Customer playbook C

Records that answer “show me”

Vericode preserves the verification evidence. Your firm preserves the program, training, incident, and fallback records around it.

Read the retention policy

Who keeps what

Use both columns when preparing for an audit. Vericode’s record supports the control; the firm’s records show how that control sits inside its wider compliance program.

No staff effort

Vericode keeps automatically

  • Each verification event: timestamp, channel, masked destination in the compliance-facing verification record, outcome, staff member, and workspace
  • An immutable, hash-chained audit trail hosted in Australia
  • Authorised-contact audit events retained for seven years to support AML/CTF record keeping
  • Exports available through the audit-trail export, verified-caller certificate, and quarterly compliance pack

Your obligations

The firm keeps

  • Your AML/CTF program document and telephone CDD procedure
  • Your staff training register
  • Your incident register and external-report references
  • Manual fallback records created during an outage, kept with the matter and backfilled using Playbook A
Masking scope: the destination is masked in the verification record shown to your compliance officer and in customer-facing evidence. This is not a claim that every internal operational log contains only masked data.

Published retention and deletion policy

Authorised-contact audit events have a seven-year retain-until value. That record survives staff changes because it is workspace-owned. Handling for other information follows the policy below without inventing an unsupported fixed period.

When a staff member leaves

Verification records belong to the workspace, not the individual user. They remain available to authorised workspace members after the departing person’s access is removed.

When a subscription is cancelled

Vericode provides an export window so the firm can retrieve its verification records. After that window, workspace data is scheduled for deletion, subject to legal, security, dispute-resolution, and operational retention obligations described in the Privacy Policy.

When deletion is requested

Send the request to [email protected]. Vericode assesses the request against applicable legal and operational retention obligations, confirms what can be deleted, and explains any record that must be retained.

Other record classes

Billing, account, support, and general workspace information are retained and deleted as described in the Privacy Policy. No fixed period is claimed here where one has not been published.

The audit answer

Export the verification evidence, then produce the firm-owned program, training, incident, and fallback records that explain how staff used the control.

Not legal advice. This operational guide does not replace advice on your firm’s AML/CTF, privacy, professional, insurance, or record-keeping obligations.