Understanding AML/CTF Record-Keeping Requirements for Reporting Entities

Published By:

Hannah Deuk

Founder & Principal Lawyer

Key Takeaways:

  • The Seven-Year Rule Varies: While many records must be kept for seven years, the start date depends on the record type. For customer due diligence records, the clock starts after the business relationship ends, not when the record was created.
  • Document Decisions, Not Just Data: It is not enough to keep copies of identification documents. To comply with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), you must record the actions taken and the rationale behind your risk assessments and decisions.
  • Specific Record Categories Are Mandatory: Reporting entities must create and retain specific records, including your AML/CTF Program and risk assessments, all Customer Due Diligence (CDD) files, details to reconstruct transactions, and records of any Suspicious Matter Reports (SMRs).
  • Balance Retention with Privacy Obligations: Prematurely deleting records is a breach, but retaining them indefinitely without proper controls creates risks under the Privacy Act 1988. Records must be stored securely and access must be limited to authorised staff.
Jump to...
August 14, 2026

Introduction

For reporting entities, record keeping is a standalone anti-money laundering (AML) obligation rather than just an administrative exercise. Reporting entities must create and retain accurate records to demonstrate compliance with their duties and to support the supervisory and investigative functions of AUSTRAC.

These record-keeping requirements are principally outlined in Part 10 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act). This article explains the key obligations, including the general seven-year retention rule for many record categories, to help businesses manage their compliance framework effectively.

Interactive Tool: See How Long You Must Keep Your AML Records

AML Record Retention Checker for Reporting Entities

Quickly check your AML/CTF record-keeping and retention obligations under Australian law.

What type of AML/CTF record are you assessing?

Has the business relationship with the customer ended, or is the record no longer relevant?

Are the records subject to any ongoing investigation, legal request, or AUSTRAC inquiry?

✅ CDD Records: Standard 7-Year Retention Applies

Under Section 107 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and Section 111 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), Customer Due Diligence records must be kept for seven years after the business relationship ends or after the last occasional transaction. Ensure your records are securely stored and accessible for this full period.

  • Section 107 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
  • Section 111 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Get AML/CTF Legal Advice

✅ Transaction Records: 7 Years from Completion

Transaction and designated service records must be retained for seven years from the date the transaction was completed. If you received documents from a customer, keep them for seven years from the date received. This is required by Section 107 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and Section 108 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth).

  • Section 107 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
  • Section 108 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Speak to a Lawyer about AML/CTF Compliance

✅ Program & Risk Records: Retain 7 Years After Relevance Ends

AML/CTF program, policy, and risk assessment records must be kept for seven years after they are no longer relevant for demonstrating compliance. Use professional judgement to determine when a record is obsolete, but err on the side of caution.

  • Section 107 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Get AML/CTF Program Advice

⚠️ SMR & Sensitive Records: Retention and Security Required

Suspicious Matter Reports (SMRs) and related records must be retained for seven years and stored securely with access limited to authorised personnel. This is critical to comply with both the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and the Privacy Act 1988 (Cth).

  • Section 123 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
  • Privacy Act 1988 (Cth)
Get Advice on SMR Handling & Privacy

⚖️ Records Under Investigation: Retain Until Released

If records are subject to an AUSTRAC, law enforcement, or court investigation, do not destroy or delete them—even if the standard retention period has expired. Retain all relevant records until the investigation or legal proceedings are formally concluded.

  • Section 107 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Speak to a Lawyer about Investigation Holds

⚠️ Ongoing Relationship: Retention Period Not Yet Triggered

The seven-year retention period for most AML/CTF records only begins once the business relationship ends or the record is no longer relevant. Continue to retain all records securely until the correct trigger event occurs.

  • Section 107 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Get Advice on AML/CTF Record Management

Request Free Consultation Today

Our senior lawyers will contact you to discuss your situation & outline next steps.

Why AML Record-Keeping Matters for AUSTRAC-Regulated Entities

Records Must Show Compliance

As per Sections 111 and 116 of the AML/CTF Act, reporting entities must maintain accurate records to demonstrate they are meeting their anti-money laundering and counter-terrorism financing (AML/CTF) obligations. These records serve as evidence of the specific actions taken to comply with legal requirements. It is not enough to simply have an AML/CTF program in place; you must be able to show how it was applied.

Your records need to be sufficient to reconstruct individual transactions and show that you are meeting your customer due diligence (CDD) and AML/CTF program obligations. This means documenting:

  • what you did;
  • when you did it; and
  • the reasoning behind your decisions.

