come through well are the ones that treat audit as a question of when, not if.
Drawing on more than two decades in financial services – including enforcement work at the Financial Conduct Authority (FCA) and anti-financial crime roles at major banks and FinTechs – Iain shared what auditors look for, and how to have the answers ready before anyone asks.
An audit raises one question: Can you show that your controls work?
Firms that struggle are usually the ones that go looking for evidence after the request has landed. Firms that cope have two things in place:
“Audit readiness is a habit. It’s a muscle that has to be exercised. It’s not something that you can summon into being the same week that your audit letter arrives.”
Iain Armstrong, Executive Director of FCC Strategy, ComplyAdvantage
That honesty about limits matters. A credible framework acknowledges where its controls stop. Done well, an audit shifts from an ordeal to a retrieval task. A clean result signals leadership that compliance spend is money well spent.
Whatever triggers an audit – an internal cycle, a commissioned external review, or regulatory supervision – the process tends to follow the same shape: an initial document request, a scoping conversation, document review and walkthroughs, draft findings, then ratings and remediation.
The scoping conversation is the moment firms most often miss.
“An audit is a set of open lines of inquiry. The auditor arrives with questions they intend to pursue, and your job at the scoping stage is partly to stop those lines of inquiry from widening unnecessarily. The way you can do that is with evidence that you already hold.”
Iain Armstrong, Executive Director of FCC Strategy, ComplyAdvantage
If an auditor signals interest in an area where you have already raised a risk on your internal register, discussed a gap in committee, or documented a remediation plan, pointing to that governance typically closes the line of inquiry. Auditors expect reasoned, well-structured pushback at this stage, and they tend to respect it.
Though there are two things to be cautious about:
Proof that controls work falls into four categories:
So does system assurance: testing, on a regular cadence, that your controls do what you believe they do.
See what auditors actually look for, and how ComplyAdvantage Mesh captures the screening decisions, case notes, and configuration history that evidence a well-governed program.
Watch on demandAs a practical takeaway, remember to keep your configuration records current, log who changed what and why, review thresholds on a set cadence, and write case notes clearly enough that a stranger could reconstruct the decision two years later.
“Whatever decision we’re making, imagine you are someone two years from now trying to reverse engineer that decision. Is there enough written down and enough held in the system that would allow them to do that?”
Iain Armstrong, Executive Director of FCC Strategy, ComplyAdvantage
Then run a mock document request on yourselves each quarter. An hour spent playing the auditor reveals more about real readiness than a policy review.
Here are three questions to test yourself against:
If you can answer all three without needing a week, you are in good shape.
But if this session has raised questions about your own setup, or you haven’t yet migrated to ComplyAdvantage Mesh, where much of this evidence is generated automatically, your customer success manager is the person to talk to.
Watch the full session on demand in our knowledge base here, along with the companion session on building, scaling, and modernizing your compliance program.
ComplyAdvantage Mesh keeps system, configuration, and operational evidence live and exportable in one place, so screening reports, case decisions, and change history are ready the moment a request lands.
Get a demoOriginally published 11 August 2026, updated 25 August 2026
Disclaimer: This is for general information only. The information presented does not constitute legal advice. ComplyAdvantage accepts no responsibility for any information contained herein and disclaims and excludes any liability in respect of the contents or for action taken based on this information.
Copyright © 2026 IVXS UK Limited (trading as ComplyAdvantage).