# Running a data audit that a regulator or client can't poke holes in
A partner at a mid-sized advisory firm gets an email on a Tuesday: a Fortune 500 prospect's procurement team wants a completed data-protection questionnaire in five business days, before they'll even shortlist the firm for a $2 million engagement. The questionnaire asks for access logs, a data retention schedule, and proof of the last breach response drill. The firm has none of these ready. They lose the deal not on price or expertise, but on paperwork they should have had on file already.
This is now routine. Enterprise clients, regulators, and cyber insurers all run some version of this check before they'll sign. This lesson walks through what "audit-ready" actually looks like.
Law firms, accounting firms, consultancies, and advisory boutiques sit on unusually sensitive data: client financials, M&A plans, employee PII (personally identifiable information, data that can identify a specific person), litigation strategy. Unlike a bank, most of these firms have no dedicated compliance function checking this daily.
Two regulatory regimes matter most:
Sector-specific layers stack on top: accounting firms handling audit data face SOX (Sarbanes-Oxley Act) record-keeping rules; firms serving healthcare clients may touch HIPAAHIPAAHealth Insurance Portability and Accountability Act, loi américaine imposant la protection des données de santé (PHI). Violations : amendes jusqu'à 1,9M$ par catégorie de violation.-covered data even indirectly; firms serving EU financial clients may need to demonstrate DORA (Digital Operational Resilience Act, EU, applicable since January 2025) compliance from their vendors, including advisory firms in the supply chain.
The regulator you should assume is watching: in the EU, national Data Protection Authorities (DPAs, such as Ireland's DPC or France's CNIL) enforce GDPR. In the US, the FTC (Federal Trade Commission) enforces against unfair or deceptive data practices, and state attorneys general enforce CCPA-type laws.
Strip away the jargon and every client due-diligence questionnaire or regulatory review converges on four evidence categories.
Who touched what data, and when. Not "we have access controls," but a timestamped, exportable log.
Minimum bar: for any client file containing personal or financial data, you should be able to produce, within an hour, a list of every user who accessed it in the last 12 months.
Example log entry (illustrative):
2026-02-11T14:32:07Z | user: j.alvarez@firm.com | action: FILE_OPENED
| resource: /clients/acme-corp/due-diligence/financials.xlsx
| ip: 10.2.4.18 | mfa_verified: trueCloud platforms (Microsoft 365, Google Workspace) generate this natively, but most firms never turn on the retention settings needed to keep logs longer than 90 days. Fix that before an audit lands, not after.
A data retention schedule states how long each data category is kept and why, plus the deletion mechanism. "We delete client data when the engagement ends" is not proof. Proof is: a policy document, a system configuration showing automatic deletion after N days, and a sample deletion log.
GDPR's storage limitation principle (Article 5(1)(e)) requires data be kept "no longer than necessary." Auditors will ask for your schedule and then spot-check a real file against it.
Both GDPR (Article 33) and most US state laws require notifying regulators, and sometimes affected individuals, within a fixed window after discovering a breach (72 hours under GDPR). You cannot hit that window without a rehearsed process.
What auditors want to see: a written incident response plan, a record of at least one tabletop exercise (a simulated breach walkthrough) in the past 12 months, and named roles (who calls the regulator, who calls the client, who calls counsel).
Professional services firms routinely hand client data to a transcription vendor, an AI drafting tool, a cloud host. Under GDPR, each of these is a sub-processor, and you need a signed Data Processing Agreement (DPA) with each one, plus a current list of who they are.
If a firm uses an AI tool to summarize client contracts, the audit question is blunt: does that tool's provider train its models on your inputs? If you don't know, that's a finding.
Picture a client due-diligence request landing on a 40-person advisory boutique. The five checks a competent reviewer runs, in order:
1. Data inventory: request a list of what personal/client data is held, where (which systems, which country), and why. Firms without this documented lose points immediately.
2. Access control sample test: pick one sensitive file, ask for the access log, cross-check against the list of staff who should have access.
3. Retention spot check: pick a closed engagement from 3 years ago, ask why that data still exists or where the deletion record is.
4. Breach drill evidence: ask for the date and outcome of the last tabletop exercise.
5. Sub-processor list: ask for the DPA covering the firm's cloud storage and any AI tools in use.
A firm that can answer all five in writing, with dated evidence, clears in a day. A firm improvising answers triggers a longer, more adversarial review, or a rejected bid.
The UK Information Commissioner's Office publishes a practical self-assessment tool that mirrors this exact structure: ICO Accountability Framework.
Vérification des acquis
1. Why did the advisory firm in the opening scenario actually lose the $2 million engagement?
2. Why does GDPR matter to a US-based advisory firm that has never opened an EU office?
3. A consultancy has never directly billed a healthcare client but occasionally receives employee health records as part of an HR advisory engagement. What does this scenario illustrate about regulatory exposure in professional services?
4. Select ALL correct answers about why professional services firms (law, accounting, consulting) are especially exposed to data-protection scrutiny.
Sélectionnez toutes les réponses correctes.
5. Select ALL correct answers about how sector-specific regulatory layers can stack for a professional services firm.
Sélectionnez toutes les réponses correctes.
The fix is not a one-time scramble but a standing folder, reviewed quarterly, containing:
A useful discipline: treat this like a filing cabinet a stranger could audit with zero explanation from you. If a document requires you to talk them through it, it's not audit-ready.
GDPR Explained in 5 Minutes