Risk & Compliance

Record-Keeping Requirements for FCA Firms: A Practical Guide to SYSC 9

A practical guide to FCA record-keeping requirements under SYSC 9, plus the retention periods set by COBS, DISP and the Money Laundering Regulations 2017.

Record-Keeping Requirements for FCA Firms: A Practical Guide to SYSC 9

Records are the memory of a regulated firm. When the Financial Conduct Authority asks how a decision was reached, whether a client was treated fairly, or how a suspicious transaction was handled, the answer lives in the records the firm chose to keep. Get record-keeping right and supervision is a conversation you can win on the evidence. Get it wrong and you are arguing from a position you cannot document.

The foundation of FCA record-keeping is SYSC 9, the section of the Senior Management Arrangements, Systems and Controls sourcebook that sets the general rule. SYSC 9 tells firms to keep orderly records, but it deliberately leaves most retention periods to be set elsewhere. The precise clocks come from other parts of the Handbook, such as COBS for suitability records and DISP for complaints, and from separate legislation, most importantly the Money Laundering Regulations 2017 for anti-money-laundering records.

This guide explains the general SYSC 9 rule, sets out the retention periods that matter most in practice, and gives you a step-by-step framework for building a record-keeping regime. Every rule reference and every period below has been checked against the primary source. Where a period genuinely varies by product or activity, we say so rather than offer a single number that would mislead you.

Protect customersReduce risk and prevent harm
Meet obligationsStay aligned with laws and standards
Build trustStrengthen confidence with stakeholders
Improve decisionsUse insight to prioritise and act
Drive efficiencyStreamline audits and reporting

What SYSC 9 actually requires

The core obligation sits in SYSC 9.1.1R. It requires a firm to arrange for orderly records to be kept of its business and internal organisation, including all services and transactions undertaken by it. The word orderly matters. A shoebox of documents that technically exist but cannot be found, indexed or produced on request does not satisfy the rule. The records have to be organised well enough to be useful.

The purpose is set out in the rule itself. The records must be sufficient to enable the FCA to monitor the firm's compliance with the requirements under the regulatory system, and in particular to ascertain that the firm has complied with all its obligations with respect to clients. In other words, record-keeping is not an end in itself. It exists so that the firm can demonstrate compliance and so that the supervisor can verify it. If a record does not help you show that clients were treated properly, ask whether you are keeping the right things.

SYSC 9.1.2-AR adds a quality standard for the medium in which records are held. Records must be retained in a form that allows the FCA to access them readily and to reconstitute each key stage of the processing of a transaction. The firm must be able to identify easily any corrections or other amendments, and the contents of the records before those corrections or amendments were made. That rules out systems where edits silently overwrite history. An audit trail is not optional; it is part of the record itself.

How long you have to keep records

SYSC 9 sets a general expectation but not a single universal period. For non-MiFID business, the guidance in SYSC 9.1.5G is that records should be retained for as long as is relevant for the purposes for which they are made. That is a judgement, not a fixed number, and it puts the onus on the firm to decide what relevant means for each record type.

For MiFID business, SYSC 9.1.2R is firmer. A common platform firm must retain all records kept under the chapter in relation to its MiFID business for a period of at least five years. The words at least are significant: five years is a floor, not a ceiling. Where another rule or another purpose requires longer, the longer period wins.

The retention periods that most firms actually manage against come from the specialist sourcebooks and from legislation, not from SYSC 9 itself. The table below draws those together so you can see the landscape in one place. Treat it as a starting map, and always confirm the period against the specific rule for the record in question, because product variations can extend it.

Record typeRetention periodSource
Business, internal organisation, services and transactions (general)As long as is relevant for the purpose (guidance)SYSC 9.1.5G
Records relating to MiFID businessAt least five yearsSYSC 9.1.2R
Anti-money-laundering CDD documents and transaction recordsFive years from end of business relationship or completion of transaction (10-year cap)MLR 2017 reg 40
Complaint records (most complaints)Three years from the date the complaint was receivedDISP 1.9.1R
Complaint records (UCITS collective portfolio management)Five years from the date the complaint was receivedDISP 1.9.1R
Suitability records: pension transfer, conversion, opt-out or FSAVCIndefinitelyCOBS 9.5.2R
Suitability records: life policy, personal or stakeholder pension, DC occupational pension benefitsFive yearsCOBS 9.5.2R
Suitability records: other businessThree yearsCOBS 9.5.2R
Common FCA and AML record retention periods, each drawn from the cited primary rule.

