What records must you keep?
The AML/CTF Act requires reporting entities to retain records relating to designated services they provide. For professional services firms, this means keeping:
- KYC records: Identity documents, verification results, and beneficial ownership information for every client
- Risk assessments: Your risk assessment for each client, including the risk rating assigned and why
- AML/CTF program: Every version of your firm's AML program, with dates of each version
- Suspicious matter reports: Copies of all SMRs lodged, plus documentation of any suspicious activity that was considered but not reported
- Staff training records: Evidence of who was trained, when, and on what
- Transaction records: Records of transactions connected to designated services
- Monitoring records: Documentation of ongoing monitoring activities and their outcomes
How long must records be kept?
The standard retention period under the AML/CTF Act is 7 years from the end of the transaction, the closure of the account, or the end of the business relationship — whichever comes latest. In practice, the safest approach is to retain records for 7 years from the date of the last transaction with that client.
Longer isn't wrong: If your firm retains records longer than 7 years for other reasons (e.g. tax or professional obligations), that's fine. The AML/CTF Act sets a minimum, not a maximum.
How records must be stored
AUSTRAC doesn't prescribe a specific storage system, but records must meet these requirements:
- Readily accessible to AUSTRAC on request — you must be able to produce them promptly
- Stored securely — protected from unauthorised access, loss, or destruction
- In English or readily translatable to English
- Maintained in a way that allows AUSTRAC to determine your compliance with the AML/CTF Act
Preparing for an AUSTRAC audit
AUSTRAC can request access to your records at any time, with or without prior notice. The best preparation is having records organised by client, searchable, and exportable at short notice. Paper records stored in filing cabinets are technically compliant but practically very difficult to produce quickly across a large client base.
Purpose-built AML software maintains a searchable, timestamped audit trail automatically. CompliDesk stores all KYC records, risk assessments, program versions, and monitoring logs in a format that can be exported as a compliance report per client in one click.
What AUSTRAC looks for in an audit
- That you enrolled on time and your enrolment details are current
- That your AML/CTF program is written, current, and actually reflects your practices
- That you have conducted CDD on all clients receiving designated services
- That your records demonstrate ongoing monitoring, not just a one-time check at onboarding
- That SMRs were lodged appropriately and promptly when required
- That staff have been trained and training is documented
Manage AML compliance for all your clients from one dashboard
CompliDesk is built specifically for Australian professional services firms managing AML/CTF compliance for clients. Sign up free for free signup.
Sign up free today