
When client files sit in Microsoft 365, the AML/CTF Act still sets the rules: transaction records for 7 years, customer due diligence records for 7 years after the relationship ends, and program records for 7 years after they stop being relevant. Meeting those obligations means the records must be complete, secure and retrievable on request. Microsoft 365 is a storage location, not a compliance outcome, so confirm the actual configuration with your IT provider and keep a written record of what was checked.
TL;DR:
- Records in Microsoft 365 must be complete, secure, and retrievable; storage location alone does not fulfil compliance obligations.
- Transaction records are retained for 7 years from the creation date, while customer due diligence records end 7 years after the relationship closes.
- Record-keeping policies should document record classes, responsible roles, backup procedures, and access restrictions, with confirmation from IT providers.
- The Privacy Act pulls the other way: keep personal information only while the Act or another legitimate purpose needs it, and schedule deletion or de-identification for the rest.
Table of Contents
- What records the Act expects you to keep
- When the 7-year clocks start and stop
- Designing retention in Microsoft 365: what to document
- Privacy Act minimisation pulls the other way
- Six steps to check with IT and governance this quarter
- What a reviewer will test
- How AML Guard supports your record-keeping evidence
- FAQ
- Sources
What records the Act expects you to keep
The AML/CTF Act’s Part 10 record-keeping obligations cover several categories of material, and each one tends to map onto a different folder or system in Microsoft 365. Getting the mapping right starts with knowing what AUSTRAC actually expects a reporting entity to produce on request.
AUSTRAC’s record-keeping overview describes the baseline: records must be full and accurate, kept for a specific period, usually 7 years, and stored so they can be produced easily for review. For a Tranche 2 entity, that generally breaks down into:
- Transaction records: date, time, amount, currency or property details, and the parties to the transaction.
- Customer-provided documents: contracts, invoices, receipts and other paperwork a client hands over in connection with a transaction.
- Customer due diligence records: the information and verification results gathered to identify a customer and any beneficial owners.
- Program records: the risk assessment, policies, procedures and training material that make up the AML/CTF program itself.
One distinction catches firms out: AUSTRAC’s guidance on initial customer due diligence confirms you are not required to keep copies of identity documents. Recording the relevant details, document type, number, issuer, expiry, is enough. That matters for a Microsoft 365 deployment, because it means a firm does not need to hoard scanned passports and licences indefinitely; it needs to keep an accurate record of what was sighted and verified.
When the 7-year clocks start and stop
Each record category runs on its own retention trigger, and getting the start date wrong is one of the more common design mistakes.
- Transaction records run for 7 years from the day the record was made, under section 107 of the Act. The clock starts at creation, not at the end of a file or matter.
- Customer-provided transaction documents, such as contracts or settlement paperwork, run for 7 years from the day you were given the document under section 108.
- CDD records run for 7 years from when the business relationship ends, or when an occasional transaction is completed, under section 111. For an ongoing client, that date is often months or years after the records were first created.
- Program records, the risk assessment, policies and training material, run for 7 years from when they stop being relevant under section 116. AUSTRAC leaves that point to your professional judgement, and a superseded version can stay relevant for some time, so record the date you chose and why.
Designing retention in Microsoft 365: what to document
AUSTRAC’s record keeping checklist asks for a documented policy, not just a folder structure. A defensible design, whether built around Microsoft 365 or another system, should set out:
- Record classes and formats: which categories exist (transaction, CDD, program) and what format they are stored in.
- Systems of record: which platform holds each class, and how it is backed up.
- Accountable role: who is responsible for each class and for responding to a retrieval request.
- Protection and production procedures: how access is restricted, and how a complete record set would be produced for AUSTRAC.
Integrity matters as much as storage. The checklist points to secure storage, restricted access for sensitive records, regular backups and a data recovery plan; test the plan rather than assume it works. In operational terms, that means controlled write access, an audit trail of who touched a record and when, and backed-up copies held somewhere other than the primary working folder. None of that is a Microsoft 365 setting you can simply assume is switched on; retention policies, deletion rules and access controls all need to be configured deliberately and confirmed, not inherited by default.
Pro Tip: Ask your IT provider for written confirmation of the retention and access settings applied to each record class, and keep that confirmation as audit evidence rather than relying on a verbal assurance.
