Gå til hovedinnholdet Gå til menyen
Book a demo

Compliance Evidence Should Be a By-product, Not an Audit Project

What a firm can prove about a customer relationship matters as much as what it actually did — and the two are not the same thing.

A firm can run its client relationships well for years without ever discovering that its compliance evidence has a problem. Customers are onboarded, risk assessments completed, screening performed, reviews carried out on schedule. Nothing about the relationship suggests anything is wrong, because nothing is wrong — the work is genuinely being done.

The weakness, where it exists, tends to stay invisible until somebody asks a specific question: not "did you do the right thing," but "show me exactly what you did, what you knew, and why." That question can come from a regulator, an auditor, a new MLRO reviewing a legacy book, or an internal review. The answer depends on something most firms have never actually tested: whether the history of a customer relationship is retrievable and coherent, or scattered across whoever happened to touch it along the way.

Doing the compliance work properly and being able to prove it several years later are two different capabilities. A firm can be strong on the first and weak on the second — and the second weakness carries its own risk, independent of whether anything was ever actually done wrong.

Commercial lifecycle management is not compliance lifecycle management

Most firms manage the commercial side of a client relationship through a CRM, an onboarding tool, or a broader client-lifecycle platform — frequently very good at what they were built for: moving a prospective client to an active, revenue-generating relationship efficiently. That is not a criticism of the category; it reflects what these systems were designed to optimise, and the regulated evidentiary record may not have been the primary design objective.

As a result, compliance work often happens alongside the commercial workflow rather than inside it: a registry search here, a sanctions and PEP screen there, a spreadsheet of outstanding items, a screenshot that might matter later, a document in SharePoint, a judgement call explained wherever seemed most natural at the time.

A conscientious person can make this work, but the result depends heavily on that person's own filing discipline, and on nobody else ever needing to reconstruct it without them. That person goes on leave, changes role, or leaves; someone else takes over with different habits and a different sense of what mattered. None of this shows up commercially — the relationship continues uninterrupted. It becomes visible only once somebody has to rebuild what happened, and finds the story living in several people's heads and folders rather than one coherent record.

The real audit question is not "what do you know today"

Imagine an auditor selecting a single client relationship, at random, several years after onboarding, and asking the firm to reconstruct it in full.

Depending on the applicable framework and the customer, the firm may need to show: who the customer was and the relevant corporate detail; jurisdiction and business activity; the ownership and control structure, including the ownership chain where one exists; the beneficial owners identified; the geographic and other risk factors considered; the screening carried out and its results; the documentation obtained; what was actually known when the risk assessment was performed; the resulting classification and why it was appropriate then; who decided, and when; why the firm accepted, declined or continued the relationship; what changed afterwards; whether that triggered further review; what was done, by whom; and the eventual outcome.

This is not a universal checklist applying identically everywhere — requirements vary by framework and customer type. The underlying principle is consistent: the firm must be able to evidence the decision in the context in which it was actually made, not reconstruct a plausible version of it after the fact. The EU's Anti-Money Laundering Regulation (Regulation (EU) 2024/1624, "AMLR"), directly applicable from 10 July 2027, makes this explicit. Article 20 requires obliged entities to be able to demonstrate to their supervisors, at all times, that the due diligence measures taken are appropriate in view of the risks identified — not merely that a measure was taken, but that its adequacy can be shown. Article 21(3) goes further: it requires obliged entities to keep records of the actions taken to comply with due diligence, including the decisions taken, the relevant supporting documents and the justifications for them. It also requires documents, data and information held by the obliged entity to be updated whenever customer due diligence is reviewed under Article 26. Compliance evidence, on this reading, is not only the underlying facts — it is the decisions and the reasoning behind them, kept alongside those facts.

A current record is not a historical record

One of the more consequential mistakes a compliance system can make is quiet and easy to overlook: overwriting yesterday's information with today's.

Suppose a corporate customer's ownership structure changes. If the system simply replaces the old structure with the new one, it will correctly tell the firm who owns the customer today. It will not tell an auditor, two years from now, why the assessment made at onboarding was reasonable given what was known then — because that earlier state no longer exists in its original form.

This extends beyond customer data: the regulatory environment itself changes, as risk factors evolve, guidance is updated, and a firm's own methodology and risk appetite develop. The point is not that every historical rule must be reproduced inside every file — only that the evidence around a historical decision must preserve enough of its original context to be understood on its own terms, rather than judged against information that did not yet exist. Article 26 of the AMLR requires ongoing monitoring: obliged entities must keep customer information up to date on a risk-sensitive basis and specifically review it when the customer's relevant circumstances change or the firm becomes aware of a relevant fact. The Regulation does not itself prescribe how that history should be preserved. From an operational and evidentiary perspective, though, a system that keeps the prior state alongside the new one, rather than replacing it, is what actually makes it possible to show what changed and why the resulting action was appropriate.

The evidence record should follow the heartbeat of the relationship

The right mental model is not a single document produced at onboarding and quietly maintained. It is closer to a chronological series of point-in-time snapshots taken at every meaningful moment: the information available, the evidence behind it, what changed, what that required, who assessed it, and what was decided, and when. New information should append to that history, not overwrite it.

At IQON, we think of this as the heartbeat of the client relationship — from inception, through onboarding, every subsequent change, review and decision, to the eventual end of the relationship, each significant event adding another beat to the record. The metaphor matters less than the requirement it captures: at any point in the relationship's life, the firm should be able to see what it looked like then, and what happened next.

