About

AML Record Retention: How Long Should You Keep KYC Data?

AML Record Retention: How Long Should You Keep KYC Data?
Published on 8/30/2026

AML record retention is one of those compliance duties that sounds simple until a real file review begins. A customer was onboarded eight years ago, refreshed three times, screened again after a sanctions alert and then closed last month. Which KYC documents can be deleted, which must be kept and when does the retention clock actually start?

For Jamaican organisations, the answer sits at the intersection of anti-money laundering obligations, privacy law, records management and practical audit readiness. Keep KYC data too briefly and the organisation may be unable to reconstruct a transaction or respond to a regulator. Keep it forever and the organisation creates unnecessary privacy, cyber security and reputational risk.

This article gives general guidance, not legal advice. Regulated entities should confirm the exact rule that applies to their sector, supervisor and risk profile.

Short answer: most KYC data should be kept for at least seven years

For many regulated businesses in Jamaica, the practical AML record retention baseline is at least seven years after the business relationship ends or after the relevant transaction is completed. This commonly applies to customer identification records, customer due diligence materials, beneficial ownership information, transaction records and supporting documents that would allow the organisation to reconstruct what happened.

The seven-year period is especially important because the retention clock usually does not start when the customer first provides the KYC data. For an ongoing customer relationship, it normally starts when the relationship ends. For a one-off transaction, it normally starts when that transaction is completed.

Internationally, FATF Recommendation 11 expects financial institutions to retain transaction and customer due diligence records for at least five years. Jamaica’s AML framework, including the Proceeds of Crime Act and related Money Laundering Prevention Regulations, is generally understood to require a longer retention period for many regulated businesses. Where sector guidance sets a stricter or more specific requirement, that rule should govern.

A simple internal rule can help: keep AML records long enough to satisfy the legal requirement, preserve investigation and audit evidence, then securely dispose of what is no longer needed.

Why KYC retention is different from ordinary customer data

KYC data is not just another customer record. It often includes passports, TRNs, proof of address, occupation details, source of funds, source of wealth, ownership structures, politically exposed person screening, sanctions screening, adverse media results, risk ratings and notes from enhanced due diligence.

Some of this information may not be legally classified as sensitive personal data in every case, but it is still high-impact personal data. If exposed, it can create fraud risk, identity theft risk, physical safety concerns for high-profile customers and regulatory consequences for the organisation.

AML laws require organisations to collect and retain enough information to identify customers, understand risk and assist competent authorities. Data protection law pushes organisations to collect only what is necessary, use it fairly, secure it properly and avoid keeping it longer than needed. The tension is manageable, but it must be designed into the retention process rather than handled case by case.

For a deeper look at this overlap, PLMC has discussed the practical connection between AML and data privacy rules, including how organisations can meet both obligations without treating either as an afterthought.

What counts as KYC data for retention purposes?

KYC data should be defined broadly in the retention schedule. If a record helped the organisation identify the customer, assess risk, monitor activity or decide whether to continue the relationship, it may be part of the AML file.

Common KYC and AML record categories include:

  • Customer identity documents, such as passport, driver’s licence, national ID or company registration documents.

  • Verification evidence, such as proof of address, certification notes, digital verification results or onboarding checklists.

  • Beneficial ownership and control information for companies, partnerships, trusts or other structures.

  • Risk assessments, customer risk ratings, politically exposed person screening and sanctions screening results.

  • Transaction records, payment instructions, account activity records and documents explaining source of funds or source of wealth.

  • Enhanced due diligence materials for higher-risk customers, unusual transactions or complex ownership structures.

  • Internal decisions relating to onboarding, refusal, exit, monitoring alerts or suspicious transaction escalation.

Suspicious transaction reports, internal suspicious activity assessments and related communications require special handling. They should be tightly restricted because of confidentiality and tipping-off risks. Retention rules may apply, but access should be limited to personnel with a clear AML need.

When does the retention clock start?

A common mistake is treating the date of collection as the start of the retention period. That approach can lead to premature deletion. If a customer opened an account in 2018 and closed it in 2026, the KYC file should generally not be deleted in 2025 simply because the passport copy was collected seven years earlier.

The better approach is to define a retention trigger for each record type.

