RegTech and Compliance · 25 February 2026 · 9 min read
UK Record-Keeping Obligations: A Practical Reading
The UK ML regulations set retention rules that look simple and behave less simply. DC-Services maps the requirements to actual document handling.

The UK Money Laundering Regulations set out retention and traceability requirements that are short in text and demanding in practice. Records must survive in a form that can be produced, indexed and tied back to the original engagement years after the file went quiet. DC-Services maps the requirement to the document handling: what is kept, in what state, where it lives, and how long it stays there — without the regulatory phrasing pretending to be its own implementation plan.
What The Regulations Actually Require
The headline rule is familiar: records of customer due diligence and supporting transaction material must be retained for five years after the end of the business relationship or completion of the occasional transaction. The harder part is what counts as a record, and what counts as the end of the relationship — neither of which is as obvious in a long-running engagement as it looks on the page.
The file works to the substance of the requirement rather than the comfortable minimum. Where a relationship is on pause rather than ended, the retention clock is treated accordingly. Where the regulation lists categories of record, each category is mapped to specific document types in the working file, so retention is operational rather than aspirational.
Form, Not Just Existence
A retained record that cannot be produced in a usable form is, for regulatory purposes, the same as a record that does not exist. Files held in formats that have since become unreadable, on hardware nobody has access to, or in cloud accounts the original owner no longer controls, fail the test the moment they are asked for.
Records are stored in formats that survive software cycles, with checksums and indices that make production a routine task rather than an expedition. The point is unglamorous: a record that exists and can be produced is the only kind of record the regulations consider you to hold.
Indexing So That Production Is Possible
A five-year retention window is not useful if the file cannot be located. Practical retention requires an index that ties every document to the matter, the date, the source and the version. Without it, the right document may be present and still effectively missing.
Each archived item carries metadata covering the engagement reference, the document type, the date of receipt, the source and a content hash. Locating a specific record three years on becomes a query rather than an excavation.

Sealing And Versioning
Retention is undermined by quiet editing. A record that was correct when it was filed and has since been altered without trace is no longer the record that was relied on at the time. The regulation assumes the file kept is the file produced, and that assumption needs operational support.
Archived versions are sealed against further change once filed. Where a document is reissued or corrected, the original is preserved alongside the new version, with the relationship between them documented. The history is then auditable, not reconstructed under pressure.
When The Clock Actually Stops
The five-year period starts at the end of the relationship or the completion of the transaction, which sounds straightforward and often is not. Long-running engagements, dormant matters and recurring instructions complicate the question of when the relationship has actually ended in regulatory terms.
The file records an explicit end-of-relationship determination for each engagement, with the basis on which it was made. The retention clock then runs from a documented event rather than a guess at one. Where the determination changes — for example, where the client returns — the clock is reset with a note explaining why.
Retention Categories and Practical Handling
| Record category | Minimum retention | Practical requirement |
|---|---|---|
| Customer due diligence | 5 years from end of relationship | Indexed, sealed, in readable format |
| Transaction records | 5 years from transaction completion | Linked to CDD and engagement reference |
| Internal SAR records | 5 years from report | Held separately with access controls |
| Risk assessments | 5 years from supersession | Versioned, with the prior version preserved |
| Training records | 5 years from delivery | Tied to specific named individuals |
Frequently asked questions
Does the five-year clock start at engagement or at end of relationship?
At end of relationship for CDD, and at completion for occasional transactions. The file records an explicit determination of when the relationship ended, with the basis for that determination, so the clock runs from a documented event.
What counts as a record being held in a usable form?
A record that can be located, opened and produced in a format the regulator can read. Files in obsolete formats, on inaccessible hardware, or under credentials nobody currently holds fail the test even if the bits still exist somewhere.
How is editing of archived material prevented?
Archived versions are sealed once filed. Corrections produce a new version, and the prior version is preserved alongside, with the relationship between them recorded. Nothing in the archive is silently overwritten.
How are dormant matters treated for retention purposes?
A dormant matter is not the same as a closed one. The file records dormancy explicitly and keeps the retention clock paused. The clock starts when an end-of-relationship determination is made and documented.
Does DC-Services advise on regulatory interpretation?
No. The work is documentation: mapping requirements to the file, holding records in a form that can be produced, and recording the determinations on which retention depends. Regulatory interpretation remains a matter for the firm's regulated advisers.
Retention is operational, not aspirational. The records that count are the ones that can still be produced — in form, in index, and in version — when somebody asks.
More in RegTech and Compliance
- Structuring a Source-of-Funds File Counterparties Will Actually Read
29 Jan 2026
- Scope Letters and Why Engagement Boundaries Are Written Down
27 Mar 2026
- Travel Rule Data Fields and What They Add to a Documentation File
14 May 2026
- Politically Exposed Persons Screening: What the File Records
28 Apr 2026
- Evidencing Card-Not-Present Purchases in a Source-of-Funds File
12 Jun 2026
- Reviewing a Documentation File on a Tablet or Mobile Device
2 Jul 2026
- Third-Party Signatories Inside a Documentation Engagement
12 Jul 2026
- What Record Reconstruction Can and Cannot Prove
29 Apr 2026
- Inheritance and Deceased Holder Records in Digital Asset Files
8 Jul 2026
- The Regulatory Perimeter Around Documentation and Record Review
16 Sept 2026
- The Scope Letter as the Spine of a Documentation Engagement
4 Nov 2026