← Back to blog

Compliance review checklist: audit-ready guide for UK teams

August 6, 2026
Compliance review checklist: audit-ready guide for UK teams

A working compliance review checklist, paired with an 8-step running process, gives compliance officers and audit managers an immediately usable route to audit readiness. The ten control areas to cover are: governance, policies, client onboarding and KYC, conflicts and independence, HR and training, service delivery, internal controls and testing, documentation and evidence, third-party and vendor oversight, and data protection. Before you open a single policy document, take three actions: define the scope of this review cycle, take a snapshot of your current evidence holdings, and assign a named owner to each control area. A downloadable checklist template is referenced throughout this guide.

Quick-start control areas:

  • Governance: board oversight, named control owners, escalation pathways
  • Policies: version-controlled, approved, and communicated to staff
  • KYC and AML: identity verification, sanctions screening, transaction monitoring
  • HR and training: completion records, role-based training logs
  • Technical access controls: access reviews, privileged account logs
  • Vendor oversight: due diligence records, contract compliance clauses
  • Evidence: dated, signed, retained to schedule

A 'no' on any checklist item is not automatically a legal breach. Treat it as a prioritised remediation signal, not a crisis.

Pro Tip: Before the review window opens, circulate a one-page evidence request list to each control owner. Collecting evidence reactively during the review itself is the single biggest cause of delays.

Hands sorting compliance evidence documents


Table of Contents

Your compliance review checklist grouped by control area

A practical checklist should carry four fields for every item: owner, refresh cadence, pass/fail status, and required evidence. Without those fields, responsibility stays ambiguous and auditors have nothing to test against.

Control areaSample checklist itemPass / FailExpected evidence
GovernanceNamed control owners documented and currentPass / FailGovernance register, board minutes
GovernanceEscalation pathway defined and testedPass / FailEscalation policy, test record
PoliciesAll policies version-controlled and approvedPass / FailPolicy register with approval signatures
PoliciesPolicies communicated to relevant staffPass / FailDistribution log, read-receipt records
Client onboarding / KYCIdentity verification completed for all clientsPass / FailVerified ID copies, CDD records
Client onboarding / KYCRisk rating assigned and documentedPass / FailRisk assessment form
Conflicts / independenceConflicts register maintained and reviewedPass / FailConflicts register, review sign-off
HR / trainingRole-based compliance training completedPass / FailTraining completion certificates
HR / trainingNew-joiner induction records retainedPass / FailInduction sign-off sheets
Service deliveryEngagement letters in place and signedPass / FailSigned engagement letters
Internal controls / testingAccess control reviews completedPass / FailAccess review log, approvals
Documentation / evidenceEvidence retained to schedule with version controlPass / FailEvidence register, retention log
Third-party / vendor oversightVendor due diligence completed and currentPass / FailDue diligence questionnaires, contracts
Data protection / GDPRROPA current and reviewedPass / FailRecord of Processing Activities
Data protection / GDPRData breach response procedure testedPass / FailTest record, incident log

Vertical infographic illustrating five steps of compliance review process

Adapting scope by size and sector. A small professional services firm may run the governance, policies, KYC, and data protection rows as its core set, adding HR and vendor rows as capacity allows. A regulated utility or financial institution should treat all ten areas as mandatory. Sector-specific add-ons include CDM checklist items for construction and infrastructure, and an ISO 55001 audit checklist layer for asset-intensive organisations.

Cadence guidance. High-risk control areas (KYC, access controls, data protection) warrant quarterly review. Governance and policy checks typically run biannually. A full cross-area review is normally annual, timed ahead of any external audit window.


How to run an 8-step compliance review

A structured 8-step process is the practical standard most audit teams follow. Here is the sequence, with suggested timing and role responsibilities.

  1. Define scope (1–2 days). The compliance officer identifies which regulations, frameworks, and business units are in scope. Output: a written scope statement signed by the review sponsor.

  2. Map applicable regulations and frameworks (1–2 days). Cross-reference the scope against relevant obligations: FCA rules, UK GDPR, HM Treasury AML guidance, ISO 27001, or sector-specific standards such as ISO 55001. Framework mapping determines which controls are in scope and what evidence auditors will expect.

