← All articles
Compliance Operations17 minOctober 2026

How to Prepare Investor KYC Files for an Audit

Who reviews investor files and what they sample, the per-investor checklist, retention periods by jurisdiction, and a scored self-test to run before fieldwork starts.

RS
Rodolfo SantosReal Estate Compliance Attorney & Co-Founder, Verifica
How to Prepare Investor KYC Files for an Audit

Short Answer

To prepare investor KYC files for an audit, make every file show the same evidence in the same order: identity, entity and ownership documents, screening results with list dates, how each match was cleared, a risk rating with its reasoning, EDD where required, named and timestamped approvals, and periodic reviews. Then test a risk-weighted sample against your own policy, fix the gaps, and deliver an indexed export.

Key Takeaways

  • Auditors test files against your written policy, so a file that meets the law but not your own procedure is still a finding.
  • Screening evidence must show what was screened, against which lists, on what date, and who cleared each potential match and why.
  • In CIMA's 2022 to 2024 inspections of registered persons, 81% had weaknesses in CDD and ongoing monitoring, and 63% had gaps in their AML/CFT audit function.
  • Retention clocks mostly run five years from the end of the relationship. OFAC transaction records now run ten years.
  • Run a scored self-test on a risk-weighted sample about six weeks before fieldwork, and log every fix you make.

Most investor KYC findings are not about investors the fund should have rejected. They come from files that cannot prove what the team did. The ID is there but nothing records the authenticity check. The screening ran, but the file has no list date. A potential match was cleared and nobody wrote down why. This guide covers the file itself: who reviews it, what each investor file should contain, how long to keep it, and how to test a sample before anyone else does. For the wider record-keeping system behind the files, see our guide to building a defensible AML audit trail.


Who audits investor KYC files, and what do they sample?

At least six different reviewers may look at your investor files. Each one has a different mandate, so each samples differently. Knowing who is coming tells you which files they will pull and what they will test those files against.

ReviewerBasis for the reviewWhat they typically sample or ask for
Independent AML testerRequired under FinCEN's investment adviser rule, now effective January 1, 2028. OFAC lists testing and auditing as one of five essential compliance components.Files across all risk tiers, weighted toward high risk, tested against your written policy and risk methodology
Fund financial statement auditorAudit of the fund's financial statementsCapital activity, investor records behind capital accounts, and reliance on the administrator's controls
LP operational due diligence (ODD)ILPA DDQ 2.0 questions 13.26 to 13.27 (AML/CFT) and 13.23 to 13.24 (SSAE 18 / ISAE 3402 control reports)AML policy, description of controls, sometimes a redacted sample file or a walkthrough
Fund administrator's SOC 1 auditorAICPA SOC 1 examination of controls relevant to user entities' financial reportingThe administrator's onboarding controls. You receive the report and must check its scope.
SEC examinersDivision of Examinations FY2026 priorities: adviser OFAC monitoring, AML programs at broker-dealers and certain RICsSanctions screening evidence, onboarding records, policy versus practice
CIMA and CSSF inspectorsCayman AML Regulations; Luxembourg's AML/CFT Law of 12 November 2004 and CSSF Regulation 12-02Customer files, screening and match resolution, risk assessments, audit function evidence

Three points from this table matter for preparation.

First, the independent tester is the reviewer most likely to pull individual files and score them. Under the investment adviser rule FinCEN finalized in August 2024, testing must be done by a qualified outside party or an internal function not involved in running the program, and the rule sets no fixed frequency (Debevoise, 2024). FinCEN moved the rule's effective date from January 1, 2026 to January 1, 2028, and has said it will review the rule before then (FinCEN, December 31, 2025). Our guide to the 2028 rule covers the timeline in detail.

Second the SEC is already examining sanctions work. The FY2026 examination priorities say the Division will review whether broker-dealers, advisers and RICs are monitoring OFAC sanctions and ensuring compliance. For broker-dealers and certain RICs, the priorities also cover independent testing and customer identification, including beneficial owners of legal entity customers. Our SEC AML exam readiness guide goes through the document request list item by item.

Third, if your administrator runs KYC for you, its SOC 1 report is evidence for you, but only for the controls it covers. A SOC 1 is "an examination of controls at a service organization that are likely to be relevant to user entities' internal control over financial reporting" (AICPA & CIMA). It is built for financial reporting, so AML onboarding controls may be out of scope. Read the control descriptions and the complementary user entity controls before you tell anyone you rely on it.


What should a complete investor KYC file contain?

