How to Prepare Investor KYC Files for an Audit
Who reviews investor files and what they sample, the per-investor checklist, retention periods by jurisdiction, and a scored self-test to run before fieldwork starts.

Short Answer
To prepare investor KYC files for an audit, make every file show the same evidence in the same order: identity, entity and ownership documents, screening results with list dates, how each match was cleared, a risk rating with its reasoning, EDD where required, named and timestamped approvals, and periodic reviews. Then test a risk-weighted sample against your own policy, fix the gaps, and deliver an indexed export.
Key Takeaways
- Auditors test files against your written policy, so a file that meets the law but not your own procedure is still a finding.
- Screening evidence must show what was screened, against which lists, on what date, and who cleared each potential match and why.
- In CIMA's 2022 to 2024 inspections of registered persons, 81% had weaknesses in CDD and ongoing monitoring, and 63% had gaps in their AML/CFT audit function.
- Retention clocks mostly run five years from the end of the relationship. OFAC transaction records now run ten years.
- Run a scored self-test on a risk-weighted sample about six weeks before fieldwork, and log every fix you make.
Most investor KYC findings are not about investors the fund should have rejected. They come from files that cannot prove what the team did. The ID is there but nothing records the authenticity check. The screening ran, but the file has no list date. A potential match was cleared and nobody wrote down why. This guide covers the file itself: who reviews it, what each investor file should contain, how long to keep it, and how to test a sample before anyone else does. For the wider record-keeping system behind the files, see our guide to building a defensible AML audit trail.
Who audits investor KYC files, and what do they sample?
At least six different reviewers may look at your investor files. Each one has a different mandate, so each samples differently. Knowing who is coming tells you which files they will pull and what they will test those files against.
| Reviewer | Basis for the review | What they typically sample or ask for |
|---|---|---|
| Independent AML tester | Required under FinCEN's investment adviser rule, now effective January 1, 2028. OFAC lists testing and auditing as one of five essential compliance components. | Files across all risk tiers, weighted toward high risk, tested against your written policy and risk methodology |
| Fund financial statement auditor | Audit of the fund's financial statements | Capital activity, investor records behind capital accounts, and reliance on the administrator's controls |
| LP operational due diligence (ODD) | ILPA DDQ 2.0 questions 13.26 to 13.27 (AML/CFT) and 13.23 to 13.24 (SSAE 18 / ISAE 3402 control reports) | AML policy, description of controls, sometimes a redacted sample file or a walkthrough |
| Fund administrator's SOC 1 auditor | AICPA SOC 1 examination of controls relevant to user entities' financial reporting | The administrator's onboarding controls. You receive the report and must check its scope. |
| SEC examiners | Division of Examinations FY2026 priorities: adviser OFAC monitoring, AML programs at broker-dealers and certain RICs | Sanctions screening evidence, onboarding records, policy versus practice |
| CIMA and CSSF inspectors | Cayman AML Regulations; Luxembourg's AML/CFT Law of 12 November 2004 and CSSF Regulation 12-02 | Customer files, screening and match resolution, risk assessments, audit function evidence |
Three points from this table matter for preparation.
First, the independent tester is the reviewer most likely to pull individual files and score them. Under the investment adviser rule FinCEN finalized in August 2024, testing must be done by a qualified outside party or an internal function not involved in running the program, and the rule sets no fixed frequency (Debevoise, 2024). FinCEN moved the rule's effective date from January 1, 2026 to January 1, 2028, and has said it will review the rule before then (FinCEN, December 31, 2025). Our guide to the 2028 rule covers the timeline in detail.
Second the SEC is already examining sanctions work. The FY2026 examination priorities say the Division will review whether broker-dealers, advisers and RICs are monitoring OFAC sanctions and ensuring compliance. For broker-dealers and certain RICs, the priorities also cover independent testing and customer identification, including beneficial owners of legal entity customers. Our SEC AML exam readiness guide goes through the document request list item by item.
Third, if your administrator runs KYC for you, its SOC 1 report is evidence for you, but only for the controls it covers. A SOC 1 is "an examination of controls at a service organization that are likely to be relevant to user entities' internal control over financial reporting" (AICPA & CIMA). It is built for financial reporting, so AML onboarding controls may be out of scope. Read the control descriptions and the complementary user entity controls before you tell anyone you rely on it.
What should a complete investor KYC file contain?
