Reports & audit

When the file is reviewed, the evidence is already assembled.

An AML file is only as good as what a reviewer can reconstruct from it. ConveySure builds the audit record continuously as work happens, then assembles it into reports written for their actual reader — a fee earner, an MLRO, a regulator or the client.

Six outputs, each with a different reader.

ReportWritten forWhat it answers
Fee-earner AML noteThe file handlerWhat was checked, what was found, what was decided — the working file note, generated rather than retyped.
MLRO reportThe MLROReferral context, risk reasoning, decisions and conditions across the matter.
Regulator / SRA audit reportAn external reviewerThe complete evidential picture: controls, evidence, screening, decisions and their timing.
Client communicationThe clientWhat was requested and completed — in client-safe language with no internal risk content.
Evidence scheduleAny reviewerEvery document on the file: what it is, when it arrived, what state its review reached.
Review historyCompliance oversightWho looked at what, when, and what they concluded — across the life of the matter.

What is inside the bundle.

The audit bundle is a single package a firm can hand over during inspection. Each component is generated from the matter record — nothing is rebuilt from memory.

Formal AML report

The narrative document: matter facts, risk assessment, funding analysis and conclusions.

Evidence schedule

Every document with dates, types and review outcomes.

Findings & dispositions

Each finding raised and the recorded state it reached, with reasons.

Screening results

Sanctions screening events and their outcomes, timestamped.

MLRO decisions

Referrals, decisions, reasoning and conditions.

Audit timeline

The chronological record of every material action on the matter.

CSV export

Structured data for the firm's own analysis or retention systems.

Document hash manifest

Cryptographic hashes showing evidence has not been altered since receipt.

Provider records

Which automated analyses ran, when, and with what outcome — including failures.

A report you cannot stand behind is a report you cannot generate.

Report generation is held — with the reason stated — while the record is materially incomplete. This is deliberate: a polished PDF over an unresolved file is worse than no PDF at all.

  • Findings remain unresolved on the matter.
  • An MLRO decision is still pending.
  • An automated review is incomplete or failed without manual follow-up.
  • A required human confirmation has not been recorded.

The matter, in order.

  1. 4 June — Client invited

    Secure portal invitation sent; questionnaire issued.

  2. 9 June — Evidence received

    Passport, gift letter and June statement uploaded.

  3. 9 June — Automatic review complete

    Three findings raised, one flagged for query.

  4. 12 June — Client query answered

    Response and supporting document attached to the finding.

  5. 16 June — MLRO decision recorded

    Approved with conditions; reasoning on file.

  6. 17 June — Audit report generated

    Bundle assembled from the record above.

Illustrative fictional matter.

Every report says exactly where it came from.

Generated byConveySure AML — report engine
Reviewed byJ. Whitfield (fee earner)
Date generated17 June 2026, 14:22
Source-data versionMatter record as at generation time
Report statusFinal — record complete

If the matter changes after generation, the report is marked as superseded rather than silently replaced.

Next: the platform underneath the paperwork.

Audit files are only trustworthy if the platform holding them is — see how ConveySure protects client data.

See security and trust