Licensing & Compliance
Compliance Audit Legal Services: From Findings to Remediation
A practical guide to legal compliance audits in Vietnam, covering scope, legal criteria, evidence sampling, interviews, privilege, licensing, corporate governance, employment, data, anti-corruption, third parties, finding classification, remediation, board reporting and continuous monitoring. It shows how to convert verified gaps into sustainable controls.
Compliance audit legal services assess whether a business’s actual conduct, records and controls meet the Vietnamese legal obligations applicable to its activities. A legal audit is different from a financial statement audit and from a policy review. It tests the operating evidence behind licences, approvals, decisions, employment practices, data handling, payments and third-party relationships, then converts verified gaps into accountable remediation.
A Licensing & Compliance engagement should start with the company’s business model, locations, regulators, ownership and recent changes. Counsel can define legal criteria, preserve sensitive work, use proportionate sampling and distinguish a documentation weakness from an active violation. This guide describes a general method for Vietnam at the scheduled publication date; legal advice must confirm the current rules for each sector and audit period.
Define the mandate for compliance audit legal services
An audit needs a written charter. It should state the client, purpose, period, entities, sites, legal domains, exclusions, reporting line, document access, interview authority and expected deliverables. Without this boundary, the team may collect large volumes while failing to answer the board’s actual risk question.
Choose a risk-based scope
Start with activities that create material regulatory exposure: conditional business lines, government interaction, high-value payments, personal data, workplace safety, environmental impact, consumer-facing sales, cross-border transactions and critical third parties. Consider prior findings, incidents, complaints and recent acquisitions or expansions.
A compliance audit legal services workplan should state why each area is included and which locations or transactions will be tested. Exclusions must be visible. A limited audit should not later be presented as assurance over the entire enterprise.
Separate audit, investigation and certification
A routine audit tests controls against defined criteria. An investigation examines a suspected event, persons and potential misconduct. Certification or regulatory attestation may require a specified independent professional and prescribed standard. Combining these purposes without a decision can compromise evidence and stakeholder expectations.
If audit work reveals suspected fraud, corruption, retaliation, evidence alteration or another serious matter, pause the relevant workstream and establish an investigation protocol. Preserve records, control access and reassess representation, reporting and notification obligations.
Legal professional privilege and confidentiality depend on the engagement, participants, purpose and applicable law. Define counsel’s role before interviews and document collection, and do not promise employees that the company can never use or disclose information.
Establish independence and governance
Identify the executive sponsor, audit owner and committee or board recipient. Operational managers should provide evidence and factual responses but should not silently rewrite findings concerning their own controls. Conflicts and limitations should be recorded.
Compliance audit legal services governance should define who may change scope, approve a rating, receive urgent escalations and close remediation. The legal team should remain independent in applying legal criteria while understanding operational feasibility.

Create the legal obligations register
The audit criteria should come from law, implementing instruments, licences, approvals, regulator decisions, binding contracts and adopted internal commitments. Record the source, effective date, affected entity, requirement, frequency, owner and evidence. Do not rely on an undated generic checklist.
Map entity and licence obligations
Verify enterprise and investment registration, legal representatives, capital, shareholders, business lines, branches, locations and corporate approvals. Conditional sectors may require sub-licences, qualified personnel, facilities, minimum capital, reporting or continuing operating conditions.
For compliance audit legal services, possessing a licence is only the first test. Confirm scope, entity, address, validity, conditions, renewal, amendment and actual activity. Expansion, new technology, relocation or ownership change may have created a gap even though the original licence remains on file.
Prioritise current and changed law
Maintain effective-date tracking. Vietnam’s legal framework changes through new laws, amendments, decrees, circulars and decisions. The audit should test requirements that applied during the sampled period and separately identify changes necessary for future compliance.
Where interpretation is uncertain, state the competing views, authority and operational consequence. Do not convert a legal uncertainty into a confirmed violation without analysis. Assign a targeted clarification or external opinion where material.
| Register field | Purpose | Audit evidence |
|---|---|---|
| Legal source | Defines the binding criterion | Current text and effective date |
| Entity and activity | Shows where the rule applies | Registration, site and process map |
| Control owner | Assigns accountability | Job role and approval authority |
| Control frequency | Sets expected operation | Logs, reports and transaction records |
| Exception response | Shows escalation and correction | Cases, decisions and closure evidence |
Design evidence testing and sampling
For each requirement, identify the control said to satisfy it and the evidence that would prove operation. Evidence can include licences, board minutes, filings, contracts, invoices, approvals, access logs, training records, incident reports, monitoring data and regulator correspondence. A policy alone proves design, not implementation.
