L
Obiter
AML Compliance 9 min read

AML Record-Keeping Obligations for UK Solicitors

What AML records UK solicitors must keep, for how long, in what format, and how to build a record-keeping system that satisfies the SRA on inspection.

C

Obiter Editorial Team

Published 15 May 2025

Anti-money laundering record-keeping is one of the less glamorous aspects of AML compliance, but it is one of the most frequently cited failings in SRA enforcement decisions. A firm may conduct thorough identity checks and carefully assess its clients’ source of funds — but if it cannot subsequently produce the records demonstrating that it did so, it cannot prove compliance. In an inspection or investigation, the absence of records is treated as evidence of non-compliance.

This guide sets out exactly what records UK solicitors must keep under the Money Laundering Regulations 2017, for how long, in what format, and how to design a record-keeping system that will withstand regulatory scrutiny.

The Regulatory Framework for AML Records

Regulation 40: The Core Obligation

The primary record-keeping obligation for solicitors is set out in Regulation 40 of the Money Laundering Regulations 2017. Regulation 40 requires relevant persons to keep:

CDD records — a copy of, or references to, the evidence obtained in connection with customer due diligence measures, including enhanced due diligence. These must be kept for five years from the end of the business relationship.

Transaction records — supporting evidence and records in respect of transactions subject to the Regulations. These must be kept for five years from the date the transaction is completed.

Policies and procedures — records of the firm’s AML policies, controls, and procedures, including the firm-wide risk assessment, must be kept and be capable of being made available for inspection.

Other Record-Keeping Obligations

Beyond Regulation 40, several other obligations contribute to the overall AML records framework:

SAR records. The MLRO must maintain records of all internal suspicious activity reports made by staff, the decision whether to file an external SAR, and the reasons for that decision. The NCA recommends that SAR records be retained for at least five years, consistent with the wider CDD retention period.

Training records. Records of AML training provided to staff — dates, content, and attendees — must be maintained. These should be available for inspection by the SRA.

The firm-wide risk assessment. This must be documented, dated, and retained, including superseded versions so that the history of the firm’s risk assessment can be reconstructed.

Politically Exposed Person decisions. Where a client is identified as (or screened and found not to be) a PEP, the decision, its basis, and any EDD measures applied should be documented in the client file and retained for the same five-year period.

What the Five-Year Clock Measures

The retention period begins at different points depending on the type of record:

  • CDD records — five years from the end of the business relationship. The business relationship ends when the client matter is concluded (not when the file is closed internally). For clients with ongoing relationships and multiple matters, each matter generates its own five-year clock running from conclusion of that matter.
  • Transaction records — five years from the date the transaction is completed. “Completed” means the transaction is concluded, not when the file is closed internally.
  • Policies and procedures — these should be retained throughout the life of the firm, with previous versions kept so that the policy in force at any given date can be determined.

A common error is confusing the SRA Accounts Rules document retention obligation (six years from the end of the client’s matter) with the AML record-keeping obligation. The periods are different, and both apply. In practice, keeping records for six years satisfies both obligations for most purposes.

What Must Be in the CDD Record?

A compliant CDD record must contain sufficient information to demonstrate that:

  1. The firm identified the client
  2. The firm verified the client’s identity
  3. The firm identified any beneficial owners
  4. The firm obtained information about the purpose and intended nature of the business relationship
  5. The firm assessed the risk presented by the client and the matter
  6. Where EDD was required, the additional measures applied

For Individual Clients

The CDD record should contain (at minimum):

  • Full name, date of birth, and home address
  • Copies of identity documents obtained (passport, driving licence, utility bill, etc.)
  • Where electronic verification was used, a record of the check including the provider, the date, and the result
  • The risk categorisation applied to the client (standard, enhanced)
  • Where EDD was applied, the additional information obtained and the senior management sign-off

For Corporate Clients

The CDD record should contain:

  • Company name, registration number, and registered address
  • Companies House search results (or equivalent)
  • Names and verified identities of directors (at minimum)
  • Beneficial ownership structure
  • Verified identities of all UBOs (individuals with over 25% ownership or control)
  • Risk categorisation and the basis for it

Ongoing Monitoring Records

Where CDD is refreshed during an ongoing relationship — because the client’s circumstances change, the risk profile changes, or the firm conducts periodic re-verification — the updated records must be retained alongside the original CDD material. The record should show clearly when each piece of verification was obtained and why it was refreshed.

Format of Records

The Regulations require records to be kept in a form that enables them to be readily retrieved and provided to the SRA, the NCA, or other relevant authorities upon request. This has practical implications:

Paper vs. Electronic

Both paper and electronic records satisfy the Regulations provided they are accessible and retrievable. In practice, electronic records are strongly preferable because:

  • They cannot be lost, damaged, or misfiled
  • They can be searched and retrieved quickly on request
  • They can be duplicated and backed up
  • They are easier to subject to consistent retention policies

Firms that still maintain paper CDD records should ensure they are stored in a clearly indexed system, protected from damage, and subject to a clear retention and destruction policy.

