Skip to content
Tranche 2 guide

Record-keeping: seven years of what, exactly

Keep every AML/CTF record for seven years, measured from a per-record anchor. The decision and its reasoning are records too, and must stay retrievable.

By the duely Compliance Team

Record-keeping is the obligation that answers a reviewer’s first question: what did you do, and can you show it? You hold the records for seven years, the count starts from a different point for each record type, and the file has to survive the person who created it.

You became a reporting entity on 1 July 2026: a business the AML/CTF Act 2006 (Cth) captures and holds to its obligations. That happens when you provide a designated service, one of the services the Act lists as captured. For a law practice, Table 6 of the Act covers assisting in a conveyance and creating or restructuring a company or trust. Accountants, conveyancers, real estate agents, dealers in precious metals and stones, and trust and company service providers have their own lists. Enrolment opened on 31 March 2026, and the obligations started on 1 July 2026, so record-keeping is live now, not a coming problem. Whatever your sector, the obligations start producing records from your first customer.

The rule itself is short: records are retained for seven years. Everything else is detail, and the detail is where firms come unstuck.

What you keep, and from when the seven years runs

Start with what counts as a record, because the set is wider than the documents you collected. If you verified a customer’s identity, the driver licence or passport scan is a record, and so is the note of how you verified it, the method you used, and why you accepted it. If you assessed a matter and decided it did not need reporting, the reasoning behind that decision is a record. A reviewer reads the reasoning as closely as the document, because that is where compliance shows.

The retained set falls into four groups. Customer due diligence (CDD), the process of collecting and verifying a customer’s identity before you provide a designated service, produces the largest one. Reports you lodge with AUSTRAC come next: a suspicious matter report (SMR) for a suspicion of money laundering or terrorism financing, and a threshold transaction report (TTR) for cash of $10,000 or more. Program documents and the decisions behind everything make up the rest. Seven years is the term; the anchor is the variable.

Record typeWhat to keepRetention anchor
Customer due diligence (CDD) recordsIdentity information you collected and verified, the verification evidence, and the method path and source referencesSeven years from the date the record was made, or the end of the business relationship, whichever is later
Suspicious matter report (SMR) recordsThe report you lodged, the grounds for the suspicion, and the assessment and reasoningSeven years from the date the report was made
Threshold transaction report (TTR) recordsThe report and the transaction details it rests onSeven years from the date the report was made
Program and compliance recordsThe AML/CTF program, the risk assessment, and records of reviews and approvalsSeven years from the date the version was superseded

The retention obligation sits in ss 107, 108, 111, 114 and 116 of the Act — s 111 for CDD records, s 116 for the records showing your AML/CTF program obligations under Part 1A are met. The seven-year term is settled, and so is the anchor for each group. The form requirements are set out in the Act and the AML/CTF Rules 2025, which were remade in 2025 with new numbering, so an old rule reference no longer points at the provision it used to.

The CDD records are the identity information you collected, the verification evidence, and the method path: which method you used and the source references for the evidence. customer due diligence covers what counts as verified. Here the point is that the evidence and the method have to last the full seven years from the CDD record’s own anchor.

Reports are records too. An SMR is due within three business days of the suspicion forming (s41(2)), and within 24 hours where the suspicion relates to terrorism financing. The report, the grounds behind it, and the assessment and reasoning all have to be retained. suspicious matter reports walks through the clock; here the point is that the file behind the report outlives the lodgement. A TTR is due within ten business days (s43(2)), and its records are the report and the transaction details it rests on. Where privilege kept information out of a report, the documented assessment is the record, and it gets the same seven years and the same care with access.

Program records are the fourth group: your AML/CTF program, the risk assessment it sits on, and records of reviews and approvals. In practice these are what an independent evaluator asks for first.

The form requirement is about retrievability, not format. Records can be kept electronically; what matters is that you can retrieve and produce them for the full seven years. A scanned file in a shared drive satisfies that. A photo on a departing staff member’s phone does not. The test is simple: if the person who knows where a record is left tomorrow, can the firm still find it and produce it? If the answer is no, the record fails the obligation no matter how long it was kept.

What catches people out

Three mistakes cause most of the trouble in practice.

The seven years runs from the record’s own anchor, not from the calendar year. Archive by financial year and the anchor points drift out of alignment with the records. Some files are destroyed while their seven years still run, and a record destroyed early cannot be produced when a reviewer asks for it. The failure to retain is the breach; the later inability to produce is how it shows up.

