SardineCon SF/2026

Learn More

O que é Recordkeeping?

SUBSCRIBE

Recordkeeping is holding on to the records the law requires, such as CTR and SAR support, funds-transfer details, and CDD documents, for a mandated period so activity can be rebuilt later. A program is only as good as its ability to prove what it saw and what it did.

What is recordkeeping, in plain English?

Behind every filing, decision, and customer relationship sits a pile of records, and the law says you have to keep them. Recordkeeping is the discipline of retaining those required records for a mandated period so that, when someone asks later, the institution can reconstruct exactly what happened. It covers CTR and SAR supporting documentation, funds-transfer details, customer due diligence files, and more.

The mandated period is not a suggestion. In the US, many Bank Secrecy Act records must be kept for five years, and the requirement applies whether or not anyone ever asks for them. The point is that the underlying analytical work, however good, only counts if the institution can actually produce the record when a regulator or law enforcement comes calling.

It is easy to treat recordkeeping as filing-cabinet busywork, but it is really about proof. A monitoring program's decisions are only defensible if the evidence behind them still exists, is retrievable, and has not been tampered with.

What a good record has to do

  1. Complete — Capture the full picture. The record must hold everything needed to reconstruct the transaction or decision, not just fragments.
  2. Retained — Kept for the required period. Records are held for the mandated term, commonly five years under the BSA, regardless of whether they are ever requested.
  3. Retrievable — Producible on demand. When a regulator or investigator asks, the record can be found and produced quickly, not eventually.
  4. Protected — Tamper-resistant. Records are shielded from alteration, so what is produced is demonstrably what was originally captured.

What it looks like in practice

In practice

Four years after a customer relationship ended, law enforcement sends a request tied to a SAR the bank filed on that customer. The investigator needs the supporting documentation: the transaction records, the CDD file, and the analysis behind the filing.

Because the bank retained everything for the required period, indexed it, and kept it in a system that prevents alteration, the compliance team pulls the complete package within a day. Had any piece been purged early, stored somewhere unsearchable, or editable after the fact, the bank would be unable to substantiate its own filing, and being unable to reconstruct a transaction or a decision on request is a serious and surprisingly common deficiency.

Why it matters to operators

The blunt reality is that the underlying work does not count if you cannot produce it. A thorough investigation, a well-reasoned SAR, a diligent CDD process, all of it is worthless as proof if the records have been lost, purged too early, or scattered where no one can find them. Recordkeeping is what converts good work into defensible work.

Being unable to reconstruct a transaction or a decision when a regulator or law enforcement asks is one of the more common and damaging deficiencies a program can have, and it is entirely self-inflicted. The three things to get right are completeness, retrievability, and protection from alteration. Records that are incomplete, slow to retrieve, or editable after the fact all fail the same basic test: can you prove, later, exactly what you saw and did?

Operator notes

  • Know the retention clock. Many BSA records must be kept for five years; purging early is a violation even if nothing ever comes of it.
  • Retrievable means fast. A record you cannot locate on request is effectively a record you do not have.
  • Protect against alteration. If a record can be edited after the fact, its evidentiary value collapses.
  • Cover the full set. CTR and SAR support, funds-transfer details, and CDD files all carry retention duties, not just the filings themselves.
  • Test your ability to produce. Periodically confirm you can actually pull a complete package, before a real request forces the issue.

Quick questions

How long must records be kept?

It depends on the record and the jurisdiction, but in the US many Bank Secrecy Act records must be retained for five years. The requirement applies whether or not the record is ever requested, so retention schedules have to be enforced systematically.

What records fall under the requirement?

CTR and SAR supporting documentation, funds-transfer details, customer due diligence files, and other records specified by law. The scope is broad, covering both the filings and the evidence behind them.

Why is retrievability part of recordkeeping?

Because a record you cannot find when asked is functionally the same as no record. Regulators and law enforcement expect prompt production, so records must be indexed and stored in a way that makes them quickly locatable, sometimes years later.

What does protection from alteration mean?

Records must be safeguarded so they cannot be changed after they are created. If a record could have been edited after the fact, its value as proof of what actually happened is undermined.

Why is poor recordkeeping such a common finding?

Because it is easy to overlook until it is tested. Programs focus on doing the analysis and filing the reports, then discover on request that records were purged early, stored unsearchably, or left editable. The deficiency only surfaces when it is too late to fix.

Go deeper

O que saber junto com Recordkeeping