Skip to content
EBA · EU-wide

AML record retention — what to keep, and how long

Fintech Passport
August 20, 2026 · 3-min read
AML record retention — what to keep, and how long

Retention looks like an IT setting until a supervisor asks for a file and finds it redacted, or gone. Article 77 of Regulation (EU) 2024/1624 names four classes of record, sets a five-year clock that starts at the end of the relationship rather than at creation, and adds a sentence that quietly rules out a common archiving practice: documents, information and records kept under the article must not be redacted.

1. The four classes

LimbWhat must be retained
(a)A copy of the documents and information obtained in performing customer due diligence, including information obtained through electronic identification means
(b)A record of the Article 69(2) assessment — the information and circumstances considered and the results — whether or not it resulted in a report, plus a copy of the report if any
(c)Supporting evidence and records of transactions: originals or copies admissible in judicial proceedings under national law, necessary to identify transactions
(d)Where the firm participates in information-sharing partnerships, copies of documents and information obtained there and records of all instances of sharing

Limb (b) is the one most often missing. The record of an assessment that concluded no report is expressly retainable — so a system that only stores filed reports is not compliant, and the negative decisions are exactly what an inspection samples.

2. The five-year clock, and where it starts

Retention runs for five years, and the start date is the point people get wrong. It commences on the date of:

  • the termination of the business relationship; or
  • the carrying out of the occasional transaction; or
  • the refusal to enter into a business relationship or carry out an occasional transaction.

Personal data must then be deleted on expiry of the five-year period, without prejudice to retention periods under other Union legal acts or national law complying with Regulation (EU) 2016/679. Deletion is an obligation, not an option — over-retention is a finding in its own right.

Competent authorities may require further retention on a case-by-case basis where necessary for preventing, detecting, investigating or prosecuting money laundering or terrorist financing, and that further period shall not exceed five years.

3. Retention is not the whole duty

Article 78 adds the retrieval side: firms must have systems enabling them to respond fully and speedily to enquiries from the FIU or other competent authorities as to whether they maintain, or have maintained during a five-year period before the enquiry, a business relationship with specified persons — and on the nature of that relationship.

That is a searchability requirement, not a storage one. Cold archive that satisfies Article 77 but cannot answer an Article 78 enquiry within a workable time leaves the firm compliant on paper and exposed in practice.

Article 77(2) offers one relief: firms may retain references to information instead of copies, provided the nature and method of retention let them provide the information to competent authorities immediately and the information cannot be modified.

FAQ

Does the five years run from onboarding?

No — from the termination of the relationship, the carrying out of the occasional transaction, or the refusal. An archive keyed to the creation date will delete records that are still required.

Do we keep the assessments that did not result in a report?

Yes. Article 77(1)(b) covers the Article 69(2) assessment whether or not it resulted in a suspicious transaction report, including the information and circumstances considered.

Can an authority extend the period?

Yes, case by case, where necessary for the prevention, detection, investigation or prosecution of money laundering or terrorist financing — and the further period may not exceed five years.


Related: Tipping-off · Ongoing monitoring · AMLR governance

Related reads.