The decision and its reasoning are records in their own right. Keep the identity documents and discard the notes, and the file shows what you collected but not what you decided. When a reviewer asks how you verified a customer, the note of what you checked and why you accepted the evidence answers more than the scan does. A file that holds only documents cannot demonstrate a decision at all, and that gap is what an examination will surface.

Records have to stay retrievable after the people who set them up leave. A shared drive whose folder permissions sit on one person’s account, a spreadsheet only a departing partner can open, a filing cabinet whose keys are in their desk: all of it stops working on the day that person walks out. The consequence is the same as never keeping the record, because producing it is the point of keeping it.

Access is a separate question for records connected to a report. The fewer people who can see an SMR file, the better. A file note visible to staff who deal with the customer can disclose the report’s existence, and a disclosure that would, or could reasonably be expected to, prejudice an investigation is the tipping-off offence under s123 of the Act. The maximum penalty is two years imprisonment, 120 penalty units, or both, and it does not matter whether an investigation has actually started.

What is still unsettled

The seven-year term is settled, the anchor for each group is settled, and so is the requirement to keep records in a retrievable form. What moves is the rule numbering underneath. The AML/CTF Rules 2025 were remade with new numbering, so a rule number from older guidance no longer points at the provision it used to. When you draft your own procedure, cite the 2025 instrument rather than a rule number lifted from material written before the remake.

Whether AUSTRAC will publish a dedicated record-keeping guidance note is also open. The form and retrievability requirements currently rest on general AUSTRAC guidance.

Where to start

If your firm has not worked through record-keeping yet, three steps cover most of the ground:

  1. Map the record types: list the four groups against what your firm actually produces: identity files, reports, program documents, and the decisions behind them. Assign each group an owner, usually your AML/CTF compliance officer (the AMLCO).
  2. Write the reasoning into the record: agree the capture format now: what was decided, on what evidence, by whom, and when. A template filled in at the time beats a note reconstructed from memory later.
  3. Test retrieval with a departure in mind: pick three records from last quarter and produce them the way a reviewer would, with the person who filed them out of the picture. Fix whatever fails.

How duely handles this

Each matter carries a retention anchor, the date the seven years runs from, so the period is derived from the engagement rather than from a calendar year. The audit log is append-only: entries are added, never edited or removed. Evidence packs are versioned and hashed with SHA-256, which is what makes it possible to show that a pack produced today matches the one produced at the time.

Common questions

How long do I need to keep AML/CTF records in Australia?
Seven years, measured from a per-record anchor point rather than from the calendar year. CDD records, reports you lodged with AUSTRAC, program documents, and the decisions and reasoning behind them each carry their own retention period. The exact anchor for each record type is set out in the Act and the AML/CTF Rules 2025.
Do I need to keep records of my customer due diligence checks?
Yes. CDD records are the core of the obligation. They cover the identity information you collected, the evidence that verified it, and the method you used. Those records must stay retrievable for the full seven years, and the decision you made and why are part of the record, not just the documents.
Can I keep my AML/CTF records electronically?
Yes. Electronic records are accepted; what matters is that you can retrieve and produce them for the full seven years. Storage that stops being accessible when the person who set it up leaves fails that test, so make sure access does not depend on one individual.
What happens if I cannot produce my AML/CTF records?
Failure to retain and produce records is a breach of the record-keeping obligations in ss 107, 108, 111, 114 and 116 of the Act. A record destroyed before its seven years finish cannot be produced when AUSTRAC or your independent evaluator asks for it, and the failure to retain is the breach, not the later inability to produce.
Do record-keeping rules apply to my SMRs and TTRs?
Yes. A suspicious matter report (SMR) is due within three business days of the suspicion forming under s41(2), and a threshold transaction report (TTR) for cash of $10,000 or more within ten business days under s43(2). The reports you lodge, the grounds behind them, and the reasoning are records you retain for seven years.
Who is responsible for record-keeping in my firm?
Practical ownership usually sits with your AML/CTF compliance officer, the AMLCO, but the obligation belongs to the reporting entity, not to an individual. Records have to survive staff changes, so decisions, access and filing all need to work after the person who set them up has left.

This is one obligation of many

Take the 2-minute readiness assessment to see the full set that applies to your firm, or book a walkthrough and watch one matter run from scoping to a finished evidence pack.