# Workflow audit: meaning, what it covers and cost

> What a workflow audit means for a UK regulated firm: what it covers, the five deliverables, a copyable template, the UK GDPR Article 30 overlap and the cost.

Guide · Custom software · By Syed Husnain Khalid · Published 8 October 2026 · Last checked 8 October 2026
Drafted with AI. Each claim was checked against the primary sources listed below by AI on 8 October 2026; a person has not reviewed it yet.
Canonical: https://vexralabs.com/insights/workflow-audit-guide

Short answer

A workflow audit reviews how work and data move between people and systems. Ours runs two weeks and delivers a system and data map, a re-keying and bottleneck list, AI opportunities with risks and a person signing off, and a written plan with a fixed quote: **£950, credited in full against a build agreed within 90 days**.

This guide is for owners and managers of UK regulated firms, such as accountants, financial advisers and immigration advisers, who are planning new software or an integration. A build can only be priced once someone knows which systems hold which data and where staff re-type it. Building Filyst, our case management software for immigration firms, taught us that compliance dates sit on workflow steps: Filyst sets a retention date when a case closes, six years by default for UK firms. The sections cover what a workflow audit is, what it covers, the deliverables, a template, how the map relates to a UK GDPR record, the cost and when to skip one.

## What is a workflow audit?

A workflow audit, sometimes called a process audit, is a short, fixed-scope review of how work and data move through a firm. It records each system, each hand-off between people and systems, and each point where someone re-types, checks or chases information.

Re-keying means typing data that already exists in one system into a second system by hand. A workflow audit is not a financial audit, and it is not a compliance review: no regulator requires one, and it does not decide whether a firm meets its rules.

## What does a workflow audit cover?

A workflow audit covers five things: the systems, the data flows, the time lost, the places AI could help and the questions the map raises.

- Systems in use, who uses each one and what data it holds.
- Data flows between systems, including the manual ones such as email and spreadsheets.
- Time lost to re-keying, chasing documents and building reports by hand.
- Steps where AI could read or draft, each with the person who checks and signs off the output.
- Questions about records, retention and suppliers, written down for the firm’s compliance person to answer.

**Diagram: Workflow audit deliverables in order.** The five deliverables of the VexraLabs workflow audit in the order they build on each other: a system and data map; a re-keying and bottleneck list; AI opportunities, with risks; a written plan and fixed quote; and a 45-minute walkthrough call.

*Each deliverable uses the one before it. The plan ranks fixes by hours saved.*

## What do you get at the end of a workflow audit?

Our workflow audit ends with five deliverables, listed on our [services and prices](https://vexralabs.com/services) page. The written plan ranks the fixes by hours saved.

| Deliverable | What it is |
| --- | --- |
| System and data map | Every system, data flow and hand-off on one page |
| Re-keying and bottleneck list | Where data is typed twice and where work waits |
| AI opportunities, with risks | Where AI could read or draft, the risk of each, and the person who signs off the output |
| Written plan and fixed quote | The fixes in order of hours saved, with a fixed price |
| 45-minute walkthrough call | A call to go through the plan and answer questions |

## Workflow audit template

The template below is a starting point to adapt, not a finished document. Copy it into a spreadsheet or document, fill in one block per workflow, and delete what does not apply.

### 1. Workflow

- Name: [for example, new client onboarding]
- Owner: [name and role]
- Starts when: [trigger] · Ends when: [result]
- How often: [times per week or month]

### 2. Systems

- System: [name] · Used by: [roles] · Data held: [client details, documents, payments] · Supplier: [company]

### 3. Steps and hand-offs

- Step: [what happens] · Who: [role] · From system: [name] · To system: [name] · Manual or automatic: [which]

### 4. Re-keying and bottlenecks

- Data typed again: [field] · From: [system] · Into: [system] · Minutes each time: [number]
- Where work waits: [step] · Waiting for: [document, person, approval] · Typical wait: [days]

### 5. AI opportunities

- Task: [read, extract or draft what] · Risk: [what goes wrong if the output is wrong] · Person who signs off: [role]

### 6. Questions for the compliance person

- Records: [does our record of processing list this system?]
- Retention: [when does the retention period for this data start, and who deletes it?]
- Suppliers: [does this supplier support an important function, and what contract do we hold?]

### 7. Fixes

- Fix: [what changes] · Hours saved per month: [number] · Order: [1, 2, 3]

## How does a system and data map relate to a UK GDPR Article 30 record?

A system and data map holds part of what a UK GDPR record of processing activities needs, not all of it. Article 30(1) of the [UK GDPR](https://www.legislation.gov.uk/eur/2016/679/article/30), the UK’s version of the General Data Protection Regulation, says each controller “shall maintain a record of processing activities under its responsibility” containing seven items.

| Article 30(1) item | Does a system and data map hold it? |
| --- | --- |
| (a) Name and contact details of the controller, any joint controller, representative and data protection officer | No |
| (b) The purposes of the processing | In part: the map shows what each system is used for |
| (c) Categories of data subjects and of personal data | In part: the map shows what data each system holds |
| (d) Categories of recipients, including in third countries or international organisations | In part: the map shows where data flows |
| (e) Transfers to a third country or international organisation, and safeguards where Article 49(1) applies | No, unless supplier hosting locations are recorded |
| (f) Where possible, the envisaged time limits for erasure | No |
| (g) Where possible, a general description of the security measures | No |

Article 30(3) says the record must be in writing, including in electronic form, and Article 30(4) says it must be made available to the Commission on request. The Commission is the Information Commission, the UK data protection regulator, which [took over from the Information Commissioner’s Office (ICO)](https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/09/ico-welcomes-transition-to-new-information-commission-and-marks-new-chapter-with-manchester-head-office-opening/) on 30 September 2026.

