Guide · general information, not legal advice

AML/CTF record-keeping: what to keep, and for how long

Last checked 25 September 2026 against the AML/CTF Act compilation C2026C00274, the AML/CTF Rules 2025 (F2025L01026) and the Transitional Rules 2026 (F2026L00393)

The four record-keeping duties that apply to accounting practices, real estate agencies, conveyancers and legal practices, when each 7-year period starts, what the Privacy Act adds, and how to set up an index your evaluator and AUSTRAC can follow.

The short version

Four sections of the AML/CTF Act set the main record-keeping duties for these sectors. Each has its own 7-year period, and they start at different times.1 The transaction-record and program-record periods keep running after you stop being a reporting entity: those sections apply to a person who "is or was" one.2

The four record-keeping duties
What Keep for Source
Records sufficient to reconstruct each transaction in the designated service 7 years from the day the record is made s 107
Documents about the service that the client (or someone for them) gives you 7 years after the document is given s 108
Records that show your customer due diligence complied with Part 2 7 years from the end of the business relationship, or from completing a one-off transaction s 111
Records that show your AML/CTF program complied with Part 1A From when the record is made until 7 years after it stops being relevant to that compliance s 116

CDD records and program records must be in English, or in a form that is readily accessible and readily convertible into writing in English.3 Each duty is a civil penalty provision.1

Transaction records (s 107)

When you start or provide a designated service, keep enough to reconstruct each individual transaction in that service for the client.4 What that means depends on your service. For a conveyancer holding money for a settlement it might be the trust ledger entries, the payment instructions and the settlement statement; for an accountant setting up a company, the engagement, the registration and who paid what. Those examples are ours, not the Act's. Keep each record for 7 years from the day it is made.

Documents the client gives you (s 108)

If a client, or someone on their behalf, gives you a document relating to a designated service you have started to provide, keep the document or a copy for 7 years after it was given.5

Customer due diligence records (s 111)

Keep records reasonably necessary to show you complied with your customer due diligence obligations. They must include:6

  • records showing the type and content of the data you collected about the client for initial or ongoing CDD;
  • records of any analysis, identification or assessment of the client's ML/TF risk, and any decision you made.

That includes the notes the Rules require in particular cases: the steps taken when you could not identify the beneficial owners of a company, partnership or association, the steps taken and your consideration of a suspicious matter report when a party to a sale would not cooperate, and your documented reasons for relying on another entity's checks.7

The period runs until 7 years after the business relationship ends, or after you complete a one-off transaction.6 For a long-standing client that can be many years after you collected the information, so date every record and mark when the relationship ended.

If you rely on another entity's customer due diligence, the Act has two further retention rules: keep the copy of the other party's record that they give you until a 7-year period passes in which you provide no designated service to that client, and keep each written assessment of a reliance arrangement for 7 years after you prepare it.8 See our customer due diligence guide.

Program records (s 116)

Keep records reasonably necessary to show you complied with Part 1A, which is your ML/TF risk assessment, your AML/CTF policies and the duties that go with them.9 In a small practice that typically means:

  • each version of the risk assessment and the policies, with the senior manager's approval of each, and the date it was superseded;
  • the compliance officer's designation, the fit and proper checks, and the notice to AUSTRAC;
  • personnel due diligence and training records;
  • reports to the governing body;
  • independent evaluation reports and your response to them.

The list is our summary of what Part 1A asks you to do, not a list in the Act. Keep each record until 7 years after it stops being relevant to your Part 1A compliance.9 A superseded risk assessment may stay relevant for as long as decisions made under it could be questioned, so the simplest approach is to keep every version with its dates.

Your program itself must be documented before you first provide a designated service, and each update documented within 14 days after it occurs.10

Copies of ID documents and the Privacy Act

A small business that is a reporting entity is treated as an organisation under the Privacy Act 1988 for its AML/CTF activities, with any modifications the regulations prescribe, so the Privacy Act applies to that part of the business even if it would otherwise be exempt.11 The OAIC's guidance says:12

  • the AML/CTF Act does not require you to keep scanned copies or photocopies of identity documents;
  • you should take reasonable steps to destroy or de-identify copies of full identity documents once you no longer need them;
  • instead, keep the particulars you need (such as name, date of birth, residential address, document number and expiry), the type of document, what you did to verify the client and the outcome;
  • you must have a privacy policy and collection notices that explain how you handle personal information for AML/CTF purposes, but you need not give information in a collection notice where that would be inconsistent with the tipping-off offence.

The OAIC publishes a template collection notice for reporting entities and an August 2026 guide to privacy for reporting entities. Both are on its guidance page. Our Privacy Act and AML guide covers this in more detail.

