
AML/CTF Record Keeping: What Real Estate Agents Must Retain and For How Long
Record keeping is one of the nine AML/CTF obligations that applies to every Australian real estate agency from 1 July 2026. It is also the obligation most likely to create problems during an AUSTRAC examination, because poor records make it impossible to demonstrate compliance with any of the other eight. Here is what must be kept, how it must be stored, and how long it must be retained.
Every AML/CTF obligation a real estate agency carries creates a corresponding record keeping requirement. When you conduct Customer Due Diligence, the identification and verification records must be retained. When you lodge a Suspicious Matter Report, the record of that report must be kept. When you deliver staff training, the training register must be maintained. When you complete a risk assessment, the assessment document must be preserved.
The record keeping obligation under the AML/CTF Act 2006 is not simply an administrative requirement sitting alongside the other obligations. It is the evidentiary foundation of the entire compliance program. Without adequate records, a real estate agency cannot demonstrate to AUSTRAC that it has met its obligations. The absence of records is treated by AUSTRAC as evidence that the obligation was not met, regardless of what actually occurred.
This guide covers each record keeping category in full: what must be retained, in what form, for how long, and what AUSTRAC can require an agency to produce. It draws on AUSTRAC guidance published at austrac.gov.au and the requirements of the AML/CTF Act 2006 available at legislation.gov.au.
| ⚠️ THE CORE RECORD KEEPING RULE Every record required under the AML/CTF Act must be retained for a minimum of SEVEN YEARS from the date the record was made. This applies regardless of whether the transaction proceeded, was cancelled, or was abandoned. It applies to digital records, paper records, and records held in third-party systems. AUSTRAC can require production of any required record within a specified timeframe. An agency that cannot produce a required record faces the same consequence as one that never created it in the first place. |
The Seven Record Categories Every Real Estate Agency Must Maintain
The AML/CTF Act identifies specific categories of records that reporting entities must retain. For real estate agencies, seven categories are directly relevant. Each category has its own content requirements, and each carries the same seven-year minimum retention period.
| Record Category | What Must Be Retained | Triggered By |
| Customer identification records | Full name, date of birth, residential address, and all other information collected during the CDD process for each client | Every client for whom a designated service is provided |
| Customer verification records | The identity document or documents used to verify each client’s identity, including document type, issuing authority, document number, and expiry date | Every CDD verification completed, whether by face-to-face or remote means |
| Beneficial owner records | The natural person or persons identified as the beneficial owner of a company, trust, or other non-individual client, with the basis for that identification documented | Every non-individual client for whom a designated service is provided |
| Transaction records | The nature and details of each transaction conducted in providing a designated service, including the parties, the property, the consideration, and the method of payment | Every designated service transaction, whether completed, cancelled, or abandoned |
| Suspicious Matter Reports | A copy of each SMR lodged with AUSTRAC, the grounds for the suspicion, and the date of lodgement | Every SMR lodged, and every suspected matter considered but not ultimately reported |
| Staff training records | Name and role of each staff member trained, training date, content covered, delivery method, and evidence of comprehension or completion | Every training session delivered to any staff member who provides designated services |
| AML/CTF Program and Risk Assessment | The current version of the AML/CTF Program (Part A and Part B) and the ML/TF Risk Assessment, plus all previous versions with the dates they were in force | Each time the program or risk assessment is reviewed, updated, or replaced |
| 🎓 FROM LEAD COMPLY’S COMPLIANCE EXPERIENCE The transaction record category is the one most commonly underestimated by real estate agencies. In a regulated industry context, transaction records are treated as the primary audit trail for every client interaction. Agencies often assume their CRM or property management software captures sufficient transaction information. In most cases, those systems record what the agency needs for its own operations, not what AUSTRAC requires for compliance purposes. A transaction record for AML/CTF purposes must capture the nature of the designated service, the parties involved, the property details, the consideration paid, and the method of payment. Standard real estate CRM records frequently omit the payment method and the consideration breakdown in a format that satisfies the AML/CTF standard. This gap is worth auditing before July 2026 rather than discovering during an AUSTRAC examination. |
The Seven-Year Retention Period in Detail
The AML/CTF Act requires that each record be retained for seven years from the date it was made. Understanding when the clock starts is critical for agencies designing their record keeping systems.
