Salesforce Health Check: A Checklist for Financial Services Organisations
If you’ve inherited a Salesforce org, or you’re quietly worried yours has drifted, a health check tells you where you stand. For financial services firms the stakes are higher, because a messy org is a compliance risk.
Here’s a practical checklist you can run against your own setup, and what to do with what you find.
What is a Salesforce health check?
A Salesforce health check is a structured review of your org’s configuration, data, security and adoption to find gaps, risks and quick wins. It looks at how the platform is built, how healthy your data is, whether your controls meet your obligations, and whether people actually use it. The output is a prioritised list of fixes, so you know where to spend effort first.
Think of it as an MOT for your org. Everything might feel fine day to day, right up until a regulator asks for an audit trail you can’t produce, or a report the board relies on turns out to be built on duplicate records. A health check surfaces those problems before they surface you.
Before you start
Decide what “good” looks like for your firm before you review anything. A wealth manager’s priorities differ from a lender’s. Line up your obligations, your known pain points, and the outcomes you care about, so the review is measured against your world rather than a generic best-practice list.
The Salesforce health check checklist
Work through these areas. For each, you’re asking two questions: is it right, and can you prove it?
Data quality. Check for duplicate accounts and contacts, incomplete records, stale data and inconsistent formatting. In financial services, poor data doesn’t just slow teams down, it undermines suitability, reporting and any AI you layer on top later.
Security and access. Review profiles, permission sets, sharing rules and field-level security. Confirm that people can see what they should and nothing they shouldn’t, and that access is reviewed when people change roles or leave.
Compliance and audit trail. Check you can evidence what happened, when and by whom, for the processes a regulator cares about. Confirm your setup supports Consumer Duty outcomes and that complaints, cases and communications are captured with a clear, auditable history.
Configuration and technical debt. Look for overlapping automations, unused fields, hard-coded logic and workarounds that should be proper solutions. Layers of quick fixes are where orgs quietly become unmaintainable.
Releases and change management. Check whether changes are tested and deployed properly or pushed straight to production. Confirm you have sandboxes, a release process and version control rather than crossed fingers.
Reporting and dashboards. Confirm the numbers leaders rely on are accurate and come from a single source of truth, not three competing reports that disagree.
Adoption. Look at login rates, feature usage and where people are working around the system in spreadsheets. Low adoption is usually a design problem, not a training problem.
Integrations. Check the connections to your other systems are reliable, secure and don’t silently drop data.
Turning the checklist into action
A list of problems isn’t a plan. Score each finding by impact and effort, then sequence the work so the high-impact, low-effort fixes go first. A duplicate-data clean-up might unlock accurate reporting in a fortnight. A full re-architecture is a project, not a quick win, and needs treating as one.
The mistake to avoid is fixing the loudest problem instead of the most important one. A health check gives you the evidence to spend the next pound where it actually moves the needle.
When to bring in help
You can run a lightweight version of this yourself. For a regulated firm, an external review often finds things an internal team has stopped seeing, and carries more weight with a board or auditor. That’s what our Value Blueprint is: a structured health check that pinpoints the gaps, quick wins and strategic improvements in an existing org, with a clear plan for what to fix and in what order. Some people call it a health check; we call it the fastest route to getting more from what you’ve already built.
Salesforce health check FAQs
What is a Salesforce health check?
A Salesforce health check is a structured review of your org’s configuration, data, security and adoption to find gaps, risks and quick wins. It assesses how the platform is built, how healthy your data is, whether your controls meet your obligations, and whether people use it, then gives you a prioritised list of fixes.
How often should I run a Salesforce health check?
At least once a year for most firms, and more often if you’re regulated, changing fast, or have just inherited an org. A check is also worth running before a major project, after a merger or system change, and whenever reporting or adoption starts slipping.
What does a Salesforce health check cover for financial services?
On top of the usual data, security and configuration review, a financial services health check pays close attention to audit trails, access controls, complaints and case handling, Consumer Duty outcomes, and whether you can evidence the right things to a regulator. The compliance angle is what sets it apart from a generic review.
Can I do a Salesforce health check myself?
You can run a lightweight version using a checklist like this one. For a regulated firm, an external review often spots issues an internal team has stopped noticing and carries more weight with a board or auditor, so many firms combine a self-check with a periodic independent assessment.
What’s the difference between a health check and a Value Blueprint?
They’re the same idea. A Value Blueprint is our structured health check: it reviews your existing org and returns a prioritised plan of gaps, quick wins and strategic improvements, so you know exactly where to invest next rather than guessing.
If your Salesforce has drifted and you want an honest read on where it stands, start a Value Blueprint or talk to us first.