Skip to main content
CCassandra AML
Scope checkGuidesPricingSecurityAboutSign inStart free
Menu
Scope checkGuidesPricingSecurityAboutSign inStart free
Guides/Core obligations

Obligations

AML/CTF record keeping and Australia's seven-year rules

6 min read · Updated 1 August 2026

Seven years is a headline, not a complete AML/CTF retention rule. The start date differs by record type: a CDD record can run from the end of a business relationship or completion of an occasional transaction, a transaction record from creation, and a program record can remain relevant for years before its seven-year period begins. A reporting entity therefore needs a retention schedule driven by events and relationships, not one deletion date attached to every file. It must also keep records complete, accurate, secure and retrievable in English or readily accessible in a form that can be translated. This guide provides an operational framework; other laws, investigations, legal holds and professional duties may require longer retention, so deletion must be governed rather than automatic.

On this page

  1. Step-by-step process
  2. Classify the record before calculating time
  3. Use the correct seven-year trigger
  4. Preserve quality, accessibility and confidentiality
  5. Coordinate deletion, holds and system change
  6. Build an event-based retention schedule
  7. Official sources
  8. Frequently asked questions

Step-by-step process

  1. Inventory records

    Locate AML evidence across customer, transaction, program, reporting and governance systems.

  2. Assign the clock

    Classify each record and capture the correct statutory trigger and minimum period.

  3. Secure and test

    Protect integrity and confidentiality, then test complete and prompt retrieval.

  4. Hold or dispose

    Check other legal needs, approve extensions or secure disposal, and retain evidence of action.

Classify the record before calculating time

AUSTRAC's overview distinguishes customer due diligence records, transaction records, customer-provided transaction documents and AML/CTF program records. CDD evidence includes information used to identify and verify customers, representatives, beneficial owners and relevant risk or ongoing-review decisions. Transaction records capture the nature and parties sufficiently to reconstruct the activity. Program records include risk assessments, policies, versions, approvals, reviews and evidence showing compliance with Part 1A.

Do not classify only by storage location. A document in a customer folder may evidence both CDD and a transaction, while a screening result can support identification, ongoing CDD and an escalation decision. Build a data inventory that names the business owner, system, record class, trigger event, minimum period, access restrictions and disposal authority. Preserve links between records so an investigator can understand the decision without reconstructing it from unrelated systems.

Use the correct seven-year trigger

AUSTRAC states that CDD records are generally kept for seven years after an occasional transaction is completed or after the business relationship ends. General transaction records are kept for seven years from the day they are created, and transaction documents supplied by a customer are kept for seven years from the day they are provided. Those different clocks matter in a relationship lasting many years: onboarding evidence cannot simply be deleted seven years after collection while it remains part of the current relationship record.

Program records are retained from creation until seven years after the record ceases to be relevant for demonstrating compliance with the AML/CTF program requirement. Superseding a policy does not necessarily make it irrelevant immediately; the old version may explain the controls that applied to a historic customer or report. Record an end-of-relevance decision with reasons, then calculate disposal. Confirm any additional categories and detailed timing against the current Act and Rules rather than treating this summary as exhaustive.

Preserve quality, accessibility and confidentiality

Records must be sufficient to demonstrate what occurred and what the business decided. Capture source, date, version, reviewer, result and any exception. A screenshot without a timestamp or search parameters may be weak evidence; a risk rating without the factors and approval cannot explain the judgement. Where a provider or registry supplies data, preserve enough information to reproduce or understand the result within legal and licensing constraints.

Store records so authorised people can locate them promptly and produce them in English or in a readily accessible and translatable form. Apply least-privilege access, encryption where appropriate, audit logs, resilient backups and controls against alteration. SMR-related material and information that could reveal a report require particularly careful segregation because tipping-off restrictions may apply. Outsourced storage does not transfer the reporting entity's obligation to retain and retrieve evidence.

