AML Compliance Guide

Record keeping (7 years) for Trust and company service providerss — 2026 AUSTRAC Guide

If your trust and company service provider business gives a designated service from 1 July 2026, you must keep AML/CTF records for 7 years. This applies because your work often involves forming companies, acting as a registered office, arranging nominees, or providing trustee and company administration services that can be used to hide who really owns or controls assets. If you cannot produce complete records, AUSTRAC can treat that as a breach of the Act, with civil penalties up to $33.5 million per contravention, and criminal penalties for intentional contraventions.

For a trust and company service provider, record keeping is not just filing IDs in a folder. You must make and keep records that show how you met your AML/CTF obligations and records that let a regulator reconstruct each designated service you provided. That usually includes your AML/CTF program documents, your customer due diligence records, and transaction records connected to the service. AUSTRAC expects records to be full, accurate, secure, and kept in their original format or the format you usually use, such as spreadsheet files, emails, signed engagement documents, corporate registers, payment instructions, trust deeds, and onboarding notes.

What you should keep for each client matter

  • CDD records: identity documents for individuals, ASIC extracts for companies, trust deeds, trustee details, and beneficial owner information showing who owns 25% or more or exercises effective control
  • Risk and decision records: client risk rating, PEP checks, sanctions screening results, enhanced due diligence steps, and any senior management approvals
  • Transaction and service records: incorporation instructions, shareholder and director appointment documents, nominee service records, registered office arrangements, payment instructions, invoices, receipts, contracts, and correspondence that explains what you actually did

A practical process is simple. First, decide which of your services are designated services, because not every corporate or advisory task will be. Next, build a file checklist for each matter so your team captures the same records every time at onboarding, during the relationship, and when changes happen. Then store those records in a system that keeps them searchable and retrievable, with restricted access for sensitive material such as beneficial ownership documents and suspicious matter reporting records. Keep CDD records for 7 years after the business relationship ends. Keep transaction records for 7 years from the day the record is created, and customer-provided transaction documents for 7 years from the day the client gave them to you.

Do not rely on your usual corporate files

Many trust and company service providers already keep ASIC forms, trust deeds and client instructions. That does not automatically meet AML/CTF record keeping duties. You also need records that show why you assessed the client as low, medium or high risk, what checks you performed, whether a beneficial owner could not be verified, and what extra steps you took for PEPs, unusual structures or high-risk jurisdictions.

Common mistakes for this profession

  • Keeping the company file but not keeping evidence of beneficial ownership checks for the natural persons behind layers of entities or trusts
  • Assuming accounting software or practice management notes are enough, when they do not capture sanctions screening, risk assessment updates, or enhanced due diligence decisions
  • Deleting emails, chat messages, scanned IDs or payment instructions after the company is set up, even though those documents may be needed to reconstruct the designated service

Set up your record keeping so it works across all Australian offices and remote staff. Keep records in English, or in a format that can be easily translated into English. Back up electronic records securely, limit access by role, and make sure you can quickly pull a complete file if AUSTRAC asks for it. For small TCSP practices, the easiest approach is a standard matter structure: client identity, beneficial ownership, risk assessment, screening, approvals, service instructions, transaction documents, and closure date. That gives you a clear retention trigger and reduces the risk that records end up split across email inboxes, company secretarial software, and personal devices.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

When does the 7-year period start for our records?
It depends on the record type. CDD records must be kept for 7 years after the business relationship ends. Transaction records must be kept for 7 years from the day the record is created, and customer-provided transaction documents must be kept for 7 years from the day the client gave them to you.
Do we need to keep records if we only helped set up the company and had no ongoing role?
Yes, if what you provided was a designated service. A one-off incorporation, trustee arrangement or similar service can still create record keeping obligations. You must keep the relevant CDD, service and transaction records for the required period even if the client engagement ended quickly.
Can we store everything electronically and destroy the paper copies?
Electronic storage is allowed. AUSTRAC expects you to keep records in their original format or the format you usually use, and to store sensitive records securely. If you scan a signed trust deed or client instruction, make sure the copy is complete, readable, searchable and can be produced quickly if requested.
What if the client is a complex structure with offshore entities and we could not fully verify every beneficial owner straight away?
Keep a record of what information you obtained, what further steps you took, what gaps remained, and who approved the decision on whether to proceed. For a trust and company service provider, that audit trail matters because layered ownership and control structures are a core ML/TF risk. If the risk is high, your enhanced due diligence records should be especially clear.
Will meeting this obligation be expensive for a small TCSP practice?
It does not require a large compliance platform, but it does require a reliable system. Many small practices can meet the obligation by using their existing document management or practice management system, provided it can store AML/CTF records securely, keep them for the full retention period, control access, and retrieve a complete client file quickly. The cost usually comes from setting up a consistent filing process and training staff, not from AUSTRAC charging a record keeping fee.