A complete investor KYC file contains the evidence and the decisions behind it. A reviewer should be able to see what you collected, what you checked, what you found, who decided, and when. Figure 1 shows the five layers, plus the audit trail that runs through all of them.
Figure 1. The five layers of an investor KYC file. Reviewers sample down through the layers, but most findings are in the audit trail column: a document is present, but nothing shows who checked it, when, or under which version of the policy.
Use the checklist below as the standard for every file. Where your written policy asks for more, your policy wins, because that is what the tester will test against.
Identity and address
- Full legal name, date of birth, nationality, residential address and tax identification number
- Government photo ID, with the document type, number, issuing country and expiry date recorded
- Result of the document authenticity check and the liveness or selfie match, with date
- Proof of address that meets the age limit in your policy
The FinCEN CDD rule's record-keeping paragraph is a useful model even for funds it does not yet cover. For each document relied on, it requires a description noting "the type, any identification number, place of issuance and, if any, date of issuance and expiration" (31 CFR 1010.230(i)). A scan alone does not meet that standard. The file also needs a record of what was verified.
Entity documents and beneficial ownership
- Formation document, good standing or registry extract, and the governing document (operating agreement, partnership agreement, trust deed)
- Register of directors or managers, and evidence of the authorized signatory's authority
- Ownership chart traced to natural persons, with percentages and the date it was confirmed
- Identity evidence for each beneficial owner above your threshold, plus the named control person
- For fund-of-funds and nominees: the reliance letter or look-through evidence your policy requires
The 31 CFR 1010.230 baseline is each individual owning 25% or more of the equity, plus one individual with significant control. Many fund policies set lower thresholds for higher-risk investors and the tester will apply whatever your policy says. The chart also matters for sanctions. Under OFAC's 50 Percent Rule, an entity owned 50% or more in aggregate, directly or indirectly, by blocked persons is itself blocked (OFAC). If the chart stops before it reaches natural persons, nobody can show that test was run. Our guide to ultimate beneficial ownership covers how to trace layered structures.
Screening evidence and match disposition
- List of every name screened: the investor, each beneficial owner, controllers, signatories, and the entity itself
- Lists and sources used (for example OFAC SDN and non-SDN lists, UN, EU, UK, PEP, adverse media) with the provider and the run date and time
- Match settings in use at the time (fuzzy threshold or equivalent)
- For each potential match: the identifiers compared, the disposition (true match, false positive, escalated), the rationale, the reviewer's name and the date
- Ongoing monitoring evidence: re-screening dates or alert history since onboarding
The rationale is the item most often missing. "Cleared, false positive" is not a rationale. "Different date of birth (1971 vs 1958) and nationality; no other identifiers in common" is. For more on screening scope and frequency, see our guide to OFAC sanctions screening for US funds.
Risk rating, EDD and source of funds
- Risk rating, the factors scored, and the version of the risk methodology applied
- Any manual override, with the reason and the approver
- Source of funds for the subscription (where the money comes from and which account it is paid from)
- For high-risk investors and PEPs: source of wealth, adverse media review, EDD memo and senior sign-off
A rating with no factors behind it is a frequent finding, because the tester cannot reproduce it. Store the scored factors, not just the result.
Approvals, reviews and tax forms
- Approval to accept the investor: approver name, role and timestamp, dated before the capital was accepted
- Exceptions (for example a document accepted late) with written approval and a deadline
- Periodic review history at the frequency your policy sets for that risk rating, with what was re-checked
- Current W-9 or W-8 form, and any self-certifications your policy requires
Sequence matters. An approval timestamp that falls after the subscription was accepted is a finding even if every document is present. CSSF has sanctioned the same sequencing problem with intermediaries, citing a distributor agreement signed before initial due diligence was complete (CSSF, 2024).
Which program-level documents will the auditor ask for?
Auditors test files against your program, so they ask for the program first. Have these ready in one folder, each with a version number and an approval date.
- AML/KYC policy and procedures, including every version in force during the review period
- Enterprise AML and sanctions risk assessment, with the date it was last updated
- Customer risk rating methodology, with its version history
- Designation of the AML compliance officer and the board or management approval
- Training materials, attendance logs and completion dates for each relevant employee
- Prior independent test reports, findings, the remediation plan and evidence each item was closed
- Delegation agreements with administrators or placement agents, and your oversight evidence (SOC reports, review notes)
- The investor population list for the review period, with risk ratings, onboarding dates and status
Prior findings deserve particular care. A finding that appears again in the next test is treated more seriously than a new one, and OFAC's compliance framework expects organizations to fix the weaknesses testing identifies (OFAC, A Framework for OFAC Compliance Commitments). For how these documents map to the program as a whole, see the five pillars of a BSA/AML program.