A complete investor KYC file contains the evidence and the decisions behind it. A reviewer should be able to see what you collected, what you checked, what you found, who decided, and when. Figure 1 shows the five layers, plus the audit trail that runs through all of them.

Anatomy of a complete investor KYC file

Figure 1. The five layers of an investor KYC file. Reviewers sample down through the layers, but most findings are in the audit trail column: a document is present, but nothing shows who checked it, when, or under which version of the policy.

Use the checklist below as the standard for every file. Where your written policy asks for more, your policy wins, because that is what the tester will test against.

Identity and address

  • Full legal name, date of birth, nationality, residential address and tax identification number
  • Government photo ID, with the document type, number, issuing country and expiry date recorded
  • Result of the document authenticity check and the liveness or selfie match, with date
  • Proof of address that meets the age limit in your policy

The FinCEN CDD rule's record-keeping paragraph is a useful model even for funds it does not yet cover. For each document relied on, it requires a description noting "the type, any identification number, place of issuance and, if any, date of issuance and expiration" (31 CFR 1010.230(i)). A scan alone does not meet that standard. The file also needs a record of what was verified.

Entity documents and beneficial ownership

  • Formation document, good standing or registry extract, and the governing document (operating agreement, partnership agreement, trust deed)
  • Register of directors or managers, and evidence of the authorized signatory's authority
  • Ownership chart traced to natural persons, with percentages and the date it was confirmed
  • Identity evidence for each beneficial owner above your threshold, plus the named control person
  • For fund-of-funds and nominees: the reliance letter or look-through evidence your policy requires

The 31 CFR 1010.230 baseline is each individual owning 25% or more of the equity, plus one individual with significant control. Many fund policies set lower thresholds for higher-risk investors and the tester will apply whatever your policy says. The chart also matters for sanctions. Under OFAC's 50 Percent Rule, an entity owned 50% or more in aggregate, directly or indirectly, by blocked persons is itself blocked (OFAC). If the chart stops before it reaches natural persons, nobody can show that test was run. Our guide to ultimate beneficial ownership covers how to trace layered structures.

Screening evidence and match disposition

  • List of every name screened: the investor, each beneficial owner, controllers, signatories, and the entity itself
  • Lists and sources used (for example OFAC SDN and non-SDN lists, UN, EU, UK, PEP, adverse media) with the provider and the run date and time
  • Match settings in use at the time (fuzzy threshold or equivalent)
  • For each potential match: the identifiers compared, the disposition (true match, false positive, escalated), the rationale, the reviewer's name and the date
  • Ongoing monitoring evidence: re-screening dates or alert history since onboarding

The rationale is the item most often missing. "Cleared, false positive" is not a rationale. "Different date of birth (1971 vs 1958) and nationality; no other identifiers in common" is. For more on screening scope and frequency, see our guide to OFAC sanctions screening for US funds.

Risk rating, EDD and source of funds

  • Risk rating, the factors scored, and the version of the risk methodology applied
  • Any manual override, with the reason and the approver
  • Source of funds for the subscription (where the money comes from and which account it is paid from)
  • For high-risk investors and PEPs: source of wealth, adverse media review, EDD memo and senior sign-off

A rating with no factors behind it is a frequent finding, because the tester cannot reproduce it. Store the scored factors, not just the result.

Approvals, reviews and tax forms

  • Approval to accept the investor: approver name, role and timestamp, dated before the capital was accepted
  • Exceptions (for example a document accepted late) with written approval and a deadline
  • Periodic review history at the frequency your policy sets for that risk rating, with what was re-checked
  • Current W-9 or W-8 form, and any self-certifications your policy requires

Sequence matters. An approval timestamp that falls after the subscription was accepted is a finding even if every document is present. CSSF has sanctioned the same sequencing problem with intermediaries, citing a distributor agreement signed before initial due diligence was complete (CSSF, 2024).


Which program-level documents will the auditor ask for?

Auditors test files against your program, so they ask for the program first. Have these ready in one folder, each with a version number and an approval date.

  • AML/KYC policy and procedures, including every version in force during the review period
  • Enterprise AML and sanctions risk assessment, with the date it was last updated
  • Customer risk rating methodology, with its version history
  • Designation of the AML compliance officer and the board or management approval
  • Training materials, attendance logs and completion dates for each relevant employee
  • Prior independent test reports, findings, the remediation plan and evidence each item was closed
  • Delegation agreements with administrators or placement agents, and your oversight evidence (SOC reports, review notes)
  • The investor population list for the review period, with risk ratings, onboarding dates and status

Prior findings deserve particular care. A finding that appears again in the next test is treated more seriously than a new one, and OFAC's compliance framework expects organizations to fix the weaknesses testing identifies (OFAC, A Framework for OFAC Compliance Commitments). For how these documents map to the program as a whole, see the five pillars of a BSA/AML program.


