All guides
Guide
AML record-keeping: the 7-year rule in plain English
Last updated 8 September 2026
You must keep your AML/CTF records for seven years. That includes customer identification and due-diligence records, transaction records, your AML/CTF program, and reports you make to AUSTRAC.
What records to keep
- Customer identification and due-diligence records.
- Records of the designated services you provide and related transactions.
- Your AML/CTF program and its risk assessment.
- Suspicious matter and threshold transaction reports, and staff training records.
When the seven years starts
As a general rule, customer and identification records are kept for seven years after your relationship with the customer ends, and transaction records for seven years after the transaction. Keep them accessible and legible for the whole period.
Senly AML keeps every record tamper-evident, encrypted and exportable for the full seven years, so an AUSTRAC review is a non-event.
Questions, answered.
- How long do I have to keep AML records?
- Seven years. Customer and identification records are generally kept for seven years after the relationship ends, and transaction records for seven years after the transaction.
- What records do I need to keep?
- Customer identification and due-diligence records, transaction records, your AML/CTF program and risk assessment, your reports to AUSTRAC, and staff training records.
- Do the records need to be in a particular format?
- They must be kept accessible and legible for the whole seven-year period. Tamper-evident, encrypted digital records make an audit straightforward.
This guide is general information, not legal advice. The official source is austrac.gov.au.