Select a defensible sample
Define the population, period, sampling method and sample size before selection. Use risk-based selection for unusual values, sensitive third parties, government interaction or known exceptions, and add representative testing where routine operation matters. Preserve the population extract and selection logic.
A compliance audit legal services report should never extrapolate a precise enterprise-wide failure rate from a judgmental sample. It can explain observed exceptions, their significance and whether expanded testing is warranted.
Maintain evidence provenance
Record who supplied each item, where it came from, extraction date, period and any transformation. Keep native electronic records where metadata matters. Translations should be linked to the source. If management cannot produce expected evidence, report that control-evidence gap rather than assuming performance.
Access should follow need-to-know rules and data-protection requirements. Decree 13/2023 on Personal Data Protection may be relevant to employee, customer and third-party data collected during the audit. Limit collection, secure storage and define retention and deletion.
Use interviews to test, not replace, records
Interview control owners after reviewing core documents. Ask how the process works, what exceptions occur, who approves them and where evidence is stored. Compare responses across functions. A confident statement cannot substitute for a required licence, approval or transaction record.
Explain interview purpose, representation and note-taking. Distinguish direct quotation, factual summary and auditor inference. Give the interviewee a fair opportunity to clarify factual points without allowing negotiated removal of supported findings.

Core compliance domains to test
The exact domains depend on sector and risk. The following areas commonly affect Vietnamese businesses, but they should not be forced into an audit where inapplicable. Each workstream needs current criteria and evidence tailored to the entity.
Corporate governance and delegated authority
Test charters, internal governance, shareholder or member records, board decisions, legal representatives, delegations, related-party transactions and statutory registers. Compare approval thresholds with actual contracts and payments. Confirm that changes were registered where required.
Compliance audit legal services should examine whether authority operates in systems, not only on paper. Payment or contract workflows that allow users to bypass formal limits indicate a control-design issue even where sampled transactions happened to receive approval.
Employment, workplace and mandatory records
Review labour contracts, internal labour rules, payroll, working time, leave, social insurance, occupational safety, discipline, termination, foreign employees and employee-data handling. The Labour Code 2019 and related legislation provide the core framework, supplemented by current implementing rules.
Use targeted sampling across employee groups and locations. A template contract may be compliant while actual overtime, deductions or role changes are not. Interview HR and operational managers separately where practice differs from policy.
Anti-corruption, gifts and third parties
The Anti-Corruption Law 2018 includes provisions relevant to non-state enterprises as well as the public sector. Audit government interaction, gifts, hospitality, sponsorship, charitable giving, procurement conflicts, commissions and cash. Trace selected transactions to approval, recipient, business rationale, invoice and payment.
Third-party diligence should be risk-based. Verify ownership, capability, services, compensation, government links, contract and deliverables. A signed compliance clause does not resolve unexplained payment patterns or a consultant with no evidenced work product.
Data, consumer and marketing practices
Map personal data, purposes, legal basis or consent, notices, processors, access, retention, security, incidents and cross-border transfer. Review whether practice matches privacy notices. Consumer-facing businesses should test contract terms, disclosures, complaint handling, warranties and advertising against the Law on Protection of Consumers’ Rights 2023 and sector requirements.
A compliance audit legal services review should sample real campaigns and customer journeys, not only approved templates. Website, application, sales script and call-centre practices may diverge from legal sign-off.
Classify findings consistently
A finding should state criterion, condition, evidence, cause, consequence and recommendation. Separate confirmed violation, control-design gap, operating exception, evidence deficiency and improvement opportunity. Readers should understand what happened and why it matters without decoding vague phrases such as “not fully compliant.”
Use legal and business impact together
Rating can consider regulatory sanction, licence risk, criminal or civil exposure, financial impact, affected people, duration, recurrence, detectability and management override. Likelihood should reflect evidence, not optimism. A low-value repeated breach may expose a systemic weakness.
Compliance audit legal services ratings need written definitions and calibration. Similar findings should receive similar treatment across sites. Any override should identify decision-maker and rationale without changing the underlying facts.
