What auditors actually want from your FinCrime controls

FinCrime

Around 28% of attendees at ComplyAdvantage’s latest Compliance Edge webinar had never faced a compliance audit, while 45% had been audited and found areas needing improvement. 

According to ComplyAdvantage, regardless of which camp firms fall into, the message from the session was consistent.  An audit is a question of when, not if, and the businesses that emerge well-prepared are the ones that treat readiness as an ongoing discipline rather than a last-minute scramble.

Hosted by Iain Armstrong, Executive Director of Financial Crime Compliance (FCC) strategy at ComplyAdvantage and a former enforcement specialist at the Financial Conduct Authority (FCA), the session set out what separates firms that cope from those that struggle. 

Two things will have a disproportionate impact:

  • A platform that captures an evidence trail automatically.
  • A written record of what a firm’s risk framework does and does not cover.

Iain Armstrong said, “Audit readiness is a habit. It’s a muscle that has to be exercised. It’s not something that you can summon into being the same week that your audit letter arrives.”

He also flagged the scoping conversation as the stage most firms mishandle. Auditors arrive with lines of inquiry they intend to pursue, and evidence already on file – a documented remediation plan or a risk already logged on an internal register – can close those lines down quickly.

“An audit is a set of open lines of inquiry. The auditor arrives with questions they intend to pursue, and your job at the scoping stage is partly to stop those lines of inquiry from widening unnecessarily. The way you can do that is with evidence that you already hold.” – Iain Armstrong, Executive Director of FCC strategy, ComplyAdvantage

Four evidence categories came up repeatedly: 

  • System evidence showing monitoring is active.
  • Configuration evidence showing what changed and why.
  • Operational evidence covering case decisions and rationale.
  • Governance evidence such as board-signed risk appetite statements, which no vendor can supply on a firm’s behalf.

On making readiness routine, he also urged firms to keep configuration records current, log every change with an approver and reason, review thresholds regularly, and write case notes clear enough for someone to reconstruct years later.

Iain Armstrong added: “Whatever decision we’re making, imagine you are someone two years from now trying to reverse engineer that decision. Is there enough written down and enough held in the system that would allow them to do that?”

Finally, he also recommended a quarterly self-test: can you show your last configuration change with approver and date, justify a threshold, and prove screening ran for a given customer on a given date? Firms unable to answer within a week may want to speak with their customer success manager about ComplyAdvantage Mesh, which automates much of this evidence generation.

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.