Skip to main content
Category: Compliance Program Governance

Record Retention (Five-Year Rule)

Also known as: Five-Year Retention Rule, Record Retention Period, Records Retention Requirement
Simply put

Record retention refers to the period during which an organization must keep documents and records for legal, tax, financial, administrative, or other purposes before they can be disposed of. A "five-year rule" describes a specific retention period of five years that applies under certain regulations, though the exact length varies considerably depending on the record type, regulatory regime, and jurisdiction. Not every record is subject to a five-year period; some rules impose shorter or longer terms, and the applicable duration should always be confirmed against the specific regulation that governs the record in question.

Formal definition

A retention period is the amount of time an organization keeps records and documents for legal, tax, financial, administrative, or historical purposes, and it typically runs from a defined trigger point such as the date a record becomes inactive or a disclosure is made. The label "five-year rule" is not a single, universal standard; it describes discrete requirements found in particular instruments rather than one harmonized obligation, and retention periods diverge sharply across regimes and record categories. For example, under the U.S. Consumer Financial Protection Bureau's Regulation Z (12 CFR 1026.25), a five-year retention obligation attaches to specified records such as those tied to the Closing Disclosure, while other records under the same regulation are subject to shorter retention terms; this illustrates that a five-year period may govern only a defined subset of records within a given rule and should not be assumed to apply to all records under that regime. Separately, retention frameworks in records-management practice (such as approved retention schedules that may themselves be valid for a fixed number of years) are administrative controls distinct from the statutory retention duties imposed on obliged entities. Practitioners should determine the precise trigger date, covered record types, applicable duration, and governing instrument for each retention obligation, as some regimes impose periods substantially longer than five years and exact values must be confirmed against the applicable regulation.

Why it matters

Record retention obligations sit at the intersection of legal defensibility and operational discipline. When a supervisor, auditor, or law enforcement authority requests documentation, whether to reconstruct a transaction, verify a customer identity check, or test the adequacy of a control, an obliged entity must be able to produce complete and accurate records for the full period the applicable rule requires. Failing to retain records for the mandated duration can expose an organization to regulatory findings and enforcement action independent of whether any underlying misconduct occurred, because the recordkeeping duty is itself a standalone obligation in many regimes.

The term "five-year rule" is a source of frequent confusion precisely because it is not a single, harmonized standard. Retention periods diverge sharply across instruments and record categories: under the U.S. Consumer Financial Protection Bureau's Regulation Z (12 CFR 1026.25), a five-year period attaches to specified records tied to the Closing Disclosure, while most other records under the same regulation are subject to shorter terms such as two or three years. Other regimes impose substantially longer periods, for example, NHTSA's August 2024 final rule extended the retention requirement for records under 49 CFR 576.6 to ten years. Treating "five years" as a universal default therefore risks both over-retention, which creates data-protection and storage burdens, and under-retention, which can result in destroyed records that were still legally required.

For compliance and records-management functions, the practical stakes lie in mapping each record type to its correct governing instrument, trigger date, and duration. A misclassified retention schedule can cause records to be purged prematurely or held beyond their lawful basis, and neither outcome is easily remedied after the fact. Getting retention right is thus a matter of both regulatory compliance and sound information governance.

Who it's relevant to

Compliance officers and AML program managers
These professionals are responsible for ensuring that required records are retained for the correct period under each applicable instrument. They must translate statutory retention duties into internal policies and confirm that the retention period, trigger date, and covered record types align with the specific regulation governing each record, rather than applying a single blanket period across all documentation.
Records and information governance teams
These teams design and maintain retention schedules that assign holding periods to record categories. They should distinguish between the administrative validity of a schedule itself, which may lapse and require renewal after a fixed term such as five years, and the underlying legal retention duty attached to individual records, and they must guard against both premature destruction and unnecessary over-retention.
Auditors and examiners
Internal and external auditors, as well as regulatory examiners, test whether an organization can produce complete records for the full period required by the governing rule. Their reviews depend on records being correctly classified and retained, and shortfalls can lead to findings even where no underlying misconduct is present.
Legal and regulatory counsel
Counsel advise on which instrument governs a given record and for how long, particularly where periods diverge, such as a five-year duty for certain Regulation Z records versus longer periods like the ten-year requirement introduced for records under 49 CFR 576.6. They help resolve conflicts between retention mandates and data-minimization obligations and confirm exact durations against the applicable regulation.

Inside Record Retention (Five-Year Rule)

General Five-Year Retention Baseline
Many AML regimes require obliged entities to retain CDD records and transaction records for a minimum period, commonly five years, after the end of the business relationship or the date of an occasional transaction. This baseline appears, for example, in the FATF Recommendations (as a standard, not binding law), the EU AML framework, and the UK Money Laundering Regulations. Exact triggering events and start dates vary by regime and should be confirmed against the applicable instrument.
Scope of Records Covered
The retention duty typically covers customer identification and verification records (CDD/KYC documentation), records supporting the beneficial ownership determination, account files and business correspondence, and records of transactions sufficient to reconstruct individual transactions. What falls within scope depends on the specific obligation and obliged-entity category under the applicable regime.
Start Date / Triggering Event
The retention clock generally starts from a defined event, such as the termination of the business relationship or the completion of an occasional transaction, rather than from account opening. The precise triggering event differs across jurisdictions and record types and should be verified against the governing regulation.
Extension and Competent Authority Requests
In some jurisdictions, competent authorities or supervisors may require records to be retained beyond the baseline period, for example where relevant to an ongoing investigation or legal proceeding. The availability and mechanics of such extensions are regime-specific.
Distinction from Other Retention Regimes
AML record-retention obligations are separate from retention duties imposed by non-AML rules. For instance, under US Regulation Z (Truth in Lending), 12 CFR 1026.25 imposes a five-year retention duty only for records evidencing compliance with Closing Disclosure requirements; most other Regulation Z records carry a two-year retention period. Practitioners should not assume a single uniform five-year period applies across all record categories or all regulatory frameworks.
Format and Accessibility
Retention obligations generally require that records be kept in a manner that allows them to be retrieved and made available to competent authorities on request. Whether electronic copies, originals, or specific formats are acceptable depends on the applicable regime.