How long must investor KYC records be kept?
In most regimes, the answer is at least five years after the investor relationship ends, not five years after onboarding. US sanctions records are now the exception at ten years.
| Regime | Retention period | Clock starts |
|---|---|---|
| US: FinCEN CDD rule, 31 CFR 1010.230(i) (covered institutions; not yet investment advisers) | 5 years | Identifying information: after the account is closed. Verification records: after the record is made. |
| US: OFAC, 31 CFR 501.601 (amended effective March 21, 2025) | 10 years | From the date of each transaction subject to OFAC regulations |
| EU: AMLR, Regulation (EU) 2024/1624, Article 77 (applies from July 10, 2027) | 5 years; authorities may require up to 5 more, case by case | End of the business relationship, the occasional transaction, or the refusal to onboard. Personal data must then be deleted. |
| UK: Money Laundering Regulations 2017, regulation 40 | 5 years | When the firm knows or has reasonable grounds to believe the relationship has ended or the transaction is complete |
| Cayman: Anti-Money Laundering Regulations (2023 Revision), regulation 31 | At least 5 years | Termination of the business relationship; records must be available without delay |
Sources: 31 CFR 1010.230; Greenberg Traurig on the OFAC final rule; Regulation (EU) 2024/1624; UK MLR 2017, reg. 40; Cayman AML Regulations (2023 Revision).
Two practical consequences follow. First, for a closed-end fund with a ten-year term plus extensions, a file opened at first close may have to be kept for fifteen years or more. Second, the EU and UK rules require deletion once the period ends, so "keep everything forever" is not a safe default for European investors' personal data. Set retention by jurisdiction in your policy, and record when each relationship ended, because that date starts the clock. Confirm the periods with counsel for your fund's domiciles.
How do you run a pre-audit self-test on your investor files?
A self-test is a small version of the audit, run by you, early enough to fix what it finds. Draw a risk-weighted sample, score every file against the checklist above, and remediate before the reviewer arrives. Start about eight weeks out, as Figure 2 shows.
Figure 2. A suggested eight-week schedule. Most of the time goes to the Fix stage, because remediation needs investors to respond and you cannot speed that up.
The method, step by step:
- Pull the population. List every investor onboarded or reviewed in the audit period, with investor type, risk rating, onboarding date and jurisdiction.
- Draw a risk-weighted sample. No US rule sets a sample size for advisers. A workable internal standard is 25 files or 10% of the population, whichever is larger, with every high-risk and PEP investor included, at least one file from each investor type, and every file touched by a prior finding.
- Score each file against the checklist. Use the three-point scale below for each element. Score against your written policy as it stood when the file was opened, not as it stands today.
- Rank the gaps. Total the scores by element across the sample. An element that fails in many files is a process problem. A single failure is a file problem. They need different fixes.
- Remediate and log. Fix the files, but never backdate. Add the missing evidence with today's date and a note explaining the gap. A dated remediation log is a strength in an audit. A file that was quietly altered is a serious problem.
- Re-test. Re-score a few remediated files to confirm the fix holds.
| Element | 2 = complete | 1 = partial | 0 = missing |
|---|---|---|---|
| Identity verification | ID, check result and date recorded | ID on file, no check result | No valid ID |
| Ownership (entities) | Chart to natural persons, all UBOs verified | Chart present, some UBOs unverified | No chart |
| Screening | All parties, lists, date and settings recorded | Investor only, or no list date | No screening record |
| Match disposition | Identifiers compared, rationale, reviewer, date | "False positive" with no reasoning | Unresolved match |
| Risk rating | Factors, methodology version, override reason | Rating only | No rating |
| EDD / SoF / SoW | Evidence and senior sign-off | Declaration only | Required but absent |
| Approval | Named, timestamped, before acceptance | Approved after acceptance | No approval |
| Periodic review | On schedule, contents recorded | Late or undocumented scope | Overdue with no plan |
Scoring by element across investor types shows where the process breaks. Figure 3 is an illustrative result. The numbers are invented to show the method, not drawn from any survey.
Figure 3. An illustrative self-test result. Read it by row: a row that is red across every investor type, here match disposition, points to a procedure or tooling gap rather than a few weak files.
