02 / Compliance

An audit stops being a risk.

A communications audit is not lost for lack of recordings. It is lost by failing to find the right recording, in time, with proof that it is the original. This page is about that, and about turning a request that takes days into one that takes minutes.

How an audit runs today, and where it fails

The regulator asks for one specific interaction: a client, an approximate date, a product. From here, without a unified archive, the day usually goes like this.

1

The regulator asks

One specific interaction: a client, an approximate date, a product.

2

«Which system will it be in?»

Someone has to guess where to start. The knowledge lives in people's heads, not in an index.

3

You search the voice system

By phone number. It does not match: the contact actually began on chat.

4

You open email separately

One more system, one more search, more time draining away.

5

You cross-reference by hand

You assemble the interaction piece by piece, from three places that do not talk to each other.

6

And the essential part is still missing

When it finally turns up, the most important part is missing: proving that nobody has touched it since.

The three failure points are always the same: the interaction is split across channels, the index does not allow searching by case, and there is no reliable record of access. Any one of these, on its own, turns a minutes-long request into a days-long one. Together, they turn a routine audit into an internal emergency, with people idle, deadlines tight and the never-comfortable feeling that the answer depends on whoever happens to still remember how that old system works.

How you find an interaction from three years ago

In a unified archive, you search by client number, by date, by agent or by case reference, and the voice, chat and email of that interaction appear together. Retrieval takes seconds, and comes with the record of who accessed it attached. What was a hunt for a file becomes a search.

The difference is not one of speed, but of nature. In a hunt for a file, the result depends on tacit knowledge: knowing where to look, which system to open, who to call. In a search, the result is always the same, no matter who runs it. That is what an auditor values, not the speed of one particular person, but the guarantee that the answer exists and is reproducible.

What makes an audit trail an auditor will accept

An audit trail is the record of who accessed what, when and why. For an auditor, acceptable means three things: that it cannot be erased or edited by whoever consults it, that it logs every access and every export, and that it allows you to demonstrate that the recording handed over is identical to the original.

Without an audit trail, finding the recording solves half the problem. The other half, proving it is trustworthy, is the half that decides the audit. Showing that something exists is not the same as showing that this something is what happened. In a regulatory process, that distinction is everything.

A recording without a chain of custody is a claim, not evidence.

And in an audit, it is the evidence that decides

Legal requirements

Compliance that does not depend on manual heroics.

MiFID II

Directive 2014/65/EU (MiFID II) requires communications connected to transactions to be kept for five years, on any channel. A competent authority may extend the period to seven years.

DORA

Regulation (EU) 2022/2554 (DORA), in force since 17 January 2025, asks what MiFID II does not: what if the archive stops? Resilience with documented RTO and RPO.

GDPR

Keeping data for five years and erasing it at the end of the retention period are the same obligation. Article 5(1)(e) imposes storage limitation: keeping it longer is, in itself, a breach.

Audit trail

A tamper-proof record of every access and every export. Proving who listened matters as much as the recording itself. Without it, finding the file solves only half the audit.

How retention is configured by country and by channel

Retention is not a single number. An operation in Portugal, another in Spain and a chat channel may all have different periods. The archive has to apply the right rule to each interaction: keep it for the legal period, erase it automatically when that ends, and keep the trail of that erasure. Configured this way, retention stops depending on someone remembering to delete.

This is the point that fails most quietly. Organisations concentrate on keeping and forget that the law also requires erasing. An archive that keeps everything «just in case» is not prudent, it is non-compliant. Erasure by rule, automatic and logged, settles both sides of the obligation at once.

Self-assessment

Would you survive an audit?

A short test, taken from the full assessment. Answer honestly; nobody is watching.

1If you were asked right now for an interaction from three years ago, how long would it take you to hand it over?
2Can you prove who accessed that interaction, and when?
3Are recordings past their retention period deleted automatically?

In practice

How uPlayback works here

uPlayback brings the voice, chat and email of the same interaction into a single archive, searchable by case, with a tamper-proof audit trail on every access and every export. Retention rules apply by country and by channel, with automatic erasure at the end of the retention period. When the regulator asks, the answer is one search, with the evidence included.

Equipa de compliance a preparar uma auditoria
MiFID II DORA GDPR ANACOM Cloud Act

Continue reading

Go deeper on the subject.

Blog

What makes an audit trail acceptable to an auditor?

The three conditions that separate a log from evidence.

Blog

How long must I keep recordings in Portugal?

Five years, Article 16(7) and the exceptions.

Ready when you are.

Compliance, integrations and deployment answered live, with your questions on the table and no generic pitch.

Book a Demo Take the assessment