The legacy DMS: where five-year retention goes to die
Every firm has a document store nobody chose: the old practice management system, the archived share, the folder structure named after a partner who left. The records in it may well still exist. That is not the requirement. The requirement is that they can be found and read — and that is where the pattern we keep meeting starts.
In a file review the question is not "do you keep records". Almost every firm answers that without hesitation. The question is: show me the customer due diligence records for a matter you closed four years ago, today, in front of me, and tell me who else could have found them. That is where the room goes quiet.1
Retention fails in the gap between storage and retrieval. Data that exists but cannot be located, opened or attributed is not a retained record in any sense a reviewer will accept. It is a backup — and a backup is an IT asset, not a compliance one.
§ 01What the regulation requires
The Money Laundering Regulations 2017 require records of customer due diligence, and sufficient supporting records of transactions subject to due diligence or ongoing monitoring, to be kept for at least five years from the end of the relationship. The transaction record must be sufficient to reconstruct the transaction.2
Two words in that requirement do all the work. Reconstruct means someone with no prior knowledge of the client must be able to follow what happened from the records alone. Keep is not satisfied by physical persistence on a disk. A record that cannot be retrieved on request fails the requirement as surely as one never made — and the failure is worse in one respect, because the firm believes it is compliant.
Add the dimensions a reviewer actually tests: can the record be found by someone who was not there at the time; can it be read with tools the firm still has; can it be attributed to a client, a matter and a date; and can it be produced to a regulator or a court within a sensible period. Four tests. Legacy stores usually fail two.
A record nobody can open is not a record. It is an archaeological site, and the five-year clock does not care that the site is technically still there. — how we write the finding
§ 02The two-firm pattern
These are anonymised composites from reviews we have run; no firm is identified. The mechanics are what recur.
Firm A migrated, and migrated the present. The migration moved live matters plus the preceding eighteen months — a sensible reading, since nobody wants to pay for historical data cleaning. Everything older stayed in the legacy system, kept read-only on the old server, now a virtual machine nobody owns. Reading a 2019 file needs an account held by two people who have both left, and whether the CDD bundle was ever exported is unknown, because the export was a manual job with no run book. The firm has not lost a document. It simply cannot produce one.
Firm B never migrated at all. The legacy system was replaced functionally, but left running because people still need it sometimes. It now holds the only copy of the pre-2021 client base, with no exit route: the contract renews by inertia, the format is proprietary, and the person who understood the schema left in 2022 without handover. Nobody can say what would happen to those records if the vendor ceased trading or changed its terms. The risk is not a lost document; it is a lost dependency.
1. Name the person who can retrieve a CDD record from a matter closed four years ago, without help, this week. 2. Name the format it is stored in, and the software needed to read it. 3. Describe what happens to that record if your document system vendor changes terms, doubles its fee, or stops trading. If any answer is a name in the past tense, you are already in the pattern.
§ 03Why it is more dangerous than it looks
The usual assumption is that legacy storage is hygiene that can wait. In our reviews it behaves like a latent finding with three ways to surface. A regulator or reviewer asks for a file they chose, and "we will need IT to look at the old system" turns a document request into a supervision issue. A client dispute arrives years later, and the evidence that would resolve it sits in a store you cannot open. Or a vendor event forces the question: contracts renew, products are sunset, small vendors are acquired, and the firm discovers it has no exit route and no costed plan.3
§ 04What to do without an exit interview
The reason legacy retention stays broken is the assumption that the fix needs the person who built it. It does not. Work on the records that carry an obligation, not the archive in general, in this order.
- Define the legal footprint. Which categories of record must be kept, for how long, from which date. CDD and transaction records are the core; do that mapping before anyone touches storage. Half a day with the right person, and it stops the project becoming "migrate everything".
- Prove retrieval, once, in writing. Pick ten matters closed in each of the last six years and produce the CDD bundle for each. Record the time taken, who did it and what was missing. That test produces the finding, the cost case and the priority list in one exercise.
- Fix readability before searchability. A searchable index over files nobody can open is worthless. Move documents into durable, non-proprietary formats — PDF/A is the usual answer — keeping originals alongside where it matters.
- Write the run book nobody wrote. How the store is accessed, by whom, with which credentials, how dependencies are managed. Assume the author will leave, because they will. One dated page, reviewed annually, beats tribal knowledge.
- Deal with the vendor relationship deliberately. Contract term, notice period, exit assistance, format on termination, who pays for the export. Put it in the supplier register you actually manage, not in a drawer.4
None of this is a large project, and it is not the same work as digitising an archive for convenience. It is the narrower job of making sure the records that carry a legal obligation stay findable, readable and attributable for as long as the obligation lasts — with evidence, rather than confidence.
To see how your firm would fare, the test is cheap: ask for ten files across six years and time how long it takes. Our independent AML file review does that at twenty files and reports it the way a reviewer would, and the resources page has the free self-check if you would rather run the sample yourself.
- Probative Co is an independent compliance practice, not a law firm, and nothing here is legal advice. The firm patterns described are anonymised composites from our own reviews. ↩
- Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, SI 2017/692 — reg 40 (record-keeping: the five-year retention period, and records sufficient to reconstruct a transaction), with reg 28 (customer due diligence records) and reg 28(11) (ongoing monitoring). Full text: legislation.gov.uk/uksi/2017/692. In the Regulations as made, retention sits in Part 4 at regulation 40; regulation 38 concerns electronic money. ↩
- The SRA's supervisory guidance for solicitors' practices covers money laundering and terrorist financing and the assessment of firm and matter risk: sra.org.uk — money laundering and terrorist financing, sra.org.uk — client and matter risk assessments. ↩
- Where a document store holds personal data, retention and security duties under the UK GDPR and the Data Protection Act 2018 run alongside AML retention, including a defined retention period and appropriate technical measures. See ico.org.uk. ↩
Send three files.
We'll tell you what a reviewer would flag.
- No charge and no obligation — you keep the findings either way
- Turned around in ~48 hours, encrypted transfer only
- Most firms find at least one issue they did not know they had