Record-Keeping Obligations for TCSPs Under Tranche 2

Australian TCSPs must retain AML/CTF records for seven years under Tranche 2. Here is what to keep, how long, and what happens if you cannot produce them.
Under the AML/CTF Act 2006, trust and company service providers (TCSPs) must retain customer due diligence records, transaction records, and suspicious matter reports for a minimum of seven years. Tranche 2 commenced on 1 July 2026 — record-keeping obligations are now active for every enrolled TCSP.
What records must TCSPs keep under the AML/CTF Act?
TCSPs must retain the following records in a retrievable form: - Customer due diligence records — identity documents, verification results, beneficial ownership mapping, and PEP/sanctions screening outcomes for every client - Designated service records — details of each designated service provided, including the date, nature, and client - Ongoing monitoring records — risk review outcomes, changes to client risk ratings, and monitoring alert disposals - Transaction records — sufficient detail to reconstruct the transaction trail for any designated service involving funds - Suspicious matter reports — a copy of every SMR submitted to AUSTRAC, including the facts and circumstances that triggered the suspicion - Staff training records — evidence that staff with AML/CTF responsibilities completed the required training
How long must TCSPs retain AML/CTF records?
The minimum retention period is seven years under the AML/CTF Act 2006. For CDD records, the seven years run from the end of the business relationship with the client. For transaction and monitoring records, the period runs from the date each record was made. SMR copies must be retained for seven years from the date of submission to AUSTRAC. There is no discretion to dispose of records before this period expires.
How should TCSPs store compliance records?
Records must be kept in a form that AUSTRAC can retrieve promptly on request. Paper-based records are permitted but carry operational risk — misfiling, physical deterioration, and office relocations all create gaps. The AML/CTF Rules require records to be stored in a way that preserves their integrity. Scanned copies of original documents are generally accepted provided the scan is legible and any disposal of originals is documented.
Cloud-based compliance platforms satisfy these requirements by design: records are stored in a structured, immutable format with full audit trails. AMLify for TCSPs manages the full record-keeping lifecycle — from initial CDD collection through to seven-year automated retention. Explore AMLify's compliance features including audit logging and document retention for more detail.
What if a TCSP cannot produce records to AUSTRAC?
Failure to keep or produce records is a contravention of the AML/CTF Act 2006. AUSTRAC may issue an infringement notice or apply to the Federal Court for a civil penalty order. In enforcement actions, gaps in record-keeping tend to compound other compliance issues — regulators treat poor record management as evidence of a systemic failure rather than an isolated administrative error.
Key Takeaways
- Retain all AML/CTF records for seven years from the end of the relevant business relationship or the date the record was made
- Six categories of records must be kept: CDD, designated service, monitoring, transaction, SMR, and training records
- Records must be retrievable promptly and produced to AUSTRAC on demand
- Failure to keep or produce records is a civil penalty provision under the AML/CTF Act 2006
- AMLify for TCSPs automates retention and maintains an immutable audit log for every compliance action
Frequently Asked Questions
Q: When does the seven-year retention period start for CDD records?
For CDD records, the seven-year period begins from the date the business relationship ends — not the date the CDD was originally collected. If a client relationship spans many years, the retention clock starts at relationship termination, meaning records for long-standing clients may need to be held for considerably longer than seven years in practice.
Q: Do TCSPs need to keep records for prospective clients who did not proceed?
Yes. If CDD work was performed — identity documents collected and verified — those records must be retained even if the designated service was never ultimately provided. The obligation attaches when CDD is conducted, not when a service transaction is completed.
Q: Can a TCSP use its existing document management system for AML/CTF records?
An existing DMS can be used if it meets the AML/CTF Act's requirements: records must be in a retrievable format, protected from unauthorised alteration, and producible to AUSTRAC on request. A general-purpose DMS often requires manual curation to meet this standard — dedicated compliance platforms like AMLify maintain structured, AUSTRAC-ready record sets by default.
This is general information only and not a substitute for legal advice.