Scenario

Typical retention trigger

Practical approach

Ongoing customer relationship

Date the relationship ends

Keep KYC and CDD records for at least seven years after closure, subject to sector rules and legal holds.

One-off or occasional transaction

Date the transaction is completed

Keep identification and transaction records for at least seven years after completion.

KYC refresh during an active relationship

Relationship end date

Keep enough historical evidence to show what due diligence existed at the relevant time. Remove unnecessary duplicate copies where allowed.

Declined applicant with no transaction

Date of decline or final decision

Set a documented risk-based period, unless AML reporting, investigation, complaint or litigation requires longer retention.

Suspicious transaction escalation

Date of report, decision or case closure

Follow AML legal requirements, regulator guidance and strict access controls. Do not apply routine deletion without compliance review.

The retention trigger should be built into systems and paper processes. If relationship managers, compliance staff and IT teams use different dates, the organisation will struggle to prove consistency.

How the Data Protection Act 2020 affects KYC retention

Jamaica’s Data Protection Act 2020 requires personal data to be handled in line with data protection standards, including fairness, purpose limitation, security and retention discipline. The law does not prevent AML record retention. It requires the organisation to justify it, document it and avoid keeping unnecessary personal data beyond the lawful purpose.

That means an organisation can usually retain KYC data where retention is necessary to comply with AML law. The problem arises when retention becomes open-ended by habit rather than by legal basis. “We might need it someday” is not a strong retention rule. “We are retaining this category for seven years after account closure to comply with AML obligations, then applying secure disposal unless a legal hold applies” is much stronger.

A privacy-aware AML retention programme should answer four questions clearly:

  • What exact KYC data do we collect and why?

  • Which law, policy or risk reason requires us to keep it?

  • What event starts the retention period?

  • Who approves deletion, suspension of deletion or extended retention?

This is where a formal retention schedule becomes useful. PLMC’s article on how retention schedules reduce privacy exposure explains why defined triggers, ownership and disposal rules reduce risk more effectively than vague archive practices.

Building a practical AML record retention matrix

A retention matrix turns legal and policy language into operational instructions. It should be simple enough for compliance, operations, IT and records teams to use without guessing.

At minimum, the matrix should include the record category, system or storage location, owner, retention trigger, retention period, access rules, disposal method and exception process. A small financial institution, professional services firm or designated non-financial institution may not need a complex tool at first, but it does need a single source of truth.

Record category

Minimum retention approach

Key control

Customer identity and verification records

At least seven years after relationship ends or transaction completes

Store in approved KYC repository, not personal inboxes or local drives.

Beneficial ownership records

Align with customer relationship retention period

Keep historical versions that support past decisions.

Transaction records and supporting documents

At least seven years after transaction completion

Ensure records are searchable and capable of reconstruction.

Screening and monitoring evidence

Align with customer file or case retention requirement

Keep audit trail of alerts, reviews and decisions.

Enhanced due diligence files

At least seven years after relationship ends, or longer if a legal hold applies

Restrict access to compliance-approved personnel.

Refused or incomplete onboarding files

Defined risk-based period unless a report, complaint or investigation applies

Minimise unnecessary copies and document the reason for retention.

The matrix should also cover backups. A file deleted from the main KYC platform may still exist in backup media, document management systems, email exports or vendor archives. The policy should explain whether backups are overwritten on a schedule, how restoration is controlled and how the organisation prevents deleted data from being reintroduced into active use without review.

A compliance workspace shows labelled KYC files, a locked storage cabinet, a seven-year calendar, a digital records icon and a shredder for AML retention.

When should KYC data be kept longer?

The seven-year retention period should be treated as a minimum for many AML records, not as an automatic deletion command in every circumstance. Certain events should suspend routine disposal.

A legal hold may be needed where there is an active investigation, regulator request, court order, litigation threat, law enforcement inquiry, internal disciplinary matter, unresolved complaint or suspicious transaction case. In those cases, deletion can undermine the organisation’s ability to respond and may create separate legal risk.

Longer retention may also be appropriate for complex corporate structures, high-risk customers, cross-border investigations or relationships connected to assets that remain under review. The reason should be documented, approved by the appropriate function and reviewed periodically. Indefinite retention should be rare and justified.

The organisation should also decide who can place and release a legal hold. If any manager can casually instruct staff to “keep everything,” the retention programme will eventually become unmanageable. Legal, compliance, data protection and senior management should agree on the hold process in advance.