When AUSTRAC asks

How records can be required
Who asks, and for what Privilege Source
The AUSTRAC CEO, by written notice, for your program documentation LPP form s 26Q
An authorised officer, by written notice, for information or documents relevant to compliance or enforcement. Omitting to do what the notice requires can be an offence (imprisonment for 6 months or 30 penalty units, or both) LPP form s 167
The AUSTRAC CEO, by written notice, for documents, or to appear for examination on oath or affirmation. Intentionally or recklessly failing to comply is an offence (imprisonment for 2 years or 100 penalty units, or both) This section has no LPP-form provision; take advice on privilege s 172A
The AUSTRAC CEO, an authorised officer, the Australian Federal Police, the Australian Crime Commission or an approved examiner, for information on whether and how you provide designated services in Australia LPP form s 202

AUSTRAC said on 28 August 2026 that it had begun issuing section 167 notices to businesses that appear to provide designated services without having enrolled.13 Section 168 is not an enforcement power: it entitles you to reasonable compensation for making copies of documents under a section 167 notice.14

Build an index an evaluator can follow

Your independent evaluation must test your program and report in writing.15 An evaluator, like AUSTRAC, will ask to see records. Our suggestions for a small practice:

  1. One index

    A single register listing each kind of record, the section it serves, where it is kept, who is responsible, the event that starts its 7-year clock, and the earliest date it may be destroyed.

  2. One client file structure

    The same folders in every client file: CDD and verification, risk rating and decisions, client documents, transactions, and ongoing reviews.

  3. Dates on everything

    The date a record was made, a document was received, a relationship ended, or a version was superseded. Every clock depends on one of these.

  4. A destruction check

    Before destroying anything, check the index: the AML/CTF clock, any other law that requires you to keep it, and the Privacy Act duty not to keep it longer than needed.

Where we fit

We do not keep your records or act as your compliance officer. AUSTRAC's free program starter kits and its record keeping overview are the place to start. AUSTRAC links open in a new window; AUSTRAC has not reviewed or endorsed this guide. Our kit builds on the starter kits, and every edition includes a record keeping index and a privacy collection notice for CDD. Our set-up service tailors them to your practice.

Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.

Sources

Law is quoted from the authorised text on the Federal Register of Legislation, opened 25 September 2026. AUSTRAC and OAIC pages are guidance, not law.

  1. AML/CTF Act ss 107(3)–(4), 108(2)–(3), 111(2) and (4), 116(2)–(4). legislation.gov.au/C2006A00169/latest/text

  2. AML/CTF Act ss 107(3) and 116(3).

  3. AML/CTF Act ss 111(2)(b) and 116(1)(b).

  4. AML/CTF Act s 107(1) and (3).

  5. AML/CTF Act s 108(1)–(2).

  6. AML/CTF Act s 111(1)–(3).

  7. AML/CTF Rules 2025 (F2025L01026), rules 6-8(1)(c), 6-33(2)–(3) and 6-31(e). legislation.gov.au/F2025L01026/latest/text

  8. AML/CTF Act ss 114 and 114A.

  9. AML/CTF Act s 116(1) and (3).

  10. AML/CTF Act s 26N; AML/CTF Rules 2025, rule 5-15.

  11. Privacy Act 1988, compilation C2026C00227, section 6E(1A). legislation.gov.au/C2004A03712/latest/text

  12. Office of the Australian Information Commissioner, "Privacy guidance for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act", updated 28 August 2026, read 25 September 2026. Guidance, not law.

  13. AUSTRAC, "AUSTRAC issues notices to non-enrolled businesses", published 28 August 2026. Guidance, not law. austrac.gov.au

  14. AML/CTF Act ss 167(2)(c) and 168.

  15. AML/CTF Act s 26F(4)(f); AML/CTF Rules 2025, rule 5-10.

Questions

How long do we keep CDD records?

Until 7 years after the business relationship ends, or 7 years after you complete a one-off (occasional) transaction (s 111(2)).

Do we keep copies of passports and driver licences?

The AML/CTF Act does not require you to keep copies of identity documents. The OAIC says to take reasonable steps to destroy or de-identify copies once you no longer need them, and to keep instead the particulars you need (such as name, date of birth, address, document number and expiry), the type of document, what you did to verify the client and the outcome. That is OAIC guidance, not law.

Which sections apply?

Section 107 (transaction records), s 108 (documents the client gives you), s 111 (customer due diligence records) and s 116 (records of your AML/CTF program under Part 1A). Older material that cites section 106 or section 112 is out of date: both were repealed.

How can AUSTRAC ask for our records?

The AUSTRAC CEO can request your program documentation (s 26Q). An authorised officer can require information or documents by notice (s 167), and the AUSTRAC CEO can require documents or an examination (s 172A). A notice under s 202 can ask whether, and how, you provide designated services in Australia. Where you believe material is privileged, each of ss 26Q, 167 and 202 requires an LPP form.

Ready to buy

AML/CTF Program Kit

All four sector editions — accountants, real estate agencies, conveyancers and legal practices — as editable Word documents. No subscription.

Prefer it done for you? The set-up service starts at A$990 and includes the kit.

A$497 one-off, includes GST of A$45.18

Buy the kit — A$497

After payment you go straight to your download page.

Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.