Your heart is suddenly beating a little faster. Your body is starting to feel clammy – like you're coming down with something. Your stomach is knotting up and, for reasons you can't quite explain - you feel like you might cry.
You just opened the letter from your State Examiner letting you know that your firm is going to be audited. He wants documents. Loads and loads of documents. And he wants them in two weeks or less.
Meanwhile, you have just started surge meetings and are scheduled to see nine clients this week and ten the following. Your Client Service Associate scheduled Thursday through Monday off for an out-of-town wedding, and your Associate Advisor isn't ready to fly solo in meetings yet.
It is officially time to FREAK OUT.
Or is it?
It's not like you're a bad advisor. You adore your clients. You always act in their best interest. And you use the latest technology to serve them. You'll be fine, right? Of course.
Assuming, that is, that your CRM has clean, up-to-date information. And it does. You think. You hope. I guess you're about to find out.
I had a college professor once that was kind enough to tell me "The teacher should never be the first person to read your essay". And he was right – it's dumb to hand in something that can affect your future without having another set of eyes look it over first. After all, humans are AWFUL at proof-reading their own work. From that point on, I always had a friend review my work first. Preferably a peer that was doing well in that class!
This same advice holds true for an audit. The auditor should never be the first person to test your firm's CRM for accuracy and completeness. You should be doing this well before the letter arrives, preferably with the help of a compliance officer, if you have one. And your compliance officer will likely tell you that your best defense is a well-managed, single source of truth. In other words, a clean, up-to-date, properly-configured CRM.
Here's how to make sure you have one. Run this test now – before the letter arrives:
- Client Communications – Are all of your client communications documented in your CRM? Every phone call, every meeting, every email, every text? Does the note include mandatory fields like the four D's: Date, Delivery method, Doer, and Description? Have you made this as easy and fool-proof as possible by integrating your systems to capture this information automatically after each interaction?
- Access Logs - Are client notes locked down and un-editable once entered? If they are editable, do you have the access logs so you can identify who touched the record, what was changed, and when it was altered?
- Annual Review Cadence – Does your CRM track the last annual review meeting? Does it remind you or automatically launch a workflow when it's time for another? Are client cancellations / reschedules logged into the system so you know if/when/why one was missed?
- Data Retention - Can you produce the historical records going back the SEC-mandated five years (or whatever timeframe your state requires)? Have they been imported from a prior CRM migration with the four D's intact? If not, do you know how to quickly access those archived records? Can you do it yourself or will you need help from your IT vendor?
- Clean Data – I harp on this a lot because it's important but are you cleaning your data on a regular basis?
- Secure Data – Is your CRM secure? Have you verified table-stakes standards like SOC 2 Type II certification with your vendor? Does the system mandate Multi-Factor Authentication (MFA) for all user logins? Do you enforce long passphrases (15+ characters) over predictable short passwords? Are employee credentials strictly managed in a central password vault that your firm controls?
- Workflows Tied to Written Supervisory Procedures (WSPs) – Do you document your planning and advice-giving processes through structured, repeatable CRM workflows? Can you show auditors that these workflows enforce your firm's Written Supervisory Procedures (WSPs)—ensuring your team follows a consistent SOP rather than relying on inconsistent manual steps or unverified AI output?
- Human in the Loop – Do you ensure that any facts or values produced by LLMs that are used in advice-giving are reviewed and verified by a human? Do you require source-citing from your AI to document this verification? Most importantly, does your CRM document that this happened in some way?
Want a printable version to run through before your next audit? Download the CRM Audit-Preparedness Checklist
While this is, by no means, an exhaustive list of steps you should take to prepare for an audit*, it is a checklist to use as a review for your CRM. If you're unsure of any of the answers to these questions - or if you're sure you want help getting compliance-ready – reach out. I'll be the friend that looks at your work – before the professor does.
*This is where I tell you that not only is this not an exhaustive list, it's also not to be construed as compliance or legal advice. I'm not a lawyer or compliance expert. I'm a data nerd with a healthy fear of regulators and authority figures in general.