| Record Type | Seven Years From | Practical Example |
| Customer identification and verification records | The date the record was made during the CDD process | CDD completed on 1 July 2026: retain until 1 July 2033 |
| Transaction records | The date the transaction record was created | Contract exchanged 15 August 2026: retain until 15 August 2033 |
| Suspicious Matter Reports | The date the SMR was lodged with AUSTRAC | SMR lodged 3 September 2026: retain until 3 September 2033 |
| Staff training records | The date the training record was created | Training conducted 20 June 2026: retain until 20 June 2033 |
| AML/CTF Program versions | The date each version ceased to be in force | Program version replaced on 1 February 2027: retain that version until 1 February 2034 |
| Risk assessment versions | The date each version ceased to be current | Risk assessment superseded on 1 March 2028: retain until 1 March 2035 |
One practical implication of the seven-year rule deserves particular attention. A real estate agency that commences operations as a reporting entity on 1 July 2026 will not be able to destroy its earliest compliance records until 2033 at the earliest. Any record keeping system or software platform the agency adopts in 2026 must be capable of retaining records for the full seven-year period, including after the platform is changed or discontinued.
How Records Must Be Stored
The AML/CTF Act does not mandate a specific storage format. Paper records and electronic records are both acceptable. What the Act does require is that records be readily accessible for production to AUSTRAC within the timeframe specified in a formal notice.
| Storage Format | Acceptable for AML/CTF Purposes? | Key Requirements |
| Secure digital system (cloud or server) | Yes, and recommended for most agencies | Accessible by the compliance officer. Backed up regularly. Access-controlled so records cannot be altered or deleted before the retention period expires. |
| PDF or scanned documents on a secure server | Yes | Legible reproduction of original documents. Organised so specific records can be located and produced without delay. Protected against unauthorised deletion. |
| Original paper documents in physical files | Yes, but carries practical risk | Must be stored securely and protected from damage, loss, or destruction. Physical records can be more difficult to produce rapidly in response to an AUSTRAC notice. |
| Records held in CRM or property management software | Yes, if the system captures the required fields | The system must capture all required AML/CTF fields, not just the fields relevant to the agency’s own operations. Export capability must allow production to AUSTRAC. |
| Personal email or personal device storage | Not acceptable | Records must be held in a system controlled by the reporting entity, not by an individual staff member. Personal email and device storage creates chain of custody and access risk. |
| 🎓 FROM LEAD COMPLY’S COMPLIANCE EXPERIENCE The storage question that most agencies do not ask early enough is: what happens to our records if we change software platforms in three years? In a regulated industry environment, platform migration is a compliance event, not just an IT project. Records created in a previous system must be exported, preserved, and made accessible for the balance of their seven-year retention period before the old system is decommissioned. Lead Comply consistently identifies agencies that have changed CRM or property management software and lost access to records from the previous platform. Under the AML/CTF framework, those records must still be accessible and producible to AUSTRAC for seven years from creation. Building a migration plan into the record keeping system design from the outset is far less costly than reconstructing or defending the absence of records during an examination. |
When AUSTRAC Can Require Production of Records
AUSTRAC has the authority to require a reporting entity to produce any required record within a specified timeframe. This power can be exercised as part of a formal examination, during an investigation, or as a routine supervisory request. The timeframe specified in an AUSTRAC notice can be as short as five business days.
What this means in practice: every record the agency is required to keep must be organised, labelled, and stored in a manner that allows it to be located and produced quickly. A record that exists but cannot be found within the required timeframe is treated the same as a record that does not exist.
The production obligation applies to all seven record categories. AUSTRAC can request a specific client’s CDD records, all SMRs lodged in a given period, the current and all previous versions of the AML/CTF program, or the full training register for all staff. Each of these must be producible without extensive search or reconstruction.
| What AUSTRAC looks for when reviewing record keeping during an examination: Are CDD records complete for every client for whom a designated service was provided? Do verification records identify the specific document used, its issuing authority, number, and expiry? Are beneficial owner records present and documented for all non-individual clients? Do transaction records capture the required fields, including payment method? Are SMR records retained with the grounds for the suspicion documented?· Does the training register cover all staff who provide designated services, not just the principal? Are previous versions of the AML/CTF program retained with the dates they were in force? Absence of any category of required records is treated as a failure to meet the record keeping obligation. |
Building a Record Keeping System for Your Agency
A compliant record keeping system does not require expensive software. It requires a structured approach that ensures every required record is captured, stored securely, retained for the minimum period, and accessible for production to AUSTRAC. For most real estate agencies, the following framework covers the essentials.