How long must investor KYC records be kept?

In most regimes, the answer is at least five years after the investor relationship ends, not five years after onboarding. US sanctions records are now the exception at ten years.

RegimeRetention periodClock starts
US: FinCEN CDD rule, 31 CFR 1010.230(i) (covered institutions; not yet investment advisers)5 yearsIdentifying information: after the account is closed. Verification records: after the record is made.
US: OFAC, 31 CFR 501.601 (amended effective March 21, 2025)10 yearsFrom the date of each transaction subject to OFAC regulations
EU: AMLR, Regulation (EU) 2024/1624, Article 77 (applies from July 10, 2027)5 years; authorities may require up to 5 more, case by caseEnd of the business relationship, the occasional transaction, or the refusal to onboard. Personal data must then be deleted.
UK: Money Laundering Regulations 2017, regulation 405 yearsWhen the firm knows or has reasonable grounds to believe the relationship has ended or the transaction is complete
Cayman: Anti-Money Laundering Regulations (2023 Revision), regulation 31At least 5 yearsTermination of the business relationship; records must be available without delay

Sources: 31 CFR 1010.230; Greenberg Traurig on the OFAC final rule; Regulation (EU) 2024/1624; UK MLR 2017, reg. 40; Cayman AML Regulations (2023 Revision).

Two practical consequences follow. First, for a closed-end fund with a ten-year term plus extensions, a file opened at first close may have to be kept for fifteen years or more. Second, the EU and UK rules require deletion once the period ends, so "keep everything forever" is not a safe default for European investors' personal data. Set retention by jurisdiction in your policy, and record when each relationship ended, because that date starts the clock. Confirm the periods with counsel for your fund's domiciles.


How do you run a pre-audit self-test on your investor files?

A self-test is a small version of the audit, run by you, early enough to fix what it finds. Draw a risk-weighted sample, score every file against the checklist above, and remediate before the reviewer arrives. Start about eight weeks out, as Figure 2 shows.

Pre-audit timeline from eight weeks out to audit day

Figure 2. A suggested eight-week schedule. Most of the time goes to the Fix stage, because remediation needs investors to respond and you cannot speed that up.

The method, step by step:

  1. Pull the population. List every investor onboarded or reviewed in the audit period, with investor type, risk rating, onboarding date and jurisdiction.
  2. Draw a risk-weighted sample. No US rule sets a sample size for advisers. A workable internal standard is 25 files or 10% of the population, whichever is larger, with every high-risk and PEP investor included, at least one file from each investor type, and every file touched by a prior finding.
  3. Score each file against the checklist. Use the three-point scale below for each element. Score against your written policy as it stood when the file was opened, not as it stands today.
  4. Rank the gaps. Total the scores by element across the sample. An element that fails in many files is a process problem. A single failure is a file problem. They need different fixes.
  5. Remediate and log. Fix the files, but never backdate. Add the missing evidence with today's date and a note explaining the gap. A dated remediation log is a strength in an audit. A file that was quietly altered is a serious problem.
  6. Re-test. Re-score a few remediated files to confirm the fix holds.
Element2 = complete1 = partial0 = missing
Identity verificationID, check result and date recordedID on file, no check resultNo valid ID
Ownership (entities)Chart to natural persons, all UBOs verifiedChart present, some UBOs unverifiedNo chart
ScreeningAll parties, lists, date and settings recordedInvestor only, or no list dateNo screening record
Match dispositionIdentifiers compared, rationale, reviewer, date"False positive" with no reasoningUnresolved match
Risk ratingFactors, methodology version, override reasonRating onlyNo rating
EDD / SoF / SoWEvidence and senior sign-offDeclaration onlyRequired but absent
ApprovalNamed, timestamped, before acceptanceApproved after acceptanceNo approval
Periodic reviewOn schedule, contents recordedLate or undocumented scopeOverdue with no plan

Scoring by element across investor types shows where the process breaks. Figure 3 is an illustrative result. The numbers are invented to show the method, not drawn from any survey.

Illustrative self-test heatmap: percentage of sampled files passing, by element and investor type

Figure 3. An illustrative self-test result. Read it by row: a row that is red across every investor type, here match disposition, points to a procedure or tooling gap rather than a few weak files.


