A retention schedule is only as good as the rule behind each line. For banks and financial institutions, the firmest minimum comes from the anti-money-laundering law, which requires customer identification and transaction records to be kept for at least five years.1
The statutory floor
Who sets what
| Topic | Instrument | What it governs |
|---|---|---|
| AML law | Asset (Money) Laundering Prevention Act, 2064 | Minimum retention of customer identification, account and transaction records.1 |
| Privacy law | Individual Privacy Act, 2075 | Protection of personal information held by public and private bodies. No dedicated data protection authority exists.2 |
| Insurance | Insurance Act, 2079 | Nepal Insurance Authority, formerly Beema Samiti, regulating insurers since 8 November 2022.4 |
Building the schedule
A statutory minimum is a floor, not a schedule. Most institutions keep records longer because of litigation, audit or business value. Write down the reason for every period, so the next person to read the schedule knows which lines are law and which are policy.
A retention schedule should state, for every record class
- The record class, in your own nomenclature
- The rule or reason behind the period, with its citation
- The trigger: transaction date, account closure, or contract end
- The period, and who approved it
- What happens at the end: review, transfer, or certified destruction
Sources
4 sources verified, last checked 4 October 2026- 1
- 2
- 3
- 4