Record Keeping Supports AUSTRAC Supervision & Investigations

Proper record keeping is essential for AUSTRAC’s supervisory functions, allowing the regulator to assess whether your business is fulfilling its AML/CTF obligations. Complete and accurate records provide a clear picture of your compliance activities.

Should your services be ML/TF/PF, these records become critical for investigations. They can provide valuable information to the Australian Transaction Reports and Analysis Centre (AUSTRAC) and other authorities, helping them to trace illicit activities and take appropriate action.

Privacy Obligations Still Apply

Your AML record-keeping obligations do not override your responsibilities under the Privacy Act 1988 (Cth) (Privacy Act), as specifically stated in Section 105 of the AML/CTF Act. All reporting entities, including small businesses, must handle personal information in accordance with this legislation. You should only collect and retain information that is reasonably necessary for your compliance purposes and permitted under Australian Privacy Principle (APP) 3 and APP 11.

Sensitive records, such as customer identification details and suspicious matter reports, must be stored securely with access limited to authorised staff. APP 11.1 in Schedule 1 to the Privacy Act requires reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification, or disclosure. Failing to protect this information could lead to a breach of your privacy obligations and increase the risk of tipping off individuals involved in suspicious activities.

Speak to Our Senior Lawyers Today

Request your free consult & our senior lawyers will contact you to discuss your situation.

What Records Should You Keep

AML Program & Risk-Assessment Records

Under Section 116 of Part 10 of the AML/CTF Act, reporting entities must create and retain records that demonstrate compliance with their Part 1A AML program obligations. This includes keeping both current and previous versions of key documents to show how policies and risk assessments have evolved.

The statutory test is whether the records are “reasonably necessary” to demonstrate compliance. While there is no exhaustive list of documents that every reporting entity must retain, key records that help demonstrate compliance include:

  • ML/TF Risk Assessments: Your business must keep its current, documented risk assessment, along with previous versions. Records should also cover senior manager approvals and the steps taken to conduct, review, and update the assessment.
  • AML/CTF Program Documentation: You must retain the current version of your program and any earlier versions. It is also necessary to keep records of senior manager approvals and any consultations that occurred during the program’s development.
  • Governance and Oversight: This category includes records of the appointment of your AML/CTF compliance officer, minutes from governing body meetings discussing compliance, and policies outlining the responsibilities of senior managers.
  • Personnel Training and Due Diligence: You need to keep records of AML/CTF training materials, attendance registers, and background checks conducted on staff.
  • Independent Reviews: Any reports from independent evaluations of your AML/CTF program must be retained, along with records of actions taken in response to their findings.

Customer Due Diligence Records

Reporting entities have a strict obligation under Section 111 of the AML/CTF Act to keep detailed records of their CDD processes. These records must be sufficient to show what information was collected, the verification steps taken, and the rationale behind any risk assessment or decision.

The record-keeping obligation applies to all forms of CDD, including initial, ongoing, simplified, and enhanced due diligence. Initial and ongoing CDD are governed by Sections 28 and 30 of the AML/CTF Act, while simplified and enhanced CDD are governed by Sections 31 and 32. The retention period for these records is detailed under the retention requirements below.

Examples of essential CDD records include:

  • internal forms showing customer information updates;
  • results from identity verification services; and
  • documented approvals for high-risk customers.

Your records for ongoing monitoring may include:

  • Updates made to customer profiles and risk ratings, with a clear rationale for any changes.
  • System-generated alerts for unusual activity and documentation of the subsequent investigation.
  • The reasoning for closing an alert or escalating it for further review.
  • Details of any enhanced CDD measures applied.
  • Records of decisions to continue or terminate a business relationship.

Transaction & Designated-Service Records

According to Section 107(1) of the AML/CTF Act, you must make and keep transaction records for every designated service you provide. These records need to contain enough detail to allow for a full and accurate reconstruction of the transaction at a later date.

Details to record for each transaction may, depending on the designated service, include:

  • the date and time of the transaction;
  • the amount and currency involved, or details of the virtual assets;
  • information identifying the customer and any recipient;
  • the type of transaction, such as a purchase or transfer;
  • any unique transaction identifiers;
  • the payment method used; and
  • supporting documents like receipts, contracts, or agreements.

If a customer provides you with any transaction documents, such as payment instructions or signed contracts, Section 108(2) of the AML/CTF Act requires you to keep these as part of your transaction records.

