AML Record Retention Checklist for the USA

AML Record Retention Checklist for the USA

AML record retention is the systematic preservation of customer due diligence, transaction evidence, and compliance decisions required by FinCEN. The Financial Crimes Enforcement Network enforces a five-year minimum retention baseline for most AML documentation, with specific retention triggers varying by record type. Without systematic retention, compliance teams face fragmented evidence, regulatory violations, and examination exposure.

This checklist explains FinCEN record retention requirements, which documents must be retained, and how to systematize retention scheduling to maintain audit-ready evidence.

FinCEN record retention requirements

FinCEN’s record retention obligations are codified in 31 CFR Part 1010 (Bank Secrecy Act).

Key requirements:

Customer Identification Program (CIP) records: Five years from account opening or closure. Include customer name, address, TIN, and identity verification documents.

Customer Due Diligence (CDD) records: Five years from completion. Beneficial ownership verification, risk assessments, and supporting evidence must be documented.

Suspicious Activity Reports (SARs): Five years from filing date. Investigation files must evidence the reasoning that led to suspicion and the decision to file.

Currency Transaction Reports (CTRs): Five years from filing date. Include transaction details and identity verification.

Transaction records: Five years from transaction date. Records of transactions exceeding US$3,000 (or the institution policy threshold) must evidence monitoring occurred.

Customer risk assessments: Five years from assessment date. Retain written risk ratings, criteria applied, and reassessment decisions.

Ongoing monitoring records: Five years from activity date. Include beneficial ownership updates, transaction analysis, and monitoring violations.

AML record retention matrix

Record TypeRetention PeriodTrigger DateContents to Retain
CIP documentation5 yearsAccount opening or closureCustomer ID, address, TIN, verification documents
CDD/Beneficial ownership5 yearsCompletion or update dateOwnership assessment, risk rating, verification evidence
Suspicious Activity Reports5 yearsSAR filing dateSAR filing, investigation memo, decision documentation
Currency Transaction Reports5 yearsCTR filing dateCTR filing, customer ID, transaction details
Transaction records5 yearsTransaction dateTransactions >$3,000, monitoring results
Risk assessments5 yearsAssessment dateRisk rating, criteria, reassessment decisions
Ongoing monitoring5 yearsActivity dateBeneficial ownership reviews, transaction analysis
AML training records5 yearsTraining completion dateCompletion certificates, assessment scores

Common retention challenges

  • Fragmented storage: Records scattered across email, file shares, and multiple systems with no centralized index. Assign ownership and centralize in a single compliance database.
  • Unclear retention periods: Staff delete records prematurely or retain indefinitely due to unclear policies. Document trigger dates and retention periods in your AML policy.
  • Inadequate disposal documentation: Records deleted without audit evidence. Implement documented disposal procedures with approval and rationale.
  • Inconsistent SAR retention: SAR retention varies across business units. Calculate retention end dates automatically based on the filing date.
  • Disconnected training records: Training records stored separately from compliance systems. Integrate learning management data with compliance workflows.

Best practices

For AML record retention checklist:

  • Establish a written retention policy specifying periods and trigger dates for each record type.
  • Implement automated retention scheduling to calculate end dates and flag records for review.
  • Centralize records in a single indexed system rather than fragmented repositories.
  • Document all disposal decisions with approval and business rationale.
  • Conduct annual retention compliance audits to identify gaps before FinCEN inspection.

Systematic retention prevents examination risk

Manual record retention across fragmented systems exposes institutions to compliance gaps and delays when FinCEN requests documentation. A centralized compliance platform consolidates records in retention-scheduled workflows where retention periods are calculated automatically, records are flagged for disposal at expiration, and complete audit trails document retention compliance. When regulators request records, audit-ready responses are generated immediately rather than assembled manually over days.

Key takeaways

Compliance teams must maintain five-year retention of all AML documentation, including CIP files, due diligence records, SAR investigations, and transaction monitoring evidence. Retention periods are triggered by record creation date, transaction date, or filing date, depending on record type. FinCEN examinations test whether records are organized, accessible, and retained systematically.

Frequently asked questions

What is the general retention period for AML records under FinCEN rules?

FinCEN requires a minimum five-year retention for most AML documentation. The five-year period typically begins from the record creation date, transaction date, or SAR filing date, depending on the record type.

How should beneficial ownership documentation be retained?

Beneficial ownership verification documents must be retained for five years from the date the beneficial ownership determination was made or the customer relationship terminates, whichever is later.

What must be retained for Suspicious Activity Report investigations?

Retain the complete SAR filing and all investigation documentation for five years from the SAR filing date, including analysis, evidence reviewed, and decision documentation.

Are there state-level record retention requirements in addition to FinCEN requirements?

Yes, some states impose additional retention requirements. Where state requirements are more stringent than FinCEN requirements, institutions must comply with the more stringent standard.

What is Cascade, and how does it simplify AML/KYC compliance?

Cascade is an end-to-end AML software platform that centralises client data and supports AML/KYC workflows from onboarding through ongoing monitoring and reporting, helping teams standardise processes and maintain audit trails.

Who can benefit from using Cascade?

The Cascade platform supports organisations with AML/KYC obligations, including financial services firms, fintechs, wealth managers, law firms and corporate service providers.

How does Cascade ensure data security and regulatory compliance?

Cascade software provides controlled workflows, activity logging and audit trails to support traceable AML/KYC processes, though compliance depends on your policies and configuration.

How can I get started with Cascade?

Book a demo with Cascade to discuss your AML/KYC requirements and identify how the platform can support your workflows.

Disclaimer

This article is for general information only and based on publicly available sources and regulatory guidance at the time of writing. We have made our best effort to ensure accuracy and relevance to US financial services AML compliance, but FinCEN regulations, guidance, and business requirements can change. Always verify key details against current FinCEN publications and consult with a qualified compliance specialist or legal advisor before making compliance or vendor decisions.

Ready to Get Started?

Empower your compliance with the leading end-to-end AML KYC platform Cascade