Record storage
Identify the systems, folders, applications and devices used to hold customer due diligence and related records.
A clear home for regulated informationQ10 helps Queensland firms review where customer due diligence records live, who can access them, how they are retained, whether they are backed up and what evidence the business can produce.
A policy can describe what should happen. The technology environment needs to make that process secure, repeatable and supportable.
Identify the systems, folders, applications and devices used to hold customer due diligence and related records.
A clear home for regulated informationReview who can see, change, download or share sensitive records and whether access follows business roles.
Restricted to authorised peopleCheck whether systems can preserve the required records for the applicable period without relying on memory or manual clean-up.
Retention that matches the programAssess what logs, version history and records exist to show access, changes and the controls applied.
Evidence that can be producedConfirm that electronic records are backed up securely and that the business has a practical recovery path.
Recovery, not only backup reportsReview how records are removed when disposal is authorised and how unnecessary copies are avoided.
Control across the full record lifecycleLawyers, accountants, conveyancers, real estate professionals and dealers in precious metals and stones may now have AML/CTF obligations. The technology layer needs to support the program rather than becoming an unexamined gap.
Read the detailed AML/CTF Tranche 2 IT and data security guide →
What Q10 doesThe work is scoped around the systems and evidence, not around interpreting the law or replacing the business's legal and compliance advisers.
The review is intended for businesses that already understand or are obtaining advice on their obligations and need help with the systems behind them.
Q10 does not decide whether your business is captured by the AML/CTF laws, design or approve your AML/CTF program, provide legal advice or certify compliance.
Your legal or compliance adviser determines the obligations. Q10 helps make sure the systems used to meet those obligations are secure, supportable and capable of producing useful evidence.
Q10 focuses on the technology controls around storage, access, retention, backup and evidence. Legal scope and compliance decisions stay with the business and its legal or compliance advisers.
No. Q10 does not decide whether your business is regulated, write your AML/CTF program or certify compliance. We help implement and review the technology controls that support the process your advisers and business have decided to use.
There is no single required technology platform. AUSTRAC allows records to be kept electronically and expects sensitive records to be stored securely with access limited to authorised people. Q10 can help design the storage, permissions and backup around the system your business chooses.
Many AML/CTF records have seven-year retention requirements, but the starting point varies by record type. For example, customer due diligence records are generally kept for seven years after the business relationship ends, while other records use different triggers. Your retention policy should reflect the specific requirement that applies to each record type.
Potentially, yes. The important question is not the product name but how it is configured. Access controls, retention, audit history, backup, recovery and the way records are organised all matter. Q10 can help configure and review those controls.
Access should be limited to authorised people who need it for their role. Q10 can help implement role-based permissions, separate privileged access and logging so the business has better visibility over who can reach sensitive information.
AUSTRAC's current record-keeping checklist says electronic AML/CTF records should be regularly backed up to secure offsite or encrypted cloud storage, with protection against tampering or unauthorised access and a recovery plan for data loss or cyber incidents.
The useful evidence depends on the process, but commonly includes access history, approvals, version history, sign-in activity, retention settings and records showing that backups and recovery controls are working. Q10 focuses on making that evidence practical to retrieve when it is needed.
Q10 can identify technology gaps and explain what the systems can or cannot demonstrate. We do not provide a legal compliance opinion. Where a control depends on an interpretation of the law or the business's AML/CTF program, that decision should be confirmed with the appropriate adviser.
Tell us which systems hold customer identity and due diligence information, who currently manages them and where the uncertainty sits.