Record-Keeping Obligations for Accounting Firms

What accountants must keep on file under the AML/CTF Act 2006: CDD evidence, risk assessments, SMR decisions, and how long to retain each record.
Accounting firms must retain customer due diligence evidence, the ML/TF risk assessment, transaction records, and any suspicious matter report decisions for at least seven years under the AML/CTF Act 2006 — in a format AUSTRAC can retrieve on request, not just a filed PDF.
What records must an accounting firm keep?
The AML/CTF Act 2006 requires four broad categories of record for every client relationship involving a designated service: 1. CDD records — identity documents sighted, verification method used, and the outcome, for every individual and entity client 2. Transaction records — details of designated services provided, including dates, amounts, and the parties involved 3. Risk assessment and programme records — every version of the firm's ML/TF risk assessment and AML/CTF programme, not just the current one 4. Reporting records — the reasoning behind every suspicious matter report decision, including matters considered but not reported, and evidence supporting any threshold transaction report
How long must these records be retained?
Seven years is the baseline across all four categories, but the start date differs. CDD and transaction records must be kept for seven years after the client relationship ends, not from when the record was created. Programme and risk assessment records must be kept for seven years from the date each version was superseded. A firm that deletes CDD files as soon as a client leaves, rather than starting the seven-year clock at that point, falls short of the obligation.
What format do the records need to be kept in?
The AML/CTF Act 2006 doesn't mandate a specific system, but it does require records to be retrievable in a reasonable time and readable by AUSTRAC without the firm reconstructing them from memory. Identity documents scattered across client email threads, or a risk assessment that only exists on one partner's laptop, don't meet this bar in practice. Records need to be centralised, searchable by client, and exportable — including the version history of the programme itself, since reviews often ask what it said at the time a specific decision was made.
What happens if record-keeping falls short during a review?
AUSTRAC's early Tranche 2 reviews have flagged incomplete record trails as a standalone finding, even where the underlying CDD or risk decision was reasonable. A firm that verified a client properly but can't produce the evidence seven years later is treated the same as a firm that never verified at all — the record is the compliance evidence. AMLify for accounting firms timestamps and retains CDD evidence, programme versions, and reporting decisions automatically, so retrieval isn't a scramble through old email when a review lands.
Key Takeaways
- Seven years is the minimum retention period for CDD, transaction, risk assessment, and reporting records
- The seven-year clock starts differently per record type — from when a client relationship ends for CDD files, from when a version is superseded for the programme
- Records must be centralised and retrievable, not scattered across email threads and individual devices
- Missing evidence is treated as a compliance gap, even if the original decision was sound
- A 14-day free trial at [/pricing](/pricing) puts CDD evidence, programme versions, and reporting records in one auditable system
Frequently Asked Questions
Q: Does the seven-year retention period apply to every client, even low-risk ones?
Yes. The AML/CTF Act 2006 does not carve out an exception for low-risk clients — CDD and transaction records must be retained for seven years after the relationship ends regardless of the client's risk rating.
Q: Do we need to keep every past version of our AML/CTF programme, or just the current one?
Every version. AUSTRAC can ask what your programme required at the time a particular client decision was made, so superseded versions must be retained for seven years from the date each was replaced, not discarded once updated.
Q: Are scanned copies of identity documents enough, or do we need originals?
Scanned or electronic copies are acceptable, provided the verification method used is also recorded and the copy is retrievable in a reasonable time. What matters is that the evidence of verification, not just a copy of the document, is kept.
Q: What if a client relationship ends but we're later asked about them by AUSTRAC?
That's exactly why the seven-year period runs from the end of the relationship rather than the date each record was created — AUSTRAC can request evidence well after a client has left, and the firm remains responsible for producing it.
This is general information only and not a substitute for legal advice.