AML training records: what to keep, how long

AML training records: what to keep, how long

What an AML/CTF training record should show, how it links to personnel due diligence, and why the Act keeps it seven years after it stops being relevant.

AML/CTF Compliance 2 October 2026 10 min read AML Guard

Manager reviewing AML training records

Australian reporting entities need AML/CTF training records that show who was trained, on which module, when, and with what result, alongside personnel due diligence records for the same people. Under section 116, records demonstrating compliance with Part 1A of the AML/CTF Act must be retained for 7 years after they stop being relevant.


TL;DR:


AML Guard
Keep AML Training Records Connected
AML Guard links staff training, policies and risk assessments, with multilingual training records and an 8-year tamper-evident audit trail.
Book an AML Guard demo

Table of Contents

What records reporting entities must keep under the AML/CTF Act

Section 116 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) requires a reporting entity to keep records that are reasonably necessary to demonstrate compliance with its Part 1A program obligations. AUSTRAC’s record-keeping overview groups these into several practical categories, each serving a different purpose when a supervisor or internal auditor comes looking.

The business-wide ML/TF risk assessment and the AML/CTF policies sit at the top: they establish what the entity decided its risks were and how it chose to manage them. Customer due diligence files sit underneath, showing identity verification, screening outcomes and ongoing monitoring for each customer. Transaction records capture the activity itself, and records of any threshold transaction or suspicious matter reports sit beside them. Personnel due diligence and training records complete the set, evidencing that the people running the program were suitable for their roles and equipped to apply it.

Each category answers a different audit question:

These categories are connected rather than separate filing exercises. A risk assessment that flags a high-risk service line means little if the personnel handling that service line cannot show training tailored to it, and a training register means little if it cannot be tied back to the roles the risk assessment identified as sensitive. The AML/CTF Rules 2025 set out the training and personnel due diligence requirements (sections 5-8 and 5-9) that these records are meant to prove were followed. Reporting entities building or refreshing their program documents can see how the risk assessment, policies and training manual are meant to work as one linked set in our guide to AML/CTF program documents for Tranche 2.

What a defensible training record must show

A training record that survives scrutiny is not a sign-in sheet. AUSTRAC’s AML/CTF training guidance gives examples of what to record: who completed the training, what was delivered (topics, format, content and content version), how understanding was assessed and the results, and each person’s training history. That goes well beyond a name and a date.

At minimum, a defensible record should capture:

  1. The staff member’s name and role, so the record can be matched to a position with defined AML/CTF responsibilities.
  2. The module name and its version or content identifier, so the entity can show exactly what was taught at that point in time.
  3. The delivery method, whether e-learning, an in-person session or a hybrid format.
  4. The date the training was completed.
  5. The assessment type used and the result achieved, not merely attendance.
  6. The name of the person who approved or signed off the completion, and the date of that approval.
  7. The next refresher trigger and the reasoning behind it, whether that is a calendar date, a role change or a material update to the program.

Linking each entry to the specific content version matters more than it might seem. If the training manual is updated after a regulatory change, a record that simply says “AML training completed” gives no way to tell whether the staff member learned the old approach or the new one. Tying the record to a version number or content identifier closes that gap.

AUSTRAC also expects you to monitor whether training works, for example through post-training assessment of understanding. A signed attendance sheet on its own does not show whether the person understood the material or could apply it to their role; an assessment result tied to a specific module version, and a sign-off, do.

Pro Tip: Treat every training record as evidence you might need to produce on short notice, not as a filing exercise you complete and forget.

Organising, storing and retaining training records

The retention rule is not complicated, but it is easy to get wrong in practice. Part 1A records, which include training and personnel due diligence records, must be kept for 7 years after they stop being relevant under section 116 of the Act. The harder question is deciding when a record stops being relevant. For an ongoing staff member, one reasonable point is the end of their engagement with the entity. For training tied to a specific matter or project, it may be the closure of that matter. AUSTRAC’s record-keeping overview leaves this judgement to the entity, so documenting the reasoning behind a chosen retention start date is itself part of a defensible file.

Training record retention lifecycle illustration

7 years after a record stops being relevant is the period section 116 of the Act sets for Part 1A records, and it applies to training and personnel due diligence files as much as to the risk assessment and policies. CDD and transaction records run on their own clocks (sections 111 and 107).

On the technical side, a defensible register typically relies on:

Operationally, someone needs to own the register, chase overdue training, and flag missed sessions for escalation before they become a gap an auditor finds first. Linking the training calendar to HR onboarding and offboarding dates helps close the loop, since a departing staff member’s training file is exactly the kind of record that needs a clear “ceased to be relevant” date recorded against it.

