AT A GLANCE
Anti-money laundering rules require financial institutions to keep transaction records, customer due diligence files, and compliance documentation for a legally defined minimum period before they can be deleted. In nearly every major framework, that baseline is five years, counted from the date of the transaction or the end of the customer relationship, though the exact rule shifts depending on the regulator, the record type, and where the institution operates. Getting the timeline wrong creates real exposure: failed exams, unusable evidence during investigations, and, in the US, a ten-year tail on certain sanctions records. This guide covers exactly how long AML records must be kept under FATF, US, and EU rules, which data types are covered, what happens when retention falls short, and how compliance teams can build a retention program that holds up under audit.
What Is Data Retention in AML Compliance?
Data retention in AML compliance is the legally mandated practice of storing transaction records, customer identification files, and monitoring data for a set minimum period so regulators and investigators can reconstruct financial activity when needed. It isn't optional record-keeping it's a specific, enforceable obligation tied to almost every major AML law, from FATF's global standards to national banking regulations.
The requirement exists because money laundering investigations rarely happen in real time. A suspicious customer's transaction history, demonstrate that due diligence was performed correctly, and respond to a pattern often surfaces months or years after the underlying transactions occurred, and by then, the only way to prove what happened is to look back at historical records. Retained data lets institutions reconstruct the regulator's request for information within the timeframe the law demands often days, not weeks.
In practice, data retention sits at the intersection of three functions: recordkeeping (what must be stored), data governance (how it's stored, secured, and organized), and retrieval (how fast it can be pulled during an audit or investigation). A program that satisfies only the first requirement while ignoring the other two will pass a paper-based compliance check but fail the moment a regulator or law enforcement agency asks for records under time pressure.
It's also worth separating data retention from general data storage. A company can store data indefinitely for business reasons analytics, customer service, product development — without any of it counting as AML-compliant retention. AML retention specifically means the data is preserved, protected, and retrievable in a form that satisfies a named legal obligation, with a defined start date and a defined end date. That distinction matters most when institutions rely on backup systems or general IT archives as their AML record: if the data can't be isolated, dated, and produced on demand, it usually won't satisfy an examiner.
How Long Must AML Records Be Kept?
Most AML records must be kept for a minimum of five years, though the exact period depends on which regulatory framework applies and what type of record is involved.
Global baseline: FATF Recommendation 11
The Financial Action Task Force's Recommendation 11 requires financial institutions to keep all transaction records domestic and international for at least five years, with enough detail to reconstruct individual transactions for a criminal investigation if needed. The same five-year minimum applies to customer due diligence records, including identification documents, account files, and correspondence, counted from the end of the business relationship or the date of an occasional transaction. FATF's standard isn't law on its own, but it's the template most national AML regulations are built from.
United States: Bank Secrecy Act and OFAC
Under the Bank Secrecy Act and the USA PATRIOT Act, US banks generally must retain records for five years, covering customer identification program (CIP) files, Currency Transaction Reports (CTRs), and Suspicious Activity Reports (SARs) with their supporting documentation. Customer identity records specifically must be kept for five years after an account is closed. Sanctions compliance runs on a different clock: as of March 12, 2025, the Office of Foreign Assets Control extended its record retention requirement from five to ten years for records tied to blocked property and rejected or unexecuted transactions. For property that remains blocked, the ten-year period doesn't start until the asset is unblocked — meaning retention can effectively last indefinitely while sanctions stay in place.
European Union: AMLD today, AMLR from 2027
Under the EU's current AML Directive framework (Article 40 of AMLD4/5), obliged entities must retain customer due diligence documents and transaction records for five years after the end of a business relationship or an occasional transaction. Financial Action Task Force (FATF) member states can extend this by up to five additional years up to ten years total, if they can justify the extension as necessary and proportionate. That flexibility has produced real variation across the bloc: the Netherlands and France apply the five-year minimum, while Spain and Luxembourg require ten years.
That inconsistency is exactly what the EU's new Anti-Money Laundering Regulation (Regulation (EU) 2024/1624, or AMLR) is designed to eliminate. From July 10, 2027, AMLR Article 77 will apply directly across all EU member states, replacing the patchwork of national retention rules with a single harmonized standard. Institutions operating in multiple EU countries should start planning for that shift now rather than waiting for the 2027 deadline.
