Skip to main content

Record Keeping

Record keeping is the obligation that makes every other obligation provable. It is also the one firms most often satisfy accidentally rather than deliberately: records exist because work happened, but not in a form anyone could produce on request.

The obligation sits in Part 10 of the AML/CTF Act 2006 (ss 104 to 119). The provisions used most in practice are ss 107, 108, 111, 114, 114A and 116.

How long records must be kept

The general rule is seven years, running from different points depending on the record:

RecordRetention starts
Customer identification records7 years after the business relationship ends or the occasional transaction is completed (s 111(2))
Transaction records7 years from the day the record is made (s 107(3)); documents the customer gave you, 7 years after they were given (s 108(2))
Reports to AUSTRACFrom the date the report was made
AML/CTF program recordsUntil 7 years after the record is no longer relevant to showing compliance (s 116(3)). This is a judgement call, not automatically the date a version is superseded

In Duely each matter carries a retention anchor, the date from which its seven year period begins. You set it when the engagement concludes or the business relationship ends. Duely does not set it for you.

What has to be kept

The core provisions are ss 107, 108, 111 and 116. In practice the records fall into five groups:

  • Customer identification: who the customer is, the identification details captured, and the beneficial owners and controllers where the customer is not an individual.
  • Verification and screening: what was checked, how, and what the result was, including the basis recorded for confirming the customer is who they claim to be.
  • Risk and due diligence decisions: the risk assessment, the factors considered, the rating reached, the rationale, and any enhanced due diligence measures and approvals.
  • Reports: copies of reports made to AUSTRAC, internal referrals that led to them, and correspondence with AUSTRAC.
  • Program and governance: every version of the AML/CTF program, the approvals behind each version, the AML/CTF Compliance Officer appointment and the fit and proper determination behind it, and training records.

The records have to be usable

Sections 111 and 116 require records to be in English, or readily convertible to English. AUSTRAC also expects records kept in their original format and stored securely. Beyond that, good practice is that records be:

  • Accessible, meaning producible to AUSTRAC or law enforcement on request
  • Legible, in a form that can be read and understood
  • Intact, not altered, manipulated, or destroyed

A folder of scans that cannot be searched, or a system nobody can export from, does not meet the bar. The test is whether you could hand the records over, in a usable form, when asked.

AspectRecords that existRecords that answer
Finding themSpread across shared drives, inboxes, and memory of where things went.Attached to the matter they belong to, and searchable by customer or engagement.
Proving they are unalteredA file date, if it survived being copied between folders.An append-only audit log per matter, and hashed snapshots for evidence packs.
Answering a specific questionWhat did we know about this customer in March, and who decided it was enough?The decision, its rationale, the approver, and the timestamp are recorded against the matter.
Handing them overA manual assembly exercise under time pressure.A generated evidence pack for the matter, with the retention period already tracked.

Failure is a civil penalty

Failing to keep required records is a civil penalty offence. AUSTRAC can also issue infringement notices or enforceable undertakings for record keeping failures, which means the consequence is not limited to a penalty imposed after a long proceeding.

Beyond the penalty

The other obligations all depend on records to be demonstrable. A firm that completed every verification properly but cannot show it is, from the regulator's side, indistinguishable from a firm that did not.

AUSTRAC's guidance on this obligation is Record keeping overview.

Duely treats records as infrastructure rather than paperwork:

  • An immutable audit log records matter events in an append-only stream, so the history cannot be quietly edited.
  • Evidence packs are versioned snapshots with a SHA-256 hash of the generated PDF, so the file's integrity can be checked after the fact.
  • Records live where the work happened, attached to the matter, rather than in a parallel filing system that drifts out of step with reality.
An evidence pack record, showing the version and the stored hash for the generated PDF.An evidence pack record, showing the version and the stored hash for the generated PDF.
An evidence pack record, showing the version and the stored hash for the generated PDF.