AML Compliance Guide

Record keeping (7 years) for Financial adviserss — 2026 AUSTRAC Guide

If your financial advice business provides a designated service from 1 July 2026, you must keep AML/CTF records for 7 years. For financial advisers, this usually means records tied to client onboarding, identity checks, beneficial ownership, risk decisions, sanctions screening, transaction activity and your AML/CTF program. If you cannot produce proper records, AUSTRAC can treat that as a compliance failure in its own right, with civil penalties up to $33.5 million per contravention and criminal penalties for intentional breaches.

Record keeping is not just filing papers away. You must create full and accurate records, store them securely, and be able to retrieve them quickly. AUSTRAC’s guidance says the records must be reasonably necessary to show you are meeting your customer due diligence and AML/CTF program obligations, and sufficient to reconstruct individual transactions related to a designated service. For a financial advice practice, that can include client fact-finds used for AML purposes, identification details from passports or licences, ASIC extracts for company clients, trust deed details, beneficial owner checks, sanctions screening results, senior manager approvals, internal risk ratings, file notes about unusual instructions, and transaction records linked to moving money into or out of Australia on behalf of a client.

What your practice should keep and for how long

  • CDD records: keep for 7 years after the business relationship ends, including what documents or databases you relied on to verify the client
  • Transaction records for designated services: keep for 7 years from the date the transaction was completed
  • AML/CTF program documents, risk assessments, training records, screening logs and approvals: keep for 7 years so you can show how your controls operated over time
  • If you use a third party to perform CDD, keep the CDD arrangement and your assessment of that provider; the assessment record must be made within 10 business days after the assessment and kept for 7 years after it is prepared

For a small advice practice, the safest process is straightforward. First, decide exactly which advice or related services you provide are designated services, because record keeping only attaches to those services. Second, build a record keeping procedure into your client onboarding and review workflow so identity checks, sanctions screening, beneficial ownership checks and risk ratings are captured at the time they happen. Third, keep records in their original format where possible: if you screen a client in software, keep the native system record or export, not just a screenshot dropped into a PDF file. Fourth, make sure emails, CRM notes, file notes, adviser review memos and approval records are stored in one retrievable place. Fifth, lock down access to sensitive client records, especially SMR-related material, and back up electronic files to a secure offsite or encrypted cloud environment.

A common mistake in advice practices

You do not have to photocopy every ID document under the AML/CTF Act. AUSTRAC’s guidance says you must keep records of what you did to verify identity and what information the client provided. For example, if you verified a passport, record the passport details and the verification steps. If another law or your licensee requires copies, that is separate.

The weak spots for financial advisers are usually scattered systems and over-reliance on paraplanners, admin staff or platform providers. If client identity details sit in the CRM, sanctions results sit in a separate screening tool, trust documents are in email, and file notes are on an adviser’s laptop, your records are not truly manageable. Another trap is assuming ordinary advice documents automatically satisfy AML/CTF requirements. They may help, but only if they clearly show what checks were done, when, by whom, and what decision was made. Treat record keeping as evidence: if AUSTRAC asked you in 2029 why you accepted a high-net-worth offshore client into an investment structure, your file should show the identity checks, beneficial ownership analysis, sanctions screening, risk assessment, any enhanced due diligence, and the relevant transaction trail.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Do I need to keep copies of every client passport and driver licence?
No. Under AUSTRAC guidance, you are not required by the AML/CTF Act to copy the identification document itself. You must keep records of the information you used and the steps you took to verify the client’s identity. If your AFSL, licensee, platform or another law requires copies, that is a separate requirement.
When does the 7-year period start for a financial advice client?
It depends on the record type. CDD records are kept for 7 years after the business relationship ends. Transaction records are kept for 7 years from the date the transaction was completed, and AML/CTF program records should be kept for 7 years so you can demonstrate compliance over time.
Can I rely on my platform, custodian or external admin provider to keep the records for me?
You can use an external provider to help with storage or process, but the obligation still sits with your business if you are the reporting entity. You need to be confident the records are complete, secure and retrievable. If you rely on a third party for CDD, you also need a proper arrangement and records of your assessment of that provider.
What if I only advise on investments and never handle cash?
You may still have record keeping obligations if you provide a designated service. The obligation is not limited to cash handling. For financial advisers, the key issue is whether the service falls within the designated services regime, and if it does, you must keep the relevant CDD, program and transaction records.
What is the cheapest practical way for a small advice practice to comply?
Usually it is cheaper to use your existing CRM and document management system properly than to buy several separate tools. Create mandatory fields for identity verification, beneficial ownership, sanctions screening outcome, risk rating and reviewer sign-off, then set retention and backup rules across the whole file. The main cost is disciplined setup and staff training, not necessarily new software.