AML Compliance Guide

Record keeping (7 years) for Conveyancers — 2026 AUSTRAC Guide

If your conveyancing practice provides a designated service from 1 July 2026, you must keep AML/CTF records for 7 years. For conveyancers, that usually means records tied to property settlements, funds handling, customer identity checks, sanctions screening, and your AML/CTF program. If you cannot produce complete records, AUSTRAC can treat that as a compliance failure, and civil penalties can reach $33.5 million per contravention. Criminal penalties also apply for intentional contraventions.

This obligation is not just about filing documents away. You must create full and accurate records, keep them secure, and be able to retrieve them quickly if AUSTRAC asks for them. For a conveyancer, the core records are: AML/CTF program documents, customer due diligence records, and transaction records related to each designated service. Transaction records must be detailed enough to reconstruct what happened in a property matter, including key dates, amounts, payer and payee details, account identifiers, payment method, contracts, authorities, settlement statements, and any payment instructions the client gave you.

What a conveyancing practice should keep

  • CDD records for each client: what you did to verify identity, what information the client gave you, and the details taken from passports, driver licences or other government ID
  • Entity records for company or trust clients: ASIC checks, ABN or ACN, trustee details, trust deed information, and beneficial owner details for anyone holding 25% or more or exercising effective control
  • Property transaction records: contracts of sale, signed authorities, settlement figures, source and destination account details, deposit and balance payment records, and any customer-provided payment instructions or signed directions
  • AML/CTF records: your written risk assessment, AML/CTF program, senior management approvals, staff training records, sanctions screening results, and records explaining any enhanced due diligence or suspicious matter decisions

A practical way to handle this is to build record keeping into your file-opening and settlement process. At onboarding, save identity verification notes, ASIC extracts, trust records, beneficial owner information and sanctions screening results in the matter file. During the transaction, keep every settlement authority, bank detail confirmation, source-of-funds explanation, and client instruction that relates to movement of money or property. After settlement, lock the file so records cannot be altered casually, and diarise the destruction date based on the right retention rule: CDD records for 7 years after the business relationship ends, transaction records for 7 years from when the record was created or the customer gave it to you, and AML/CTF program records for the required 7-year period.

Two mistakes conveyancers make

First, keeping only copies of IDs and not recording how identity was verified. AUSTRAC says you do not have to copy the ID under the Act, but you do need records of what you did and what details were used. Second, saving the contract and settlement statement but not the client’s payment directions, amended bank details, or email instructions. Customer-provided transaction documents must also be kept.

Do not assume your practice management system solves this by itself. Check that emails, text messages, portal messages, voice notes and scanned authorities linked to trust payments or settlement instructions are captured and searchable. Keep records in English, or in a form that can be easily translated into English. Store sensitive records securely, limit access to authorised staff, and back up electronic files to an offsite or encrypted cloud system. If you rely on a third party to carry out CDD, you must assess whether they are doing it properly, prepare a record of that assessment within 10 business days, and keep both the assessment record and the CDD arrangement for the required retention period.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Do I need to keep a copy of every passport or driver licence I sight?
No. Under the Act, you are not required to copy identification documents just to meet AML/CTF record-keeping rules. You must keep a record of what information the client provided and what you did to verify identity, such as passport number, issuing country, expiry date, and the method you used. If another law or your insurer requires copies, that is a separate issue.
When does the 7-year period start for a conveyancing file?
It depends on the record type. Customer due diligence records must be kept for 7 years after the business relationship ends. Transaction records must be kept for 7 years from the day the record was created, and customer-provided transaction documents for 7 years from the day the client gave them to you.
If a matter falls over before settlement, do I still have to keep the AML/CTF records?
Yes, if you carried out CDD or collected transaction-related documents while providing a designated service. Failed or aborted property matters can still be relevant to AUSTRAC, especially where there were unusual instructions, changing parties, or concerns about source of funds. Keep the records for the normal retention period.
Can I store everything electronically, or do I need paper files?
You can store records electronically. AUSTRAC accepts hard copy or electronic storage, on-site or offsite, as long as the records are complete, secure, and easily retrievable. Keep them in their original or usual format where possible, so a spreadsheet stays a spreadsheet and an email stays an email.
What if I outsource ID checks to a verification provider or rely on another reporting entity?
You still remain responsible for compliance. If you rely on third-party CDD, you must assess whether they are properly carrying out the process, make a record of that assessment within 10 business days, and keep that record for 7 years after it is prepared. You should also keep the agreement showing who does what and when.