Article 30(5) exempts an enterprise or organisation employing fewer than 250 persons, unless any one of three conditions applies:

- the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects;
- the processing is not occasional;
- the processing includes special categories of data under Article 9(1) or personal data relating to criminal convictions and offences under Article 10.

Whether the exemption applies to a given firm is a question the audit writes down for the firm’s compliance person; the audit does not answer it.

## Which questions does a workflow audit flag for your compliance person?

A workflow audit flags questions about records, retention and suppliers for the firm’s compliance person to answer. It is not a compliance review, and none of the five deliverables is a legal opinion.

- **Records:** whether the record of processing covers each system on the map.
- **Retention:** at which step a retention period starts, and who deletes the data when it ends.
- **AI:** whether an AI opportunity needs a data protection impact assessment (DPIA). Article 35(1) of the [UK GDPR](https://www.legislation.gov.uk/eur/2016/679/article/35)requires one before processing “in particular using new technologies” that is likely to result in a high risk. The ICO’s [When do we need to do a DPIA?](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-impact-assessments-dpias/when-do-we-need-to-do-a-dpia/) names AI as an example of innovative technology. Our guide to [DPIA for AI tools](https://vexralabs.com/insights/dpia-for-ai-tools) covers when a UK firm needs one.
- **Suppliers:** for firms regulated by the Financial Conduct Authority (FCA), whether a supplier performs a critical or important operational function. [SYSC 8.1.4R](https://www.handbook.fca.org.uk/handbook/SYSC/8/1.html)treats a function as critical or important if a defect or failure in its performance would materially impair the firm’s continuing compliance, financial performance or the soundness or continuity of its services. SYSC 8.1.5AG says some firms take account of that rule as guidance. Our guide to [FCA outsourcing rules for checking a software supplier](https://vexralabs.com/insights/fca-outsourcing-software-supplier) covers the supplier checks.

Not legal advice

This guide describes our own service and quotes UK GDPR and the FCA Handbook as read on 8 October 2026. It is not legal advice. Your compliance person or a lawyer decides how the rules apply to your firm.

## How long does a workflow audit take, and what does it cost?

Our workflow audit takes two weeks and costs **£950, credited in full against a build agreed within 90 days**. Prices exclude VAT. The audit ends with a 45-minute walkthrough call. If the plan leads to a build, full builds run £8,000–25,000 in fixed-price phases.

## How should a firm prepare for a workflow audit?

A firm prepares for a workflow audit by gathering four things before it starts.

1. List the systems you use and who owns each one.
2. Pick the two or three tasks that take the most staff time.
3. Name one person who can answer questions during the two weeks.
4. Share any existing process notes and your record of processing, however rough.

## When is a workflow audit not worth it?

A workflow audit is not worth it when the answer is already obvious: a single off-the-shelf product clearly fits, or the fix is one known integration. In those cases, buy the product or go straight to a [Xero integration](https://vexralabs.com/services/xero-integration).

The audit comes before the build-or-buy decision, because its map shows which systems a new one would replace or connect. Our pillar guide, [Bespoke CRM vs off-the-shelf: UK costs and ownership](https://vexralabs.com/insights/custom-crm-vs-off-the-shelf), compares the two once the map exists. Book an audit through [our contact page](https://vexralabs.com/contact).

## Frequently asked questions

### What does workflow audit mean?

A workflow audit is a short, fixed-scope review of how work and data move between people and systems, and where data is re-typed or work waits.

### Is there a workflow audit template?

Yes. The template on this page has seven blocks: workflow, systems, steps, re-keying and bottlenecks, AI opportunities, questions for the compliance person, and fixes. It is a starting point to adapt.

### How much does a workflow audit cost?

Ours takes two weeks and costs £950, credited in full against a build agreed within 90 days. Prices exclude VAT.

### Is a workflow audit a compliance review?

No. It maps systems and flags questions about records, retention and suppliers for the firm's compliance person to answer.

### Does a small firm need a UK GDPR Article 30 record?

Article 30(5) exempts organisations with fewer than 250 staff unless the processing is likely to result in a risk, is not occasional, or includes special category or criminal offence data.

## Sources

1. [UK GDPR Article 30 (records of processing activities), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/30)
2. [UK GDPR Article 35 (data protection impact assessment), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/35)
3. [ICO, When do we need to do a DPIA?](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-impact-assessments-dpias/when-do-we-need-to-do-a-dpia/)
4. [FCA Handbook SYSC 8.1 (outsourcing)](https://www.handbook.fca.org.uk/handbook/SYSC/8/1.html)
5. [ICO, transition to the Information Commission (September 2026)](https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/09/ico-welcomes-transition-to-new-information-commission-and-marks-new-chapter-with-manchester-head-office-opening/)