  3. Assemble the review team (half a day). Assign a lead reviewer, evidence custodians for each control area, and a senior sponsor for escalation. Document the team in the review record.

  4. Pre-audit documentation review (2–3 days). Collect the current policy register, training records, contracts, and prior review findings. Identify obvious gaps before testing begins.

  5. Gap analysis (1–2 days). Compare documented controls against the checklist. Flag items where evidence is absent, outdated, or unsigned. A pre-audit gap assessment with owners assigned is far more effective than discovering gaps under external audit pressure.

  6. Test controls using sampling (2–5 days depending on scope). Select a representative sample from each control area. For access controls, pull the last 90 days of access logs. For training, sample 10–15 completion records. Document the sample size, selection method, and result.

  7. Collect and validate evidence (1–3 days). Evidence must be dated, version-controlled, and operationally verified, not just a static screenshot of a policy. Signed approvals, system-generated logs, and training certificates all carry more weight than unsigned documents.

  8. Report findings and remediate (ongoing). Produce a structured findings report, assign remediation owners, set deadlines, and track to closure with evidence of resolution. See the reporting section below for the report structure.

Suggested total timeline: a focused single-domain review can complete in one to two weeks. A full cross-area review typically runs three to six weeks for a mid-sized organisation.

Pro Tip: Centralise your evidence intake into a single folder structure or digital platform before Step 4. Teams that collect evidence into a shared, named repository cut their pre-audit preparation time significantly compared with those chasing files across email threads and shared drives. A well-managed PBC list is the fastest way to do this.


What audit-ready evidence management actually looks like

Control mapping ties each policy and technical control to a verifiable daily practice. Without it, organisations struggle to defend their compliance posture when an external auditor asks for proof. The mapping table below is the template to build from.

ControlOwnerRequired evidenceSample locationRetention rule
Access control reviewIT Security ManagerAccess review log, approvalsIT shared drive / platform3 years
AML transaction monitoringMLROAlert investigation recordsAML system export5 years (FCA)
Staff compliance trainingHR ManagerCompletion certificatesLMS exportDuration of employment + 3 years
Data breach response testDPOTest record, incident logData protection folder3 years
Vendor due diligenceProcurement LeadCompleted DDQ, contractContract management systemContract term + 3 years

Practical validity checks for evidence:

  • Dates: every document must carry a creation or approval date; undated policies fail the test
  • Approvals: signed by the named owner, not just the drafter
  • Logs: system-generated logs are preferred over manually compiled spreadsheets
  • Test outputs: for technical controls, retain the raw output, not a summary
  • Training certificates: must show the individual's name, course title, and completion date

Pro Tip: Run a five-minute "blocker check" two weeks before any external audit: pull one sample from each control area and verify it meets the validity criteria above. This catches the most common audit blockers — undated policies, missing signatures, and expired certificates — while there is still time to fix them.


AML and KYC checklist for UK financial services

UK financial services firms face specific obligations under FCA rules and HM Treasury AML guidance. The items below function as an add-on layer to the core checklist.

Client identity verification (KYC):

  • Customer due diligence (CDD) completed for all clients before onboarding
  • Enhanced due diligence (EDD) applied to high-risk clients, PEPs, and complex structures
  • Beneficial ownership verified and documented
  • Risk rating assigned, recorded, and reviewed at defined intervals

Ongoing monitoring:

  • Transaction monitoring system active with documented alert thresholds
  • Alert investigations recorded with outcome and sign-off
  • Periodic KYC refresh completed for existing clients based on risk rating

Sanctions and PEP screening:

  • Screening run at onboarding and at defined intervals thereafter
  • Screening logs retained with date, source, and result
  • Escalation records held for any positive matches

Suspicious activity reporting:

  • SAR filing procedure documented and tested
  • SARs filed with the National Crime Agency (NCA) where required
  • Internal escalation records retained, linked to the relevant transaction timeline

The FCA expects firms to maintain an auditable trail of KYC decisions, screen against sanctions and PEP lists, and run transaction monitoring with documented alert investigations. These are baseline expectations, not aspirational standards — gaps here attract supervisory attention quickly.

