
Reporting entities must keep transaction, customer due diligence and AML/CTF program records for seven years, but each clock starts at a different point. Records must be in English or readily convertible into English, and AUSTRAC’s record keeping guidance says you can record the details of identity documents instead of keeping copies. Holding fewer copies also sits better with the Privacy Act.
TL;DR:
- Transaction records must allow full reconstruction of each transaction and be retained for seven years from when the record is made.
- Customer due diligence records are kept until seven years after the business relationship ends or the occasional transaction is completed, not from when they are created.
- Records demonstrating compliance with AML/CTF program duties are kept until seven years after they cease to be relevant, with professional judgement used to decide when that is.
- Records must be in English or easily convertible into English, so plan how you would translate foreign-language documents quickly.
- Electronic storage with proper controls, backups and tamper-evident logs keeps records retrievable when you are asked for them.
Table of Contents
- Statutory foundations: the Act and AUSTRAC guidance you must follow
- Record types and retention clocks: transaction records, CDD records, program records
- What to keep for CDD and transactions: minimum fields and documentary options
- Secure storage and retrievability: technical steps for audit-ready records
- Record-keeping policy and processes: what to include and how to govern retention
- Which legal and client documents to update and the interaction with privacy law
- How an Australian audit-ready workflow works in practice
- A pragmatic view on record-keeping priorities
- How AML Guard supports audit-ready record keeping
- FAQ
- Sources
Statutory foundations: the Act and AUSTRAC guidance you must follow
The record-keeping duties sit in Part 10 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). Three sections matter most for day-to-day compliance: section 107 covers transaction records, section 111 covers customer due diligence records, and section 116 covers records that show compliance with the AML/CTF program duties set out in Part 1A. Each sets its own retention trigger, and section 108 adds a fourth for documents a customer gives you (seven years from when you were given them), so a reporting entity is running several clocks, not one.
AUSTRAC’s record-keeping overview translates these statutory duties into operational terms. It explains that records must be sufficient to reconstruct individual transactions and to demonstrate compliance with AML/CTF obligations more broadly, not just to prove that a customer was identified. That distinction matters when you design your filing systems: a record that only proves identity verification happened is not the same as a record that lets an auditor rebuild the transaction from scratch.
The English-language requirement is straightforward in principle but easy to overlook in practice. Records created in another language are acceptable, provided they are readily convertible into English on request. For a firm dealing with overseas beneficial owners or foreign-language identity documents, that usually means keeping a translation on file or having a documented process for producing one quickly, rather than scrambling to arrange translation when AUSTRAC asks.
These sections, read together with AUSTRAC’s guidance, form the backbone of any record-keeping policy. Everything that follows, which records to keep, how long, and how to store them, flows from this statutory base.

Record types and retention clocks: transaction records, CDD records, program records
Each record type under the Act has its own retention period and its own starting point, and conflating them is an easy mistake to make.
Transaction records, under section 107, must contain enough detail to reconstruct each transaction: the parties, the amounts, the dates and the nature of the transaction. The seven-year clock starts from when the transaction record was made. A conveyancer who completes a property settlement in September 2026 keeps that transaction record until September 2033, regardless of whether the client relationship continues.
CDD records, under section 111, cover identity verification, risk assessments and any analysis or decision made about the customer. Here the clock works differently: retention runs for seven years after the business relationship ends or the occasional transaction is completed, not from when the record was created. A law firm that onboarded a client in July 2026 and still acts for them years later has not started the clock yet; it only starts once the relationship actually ends.
AML/CTF program records, under section 116, cover documents showing compliance with the program duties in Part 1A, including the business-wide risk assessment, policies and evidence of reviews. These are kept for seven years after they stop being relevant to demonstrating compliance. Working out that point takes professional judgement: a superseded risk assessment is often still relevant for years afterwards, because it evidences what the firm understood and decided at the time. Keeping version history, approval dates and reviewer notes is the practical way to support that judgement if AUSTRAC ever asks why a record was or was not retained.
A real estate agency, for example, might finish a sale in November 2026 (transaction records to November 2033) and replace its first risk assessment with a revised version in 2027 (the program record clock starts only when the old version stops being relevant, which may be well after 2027). Its CDD records for that sale run until seven years after the business relationship ends or the occasional transaction is completed.
What to keep for CDD and transactions: minimum fields and documentary options
AUSTRAC’s guidance focuses on sufficiency: transaction records must let you reconstruct the transaction, and CDD records must show what you collected, how you verified it and why you applied the level of CDD you did. For customer due diligence, that generally means capturing:
- Customer identifiers: full name, date of birth, address and any identification numbers used in verification.
- Verification steps taken: which documents or data sources were checked, and the outcome.
- Who conducted the check and when, including the compliance officer or staff member responsible.
- The customer’s risk rating and the reasoning behind it, including any enhanced due diligence triggers.
- Beneficial ownership findings, including how ownership or control was determined and any third-party reliance relied upon under sections 37A or 38.
Transaction records should typically include the transaction date, the amount, the parties involved, the payment method and any supporting documents such as contracts or settlement statements. The goal is reconstruction: a reviewer with no other context should be able to follow the paper trail from instruction to completion.
A frequent question is whether you need to keep the actual identity document, a passport scan or a driver’s licence copy, on file. AUSTRAC does not require this. You can record the document’s details (type, number, issuing authority, expiry) along with who verified it and when, rather than retaining a copy of the document itself. This also helps with Privacy Act obligations, since holding fewer original documents reduces the personal information you are accountable for. Details on which documents are acceptable to check, and how to record them, are covered in our guide to acceptable ID documents.
