AML/CTF Record Keeping: It Is Not Enough to Do the Work – You Need to Keep the Evidence

For many businesses, AML/CTF compliance is thought of in terms of completing a risk assessment, having an AML/CTF program, conducting customer due diligence and submitting reports to AUSTRAC when required. 

But there is another important obligation that can easily be overlooked: 

record keeping. 

Under Australia’s updated AML/CTF framework, a reporting entity needs to be able to demonstrate what it did, why it did it, who approved it and, where appropriate, what action was taken afterwards. 

This means records such as compliance reports, Board minutes, AUSTRAC correspondence, customer due diligence records, transaction records, risk assessments and independent evaluation reports should not simply sit in someone’s email inbox. 

They form part of the organisation’s evidence of AML/CTF compliance

What does AUSTRAC expect businesses to keep? 

AUSTRAC explains that reporting entities must keep records relating to three broad areas: 

  • their AML/CTF program
  • customer due diligence (CDD)
  • transactions relating to designated services. (AUSTRAC)

Importantly, AUSTRAC’s guidance goes much further than simply keeping the current version of your AML/CTF program. 

Records can include reports, emails and correspondence, meeting minutes, approvals, logs, databases, transaction information and other evidence demonstrating how the organisation has complied. (AUSTRAC

For a registered club, for example, this could mean retaining evidence such as: 

Area Examples of records 
AML/CTF Program Current and previous programs/policies, version history and approvals 
Risk Assessment ML/TF risk assessments, reviews, changes and approval records 
Compliance Officer Appointment, fit-and-proper assessment, training and role description 
Board/Governing Body Compliance reports, agendas, minutes, decisions and action items 
AUSTRAC Guidance, correspondence, notices and evidence showing how the organisation responded 
Customer Due Diligence CDD, OCDD and ECDD records, verification outcomes and customer risk assessments 
Transactions Records sufficient to reconstruct relevant transactions 
Suspicious Matters Internal escalation records, investigations, decisions and supporting evidence 
Training Training materials, attendance, completion records and follow-up 
Independent Evaluation Evaluation reports, scope, findings, Board consideration and corrective actions 

AUSTRAC specifically identifies AUSTRAC communications received, records of decision-making and outcomes as examples of records that can demonstrate that an organisation has reviewed and updated its AML/CTF program in response to relevant communications and mandatory triggers. (AUSTRAC

That is an important point. 

It isn’t necessarily enough to receive an AUSTRAC update. A reporting entity should be able to demonstrate that relevant information was considered and, where necessary, acted upon

How long should AML/CTF records be kept? 

You will often hear the simple rule: 

“Keep AML/CTF records for seven years.”

That is useful as a starting point, but the actual requirements are more nuanced. 

For example, general transaction records generally need to be retained for seven years from when the record was created, while customer-provided transaction documents generally need to be retained for seven years from when they were provided. (Federal Register of Legislation

CDD records operate differently. 

Records reasonably necessary to demonstrate compliance with CDD obligations generally need to be retained until seven years after the business relationship ends, or seven years following completion of an occasional transaction. (Federal Register of Legislation

AML/CTF program records are different again. 

Section 116 of the AML/CTF Act requires relevant program records to be retained until seven years after the record is no longer relevant to demonstrating compliance with the reporting entity’s Part 1A obligations. (Federal Register of Legislation

This distinction matters. 

An AML/CTF risk assessment prepared in 2026, for example, may continue to be relevant for several years. You should not necessarily assume it can simply be destroyed in 2033 because seven years have passed since it was originally created. 

Compliance Officer reports and Board records 

The updated requirements place significant emphasis on governance. 

The AML/CTF Compliance Officer must report to the governing body at least once every 12 months. The report must address compliance with the organisation’s AML/CTF policies, whether those policies appropriately manage its ML/TF risks, and compliance with the Act, Rules and regulations. (AUSTRAC

The organisation should therefore retain more than just the final report. 

Good evidence would include: 

Compliance Officer Report → Board agenda → Board minutes → decisions → actions allocated → evidence actions were completed. 

AUSTRAC specifically identifies annual or more frequent compliance reports, governing-body briefings, meeting agendas, minutes, discussions, decisions and actions as records that can demonstrate compliance. (AUSTRAC

For registered clubs, this is particularly important. 

A Compliance Officer emailing a report to the CEO is very different from being able to demonstrate that the governing body received the report, considered the information and appropriately responded to identified issues. 

Customer records require particular care 

CDD information can contain substantial amounts of personal information. 

Records may include customer information, identity verification results, customer risk ratings, PEP information, source of funds or source of wealth enquiries, ECDD investigations and supporting documentation. 

AUSTRAC says reporting entities need records showing what customer information was collected, how it was verified and the analysis or decision-making supporting the level of CDD applied. (AUSTRAC

Importantly, this does not automatically mean keeping photocopies of everyone’s driver’s licence or passport

AUSTRAC’s current guidance specifically notes that businesses are not required to retain scanned copies or photocopies of identity documents themselves simply to meet the initial CDD record-keeping requirement. What matters is maintaining sufficient and accurate evidence of the information collected and the verification undertaken. (AUSTRAC

This can also reduce unnecessary privacy and cybersecurity exposure. 