Evidence expectations: retain verified ID copies, CDD and EDD records, screening logs, alert investigation records, and SAR filings. The standard retention period under the Money Laundering Regulations 2017 is five years from the end of the business relationship.

High-risk triggers requiring EDD include: clients in high-risk jurisdictions, PEPs and their associates, complex or unusual ownership structures, and transactions with no apparent economic rationale.


How to report findings and manage remediation to closure

A findings report that lands well with senior management has a clear structure. The audit report format matters as much as the content: a disorganised report buries the risk signal.

Sample report outline:

  1. Executive summary: scope, review period, overall RAG rating, top three findings
  2. Methodology: team, approach, sample sizes
  3. High-priority findings: control area, gap description, root cause, recommended action, owner, due date
  4. Medium and low findings: same fields, condensed
  5. Positive observations: controls operating effectively
  6. Remediation plan: owner, deadline, evidence required on closure

Remediation tracker fields to capture:

  • Finding reference and control area
  • Risk rating (Red / Amber / Green)
  • Root cause category (process gap, training gap, system gap, ownership gap)
  • Recommended action
  • Named owner
  • Due date
  • Status (open, in progress, closed)
  • Evidence of closure (document reference or upload)

Remediation stalls most often when findings have no named owner, no deadline, and no defined evidence requirement for closure. A finding marked "closed" with no supporting evidence is not closed — it is deferred.

Escalation thresholds. Red-rated findings should be escalated to the compliance committee or board within five working days of the report being issued. Amber findings with no owner assigned after ten working days should trigger a follow-up from the compliance officer.

Presenting risk to senior management. Frame findings in terms of regulatory consequence and operational impact, not technical detail. A finding described as "access controls not reviewed in 18 months" lands harder than "access review cadence non-compliant with policy."


Choosing the right template format: PDF, CSV, or digital

The format you choose affects how well evidence survives an audit, not just how easy the review is to run.

PDF. Best for board packs, external audit submissions, and point-in-time snapshots. PDFs are easy to share and hard to alter accidentally. The limitation is that they are static: you cannot update a finding or add evidence without creating a new version.

CSV and Excel. Flexible for building custom checklists and running gap analyses. The risk is version control: without strict file-naming discipline, teams end up with multiple conflicting versions. A compliance checklist template that saves each run with a timestamp is specifically useful here, because the timestamp becomes part of the audit trail.

Digital platforms. The strongest option for ongoing compliance management. A digital tool centralises evidence, timestamps every update, and produces exportable reports without manual assembly. For teams running continuous assurance, a digital platform removes the version-control problem entirely.

Quick implementation tips:

  • Use a canonical file-naming convention: [ControlArea]_[ReviewDate]_[Version] (e.g. DataProtection_2026-03_v2)
  • Tag every evidence file with a retention date at upload
  • Maintain a single PBC list per review cycle and update it in real time
  • Export a PDF summary at the close of each review cycle for the audit file
  • Restrict edit access to evidence files once a review cycle closes

Pro Tip: When sharing evidence with external auditors, export a read-only PDF of the completed checklist alongside the evidence pack. Auditors can navigate it without needing access to your internal systems, which speeds up fieldwork considerably.


UK regulatory references every compliance team should align to

Framework mapping is how you decide which controls are in scope and what evidence auditors will expect. The table below maps the primary UK references to the control areas they govern.

Regulator / bodyPrimary guidanceControl areas covered
FCAFCA Handbook (SYSC, COBS, CASS)Governance, conduct, client money, conflicts
ICOUK GDPR, Data Protection ActData protection, ROPA, breach response
HM TreasuryMoney Laundering Regulations 2017, AML guidanceKYC, AML, transaction monitoring, SARs
ICAEWPractice Assurance compliance review helpsheetsGovernance, policies, engagement quality
ISO 27001Information security management standardTechnical access controls, incident management
ISO 27001Privacy information managementData protection, vendor oversight
ISO 55001Asset management systemsAsset condition, maintenance controls (utilities)

Maintaining a live reference list. Embed a reference column in your checklist template that cites the specific regulation or standard each item maps to. When a regulation is updated, the reference column tells you exactly which checklist items need review. For ISO 9001 internal audit teams, this approach also satisfies the standard's requirement for documented audit criteria.