Validate facts without negotiating conclusions
Provide responsible managers the factual evidence and allow corrections supported by source material. Resolve mistaken entity, date, sample or process descriptions. Legal conclusions remain counsel’s responsibility, and final management disagreement can be recorded transparently.
Urgent matters should not wait for the final report. Escalate ongoing unlicensed activity, safety danger, retaliation, evidence destruction, material data incident or suspected crime through the agreed protocol and begin lawful containment.
A credible compliance audit does not promise that no violation exists. It shows which obligations were tested, what evidence was examined, which limitations remain and how the business will correct verified weaknesses. Decision-makers can then distinguish urgent legal exposure from a documentation gap and allocate remediation resources where they produce the greatest control improvement.
Jurion & Partners Professional Perspective
Turn findings into remediation
Every accepted finding needs an action owner, deliverable, legal outcome, resources, deadline, interim control and closure evidence. “Update policy” is inadequate where the root cause is a broken workflow, unclear authority, poor system configuration or incentive conflict.
Address root cause and immediate exposure
Contain ongoing harm first: pause the affected activity where necessary, preserve evidence, obtain an urgent permit, correct a disclosure or restrict unsafe access. Then identify why the control failed. Common causes include ownership gaps, outdated legal registers, manual workarounds, weak data, inadequate supervision or deliberate override.
A compliance audit legal services remediation plan should link each action to the failed requirement and expected evidence. Policy, training, system, contract and monitoring changes may all be required. Avoid generic annual training as the default cure for a structural issue.
Decide regulator and stakeholder communication
Assess whether law, licence, contract or incident rules require notification, correction or cooperation. Confirm facts and authority before communication. A voluntary disclosure should have a defined objective and truthful scope; silence should not be chosen merely to avoid uncomfortable reporting.
Insurers, lenders, customers, employees or transaction counterparties may have notice rights. Coordinate communications so that one workstream does not contradict another or waive protection inadvertently.
Verify closure independently
Management’s statement that an action is complete is not closure evidence. Retest the redesigned control on new transactions and verify required filing or licence output. Record residual risk and formal risk acceptance by an authorised decision-maker where full remediation is not feasible.

Board reporting and continuous monitoring
The final report should include mandate, scope, criteria, method, limitations, findings, management response, remediation and urgent decisions. Executive reporting should highlight themes and material exposure without hiding the source evidence. Technical appendices can preserve transaction detail.
Give decision-makers a usable dashboard
Track open findings by severity, owner, age, due date, interim control and retest result. Show overdue and repeatedly extended items. Trend data should distinguish new findings from legacy backlog and avoid celebrating closure that has not been verified.
Compliance audit legal services should end with a monitoring plan. Legal-change review, licence calendars, control testing, incident analysis and targeted follow-up audits keep the obligations register alive. New products, locations, investors and acquisitions should trigger scope reassessment.
Rotate deep-dive audits by risk while maintaining continuous monitoring for licences, high-risk payments, data incidents and overdue remediation. Use the results of complaints, incidents and prior exceptions to adjust the next cycle. This balances broad coverage with the focused evidence testing needed for meaningful assurance.
Documents to provide to counsel
Begin with a business map, regulatory inventory and prior findings so counsel can design a focused request list. Identify the entities, sites, products, audit period and decision expected from the review, together with known incidents or restrictions on evidence access.
- Enterprise, investment, sector licences, approvals and regulator correspondence.
- Organisation, delegations, governance records and obligations register.
- Policies, procedures, training, monitoring and exception logs.
- Transaction populations, system access and sample source records.
- Prior audits, incidents, complaints, investigations and remediation status.
- Third-party, employee, customer, privacy and reporting documentation.
Clients requiring a tailored audit plan may Book a Consultation. Secure, staged production lets counsel test the highest-risk questions early and reduces unnecessary collection of sensitive personal or commercial data.
Final audit checklist
Confirm mandate, scope, legal criteria, independence, data controls, sample, interviews, findings, escalation, management response, remediation ownership and closure testing. State limitations clearly and preserve the evidence index. Update the obligations register with every verified legal change.
Well-designed compliance audit legal services should give leadership a reliable picture of tested risk, a prioritised remediation portfolio and an evidence-based path to sustainable compliance. The objective is not a report with no findings; it is a business capable of detecting, correcting and preventing legal control failures.
Phân tích
Phân tích
Phân tích