AML Compliance Guide

Record keeping (7 years) for Virtual asset service providerss — 2026 AUSTRAC Guide

If your virtual asset service provider business provides a designated service in Australia, you must keep AML/CTF records for 7 years. For a VASP, that means records that show who your customer was, what service you provided, and enough transaction detail to reconstruct crypto-to-fiat, crypto-to-crypto, custody, transfer or other relevant activity. If you cannot produce those records when AUSTRAC asks, you may be treated as non-compliant with the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth), with civil penalties of up to $33.5 million per contravention and criminal penalties for intentional breaches.

Record keeping is not just saving a few screenshots from your platform. You must make and keep records that are reasonably necessary to show you are meeting your AML/CTF obligations, and records that are sufficient to reconstruct each designated service transaction. For a VASP, that usually includes customer onboarding records, wallet and account identifiers, blockchain transaction hashes, fiat funding details, timestamps, asset type and amount, recipient details where available, internal approval records, sanctions screening results, and any customer-provided transaction documents such as signed instructions, order forms or transfer requests.

What your VASP should do in practice

  • Map which of your services are designated services and set a recordkeeping rule for each one.
  • Keep AML/CTF program records, CDD records and transaction records in one retrievable system, even if trading, custody and onboarding sit in different platforms.
  • For each transaction, capture enough detail to fully and accurately reconstruct it: date and time, customer identifier, wallet address or account reference, asset, quantity, value, payment method, recipient details and transaction hash or unique identifier.
  • Keep customer-provided transaction records for 7 years from the day the customer gave them to you, not from the later transaction date.
  • Retain CDD records for 7 years after the business relationship ends, and keep transaction records for 7 years from when the record was created or the transaction was completed.

Format and storage matter

AUSTRAC expects records to be kept in their original format or the format you usually use. If your exchange data sits in CSV, database tables, wallet logs, API logs or chat-based support records, keep them in a form that preserves structure and usability. Records should be in English, or easily translated into English, securely stored, backed up, and accessible quickly if AUSTRAC requests them.

A common mistake for VASPs is assuming the blockchain is the record, so the business does not need to keep its own files. On-chain data alone is not enough because it usually does not show the customer behind the wallet, the reason for the transfer, internal risk decisions, linked fiat movement, or documents the customer provided. Another mistake is keeping only front-end transaction summaries and not preserving raw system logs, support tickets, sanctions alerts, or manual review notes that explain how a suspicious transfer, unusual wallet pattern or PEP escalation was handled.

Practical controls that work for VASPs

  • Link wallet addresses, customer profiles and case management records so a reviewer can follow the full path of a transaction from onboarding to settlement.
  • Archive blockchain analytics results, sanctions matches and enhanced due diligence notes against the relevant customer or transfer.
  • Set retention rules across all systems, including cloud storage, exchange engines, helpdesk tools, messaging platforms and outsourced custody providers.
  • Test retrieval by pulling a sample customer file and a sample transaction file end-to-end.
  • Restrict access to sensitive records such as SMR-related material and dispose of records securely when the retention period ends.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Do we need to keep records if the transaction is visible on a public blockchain?
Yes. Public blockchain data does not replace your AML/CTF recordkeeping duties. You still need records showing the customer, the designated service provided, any linked fiat movement, internal decisions, and enough information to reconstruct the transaction in your own systems.
What if we use an overseas custody provider or exchange infrastructure vendor?
You can use an external provider, but your business still has to make sure the records are kept and can be produced. Build this into your contracts, confirm retention periods, and make sure you can retrieve records quickly in English or in a format that can be easily translated into English.
When does the 7-year period start for VASP records?
It depends on the record type. Customer due diligence records are kept for 7 years after the relationship ends. General transaction records are kept for 7 years from the day the record is created or from the date the transaction was completed, and customer-provided transaction documents are kept for 7 years from the day the customer gave them to you.
Do we have to keep chat messages, support tickets and compliance notes?
If those records help show how you met your AML/CTF obligations or help reconstruct a transaction, keep them. For a VASP, support chats about wallet changes, transfer instructions, account access issues, sanctions escalations or unusual transaction reviews can all be relevant records.
Is there a low-cost way for a small VASP to handle this properly?
Yes, if you design it early. Use a single retention policy, centralise customer and transaction identifiers across systems, automate exports from trading and wallet platforms, and back up records to secure cloud storage. The cheapest approach is usually consistent system design, because reconstructing missing records later is slow, expensive and risky.