Record Keeping
Record keeping is the anti-money laundering duty to retain records of customer checks and transactions. Most regimes require these to be kept for at least five years, so activity can be traced by investigators and a firm can prove it met its obligations. Key takeaways Record keeping is the AML duty to retain records of checks and transactions. It covers identity records, transactions, risk assessments, and reports. Most regimes require records to be kept for at least five years. The rule comes from the FATF standard and national law. Records give investigators an audit trail and prove compliance. Poor record keeping is a common and avoidable examination finding. On this page What it isWhy records matterWhat to keepHow longFormat and storageRecords and investigationsCommon failuresDoing it wellFAQsRead more 5 years Minimum record retention under the global AML standard Source: FATF Recommendation 11 1970 Year the US Bank Secrecy Act introduced record-keeping duties Source: FinCEN $800B to $2T Laundered worldwide each year that records help trace Source: UNODC What is record keeping in AML? Record keeping is the duty to hold on to evidence of the checks and transactions a firm handles. It means keeping who a customer is, what they did, and what the firm did about it, in a form that can be found later. It is one of the quieter parts of an AML program, easy to overlook next to screening or monitoring, but it is where the whole system leaves a trail. Without records, there is no proof anything was checked. The duty runs across every regulated firm. Read more: it is one of the obligations inside an AML compliance program. Why records matter Records matter for two reasons: they help catch criminals, and they protect the firm. Both come down to having evidence when it is needed. For investigators, records are the trail that money leaves. When law enforcement follows a suspect, the account records, transaction histories, and identity checks held by firms are often what let them build a case. For the firm, records are the proof that it did its job, which is exactly what a regulator asks to see. A firm with good records can answer questions. A firm without them cannot, whatever it actually did. What records to keep The rules cover a defined set of records, spanning the customer relationship from start to finish. Each supports a different part of the trail. Identity records. The evidence gathered during customer due diligence, such as documents and checks. Transaction records. Details of the transactions a customer made. Risk assessments. How the firm judged the risk of a customer or its business. Reports. Copies of any suspicious activity report filed and the reasoning behind it. Correspondence. Relevant communications about the account or activity. Together these let someone reconstruct not just what a customer did, but what the firm knew and decided. How long to keep records Most regimes settle on a minimum of five years, and that figure is remarkably consistent worldwide. The clock usually starts when the relationship ends or the transaction takes place. The global standard-setter, the FATF, calls for records to be kept for at least five years in its Recommendation 11, and national laws follow it. In the US, the Bank Secrecy Act requires a five-year retention period, and the EU applies a similar rule. Some records may need to be kept longer if an investigation is open. Set out record keeping in your AML policy Generate a tailored AML policy draft that records your controls, checks, and retention approach. Open the AML Policy Generator → Format and storage The rules care less about the exact format than about whether records can be found and read. Two qualities matter most. Retrievable. Records must be produced promptly when a regulator or investigator asks. Readable. They must be complete and legible, not fragments no one can interpret. Records can be kept on paper or, far more often now, electronically. What matters is that a firm can retrieve a specific customer’s history quickly, rather than searching through disorganized files while an examiner waits. Record keeping and investigations Records come into their own when something goes wrong. An investigation, whether by the firm or by law enforcement, runs on the evidence that was kept. When a suspicious pattern emerges, investigators look back through the records to understand it: who the customer is, where the money came from, and where it went. Good records make that possible; missing ones can stall a case entirely. This is why the duty exists in the first place, to keep the trail intact for the day it is needed. Worth knowing. Record keeping is often where a firm’s compliance is truly tested. A program can screen and monitor well, but if it cannot produce the records to prove it, a regulator has no way to confirm the work was done. In practice, weak record keeping can turn a firm that did the right thing into one that cannot show it, which amounts to the same finding. Common record-keeping failures Record-keeping failures tend to be mundane rather than dramatic, which is what makes them so common. A few recur. Gaps. Records missing for some customers or periods. Early destruction. Records deleted before the retention period ends. Poor retrieval. Records that exist but cannot be found quickly. Incomplete files. Records that capture part of the story but not the decision behind it. None of these is hard to avoid, which is exactly why regulators take a dim view of them. How firms do record keeping well Doing record keeping well is a matter of discipline more than technology. A few habits keep a firm on solid ground. Define what to keep. Set a clear policy on records and retention periods. Store it well. Keep records secure, organized, and easy to retrieve. Hold for the full period. Do not destroy records early, and extend where needed. Test retrieval. Check that a specific record can actually be found on request. Get an indicative … Read more