Blog · For CA & audit firms

"We log file activity" isn't the same as "we have a client-data audit trail" - here's the difference

A generic file-activity log tells you a file moved. It doesn't tell you whether the person moving it was even staffed on that client's engagement. That distinction is the entire difference between a monitoring log and an actual audit trail for a firm holding client financial data.

Three things a real client-data audit trail needs

1. Who's assigned to what

A roster mapping each employee to each client engagement, with a start date and - critically - an end date when they roll off.

2. Access, flagged against assignment

Every access to a client's records, checked against whether the person accessing it was actually assigned at that moment.

3. A gate on bulk export

Any bulk pull of client records goes through an approval step and is recorded with who requested it, why, and who approved it.

Why "assigned" matters more than "accessed"

Most file-activity logs record an event and stop there: a person touched a file. That's necessary but not sufficient. The actually useful signal is whether that access was expected - and the only way to know that is to have a real record of who's staffed on which engagement in the first place, so access can be checked against it automatically instead of reconstructed by hand after the fact.

Custelis keeps an engagement roster - which employee is assigned to which client, with an effective-from date and, when they roll off, a revocation timestamp. Every access to that client's records is logged against that roster: did this person have an active assignment at the time they accessed this? If not, it's flagged automatically - not because access is inherently wrong, but because unassigned access to a client's data is exactly the kind of thing a partner should know about, not discover during an unrelated review months later.

Bulk exports get their own gate

A single file moving is one thing. A bulk export of client records is a different risk entirely, and it's handled differently: a request records who's asking, how many records, and why, and it sits pending until approved. The resulting ledger shows the full chain - requester, record count, purpose, approver, whether it was watermarked - not just "an export happened."

What to ask your current vendor: can you show, right now, whether anyone accessed a specific client's records without being staffed on that engagement? If the honest answer requires cross-referencing two systems that don't talk to each other, that's not really an audit trail - it's raw material for one.

Related reading

See the client-data registry live

No credit card to start. Intrusive features stay off until your own DPIA is recorded.

Try for free

← Back to the blog