Linking training records to personnel due diligence and role risk

Training and personnel due diligence are not separate obligations sitting side by side. AML/CTF policies must deal with training for people whose functions are relevant to the Act and with due diligence on those same people, as set out in section 26F(4)(d) and (e). AUSTRAC’s guidance covers personnel due diligence and training together, starting from the roles that need both, so a training record without a matching personnel due diligence file tells only half the story.

A workable mapping documents, for each relevant role:

A staff member handling high-risk customer onboarding, for instance, would sit against a more rigorous assessment standard and a shorter refresher cycle than someone in a support role with no direct customer contact, and the mapping should make that difference visible rather than leaving it implied.

A practical checklist and template for training records

A short checklist keeps a training register consistent across staff and locations:

  1. Confirm the role has been assessed as relevant to the Act before assigning training.
  2. Record the module name, version and delivery method for every completion.
  3. Capture the assessment result, not just attendance.
  4. Record an approver’s name and sign-off date for every entry.
  5. Set and document the next refresher trigger and the reasoning behind it.
  6. Store the record with a timestamp that cannot be altered after entry.

A simple register can use these column headings: staff name, role, module name and version, delivery method, completion date, assessment result, approver, refresher trigger, and retention start date. Each column should hold an actual value rather than a placeholder; an empty assessment result column is itself a gap worth closing before an auditor asks about it.

For guidance on what the training content itself should cover, see our AML training manual guide, which sets out module structure separately from the record-keeping obligations covered here.

How a compliance platform can produce audit-ready training records

Some firms build this register manually in a spreadsheet; others use a platform. AML Guard, for example, runs multilingual training modules and keeps completion records in its 8-year tamper-evident audit trail, above the Act’s seven-year minimum.

Consistency between the risk assessment, the policies and the training manual is easy for a reviewer to test, and that consistency is easier to maintain when the three documents come from the same underlying data.

Because the training manual, policies and risk assessment are generated from the same set of answers, the manual stays consistent with the policies, and each completion record sits in the same audit trail. That reduces the manual reconciliation work involved in proving who completed which training, and when.

Where audits actually go wrong

A common weakness is not missing training. It is training that cannot be tied to a role’s risk level, or evidence that shows attendance without showing understanding. Prioritise records that are timestamped, version-matched and instantly retrievable. Where evidence is thin, fix the weakest role-risk pairings first, not the easiest ones.

Turning training records into an audit-ready system

Building and maintaining this register by hand is achievable for a small team, but it becomes harder to sustain as staff numbers grow, roles change, and training content gets updated to reflect new guidance. AML Guard produces the training manual, AML/CTF policies and the business-wide risk assessment as one linked set, so the manual matches the policies and risk assessment it was built from.

AML Guard runs multilingual training modules with completion records held in its 8-year tamper-evident audit trail, so a compliance officer responding to an AUSTRAC request can find a staff member’s training history without searching through separate files. Features relevant to record keeping include:

If your current register relies on spreadsheets and sign-in sheets, book a demo to see how the platform handles training records, or check pricing for the plan that suits your team.

Sources

FAQ

How long do I retain AML/CTF training records?

Training records are Part 1A records, and under section 116 they must be kept for 7 years after they stop being relevant. AUSTRAC leaves that point to your judgement; for an ongoing staff member, the end of their engagement is one reasonable choice.

What are the current AML/CTF rules in Australia?

The governing framework is the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) together with the AML/CTF Rules 2025, which set out program, personnel due diligence and training obligations for reporting entities. Tranche 2 obligations for real estate, legal, accounting, and trust and company service providers are now in force.

Is there free online AML/CTF training available in Australia?

AUSTRAC provides e-learning modules as educational material, but these are supplementary and do not replace training tailored to a reporting entity’s own risks and roles. A reporting entity still needs its own program-specific training and a record showing staff completed it.

How often must AML/CTF training be refreshed?

There is no fixed refresher interval in the Act or the Rules. The Rules require initial training and ongoing training appropriate to each person’s function and the risks relevant to it, and AUSTRAC says the frequency depends on those functions and risks. Record why you chose the interval.

What does AML Guard record for staff training?

AML Guard runs multilingual training modules and stores completion records in its 8-year tamper-evident audit trail, above the Act’s seven-year minimum.

See How AML Guard Works

Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.

Book a Demo
This article is for general information purposes only and does not constitute legal advice. Firms should obtain independent professional advice on their specific AML/CTF obligations.
Last reviewed: 2 October 2026.