NEXSUM_LABS
  1. Home
  2. Work
  3. A financial advisory firm's CRM went from liability to system of record
Book a call

[ Case study ]

Financial servicesHubSpot CRMDedupe/validation routinesAudit loggingCompliance-aligned permissions

A financial advisory firm's CRM went from liability to system of record

Compliance flagged the CRM: client records contradicted the books, contact data was stale enough to be a retention risk, and advisers maintained parallel records because they didn't trust the official one. The tool meant to prove diligence was the diligence problem.

CLIENT a wealth-management advisory firm — FOCUS Reconcile the CRM against the books

HubSpot CRMCRM IntegrationsHubSpot CRMFinancial servicesRepresentative example
Client
a wealth-management advisory firm
Industry
Financial services
Engagement
8 weeks — systems pod — automation specialist + engineer
Service
CRM Integrations / HubSpot CRM
Headline outcome
Client records failing the quarterly compliance sample check: 31% → 3%, read from Compliance audit reports

Representative examplesEvery case study in this library is an illustrative composite of the kind of engagement we deliver — written to show our method and standards, not to name clients.

Where they started

The client is a wealth-management advisory firm where advisers hold books of long-term clients and compliance obligations shape every client communication. Its regulator expects client records to be accurate and traceable, and the firm's own compliance officer samples records quarterly to test exactly that. The firm adopted a CRM years ago to be the system of record, and compliance wants to trust it — but the tool was configured for administrators rather than for the advisers, whose working hours are spent with clients rather than screens.

What it was costing

Compliance flagged the CRM: client records contradicted the books, contact data was stale enough to be a retention risk, and advisers maintained parallel records because they didn't trust the official one. The tool meant to prove diligence was the diligence problem.

What they could see

  • The compliance sample check returns records whose client details contradict the firm's own books of business.
  • Contact records show clients at addresses and with numbers the firm knows are years out of date.
  • Advisers keep client notes in personal files because the CRM's version of their own client is wrong.
  • Nobody can produce, on request, a clean trail of who corrected what, when, and why.
  • The annual audit preparation turns into a scramble to reconcile records the firm already pretends are current.

The constraints we worked inside

  • Financial-services compliance sets the bar — record accuracy and audit trails are regulatory, not optional.
  • Advisers are paid for relationships, not data entry; the fix had to reduce their typing.
  • Nothing could be deleted — corrections, never removals, with history preserved.

What had been tried before

A quarterly data-cleanup drive was organised where support staff corrected contact records en masse before each sample check.
The records passed that quarter's check and decayed again by the next one, because nothing in daily work kept them current.
A temporary intern was assigned to reconcile the CRM against the firm's client list record by record.
The work outlasted the placement and the corrections sometimes guessed; two well-meant edits created the kind of errors compliance was looking for.
A partners' memo declared the CRM the mandatory system of record for all client activity.
Mandates raised the cost of using a tool advisers already found hostile; parallel records multiplied while official activity fell.

What we proposed

Accuracy should be a property of the system rather than a quarterly campaign. First, reconcile the CRM against the firm's client list from the books, with every mismatch either resolved or flagged through a documented review — never ignored. Then automate the hygiene humans skip: duplicate detection, address validation, and review-date reminders running continuously, so records pass the compliance sample because they are maintained, not because they were cleaned. The adviser's own notes and view became the default interaction model — corrections flow from their daily work instead of mandates about it. Nothing gets deleted; corrections preserve history.

Just as important is what we ruled out, and why:

  • A new CRM platformHygiene follows process, not tools, and migrating a firm's records during audit season risks the exact accuracy the project exists to establish.
  • Locking fields read-only for advisersThe advisers' own knowledge is the best source of truth; a read-only CRM would push their corrections further into private files, not out of them.
  • Full automation from custodian data feedsIntegration lead time and compliance review stretched beyond the engagement, and the feed would still miss the contact-level detail that fails sample checks.

How the work ran

01Reconcile the CRM against the books

Client records were matched to the firm's client list with a documented discrepancy review — every mismatch resolved or flagged, never ignored.

02Automate the hygiene that humans skip

Duplicate detection, address validation, and review-date reminders run continuously — accuracy becomes a property of the system, not a quarterly clean-up.

03Make the adviser's version the official one

The adviser's workflow (their notes, their view) became the CRM's default interaction model — trust returned because the tool finally served them.

Delivered by the systems pod — automation specialist + engineer over 8 weeks, with working increments reviewed with the client every week.

The stack, and the reasoning

HubSpot CRM
Already the nominal system of record with native audit history; the regulator's traceability requirement made the existing platform the right spine to repair rather than replace.
Dedupe/validation routines
Duplicate detection and address validation run continuously, so accuracy is a property of the system — the quarterly campaign model is what kept failing.
Audit logging
Corrections are recorded with who, when, and why; under a no-deletion policy, the audit trail is not a feature of the project but its evidence.
Compliance-aligned permissions
Advisers see and correct their own book, compliance sees everything; the boundary was drawn from the sample-check criteria, not from a template.

What went wrong

Obstacle

Merging duplicate records normally deletes the losing record, and the firm's no-deletion rule — corrections only, history preserved — meant standard merge behaviour was non-compliant by itself.

Handled: We built a merge-with-history pattern: superseded records are marked rather than removed, the surviving record links to them, and compliance signed off the pattern against the retention policy.

Obstacle

We built the reconciliation around clean data, then discovered the compliance officer's sample check tested specific criteria our hygiene did not prioritise — our version of clean and the audit's version of clean were not the same thing.

Handled: We restarted the checklist from her sample criteria, re-cut the validation rules to test exactly what the audit tests, and the review loop ran against the check from then on.

How we worked together

Cadence
A weekly reconciliation review with the compliance officer and ops manager through the eight weeks, plus a short adviser pilot session at the mid-point of the reconfiguration.
Client side
The compliance officer owned the standard the work had to meet; the ops manager ran the mismatch reviews; two advisers piloted the new interaction model.
Decisions
The sample-check criteria defined done — every rule, field, and permission traces to them; advisers held a veto over anything that added typing to their day.
They provided
The client list from the firm's books, sample custodian exports, compliance policy documents, and adviser time for verification of their own books.

What changed

The headline: client records failing the quarterly compliance sample check31% → 3%, read from Compliance audit reports. A second check: deleted records (corrections only, history preserved) at 0.

Advisers stopped maintaining a private version of the truth because the official version stopped contradicting them — their own notes became the record, and the typing they do serves them first and the audit second. The compliance officer walks into sample checks expecting to pass rather than expecting to find something, and the annual scramble before audits has quieted into a routine review. The CRM turned from the thing compliance policed into the thing that proves the firm's diligence.

The result was read from Compliance audit reports against the pre-engagement baseline over the stated window, with a guardrail check on deleted records (corrections only, history preserved). Where platform-reported numbers and business outcomes differ, this record says which layer it is quoting.

What they own now

  • The reconciliation runbook — matching rules, discrepancy categories, and the review trail — owned by the ops manager.
  • Continuous validation routines with alerting, configured to the compliance sample criteria.
  • The merge-with-history procedure documenting how duplicates are resolved without deletion.
  • A permissions matrix signed off by compliance, showing each role's visibility and its reasoning.
  • A quarterly pre-audit checklist mapping the sample check to the system's own reports.

What we would do differently

We would have started with the compliance officer's sample-check criteria — we built to 'clean data' when the actual bar was 'passes the audit'.

CRM IntegrationsHubSpot CRMFinancial servicesHubSpot CRM

Next case study

A course business's email finally knows who bought what