What AML records should an accountancy firm keep?
Last updated: August 21, 2026
AML record keeping ensures accountancy firms can evidence how they discharged their obligations under the Money Laundering Regulations. In addition to basic identity checks, records should extend to client risk assessments, employee instruction, internal disclosures, and how regulated information is eventually disposed of.
Just as importantly, sensitive material such as suspicious activity reports (SARs) must be kept securely and only for as long as there is a proper reason to retain it.
Key takeaways
- Records should show the judgement behind an AML decision rather than simply showing the documents collected.
- The firm-wide risk assessment must connect with client files and day-to-day AML procedures.
- Training records capture both what was covered and whether relevant staff understood it.
- Internal SARs require restricted handling outside the ordinary client record.
- Effective retention arrangements cover retrieval, storage, and timely deletion once the applicable retention period ends.
The importance of AML record keeping for accountancy firms
AML records allow the firm’s compliance activity to be examined after the event, including whether its stated controls were actually applied in individual cases.
Per HMRC guidance, businesses need to keep core AML records covering due diligence, risk assessment, governance, and training. HMRC also states that comprehensive records can be important if the firm later has to account for its handling of a particular client or service during an investigation.
Records should also outline why certain AML outcomes (such as a change in client circumstances) made sense at the time and whether that judgement was routine or higher risk, including the money laundering reporting officer’s (MLRO) conclusion on any internal report.
AML record categories for accountancy firms
The firm-wide risk assessment (FWRA) is a core AML record, and it should be kept with the information used to prepare it, including the firm’s main risk factors and any supervisory or sector guidance considered. Under Regulation 18, firms must keep an up-to-date written record of their FWRA, with the risks identified then driving wider AML controls and client-level decisions.
Additionally, policies, controls, and procedures (PCPs) are another mandatory record category. PCPs need to explain how the firm manages client risk from onboarding through ongoing monitoring, and how staff should handle records and internal reports. Regulation 19 requires PCPs to be kept current, approved at the right level, and communicated within the business where relevant.
Responsibility for AML within the firm also needs to be documented. In the case of a sole practitioner, this typically only requires a short record identifying the nominated officer and explaining how oversight of the firm’s AML compliance is handled. When that assessment includes a compliance review, the findings and any resulting action should be recorded.
Practical takeaway: If the FWRA identifies higher exposure to cash-intensive clients, those AML threats should be visible in the risk assessment and ongoing monitoring of the affected relationships.
AML training and staff competence records
Training records need enough detail to demonstrate both attendance and understanding. This includes relevant employees who help the firm comply with the Money Laundering Regulations or manage financial crime risk. Regulation 24 reinforces this by requiring firms to keep a written record of the AML awareness and training measures provided to those employees.
Once again, supervisory expectations differ for sole practitioners, insofar as there may be no employees requiring formal AML training records; however, evidence of the practitioner’s own AML knowledge and continuing development remains relevant
Nonetheless, training records also need to cover non-accountant roles where their work could affect AML decisions, explaining which AML responsibilities apply to the role and how the firm established that the employee could carry them out.
CCAB guidance also points to updating the record when changes in risk, regulation, or procedure require further training.
Client due diligence, transaction, and SAR records
For each client, the firm should retain enough evidence to support AML checks completed, as well as the risk conclusion and significant decisions throughout the relationship.
If transaction records are relevant to the firm’s AML duties, they must be sufficient to reconstruct the transfer and evidence the audit trail.
Internal reports and the nominated officer’s decision notes should be retained separately from ordinary client working papers, with access restricted to those who need it.
How long do accountancy firms need to keep AML records?
Under Regulation 40, customer due diligence and business relationship records are generally kept for five years from the end of the client relationship, while occasional transaction records are retained for five years from the transaction date.
Once that period ends, AML personal data should not be retained automatically. Records must remain readily retrievable while they are held, but keeping them for longer requires a separate legal justification.
Litigation or another statutory obligation can provide that justification for particular information, but where no such exception applies, the firm should delete the records when the relevant retention period expires.
AML record organisation, access, and retrieval
A proportionate structure might keep the FWRA, PCPs, responsibility records, and training material together, with due diligence and risk information held against individual clients. In any case, records must remain secure, retrievable, and protected against loss.
HMRC also highlights records held by third parties and the need to respond fully and promptly to law enforcement enquiries about whether the firm has, or had in the previous five years, a business relationship with a named individual or entity.
When third-party AML tools or identity providers are used, the firm should therefore be able to retrieve the relevant information if access to the provider changes or fails.
In summary
Strong AML records create continuity between the information available to the firm and the action it took in response. The practice’s AML supervisor should be able to follow that history later without relying on recollection or undocumented context.
Ultimately, the records should form a coherent compliance history rather than a series of isolated checks.
FAQs
Not always. The key requirement is that CDD evidence, the client risk assessment, and significant AML decisions can be identified and retrieved for that relationship. Accountancy firms can organise this material within their existing client systems, provided it remains easy to locate and follow.
A low-risk client file should still explain the basis for the low-risk assessment. The level of detail can be proportionate to the circumstances, but the AML record must identify the factors relied on, as well as when the client was assessed as low risk.
Non-accountant staff can need AML training records if their work affects the firm’s AML process. For example, someone who helps collect client information should understand the parts of the process relevant to that role. The firm should be able to show that the instruction matched those responsibilities and that competence was checked where appropriate.
A separate, access-controlled location should be used for internal SAR material rather than the general client file. The nominated officer’s decision notes need to be protected on the same basis.
The starting point depends on the record type. For CDD and business relationship material, the five-year period generally begins when the relationship ends; for an occasional transaction, it begins on the transaction date.
The firm should be able to obtain the information when needed even if an outside provider stores it. This means knowing what the provider holds, how the material can be recovered if access is disrupted, and whether a law-enforcement inquiry can still be answered within a reasonable timeframe.
References and Source Material
- Money Laundering Regulations 2017 (Regulation 18, 19, 24, 40)
- HMRC, Your responsibilities under money laundering supervision
- HMRC, Risks common to accountancy service providers
- HMRC, Risk assess your business for money laundering supervision
- HMRC, Economic Crime Supervision Handbook (ECSH33520, ECSH33220)
- HMRC, Anti-money laundering guidance for supervised businesses (AMLG11700 – Guidance for all sectors: Record Keeping)
- CCAB, Anti-Money Laundering and Counter-Terrorist Financing Guidance for the Accountancy Sector