The five-year AML record rule under MLR 2017

For any firm within scope of the money-laundering regime, the retention rule that draws the most supervisory attention is regulation 40 of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017. This is separate legislation, not part of the FCA Handbook, but it sits alongside SYSC 9 and applies to a wide range of regulated firms.

Regulation 40 requires a relevant person to keep two kinds of record. The first is a copy of any documents and information obtained to satisfy the customer due diligence requirements in regulations 28, 29 and 33 to 37. The second is sufficient supporting records, whether original documents or copies, in respect of a transaction that is the subject of customer due diligence or ongoing monitoring, to enable the transaction to be reconstructed.

The period is five years. For an occasional transaction, it begins on the date the relevant person knows, or has reasonable grounds to believe, that the transaction is complete. For records tied to a business relationship, it begins on the date the relationship comes to an end. There is an upper limit: a relevant person is not required to keep the transaction records referred to in the relevant provision for more than 10 years. When the retention period expires, the firm must delete personal data obtained for the purposes of the Regulations, unless a listed exception applies, such as a legal requirement to retain it or the need to keep it for court proceedings.

The practical lesson is that the AML clock is event-driven, not calendar-driven. It does not start when you onboard a client; it starts when the relationship ends or the transaction completes. A long-standing relationship can require you to hold onboarding records for years before the five-year clock even begins to run.

Where the specialist rules set the clock

Two areas of the Handbook set periods that compliance teams manage against day to day: complaints and suitability. Both illustrate how the general SYSC 9 principle is given a specific number elsewhere.

For complaints, DISP 1.9.1R requires a firm to keep a record of each complaint received and the measures taken for its resolution. Most complaint records must be retained for three years from the date the complaint was received. Complaints relating to collective portfolio management services for a UCITS scheme must be kept for five years from that date. The record is expected to cover the complaint lifecycle, so the investigation notes, the final response and any redress calculation all belong in it.

For investment suitability, COBS 9.5.2R sets retention periods that vary sharply by product. A suitability record relating to a pension transfer, pension conversion, pension opt-out or FSAVC must be retained indefinitely. A record relating to a life policy, personal pension scheme, stakeholder pension scheme or benefits in a defined contribution occupational pension scheme must be kept for five years. In any other case the period is three years. The indefinite category exists because the consequences of these decisions can surface decades later, and the firm may still need to justify the advice it gave.

This is why a single firm-wide retention number is dangerous. A wealth manager advising on pension transfers, handling MiFID transactions and running an AML programme is simultaneously subject to indefinite retention, five-year retention and event-driven five-year retention. A framework that keeps everything for three years would breach several rules at once. Building a controlled record estate is exactly the kind of work our control tooling is designed to support.

Where the specialist rules set the clock

Conflicts, and the records that prove your controls work

Not every record-keeping obligation is about client transactions. Some are about proving that the firm's own controls operate. SYSC 10.1.6R is a good example. It requires a firm to keep and regularly update a record of the kinds of service or activity carried out by or on behalf of the firm in which a conflict of interest entailing a material risk of damage, or for a common platform firm a risk of damage, to the interests of one or more clients has arisen or, in the case of an ongoing service or activity, may arise.

The phrase regularly update is doing real work. A conflicts record written once at authorisation and never revisited is not compliant, because conflicts change as the business changes. The record is meant to be a living document that reflects the firm as it is now, not as it was on the day the compliance manual was signed off.

The wider point is that supervisors read records as evidence of whether a control framework is real. A policy that says conflicts will be identified and managed carries little weight without a maintained conflicts record behind it. The same logic applies to governance minutes, training logs and monitoring reports. Treat control-evidence records as first-class citizens alongside transaction and client records, because they are often the first thing a supervisor asks to see.

Common retention periods by record category

Illustrative grouping of the retention periods cited in this article. Actual periods depend on the specific rule and product.

Common retention periods by record category
6Total %
Indefinite (pension transfers, COBS 9.5.2R)1%
Five years (MiFID, life and pension suitability, AML)3%
Three years (most complaints, other suitability)2%

Building a record-keeping framework that survives supervision

A durable framework starts with knowing what you must keep and for how long, then wraps controls around it so the right records exist, stay accessible and are disposed of only when it is safe to do so. The steps below give a practical sequence for a firm building or reviewing its regime.