Secure storage matters while records are being retained

Retention is not only about how long records are kept. It is also about how safely they are kept during that period.

KYC files should not be scattered across email inboxes, shared drives, messaging apps, branch cabinets and personal folders. Fragmented storage makes it harder to locate records for AML purposes and harder to honour privacy obligations. It also increases the chance that outdated ID documents remain accessible to staff who no longer need them.

Strong controls include role-based access, encryption where appropriate, audit logs, clean desk practices for paper files, secure scanning procedures, vendor due diligence and periodic access reviews. Staff should understand that convenience is not a lawful basis for keeping extra passport copies in unofficial locations.

KYC data shared with processors, cloud providers, screening vendors or outsourced compliance partners should also be covered by contracts and instructions. The organisation remains accountable for how personal data is processed, retained, returned or deleted when services end.

What should happen when the retention period expires?

Once the retention period has expired and no legal hold applies, KYC data should move through a controlled disposal process. Deletion should be deliberate, documented and irreversible enough for the medium involved.

Paper records may require cross-cut shredding or secure destruction by an approved vendor. Digital records may require deletion from active systems, controlled overwriting through normal backup cycles and confirmation that archived exports have been addressed. Old laptops, scanners, external drives and mobile devices can hold surprising amounts of KYC data, especially in organisations that handled onboarding manually before moving to digital workflows.

A disposal log should record what was destroyed, when, by whom, under what authority and through which method. This log should not reproduce the personal data being destroyed. It should provide evidence that the disposal process happened.

For practical disposal steps, especially where older paper files and devices are involved, PLMC’s secure disposal process for paper files and old devices is a useful companion to an AML retention review.

Common AML retention mistakes to avoid

Many AML retention failures come from weak process rather than bad intent. The most common issues are predictable.

Organisations often keep KYC records forever because no one owns deletion. Others delete based on the date of onboarding instead of the date the relationship ended. Some retain official copies in a KYC system but leave duplicate ID scans in email, downloads folders or branch cabinets. Another common issue is treating all refused applications the same, even when some involve suspicious activity concerns that require a different compliance response.

The strongest programmes avoid these problems by combining AML expertise, privacy governance and records management. The goal is not to minimise records at all costs. The goal is to retain the right records, for the right period, in the right place, with the right controls.

Frequently Asked Questions

Does Jamaica require KYC records to be kept for seven years? For many regulated businesses in Jamaica, AML records such as KYC, CDD and transaction records should generally be retained for at least seven years after the relationship ends or the transaction is completed. Organisations should confirm any sector-specific rule or supervisory guidance that applies to them.

Does the seven-year period start when the customer gives us the ID document? Usually no. For an ongoing relationship, the safer approach is to start the retention period when the relationship ends. For a one-off transaction, it generally starts when the transaction is completed.

Can a customer ask us to delete KYC data before the AML retention period expires? A customer may make a data protection request, but the right to deletion is not absolute. If the organisation is legally required to retain the data for AML compliance, it should explain the lawful reason for continued retention, restrict use to the relevant purpose and delete the data when the retention period ends.

Should we keep expired IDs after a customer provides updated identification? Often, yes, at least where the expired ID formed part of the due diligence evidence at a particular point in the relationship. The organisation should keep enough historical evidence to show what it knew and when, but it should avoid unnecessary duplicate copies.

Do KYC records in email and shared drives count for retention purposes? Yes. If the record contains KYC data, it creates privacy, security and compliance risk regardless of where it is stored. Unofficial copies should be moved into approved systems or securely deleted according to policy.

What if AML retention conflicts with data protection minimisation? The two duties can be reconciled. AML law may require retention, but data protection principles still require purpose limitation, access control, security, accuracy where relevant and disposal once the legal purpose has expired.

Need help aligning AML retention with data protection?

AML record retention should not depend on guesswork, old filing habits or individual staff memory. A clear retention schedule protects the organisation during audits, supports lawful investigations and reduces unnecessary privacy exposure.

Privacy & Legal Management Consultants Ltd. supports Jamaican organisations with AML compliance, data protection implementation, governance, risk and compliance integration, training and practical risk assessment support. If your KYC retention rules need review, a focused consultation can help you identify gaps and build a defensible way forward.