Obligations
AML/CTF record keeping and Australia's seven-year rules
Seven years is a headline, not a complete AML/CTF retention rule. The start date differs by record type: a CDD record can run from the end of a business relationship or completion of an occasional transaction, a transaction record from creation, and a program record can remain relevant for years before its seven-year period begins. A reporting entity therefore needs a retention schedule driven by events and relationships, not one deletion date attached to every file. It must also keep records complete, accurate, secure and retrievable in English or readily accessible in a form that can be translated. This guide provides an operational framework; other laws, investigations, legal holds and professional duties may require longer retention, so deletion must be governed rather than automatic.
Step-by-step process
Inventory records
Locate AML evidence across customer, transaction, program, reporting and governance systems.
Assign the clock
Classify each record and capture the correct statutory trigger and minimum period.
Secure and test
Protect integrity and confidentiality, then test complete and prompt retrieval.
Hold or dispose
Check other legal needs, approve extensions or secure disposal, and retain evidence of action.
Classify the record before calculating time
AUSTRAC's overview distinguishes customer due diligence records, transaction records, customer-provided transaction documents and AML/CTF program records. CDD evidence includes information used to identify and verify customers, representatives, beneficial owners and relevant risk or ongoing-review decisions. Transaction records capture the nature and parties sufficiently to reconstruct the activity. Program records include risk assessments, policies, versions, approvals, reviews and evidence showing compliance with Part 1A.
Do not classify only by storage location. A document in a customer folder may evidence both CDD and a transaction, while a screening result can support identification, ongoing CDD and an escalation decision. Build a data inventory that names the business owner, system, record class, trigger event, minimum period, access restrictions and disposal authority. Preserve links between records so an investigator can understand the decision without reconstructing it from unrelated systems.
Use the correct seven-year trigger
AUSTRAC states that CDD records are generally kept for seven years after an occasional transaction is completed or after the business relationship ends. General transaction records are kept for seven years from the day they are created, and transaction documents supplied by a customer are kept for seven years from the day they are provided. Those different clocks matter in a relationship lasting many years: onboarding evidence cannot simply be deleted seven years after collection while it remains part of the current relationship record.
Program records are retained from creation until seven years after the record ceases to be relevant for demonstrating compliance with the AML/CTF program requirement. Superseding a policy does not necessarily make it irrelevant immediately; the old version may explain the controls that applied to a historic customer or report. Record an end-of-relevance decision with reasons, then calculate disposal. Confirm any additional categories and detailed timing against the current Act and Rules rather than treating this summary as exhaustive.
Preserve quality, accessibility and confidentiality
Records must be sufficient to demonstrate what occurred and what the business decided. Capture source, date, version, reviewer, result and any exception. A screenshot without a timestamp or search parameters may be weak evidence; a risk rating without the factors and approval cannot explain the judgement. Where a provider or registry supplies data, preserve enough information to reproduce or understand the result within legal and licensing constraints.
Store records so authorised people can locate them promptly and produce them in English or in a readily accessible and translatable form. Apply least-privilege access, encryption where appropriate, audit logs, resilient backups and controls against alteration. SMR-related material and information that could reveal a report require particularly careful segregation because tipping-off restrictions may apply. Outsourced storage does not transfer the reporting entity's obligation to retain and retrieve evidence.
Coordinate deletion, holds and system change
At the end of the minimum AML period, check for other retention duties, litigation or regulatory holds, active investigations, complaints, insurance needs and professional standards. A seven-year minimum is not an instruction to delete where another lawful reason requires preservation. Conversely, indefinite retention increases privacy, security and discovery risk. Document the lawful basis, review extended holds and dispose securely when all needs have ended.
System migrations are a common failure point. Before decommissioning a CRM, practice platform or screening service, reconcile record counts, metadata, attachments, audit history and relationship end dates. Test retrieval from the archive and preserve vendor certificates or migration logs. Contract terms should address export formats, deletion, subcontractors, data location, breach notification and access after termination. Sampling should include closed customers and superseded program versions, not only current files.
Build an event-based retention schedule
Governance reporting should show records without a valid trigger date, overdue archive actions, failed retrieval tests, unauthorised access and vendor issues. A retention schedule becomes effective only when systems can execute it. If automation is not yet reliable, apply a controlled manual process and prevent premature deletion until the gap is remediated.
- Inventory CDD, transaction, customer-supplied, program, governance, training, screening and reporting records across every system.
- Map each class to the current statutory rule, trigger event, minimum period and any other applicable retention duty.
- Capture relationship end and occasional-transaction completion dates as controlled data rather than free-text notes.
- Apply security, audit, language and retrieval standards according to sensitivity, including strict protection for SMR information.
- Create legal-hold and regulator-request processes that suspend disposal without silently extending every record forever.
- Approve and evidence disposal, then test that linked records and backups follow the authorised outcome.
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
Frequently asked questions
Can CDD documents be deleted seven years after onboarding?
Not merely because seven years have passed since collection. AUSTRAC ties the CDD period to completion of an occasional transaction or the end of the business relationship. Current relationships, ongoing relevance, other laws and holds must be considered before an authorised disposal decision.
When does the period for a superseded AML policy begin?
Program records are kept until seven years after they cease to be relevant to demonstrating compliance. A superseded policy can remain relevant to historic decisions and transactions. Document when and why relevance ends, preserve linked evidence, and then apply the period required by current law.
May AML records be stored outside Australia or by a cloud provider?
The reporting entity must still meet accessibility, security, integrity, language and production requirements and comply with any other applicable data law. Assess vendor, location, subcontracting, export and termination risks. Ensure records can be produced promptly even if the contract ends.
Should everything be deleted as soon as the AML period ends?
No automatic rule fits every record. Check other statutory, professional, contractual, investigation and legal-hold requirements. Where no lawful or necessary basis remains, secure disposal supports privacy and security. Record the decision and ensure archives and backups are handled consistently.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.