Take a concrete case. A corporate customer undergoes a material ownership change, and a new beneficial owner appears in another jurisdiction. Depending on the circumstances, this may or may not trigger enhanced due diligence — a risk-based judgement, not an automatic rule. What the record needs to show is not just the new structure but that the change occurred, what changed, what was considered, what further checks were required, who reviewed the matter, and what was decided, and when. A regulated relationship changes, and change can create an obligation; a good system helps surface it, ensures the right workflow follows, and preserves what happened, rather than presenting only the current state as though it were the only one that ever existed.

Technology should remove the documentation work, not the judgement

For a corporate customer, much of the relevant factual environment — corporate information, jurisdiction, industry, ownership and ownership chains, beneficial ownership, screening, relevant risk factors, supporting documentation, and how all of it changes over time — can be assembled and maintained systematically. A compliance professional should not have to manually recreate an audit trail for information the system already holds. Technology's job is to collect, structure, preserve, monitor, surface, summarise, coordinate and timestamp; the human's job is the judgement the facts inform.

IQON is currently rolling out AI-assisted functionality that summarises the evidence assembled during risk classification — not to decide whether a customer should be accepted, but to address a distinctly human, administrative problem. A customer file can accumulate a great deal of information quickly, and assembling it into something a decision-maker can actually absorb takes time and risks something relevant being missed. The AI helps assemble and summarise that information and bring the relevant points to the decision-maker's attention, which helps reduce that risk — it does not guarantee that nothing will ever be overlooked. The summary is an input to the decision, not the decision itself; the accountable person reviews it and decides, and the record preserves what was available, what was presented, what was decided, and, where appropriate, why.

This sits comfortably with where the AMLR draws the line. Article 76(5) permits automated processes, including profiling and AI systems, over data obtained through customer due diligence — but any decision to enter into, refuse, maintain or adjust the due diligence applied to a relationship requires meaningful human intervention, and the customer retains a right to an explanation and to challenge it. Article 18 addresses the parallel question of outsourcing: it permits obliged entities to delegate AML/CFT tasks to service providers, including technology providers, but the obliged entity remains fully liable for anything done or left undone in connection with that outsourced work, and certain decisions — among them the customer's risk profile and the decision to enter into the relationship — generally cannot be handed to a third party at all, subject to the Regulation's own specific exceptions. Read together, the two provisions point the same way: a substantial amount of AML work, administration and specialist activity can be delegated or technology-supported, but the accountability for the decisions the framework assigns to the obliged entity does not travel with it.

Auditability should survive the people who created the file

The deeper problem with manual record-keeping is not that a document might get lost. It is that the exact state and context of information is hard to preserve when it depends on one person's approach to copying, screenshotting, summarising and filing — which works only for as long as that person answers questions about the file.

By the time an auditor asks, the person who gathered the information may have moved on, and so may the person who made the decision; whoever handles the audit may never have known the relationship existed. A useful test for any evidence system is whether someone with no prior knowledge of the relationship could retrieve and understand its full compliance history years later — without depending on anyone's memory, seniority, or knowledge of how the file was organised.

The dash-cam problem

Imagine somebody drives into your car. You may be completely certain you drove correctly, but there is still a significant difference between saying "that is what happened" and producing contemporaneous evidence of what happened. A dash cam does not make you a better driver, and it does not make the decision for you. It gives you an independent, timestamped record capable of demonstrating what occurred, on demand, to someone who was not there.

Compliance evidence serves the same function. A firm may have acted entirely correctly throughout a relationship, but years later, if it cannot show what it knew, what it considered, what it decided, and what happened afterwards, its ability to defend that position is far weaker than the quality of its underlying work deserves. The risk is not only that a firm did something wrong; it is that it did everything right and can no longer prove it — and under a regime like the AMLR's, that has a cost. Article 77 requires the underlying due diligence documentation and transaction records to be kept, generally for five years from the end of the relationship; where a firm retains references rather than copies, the Regulation permits this only where the information can still be provided immediately to a competent authority and cannot be modified or altered. A record that technically exists somewhere is of limited value if it cannot be found, in its original state, and produced when asked for. Article 78 adds a related but narrower obligation: firms must have systems capable of responding fully and speedily to a competent authority's enquiry as to whether they hold, or held, a relationship with a specified person, and the nature of it.

Build the evidence while the relationship is happening

IQON was built starting from the regulated relationship, not the commercial workflow, with auditability treated as part of the architecture rather than something added afterwards. The intention is not to push compliance professionals into a separate system while everyone else works in the commercial one — it is to support the client-lifecycle workflow in a way that produces the compliance evidence as a natural consequence of the work being done, rather than a separate exercise on top of it. IQON is not designed to help a firm reconstruct its audit trail after the fact; it is designed so that the audit trail already exists, because the platform captures the point-in-time facts, the decisions and the reasons behind them as they happen, and preserves the history rather than overwriting it. Good auditability should be a consequence of doing the work well — not another piece of work competing for the same compliance team's time.

A compliance team should not discover whether its evidence holds up when the auditor arrives. By then the decisions may be years old, the underlying facts may have moved on, and the people who made them may no longer be there to explain their reasoning. The evidence should already exist, because it was created as part of running the relationship. If a firm has to reconstruct its compliance evidence before it can withstand an audit, the evidence system has already failed.

Book a demo

Protected by reCAPTCHA
Privacy - Terms

Thank you

Why IQON

  • Modular platform for onboarding, KYC/AML and reporting

  • Digital onboarding and document signing with eID

  • Continuous AML monitoring

  • Simple, intuitive client reporting across web and mobile

  • Fully white-labelled apps and portals

  • Digitalized processes that improve speed and accuracy

  • Easy, vendor-agnostic integrations