Back to all insights
comply

Five registers your auditor will ask about

turph. insights · 5 min read · 21 July 2026

A regulated firm keeps registers because someone will ask. The auditor asks about claims and provisions. The supervisor asks about rejected clients and conflicts of interest. The compliance officer asks about incidents and complaints. Each register answers one question: what happened, and what did we do about it.

The five

Rejected clients. Who was turned away, when, and why. Office, client, ultimate beneficial owner, date of rejection, reason. This is the register that proves your onboarding has teeth.

Claims. Every demand made against the firm. The claimant, the amount, the probability the claim succeeds, what insurance covers, the provision formed, which lawyer is on it. These are the numbers the auditor wants at year-end, and they are not in the accounting system.

Incidents. Events with legal or financial consequences that did not, or not yet, become a claim. Same fields as a claim, because an incident can become one.

Complaints. Same again. A complaint that is handled badly is a claim in waiting, so it is tracked the same way from the start.

Conflicts of interest. Per person: the conflict, the period, the action taken. The register that shows the firm noticed.

What "open" means

The question an auditor asks about a register is never "what is in it". It is "what is still running". Open should mean one thing: no closing date. Not a status value, because which status counts as closed is something the firm decides and may change; the closing date is a fact. A register landing page shows per register how many are open, how many closed, and the total. That is the whole overview.

Claims: 2 open, 11 closed
Incidents: 1 open, 7 closed
Oldest open item: claim 2026-004, 94 days without a mutation

One screen across all five

Firms end up with five spreadsheets because they need to ask one question across the registers: what is open, oldest first, regardless of type. That question deserves one screen with the shared fields, type, number, date, summary, status, owner, country, amount, days open, and a filter per register. The item that has waited longest sits at the top, because that is the one nobody has looked at.

What does not belong here

Data breaches and security incidents belong with information security, where the reporting duty, the root-cause analysis and the question whether data subjects were informed live. Audit findings belong with the audit. A claims register is for legal and financial exposure, and it should say so at the door, otherwise the same event gets registered twice and reconciled never.

Step 8 of the tour shows a register signal on the dashboard, next to deadlines and deals.

Take the tour