2026-08-17

Added

AML/CFT/CPF Handbook — 9 Record Keeping

Regulated entities must maintain documentary evidence of compliance with the Proceeds of Crime Act 2015, including customer identification, transaction records, and correspondence, without applying a risk-based approach to the extent of retention. Specific record categories apply to simplified due diligence, enhanced due diligence, non-face-to-face relationships, politically exposed persons, correspondent banking, and life assurance beneficiaries. Records must be retained for five years from the completion of occasional transactions, the end of business relationships, or the date reliance on a third party was placed, with deletion required upon expiry unless other enactments or legal proceedings necessitate retention. Entities must also maintain risk assessments, training logs, suspicious activity reports, and compliance monitoring records, while ensuring adherence to data protection obligations.

Gibraltar Financial Services Commission logo

Gibraltar

Gibraltar Financial Services Commission

Scan of the document's first page
Share

Get GFSC alerts — same-day email on every new publication.

Read the rest free

Source: Gibraltar Financial Services Commission — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from GFSC

We email you every new GFSC publication the day it's published.

Topics