What records must you keep?
The AML/CTF Act requires reporting entities to retain records relating to designated services they provide. For professional services firms, this means keeping:
- KYC records: The identity information you collected and verified, your verification results, and beneficial ownership information for every client. Note that from 31 March 2026 the AML/CTF Act does not require you to keep scanned copies of the identity documents themselves — keep the details taken from them, the document type, what you did to verify, and the outcome
- Risk assessments: Your risk assessment for each client, including the risk rating assigned and why
- AML/CTF program: Every version of your firm's AML program, with dates of each version
- Suspicious matter reports: Copies of all SMRs lodged, plus documentation of any suspicious activity that was considered but not reported
- Staff training records: Evidence of who was trained, when, and on what
- Transaction records: Records of transactions connected to designated services
- Monitoring records: Documentation of ongoing monitoring activities and their outcomes
How long must records be kept?
The standard retention period under the AML/CTF Act is 7 years from the end of the transaction, the closure of the account, or the end of the business relationship — whichever comes latest. In practice, the safest approach is to retain records for 7 years from the date of the last transaction with that client.
But longer isn't automatically safe either. The AML/CTF Act sets a minimum, not a maximum, so retaining records beyond 7 years for another genuine reason — tax or professional obligations, for example — is fine. What changed on 1 July 2026 is that reporting entities are now covered by the Privacy Act for this data, and APP 11.2 requires you to destroy or de-identify personal information once it is no longer needed for any purpose you're permitted to hold it for. "Keep everything forever, just in case" is no longer a safe default. See our Privacy Act compliance guide.
How records must be stored
AUSTRAC doesn't prescribe a specific storage system, but records must meet these requirements:
- Readily accessible to AUSTRAC on request — you must be able to produce them promptly
- Stored securely — protected from unauthorised access, loss, or destruction
- In English or readily translatable to English
- Maintained in a way that allows AUSTRAC to determine your compliance with the AML/CTF Act
Preparing for an AUSTRAC audit
AUSTRAC can request access to your records at any time, with or without prior notice. The best preparation is having records organised by client, searchable, and exportable at short notice. Paper records stored in filing cabinets are technically compliant but practically very difficult to produce quickly across a large client base.
Purpose-built AML software maintains a searchable, timestamped audit trail automatically. CompliDesk stores all KYC records, risk assessments, program versions, and monitoring logs in a format that can be exported as a compliance report per client in one click.
What AUSTRAC looks for in an audit
- That you enrolled on time and your enrolment details are current
- That your AML/CTF program is written, current, and actually reflects your practices
- That you have conducted CDD on all clients receiving designated services
- That your records demonstrate ongoing monitoring, not just a one-time check at onboarding
- That SMRs were lodged appropriately and promptly when required
- That staff have been trained and training is documented
Manage AML compliance for all your clients from one dashboard
CompliDesk is built specifically for Australian professional services firms managing AML/CTF compliance for clients. Sign up free today.
Sign up free today