If your financial advice business provides a designated service from 1 July 2026, you must keep AML/CTF records for 7 years. For financial advisers, this usually means records tied to client onboarding, identity checks, beneficial ownership, risk decisions, sanctions screening, transaction activity and your AML/CTF program. If you cannot produce proper records, AUSTRAC can treat that as a compliance failure in its own right, with civil penalties up to $33.5 million per contravention and criminal penalties for intentional breaches.
Your AML/CTF obligations
Record keeping is not just filing papers away. You must create full and accurate records, store them securely, and be able to retrieve them quickly. AUSTRAC’s guidance says the records must be reasonably necessary to show you are meeting your customer due diligence and AML/CTF program obligations, and sufficient to reconstruct individual transactions related to a designated service. For a financial advice practice, that can include client fact-finds used for AML purposes, identification details from passports or licences, ASIC extracts for company clients, trust deed details, beneficial owner checks, sanctions screening results, senior manager approvals, internal risk ratings, file notes about unusual instructions, and transaction records linked to moving money into or out of Australia on behalf of a client.
What your practice should keep and for how long
For a small advice practice, the safest process is straightforward. First, decide exactly which advice or related services you provide are designated services, because record keeping only attaches to those services. Second, build a record keeping procedure into your client onboarding and review workflow so identity checks, sanctions screening, beneficial ownership checks and risk ratings are captured at the time they happen. Third, keep records in their original format where possible: if you screen a client in software, keep the native system record or export, not just a screenshot dropped into a PDF file. Fourth, make sure emails, CRM notes, file notes, adviser review memos and approval records are stored in one retrievable place. Fifth, lock down access to sensitive client records, especially SMR-related material, and back up electronic files to a secure offsite or encrypted cloud environment.
A common mistake in advice practices
You do not have to photocopy every ID document under the AML/CTF Act. AUSTRAC’s guidance says you must keep records of what you did to verify identity and what information the client provided. For example, if you verified a passport, record the passport details and the verification steps. If another law or your licensee requires copies, that is separate.
The weak spots for financial advisers are usually scattered systems and over-reliance on paraplanners, admin staff or platform providers. If client identity details sit in the CRM, sanctions results sit in a separate screening tool, trust documents are in email, and file notes are on an adviser’s laptop, your records are not truly manageable. Another trap is assuming ordinary advice documents automatically satisfy AML/CTF requirements. They may help, but only if they clearly show what checks were done, when, by whom, and what decision was made. Treat record keeping as evidence: if AUSTRAC asked you in 2029 why you accepted a high-net-worth offshore client into an investment structure, your file should show the identity checks, beneficial ownership analysis, sanctions screening, risk assessment, any enhanced due diligence, and the relevant transaction trail.
A lightweight AML platform, built exclusively for Tranche 2
Get AUSTRAC's mandates done as fast and effortless as possible.