What are the most common investor KYC audit findings, and how do you fix them?

The most common findings are documentation gaps, not wrong decisions: unverified beneficial owners, screening with no evidence of how matches were resolved, risk ratings with no reasoning, and overdue periodic reviews. Published regulator data shows the pattern clearly.

The Cayman Islands Monetary Authority reviewed inspections of 113 registered persons under the Securities Investment Business Act between January 2022 and March 2024 (CIMA, May 8, 2025). It found:

  • 81% of the registered persons inspected had weaknesses in their CDD and ongoing monitoring programs.
  • 28% of findings concerned weak documentation of sanctions screening, at onboarding and on an ongoing basis, and of how potential matches were resolved.
  • 19% of findings concerned weak documentation of identification and verification of ultimate beneficial owners, controllers and relevant parties.
  • 18% of findings concerned weak documentation of ongoing monitoring, including periodic file reviews.
  • 63% of registered persons had gaps in their AML/CFT audit function, including audits that did not test effectiveness and no evidence of independence.
FindingUsual root causeRemediation
UBO identity not verifiedOwnership chart collected but individuals never onboardedVerify each UBO above the threshold. Add a step that blocks approval until every UBO is verified.
Match cleared with no rationaleScreening tool records the outcome, not the reasoningWrite a rationale for each open file. Make a written rationale a required field before a match can be closed.
Screening covers the investor onlyRelated parties never entered into the screening toolRe-screen all UBOs, controllers and signatories, and record the run date.
No list date or versionScreenshots or exports without metadataRe-run and keep the provider's report showing lists and timestamp.
Risk rating unexplainedRating typed in by handRe-rate using the methodology, store the factors, and record the version.
Approval after capital acceptedApproval done by email, recorded laterRecord a late-approval exception, then require approval before the capital call or closing.
Periodic reviews overdueNo calendar tied to risk ratingClear the backlog with high-risk files first. Set review dates automatically from the rating.
Prior finding repeatedRemediation plan with no owner or closure evidenceAssign an owner and a date to each item, and file the evidence that it was closed.

Luxembourg shows a similar pattern. In a 2024 sanction against a fund manager, CSSF found that one distributor agreement was signed before initial due diligence was complete. For two distributors, annual reviews required by the manager's own policy were still not done two years late. Five distributors had not been screened against sanctions and PEP lists in due time. The manager also relied on a group ISAE 3402 control report that covered only a small portion of its applications (CSSF, 2024). In March 2026 CSSF said the fight against money laundering, terrorist financing and proliferation financing "remains a key priority" for fund supervision (CSSF, 2026).


How should you present KYC files to an auditor?

Present files so the reviewer finds every item in the same place in every file. That means an index, consistent naming, and one export per investor that opens without your systems.

  • A master index (spreadsheet) listing each investor ID, legal name, type, jurisdiction, risk rating, onboarding date, last review date, approver and the path to the file
  • Consistent naming, for example INV-0142_03-Screening_2026-08-14.pdf: investor ID, a numbered section matching the checklist, and the date of the evidence
  • Fixed section order in every file: 01 Identity, 02 Entity and UBO, 03 Screening, 04 Risk and EDD, 05 Approvals, 06 Reviews, 07 Tax
  • A one-page summary at the front of each file with the status of each section and the audit trail extract
  • Read-only exports (PDF plus the original files) with the audit log included, so timestamps cannot be questioned
  • A request tracker during fieldwork: request, date received, owner, date delivered

Deliver only what was requested and keep a copy of everything you send. Redact only where the reviewer agrees. Note that Article 77 of the EU AMLR states that records retained under it must not be redacted for competent authorities. Agree on secure transfer before the first file goes out.


How Verifica produces audit-ready investor files

Most of the findings above come from evidence that was never captured at the time of the check. Verifica is built to capture it. Each investor completes one guided flow with smart forms tailored to their investor type: government ID with document authenticity checks, biometric liveness, sanctions, PEP and adverse-media screening powered by LSEG Risk Intelligence, and UBO mapping for companies, trusts and fund-of-funds structures. Every step is timestamped in the audit trail.

Anything that needs judgment, such as a potential match, is flagged to a human reviewer rather than auto-approved, so the disposition and reviewer are recorded in the file. Once the checks complete, Verifica generates the KYC file in under 60 seconds as an exportable, timestamped audit file, so each investor file follows the same structure. Ongoing monitoring is available for re-screening after onboarding.

Verifica is software, not a law firm. Your risk thresholds, policy and sign-off stay with your team, and your self-test should still score Verifica files against your own policy.