What are the most common investor KYC audit findings, and how do you fix them?
The most common findings are documentation gaps, not wrong decisions: unverified beneficial owners, screening with no evidence of how matches were resolved, risk ratings with no reasoning, and overdue periodic reviews. Published regulator data shows the pattern clearly.
The Cayman Islands Monetary Authority reviewed inspections of 113 registered persons under the Securities Investment Business Act between January 2022 and March 2024 (CIMA, May 8, 2025). It found:
- 81% of the registered persons inspected had weaknesses in their CDD and ongoing monitoring programs.
- 28% of findings concerned weak documentation of sanctions screening, at onboarding and on an ongoing basis, and of how potential matches were resolved.
- 19% of findings concerned weak documentation of identification and verification of ultimate beneficial owners, controllers and relevant parties.
- 18% of findings concerned weak documentation of ongoing monitoring, including periodic file reviews.
- 63% of registered persons had gaps in their AML/CFT audit function, including audits that did not test effectiveness and no evidence of independence.
| Finding | Usual root cause | Remediation |
|---|---|---|
| UBO identity not verified | Ownership chart collected but individuals never onboarded | Verify each UBO above the threshold. Add a step that blocks approval until every UBO is verified. |
| Match cleared with no rationale | Screening tool records the outcome, not the reasoning | Write a rationale for each open file. Make a written rationale a required field before a match can be closed. |
| Screening covers the investor only | Related parties never entered into the screening tool | Re-screen all UBOs, controllers and signatories, and record the run date. |
| No list date or version | Screenshots or exports without metadata | Re-run and keep the provider's report showing lists and timestamp. |
| Risk rating unexplained | Rating typed in by hand | Re-rate using the methodology, store the factors, and record the version. |
| Approval after capital accepted | Approval done by email, recorded later | Record a late-approval exception, then require approval before the capital call or closing. |
| Periodic reviews overdue | No calendar tied to risk rating | Clear the backlog with high-risk files first. Set review dates automatically from the rating. |
| Prior finding repeated | Remediation plan with no owner or closure evidence | Assign an owner and a date to each item, and file the evidence that it was closed. |
Luxembourg shows a similar pattern. In a 2024 sanction against a fund manager, CSSF found that one distributor agreement was signed before initial due diligence was complete. For two distributors, annual reviews required by the manager's own policy were still not done two years late. Five distributors had not been screened against sanctions and PEP lists in due time. The manager also relied on a group ISAE 3402 control report that covered only a small portion of its applications (CSSF, 2024). In March 2026 CSSF said the fight against money laundering, terrorist financing and proliferation financing "remains a key priority" for fund supervision (CSSF, 2026).
How should you present KYC files to an auditor?
Present files so the reviewer finds every item in the same place in every file. That means an index, consistent naming, and one export per investor that opens without your systems.
- A master index (spreadsheet) listing each investor ID, legal name, type, jurisdiction, risk rating, onboarding date, last review date, approver and the path to the file
- Consistent naming, for example
INV-0142_03-Screening_2026-08-14.pdf: investor ID, a numbered section matching the checklist, and the date of the evidence - Fixed section order in every file: 01 Identity, 02 Entity and UBO, 03 Screening, 04 Risk and EDD, 05 Approvals, 06 Reviews, 07 Tax
- A one-page summary at the front of each file with the status of each section and the audit trail extract
- Read-only exports (PDF plus the original files) with the audit log included, so timestamps cannot be questioned
- A request tracker during fieldwork: request, date received, owner, date delivered
Deliver only what was requested and keep a copy of everything you send. Redact only where the reviewer agrees. Note that Article 77 of the EU AMLR states that records retained under it must not be redacted for competent authorities. Agree on secure transfer before the first file goes out.
How Verifica produces audit-ready investor files
Most of the findings above come from evidence that was never captured at the time of the check. Verifica is built to capture it. Each investor completes one guided flow with smart forms tailored to their investor type: government ID with document authenticity checks, biometric liveness, sanctions, PEP and adverse-media screening powered by LSEG Risk Intelligence, and UBO mapping for companies, trusts and fund-of-funds structures. Every step is timestamped in the audit trail.
Anything that needs judgment, such as a potential match, is flagged to a human reviewer rather than auto-approved, so the disposition and reviewer are recorded in the file. Once the checks complete, Verifica generates the KYC file in under 60 seconds as an exportable, timestamped audit file, so each investor file follows the same structure. Ongoing monitoring is available for re-screening after onboarding.