Suspicious Matter Reporting Records

Reporting entities must maintain records related to any suspicious matter reports (SMRs) filed with AUSTRAC. The obligation to submit an SMR is imposed by Section 41 of the AML/CTF Act. Records connected with SMRs must be retained where they are reasonably necessary to demonstrate compliance with Part 1A under Section 116.

This includes not only the SMR itself, but also all supporting documents and internal deliberations. You should document the entire process, from when a matter was first identified to when a suspicion was formed and the report was submitted.

These records are highly sensitive and must be stored securely with strict access controls limited to authorised personnel. Proper handling of SMR-related information is essential to prevent unauthorised disclosure and to comply with the tipping-off provisions in Section 123 of the AML/CTF Act.

Request Free Consultation Today

Our senior lawyers will contact you to discuss your situation & outline next steps.

How Long Must AML Records Be Retained by Reporting Entities?

The General Seven-Year Rule

Under the AML/CTF Act, many types of records must be kept for a period of seven years. This is a core record-keeping obligation for all reporting entities.

However, the seven-year retention period does not always begin when the record is created. The starting point, or trigger, depends on the type of record. For instance, CDD records must be kept for seven years after the business relationship ends, or after the final occasional transaction is completed under Section 111(2) of the AML/CTF Act.

Retention Periods Depend on the Record Category

A single “seven years from creation” rule does not apply to all documents. The retention period is determined by the specific category of the record, and a well-structured retention policy will identify the correct legal trigger for each type of record.

Different triggers apply to various record categories:

  • CDD Records: The seven-year period begins after the business relationship with the customer ends or from the date of the last occasional transaction under Section 111(2) of the AML/CTF Act.
  • Transaction Records: These must be retained for seven years beginning on the day the record is made under Section 107(3) of the AML/CTF Act. If a customer provides a document related to a transaction, it must be kept for seven years beginning on the day after it was given to the reporting entity under Section 108(2).
  • AML/CTF Program Records: These records must be kept for seven years after the record is no longer relevant for demonstrating compliance under Section 116(3) of the AML/CTF Act. This requires professional judgement to determine when a record, such as an old risk assessment, is no longer needed to show compliance.

Speak to Our Senior Lawyers Today

Request your free consult & our senior lawyers will contact you to discuss your situation.

How Must Records Be Stored & Made Available?

Records Can Be Electronic or Physical

Sections 107, 111 and 116 of the AML/CTF Act do not prescribe one mandatory storage medium or a specific storage format for compliance records. Reporting entities can keep records in either hard copy or electronic form, and may store them on-site or at an offsite location.

If you choose to maintain electronic records, they must be secure and accurate. In addition, they must be easily retrievable and can be produced in their original format. For instance, a spreadsheet should be kept as a spreadsheet file rather than being converted into a PDF, which could alter its structure or usability.

Records Must Be Accessible & Intelligible

A key part of the record-keeping obligation is ensuring that records can be retrieved promptly when required by AUSTRAC or other authorities. Your systems should allow you to link records to the relevant customer or transaction and provide them in a usable format.

Under Sections 111(2)(b) and 116(1)(b) of the AML/CTF Act, CDD records and Part 1A compliance records must be in English or in a form that is readily accessible and readily convertible into writing in English.

Fragmented data storage can create significant compliance risks. Storing information across various disconnected platforms can make it difficult to produce a complete and coherent record for a specific customer or transaction. These platforms may include:

  • onboarding tools;
  • CRMs;
  • blockchain analysis tools;
  • email inboxes; and
  • shared drives.

Security Access Controls & Audit Trails

While not all security measures are explicitly prescribed, implementing robust controls helps demonstrate that records are protected from unauthorised access, alteration, or loss. APP 11.1 in Schedule 1 to the Privacy Act requires reasonable steps to protect personal information, but does not prescribe one mandatory technical solution.

As noted earlier, under privacy obligations, sensitive records such as customer identification details and SMRs require particularly stringent protection.

Practical controls to protect your records include:

  • Access Controls: implementing measures like password protection and role-based access to limit who can view or modify sensitive information.
  • Encryption: using encryption for electronic records to protect data both in transit and at rest.
  • Secure Storage: keeping physical paper records in locked cabinets or other restricted-access areas.
  • Regular Backups: performing regular backups of all electronic AML/CTF records to a secure offsite location or an encrypted cloud service.
  • Data Recovery Plan: having a clear plan to recover data in the event of a system failure, cyber incident, or other disruption.