Frequently Asked Questions

What should be in an investor KYC file for an audit?

Identity evidence with the verification result, address proof, and for entities the formation documents, an ownership chart traced to natural persons and verified beneficial owners. Add screening results showing lists, dates and how each match was cleared, a risk rating with its factors, EDD and source of funds where required, a named and timestamped approval, periodic review history and tax forms.

How many investor files will an auditor sample?

No US rule fixes a sample size for advisers, and testers set their own sample based on risk. Expect them to over-weight high-risk investors, PEPs, complex entities and areas with prior findings. For your own self-test, a workable standard is 25 files or 10% of the population, whichever is larger, with every high-risk file included.

How long do I need to keep investor KYC records?

Generally at least five years after the relationship ends. That is the period under the EU AMLR from July 10, 2027, the UK MLR 2017 and Cayman's AML Regulations. FinCEN's CDD rule uses five years for covered institutions. OFAC raised its recordkeeping period for transactions subject to sanctions regulations to ten years from March 21, 2025.

Do I need to keep proof of which sanctions lists I screened against?

Yes, in practice. A result reading "no match" proves little unless the file shows which lists and sources were checked, when the screening ran, and which names were included. CIMA found that 28% of findings in its 2022 to 2024 inspections of registered persons concerned weak documentation of sanctions screening and match resolution.

What is the most common investor KYC audit finding?

Missing documentation of decisions that were actually made. Typical examples are beneficial owners named but not verified, potential matches cleared without a written rationale, risk ratings with no recorded factors, and overdue periodic reviews. CIMA found weaknesses in CDD and ongoing monitoring at 81% of the registered persons it inspected between 2022 and 2024.

Can I rely on my fund administrator's KYC for an audit?

You can delegate the work, but not the responsibility. Get the administrator's SOC 1 report and check whether it actually covers AML onboarding controls, since SOC 1 is designed around financial reporting. Keep your own oversight evidence, such as periodic file reviews of the administrator's work, and be ready to produce sample files on request.

Does FinCEN's investment adviser AML rule apply yet?

No. FinCEN postponed the effective date from January 1, 2026 to January 1, 2028, and said it will review the rule before then. OFAC sanctions obligations already apply, and the SEC's FY2026 priorities include reviewing whether advisers monitor OFAC sanctions. Investor files built to a full standard now will hold up under either regime.


Sources

  1. 31 CFR 1010.230, Beneficial ownership requirements for legal entity customers (FinCEN rule, via Cornell LII)
  2. FinCEN Issues Final Rule to Postpone Effective Date of Investment Adviser Rule to 2028 (FinCEN, December 31, 2025)
  3. Fact Sheet: Investment Adviser AML/CFT Program Final Rule (FinCEN, August 28, 2024)
  4. New Anti-Money Laundering Requirements for Investment Advisers: Ten FAQs (Debevoise & Plimpton, September 9, 2024)
  5. Examination Priorities, Fiscal Year 2026 (SEC Division of Examinations, November 17, 2025)
  6. US Treasury Extends Recordkeeping Requirement for Economic Sanctions Compliance to 10 Years (Greenberg Traurig, April 2025, on OFAC's final rule of March 20, 2025)
  7. A Framework for OFAC Compliance Commitments (OFAC, May 2019)
  8. Entities Owned by Blocked Persons (50 Percent Rule) (OFAC FAQs)
  9. Regulation (EU) 2024/1624 (AMLR), Articles 77 and 90 (Official Journal of the EU, June 19, 2024)
  10. The Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017, regulation 40 (legislation.gov.uk)
  11. Anti-Money Laundering Regulations (2023 Revision), regulation 31 (Cayman Islands)
  12. Key Findings from On-site Inspections of Registered Persons (CIMA, May 8, 2025)
  13. Administrative sanction of 2 April 2024 (CSSF, published July 12, 2024)
  14. The CSSF's 2026 priorities for supervising the investment fund sector (CSSF, March 31, 2026)
  15. ILPA Due Diligence Questionnaire 2.0 (ILPA, November 2021)
  16. SOC 1: SOC for Service Organizations, ICFR (AICPA & CIMA)
Rodolfo Santos

Rodolfo Santos is a real estate compliance attorney with 10+ years of experience in cross-border transactions and the co-founder of Verifica, an AI-powered compliance platform for real estate professionals. He has closed over 150 property transactions worth more than €50 million.

See a full check run
on a real file.

Identity, documents, and screening in one engine, start to report.

Request a demo