| Step 1 | Design the record structure before transactions begin: Establish a folder or system structure that organises records by category and by client before the agency starts providing designated services. Retrofitting a record keeping structure after records have accumulated is significantly more difficult. |
| Step 2 | Integrate record collection into the CDD process: CDD records should be captured as part of the client onboarding workflow, not as a separate administrative step. If the agent collects the identification document and verifies it, the record of that process must be created at the same time. |
| Step 3 | Document the basis for decisions, not just the outcome: For CDD, the record must show not just what was collected but what was verified and how. For SMR decisions, the record must show the grounds for the suspicion. For risk assessment conclusions, the record must show the methodology. |
| Step 4 | Implement access controls: The record keeping system must prevent unauthorised alteration or deletion of records. Access should be restricted to the compliance officer and designated staff, with a log of access maintained where the system allows. |
| Step 5 | Build in a retention schedule: Configure the system with the seven-year retention period so that records are not accidentally deleted before their retention period expires. Review retention dates annually. |
| Step 6 | Test production capability annually: Once per year, run a production test: can you locate and export a specific client’s CDD records, a specific SMR, and the current and previous program versions within five business days? If not, the system needs to be reorganised. |
How Lead Comply Supports AML/CTF Record Keeping
Lead Comply incorporates record keeping system design into every AML/CTF program engagement. The goal is an agency that has the right records in the right place from the first day it operates as a reporting entity. Key services include:
- Record keeping framework design: a structure tailored to the agency’s size, systems, and designated services
- CDD record templates: standard forms that capture all required fields for individual, company, trust, and SMSF clients
- Transaction record templates: covering the designated service type, parties, property, consideration, and payment method
- SMR record templates: designed to document both the grounds for a suspicion and the decision to report or not report
- Training register design: a compliant record format for staff training documentation
- Retention schedule: a configured calendar of minimum retention dates for each record category
- Production readiness review: an annual check confirming records can be located and produced within five business days
| 📋 WHAT GOES WRONG IN PRACTICE — WHAT LEAD COMPLY SEES The three record keeping failures Lead Comply identifies most consistently across agency reviews: 1 — CDD records are collected but not organised by client. Agents collect identification documents during the transaction and store them in the transaction file rather than a client record. When AUSTRAC requests all CDD records for a specific client, the agency cannot locate them without searching through every transaction file that client was involved in. 2 — Transaction records capture what the CRM needs, not what AML/CTF requires. Most real estate CRMs record property details, parties, and price. Few record the method of payment or the nature of the designated service in AML/CTF terms. This leaves a required field consistently absent from the transaction record. 3 — Previous versions of the AML/CTF program are not retained when the program is updated. Agencies replace their program document and delete or overwrite the previous version. AUSTRAC requires the previous version to be retained with the dates it was in force. This is a straightforward gap that an AUSTRAC examination will identify. |
| ✓ WHAT A RECORD-KEEPING-COMPLIANT REAL ESTATE AGENCY LOOKS LIKE – A defined record keeping structure in place before designated services commence. – Complete CDD records for every client: identification, verification, and beneficial owner. – Transaction records capturing all required fields, including payment method. – All SMRs retained with the grounds for the suspicion documented. – A training register covering all staff who provide designated services. – Current and all previous program versions retained with dates in force. – Records stored in a system with access controls and protected against premature deletion· Seven-year retention schedule configured and reviewed annually. – Production capability tested: any required record can be located within five business days |
| Frequently asked questions on AML/CTF record keeping: Do we need to keep records if a transaction falls through before settlement? — Yes. The obligation to retain records arises when the designated service is provided, which includes acting for a client even if the transaction does not complete. Can we store records in our existing CRM? — Yes, provided the CRM captures all required AML/CTF fields and allows export for production to AUSTRAC. Most CRMs require supplementary documentation to meet all requirements. What happens if records are lost in a fire or system failure? — AUSTRAC expects agencies to have appropriate backup and disaster recovery arrangements. The obligation to retain records includes maintaining them in a manner protected against accidental destruction. Do we need to keep records for clients we acted for before 1 July 2026? — The record keeping obligation applies to designated services provided on or after 1 July 2026. Pre-commencement records are not required under the AML/CTF Act, though they may be relevant under other legislation. |
About Lead Comply
Lead Comply is a Sydney-based AML/CTF compliance consultancy helping Australian real estate agencies and SMEs meet their Tranche 2 obligations. Our practice draws on six-plus years of direct experience managing AML/CTF programs in a regulated Australian industry, including record keeping framework design and documentation auditing across operational teams. This article reflects that experience alongside current AUSTRAC guidance and the AML/CTF Act 2006.
Book a free 30-minute Clarity Call with Lead Comply. In 30 minutes you will know whether your seven record categories, storage approach, and retention periods meet the AML/CTF standard before 1 July 2026.