When to escalate to specialists. Jurisdictional variance, novel product structures, and regulatory change all warrant legal or regulatory specialist input. The checklist is a starting point, not a substitute for qualified advice on complex or contested obligations.


Digitising compliance reviews: benefits, risks, and a readiness checklist

Digitising evidence collection converts audit preparation from a calendar event into an ongoing activity. Teams that centralise evidence into a timestamped repository stop scrambling before external audits and start maintaining a continuous, auditable record.

Practical benefits:

  • Reduced prep time: evidence is already collected and organised when the audit window opens
  • Single source of truth: no competing spreadsheet versions across departments
  • Easier control mapping: digital frameworks link each checklist item to its evidence record
  • Faster remediation tracking: RAG status updates in real time as owners close findings
  • Better executive reporting: automated summaries replace manual slide-building

Implementation readiness checklist:

  1. Scope the first pilot domain (start with one control area, not all ten)
  2. Identify evidence owners for that domain
  3. Select or build a template that includes owner, cadence, and evidence fields
  4. Centralise evidence intake into a single repository
  5. Define retention and export rules before the first run
  6. Measure time saved in the pilot before scaling to additional domains

Practical risks and mitigations:

  • Data security: ensure the platform meets ISO 27001 or equivalent; restrict access by role
  • Integration: check whether the tool connects to your HR system for training records and your IT system for access logs
  • Change management: brief evidence owners before the pilot; resistance usually comes from unclear expectations, not the technology itself
  • Training: a 30-minute walkthrough for evidence custodians is enough for most platforms

For teams evaluating best compliance software UK options, the key differentiators are evidence management depth, template flexibility, and the quality of executive reporting outputs.


Key takeaways

A structured compliance review checklist, run against all ten control areas with named owners and dated evidence, is the most direct route to audit readiness for UK compliance teams.

PointDetails
Cover all ten control areasGovernance, policies, KYC, conflicts, HR, service delivery, controls, evidence, vendors, and data protection form the complete scope.
Assign named owners before the review opensAmbiguous ownership is the leading cause of evidence gaps and stalled remediation.
Treat 'fails' as remediation signalsA checklist failure indicates a programme gap to fix proportionately, not an immediate legal breach.
Dated, version-controlled evidence is the standardSigned policies alone are insufficient; auditors expect operational proof such as logs, certificates, and test outputs.
Intelligentassessments digitises the processThe platform replaces manual spreadsheets with structured frameworks, evidence management, and real-time RAG dashboards for continuous assurance.

The review that never quite finishes

Most compliance reviews stall for the same three reasons: nobody owns the evidence for a specific control, the scope was defined too broadly to complete in the available time, and the team treats the review as a once-a-year event rather than a continuous process.

The conventional wisdom is that a bigger, more thorough review is always better. It is not. A focused quarterly review of your highest-risk control areas produces more reliable assurance than an annual sweep that runs out of steam before it reaches vendor oversight or data protection. Auditors notice when the last three rows of a checklist are consistently blank.

The other thing practitioners underestimate is how much of the work happens before the review formally opens. Teams that invest two days in scoping, evidence pre-collection, and owner briefing complete their reviews faster and with fewer findings than teams that start cold. The checklist is not the hard part. Getting the right people to supply the right evidence on time is.

Small, focused cycles. Named owners. Dated evidence. Those three habits do more for audit readiness than any template.


Intelligentassessments cuts audit prep time for compliance teams

Spreadsheet-based compliance reviews have a ceiling: version conflicts, missing evidence, and manual report-building consume time that should go into actual risk analysis. Intelligentassessments replaces that process with a continuous assurance platform built for regulated UK organisations.

Intelligentassessments

The platform gives compliance officers structured assessment frameworks, centralised evidence management with version control, weighted RAG scoring that rolls up across control areas, and instant PDF reporting for board packs and external auditors. Evidence owners upload directly into the platform; the audit trail builds itself. There are no competing spreadsheet versions and no last-minute scramble before an external audit.

For teams ready to move from annual checklists to continuous assurance, book a demo to see how Intelligentassessments handles evidence mapping, remediation tracking, and executive reporting in a single platform.


Useful UK sources and further reading