AML 5-Year Records: Exactly What You Must Keep under L.4557/2018
'5 years' — but 5 years from when? And exactly what? The law is clear, but many professionals keep either too little or the wrong documents.
What the Law Says: Article 25 L.4557/2018
Under Article 25 L.4557/2018, obliged entities are required to retain: "Copies of the required due diligence documents or information for a period of 5 years after the end of the business relationship or the completed occasional transaction." A crucial detail: the 5 years run from the END of the relationship, not its start. If a client remains your client for 10 years, the records must be kept for 15 years in total (10 + 5). For STRs and internal reports: these records must be kept for 5 years from the date of submission.
Exactly Which Documents Must You Keep?
Complete list of mandatory records: Identification Documents: • Copy of national ID/passport (natural persons) • Articles of association, tax number, tax office (legal entities) • UBO details and related documents Due Diligence Documents: • Risk assessment and score justification • CDD checklist with completion dates • Results of sanctions/PEP list checks • Source of funds documentation (for EDD) Transactions: • Details of all significant transactions • Documentation of unusual transactions (even if no STR was filed) Internal Documentation: • Reasons for refusing an engagement (if applicable) • STRs or SARs filed
Digital or Physical Records?
L.4557/2018 accepts digital record-keeping, provided: • The integrity of documents is ensured (they cannot be altered) • Immediate retrieval is possible for supervisory authorities • GDPR security requirements are met (encryption, access by authorised persons only) In practice: scanned PDFs stored in a secure cloud (not in email or on the desktop) are acceptable and preferable to physical files for ease of retrieval. Caution: Google Drive or Dropbox are not considered "secure" solutions for KYC documents without additional configuration — you need a GDPR-compliant platform.
What Authorities Check & Checklist
In a supervisory audit, authorities typically check: ✓ File completeness (do you have all required documents?) ✓ Currency (are they up to date or have they expired?) ✓ Storage security (where and how are they stored?) ✓ Retrievability (can you provide any file immediately?) ✓ 5-year retention (for former clients) Record-keeping checklist: ☐ Every active client: complete CDD file ☐ Every file: creation date + last update date ☐ Document expiry: alert system before expiry ☐ Former clients: records kept up to 5 years after end of relationship ☐ Annual internal review of file completeness