AML/CTF record keeping: can your Microsoft 365 prove it?

Avatar photo
By Chris Arceo / Oct 2, 2026 / Cybersecurity & Compliance

Since 1 July 2026, around 80,000 law firms, accounting practices, conveyancers and real estate agencies have been AUSTRAC reporting entities. Most have now enrolled, appointed a compliance officer and adopted an AML/CTF program. The harder part starts now, and it has very little to do with the law itself. AML/CTF record keeping means producing seven years of customer due diligence, risk assessments and reporting records on request, and proving who could see them along the way.

For most professional services firms in Perth, those records live in Microsoft 365. That makes Tranche 2 an IT question as much as a legal one.

What Tranche 2 changed, in one minute

The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 extended AUSTRAC’s regime to lawyers, accountants, conveyancers, real estate professionals, trust and company service providers, and dealers in precious metals and stones. Obligations apply when a firm provides a designated service: helping with a property transaction, holding client money, setting up companies or trusts, acting as a nominee, or providing a registered office address.

Captured firms must enrol with AUSTRAC, run a risk-based AML/CTF program, carry out customer due diligence, screen for sanctions and politically exposed persons, report suspicious matters, and keep records. Enrolment closed on 29 July 2026 for firms already providing designated services.

We are not AML advisers, and this post is not legal advice. Your obligations depend on which services you provide, and that is a conversation for your lawyer or AUSTRAC’s own guidance. What we can tell you is what the systems side looks like, because that is where firms get caught out.

AML/CTF record keeping is a systems problem

AUSTRAC’s record keeping guidance is plain about it. Customer identification records must be kept for seven years after the business relationship ends. Program records must be kept until seven years after they stop being relevant. Records have to be retrievable when AUSTRAC asks for them.

Now think about where those records actually sit in a typical firm. ID documents arrive as email attachments. Due diligence notes are saved into a matter folder in SharePoint, or into someone’s OneDrive. The risk assessment is a Word document that three partners have edited. Training records are spread across a learning platform and a spreadsheet.

Microsoft 365 does not keep any of that for seven years by default. When a staff member leaves and their licence is removed, their mailbox and OneDrive are deleted after a short grace period unless someone has put retention in place. Deleted items are recoverable for weeks, not years. Standard audit logs, which show who opened what, are kept for 180 days. If your AML/CTF record keeping depends on Microsoft’s defaults, you have a gap today, even if nobody has asked for the records yet.

Where AML/CTF obligations land in Microsoft 365

Here is how the obligations map to systems and controls. The last column points to the work we have already written about, because most of these controls are not new. They are the same ones the Privacy Act, SMB1001 and your cyber insurer already expect.

AML/CTF obligation Where the evidence usually lives Control that proves it Read more
Seven-year record keeping Exchange, SharePoint, OneDrive, practice management system Retention policies and retention labels in Microsoft Purview, applied before staff leave Data governance for small business
Retrieving records on request Matter folders spread across sites and personal storage A defined location for AML records, plus eDiscovery search across the tenant Data classification for Copilot
Confidential suspicious matter reports Compliance officer’s mailbox and working files Restricted site or library, sensitivity labels, access reviews Access management
Protecting client ID documents Inboxes and shared drives Phishing-resistant MFA, conditional access, data loss prevention Phishing-resistant MFA
Showing controls work over time Nowhere, in most firms Audit logging with longer retention, documented quarterly access reviews IT system audits

Suspicious matter files need tighter access than anything else you hold

This is the part we would worry about most. The AML/CTF Act restricts disclosing information about a suspicious matter report in ways that could prejudice an investigation, commonly called tipping off. Your SMR working files are, by design, information that most of your own staff should never see.

In a lot of firms, nobody could tell you today who can open the compliance officer’s folders. Permissions in SharePoint and Teams grow by accident. A matter site gets shared with “everyone except external users” to save time. A former employee’s access was never removed. A partner’s assistant has full mailbox access that predates the AML program by a decade.

Then add AI. Microsoft 365 Copilot respects existing permissions, which sounds safe until you realise it means Copilot will surface anything a user can technically reach. If a junior staff member can open the SMR folder, Copilot can summarise it for them. We covered why this is really a permissions problem rather than an AI problem, and the same fix applies here: classify the sensitive data, lock down who can reach it, and review that access on a schedule you can show an auditor. If your firm is weighing up AI tools, where that data goes matters too.

You already have most of the building blocks

Firms tend to treat each new regime as a fresh project. That is expensive and it is unnecessary. AML/CTF record keeping overlaps heavily with obligations you already carry.