The single most common failure is not a missing rule but a retention schedule that does not map cleanly onto the way records are actually stored. Emails, call recordings, advice files and AML documents often live in different systems with different default retention settings. If those settings do not reflect the rules above, records are quietly deleted early or kept long past their lawful basis. Bring the schedule and the systems into line before you consider the job done. Firms preparing for authorisation should build this in from the start rather than retrofitting it, and our authorisation support covers exactly that groundwork.

1
Map obligations
List every record type your permissions generate and the rule that governs each one.
2
Set retention schedule
Assign the correct period per record type, using the longest applicable rule where several overlap.
3
Fix the start date
Record when each clock starts, since AML runs from relationship end, not onboarding.
4
Control access and integrity
Ensure records are readily retrievable and that amendments leave an audit trail.
5
Assign ownership
Name an owner for each record category so retention and quality are somebody's job.
6
Test and review
Sample records periodically and update the schedule when the business or rules change.

Conclusion

Record-keeping under SYSC 9 is deceptively simple at the level of principle and genuinely complex in the detail. The general rule asks for orderly records that let the firm demonstrate compliance and let the FCA verify it, held in a form that preserves an audit trail. But the retention clocks that determine what you actually keep, and for how long, are set by rules spread across COBS, DISP and the Money Laundering Regulations 2017. A framework that treats all records as one category will breach several of those rules at once.

The firms that handle this well do three things. They map each record type to the specific rule that governs it, they set the retention clock from the correct start date, and they wrap access controls and integrity checks around the whole estate so that records can be produced, trusted and disposed of lawfully. Do that, and record-keeping stops being a compliance chore and becomes what it was always meant to be: the evidence base that lets you show, on demand, that you did the right thing.

Frequently asked questions

What is the general FCA record-keeping requirement?

SYSC 9.1.1R requires a firm to arrange for orderly records to be kept of its business and internal organisation, including all services and transactions it undertakes. The records must be sufficient to enable the FCA to monitor the firm's compliance and to ascertain that the firm has met its obligations to clients.

How long must AML records be kept?

Under regulation 40 of the Money Laundering Regulations 2017, records of customer due diligence and supporting transaction records must be kept for five years. That period begins when a transaction is completed, for an occasional transaction, or when the business relationship comes to an end. The transaction records need not be kept for more than 10 years.

Is there a single retention period for all FCA records?

No. SYSC 9 sets a general expectation but leaves most periods to other rules. For MiFID business, SYSC 9.1.2R requires at least five years. Complaints are generally three years under DISP 1.9.1R, while pension transfer suitability records must be kept indefinitely under COBS 9.5.2R. Always check the rule for the specific record.

How long must complaint records be kept?

Under DISP 1.9.1R a firm must keep a record of each complaint received and how it was resolved. Most complaint records must be retained for three years from the date the complaint was received. Complaints relating to collective portfolio management for a UCITS scheme must be kept for five years from that date.

Do records have to include an audit trail of changes?

Yes. SYSC 9.1.2-AR requires records to be held in a form that lets the FCA access them readily and reconstitute each key stage of a transaction, and that makes it easy to identify any corrections or amendments and the contents of the records before those changes were made. Systems that silently overwrite history do not meet this standard.

What record must a firm keep about conflicts of interest?

SYSC 10.1.6R requires a firm to keep and regularly update a record of the kinds of service or activity in which a conflict of interest entailing a material risk of damage to one or more clients has arisen or, for an ongoing service or activity, may arise. The record must be kept current as the business changes.

Ready to move money with confidence?

Nasara Control helps UK firms send and control payments with lower fees, better rates and full visibility.

Talk to an expert
Secure by designBank-grade security and encryption
Built for UK firmsMade for FCA-regulated businesses
Data protectedYour data stays private and controlled
Global reachCross-border payments worldwide
Accepting enquiries

Tell us what you’re working on.

New firm, FCA authorisation, ongoing compliance or controlled payments, send a note and we’ll come back within one business day.

The business control layer for firms that start, get authorised, stay compliant and make controlled payments.

Nasara Connect is a trading name of Mema Financial Services Ltd, registered with the Financial Conduct Authority as a Small Payment Institution under the Payment Services Regulations 2017 (Firm Reference Number 1040933) and with HM Revenue & Customs for anti-money laundering supervision (registration number XFML00000205542). Registered in England & Wales, company number 15382445. View on the FCA Register.

© 2026 Nasara Connect. All rights reserved.

Cyber Essentials Certified