Skip to content
Q10 Systems
Home Pricing Switching providers Resources Call Q101300 110 210 Talk to Q10
AML/CTF technology readiness

Your AML/CTF program still needs secure systems behind it.

Q10 helps Queensland firms review where customer due diligence records live, who can access them, how they are retained, whether they are backed up and what evidence the business can produce.

The operational question

Where do the records actually live, and can the business control and recover them?

A policy can describe what should happen. The technology environment needs to make that process secure, repeatable and supportable.

Storage

Record storage

Identify the systems, folders, applications and devices used to hold customer due diligence and related records.

A clear home for regulated information
Access

Access control

Review who can see, change, download or share sensitive records and whether access follows business roles.

Restricted to authorised people
Retention

Retention

Check whether systems can preserve the required records for the applicable period without relying on memory or manual clean-up.

Retention that matches the program
Evidence

Audit evidence

Assess what logs, version history and records exist to show access, changes and the controls applied.

Evidence that can be produced
Recovery

Backup and recovery

Confirm that electronic records are backed up securely and that the business has a practical recovery path.

Recovery, not only backup reports
Disposal

Secure disposal

Review how records are removed when disposal is authorised and how unnecessary copies are avoided.

Control across the full record lifecycle
Why this matters now

Newly regulated sectors now need their processes and systems to work together.

Lawyers, accountants, conveyancers, real estate professionals and dealers in precious metals and stones may now have AML/CTF obligations. The technology layer needs to support the program rather than becoming an unexamined gap.

Program saysKeep complete and accurate records
Systems mustStore, protect and retrieve them
Business needsConfidence that the evidence is usable
What Q10 does

A practical review of the technology controls behind the process.

The work is scoped around the systems and evidence, not around interpreting the law or replacing the business's legal and compliance advisers.

Map the record flowWhere information enters, where it is stored and which systems or people touch it.
Review permissionsWhether access is limited, consistent and removed when roles change.
Check retention capabilityWhether Microsoft 365, document management or business systems can preserve the required records.
Review backup and recoveryWhether records are protected separately and can be restored after loss or a cyber incident.
Document findingsA concise view of gaps, priorities, evidence and practical remediation options.
Who this is for

Queensland firms moving from a written program to an operational process.

The review is intended for businesses that already understand or are obtaining advice on their obligations and need help with the systems behind them.

  • Accounting and professional services firms
  • Legal practices and conveyancers
  • Real estate businesses
  • Dealers in precious metals and stones
  • AML consultants seeking a technology implementation partner
Important boundary

Q10 supports the technology controls and evidence.

Q10 does not decide whether your business is captured by the AML/CTF laws, design or approve your AML/CTF program, provide legal advice or certify compliance.

Your legal or compliance adviser determines the obligations. Q10 helps make sure the systems used to meet those obligations are secure, supportable and capable of producing useful evidence.

AML/CTF technology FAQ

Questions about the systems behind AML/CTF record keeping.

Q10 focuses on the technology controls around storage, access, retention, backup and evidence. Legal scope and compliance decisions stay with the business and its legal or compliance advisers.

Does Q10 provide AML/CTF legal or compliance advice?

No. Q10 does not decide whether your business is regulated, write your AML/CTF program or certify compliance. We help implement and review the technology controls that support the process your advisers and business have decided to use.

Where should AML/CTF records be stored?

There is no single required technology platform. AUSTRAC allows records to be kept electronically and expects sensitive records to be stored securely with access limited to authorised people. Q10 can help design the storage, permissions and backup around the system your business chooses.

Do AML/CTF records really need to be kept for seven years?

Many AML/CTF records have seven-year retention requirements, but the starting point varies by record type. For example, customer due diligence records are generally kept for seven years after the business relationship ends, while other records use different triggers. Your retention policy should reflect the specific requirement that applies to each record type.

Can SharePoint or Microsoft 365 be used for AML/CTF records?

Potentially, yes. The important question is not the product name but how it is configured. Access controls, retention, audit history, backup, recovery and the way records are organised all matter. Q10 can help configure and review those controls.

Who should be able to access sensitive identity records?

Access should be limited to authorised people who need it for their role. Q10 can help implement role-based permissions, separate privileged access and logging so the business has better visibility over who can reach sensitive information.

Do we need a separate backup of AML/CTF records?

AUSTRAC's current record-keeping checklist says electronic AML/CTF records should be regularly backed up to secure offsite or encrypted cloud storage, with protection against tampering or unauthorised access and a recovery plan for data loss or cyber incidents.

What evidence should our systems keep?

The useful evidence depends on the process, but commonly includes access history, approvals, version history, sign-in activity, retention settings and records showing that backups and recovery controls are working. Q10 focuses on making that evidence practical to retrieve when it is needed.

Can Q10 tell us whether our current setup is compliant?

Q10 can identify technology gaps and explain what the systems can or cannot demonstrate. We do not provide a legal compliance opinion. Where a control depends on an interpretation of the law or the business's AML/CTF program, that decision should be confirmed with the appropriate adviser.

Technology readiness

Start with where the records live today.

Tell us which systems hold customer identity and due diligence information, who currently manages them and where the uncertainty sits.

Talk to Q10
1300 110 210Queensland-wide, remote
Start a conversation

Tell us what you need help with.

Tell us what is happening in plain English. You do not need to diagnose the issue first.