Framework What it already asks of you How it helps with AML/CTF
Privacy Act Protect personal information, notify eligible breaches, destroy data you no longer need Client ID documents are personal information, so security and breach planning carry straight over. Seven-year AML retention is your lawful reason to keep them
SMB1001 Documented policies, MFA, access control, backups, staff training, and an AI use policy at Gold Gives you evidence of governance and training that an AML/CTF program also needs
Essential Eight Restricting admin privileges, MFA, patching, backups Reduces the chance that AML records are stolen or encrypted in a ransomware attack
Cyber insurance Evidence of MFA, EDR, backups and access reviews before cover is offered The same evidence pack answers AUSTRAC questions about how records are protected

We wrote a longer piece on how the Privacy Act, Essential Eight and SMB1001 overlap. AML/CTF slots into the same picture as one more consumer of the same controls. If your IT provider also handles personal information on your behalf, check whether they understand their processor obligations under the Privacy Act, because the same provider will be touching your AML records. And if the Essential Eight is part of your plan, keep an eye on the ASD’s transition to the Essentials series.

What this looks like for law firms, accountants and real estate agencies

Law firms already run tight matter management, but AML records often sit outside the practice management system in email and personal folders. The fix is usually a defined home for AML records with retention labels, and a clean-up of mailbox delegation. Our IT services for law firms and our guide to what a Perth practice actually needs cover the wider setup.

Accounting practices are only captured for certain services, such as company and trust formation, so the challenge is separating AML-relevant engagements from everyday tax work. We covered the broader obligations in our compliance guide for Perth accounting firms, and our IT services for accountants page explains how we support practices.

Real estate agencies handle high volumes of buyer and vendor ID through email, often across many agents with high staff turnover. That makes offboarding and retention the biggest risks. Our IT support for real estate agencies covers how we handle it. Business email compromise is also a live threat in property settlements, which we explain in how AI has changed BEC.

What you should do now

Find out where your AML records actually live. Ask your compliance officer to list every place customer due diligence, risk assessments and SMR working files are stored, including email. If the answer includes personal OneDrive folders, you have a retention and access problem to fix first.

Check retention before your next staff departure. Confirm that Purview retention policies cover the mailboxes, sites and OneDrive accounts holding AML records for at least seven years. It is quick to configure and very hard to fix after a mailbox has been purged.

Run an access review on your most sensitive folders. Find out who can open the compliance officer’s files, remove anyone who should not, and record that you did it. Then repeat it quarterly. If you want help, we run Microsoft 365 access and data governance reviews for professional services firms, and our vCIO service can keep the review cycle running. Contact us on 1300 EPIC IT to book one.

Frequently asked questions

How long do AML/CTF records need to be kept in Australia?

AML/CTF record keeping rules generally require records to be kept for seven years. Customer identification records are kept for seven years after the business relationship ends, transaction records for seven years from creation, and program records until seven years after they are no longer relevant. Check AUSTRAC’s guidance for the rule that applies to each record type.

Does Microsoft 365 keep emails for seven years by default?

No. Without retention policies, deleted items are only recoverable for a short period, and a departing staff member’s mailbox and OneDrive are deleted after their licence is removed. To meet AML/CTF record keeping obligations, configure Microsoft Purview retention policies or labels on the locations that hold AML records.

Who is captured by the Tranche 2 AML/CTF reforms?

From 1 July 2026, lawyers, accountants, conveyancers, real estate professionals, trust and company service providers, and dealers in precious metals and stones are captured when they provide designated services. Whether your firm is captured depends on the services you provide, so confirm your position with AUSTRAC’s guidance or a legal adviser.

Can Microsoft Copilot expose suspicious matter reports?

Copilot can only show a user content they already have permission to open, but in many firms those permissions are far too broad. If staff outside your compliance function can reach SMR working files, Copilot can surface them. Tighten permissions and apply sensitivity labels before rolling out Copilot.

Is AML/CTF compliance an IT responsibility?

The AML/CTF program is owned by your governing body and compliance officer, not your IT provider. Your IT provider is responsible for the systems that store, protect and retrieve the evidence. Both sides need to agree where records live, how long they are kept, and who can access them.

Can your Microsoft 365 stand up to an AUSTRAC request?

Our Perth team will review where your AML records live, how long they are kept and who can reach them. Book a free Microsoft 365 access and retention review.

Book a Free Review

About the Author
Written by Chris Arceo, Cyber Security Officer at Epic IT, a CRN Fast50-recognised managed IT services provider in Perth. Chris holds a Bachelor of Science in Information Technology (Network Administration) and over a dozen active certifications including CompTIA Security+, Cisco CCNA, and specialist qualifications across Datto, Sophos, Kaseya, and ConnectWise platforms.

Further Reading

Previous

Property Shell reporting: find stalled reservations before they die

Return to News
Back to News
Next
No next posts to show