Handling and security Current

Preparing an evidence package for an audit or regulator request

A practical checklist for pulling evidence together under time pressure.

A regulator or auditor request often comes with a deadline, which is the wrong time to discover your evidence is scattered or incomplete. This guide sets out a practical checklist. It is general information, not legal or compliance advice.

Action plan

1 Confirm exactly what the request covers Pulling more or less than what's genuinely requested wastes time or leaves gaps.

Before assembling anything, confirm the specific matter, time period, and record types the request actually covers. A package that's broader than requested wastes preparation time; one that's narrower leaves gaps a regulator will need to follow up on.

  • Confirm the specific matter or client the request relates to
  • Confirm the time period the request covers
  • Confirm which record types are actually in scope before starting

Done when: The exact scope of the request has been confirmed before assembly begins

2 Assemble records sufficient to reconstruct what was done AUSTRAC's own standard for AML/CTF records is a useful benchmark for any evidence package, even outside AML/CTF matters.

For AML/CTF-related matters, AUSTRAC's guidance sets the standard for records as reasonably necessary to show compliance and sufficient to reconstruct what was done. Where a request falls outside AML/CTF specifically, that same standard is still a useful practical benchmark: an evidence package should let the regulator or auditor reconstruct what your firm did and why, not just show that something happened.

  • Include records that show what was checked, when, and by whom, not just the outcome
  • Include the reasoning behind material decisions, not only the decision itself
  • Check the package would let someone unfamiliar with the matter reconstruct what happened

Done when: The assembled package is sufficient for someone unfamiliar with the matter to reconstruct what was done

AUSTRAC: record keeping overview
3 Review the package for completeness and accuracy before sending A second review catches gaps and errors a request under time pressure can otherwise miss.

Before sending the package, have someone other than the person who assembled it review it against the confirmed scope, checking for missing records, inconsistencies, and anything that needs a covering explanation.

  • Have someone other than the assembler review the package before it's sent
  • Check the package matches the confirmed scope exactly
  • Add a covering explanation for anything that needs context

Done when: The package has been independently reviewed for completeness and accuracy before being sent

See how structured intake and review works