WhenToDeletePowered by ScheduleOneSearch the register
AML/CTFCommonwealthMinimum retention

Customer due diligence (KYC) records

How long should Australian businesses keep customer due diligence (KYC) records, and when does the clock start?

Keep for7 years
Clock startsThe business relationship endsOr the occasional transaction is completed
Applies toAML/CTF reporting entities

General information, not legal advice or permission to destroy a record. Coverage may be incomplete or out of date. Check the official text, other applicable obligations and any investigations, disputes or legal holds before disposal. Get advice for your situation. Terms of use.

Under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, AML/CTF reporting entities must keep customer due diligence (KYC) records for at least 7 years. Clock starts: the business relationship ends.

Records needed to show compliance with customer due diligence obligations, and records of electronic verification requests.

4 provisions of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 apply to these records. Each one is set out below.

The terms

s 111(2)Anti-Money Laundering and Counter-Terrorism Financing Act 2006
7 years
the business relationship ends or the reporting entity completes the provision of the occasional transaction
s 114(1)Anti-Money Laundering and Counter-Terrorism Financing Act 2006
7 years
that began at a time after Part 2 had that effect; and throughout the whole of which the reporting entity did not provide any designated services to the customer
s 35F(2)Anti-Money Laundering and Counter-Terrorism Financing Act 2006
7 years
that began at a time after the verification request was made; and throughout the whole of which the reporting entity did not provide any designated services to the individual
s 35F(3)Anti-Money Laundering and Counter-Terrorism Financing Act 2006
Destroy or de-identify
must delete the record at the end of the 7 year period referred to in that subsection

Conditions and exceptions Caution

Records of an electronic verification request made to a credit reporting body must be deleted at the end of their 7-year period (s 35F(3)).

From the provisions:

  • Applies where the reporting entity complies with section 28 (initial CDD) or section 30 (ongoing CDD) in relation to a customer to whom it provides or proposes to provide a designated service
  • The first person carried out the initial procedure mentioned in paragraph 37A(1)(a) or 38(b)
  • Part 2 has effect as if the reporting entity complied with paragraph 28(3)(c) or (d)
  • The first person makes a record and gives a copy to the reporting entity
  • The 7-year period must be one throughout which no designated services were provided to the individual

The law

Anti-Money Laundering and Counter-Terrorism Financing Act 2006, s 111(2) · Retention of records of customer due diligenceOfficial text ↗
The reporting entity must retain, until the end of the 7 year period that begins when the business relationship ends or the reporting entity completes the provision of the occasional transaction, records that: (a) are reasonably necessary to demonstrate compliance with the reporting entity's obligations under Part 2; and (b) are in the English language, or in a form in which the records are readily accessible and readily convertible into writing in the English language.
Text as at 1 July 2026
Anti-Money Laundering and Counter-Terrorism Financing Act 2006, s 114(1) · Retention of information if initial customer due diligence taken to have been carried out by a reporting entityOfficial text ↗
the reporting entity must retain the copy until the end of the first 7‑year period: (d) that began at a time after Part 2 had that effect; and (e) throughout the whole of which the reporting entity did not provide any designated services to the customer.
Text as at 1 July 2026
Anti-Money Laundering and Counter-Terrorism Financing Act 2006, s 35F(2) · Retention of verification information—reporting entitiesOfficial text ↗
The reporting entity must retain the record, or a copy of the record, until the end of the first 7 year period: (a) that began at a time after the verification request was made; and (b) throughout the whole of which the reporting entity did not provide any designated services to the individual.
Text as at 1 July 2026
Anti-Money Laundering and Counter-Terrorism Financing Act 2006, s 35F(3) · Retention of verification information—reporting entitiesOfficial text ↗
A reporting entity that retains a record, or a copy of a record, under subsection (2) must delete the record at the end of the 7 year period referred to in that subsection.
Text as at 1 July 2026

Other terms that apply to these records

This page covers customer due diligence (kyc) records on their own. The same file is often caught by other laws as well, with different periods and start dates. See why a legal term is not a schedule.

3 records. 3 sets of rules. They don't agree.

One business file can hold all of these at once.

Customer due diligence (KYC) records7yAnti-Money Laundering and Counter-Terrorism Financing Act 2006, s 111(2), s 114(1), s 35F(2), s 35F(3) · the business relationship ends
AML/CTF transaction records7yAnti-Money Laundering and Counter-Terrorism Financing Act 2006, s 107(1), (3), s 108(2) · the record is made or the document is given
Personal information no longer neededDestroyPrivacy Act 1988, Schedule 1, APP 11.2, APP 4.3 · no longer needed for any permitted purpose

Now do that for every record your organisation holds, and redo it when the law changes. ScheduleOne has done that work, and keeps it current.

See ScheduleOne →