💡Tip: If your institution operates across multiple jurisdictions, don't set your policy to the shortest applicable retention period set it to the longest. A single ten-year retention baseline is easier to defend under audit than juggling five different rules by country.
What Types of Data Must Financial Institutions Retain for AML?

AML retention obligations cover any data that documents a transaction, a customer's identity, or a compliance decision not just financial records.
The main categories are:
- Transaction data: amounts, dates, parties, and channels for every transaction, kept in enough detail to reconstruct the activity later.
- Customer due diligence (KYC) data: identity verification documents, proof of address, beneficial ownership information, and updates made during periodic reviews.
- Sanctions and watchlist screening records: evidence that a customer or transaction was screened against sanctions lists, PEP lists, and internal watchlists, including match and no-match results.
- Risk assessment data: the risk rating assigned to a customer or transaction and the factors that produced it.
- Suspicious Activity Reports (SARs) and supporting documentation: the report itself, plus the underlying analysis and evidence that led to filing it.
- Correspondence and case notes: internal communications, investigation notes, and decisions tied to a specific customer or alert.
- Geographic and biometric data: origin and destination of funds, or identity-verification data such as facial recognition, were collected to support the categories above.
Not every institution collects every category above, and what counts as "necessary" data depends on your risk profile and the products you offer. The consistent rule across regulators is that if a record was used to make a compliance decision, it needs to be retained long enough to defend that decision later.
What Happens When AML Data Retention Fails?
Poor data retention creates two kinds of damage at once: it exposes the institution to direct regulatory penalties, and it quietly weakens every AML function that depends on historical data.
On the regulatory side, examiners treat recordkeeping gaps as a standalone finding, separate from whatever underlying issue the missing records relate to. That means an institution can face fines and remediation orders purely for failing to produce records within the required timeframe even if the underlying transactions were legitimate. In the US and EU, recordkeeping failures are also commonly flagged during routine exams, not just major investigations, making them one of the more preventable sources of regulatory action.
On the operational side, missing or incomplete historical data:
- Slows down or derails SAR investigations, since analysts can't establish a customer's full transaction pattern.
- Weakens ongoing risk assessments, because there's no historical baseline to compare current behavior against.
- Creates evidentiary gaps in legal proceedings, where institutions may be unable to produce documentation a court or regulator requests.
- Increases fraud exposure, since gaps in historical data make it harder to spot repeat bad actors over time.
- Damages standing with regulators, who tend to scrutinize institutions with a history of recordkeeping failures more closely in future exams.
The common thread is that data retention failures rarely show up as an isolated problem. They surface during an audit, a SAR investigation, or a legal proceeding — at the exact moment the institution most needs the data to be there.
What Are the Most Common AML Data Retention Challenges?

The most common data retention challenges are volume, jurisdictional complexity, and the tension between AML retention mandates and privacy law each with a fairly standard fix.
- Data volume and fragmentation. Transaction and customer data accumulates fast, often across systems that don't talk to each other. Fix: centralize AML-relevant data in a single system of record, or at minimum a searchable index spanning source systems, rather than relying on point-in-time exports.
- Cross-border regulatory variance. Institutions operating in several countries face different retention periods for the same customer relationship. Fix: adopt the strictest applicable retention period as your default, and document the jurisdictional basis for any exceptions.
- Privacy law tension (GDPR and similar frameworks). Data protection laws generally require deleting personal data once it's no longer needed, while AML law requires keeping it. Fix: document the AML legal basis for retention explicitly in your data protection records, so retained data is defensible under both frameworks rather than looking like an unexplained exception to your privacy policy.
- Secure long-term storage. Data held for five to ten years is a growing target for breaches, and storage costs compound over time. Fix: use encrypted, access-controlled archival storage with periodic security audits, and reassess storage costs against actual regulatory need rather than defaulting to keeping everything indefinitely.
- Timely retrieval during investigations. Retention only has value if the data can be found quickly. Fix: test retrieval speed on a schedule, not just after an incident a regulator's request usually comes with a deadline measured in days.
- Data quality decay. Records left untouched for years accumulate errors, duplicates, and outdated information. Fix: run periodic validation checks on archived data, not just newly collected data.
How Can Financial Institutions Build a Compliant AML Data Retention Strategy?
A compliant AML data retention strategy starts with a written policy that maps every record type to its legal retention period, its trigger date, and its destruction date not a general instruction to "keep AML data."
