A recap of the latest session in our Compliance Edge webinar series, hosted by Iain Armstrong, Executive Director of Financial Crime Compliance (FCC) Strategy at ComplyAdvantage.
This session started with a poll.
Around 28% of attendees had never been through a compliance audit, while 45% had been audited and identified areas for improvement.
Whichever group you sit in, you’ll agree on one thing: work in FinCrime compliance long enough, and an audit will eventually find you. The firms that come through well are the ones that treat audit as a question of when, not if.
Drawing on more than two decades in financial services – including enforcement work at the Financial Conduct Authority (FCA) and anti-financial crime roles at major banks and FinTechs – Iain shared what auditors look for, and how to have the answers ready before anyone asks.
Audit readiness is a habit, not a scramble
An audit raises one question: Can you show that your controls work?
Firms that struggle are usually the ones that go looking for evidence after the request has landed. Firms that cope have two things in place:
- Their platform captures the trail as they go, and they understand exactly what it captures.
- They hold a written record of what their risk management framework does and what it can’t do, along with a documented acceptance of those limits.
“Audit readiness is a habit. It’s a muscle that has to be exercised. It’s not something that you can summon into being the same week that your audit letter arrives.”
Iain Armstrong, Executive Director of FCC Strategy, ComplyAdvantage
That honesty about limits matters. A credible framework acknowledges where its controls stop. Done well, an audit shifts from an ordeal to a retrieval task. A clean result signals leadership that compliance spend is money well spent.
The scoping conversation is where audits are won
Whatever triggers an audit – an internal cycle, a commissioned external review, or regulatory supervision – the process tends to follow the same shape: an initial document request, a scoping conversation, document review and walkthroughs, draft findings, then ratings and remediation.
The scoping conversation is the moment firms most often miss.
“An audit is a set of open lines of inquiry. The auditor arrives with questions they intend to pursue, and your job at the scoping stage is partly to stop those lines of inquiry from widening unnecessarily. The way you can do that is with evidence that you already hold.”
Iain Armstrong, Executive Director of FCC Strategy, ComplyAdvantage
If an auditor signals interest in an area where you have already raised a risk on your internal register, discussed a gap in committee, or documented a remediation plan, pointing to that governance typically closes the line of inquiry. Auditors expect reasoned, well-structured pushback at this stage, and they tend to respect it.
Though there are two things to be cautious about:
- Handing over more than you were asked for widens the surface for scrutiny.
- A long, templated document request should be scoped down to what is relevant to your business – be precise about definitions, date ranges, and populations, and hold that line if scope starts to drift.
What are the four kinds of evidence auditors want?
Proof that controls work falls into four categories:
- System evidence: Your monitoring is running. In ComplyAdvantage Mesh, a single screening report, one click from the customer view, shows the risk level, monitoring status, screening frequency, and hits generated over the period.
- Configuration evidence: What you set up, when, and why. Configurations are versioned, so you can show what was live when a customer was screened in March versus now, and demonstrate that a change was made on a date, by a named person, for a stated reason. That can close off a common line of inquiry, whether controls have quietly weakened over time.
- Operational evidence: How your team works alerts. Case records include the date a case opened and closed, the decision, and the written rationale. Consistent, well-structured decision notes carry real weight with auditors, and this is exactly the kind of note our AI agentL1 screening agent drafts for analysts to review and confirm. The customer audit log records every monitoring event with a timestamp.
- Governance evidence: The one category no vendor can supply. A board-signed risk appetite, policies on a fixed review cycle, committee minutes showing genuine challenge, and management information that reaches leadership all sit with the firm.
So does system assurance: testing, on a regular cadence, that your controls do what you believe they do.
Build your audit evidence trail before the questions arrive
See what auditors actually look for, and how ComplyAdvantage Mesh captures the screening decisions, case notes, and configuration history that evidence a well-governed program.
Watch on demandHow to make audit readiness a habit
As a practical takeaway, remember to keep your configuration records current, log who changed what and why, review thresholds on a set cadence, and write case notes clearly enough that a stranger could reconstruct the decision two years later.
“Whatever decision we’re making, imagine you are someone two years from now trying to reverse engineer that decision. Is there enough written down and enough held in the system that would allow them to do that?”
Iain Armstrong, Executive Director of FCC Strategy, ComplyAdvantage
Then run a mock document request on yourselves each quarter. An hour spent playing the auditor reveals more about real readiness than a policy review.
Here are three questions to test yourself against:
- Can you show me your last configuration change, with approver and date?
- Why this threshold?
- Can you prove that screening was run for this customer on this date?
If you can answer all three without needing a week, you are in good shape.
But if this session has raised questions about your own setup, or you haven’t yet migrated to ComplyAdvantage Mesh, where much of this evidence is generated automatically, your customer success manager is the person to talk to.
See your audit trail before the auditor asks for it
ComplyAdvantage Mesh keeps system, configuration, and operational evidence live and exportable in one place, so screening reports, case decisions, and change history are ready the moment a request lands.
Get a demoOriginally published 11 August 2026, updated 11 August 2026
Disclaimer: This is for general information only. The information presented does not constitute legal advice. ComplyAdvantage accepts no responsibility for any information contained herein and disclaims and excludes any liability in respect of the contents or for action taken based on this information.
Copyright © 2026 IVXS UK Limited (trading as ComplyAdvantage).
