Record-keeping — 7 years of what, exactly
The records the AML/CTF Act requires you to keep, when each seven-year period starts, and what the Act does and does not say about format and storage.
In short
The AML/CTF Act requires three main sets of records, each kept for 7 years from a different starting point. CDD records run from the end of the business relationship or completion of a one-off transaction (s 111). Transaction records run from the day the record is made (s 107), and documents a customer gives you run from when they are given (s 108). Programme records run until 7 years after they stop being relevant (s 116). Records must be in English or readily convertible to English. The Act does not say where they must be stored.
Records are how you show AUSTRAC that you did what the AML/CTF Act 2006 (Cth) requires. The rules are in Part 10 of the Act and s 116, and AUSTRAC groups them into three sets. The 7-year period is the same for each, but the starting point is not.
1. Customer due diligence records (s 111). You must keep records reasonably necessary to show you complied with the CDD obligations in Part 2. They must include:
- records showing the type and content of the data you collected about the customer;
- records of any risk analysis or assessment you made, and any decisions you took, in doing CDD (s 111(3)).
Keep them until the end of the 7 years that begin when the business relationship ends or you finish providing an occasional transaction (s 111(2)). AUSTRAC's guidance notes that the Act does not require you to copy identity documents. You can record the details you used instead, although another law may require copies.
2. Transaction records (ss 107, 108).
- Transaction records. You must keep "sufficient records to allow the reconstruction of individual transactions" (s 107(1)). Keep them for 7 years from the day each record is made (s 107(3)). AUSTRAC's examples include the date, the amount, the customer, the payment method, and contracts or other documents that give context.
- Customer documents. If a customer, or someone on their behalf, gives you a document relating to the service, you must keep it, or a copy, for 7 years after it was given (s 108). AUSTRAC's examples include signed contracts and payment instructions.
3. Programme records (s 116). You must keep records reasonably necessary to show you complied with Part 1A, the programme obligations. AUSTRAC's examples include:
- each version of your risk assessment and policies;
- the senior manager's approvals (s 26P);
- notifications to the governing body;
- personnel due diligence and training records;
- the compliance officer's appointment and fit-and-proper assessment;
- the compliance officer's reports;
- independent evaluations;
- the processes you use to decide whether to report suspicious matters.
Keep each record from when it is made until 7 years after it is no longer relevant to your Part 1A compliance (s 116(3)). AUSTRAC says you will need to use judgement to decide when that point is reached.
Reliance records. If you rely on another person's collection and verification under s 37A or s 38 and they give you a copy of their record, you must keep that copy (s 114). If you have a written reliance arrangement under s 37A, keep each record of your regular assessment of it for 7 years after you finish preparing the record (s 114A).
Form and storage. The Act's only form requirement is that CDD and programme records are in English, or readily accessible and readily convertible into English (ss 111(2)(b), 116(1)(b)). The record-keeping provisions do not say where records must be stored. AUSTRAC's guidance says:
- records may be hard copy or electronic, at your premises or offsite;
- you can use an external provider;
- records should stay in their original or usual format;
- sensitive records, such as identity details and suspicious matter reports, should be stored securely with access limited to authorised staff.
AUSTRAC also points out that every reporting entity must comply with the Privacy Act 1988 (Cth), even a small business.
Practical checks. None of these is a legal rule, but each one makes the obligations above easier to prove:
- Can you find a customer's CDD file, including the risk rating and the reasons for it, without searching several inboxes?
- Does each file record the date the relationship or transaction ended, so you know when the 7 years run out?
- Do you keep every version of your risk assessment and policies, with the approval date and the approving senior manager?
- Are identity and suspicious-matter records restricted to the people who need them?
What to do next. Map where each of the three record sets lives today. Set a retention rule for each, measured from the right starting point. Restrict access to identity and suspicious-matter records.
Frequently asked questions
- When does the seven-year clock start for a buyer's CDD pack?
- When the business relationship ends or, for a one-off transaction, when you finish providing it (s 111(2)). AUSTRAC gives a one-off property purchase as an example of an occasional transaction. For most sales that will be when your service ends, which in practice is usually settlement. That last step is our reading, so record the end date you use for each file.
- Can records be kept entirely in the cloud?
- The AML/CTF Act does not say where records must be kept. Its only form requirement is that records are in English or readily convertible to English (ss 111(2)(b), 116(1)(b)). AUSTRAC's guidance says records may be hard copy or electronic, at your premises or offsite, and that you can use an external provider. It expects sensitive records, such as identity details and suspicious matter reports, to be stored securely with access limited to authorised staff. AUSTRAC also notes that every reporting entity, including a small business, must comply with the Privacy Act 1988.
- Are paper records acceptable?
- Yes. AUSTRAC's guidance says records may be hard copy or electronic. It expects you to keep records in their original format or the format you usually use.
- Does this apply to SMRs we decided not to file?
- No rule expressly requires a written record of a decision not to report. AUSTRAC's guidance says you may choose to record your reasons. If you remain suspicious but cannot yet confirm reasonable grounds, AUSTRAC expects written records of the steps you take. Your policies must provide for timely review of potential suspicious matters (Rule 5-12). You must keep records reasonably necessary to show you followed your policies (s 116). A short dated note of each decision is the simplest way to do that.