Request Free Consultation Today

Our senior lawyers will contact you to discuss your situation & outline next steps.

Common Record-Keeping Failures for AUSTRAC-Regulated Entities

Keeping Customer Documents Without Decision Records

Reporting entities may retain identification documents but fail to record:

  • the verification steps taken;
  • the customer’s ML/TF risk assessment;
  • the reasons for key CDD decisions; and
  • how inconsistencies were resolved.

Section 111(3)(a)–(b) of the AML/CTF Act requires records of the data collected and the relevant analysis, assessment, and decision-making. It does not require a scanned copy of every identification document, where the relevant information and verification steps are otherwise recorded.

Incomplete Monitoring & Alert Records

Records should explain how significant monitoring alerts were investigated and resolved. This may include:

  • the evidence reviewed;
  • the outcome of the investigation;
  • any internal escalation; and
  • the reasons for closing or escalating the alert.

These records support AML/CTF compliance with Section 30(2)(a) and 111(3)(b) of the AML/CTF Act. However, the legislation does not require a separate closure record for every automated alert.

Inconsistent Customer Information

Differences in customer names, beneficial ownership details or transaction histories across systems can undermine CDD and ongoing monitoring. Material inconsistencies should be investigated and documented where necessary to demonstrate compliance with Sections 28, 30 and 111 of the AML/CTF Act.

Incorrect Retention or Deletion

Reporting entities face risks from both premature deletion and indefinite retention of records. Deleting records before the mandatory retention period has expired is a direct breach of your record-keeping obligation.

Conversely, retaining records for longer than necessary without proper controls can create issues under the Privacy Act. Indiscriminate retention without appropriate security measures increases privacy and data governance risks.

Speak to Our Senior Lawyers Today

Request your free consult & our senior lawyers will contact you to discuss your situation.

Practical Steps for Compliant Record-Keeping

Maintain an AML Records Register

Although Part 10 of the AML/CTF Act does not expressly require an “AML records register”, maintaining one is good practice. For each record category, it should identify:

  • the type of record;
  • the person responsible;
  • where and how it is stored;
  • the applicable retention period;
  • the event that starts the retention period; and
  • the relevant access and security controls.

Test Record Retrieval

Periodically test whether the business can produce a complete customer or transaction file, including:

  • initial CDD records;
  • customer risk assessments;
  • transaction records;
  • monitoring alerts and investigation notes; and
  • relevant reporting decisions.

This is a best-practice measure rather than a separate statutory requirement, but it can identify gaps before records are requested by AUSTRAC.

Align Data Governance with the AML Program

The AML/CTF program should be aligned with the business’s:

  • data-retention policy;
  • privacy framework;
  • information-security controls; and
  • vendor and outsourcing arrangements.

This helps prevent required AML/CTF records from being deleted too early or personal information from being retained longer than necessary.

Request Free Consultation Today

Our senior lawyers will contact you to discuss your situation & outline next steps.

Conclusion

Effective AML compliance is built on maintaining reliable evidence of your record-keeping practices throughout the customer lifecycle. Reporting entities must be able to demonstrate not only that they have an AML/CTF program, but also how it was applied, why key decisions were made, and that records can be retrieved when AUSTRAC requests them.

Meeting these detailed record-keeping obligations requires a thorough and proactive approach to compliance. If you need assistance developing or testing your AML/CTF program and record-keeping framework, contact the expert AML/CTF compliance lawyers at Click Legal today for tailored guidance.

Frequently Asked Questions

JUMP TO...
Table of Contents

Published By:

Hannah Deuk

Founder & Principal Lawyer

Request A Free Consultation

Our senior lawyers will contact you to discuss your situation & outline next steps.

Insights Library

Legal & Compliance Insights

Browse practical articles, guides & updates from our lawyers on key legal & compliance issues.

Join our Newsletter

Subscribe to our newsletter for the latest legal updates, insights, and firm news delivered straight to your inbox.

What Our Clients Say About Working With Us

Ready-to-Use Legal & Compliance Templates

Lawyer‑drafted legal templates in downloadable Word format.

CONTACT

Request A Consultation

Not sure which matter or service is right for you? Leave your details & our lawyers will contact you to discuss your situation & outline next steps.

Inquire Now

Tell us briefly what you need help with & we’ll reply within 1 business day.