If your trust and company service provider business gives a designated service from 1 July 2026, you must keep AML/CTF records for 7 years. This applies because your work often involves forming companies, acting as a registered office, arranging nominees, or providing trustee and company administration services that can be used to hide who really owns or controls assets. If you cannot produce complete records, AUSTRAC can treat that as a breach of the Act, with civil penalties up to $33.5 million per contravention, and criminal penalties for intentional contraventions.
Your AML/CTF obligations
For a trust and company service provider, record keeping is not just filing IDs in a folder. You must make and keep records that show how you met your AML/CTF obligations and records that let a regulator reconstruct each designated service you provided. That usually includes your AML/CTF program documents, your customer due diligence records, and transaction records connected to the service. AUSTRAC expects records to be full, accurate, secure, and kept in their original format or the format you usually use, such as spreadsheet files, emails, signed engagement documents, corporate registers, payment instructions, trust deeds, and onboarding notes.
What you should keep for each client matter
A practical process is simple. First, decide which of your services are designated services, because not every corporate or advisory task will be. Next, build a file checklist for each matter so your team captures the same records every time at onboarding, during the relationship, and when changes happen. Then store those records in a system that keeps them searchable and retrievable, with restricted access for sensitive material such as beneficial ownership documents and suspicious matter reporting records. Keep CDD records for 7 years after the business relationship ends. Keep transaction records for 7 years from the day the record is created, and customer-provided transaction documents for 7 years from the day the client gave them to you.
Do not rely on your usual corporate files
Many trust and company service providers already keep ASIC forms, trust deeds and client instructions. That does not automatically meet AML/CTF record keeping duties. You also need records that show why you assessed the client as low, medium or high risk, what checks you performed, whether a beneficial owner could not be verified, and what extra steps you took for PEPs, unusual structures or high-risk jurisdictions.
Common mistakes for this profession
Set up your record keeping so it works across all Australian offices and remote staff. Keep records in English, or in a format that can be easily translated into English. Back up electronic records securely, limit access by role, and make sure you can quickly pull a complete file if AUSTRAC asks for it. For small TCSP practices, the easiest approach is a standard matter structure: client identity, beneficial ownership, risk assessment, screening, approvals, service instructions, transaction documents, and closure date. That gives you a clear retention trigger and reduces the risk that records end up split across email inboxes, company secretarial software, and personal devices.
A lightweight AML platform, built exclusively for Tranche 2
Get AUSTRAC's mandates done as fast and effortless as possible.