The notice usually arrives with a request list and a date. The bank, or an outside firm it engages, will typically pull samples from your files, and someone will usually want to interview whoever runs BSA/AML. At many growth-stage fintechs, that someone is one of two people: a head of compliance and an analyst, with everything else borrowed from operations, engineering and customer support.
A two-person team cannot rebuild a program before fieldwork, and it should not try. Small teams rarely struggle in a bank audit because they are small. They struggle because of surprises: a decision never written down, a procedure nobody follows, a gap the auditor finds first. Preparing well means removing the surprises.
Start with what the bank is actually testing
Before anyone pulls a file, read three things: the audit or oversight clause in your program agreement, the bank's request list, and the findings from any prior review. Together they tell you the scope, the lookback period, the areas in play and the issues the bank already expects to see closed.
Then ask the bank what the list leaves open. Which period will samples come from? Will the auditors select samples, or ask you for full populations? Are interviews or a system walkthrough planned? Who is doing the work: the bank's oversight team, its internal audit function or an outside firm? The answers tell you where to spend your hours.
Keep the bank's position in mind. Under the interagency guidance on third-party relationships that the federal banking agencies issued in 2023, a bank is generally expected to manage the risk of each third-party relationship, a fintech partnership included, in proportion to that risk, and its own examiners review how well it does that. The auditor is looking for a program the bank can defend, not a perfect one.
Map the evidence before the request list does it for you
Sponsor bank audits are commonly sample-based. The auditor selects items from a period and checks each one against your own policies and procedures and the terms of your program agreement, so much of the test is whether the records behind your documents exist and agree. An evidence map built before fieldwork shows where the records live and who can pull them.
| Audit area | What is commonly sampled | Evidence to have ready |
|---|---|---|
| Customer onboarding | Accounts opened in the lookback period | Identity verification results, business verification and beneficial ownership for business customers, and the risk rating assigned at onboarding |
| Risk rating and enhanced due diligence | Higher-risk customers | The rating methodology, enhanced due diligence files, approvals and periodic refresh dates |
| Transaction monitoring | Alerts and cases closed | Disposition notes with a rationale, case files, and the time from alert to decision |
| Referrals to the bank | Unusual activity referred to the bank | Referral files, the facts provided, the dates of detection and referral, and the bank's acknowledgment |
| Sanctions screening | Potential matches cleared | Screening records, evidence that lists were updated, and the reason each match was cleared |
| Complaints and disputes | Complaints from every channel and, where your products are covered by Regulation E, error disputes | The complaint log, resolution records, root cause analysis and reporting to the bank |
| Governance and training | Board materials and staff in scope | Policy approval dates, compliance reporting to the board, the current risk assessment and training completion records |
A row with no clear owner or no reliable way to pull the records is your first gap, and it matters more than any policy edit.
Split the work so two people can carry it
With two people, the division of labor has to be explicit, because alerts still need working and customers still need onboarding while the audit runs. The split that tends to work:
- The compliance lead owns the bank. One point of contact for the auditors, the scoping calls, interviews, the alignment of procedures with practice, and every management response. Nothing goes to the bank without passing through them.
- The analyst owns the evidence. Sample pulls, file assembly, the self-test described below, and the index that shows where each item lives.
- The business lends named people. An engineer for data extracts and system walkthroughs, a support lead for complaints and disputes, finance for reconciliations. Put their names and dates on the plan, and ask their managers for the time up front.
Keep a single request tracker: request number, item, owner, due date, status and file location. It stops two people answering the same question twice and records what you gave the bank and when.
Sometimes the split does not hold: the team cannot carry the audit and the day job at once. That is a staffing decision, not a failure. Common options are temporary capacity for evidence pulls, an independent BSA/AML review ahead of the bank's audit so the findings are yours first, or a senior compliance lead on a fractional basis to own the bank relationship while the in-house team keeps the program running. Decide early. Capacity added in the last week before fieldwork mostly adds coordination.
Test yourself before the bank does
The most valuable week of preparation is the one you spend auditing yourself. Pull a small sample from the lookback period the bank is likely to use and test it against your own procedures, the way the auditor will.
- Does every sampled onboarding file show the verification your procedure requires, and the risk rating it produced?
- Where a customer triggered enhanced due diligence, is it in the file and approved by the right person?
- Does each closed alert carry a rationale someone else could follow, and was it worked within your own stated timelines?
- Were referrals to the bank made on the terms and timelines your program agreement sets?
- Is every cleared sanctions match documented with the reason it was cleared?
- Were complaints logged from every channel, resolved and reported to the bank as agreed?
- Are policies approved, dated and consistent with the procedures your team follows today?
When the self-test finds exceptions, and it usually will, record each one, fix what can be fixed, and write a short remediation note with an owner and a date. Decide with your leadership, and with your counsel where the program agreement requires notice, how and when to raise them with the bank.
I have led compliance and validation testing for banks. From the testing side, a gap the company found, documented and started fixing reads very differently from the same gap found by the tester.
In a small program, a frequent source of findings is not a missing control. It is a written procedure that describes a process the team no longer runs, or never ran. Where the two disagree, you have two honest options: change the practice to match the procedure, or update the procedure through your normal approval process to match a practice you can defend.
Resist the urge to rewrite the whole policy set in the final weeks. Auditors typically test files against the procedures in force during the sample period, so a policy approved last Tuesday does not fix last year's files. Fix the specific conflicts you found, record each change and its date, and leave the rest for the normal review cycle.
Top 25 U.S. Banking Institution
Conducted comprehensive 2LOD compliance testing and transactional reviews across the Banking division. Identified deficiencies and recommended actionable remediation strategies.
Run fieldwork like a project
Once fieldwork starts, a few habits carry a small team a long way:
- Hold a short check-in with the auditors on a fixed schedule, so open requests surface early instead of at the closing meeting.
- Prepare everyone who will be interviewed. Answer what you know, say so when you do not, and follow up in writing rather than guess.
- Answer each request as made, indexed to its number. Raise any related issue deliberately through the compliance lead, not buried in a pile of files.
- Draft management responses that address each finding on its facts, name an owner and set dates you can meet. A missed remediation date can become a finding of its own at the next review.
What to do this quarter
- Read the audit clause in your program agreement and the bank's last findings, and list what the bank expects to see closed.
- Build the evidence map: every audit area, where its records live, and who can pull them.
- Name owners across the business and get their time committed before the request arrives.
- Self-test a small sample from the likely lookback period, and give every exception an owner and a date.
- Reconcile procedures with practice where they conflict, through your normal approval process.
- Set up the request tracker, choose who speaks for the program in interviews, and decide now whether you need outside capacity.
Related: how Ethixera supports fintechs with sponsor bank readiness and diligence preparation, and how a fractional chief compliance officer can own the bank relationship when a two-person team needs senior cover.

