Record-keeping is the obligation that answers a reviewer’s first question: what did you do, and can you show it? You hold the records for seven years, the count starts from a different point for each record type, and the file has to survive the person who created it.
You became a reporting entity on 1 July 2026: a business the AML/CTF Act 2006 (Cth) captures and holds to its obligations. That happens when you provide a designated service, one of the services the Act lists as captured. For a law practice, Table 6 of the Act covers assisting in a conveyance and creating or restructuring a company or trust. Accountants, conveyancers, real estate agents, dealers in precious metals and stones, and trust and company service providers have their own lists. Enrolment opened on 31 March 2026, and the obligations started on 1 July 2026, so record-keeping is live now, not a coming problem. Whatever your sector, the obligations start producing records from your first customer.
The rule itself is short: records are retained for seven years. Everything else is detail, and the detail is where firms come unstuck.
What you keep, and from when the seven years runs
Start with what counts as a record, because the set is wider than the documents you collected. If you verified a customer’s identity, the driver licence or passport scan is a record, and so is the note of how you verified it, the method you used, and why you accepted it. If you assessed a matter and decided it did not need reporting, the reasoning behind that decision is a record. A reviewer reads the reasoning as closely as the document, because that is where compliance shows.
The retained set falls into four groups. Customer due diligence (CDD), the process of collecting and verifying a customer’s identity before you provide a designated service, produces the largest one. Reports you lodge with AUSTRAC come next: a suspicious matter report (SMR) for a suspicion of money laundering or terrorism financing, and a threshold transaction report (TTR) for cash of $10,000 or more. Program documents and the decisions behind everything make up the rest. Seven years is the term; the anchor is the variable.
| Record type | What to keep | Retention anchor |
|---|---|---|
| Customer due diligence (CDD) records | Identity information you collected and verified, the verification evidence, and the method path and source references | Seven years from the date the record was made, or the end of the business relationship, whichever is later |
| Suspicious matter report (SMR) records | The report you lodged, the grounds for the suspicion, and the assessment and reasoning | Seven years from the date the report was made |
| Threshold transaction report (TTR) records | The report and the transaction details it rests on | Seven years from the date the report was made |
| Program and compliance records | The AML/CTF program, the risk assessment, and records of reviews and approvals | Seven years from the date the version was superseded |
The retention obligation sits in ss 107, 108, 111, 114 and 116 of the Act — s 111 for CDD records, s 116 for the records showing your AML/CTF program obligations under Part 1A are met. The seven-year term is settled, and so is the anchor for each group. The form requirements are set out in the Act and the AML/CTF Rules 2025, which were remade in 2025 with new numbering, so an old rule reference no longer points at the provision it used to.
The CDD records are the identity information you collected, the verification evidence, and the method path: which method you used and the source references for the evidence. customer due diligence covers what counts as verified. Here the point is that the evidence and the method have to last the full seven years from the CDD record’s own anchor.
Reports are records too. An SMR is due within three business days of the suspicion forming (s41(2)), and within 24 hours where the suspicion relates to terrorism financing. The report, the grounds behind it, and the assessment and reasoning all have to be retained. suspicious matter reports walks through the clock; here the point is that the file behind the report outlives the lodgement. A TTR is due within ten business days (s43(2)), and its records are the report and the transaction details it rests on. Where privilege kept information out of a report, the documented assessment is the record, and it gets the same seven years and the same care with access.
Program records are the fourth group: your AML/CTF program, the risk assessment it sits on, and records of reviews and approvals. In practice these are what an independent evaluator asks for first.
The form requirement is about retrievability, not format. Records can be kept electronically; what matters is that you can retrieve and produce them for the full seven years. A scanned file in a shared drive satisfies that. A photo on a departing staff member’s phone does not. The test is simple: if the person who knows where a record is left tomorrow, can the firm still find it and produce it? If the answer is no, the record fails the obligation no matter how long it was kept.
What catches people out
Three mistakes cause most of the trouble in practice.
The seven years runs from the record’s own anchor, not from the calendar year. Archive by financial year and the anchor points drift out of alignment with the records. Some files are destroyed while their seven years still run, and a record destroyed early cannot be produced when a reviewer asks for it. The failure to retain is the breach; the later inability to produce is how it shows up.
The decision and its reasoning are records in their own right. Keep the identity documents and discard the notes, and the file shows what you collected but not what you decided. When a reviewer asks how you verified a customer, the note of what you checked and why you accepted the evidence answers more than the scan does. A file that holds only documents cannot demonstrate a decision at all, and that gap is what an examination will surface.
Records have to stay retrievable after the people who set them up leave. A shared drive whose folder permissions sit on one person’s account, a spreadsheet only a departing partner can open, a filing cabinet whose keys are in their desk: all of it stops working on the day that person walks out. The consequence is the same as never keeping the record, because producing it is the point of keeping it.
Access is a separate question for records connected to a report. The fewer people who can see an SMR file, the better. A file note visible to staff who deal with the customer can disclose the report’s existence, and a disclosure that would, or could reasonably be expected to, prejudice an investigation is the tipping-off offence under s123 of the Act. The maximum penalty is two years imprisonment, 120 penalty units, or both, and it does not matter whether an investigation has actually started.
What is still unsettled
The seven-year term is settled, the anchor for each group is settled, and so is the requirement to keep records in a retrievable form. What moves is the rule numbering underneath. The AML/CTF Rules 2025 were remade with new numbering, so a rule number from older guidance no longer points at the provision it used to. When you draft your own procedure, cite the 2025 instrument rather than a rule number lifted from material written before the remake.
Whether AUSTRAC will publish a dedicated record-keeping guidance note is also open. The form and retrievability requirements currently rest on general AUSTRAC guidance.
Where to start
If your firm has not worked through record-keeping yet, three steps cover most of the ground:
- Map the record types: list the four groups against what your firm actually produces: identity files, reports, program documents, and the decisions behind them. Assign each group an owner, usually your AML/CTF compliance officer (the AMLCO).
- Write the reasoning into the record: agree the capture format now: what was decided, on what evidence, by whom, and when. A template filled in at the time beats a note reconstructed from memory later.
- Test retrieval with a departure in mind: pick three records from last quarter and produce them the way a reviewer would, with the person who filed them out of the picture. Fix whatever fails.
How duely handles this
Each matter carries a retention anchor, the date the seven years runs from, so the period is derived from the engagement rather than from a calendar year. The audit log is append-only: entries are added, never edited or removed. Evidence packs are versioned and hashed with SHA-256, which is what makes it possible to show that a pack produced today matches the one produced at the time.