All guides

Guide

AML record-keeping: the 7-year rule in plain English

Last updated 8 September 2026

You must keep your AML/CTF records for seven years. That includes customer identification and due-diligence records, transaction records, your AML/CTF program, and reports you make to AUSTRAC.

What records to keep

  • Customer identification and due-diligence records.
  • Records of the designated services you provide and related transactions.
  • Your AML/CTF program and its risk assessment.
  • Suspicious matter and threshold transaction reports, and staff training records.

When the seven years starts

As a general rule, customer and identification records are kept for seven years after your relationship with the customer ends, and transaction records for seven years after the transaction. Keep them accessible and legible for the whole period.

Senly AML keeps every record tamper-evident, encrypted and exportable for the full seven years, so an AUSTRAC review is a non-event.

Questions, answered.

How long do I have to keep AML records?
Seven years. Customer and identification records are generally kept for seven years after the relationship ends, and transaction records for seven years after the transaction.
What records do I need to keep?
Customer identification and due-diligence records, transaction records, your AML/CTF program and risk assessment, your reports to AUSTRAC, and staff training records.
Do the records need to be in a particular format?
They must be kept accessible and legible for the whole seven-year period. Tamper-evident, encrypted digital records make an audit straightforward.
How Senly keeps records

This guide is general information, not legal advice. The official source is austrac.gov.au.