Secure storage and retrievability: technical steps for audit-ready records
AUSTRAC’s record keeping checklist asks you to store records so they are easily retrievable: can you produce the record promptly if asked? AUSTRAC expects records kept in their original format, whether paper or electronic, and electronic storage with proper backups is the more resilient option for most firms.
The checklist’s controls include access limits so only authorised staff can view sensitive records, encryption or password protection for electronic records, regular backups to a secure offsite location or encrypted cloud storage, and a data recovery plan. Tamper-evident audit trails, where every access or edit is timestamped and logged, give you a defensible answer when asked whether a record has been altered since creation.
The practical test is simple: if AUSTRAC requested a specific customer’s CDD file or a transaction record from three years ago, could your team locate, retrieve and translate it (if needed) within a short timeframe? If the honest answer is no, your storage system needs work before your retention policy does.
Record-keeping policy and processes: what to include and how to govern retention
A written policy turns the statutory duties into something your team can actually follow. At minimum, it should set out:
- Scope: which records are covered (transaction, CDD, program) and which systems hold them.
- Retention rules: the seven-year period for each record type and its specific trigger event.
- Responsibilities: who is accountable for filing, archiving and eventually disposing of records.
- Security and access: who can view, edit or export records, and how that access is logged.
- Review and independent evaluation: how often the policy itself is checked against current obligations.
Operationally, this means consistent file naming, version history on program documents, a defined archival process once records age out of active use, and secure disposal once the retention period genuinely expires, consistent with the Privacy Act’s requirement to destroy or de-identify personal information you no longer need. Staff training on these processes, and records of who completed it and when, should themselves be retained as evidence of your Part 1A compliance.
Pro Tip: Review your record-keeping policy every time your AML/CTF program is updated, not on a separate schedule, so the two never drift apart.
Which legal and client documents to update and the interaction with privacy law
Record-keeping obligations rarely sit in isolation. They usually require updates to client-facing and internal documents: engagement letters, privacy policies, collection notices, onboarding or KYC forms, and staff contracts that reference confidentiality and data handling.
Collection notices and privacy policies should state plainly how long records are kept, why, and whether any third party relied on for CDD (under sections 37A or 38) will also hold a copy. Vague language (“as required by law”) is technically true but unhelpful if a customer asks a direct question.
The Privacy Act works alongside the AML/CTF Act, not against it: you are required to retain what the Act demands, but no more, and to destroy or de-identify personal information once it is no longer reasonably necessary. Collecting everything “just in case” is not a safer position; it is a separate compliance risk.
How an Australian audit-ready workflow works in practice
A practical implementation links the program documents (the risk assessment and AML/CTF policies the Act requires, plus a compliance action plan and training manual), so updates to one are reflected across the set, with version history showing what changed and when. Automation can help at specific points: capturing identity and document details at onboarding, running sanctions and PEP screening with ongoing re-screening, and resolving beneficial ownership against a company’s ACN. An officer still approves each determination before CDD proceeds; automation assists the process, but retention itself remains governed by the Act.
A pragmatic view on record-keeping priorities
Retrievability beats volume. A small team with a simple, consistently applied policy and an automated audit trail will outperform a larger file of records nobody can locate on request. Get help or an independent evaluation once your program documents or client base outgrow manual tracking.
How AML Guard supports audit-ready record keeping
We built our platform around the record-keeping duties set out above, not as an afterthought. Guided wizards produce your business-wide risk assessment, policies, compliance action plan and training manual as one linked set, so a reviewer sees consistent reasoning across every document. Identity verification, sanctions and PEP screening, and ACN-based beneficial ownership checks start from our secure client intake workflow, with an officer approving each determination before CDD proceeds.
Records sit in an 8-year tamper-evident audit trail, above the Act’s seven-year minimum. If you want to see how this works for your firm, book a demo or check current plans on our pricing page.
FAQ
How long should AML records be kept?
Under the AML/CTF Act, the retention period is seven years for every record type, but the starting point differs: transaction records run seven years from when the record was made, documents a customer gives you seven years from when you were given them, CDD records until seven years after the business relationship ends or the occasional transaction is completed, and program records until seven years after they stop being relevant.
What are the new AML rules in Australia?
Tranche 2 obligations extend AML/CTF duties to real estate, legal, accounting, and trust and company service providers, bringing them into the same reporting entity framework as banks and financial institutions. The AML/CTF Rules set out the documentation and program requirements that sit alongside the Act’s record-keeping sections.
What are the AUSTRAC record-keeping requirements?
The Act requires reporting entities to keep transaction, CDD and program records that are sufficient to reconstruct transactions and demonstrate compliance, in English or a form readily convertible into English. AUSTRAC’s record keeping checklist sets out practical storage, security and backup controls that support this.
How long do I retain AML CTF records?
Every record type under the Act is retained for seven years, counted from a different trigger: the day the record is made for transaction records, the end of the business relationship (or completion of the occasional transaction) for CDD records, and loss of relevance for program records. Treating all records as subject to a single fixed date is a common and avoidable error.
Sources
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), Part 10
- Record keeping checklist | AUSTRAC
- Record keeping overview | AUSTRAC
Recommended
- Tranche 2 AML Australia: your compliance obligations explained
- AML/CTF Program Documents for Tranche 2
- AML risk assessment template for Tranche 2 firms
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.