Pricing Privacy Act About Get Started Free
AUSTRAC compliance guide

How to store AML compliance records for AUSTRAC — the 7-year requirement explained

AUSTRAC requires every AML/CTF reporting entity to keep records for a minimum of 7 years. For professional services firms with dozens of clients, managing this compliantly requires proper systems — not spreadsheets.

What records must you keep?

The AML/CTF Act requires reporting entities to retain records relating to designated services they provide. For professional services firms, this means keeping:

How long must records be kept?

The standard retention period under the AML/CTF Act is 7 years from the end of the transaction, the closure of the account, or the end of the business relationship — whichever comes latest. In practice, the safest approach is to retain records for 7 years from the date of the last transaction with that client.

Longer isn't wrong: If your firm retains records longer than 7 years for other reasons (e.g. tax or professional obligations), that's fine. The AML/CTF Act sets a minimum, not a maximum.

How records must be stored

AUSTRAC doesn't prescribe a specific storage system, but records must meet these requirements:

Preparing for an AUSTRAC audit

AUSTRAC can request access to your records at any time, with or without prior notice. The best preparation is having records organised by client, searchable, and exportable at short notice. Paper records stored in filing cabinets are technically compliant but practically very difficult to produce quickly across a large client base.

Purpose-built AML software maintains a searchable, timestamped audit trail automatically. CompliDesk stores all KYC records, risk assessments, program versions, and monitoring logs in a format that can be exported as a compliance report per client in one click.

What AUSTRAC looks for in an audit

Manage AML compliance for all your clients from one dashboard

CompliDesk is built specifically for Australian professional services firms managing AML/CTF compliance for clients. Sign up free for free signup.

Sign up free today

AML record-keeping — quick answers

Yes. The 7-year retention requirement runs from when the record was created or the client relationship ended, whichever is relevant to the specific record type — not from when the client stops being active. Deleting a departed client's KYC file early is a genuine compliance risk.
It can technically hold the data, but it won't demonstrate the tamper-proof audit trail AUSTRAC expects — timestamped evidence of who checked what, when, and what decision was made. A platform with built-in audit logging removes the guesswork of proving your records haven't been altered after the fact.
No — it's broader: identity verification records, risk assessments, transaction records tied to designated services, and records of any reports made to AUSTRAC (or the grounds for deciding not to report). ID documents alone aren't sufficient evidence of a working compliance program on their own.