Accessible Format

Records must be retrievable in a form that is intelligible — a scanned image of a passport should be a legible image file, not a corrupted or unclear scan. Where records are stored in a document management system, the system must be capable of retrieving records by client name and matter number.

Completeness

The SRA will not be satisfied by a record that shows identity documents were obtained but does not include the documents themselves. Firms should ensure that their record-keeping practice involves retaining the documents, not just recording that documents were seen.

The Retention Period in Practice

What Happens at the End of Five Years?

The Regulations require records to be kept for five years, but they do not require them to be destroyed after five years. Most UK law firms have data retention policies (required under GDPR and UK GDPR) that set a maximum retention period. AML records must be kept for at least five years; data protection considerations suggest they should not be kept indefinitely beyond what is necessary.

The practical approach most firms adopt is:

  • Set a retention period of at least five years for AML records
  • Review at the end of the period whether there is a legitimate reason to retain for longer (e.g., ongoing regulatory investigation, pending litigation involving the matter)
  • Destroy securely when the retention period has been met and there is no reason for further retention

High-Risk Matters

For matters that present elevated risk — large-value transactions, EDD clients, or matters where an SAR was filed — many firms adopt a longer retention period (e.g., seven or ten years) as a precaution.

Concurrent Regulatory Retention Periods

Several other retention obligations overlap with AML record-keeping:

  • SRA Accounts Rules — records of client account transactions must be kept for a minimum of six years
  • UK GDPR — personal data must be kept only for as long as necessary for the purposes for which it was collected; AML compliance constitutes a legal obligation justifying retention for the MLR period
  • HMRC requirements — tax and financial records may have their own retention periods
  • Limitation periods — professional negligence claims have a six-year limitation period, which may inform decisions to retain matter files beyond the minimum

The safest practice is to adopt a retention period that satisfies the most demanding applicable obligation.

Building a Record-Keeping System

Centralised vs. File-Level Storage

There are two broad models for AML record storage:

File-level storage — CDD documents are stored in the individual matter file. This is simple and ensures that the CDD record is easily found alongside the file to which it relates. The risk is that if the matter file is destroyed, the CDD records go with it.

Centralised AML register — CDD records are stored centrally, indexed by client, with links to associated matter files. This is more robust for long-term retention because the AML register is maintained independently of individual matter files. The SRA increasingly expects firms to maintain a centralised client register that records AML status.

Best practice combines both: CDD documents stored at the matter level for day-to-day use, with key compliance data also recorded in a centralised AML register or practice management system.

Practice Management System Integration

Most modern practice management systems (PMS) include functionality for recording and storing CDD information. Firms should ensure that:

  • CDD data entry is mandatory for all in-scope matters
  • The PMS can generate a report showing all matters where CDD is incomplete or overdue for renewal
  • Records are securely backed up
  • Access to CDD records is appropriately controlled (access only to those with a legitimate need)

Audit Trails

An audit trail — a record of who accessed, modified, or added to the CDD record, and when — is best practice and increasingly expected by the SRA. This provides assurance that records have not been altered and demonstrates the chronology of compliance activity.

Common Record-Keeping Failures

The SRA’s published enforcement decisions and inspection feedback highlight recurring record-keeping failures:

No record that CDD was conducted. The firm conducted identity checks but did not retain evidence of the documents obtained. The fee earner remembers seeing the passport; there is nothing in the file to prove it.

Incomplete records. Identity documents retained but no record of the source of funds check, the risk assessment, or the basis for any enhanced due diligence.

Stale records. CDD obtained three years earlier has not been refreshed, despite the client returning for a new matter with materially changed circumstances.

Inaccessible records. Documents stored in a system that is no longer accessible, or in a format that cannot be read with current software.

Premature destruction. Files destroyed before the five-year retention period has run, because the firm’s standard file destruction policy was applied without checking AML retention requirements.

Inadequate SAR records. The MLRO made a decision not to file an SAR, but there is no written record of the reasoning. If the matter subsequently comes to light as involving criminal funds, the firm cannot demonstrate the decision was properly considered.


Obiter stores all AML records — identity documents, verification results, risk assessments, EDD files, and SAR decisions — in a searchable, audit-trailed compliance register that is separate from individual matter files. When the SRA asks for your CDD record for a matter completed four years ago, your MLRO can produce it in under a minute.

Topics:

record-keeping aml compliance audit-trail

Ready to reclaim 12+ hours a week?

See how Obiter handles your legal admin so you can focus on advising clients.