AML Compliance Guide

Record keeping (7 years) for Bookkeeperss — 2026 AUSTRAC Guide

If your bookkeeping practice provides a designated service from 1 July 2026, you must keep AML/CTF records for 7 years. For bookkeepers, this usually matters where you handle client money, arrange transactions, or carry out work connected to a designated service rather than doing basic data entry or standalone tax return preparation. If your records are incomplete, missing, or cannot be produced, AUSTRAC can treat that as a breach in its own right, with civil penalties up to $33.5 million per contravention and criminal penalties for intentional contraventions.

This obligation is broader than just keeping copies of IDs. You must create and retain records that show how your bookkeeping business met its AML/CTF duties, including your AML/CTF program documents, customer due diligence records, and transaction records related to any designated service you provide. AUSTRAC expects records to be full, accurate, securely stored, and easy to retrieve. They can be electronic or paper, and they should usually be kept in their original format, so if you assess risk in a spreadsheet, keep the spreadsheet rather than only a PDF export.

What a bookkeeping practice needs to keep

  • CDD records for each client you onboard for a designated service: what information you collected, how you verified the client, and beneficial owner details where the client is a company or trust
  • Records of your ML/TF risk assessment, AML/CTF program, updates, senior management approvals, staff training logs, sanctions screening results, and any enhanced due diligence for higher-risk clients such as PEPs
  • Transaction records connected to the designated service, including payment instructions, trust or client account directions, invoices, remittance details, correspondence approving payments, and customer-provided transaction documents
  • Suspicion-related working papers and internal escalation records, stored securely with very restricted access so you do not risk tipping off a client

For most bookkeepers, the practical process is simple. First, decide which of your services are designated services and separate them from ordinary bookkeeping work that is not captured. Next, set up one client file structure for AML/CTF records: onboarding, ownership and control, sanctions checks, service instructions, transaction support, and ongoing review. Then apply the right retention period: keep CDD records for 7 years after the business relationship ends, and keep transaction records for at least 7 years from the date the transaction was completed. If you rely on another reporting entity for CDD, keep the CDD arrangement and your assessment of that arrangement, and retain those records for the required period.

Two mistakes bookkeepers make

Do not assume your normal accounting software archive is enough. AML/CTF records must show why you were comfortable with the client, who really owned or controlled the entity, what checks you performed, and how you handled risky instructions. Also, electronic payments do not trigger threshold transaction reports, but records of those payments still need to be kept if they relate to a designated service.

A common misconception for bookkeepers is that if you do not take cash, record keeping is minimal. That is wrong. Physical cash matters for TTRs, but record keeping applies much more widely. Another misconception is that you must copy every passport or licence. Under AUSTRAC guidance, you are not required under the Act to copy identification documents if you instead keep a proper record of what you relied on to verify identity, such as document type, number, issuing country or authority, and verification outcome. In practice, bookkeepers should also make sure records can be produced in English, are backed up, and remain accessible even if you change practice management software, payroll platforms, or cloud storage providers.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Do I need to keep AML/CTF records if my bookkeeping business only does BAS, payroll, and data entry?
Not necessarily. The AML/CTF obligation only applies if you provide a designated service, and not every bookkeeping service is designated. If your work is limited to ordinary bookkeeping tasks and does not involve a designated service, this record-keeping obligation under the AML/CTF Act does not apply for that work.
Can I store everything in Xero, MYOB, or my document management system?
Yes, if the system lets you keep full and accurate records securely for the full retention period and retrieve them quickly. You also need to keep records in the format you usually use where possible, protect sensitive files from unauthorised access, and make sure backups remain available if you change software.
Do I have to keep copies of clients’ passports and driver licences?
No. AUSTRAC guidance says you are not required under the Act to copy identification documents if you keep a record of what you did to identify the customer and what information they provided. Many bookkeepers will still choose to keep copies where another law, engagement terms, or internal process requires it.
What if I stop acting for a client but still have old payment instructions and correspondence?
Keep them for the full retention period. CDD records must be kept for 7 years after the relationship ends, and transaction records must be kept for at least 7 years from the date of the transaction. Do not delete old email approvals, invoice instructions, or payment direction records just because the client has left.
Is there a low-cost way for a small bookkeeping practice to manage this properly?
Yes. Most small firms can do this with a structured folder system, a simple record-keeping policy, restricted user permissions, and automatic cloud backups rather than buying specialist AML software straight away. The main cost is usually staff time spent filing records consistently and making sure designated-service files are separate from ordinary bookkeeping jobs.