The Importance of Record Keeping
Under AUSTRAC regulations, if it isn't documented, it didn't happen. Tranche 2 entities must maintain comprehensive records of all AML/CTF activities, decisions, and transactions for seven years. CompliDesk automatically generates a secure, time-stamped audit trail for your business, ensuring you are always prepared for an AUSTRAC audit or independent review.
What Must Be Recorded?
To remain compliant, your firm must keep detailed records of:
- KYC & CDD: All client identification documents, biometric verification results, and PEP/sanction screening reports.
- Risk Assessments: The completed risk questionnaires and documented rationales for every client risk rating.
- Decisions: Any compliance decisions, such as approvals for high-risk clients or investigations into suspicious activity.
- Training: Records of staff training completion, including dates, topics covered, and assessment scores.
The CompliDesk Automated Audit Trail
CompliDesk removes the burden of manual record keeping. Every action taken on the platform—from sending a KYC request to approving a risk assessment—is automatically logged with an immutable timestamp and the user's details. These records are encrypted and stored securely in Australian-based servers, satisfying both AUSTRAC and Australian privacy regulations.
Key Benefits of CompliDesk Audit Trails
- Automated Logging: No manual record keeping; every action is automatically logged with time and user stamps.
- 7-Year Secure Storage: Bank-grade, encrypted storage that complies with AUSTRAC's record-keeping laws.
- Instant Audit Reports: Generate comprehensive compliance reports for AUSTRAC audits in one click.
- Secure Document Management: Store IDs, risk assessments, and communication history in one secure location.
How the Feature Works
- Track: The system automatically captures every compliance event, verification check, and decision in real time.
- Store: Records are encrypted and stored securely in Australian-based cloud servers.
- Report: In the event of an AUSTRAC audit or independent review, export the complete audit trail instantly as a PDF.
- File: Track and log Suspicious Matter Reports (SMRs) and Threshold Transaction Reports (TTRs) securely.
Why it Matters Under AUSTRAC Tranche 2
Record-keeping breaches are among the most common compliance failures. Under the AML/CTF Act, you must keep records of your risk assessments, KYC verifications, transactions, and training for 7 years. Failing to produce these records during an AUSTRAC audit can lead to substantial fines and reputational damage. CompliDesk makes record keeping effortless.
Industries That Should Use It
All Tranche 2 entities must maintain a compliant audit trail. CompliDesk supports:
- Lawyers & Conveyancers: To maintain a clear record of funds origin and transaction authorization.
- Accountants: To document compliance decisions, client structures, and tax advice files.
- Real Estate Professionals: To store sales records, buyer identity checks, and agent diaries.
- TCSPs & VASPs: To log high-volume transactions, company registers, and crypto wallet addresses.
- Precious Metals Dealers: To maintain buy/sell registers and cash transaction logs.
Compliance Best Practices
- Retain all compliance records for a minimum of seven years after the client relationship ends.
- Ensure your record-keeping system is secure, backed up, and only accessible by authorized staff.
- Document the reasoning behind all compliance decisions, especially when filing or choosing not to file an SMR.
- Never discuss a Suspicious Matter Report (SMR) with the client (avoiding "tipping off" offenses).
Frequently Asked Questions (FAQ)
What records are we legally required to keep under AUSTRAC Tranche 2?
You must keep records of your AML/CTF Program, all client identification and verification (KYC) documents, risk assessments, transaction records, staff training logs, and any reports filed with AUSTRAC.
How long do we need to store KYC and transaction records?
Under Australian law, all AML/CTF compliance records must be retained for a minimum of seven (7) years from the date the record was made, or from the date the client relationship ended.
What is the "tipping off" offence in relation to SMRs?
Tipping off is a criminal offense under the AML/CTF Act. It occurs when you disclose to a client or any third party that a Suspicious Matter Report (SMR) has been, or is being, compiled or filed with AUSTRAC.
Are the records stored in CompliDesk hosted in Australia?
Yes. All data and documents uploaded to CompliDesk are hosted on secure, encrypted servers located in Australia, fully complying with local data sovereignty and privacy regulations.