An upcoming compliance audit meant proving who could access client files and why. In practice, permissions had grown loosely over the years, and far more staff had access than needed it.
There was no record of who had touched which file, no incident response plan, and no documented access policy an auditor could review.
Audited every account and rebuilt file permissions around who needed access.
Enabled access logging so every file touch is recorded and reviewable.
Wrote an incident response plan and a documented access policy for the audit.
Trained staff on the new access rules two weeks before the audit date.
The firm met every audit requirement with a week to spare. Client file access is now logged and reviewed, and the documented policy gets reused for every audit since.