From there, the strongest programs share a few traits: retention rules are automated rather than manually tracked, archived data is encrypted and access-controlled, and the policy is reviewed at least annually against regulatory changes like the EU's 2027 AMLR transition or the 2025 OFAC extension. Regtech platforms that automate transaction monitoring and case management typically build retention scheduling directly into the workflow, which removes the risk of someone manually forgetting to extend or close out a record.
Ownership matters as much as tooling. Retention policies tend to fail quietly when responsibility is split across IT, legal, and compliance without one team accountable for the full lifecycle from the moment a record is created to the day it's legally allowed to be deleted. The institutions that handle this well typically assign a single compliance owner to the retention policy itself, separate from whoever owns general data storage, and give that owner visibility into every system where AML-relevant data lives, not just the primary case management platform, to reduce the risk of non-compliance.
💡Practical Tips
- Set retention triggers to specific dates (transaction date, account closure date), not vague timeframes "five years" only works if the system knows exactly when the clock started.
- Build destruction into the policy, not just storage. Regulators increasingly expect proof that data is deleted on schedule, not just retained indefinitely "to be safe."
- Keep an audit trail of the retention policy itself when it was updated, why, and which regulation triggered the change.
- Separate AML retention rules from general data retention policies. Treating AML data like standard business records is one of the most common reasons institutions over- or under-retain.
- Run a retrieval drill at least once a year: pull a record from year four or five of its retention period and time how long it takes to produce.
Frequently Asked Questions
Does GDPR conflict with AML data retention requirements?
- Not directly — GDPR includes an exception for data retained to comply with a legal obligation, and AML recordkeeping law qualifies. The practical requirement is documenting the AML legal basis for holding data past the point it would otherwise be deleted under a general privacy policy.
How long must KYC documents be kept after an account closes?
- Under most frameworks, KYC and customer identification records must be kept for five years after the account is closed or the customer relationship ends, though some jurisdictions extend this to ten years.
Do cryptocurrency exchanges follow the same AML retention rules as banks?
- Largely, yes. Under the EU's incoming AMLR and FATF's standards, crypto-asset service providers are treated as obliged entities and are subject to the same core retention periods as banks, though specific triggers can differ based on how a jurisdiction defines a crypto transaction.
Can AML records be stored digitally, or do they need to be kept on paper?
- Digital storage is accepted under virtually every major framework, provided the records remain accurate, readable, and retrievable for the full retention period. Paper is not required.
Who enforces AML record-keeping requirements?
- National financial regulators and banking supervisors enforce these rules domestically for example, FinCEN and federal banking regulators in the US, or national competent authorities in the EU, with the EU's new AMLA taking on direct supervision of high-risk institutions as it becomes fully operational.
Can a company delete AML data before its retention period ends?
- No. Deleting AML records before the mandated retention period ends is itself a compliance violation, regardless of whether the deletion was intentional or the result of a poorly configured data lifecycle policy.
How long do banks keep video surveillance footage related to AML or fraud monitoring?
- Video retention isn't governed by AML recordkeeping law directly it typically falls under separate internal security policies or national data protection rules, and periods vary widely by institution, often 30 to 90 days unless the footage is tied to an active investigation, in which case it's preserved until that investigation closes.
What's the difference between a data retention policy and a data destruction policy?
- A retention policy defines how long a record must be kept and why; a destruction policy defines what happens once that period ends. Regulators expect both to exist together a retention policy without a matching destruction schedule tends to result in institutions holding onto far more data than the law requires, which increases both storage cost and data breach exposure without any compliance benefit.
Conclusion
Effective AML data retention comes down to three things: knowing the exact retention period that applies to each record type, building a system that enforces those periods automatically, and being able to prove quickly that the data is there when a regulator asks for it. The rules themselves aren't especially complicated; five years is the standard baseline nearly everywhere. What causes problems is inconsistent application across jurisdictions, record types, and systems that don't talk to each other.
As the EU moves toward a single harmonized retention standard under AMLR in 2027 and US sanctions rules extend retention windows further, institutions that treat retention as a static policy rather than a living, auditable system will fall behind. Pairing a solid retention framework with strong historical analysis, the kind covered in our earlier piece, “Time-Series Analysis: 10 Compelling Use Cases in Compliance,” gives institutions both the data and the tools to use it effectively when regulators or investigators come asking.

.webp)



