Articles
0
MIN READ

Seven years on the clock: what AML/CTF record-keeping means for Australian law firms

Share

Author

Olivia Goodey
Olivia Goodey
,
Business Development Manager

Table of Contents

Find out how we can help you onboard clients faster
Book a demo

Australian law firms that provide newly regulated services have now been inside the anti-money laundering and counter-terrorism financing (AML/CTF) regime for more than three months. Enrolment with AUSTRAC (the Australian Transaction Reports and Analysis Centre, the national AML/CTF regulator) was the first hurdle. The quieter, longer-running obligation is record-keeping: what a firm must keep, for how long and in what form.

The rules sit in the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (the AML/CTF Act). As Gilbert + Tobin notes, the amending reforms generally commenced on 31 March 2026, or 1 July 2026 for newly regulated entities. This article draws on AUSTRAC's record-keeping overview, last updated on 27 March 2026, to explain the core requirements.

The records you must keep

According to AUSTRAC, the Act requires several distinct types of record, each with its own trigger and retention period.

AML/CTF program records are records reasonably necessary to show the firm is meeting its program obligations (s 116(1)). In practice, this points to the written risk assessment, program documents, training logs and the compliance officer's appointment.

Customer due diligence (CDD) records (s 111) cover the customer information collected, the steps taken to verify it, and the analysis of money laundering and terrorism financing (ML/TF) risk that determined the level of CDD applied.

Transaction records (s 107(1)) must contain enough detail to fully and accurately reconstruct the transaction. Documents the customer provides, such as signed contracts, order forms and payment instructions, are covered separately by s 108.

Third-party CDD records apply where a firm relies on another party's due diligence. AUSTRAC points to ss 37B, 111, 114 and 114A, and says the firm must assess whether the third party is properly carrying out that process and keep a record of the assessment.

The seven-year rule, and when the clock starts

The headline retention period is seven years, but the start date differs by record type.

  • Program records: from when the record is made until seven years after it is no longer relevant to showing compliance (s 116(3)).
  • CDD records: seven years from when an occasional transaction is completed or the business relationship ends (s 111(2)).
  • Transaction records: seven years from the day the record is created (ss 107 and 108(2)).
  • Customer-provided documents: seven years from the day the firm was given them (s 108(2)).
  • Third-party CDD assessments: prepared within 10 business days of completing the assessment and kept for seven years after the record is prepared.

This matters for law firms because the CDD clock does not start while a client relationship is ongoing. In AUSTRAC's worked example, a business relationship runs from 7 February 2027 to 5 April 2029, and the records must be kept until 4 April 2036. Matter closure and retainer end dates therefore need to be captured reliably, not assumed.

Format, language and storage

AUSTRAC says records may be hard copy or electronic, held at the firm's premises or offsite, but should be kept in their original format or the format the firm usually uses. Program and CDD records must be in English or in a format that can easily be accessed and translated into English. Sensitive records should be stored securely, with access limited to authorised staff, and all reporting entities must comply with the Privacy Act 1988 (Cth).

One point that often surprises practitioners is that the AML/CTF Act does not require firms to copy identity documents provided as part of CDD. AUSTRAC notes that other laws may still impose that duty. Firms can meet their record-keeping obligations themselves or through an external provider.

What this means for law firms

Law firms already hold extensive file records, but AML/CTF retention is a different test. A closed matter file destroyed under a firm's ordinary retention policy may still contain CDD or transaction records that must be kept longer. Conversely, keeping everything indefinitely creates its own privacy exposure.

Firms also need to be able to retrieve records quickly. Record-keeping is closely tied to a firm's ability to show its program works if AUSTRAC asks. Some firms use platforms, including Legl, to keep CDD evidence and risk assessments consistently stored and linked to the client and matter.

Older files need a check too. AUSTRAC notes that solicitors may have additional record-keeping obligations for transactions that occurred before 7 January 2025, the date the Financial Transaction Reports Act 1988 (Cth) was repealed.

Key takeaways

  • Map each record type to its trigger. Program, CDD, transaction, customer-document and third-party records start their seven-year clocks at different points.
  • Align your retention policy. Check that matter-closure destruction schedules do not delete AML/CTF records early.
  • Record the verification details. Capture how identity was verified, rather than assuming a copy of the document is required.
  • Secure and limit access. Treat AML/CTF records as sensitive and keep them in English or an easily translated format.
  • Test retrieval. Run a periodic check on how quickly your compliance officer can produce a complete client CDD file.

Looking ahead

With enrolment behind the profession, regulatory attention is likely to shift from who has enrolled to whether programs work in practice, and records are the first evidence AUSTRAC would ask to see. Watch for further AUSTRAC guidance for the legal sector and any enforcement outcomes involving record-keeping failures.

This article is general information, not legal advice. Firms should confirm requirements against the current legislation.

Sources