Retrievability is the practical test. AUSTRAC’s checklist asks you to store records so they are easily retrievable, and a record that exists somewhere in a tenant but cannot be produced promptly and completely does not do its job. Lead with demonstrated backup, recovery and access logs, not a description of where the files happen to sit.

Privacy Act minimisation pulls the other way
The AML/CTF Act sets a floor: keep these records for these periods. The Privacy Act sets a ceiling of its own, in the opposite direction: do not keep personal information longer than you actually need it. Those two obligations sit side by side, and a retention policy has to satisfy both.
A workable framework is simple. Keep what the statutory periods require, and nothing extra by default. Limit the sensitive fields you retain, particularly where AUSTRAC guidance already tells you that recording details is enough and a document copy is not required. Where you do hold additional personal information beyond the statutory minimum, write down why, and set a deletion or de-identification date rather than leaving it indefinitely. Firms should confirm these choices with their privacy adviser and keep the rationale on file, since a Privacy Act complaint and an AUSTRAC review ask different questions of the same record.
Six steps to check with IT and governance this quarter
A short, repeatable checklist turns the obligations above into something an officer can actually run.
- Map record classes to storage locations and file formats, and write the mapping down.
- Assign an accountable role for each class and its applicable retention period.
- Confirm backup, recovery and tamper evidence with IT, and keep that confirmation on file.
- Restrict and log access to sensitive CDD and transaction records.
- Test retrieval by simulating a regulatory request for a specific file, and record how long it took and what was produced.
- Document privacy minimisation decisions and any scheduled deletion or de-identification dates.
Pro Tip: Run the retrieval test on a record that is at least two years old, not a recent file; that is the scenario most likely to expose a gap in backups or access history.
What a reviewer will test
A reviewer is unlikely to stop at where files are stored. Expect to be asked whether you can retrieve a complete, accurate record on demand, explain who could access it, and show that it has not been altered without a trace. That is a governance question before it is a technology question.
The strongest position is documented decisions: a written policy that names record classes and accountable roles, a signed confirmation from IT about actual settings, and a log of a retrieval test that worked. Consistency between the risk assessment, the policies and the training material matters as much as any individual control. Operational proof beats a well-written policy statement every time.
How AML Guard supports your record-keeping evidence
Building the governance evidence described above from scratch, program artefacts, accountable roles, retrieval tests, takes real time, and AML Guard is built to shorten that work for Tranche 2 reporting entities. Guided wizards produce the business-wide risk assessment, AML/CTF policies, compliance action plan and staff training manual as one linked set, so the artefacts match each other.
Customer due diligence runs end to end, from identity verification through sanctions, PEP and adverse media screening, with every CDD record sitting in an 8-year tamper-evident audit trail, above the Act’s seven-year minimum. A governance dashboard tracks compliance status, and REX CRM integration pushes compliance status without exposing underlying CDD data. If your firm wants a platform built around these obligations rather than a folder structure assembled by hand, book a demo or view plans and pricing.

FAQ
How long must transaction records be kept under the AML/CTF Act?
Transaction records must be kept for 7 years from the day the record was made, under section 107 of the AML/CTF Act. The clock starts at creation, not at the end of the matter or file.
Do I need to keep copies of identity documents?
No. AUSTRAC’s customer due diligence guidance confirms you can record the details of an identity document, such as its type, number and expiry, rather than keeping a copy.
Does storing records in Microsoft 365 satisfy the AML/CTF Act?
Storage location alone does not satisfy the obligation. Records must still be complete, secure and retrievable on request, so confirm the actual retention, deletion and access settings with your IT provider and document that confirmation.
How does the Privacy Act affect how long I keep CDD records?
The AML/CTF Act sets a 7 year minimum for CDD records after the business relationship ends, under section 111. The Privacy Act then limits keeping personal information beyond that statutory need, so firms should schedule deletion or de-identification once the retention period and any legitimate business purpose have passed.
How long does AML Guard retain CDD records?
AML Guard holds CDD records in an 8-year tamper-evident audit trail, which sits above the Act’s 7-year statutory minimum.
Sources
- Record keeping overview | AUSTRAC
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Record keeping checklist | AUSTRAC
Recommended
- Tranche 2 AML Australia: your compliance obligations explained
- Acceptable ID documents for Tranche 2 firms
- AML risk assessment template for Tranche 2 firms
- AML/CTF Program Documents for Tranche 2
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.