Country-specific guidance Current
Setting a record retention schedule under New Zealand's AML/CFT Act
The retention clock runs from different trigger points depending on the record.
New Zealand's AML/CFT Act sets a minimum retention period for client records, but the clock doesn't start from the same point for every record type. This guide sets out a practical approach to building a retention schedule. It is general information, not legal or compliance advice.
Action plan
1 Apply the five-year minimum retention period Five years is the recurring minimum across every AML/CFT record category, but the trigger point differs.
Department of Internal Affairs guidance on the AML/CFT Act's record-keeping obligation sets a five-year minimum retention period across each category of required record: identity and verification evidence, records relevant to establishing a business relationship, transaction records, suspicious activity reports, and risk assessments and AML/CFT programmes. Build a five-year floor into your retention schedule as the default.
- Set a five-year minimum retention period as your schedule's default
- Apply it across identity evidence, business relationship records, transaction records, and programme documents
- Treat five years as a floor, not a fixed period that's automatically correct for every record
Done when: A five-year minimum retention period is applied as the schedule's default across required record categories
DIA: AML/CFT guideline on record keeping2 Track the correct trigger point for each record type Identity evidence and business relationship records run from the end of the relationship; transaction records run from completion.
DIA's guidance is specific that identity and verification evidence, and records relevant to establishing a business relationship, must be kept for five years from the end of the business relationship, while transaction records run five years from completion of the transaction, and suspicious activity reports run five years from when the report was made. Track each record type against its own trigger, rather than applying a single retention date to a client's whole file.
- Track identity evidence and business relationship records from the end of the relationship
- Track transaction records from the date the transaction was completed
- Track suspicious activity reports from the date the report was made
Done when: Each record type's retention period is tracked from its own correct trigger point, not a single client-file date
See storing client identity evidence securely3 Have a clear basis for deciding when a business relationship has ended The Act's own definition of business relationship turns on duration, not a fixed closure event.
The AML/CFT Act defines a business relationship by reference to an element of duration, or expected duration, between your firm and the customer, rather than a single fixed closure event. Because the five-year clock for several record categories starts from the end of that relationship, set a clear, documented basis within your own firm, such as the closure of a client file or a defined period of inactivity, for deciding when a relationship has genuinely ended, and apply it consistently.
- Set a documented, consistent basis for deciding when a client relationship has ended
- Avoid leaving this as an undocumented, case-by-case judgement call
- Reassess dormant client files periodically against your own criteria
Done when: A documented, consistently applied basis exists for when a business relationship is treated as having ended
AML/CFT Act 2009: interpretation