AML/CTF reforms: What they mean for records management

Most conversations about Australia’s AML/CTF reforms focus on customer due diligence, risk assessments and reporting obligations. That is understandable. But it misses a critical point. The success of an AML/CTF program depends heavily on the quality of the records behind it.

If an organisation cannot find, secure, retrieve, explain and defensibly dispose of the information needed to demonstrate compliance, then compliance becomes difficult to prove. That makes records management and information governance central to Australia’s amended AML/CTF regime, not supporting activities sitting somewhere in the background. 

From 2026, the expanded AML/CTF regime affects existing reporting entities and newly captured Tranche 2 businesses, including real estate, legal, accounting, conveyancing, trust and company service providers, and dealers in precious metals and stones. These organisations face obligations around customer due diligence, reporting and seven-year recordkeeping. For many of these organisations, the biggest challenge will not be understanding that records must be kept.

The bigger challenge will be managing those records properly.

AML/CTF compliance is only as strong as the records behind it

AML/CTF compliance is evidence-based. It relies on an organisation being able to show what was done, when it was done, who made the decision, what information was relied on, how risk was assessed and how obligations were met. That means records must do more than exist. They need to be accurate, secure, accessible, auditable and governed throughout their lifecycle. 

Under the reformed AML/CTF framework, reporting entities must manage records relating to customer due diligence, AML/CTF programs, risk assessments, transactions, reports to AUSTRAC, governance decisions, independent evaluations, training and personnel due diligence. 

These are not just administrative records. They are compliance evidence. If they are scattered across inboxes, unmanaged shared drives, local folders, legacy systems or inconsistent onboarding processes, the organisation’s ability to demonstrate compliance becomes weaker.

The seven-year rule is not as simple as it sounds

Many organisations will hear “seven-year recordkeeping” and assume the task is straightforward. It is not.
The AML/CTF reforms introduce different retention triggers for different record types.

Customer due diligence records must be kept for seven years after the customer relationship ends. Transaction records must be kept for seven years after the transaction. AML/CTF program records must be kept from when the record is made until seven years after the record is no longer relevant to demonstrate compliance.

That final trigger is particularly important.
It requires organisations to make a defensible judgment about when a record is no longer relevant. This is a governance decision, not just an administrative one. A basic retention rule will not be enough.

Organisations will need retention schedules that distinguish between customer due diligence records, transaction records, program records, reporting records, training evidence, governance documentation and risk assessment materials.
They will also need disposal processes that can show when information was destroyed, why it was destroyed and who authorised the action.

Without that structure, organisations risk two problems: disposing of records too early or keeping personal information longer than necessary. Both create compliance risk.

“Keep everything” is no longer a defensible strategy

For years, many organisations have treated over-retention as the safer option. Keep everything, just in case. That approach is increasingly risky. One of the most significant information governance implications of the AML/CTF reforms is the tension between legal retention obligations and privacy-driven disposal obligations.

From 31 March 2026, organisations are no longer required to retain copies of full identity documents for AML/CTF purposes. Instead, they need to keep sufficient information to demonstrate that customer identification and verification took place.
At the same time, Australian Privacy Principle 11.3 requires personal information to be destroyed or de-identified when it is no longer needed, unless retention is required by law.

This creates a practical challenge for records managers, privacy officers and compliance teams:

  • What information must be kept?
  • What information should be destroyed?
  • How can those decisions be documented?

This is where “keep everything” becomes a liability rather than a safeguard. Organisations need to understand which data points are required to demonstrate compliance, which copies or supporting documents are unnecessary, and when personal information should be destroyed or de-identified.
Good records management is not about keeping more. It is about keeping the right information for the right reason, for the right period of time.

Access controls matter, especially for sensitive AML/CTF records

AML/CTF records can contain sensitive customer information, due diligence material, risk assessments, reporting decisions and suspicious matter reporting information. That makes access control a core records management issue.

The reformed tipping-off offence commenced on 31 March 2025 and focuses on disclosures that could reasonably be expected to prejudice an investigation. For information management, this creates a clear need to restrict access to sensitive AML/CTF records, including suspicious matter reporting and customer due diligence information.

Records should not be accessible simply because someone has access to a shared drive, inbox or client folder.
Organisations need controls that reflect the sensitivity of the information. That includes role-based access, secure storage, audit trails, version control and clear ownership of AML/CTF records.

If access to sensitive information cannot be explained or controlled, the organisation has an information governance problem.

Tranche 2 businesses cannot afford informal records practices

For many newly captured Tranche 2 businesses, AML/CTF compliance will expose weaknesses in current records management practices. Legal, accounting, conveyancing, real estate and related professional services organisations may have client information spread across email chains, matter folders, practice management systems, shared drives and paper files. That creates a challenge.

