All posts
record-keepingaustracaml-compliancetranche-2getting-started

Switching CRM or AML provider? The seven-year records you have to take with you

The AML/CTF record-keeping obligation doesn't end when you cancel a subscription. What to export before you switch providers, and what 'able to produce it' means once the old system is gone.

By AML Simple Team

Switching CRM or AML provider? The seven-year records you have to take with you

Cancelling a subscription doesn't cancel your obligation to the records that were in it.

Under the AML/CTF Act 2006 (s 107), your agency must retain customer identification records, screening results, transaction records, and program versions for 7 years, and customer identification records for 7 years after the relationship ends. That obligation sits with your agency, not with whichever vendor happened to be storing the data at the time. Switch CRM, switch AML tool, or switch both, and the requirement to produce those records on request doesn't move with the old login.

What "able to produce it" actually means

AUSTRAC's record-keeping requirement isn't satisfied by records existing somewhere. It's satisfied by your agency being able to retrieve them and hand them over, in a reasonable time, for as long as the retention clock is running. See our full breakdown of the record-keeping obligation for what counts and how long each record type is held.

That's the part switching a provider puts at risk. If a client's identification record, screening result, or program version exists only inside an account you've cancelled, your agency can't produce it, even if the record itself technically still exists on the old vendor's server. A locked-out login is not a retrievable record. Neither is a vendor who no longer answers support tickets six months after you left, or a company that's been acquired, rebranded, or wound down. None of that changes what AUSTRAC can ask for.

Export before you cancel, not after

The order matters. Export first, confirm the export is complete and usable, then cancel. Doing it the other way round assumes the old vendor will still let you back in after your subscription lapses, which is not something any vendor guarantees and not something worth betting your compliance record on.

What to export, at minimum:

  • Customer identification records: document type, document number, issuer, expiry date, verification method, and who verified it and when, for every client on file
  • Screening results: every sanctions and PEP check you've run, with the timestamp, the result, and the decision made on any match
  • Transaction records: the designated service transactions tied to those clients
  • AML/CTF program versions: the program document itself, plus any prior versions, since AUSTRAC can ask which version was in force at a given date
  • Risk assessments and training records: both carry the same 7-year retention period
  • SMR and TTR copies: if your agency has lodged any, the copies you're required to retain

Ask the old vendor directly what export formats they support before you commit to leaving. A vendor that can't answer that question, or answers with "we'll look into it," is telling you something about how this is going to go.

Where agencies get caught out

The gap isn't usually the switch itself. It's the assumption that records will still be reachable later, when the trigger for actually needing them (an audit, a client dispute, an AUSTRAC request) can land well after the vendor relationship has ended. A client identification record has to survive 7 years after the relationship ends, which is often years after you've already changed software twice.

The other common gap is partial export. An agency exports client contact details because that's what the CRM migration wizard offers, and assumes screening history and program versions came along for the ride. They didn't, because CRM exports and compliance-record exports usually aren't the same button. Check both separately.

Once you've confirmed the records are out and stored somewhere your agency actually controls, keep a note of what was exported, in what format, and when. That note is itself useful evidence that the migration was handled properly if anyone ever asks.

Doing it yourself

If you're managing this without a dedicated export feature, the underlying task is the same:

  1. Request a full data export from the outgoing vendor, specifying every record category above, not just contact details
  2. Store the export somewhere your agency controls directly, not inside another vendor's account that could itself lapse
  3. Confirm the export actually opens and reads correctly before you cancel, not after
  4. Keep the export retrievable and organised for the remainder of each record's 7-year period, even as software changes again in future
  5. Document the migration date and what was moved, for your own audit trail

Choosing the next provider carries the same stakes in reverse. Our guide to evaluating an AML compliance tool covers what to check before you sign up with anyone new, including how easy they make it to leave.

AML Simple's record keeping includes data export as part of the paid plans, so an agency that later moves on isn't left trying to extract seven years of client history from a vendor that no longer wants to help. That's one detail among several worth checking with any provider, including us, before you commit.

The point that matters

The 7-year clock keeps running regardless of which software your agency is using. Whoever holds the login when AUSTRAC comes asking isn't the point, your agency being able to produce the record is. Confirm you can export everything before you sign anything cancelling the old account, not after.

Penalties for non-compliance can reach up to A$36,400,000 per contravention for a body corporate, or up to A$7,280,000 per contravention for an individual, under AML/CTF Act 2006 s 175.

We use cookies for advertising measurement. See our Privacy Policy.