Before a CDD spot check, clean the path between your case system and the reviewer — not the underlying customer risk itself. Auditors should not spend hours hunting attachments.
Export cases with a stable ID, onboarding date, product, and risk band. Include the decision rationale as it stood at approval time. If an alert was closed as false positive, keep the disposition note with the date and reviewer name.
Agree a secure transfer method your information security policy already allows. Do not improvise personal cloud links for identity documents.
Tell reviewers what changed mid-period — new ID vendors, revised thresholds — so samples are judged against the right standard. That context prevents false findings and builds trust in the ones that remain.