AML/CTF obligations require records to be secure, retrievable, auditable and available in English or readily convertible to written English. AUSTRAC also expects records to be kept in their original or usual format, such as keeping an Excel file as a spreadsheet rather than converting it to PDF.

This is not compatible with inconsistent storage habits, unclear ownership or ad hoc filing practices. A template AML/CTF policy will not fix poor information governance.
Organisations need to understand where AML/CTF records are created, where they are stored, who owns them, who can access them and how they can be retrieved when needed.

Records management is becoming a front-line compliance capability

The AML/CTF reforms should change how organisations think about records management.
This is no longer just about filing, storage or retention. It is about the ability to prove compliance, protect sensitive information and reduce regulatory risk.
Strong AML/CTF records management should answer practical questions:

  • What AML/CTF records are we required to create and keep?
  • Where are customer due diligence records stored?
  • How are risk assessments and program documents version-controlled?
  • Who can access suspicious matter reporting records?
  • Can we retrieve records quickly if AUSTRAC requests them?
  • Are records stored securely and auditable?
  • When does the seven-year retention period begin for each record type?
  • What personal information should be destroyed or de-identified?
  • Can we prove disposal decisions were authorised?

If these questions are difficult to answer, the issue is not only compliance. It is governance maturity.

What organisations should do now

Organisations affected by the AML/CTF reforms should not treat records management as an afterthought. They should review their information environment as part of AML/CTF readiness.
Practical priorities include:

  1. Map AML/CTF record types
    Identify the records required for customer due diligence, transactions, reporting, risk assessment, governance, training and independent evaluation.
  2. Build a retention schedule
    Distinguish between the different seven-year triggers for customer due diligence records, transaction records and AML/CTF program records.
  3. Strengthen access controls
    Restrict access to sensitive customer due diligence and suspicious matter reporting information to appropriate personnel.
  4. Review privacy obligations
    Update processes for collection notices, consent where relevant, destruction, de-identification and management of identity document copies.
  5. Improve auditability
    Ensure records can show when decisions were made, what information was relied on, who approved actions and when records were reviewed or disposed of.
  6. Reduce reliance on unmanaged locations
    Review the use of email chains, shared drives, local folders and inconsistent onboarding processes for AML/CTF-related records.
  7. Document governance decisions
    Version-control AML/CTF policies, risk assessments, senior management approvals, remediation actions and independent evaluation materials.

The real issue is information governance

AML/CTF compliance is becoming an information governance test.

  • Can the organisation see what information it holds?
  • Can it classify sensitive records?
  • Can it control access?
  • Can it retain information for the correct period?
  • Can it destroy information when it is no longer required?
  • Can it prove the decisions it has made?


These are records management and information governance questions. They sit directly within Grace Information’s Governance Clarity approach, which helps organisations gain visibility, control and confidence across the information environment.
You cannot govern information you cannot see. And you cannot prove compliance with records you cannot find, trust or control.

Final thoughts

Australia’s AML/CTF reforms are not just changing the compliance obligations of affected organisations. They are raising the standard for how sensitive information must be managed.
For records managers, privacy teams, compliance leaders and executives, the message is clear: AML/CTF readiness requires more than policies and procedures.

It requires disciplined records management, secure information handling, defensible disposal and strong information governance.
Organisations that address these foundations early will be better placed to meet their obligations, reduce risk and respond confidently when records are required.

Need to understand whether your records management environment is ready for AML/CTF obligations?
Grace Information helps organisations gain clarity, control and confidence across their information environment through practical records management, information governance and compliance-focused advisory services.

FAQs

What do AML/CTF reforms mean for records management?
AML/CTF reforms mean organisations must be able to create, retain, secure, retrieve and dispose of records that demonstrate compliance. This includes customer due diligence records, transaction records, AML/CTF program records, risk assessments, governance records, reporting records and training evidence.

Customer due diligence records must be kept for seven years after the customer relationship ends. Transaction records must be kept for seven years after the transaction. AML/CTF program records must be kept until seven years after they are no longer relevant to demonstrate compliance.

From 31 March 2026, organisations are no longer required to retain copies of full identity documents for AML/CTF purposes. They should keep sufficient information to demonstrate that identity verification occurred.

AML/CTF obligations require certain records to be retained, while Australian Privacy Principle 11.3 requires personal information to be destroyed or de-identified when it is no longer needed, unless retention is required by law. Organisations need clear governance processes to manage this balance.

Information governance helps organisations understand what records exist, where they are stored, who can access them, how long they must be retained and when they should be disposed of. These controls support AML/CTF compliance by making records secure, retrievable and auditable.

This article is intended to provide general information and commentary on records management, information governance and related regulatory developments. It does not constitute legal, regulatory, compliance or professional advice. Readers should obtain independent advice appropriate to their circumstances before acting on any information contained in this article.

Further reading sources:

Share this

You might also like

Get a moving quote