What the program must retain
AUSTRAC's record-keeping guidance and checklist set out the record classes and periods. A practice should not rely on memory: define the retention schedule, the storage location and who can access each class, and apply the same discipline to paper and digital files.
- The ML/TF/PF risk assessment and the AML/CTF program, including versions
- Customer identification and verification records for each captured customer
- Transaction records for designated services, including the service scope decision
- SMR, TTR and IFTI records and the reasoning behind reporting decisions
- Staff training and personnel due diligence records
- Independent evaluation and review records
Make the evidence connected, not just stored
A folder of scanned documents is weaker than a connected record. For each captured client, the file should link the scope decision, the identity evidence, the screening results, the risk rating, the approvals and the monitoring events, with dates and responsible persons. When an examiner asks 'why was this client rated medium risk?', the answer should be one screen, not a search.
Cassandra AML records evidence with checksums, audit events and approval separation so a retained file can show when each decision was made and who made it, without allowing silent edits.
Responding to AUSTRAC and TPB requests
AUSTRAC supervises the AML/CTF regime and the TPB supervises tax practitioner conduct. A request from either regulator is a test of the record-keeping system. A practice that can retrieve a complete file quickly has a different conversation from one producing a folder of unlinked documents.
- Respond within the stated timeframe and produce the exact records requested
- Involve the compliance officer and, where appropriate, advisers
- Do not alter, delete or reconstruct records after a request
- Remediate gaps promptly and document the fix
Retention and destruction
Retention is not indefinite hoarding. A defined schedule with controlled destruction is itself an internal control; it prevents stale personal information lingering beyond the lawful period and makes the compliance program easier to run.
- Keep records for the periods the Act and Rules require, commonly seven years
- Destroy records only when the retention period has ended and no legal hold applies
- Protect SMR-related information with restricted access
- Record destruction decisions so the schedule can be demonstrated
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
Frequently asked questions
How long must tax practices keep AML/CTF records?
The Act and Rules require the periods they specify, commonly seven years for customer identification, transaction and reporting records. Check the current provisions and AUSTRAC's record-keeping guidance.
Can we keep records in the cloud?
Yes, where the storage preserves the record, restricts access and supports the retention period. The control that matters is retrievability, integrity and auditability, not the medium.
What if a record is missing when AUSTRAC asks?
Be honest, produce what exists and remediate the process that failed. Reconstructing or altering records after a request is a separate and more serious problem.
Does the TPB regime change AUSTRAC record keeping?
No. The TPB Code of Professional Conduct and the AML/CTF regime are separate. A practice should meet both, and the same client-file discipline can serve both regulators.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.