0 of 39 items completed 0%
Pre-Audit Preparation Confirm the scope and focus areas of the upcoming regulatory examination Assign an internal audit coordinator as the single point of contact for regulators Notify all relevant business lines and functions of the examination scope and timeline Review findings from the previous examination and confirm all remediation actions are complete Conduct an internal pre-audit review of the areas in scope Identify and brief all staff who may be interviewed by regulators Prepare a summary of material changes since the last examination (products, processes, systems)
Document & Evidence Preparation Compile the standard document pack: policies, procedures, organisational charts, and governance minutes Prepare a complete register of all regulatory reports submitted in the review period Gather evidence of control testing and assurance activities Prepare a log of all regulatory breaches, near-misses, and complaints in the review period Compile evidence of staff training completion for regulated activities Prepare board and committee minutes relevant to the examination scope Gather evidence of any third-party assurance reports (SOC 2, penetration tests, etc.) Ensure all documents are version-controlled and clearly labelled with effective dates
Governance & Oversight Evidence Prepare a summary of the governance structure and committee terms of reference Compile evidence of management information provided to the board and risk committees Prepare a summary of the three lines of defence model and how it operates Gather evidence of senior management accountability and decision-making Prepare a summary of the risk appetite framework and how it is applied Compile evidence of whistleblowing and speak-up culture activities
Customer & Conduct Evidence Prepare a summary of customer complaint volumes, themes, and resolution outcomes Compile evidence of treating customers fairly / consumer duty compliance Gather evidence of product governance and suitability assessments Prepare a summary of vulnerable customer identification and support processes Compile evidence of financial promotions approval and review processes Gather evidence of AML/KYC controls and suspicious activity reporting
Technology & Data Evidence Prepare a summary of the technology architecture and key systems Compile evidence of cybersecurity controls and incident response capability Gather evidence of data governance and data quality management Prepare a summary of business continuity and disaster recovery testing Compile evidence of third-party and outsourcing risk management Gather evidence of change management and system testing processes
During the Examination Maintain a log of all regulator requests and responses Ensure all responses are reviewed by Legal and Compliance before submission Brief senior management daily on examination progress and emerging issues Do not provide documents outside the agreed scope without senior approval Escalate any unexpected regulator concerns to the CEO and Board immediately Keep a record of all meetings and interviews with regulators