The six retention clocks running in your practice
Ask how long a client file should be kept and there is no single answer. That's not the real problem.
·31 July 2026·About 5 minutes
A company set-up completed a few years ago.
Two directors. The usual paperwork. A photo of each director’s driver’s licence emailed to the practice so identity could be verified.
The work was finished that month.
The licences were never looked at again.
Today, they are probably still somewhere in the business. A client file. A mailbox. A shared drive. A scan folder. A backup.
Nobody deliberately chose to keep them. Nobody deliberately reviewed them. They simply stayed where they landed.
The surprising part?
They may be the only documents in that file that no regulator required the practice to keep.
Everyone talks about seven years. The answer is less tidy than that.
Ask an accounting practice how long client records should be retained and you’ll usually get a single answer.
Seven years.
Sometimes five.
Both answers are correct. Neither answers the question.
A typical client file can be subject to at least six different retention periods, set by four different bodies and beginning at six different points in time.
The retention period is not the difficult part.
The starting date is.
A tax record begins on one date. An audit work paper on another. AML/CTF records on another again. Some periods start when work is completed. Some start when a report is issued. Some start when the business relationship ends.
The result is a file where multiple retention obligations are running at the same time, each on a different schedule, with nothing in the file itself explaining which document belongs to which clock.
The six clocks
Company financial records
7 years- Clock starts
- when the transactions covered by the records are completed
- Set by
- Corporations Act 2001 (Cth), s286
Taxation records
5 years- Clock starts
- when the records were prepared or obtained, or the transaction completed, whichever is later
- Set by
- Income Tax Assessment Act 1936 (Cth), s262A
Client records under the Code
At least 5 years- Clock starts
- after the tax agent service has been provided
- Set by
- Tax Practitioners Board
Audit work papers
7 years- Clock starts
- after the date of the audit report or review
- Set by
- CPA Australia guidance
Superannuation records
10 years- Clock starts
- varies by document (trust deed, trustee minutes, investment strategy, trustee declarations)
- Set by
- ATO
Customer due diligence records
7 years- Clock starts
- from the end of the business relationship
- Set by
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), Part 10
In practice, one client folder can hold documents sitting on several of these at once.
Tax records on five years.
Company records on seven years.
Audit work papers on seven years.
Superannuation records on ten years.
Customer due diligence records on seven years, beginning only when the business relationship ends.
And then there is the driver’s licence collected during onboarding.
Sitting alongside records that run for five, seven and ten years.
Often without being one of the records the practice was required to keep.
The problem isn’t the clocks
The problem is that none of those clocks applies to the client file itself.
Every obligation applies to a specific type of record. The client folder is simply the way practices organise work.
The legislation recognises records.
The software recognises clients.
Those are not the same thing.
Practice management systems are designed to store work by client, job or matter. They are not designed to determine which Act governs each document inside that file, when a retention period begins, or when a document should be destroyed.
So retention becomes something people remember rather than something systems manage.
That works reasonably well until somebody asks a simple question:
What exactly are we holding, and why are we still holding it?
The document with no obvious home
The other records in the table exist because legislation, a regulator or a professional obligation requires them to be kept.
Identity documents are different.
All three regulators with an interest have reached the same conclusion: keep a record of the verification. Not necessarily a copy of the document itself.
The Tax Practitioners Board has been particularly clear. In its guidance on keeping proper client records, it notes that “we do not recommend that you keep copies of identity documents”. Its practice note goes further, stating that the TPB “does not require or recommend that registered tax practitioners retain copies or originals of identification documents”.
The expectation is a contemporaneous record of the verification process. Where copies have been received electronically, the TPB recommends they be destroyed once that record has been made. The concern is not only privacy. Holding identity documents increases the value of the information a practice holds and makes it a more attractive target.
AUSTRAC takes a similar position from the AML/CTF perspective. In its record-keeping guidance, it states that reporting entities “aren’t required to make copies of identification documents provided as part of CDD”. What must be retained is the record of what was done to identify the customer and the information provided during that process.
The OAIC reaches the same conclusion and adds a disposal obligation. In its privacy guidance for reporting entities, it confirms that the AML/CTF Act “does not require you to keep scanned copies or photocopies of identity documents themselves for record keeping purposes”, and that organisations should take reasonable steps to destroy or de-identify those copies when they are no longer required.
Read those positions together and the picture becomes clear.
The document many practices assume they are required to retain is often the one no regulator required them to keep.
One qualification that matters
Before anyone starts deleting records, there is an important distinction.
Copies of identity documents created before 31 March 2026 are treated differently. The OAIC has confirmed that reporting entities are authorised to retain those records for seven years after the business relationship ends.
The move toward keeping verification records rather than document images is not retrospective.
What changes is the expectation going forward.
New verifications should produce a record of the check rather than a photograph or scan of the identity document itself. Historical copies need to be identified, secured and managed appropriately rather than left sitting indefinitely throughout the business.
Which category a particular document falls into is a matter for the practice and its advisers.
If in doubt, seek advice.
Which raises a harder question
A client’s driver’s licence is not sitting in the practice because a regulator required it to be there. So the questions that follow are simpler ones.
Why is it still there?
How many copies exist?
Which mailbox received it?
Which shared drive holds it?
Who can still open it?
Could the practice locate every copy if it needed to?
Most firms have never had cause to find out.
What this means in practice
The real challenge is not calculating retention periods.
It is knowing four things:
What information the practice holds.
Where it is held.
Who can access it.
What happens to it when it is no longer needed.
Those are technology and data management questions as much as compliance questions.
Start with one client
Pick the last client the practice onboarded.
Now try to identify every place their identity documents exist today.
The client file.
The mailbox.
Sent items.
Downloads.
Shared folders.
Backups.
Most firms discover more copies than they expected.
And that usually tells them more about their readiness than any retention schedule ever could.
Where efex can help
The technology side of AML/CTF and privacy obligations is often the hardest part to see.
We help firms locate and map client data across Microsoft 365, shared drives and endpoints, configure retention and disposal rules so they run automatically, and control who can access the records that remain.
Your obligations under the AML/CTF Act and the Privacy Act, and how they apply to your practice, are matters for the regulators and your own compliance and legal advisers.
We have created a helpful checklist that starts with a simple question:
Could your practice locate every copy of a client’s identity documents today?
It then works through thirteen technology and data management questions covering storage, access, retention and security.
You won’t need a client file.
Nothing is uploaded.
Start the AML/CTF Technology and Data Checklist.
Thirteen questions. About three minutes. Your three highest-priority actions at the end.
efex does not determine whether a business is captured by the AML/CTF regime and does not provide legal or compliance advice.
Sources
- Corporations Act 2001 (Cth), s286, Obligation to keep financial records
- Income Tax Assessment Act 1936 (Cth), s262A, Keeping of records
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), Part 10
- Tax Practitioners Board, Obligation to keep proper client records
- TPB(PN) 5/2022, Proof of identity requirements for client verification
- AUSTRAC, Record-keeping overview
- OAIC, Privacy guidance for reporting entities under the AML/CTF Act
- ATO, SMSF record-keeping requirements
- CPA Australia, Client Relationship Guide
Thirteen questions. About three minutes. No client files.
Or talk it through first. Thirty minutes, no obligation, with somebody who does this work every day.
These articles explain what the regulators have published and what it commonly means in practice. General information only, not legal or compliance advice.
