← All articlesAll firms31 May 2026 · 6 min read

AML record-keeping: what an inspector actually wants to see

What Irish AML supervisors look for in your records: CDD files, risk assessments, training logs, STR records and the AMLR five-year retention rule.

An AML inspection is, above all, a records exercise. Whether the inspector comes from the PSRA, the Law Society of Ireland, a designated accountancy body, the AMLCU or the Central Bank of Ireland, they will not watch you onboard a client. They will read what you wrote down at the time - and if it is not written down, as far as the inspection is concerned, it did not happen.

The stakes around this are rising. Ireland launched a National Risk Assessment and a 30-point AML/CFT Action Plan on 18 June 2026, signalling more active supervision across every sector. The AMLCU's administrative financial sanctions regime has been in force since 30 June 2026 under S.I. No. 307 of 2026. And from 10 July 2027 the AMLR - Regulation (EU) 2024/1624 - replaces the substantive rulebook, bringing its own record-keeping discipline. Here is what a well-kept file set looks like.

The core documents every inspector asks for

Expect a request list along these lines, usually before the visit:

  • Your business-wide risk assessment, current version and review history. This is normally read first, because it tells the inspector whether the rest of the file should make sense.
  • Your AML policies, controls and procedures, with approval dates and the names of your compliance officer and MLRO.
  • Your training log - who was trained, when, on what, and how you know it landed.
  • A sample of client files, often chosen by the inspector from your client list rather than by you.
  • Your STR records, including internal escalations that did not result in a report.
  • Screening and beneficial-ownership evidence, including RBO extracts.

Notice that only one of those six items is about individual clients. Programme-level records carry as much weight as client files.

What a defensible client file contains

For each sampled client, the inspector wants to reconstruct your decisions:

  1. Identification and verification evidence - documents, or the record of an electronic verification, dated.
  2. Beneficial-ownership analysis for corporate clients: who you identified against the 25 per cent threshold, and how.
  3. The RBO extract obtained before the business relationship began, your comparison against what the client told you, and your discrepancy decision - including any report to the Registrar.
  4. Sanctions and PEP screening results, dated, with a note of how any potential matches were resolved.
  5. A risk rating with reasoning, not just a word in a column.
  6. Evidence of enhanced measures where triggers applied - source of funds and wealth work, senior approval.
  7. Ongoing monitoring notes and periodic review dates.

The single most common weakness is not missing documents - it is missing reasoning. A passport copy with no note of who checked it, when, and what they concluded is half a record.

What about STRs and the dual-reporting trail?

Ireland's dual-reporting arrangement creates its own records burden. Suspicious Transaction Reports go to FIU Ireland through the goAML portal at fiu-ireland.ie and to the Revenue Commissioners through ROS. A clean STR trail shows:

  • the internal escalation to the MLRO, dated;
  • the MLRO's decision, with reasons - especially where the decision was not to report;
  • both submissions, with dates and any acknowledgements;
  • careful handling so nothing in the client-facing file risks tipping off.

Inspectors pay particular attention to the "considered but not reported" decisions, because that is where judgement lives. A log of those decisions is one of the strongest signals of a functioning programme.

How does the AMLR change retention?

Under the AMLR, records are retained for five years - and then deleted. That second half is new discipline for most Irish firms, whose archives tend to accumulate indefinitely.

This turns record-keeping into a lifecycle: know when each record's clock starts, keep it retrievable for five years, then dispose of it. Firms holding personal data longer than justified also create a data-protection problem, which is a separate conversation with the Data Protection Commission nobody wants. Building retention and deletion dates into your filing system now - rather than promising a future clear-out - is the practical fix.

Where the AMLR's finer record-keeping details interact with AMLA's technical standards - the first drafts of which went to the European Commission around 10 July 2026 and are awaiting adoption - expect refinements, and leave room in your procedures to absorb them.

What impresses an inspector - and what does not

In our experience of what supervisors publish and ask for, the pattern is consistent. What lands well:

  • Records that are dated, versioned and attributable to a named person.
  • An honest action log: gaps identified, owners assigned, deadlines met.
  • Fast retrieval. Producing a complete file in minutes says more than any policy document.

What lands badly:

  • Policies with no evidence they are followed - the "beautiful binder" problem.
  • Risk ratings with no reasoning.
  • Files scattered across inboxes, shared drives and one partner's memory.
  • Backdating. If a check was done late, record it late with an explanation. An honest late record is a finding; a falsified one is far worse.

What to do now

  • Pull three client files at random and try to reconstruct every onboarding decision from the paper alone.
  • Fix the reasoning gap: require a dated note of who decided what, and why, at each CDD step.
  • Centralise: one place per client for identity evidence, RBO extracts, screening results and review notes.
  • Build an STR decision log, including escalations that did not lead to a report.
  • Add retention start-dates to your files now, so five-years-then-delete is executable in 2032, not a guess.
  • Put your BWRA, policies and training log in inspection-ready shape - they are asked for first.

Where CompliDesk fits

CompliDesk Ireland keeps every check, decision and document in one dated, retrievable record per client, with retention built in - so an inspection request is an export, not a scramble. See it working on your own files by booking a demo.

General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.

Get AMLR-ready before 10 July 2027

Join the waitlist for CompliDesk Ireland and lock in founding-member pricing.

Join the waitlist