Common questions

Answers to the questions practitioners most commonly ask about Record Retention (Five-Year Rule).

Is there a single global 'five-year rule' that requires all AML records to be kept for exactly five years?
No. There is no single universal rule. A five-year minimum retention period is a common baseline reflected in the FATF Recommendations, which are standards rather than binding law, and it appears in many national frameworks such as the EU AML Directives and the UK Money Laundering Regulations. However, the exact period, its start date, and the records covered vary by jurisdiction and by the type of record. Some regimes permit or require longer retention, and competent authorities may extend the period in specific circumstances. Exact requirements should always be confirmed against the applicable regulation for each jurisdiction and obliged entity.
Does the five-year period always start on the date a record is created?
Not necessarily, and this is a frequent point of confusion. In many AML regimes the retention clock is tied to a specific triggering event rather than the record's creation date. For customer due diligence and identification records, the period commonly runs from the end of the business relationship or the date of an occasional transaction, while transaction records are often retained for a period measured from the date the transaction was completed. Because the trigger differs by record type and jurisdiction, the applicable regulation should be checked to determine when the clock begins.
Which records are typically covered by AML retention obligations?
Coverage generally extends to customer due diligence and identification materials, records supporting the business relationship, transaction records sufficient to reconstruct individual transactions, and documentation related to internal analysis and any reports made to authorities. The precise categories are defined by the governing regime, so obliged entities should map their record types to the specific instrument that applies to them rather than assuming uniform coverage. Retention obligations under AML frameworks are distinct from record-keeping duties arising under other bodies of law, which may set different periods for different document types.
How should retention obligations be handled when multiple regulatory regimes apply to the same record?
Where more than one framework applies, entities generally apply the longer or more stringent retention period to avoid falling short of any single obligation, subject to legal advice. It is important to identify which duty attaches to which record type, because a period specified under one regime for a particular document does not necessarily apply to all records held by the entity. Firms often maintain a retention schedule that maps each record category to its governing source instrument and period, and confirm the applicable values against the relevant regulations.
Can records be kept in electronic form to satisfy retention requirements?
In many jurisdictions retained records may be held electronically, provided they remain complete, accessible, and capable of being reproduced or reconstructed on request by the competent authority. Requirements around format, integrity, and retrievability differ between regimes, so entities should confirm whether their storage arrangements meet the standards set out in the applicable regulation, including any expectations about how quickly records must be made available.
What should happen to AML records once the retention period ends?
Once the minimum retention period expires, many frameworks expect or require that personal data be deleted unless a lawful basis exists to keep it longer, reflecting the interaction between AML retention duties and data protection obligations such as those under the EU General Data Protection Regulation. Some regimes permit extension where retention remains necessary, for example in connection with an ongoing investigation or at the direction of an authority. Entities should establish a defensible process for reviewing, extending where justified, and securely disposing of records, and confirm the specific rules under the applicable regime before deletion.

Common misconceptions

A single global five-year rule applies to all financial-crime and financial records.
There is no universal five-year rule. AML frameworks commonly reference a five-year minimum, but triggering events, start dates, and covered record types differ by jurisdiction. Separately, non-AML rules impose their own, sometimes shorter, periods; for example, most US Regulation Z records must be kept for two years, with the five-year duty under 12 CFR 1026.25 limited to Closing Disclosure-related records.
The five-year period always begins when the account is opened.
In many AML regimes the retention period typically starts from the end of the business relationship or the completion of an occasional transaction, not from account opening. The exact triggering event varies and should be confirmed against the governing regulation.
Records can be destroyed automatically once the five-year period ends.
Not necessarily. In some jurisdictions competent authorities or supervisors may require retention beyond the baseline, such as where records are relevant to an ongoing investigation or proceeding. Automatic destruction schedules should account for such possible extensions.

Best practices

Map each category of records you hold to the specific retention obligation that governs it, distinguishing AML retention duties from separate obligations under consumer-protection or other rules, and confirm the exact period and start date against the applicable regulation rather than assuming a uniform five-year period.
Document the triggering event for each retention clock (for example, end of the business relationship versus completion of an occasional transaction) so that destruction dates are calculated consistently and defensibly.
Implement a legal-hold mechanism that suspends routine destruction where a competent authority, supervisor, or ongoing investigation or proceeding may require records to be kept beyond the baseline period.
Ensure retained records remain retrievable and can be made available to competent authorities on request, addressing format, indexing, and accessibility for both electronic and physical records.
Maintain a written retention schedule that identifies the source instrument for each retention period, and review it periodically to reflect regime-specific changes and divergences across jurisdictions in which you operate.
Coordinate retention practices across AML, credit, and other compliance functions to avoid conflating differing periods and to prevent premature destruction of records subject to a longer applicable duty.