Verifica is software, not a law firm. Your risk thresholds, policy and sign-off stay with your team, and your self-test should still score Verifica files against your own policy.
Frequently Asked Questions
What should be in an investor KYC file for an audit?
Identity evidence with the verification result, address proof, and for entities the formation documents, an ownership chart traced to natural persons and verified beneficial owners. Add screening results showing lists, dates and how each match was cleared, a risk rating with its factors, EDD and source of funds where required, a named and timestamped approval, periodic review history and tax forms.
How many investor files will an auditor sample?
No US rule fixes a sample size for advisers, and testers set their own sample based on risk. Expect them to over-weight high-risk investors, PEPs, complex entities and areas with prior findings. For your own self-test, a workable standard is 25 files or 10% of the population, whichever is larger, with every high-risk file included.
How long do I need to keep investor KYC records?
Generally at least five years after the relationship ends. That is the period under the EU AMLR from July 10, 2027, the UK MLR 2017 and Cayman's AML Regulations. FinCEN's CDD rule uses five years for covered institutions. OFAC raised its recordkeeping period for transactions subject to sanctions regulations to ten years from March 21, 2025.
Do I need to keep proof of which sanctions lists I screened against?
Yes, in practice. A result reading "no match" proves little unless the file shows which lists and sources were checked, when the screening ran, and which names were included. CIMA found that 28% of findings in its 2022 to 2024 inspections of registered persons concerned weak documentation of sanctions screening and match resolution.
What is the most common investor KYC audit finding?
Missing documentation of decisions that were actually made. Typical examples are beneficial owners named but not verified, potential matches cleared without a written rationale, risk ratings with no recorded factors, and overdue periodic reviews. CIMA found weaknesses in CDD and ongoing monitoring at 81% of the registered persons it inspected between 2022 and 2024.
Can I rely on my fund administrator's KYC for an audit?
You can delegate the work, but not the responsibility. Get the administrator's SOC 1 report and check whether it actually covers AML onboarding controls, since SOC 1 is designed around financial reporting. Keep your own oversight evidence, such as periodic file reviews of the administrator's work, and be ready to produce sample files on request.
Does FinCEN's investment adviser AML rule apply yet?
No. FinCEN postponed the effective date from January 1, 2026 to January 1, 2028, and said it will review the rule before then. OFAC sanctions obligations already apply, and the SEC's FY2026 priorities include reviewing whether advisers monitor OFAC sanctions. Investor files built to a full standard now will hold up under either regime.
Sources
- 31 CFR 1010.230, Beneficial ownership requirements for legal entity customers (FinCEN rule, via Cornell LII)
- FinCEN Issues Final Rule to Postpone Effective Date of Investment Adviser Rule to 2028 (FinCEN, December 31, 2025)
- Fact Sheet: Investment Adviser AML/CFT Program Final Rule (FinCEN, August 28, 2024)
- New Anti-Money Laundering Requirements for Investment Advisers: Ten FAQs (Debevoise & Plimpton, September 9, 2024)
- Examination Priorities, Fiscal Year 2026 (SEC Division of Examinations, November 17, 2025)
- US Treasury Extends Recordkeeping Requirement for Economic Sanctions Compliance to 10 Years (Greenberg Traurig, April 2025, on OFAC's final rule of March 20, 2025)
- A Framework for OFAC Compliance Commitments (OFAC, May 2019)
- Entities Owned by Blocked Persons (50 Percent Rule) (OFAC FAQs)
- Regulation (EU) 2024/1624 (AMLR), Articles 77 and 90 (Official Journal of the EU, June 19, 2024)
- The Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017, regulation 40 (legislation.gov.uk)
- Anti-Money Laundering Regulations (2023 Revision), regulation 31 (Cayman Islands)
- Key Findings from On-site Inspections of Registered Persons (CIMA, May 8, 2025)
- Administrative sanction of 2 April 2024 (CSSF, published July 12, 2024)
- The CSSF's 2026 priorities for supervising the investment fund sector (CSSF, March 31, 2026)
- ILPA Due Diligence Questionnaire 2.0 (ILPA, November 2021)
- SOC 1: SOC for Service Organizations, ICFR (AICPA & CIMA)
Rodolfo Santos is a real estate compliance attorney with 10+ years of experience in cross-border transactions and the co-founder of Verifica, an AI-powered compliance platform for real estate professionals. He has closed over 150 property transactions worth more than €50 million.



