Help Centre/Taking your records with you

Taking your records with you

In brief: Every export you can download yourself, and how to request a complete export of your firm's records.

Your firm must keep its customer due diligence records for five years after each client relationship ends, and be able to produce them when your supervisor asks (Money Laundering Regulations 2017, reg 40). That duty stays with your firm if you stop using Certivus. This page lists what you can download yourself, and how to get everything else.

Download what you need before your firm is closed. A closed firm cannot sign in.

Firm-wide downloads

WhatWhereFormatWhat it contains
Compliance packSettings, AML Compliance, Download compliance packZIPAnnual MLRO report, your active policies, controls and procedures, your latest signed-off firm-wide risk assessment, and the evidence files your firm uploaded (training certificates, audit evidence, policy documents, beneficial owner and source of funds evidence)
Inspection packReports, Generate inspection packPDFFirm-wide risk assessment summary, client risk register, screening summary, SAR log and recent audit trail
Data exportsReports, Data exportsCSVClient register, AML history, SAR log (MLRO only) and audit trail (the most recent 1,000 events)
AML audit exportReports, AML audit exportCSV or PDFEvery check you run, mapped to the regulation it satisfies
Firm-wide risk assessmentSettings, Risk, Download on any version (firm owner or manager)PDFEach signed-off version with its actions
Annual MLRO reportSettings, AML Compliance, MLRO appointments, Annual MLRO reportPDFThe report for the period you choose
Annual compliance reviewAnnual compliance review, once signed offPDF and ZIPThe signed review and the supervisor-visit bundle

Per-client downloads

WhatWhereFormatWhat it contains
Compliance packClient profile, Compliance PackPDFIdentity and AML results, risk assessment, monitoring, MLRO decisions, and the client's documents on file
Group packCompany profile, Group packZIPCompany details, beneficial owner register and evidence, linked owners, subsidiaries and the audit log
Full PDF reportClient profile, more menu, Download full PDF reportPDFA summary of everything on the client's file
Selected clientsClients list, select rows, ExportCSVOne line per selected client

A complete export

Firm owners can open Settings, Security & data and choose Export firm records. A platform admin can run the same export from the firm's detail page, including when the firm can no longer sign in. When the export is ready, choose Download ZIP.

The archive contains:

  • README.txt and manifest.json: the firm, generation time, exporting user, included parts, row counts, exclusions and any failures.
  • firm/: the existing compliance pack PDFs and stored firm evidence.
  • clients/<name>-<id>/: each client's data and history as JSON and CSV, plus their stored documents and evidence. Structured files avoid generating a separate PDF for every client and preserve the recorded history.
  • data/: CSV registers for clients, verification summaries, risk assessment history, EDD, source of funds, beneficial owners, client audit entries, MLRO actions, training, policy versions, PSC discrepancy reports and supporting AML, monitoring and firm records. Reads are paginated rather than capped at the most recent 1,000 rows.

SAR records and SAR-related audit entries/actions are included only when Certivus confirms the exporting user has permission to see that firm's SARs. Without that permission, restricted references are omitted and the annual MLRO report is excluded because it contains SAR figures. Being a platform admin does not bypass this check.

Keep the page open while the export runs. You can Cancel export before downloading. If a record or document cannot be retrieved, the page warns that the export is incomplete and lists each failed part. The ZIP manifest also lists those failures. An incomplete ZIP is not a complete record: retry or contact Support to resolve the missing parts. Externally hosted evidence without a stored copy must be retrieved separately.

The export uses your existing access permissions. Avoid editing records while it runs: the archive is assembled over time, not from a single database snapshot. Store it securely; it contains personal and confidential data. Original uploaded files are preserved as stored.

Owners and managers can still choose Request an export via Support for help with missing records or secure delivery after access ends.

After you leave

When a firm leaves, Certivus archives it rather than deleting it, so its records are still kept for the retention period. If a firm is ever deleted while any of its client records are still inside their five years, Certivus requires a written justification first and keeps a record of every client that was removed.

Records are kept for five years after each client relationship ends, then queued for deletion unless a legal hold applies. See Deleting, archiving & restoring clients.

Files in the client's Documents tab

Identity check evidence groups captured files by check. Expand a check to see its images, videos and documents. Where recorded, the heading shows the document type, issuing country and expiry date. Use View to preview a file or Download to save it with a readable name based on the client reference, surname, document type, part and date. Missing details are omitted.

Identity evidence has no edit, archive or delete action in this tab. It is kept for 5 years after the relationship ends. Under Your documents, use Upload to add internal files, or Archive to remove a document from the active list. The confirmation says Document archived.

Use Compliance Pack in the client profile header for the combined export. There is no separate PDF report button in the Documents tab.

Didn't find what you needed?

Contact support