FFIEC Compliance Audit Checklist
Complete this checklist to document the audit scope, control assessments, findings, remediation, and final review for the institution or branch being evaluated.
Audit Identification
Audit Name or ID
*
Audit Date
*
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Auditor Name
*
Institution or Branch Name
*
Branch / Location
*
Review Period Start Date
*
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Review Period End Date
*
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Compliance Scope and Applicability
Audit scope area(s)
*
BSA/AML
Consumer compliance
Deposit operations
Lending
Information security
Vendor oversight
Complaint handling
Other
Audit type
*
Internal
External
Targeted review
Follow-up
Review location
*
On-site
Remote
Hybrid
Control Assessment Checklist
Policy / Procedure Documentation
*
Rows
Compliant
Partially Compliant
Non-Compliant
Not Applicable
Policy / Procedure Documentation
1
2
3
4
Policy / Procedure Comments
Staff Training Completion
*
Rows
Compliant
Partially Compliant
Non-Compliant
Not Applicable
Staff Training Completion
5
6
7
8
Monitoring and Testing Performed
*
Rows
Compliant
Partially Compliant
Non-Compliant
Not Applicable
Monitoring and Testing Performed
9
10
11
12
Issue Escalation
*
Rows
Compliant
Partially Compliant
Non-Compliant
Not Applicable
Issue Escalation
13
14
15
16
Record Retention
*
Rows
Compliant
Partially Compliant
Non-Compliant
Not Applicable
Record Retention
17
18
19
20
Customer Disclosures and Notices
*
Rows
Compliant
Partially Compliant
Non-Compliant
Not Applicable
Customer Disclosures and Notices
21
22
23
24
Overall Control Effectiveness
Ineffective
1
2
3
4
Highly Effective
5
1 is Ineffective, 5 is Highly Effective
Findings and Risk Evaluation
Number of Exceptions Noted
Severity / Risk Rating
*
Please Select
Low
Medium
High
Critical
Finding Summary
*
Impacted Area
*
Please Select
Governance
Policies and Procedures
Monitoring and Reporting
Customer Due Diligence
Training and Awareness
Access Controls
Incident Management
Other
Root Cause
*
Likelihood / Impact Rating
*
Rows
Likelihood
Impact
Low
25
26
Moderate
27
28
High
29
30
Is the Issue Recurring?
*
Yes
No
Remediation and Follow-Up
Required Remediation Actions
*
Responsible Owner
*
Target Completion Date
*
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Follow-Up Status
*
Open
In Progress
Resolved
Deferred
Verification Notes
Evidence of Remediation Attached or Will Be Provided
*
Attached
Will Be Provided
Final Review
Overall Audit Conclusion
*
Satisfactory
Needs Improvement
Unsatisfactory
Final Comments or Recommendations
Acknowledgment: Information is accurate and complete for the audit record
*
Yes
No
Submit Audit Checklist
Should be Empty: