Who did what, when β without anyone writing it down.
FigsFlow keeps an audit trail across the whole client record. Every proposal sent, letter released, due diligence check cleared, fee overridden and officer decision taken is recorded as it happens, with a timestamp and a named person against it. Nobody maintains a log, because the log is a by-product of the work.
MLRO or compliance, the retention and immutability sections are what you want. Partner, start with the file review scenario below.
The tour runs in your browser. No form until you want one.
- Opened02/09/2026 Β· proposal sent
- CapturedAutomatically Β· as it happens
- AttributedNamed user, every event
- EditableNo Β· readable only
- RetainedFive years from relationship end
nobody maintains this by hand
Filtering changes what you are shown. It does not change what was recorded β the underlying trail is the same whichever view a reviewer picks.
βWho approved this, and when?β is not a question a folder can answer
A reviewer picks up a client file from eighteen months ago and asks a simple question. The letter is there. The AML documents are there. What is missing is the sequence β whether the check finished before the firm acted, who cleared it, and whether the fee on the letter was the one that was approved.
Reconstructing it after the fact
Five places to look, and no guarantee they agree.
- 01Check the document folder's modified dates
- 02Search someone's inbox for the approval
- 03Ask the manager what they remember
- 04Compare the AML file against the letter date
- 05Write a note explaining the gap
A modified date tells you a file changed. It does not tell you who changed it, what it said before, or whether anyone approved it.
Reading it off the record
One place, in order, with names and times attached.
- 01Open the client's trail
- 02Read the sequence
The check, the clearance, the letter and the fee sit in the order they happened, so the answer is read rather than reconstructed.
Four things every event carries
An entry that says something changed is not much use to a reviewer. These four together are what makes a trail readable years later.
Who.
A named user, not a shared login or a role. If a nominated officer cleared a high-risk client, the record says which officer rather than that somebody with the right permission did.
What.
The action in plain terms, and where relevant what it changed from. A fee override records the calculated figure alongside the one that replaced it, so the change is legible rather than implied.
When.
A timestamp written at the moment the action happened. Not the date somebody typed a note about it afterwards, which is the flaw in most manual compliance logs.
Why, where a reason is required.
Some actions do not save without one. An MLRO override of a risk rating carries the reason the officer gave, and the reason stays attached to the event rather than living in an email.
A log that records the change but not the reason answers half the question.
The trail is readable. It is not editable.
A record your team can tidy up is not evidence. Events in FigsFlow are written once and cannot be amended or deleted afterwards, including by an administrator. Where something was wrong, the correction is a new event that sits after the original rather than in place of it β so the mistake and the fix are both visible, which is what a reviewer is actually looking for.
The same trail answers four different questions
A supervisory reviewer, a professional indemnity insurer, a client in dispute and your own MLRO are all asking about the same record from different angles. What each of them needs from it is not the same.
Marked items are what that reviewer looks for first. The trail underneath is the same in every case.
What the trail is, and what it is not
An audit trail is evidence of what your firm did. It is not an opinion on whether what your firm did was right. FigsFlow records the sequence and puts it in front of whoever needs to read it; judging whether the diligence was adequate, whether a fee override was appropriate, or whether a report should go to the National Crime Agency stays with your firm.
Ask on a demo call about anything not listed here. Capability and regulatory statements should be re-verified and date-stamped before release.
What eighteen months looks like when nobody kept a log
Because nobody had to. Each stage below wrote its own entry as the work happened. Read left to right and you have the sequence a file review asks for β including the part where something went wrong and was corrected.
What this looks like at your size
Evidence your own process without keeping a compliance log alongside doing the work.
Know which member of the team took an action without having to ask them eighteen months later.
A consistent trail across a growing team, so a file review does not depend on who happened to onboard the client.
Delegated permissions across offices, with the trail held inside your own Microsoft tenant.
Where the entries come from
The trail is not a module you switch on. It is what the rest of the platform writes as it runs.
AML and client due diligence
Checks, escalations and officer decisions, each with a timestamp and a name.
See AML and CDD βRisk assessment
The computed score, the band, and any override with the reason the officer gave.
See risk assessment βCompanies House
What the register held when the record was built, and when it changed.
See Companies House βMTD Income Tax
Quarterly jobs completed and by whom, across the tax year.
See MTD Income Tax βWhat practices ask about the audit trail
No. Events are append-only. There is no permission level, including administrator, that can amend or remove a recorded event. A correction is added as a new event after the original, so both remain visible.
No. It is not a separate module or an optional setting. The trail is written by the rest of the platform as work happens, which is the point β a log that depends on somebody enabling or maintaining it is the log most likely to have gaps.
To the retention period your firm sets. For client due diligence evidence, the Money Laundering Regulations 2017 require retention for five years from the end of the business relationship, and FigsFlow flags the file for deletion review at the end of that period rather than deleting it silently.
Yes. Access events are recorded alongside actions, so you can see who opened a client record and when, not only who changed something on it.
The client record is structured and exportable so a reviewer has the sequence in one place rather than assembled from folders and inboxes. Ask on a demo call about the export formats available for your plan.
No, and it is worth being precise about this. A trail is evidence of what your firm did. Whether what your firm did met its obligations is a matter for your firm, your procedure and your supervisory body. FigsFlow evidences; it does not advise or certify.
Bring a file your last review picked up on
Thirty minutes with a practice specialist. Ask the questions your reviewer asked, and watch them answered off one client record instead of four folders and an inbox.
Most of what lands in the trail starts with the check that gates the engagement. AML and client due diligence