Under the AML/CTF Act, reporting entities must retain certain records for 7 years. This requirement applies to customer identification records, transaction records, AML/CTF program documents, and reporting records. Here's exactly what must be kept and how.

Which records must be retained?

Customer identification records: The information you collected and verified, your verification results, beneficial ownership information, and any updates to customer records. Retained for 7 years from the end of the relationship.

Note what this does not require. From 31 March 2026, the AML/CTF Act does not require you to keep scanned copies or photocopies of the identity documents themselves. What you must be able to show is the information taken from the document β€” name, date of birth, residential address, expiry date, passport or licence number β€” plus the document type, what you did to verify the customer, and the outcome of your verification and ML/TF risk assessment. Copies you made before 31 March 2026 are a different matter: those are records under the AML/CTF Act and must be kept for the full 7 years.

Transaction records: Records of all transactions β€” including the amount, date, parties involved, and the method of payment. Retained for 7 years from the date of the transaction.

AML/CTF program records: Your written AML/CTF program (including all versions), risk assessments, and independent review reports. Retained for 7 years after the program ceases to have effect.

Reporting records: Copies of all SMRs and TTRs lodged with AUSTRAC. Retained for 7 years from the date of lodgement.

Format requirements

Records can be kept in electronic or paper format. AUSTRAC does not prescribe a specific format, but records must be legible and accessible. Cloud-based compliance software that automatically archives records in a searchable format satisfies AUSTRAC's requirements.

Producing records to AUSTRAC

AUSTRAC can request records at any time β€” during a compliance assessment, investigation, or audit. You must be able to produce records within the timeframe specified in the request, which may be as short as 24 hours in urgent cases.

Privacy Act considerations

The two regimes don't conflict, and neither overrides the other. APP 11.2 requires you to destroy or de-identify personal information once it is no longer needed β€” but it carves out information you are required or authorised by Australian law to retain, which is exactly what the AML/CTF Act's 7-year rule does. So you keep what the AML/CTF Act requires, and you destroy the rest.

The practical consequence is that the 7-year rule is not a licence to keep everything. It protects the records you are required to hold; it does not protect the extra material you collected along the way and no longer need. Retained information can also only be used for AML/CTF compliance purposes β€” not for marketing or other business purposes.

If your turnover is under $3 million, note that becoming a reporting entity brought you under the Privacy Act for this data even though the small business exemption would otherwise apply. See our Privacy Act compliance guide for what that means in practice.

What happens if records are incomplete?

Failure to maintain adequate records is an AML/CTF breach in its own right β€” separate from any underlying compliance failure. AUSTRAC can take enforcement action for record-keeping failures even if the underlying transactions were legitimate.

How CompliDesk handles record keeping

CompliDesk automatically maintains a full audit trail for every client β€” every identity check, screening result, risk assessment, questionnaire answer and compliance decision. The evidence pack can be downloaded as a PDF for any client at any time, producing a complete 7-year-ready compliance record in minutes.

CompliDesk helps all Tranche 2 entities stay compliant.

Whether you're a lawyer, accountant, real estate agent, conveyancer or TCSP β€” CompliDesk guides you through every step of your AUSTRAC obligations. Sign up free today.

Sign up free today

Related reading: What your AML/CTF Program must include Β· SMR and TTR reporting guide Β· Suspicious Matter Reports guide Β· Frequently asked questions