AML/CTF
AML Records and the Seven-Year Paper Trail Â
Â
Â
A partner asks for the AML file.
The manager finds the client folder. Admin finds an ID check. Someone remembers a conversation about beneficial ownership, but nobody can find the risk rating, approval record or monitoring date.
That is the AML record keeping problem.
Not that firms keep no records. Accounting firms keep records for everything.
The problem is that ordinary client files were not designed to prove AML/CTF compliance.Â
The client file is not the AML file
Most firms already have tax workpapers, ASIC documents, emails, signed engagement letters, and client notes.
That is not the same as a complete AML compliance record.
AML/CTF record keeping has a different purpose. It needs to prove that your firm followed the process before providing a designated service. It needs to show what was checked, who checked it, what was decided, who approved it, and where the evidence sits.
The question is not, âDo we have the client information?â The question is, âCan we prove the AML/CTF workflow was followed?â
That is the gap.
A client file shows the work your firm performed. An AML file shows the compliance decision that allowed the work to proceed.
Both matter. They are not the same thing.
What AML records accounting firms need to keep
 For every designated service file, your firm needs a minimum AML evidence set.
That evidence should include:
- completed scope and trigger check
- CDD documents and verification outputs
- beneficial ownership summary or UBO map
- PEP, sanctions and adverse media screening results, with dates
- risk rating record, including score, tier, rationale and approval
- signed engagement letter with AML/CTF clauses
- monitoring refresh date and event-driven monitoring notes
- internal escalation records, where applicable, stored separately with restricted access
This is where many firms get exposed.
They may have collected identity information. They may have checked an ASIC extract. They may have discussed the client at partner level.
But if the file does not show the trigger check, CDD evidence, beneficial ownership assessment, screening date, risk rating, approval and monitoring cadence, the AML record is incomplete.
It does not matter that the client has been with the firm for 20 years. It does not matter that no red flags are visible. It does not matter that the partner is comfortable.
The file still needs to tell the story.
The seven-year AML record retention problemÂ
AML/CTF records must be retained for a minimum of seven years from the date the record is created, or the engagement concludes, whichever is later.
That sounds simple until you test it inside a real firm.
Seven years is longer than many staff stay in the same role. It is longer than many firms keep the same software stack. It is long enough for folders to be renamed, systems to be migrated, and informal habits to disappear.
That is why seven-year AML record retention is not just a storage issue. It is a systems issue.
Your firm needs:
- one agreed AML evidence location
- a consistent naming convention
- secure access rules
- a clear archive process
- a policy for retaining records for the required period
- a process for retrieving records when requested
If only one person knows where records are stored, the firm does not have a system. It has a huge risk.
Sight it or store it?
Do we need to store copies of client identity documents, or is it enough to sight and verify them?
This is one area where firms need to be careful.
Firms need to be able to prove that identity was sighted, verified, and recorded. If verification is completed through a digital process, the time-stamped receipt or report should be retained as evidence. If ID is sighted in person, the firm still needs a clear record of what was sighted, when it was sighted, who verified it and the outcome of that verification.
The unresolved practical question is exactly how each firm should balance copies of original ID documents, verification outputs, privacy risk, and secure storage.
Do not leave it to individual staff judgement.
Create a written firm policy that states:
- What identity evidence is collected.
- Whether copies of original ID documents are retained.
- What verification outputs are stored.
- Where those records are stored.
- Who can access them.
- How long they are retained.
- When the AML/CTF Compliance Officer must be consulted.
This is not a place for personal preference. It is a place for firm-wide standards.
Â
Restricted access AML records
Most AML evidence can sit in the firmâs agreed AML compliance location for the client.
Escalation records are different.
If a concern is escalated to the AML/CTF Compliance Officer, those records should be stored in a separate restricted-access file. Not in the ordinary client file. Not in a general team folder. Not in a place where staff without a need to know can infer that a client is under internal review.
That restricted file may contain:
- the original concern raised by the staff member
- the AML/CTF Compliance Officerâs assessment
- the decision to lodge or not to lodge an SMR
- the decision to continue, pause or cease work
- review notes if the matter remains ongoing
This came up directly in our live sessions. Firms were asking where to store sensitive records, how to lock down access, and how to avoid creating unnecessary internal visibility.
The practical rule is simple.
Normal AML records go in the normal AML evidence location. Escalation records go in a restricted-access location.
Different purpose. Different access. Different risks.Â
Facts only in escalation records
Escalation records need discipline.
The staff member raising a concern should record facts, not conclusions.
Not this: âI think the client is laundering money.â
This: âThe client refused to provide the shareholder register after three requests. They asked whether the firm could proceed first and said the ownership details were ânot relevantâ. The client also asked for the structure to be completed before the end of the week.â
That second version is useful.
It gives the AML/CTF Compliance Officer something to assess. It avoids speculation. It protects the staff. It creates a cleaner record.
A good internal escalation record should capture:
- client name and file reference
- staff member raising the concern
- date and time
- description of the concern, facts only
- relevant documents or observations
- AML/CTF Compliance Officer assessment
- SMR lodged or not lodged, with reasons
- engagement decision
- review date, if ongoing
This is not about turning accountants into investigators. It is about recording what happened clearly enough for the firm to make a defensible decision.Â
What âretrievable on requestâ really means
AUSTRAC does not just assess whether a firm has an AML/CTF program. It assesses whether the firm can demonstrate that the program is operating.
That makes retrievability part of compliance.
If AUSTRAC asks for records, your firm needs to be able to retrieve them within a reasonable timeframe.
Not after three people search their inboxes.
Not after someone checks an old local drive.
Not after the former practice manager is called to ask where the folder used to be.
A retrievable AML record is one that authorised people can locate quickly, in the expected place, using the firmâs agreed naming convention.
A simple naming convention helps.
For example:
- ClientRef_AML_Onboarding_Date
- ClientRef_AML_RiskRating_Date
- ClientRef_AML_MonitoringReview_Date
- ClientRef_AML_Escalation_Date
The exact format matters less than consistency.
Same record type. Same location. Same naming standards. Every time.Â
The 30-minute AML file test
Here is a practical test for your firm. Pick one designated service client.
Give the team 30 minutes to locate the complete AML record.
Can they find:
- the scope and trigger check?
- the CDD evidence?
- the beneficial ownership summary?
- the screening results with dates?
- the risk rating and approval record?
- the signed engagement letter?
- the monitoring refresh date?
- any escalation record, if applicable, in the restricted location?
If the answer is no, the issue is not effort. It is a system design issue.
The honest question is not whether your firm keeps client records. Of course it does.
The honest question is whether your firm can prove, seven years from now, that it followed the AML/CTF process properly today.
Best Practice Group delivers a turnkey AML/CTF Tranche 2 Training and Certification Program designed specifically for public accounting firms. It includes a complete compliance playbook, two live implementation sessions, 16 operational templates, mandatory compliance assessments, and two certificates per participant issued by Best Practice Group.
Your AML/CTF obligations are live now. If your firm still needs to operationalise effectively, then the time to enrol is now.
đ Register for the AML/CTF Tranche 2 Training Program
đ Get the Free AML Playbook
Or contact us directly:
đ§Â team@bestpracticegroup.com.au
đ 1300 274 636
This article is general guidance only and does not constitute legal advice. Firms should confirm their specific obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and seek independent legal advice where required.
The AML Client Conversation Most Accounting Firms Are Dreading
Coming Soon