Privacy obligations also apply 

AML/CTF records should not be treated like ordinary operational documents. 

AUSTRAC states that reporting entities must comply with the Privacy Act 1988, including small businesses that might otherwise assume the Privacy Act does not apply to them. (AUSTRAC

This becomes particularly important when records contain customer identification information or information associated with suspicious matters. 

AUSTRAC recommends limiting access to authorised personnel and using security controls such as restricted access, password protection or encryption. Paper records should similarly be secured in locked or restricted-access locations. (AUSTRAC

For clubs, I would therefore strongly recommend role-based access

A Duty Manager may need access to certain CDD or transaction-monitoring information without necessarily requiring unrestricted access to every AML/CTF record held by the organisation. 

Be particularly careful with suspicious matter information 

Suspicious Matter Reports and the information surrounding them need additional protection. 

The organisation needs to consider the AML/CTF Act’s tipping-off provisions when determining where information is stored and who can access it. 

AUSTRAC specifically identifies customer identification information and suspicious matter information as examples of sensitive records that should be securely stored with access limited to authorised personnel. Poor information security can increase the risk of breaching tipping-off obligations. (AUSTRAC

Practically, I would not recommend putting SMR information into a general compliance folder that every manager can access. 

Electronic storage is acceptable 

There is no requirement that AML/CTF records all be maintained as paper files. 

AUSTRAC confirms that records may be maintained electronically or in hard copy and may be stored onsite or offsite. (AUSTRAC

However, the system needs to allow the organisation to find and retrieve the evidence when required

AUSTRAC’s checklist recommends that organisations specify: 

  • what records must be kept
  • where and in what format they will be stored
  • how long they will be retained
  • who is responsible for maintaining them
  • how they will be protected against unauthorised access, loss or tampering
  • how they can be produced for regulatory review or audit. (AUSTRAC)

Electronic records should also be appropriately backed up, with AUSTRAC recommending secure offsite or encrypted cloud backups and appropriate recovery arrangements. (AUSTRAC

Don’t convert everything to PDF 

One small point in AUSTRAC’s current guidance is particularly useful for businesses using electronic compliance systems. 

AUSTRAC says it expects records to generally be maintained in their original or usual format

For example, an Excel spreadsheet would ordinarily remain as a spreadsheet rather than being converted to a PDF where that conversion could affect its structure or usability. (AUSTRAC

The objective should be to preserve the integrity and usefulness of the evidence. 

A simple approach for clubs 

For a registered club, I would recommend establishing a structured AML/CTF record system along the following lines: 

1. Governance — Board reports, minutes, Compliance Officer appointment and approvals. 

2. AML/CTF Program — current and superseded policies, version histories and approvals. 

3. Risk Assessments — ML/TF and proliferation financing risk assessments, reviews and changes. 

4. AUSTRAC Communications — relevant updates, correspondence and regulatory feedback, together with evidence showing what the club did in response. 

5. Training & Personnel — training, competency and personnel due diligence. 

6. Customer Due Diligence — CDD, OCDD and ECDD records with appropriately restricted access. 

7. Transaction Monitoring & Reporting — transaction monitoring evidence, TTRs and related compliance records. 

8. Suspicious Matters — highly restricted investigation and SMR records. 

9. Independent Evaluations — reports, findings, Board consideration, corrective actions and evidence of close-out. 

This turns AML/CTF record keeping into a structured compliance process rather than an electronic filing cabinet. 

The practical test 

A simple question I encourage Compliance Officers and senior managers to ask is: 

“If AUSTRAC walked in tomorrow and asked us to show how we complied with this requirement, could we find the evidence?”

For example: 

Can you show me the last Compliance Officer report? 

Can you show me when the Board considered it? 

Can you show me what action was taken? 

Can you show me the previous version of your risk assessment and why it changed? 

Can you show me how you responded to an AUSTRAC update? 

Can you show me why this customer was classified as high risk and what enhanced due diligence was undertaken? 

If those records can be produced quickly, securely and in a logical sequence, the organisation is in a much stronger position to demonstrate compliance. 

The objective isn’t simply to keep documents for seven years

It is to maintain an evidence trail showing that your AML/CTF framework is actually operating. 

That is the difference between having an AML/CTF program and being able to prove that you are implementing it

For further guidance, see AUSTRAC’s Record Keeping Overview and AUSTRAC’s Record Keeping Checklist

#CHDPartners #CIRT #RTO #WHS #WorkHealthAndSafety #Training #RiskManagement #SecurityAndSafetyCompliance #SME #SmallBusiness #MichaelHuggett #AUSTRAC #AMLCTFAnnualComplianceReports #AMLCTFCompliance #AMLCTF #AntiMoneyLaundering 

Previous Post
Personal Emergency Evacuation Plans: Does Your Workplace Need One?