Coordinate deletion, holds and system change

At the end of the minimum AML period, check for other retention duties, litigation or regulatory holds, active investigations, complaints, insurance needs and professional standards. A seven-year minimum is not an instruction to delete where another lawful reason requires preservation. Conversely, indefinite retention increases privacy, security and discovery risk. Document the lawful basis, review extended holds and dispose securely when all needs have ended.

System migrations are a common failure point. Before decommissioning a CRM, practice platform or screening service, reconcile record counts, metadata, attachments, audit history and relationship end dates. Test retrieval from the archive and preserve vendor certificates or migration logs. Contract terms should address export formats, deletion, subcontractors, data location, breach notification and access after termination. Sampling should include closed customers and superseded program versions, not only current files.

Build an event-based retention schedule

Governance reporting should show records without a valid trigger date, overdue archive actions, failed retrieval tests, unauthorised access and vendor issues. A retention schedule becomes effective only when systems can execute it. If automation is not yet reliable, apply a controlled manual process and prevent premature deletion until the gap is remediated.

  • Inventory CDD, transaction, customer-supplied, program, governance, training, screening and reporting records across every system.
  • Map each class to the current statutory rule, trigger event, minimum period and any other applicable retention duty.
  • Capture relationship end and occasional-transaction completion dates as controlled data rather than free-text notes.
  • Apply security, audit, language and retrieval standards according to sensitivity, including strict protection for SMR information.
  • Create legal-hold and regulator-request processes that suspend disposal without silently extending every record forever.
  • Approve and evidence disposal, then test that linked records and backups follow the authorised outcome.

Official sources

Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.

  • AUSTRAC - Record-keeping overview
  • Federal Register - AML/CTF Act 2006
  • Federal Register - AML/CTF Rules 2025

Frequently asked questions

Can CDD documents be deleted seven years after onboarding?

Not merely because seven years have passed since collection. AUSTRAC ties the CDD period to completion of an occasional transaction or the end of the business relationship. Current relationships, ongoing relevance, other laws and holds must be considered before an authorised disposal decision.

When does the period for a superseded AML policy begin?

Program records are kept until seven years after they cease to be relevant to demonstrating compliance. A superseded policy can remain relevant to historic decisions and transactions. Document when and why relevance ends, preserve linked evidence, and then apply the period required by current law.

May AML records be stored outside Australia or by a cloud provider?

The reporting entity must still meet accessibility, security, integrity, language and production requirements and comply with any other applicable data law. Assess vendor, location, subcontracting, export and termination risks. Ensure records can be produced promptly even if the contract ends.

Should everything be deleted as soon as the AML period ends?

No automatic rule fits every record. Check other statutory, professional, contractual, investigation and legal-hold requirements. Where no lawful or necessary basis remains, secure disposal supports privacy and security. Record the decision and ensure archives and backups are handled consistently.

Put it into practice

Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.

Run the free scope checkCreate a free workspace

Keep reading

Obligations

Your AML/CTF program

Read
Obligations

SMRs & tipping off

Read
Obligations

Ongoing CDD triggers

Read

This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.

CCassandra AML

AML/CTF compliance workspace for Australian tax agents, accountants, lawyers, conveyancers, real estate professionals, trust and company service providers, and precious-metals and stones dealers — with designated-service decisions and review-ready records.

Owned and operated by Cassandra Research Pty Ltd, an Australian company based in Melbourne, Victoria.

Product

Create workspaceFree scope checkSign inPricingSecurity

AML/CTF guides

All guidesTranche 2 foundationsCore obligationsTax agentsBAS agentsAccountantsLawyersConveyancersReal estateTrust & company servicesPrecious-items dealersKnowledge RSS feed

Company

AboutContactEditorial standards

Legal

Privacy PolicyTerms of ServiceCookie NoticeAccessibility

Cassandra AML assists compliance work. It does not provide legal advice, guarantee compliance or imply AUSTRAC endorsement.

© 2026 Cassandra Research Pty Ltd, Melbourne, Australia. All rights reserved.