Free resource
Built around a broker's real stack - MT4/MT5, IB and affiliate portals, PSPs, KYC, withdrawals and vendor access. Name the evidence an auditor will ask for, and the gap.
The actual structure of the file, straight from the template we use on live engagements.
Sheet: Start here
Read this tab first, then work through the checklist. Score honestly - a 'Partly' you can see is worth more than a 'Yes' you cannot evidence. This is a working tool, not a certificate: it shows where an assessor will push, before they do.
| Topic | Detail |
|---|---|
| What this is | An evidence checklist built around a broker's real stack - MT4/MT5, IB and affiliate portals, PSPs, KYC and withdrawals - not a generic IT list. Access that grew organically is where Stage 1 is usually lost. |
| How to score | Yes = in place and you can show the evidence today. Partly = it exists but is incomplete, informal or unevidenced. No = not in place. Only a clear Yes counts when it is audited. |
| The #1 mistake | Assuming the trading platform is 'the vendor's problem'. Admin access, IB-term changes and withdrawal approval are your controls, and they are exactly what an auditor probes. |
| A second pair of eyes | If you want someone who has sat on the other side of the audit table to sanity-check your scoring before it counts, that is what we do at kellwick.com. |
Sheet: Broker Evidence
For each system, name the evidence, score it, and note the gap. The middle columns are filled in - what a pass looks like, and the failure that is specific to brokers.
| System / area | Evidence expected | What good looks like | Most common failure (the red flag) | Status (Yes / Partly / No) | Owner | Gap / action |
|---|---|---|---|---|---|---|
| MT4 / MT5 admin | Who holds admin, approval record, periodic review | A short, named admin list with approval and a dated review | Historic admin access nobody remembers granting - the classic broker finding | - | - | - |
| IB / affiliate portal | Access owners; ability to change IB terms is controlled | Changing IB commercials needs approval and is logged | Any support agent can alter IB terms - a fraud and integrity risk | - | - | - |
| PSP / back office | No shared credentials; actions attributable to a person | Individual logins; PSP actions trace to a named person | A shared 'finance' login used by several people | - | - | - |
| KYC documents | Access to client identity data is reviewed and logged | KYC access is least-privilege, reviewed and logged | The whole support team can open any client's passport and card data | - | - | - |
Preview only. The download is a fully editable .xlsx file.
Go deeper
See how this template fits the wider readiness work, and where we pick it up on a live engagement.
Explore the related serviceMore resources