What stops most compliance teams from leaving a system they dislike is not the cost of the new one. It is the fear that the historical record, the completed reviews, attestations, and evidence files examiners will ask about, gets lost in the move. That fear is legitimate, and it is solvable with a compliance platform migration plan built around the audit trail instead of around the software.
Key Takeaways:
- Your audit trail is more than documents: it includes completed tasks, attestations, evidence files, findings history, and board reports, each with dates, owners, and statuses
- Retention obligations, such as the five-year BSA requirement under 31 CFR § 1010.430, attach to the records and survive the switch
- Export metadata, not just files; a folder of PDFs cannot show an examiner who did what, when
- Run 30 days in parallel, cut over at a period boundary, and keep the old system read-only until retention windows lapse
Why the Audit Trail Blocks Every Compliance Platform Migration
Examiners ask backward-looking questions. Show me the last eight quarterly BSA control reviews. Show me who attested to the vendor management policy last year. Show me the remediation history for the finding from your previous exam. If those answers live only in the incumbent system, switching platforms can feel like burning the library.
The concern is grounded in real supervisory expectations. The FFIEC BSA/AML Examination Manual directs examiners to review documentation of monitoring, testing, and corrective action across the review period, which typically reaches back to the prior examination. A migration that cannot produce that history creates a supervisory problem where none existed.
Which Records Must Survive the Switch?
Retention obligations attach to the records, not to the software that holds them. Under 31 CFR § 1010.430, BSA records must be retained for five years and remain accessible within a reasonable period of time. Suspicious activity reports and their supporting documentation carry their own five-year requirement under 31 CFR § 1020.320. Nothing about a platform switch pauses either clock.
Beyond formal retention rules, plan for examiner lookback. Document requests routinely cover the full period since the last examination, and history tied to open or recently closed findings can reach further. The practical standard is the one we describe in examiner-ready evidence requirements: every completed control should answer who performed it, when, against which requirement, and with what evidence.
The Compliance Software Migration Checklist: Seven Steps
1. Inventory what constitutes your audit trail today. List every record type an examiner has requested in the past two exams: completed tasks, policy attestations, evidence files, findings and their remediation history, committee minutes, and board reports. This inventory, not the vendor's export tool, defines the scope of the migration.
2. Confirm the retention obligations that survive the switch. Map each record type in your inventory to its retention requirement, starting with the five-year BSA windows cited above and adding any state, contractual, or litigation-hold obligations. Records still inside a retention window must remain producible somewhere, in the new system, the old one, or a controlled archive.
3. Export with metadata intact. The evidentiary value of a completed review is the metadata: completion date, performer, approver, status, and the requirement it satisfied. Insist on structured exports (CSV, JSON, or database extracts) that carry those fields, not just the attached documents.
4. Map historical records into the new system's structure. History dumped into a "Legacy" folder is technically retained and practically useless. Completed work should land attached to the same obligations and controls it satisfied, so that a request for three years of quarterly reviews returns one continuous record, not a live system plus an archaeology project.
5. Run 30 days in parallel with the incumbent still on. For one full month, controls execute in both systems and nothing is turned off. This proves the new platform on real work while the old system remains the fallback. A structured approach to this is covered in how to run a 30-day compliance platform pilot.
6. Cut over at a period boundary. End the parallel run at a month or quarter close, so each reporting period lives entirely in one system. Every control cycle that starts after the boundary starts in the new platform, and every cycle before it is complete in the old export.
7. Keep the old system read-only, or retain its exports, until retention windows lapse. Negotiate read-only access as part of the termination, or hold verified structured exports under your document retention policy. Only when the last retention window closes does the incumbent's record become disposable.
Common Audit Trail Migration Failures
Three failure modes account for most migration regret.
| Failure mode | What gets lost | How to avoid it |
|---|---|---|
| Flat PDF dump | The who-did-what-when metadata that makes records evidentiary | Export structured records with dates, owners, and statuses (step 3) |
| Migrating open items only | Completed work and closed findings, exactly what lookback requests target | Migrate history into the new structure, not just the active queue (step 4) |
| Mid-cycle cutover | A clean record for the transition period; controls end up half in each system | Cut over at a month or quarter boundary (step 6) |
Each failure is invisible on go-live day and expensive at the next exam, when a routine document request takes weeks instead of minutes.
How Modern Teams Migrate Without Breaking the Record
Canarie's migration motion treats history as first-class content. During a 48-hour CMS conversion, teams import policies, procedures, existing controls, risk registers, Excel trackers, open findings, recurring tasks, and historical evidence, and Canarie normalizes all of it into one structure: source, obligation, control, work, evidence, attestation, examination request. Completed work arrives attached to the controls and obligations it satisfied, with dates and owners intact, so lookback questions have answers on day one.
The deployment then runs 30 days in parallel, with no requirement to shut off the incumbent system, which also avoids the multi-month gap of a traditional GRC implementation.
See how a migration preserves your full audit trail →
Frequently Asked Questions
How long do banks need to retain compliance records after switching platforms?
The retention clock is unaffected by the switch. BSA records must be kept for five years under 31 CFR § 1010.430, SARs and supporting documentation for five years under 31 CFR § 1020.320, and other regulations impose their own windows. Whatever system change occurs, each record must remain producible until its window closes, from the new platform, a read-only incumbent, or a controlled archive.
Do we have to migrate everything, or can we archive the old system?
A hybrid approach works if it is deliberate. Records examiners actively request, completed controls, attestations, findings history from the lookback period, belong in the new system's structure so they can be produced quickly. Older records still inside a retention window can live in a verified archive or a read-only instance of the old system, provided you can retrieve them within a reasonable period of time.
When is the best time to cut over to a new compliance platform?
At a period boundary, after a successful parallel run. Cutting over at a month or quarter close means every reporting period is complete in exactly one system, which keeps board reports, control cycles, and testing schedules coherent. Cutting over mid-cycle splits controls across two systems for that period and creates permanent ambiguity in the record.
Will examiners accept records exported from a decommissioned system?
Yes, if the records are complete and their integrity is demonstrable. Structured exports that preserve dates, performers, approvers, and statuses, retained under your document retention policy, meet the accessibility expectation in 31 CFR § 1010.430. A folder of undated PDFs generally does not, because it cannot establish who completed the work or when it happened.