Ongoing monitoring under the AMLR: review frequencies and event-driven reviews
Article 26 AMLR makes ongoing monitoring a duty with fixed elements, and AMLA is consulting on Guidelines for it. How periodic reviews, event-driven reviews and transaction monitoring fit together.
Cet article n'est pas encore disponible dans cette langue ; l'original anglais est affiché. La traduction suit automatiquement.
Ongoing monitoring has always been part of customer due diligence, but the AMLR spells out what it means. Article 26 requires obliged entities to monitor the business relationship, including transactions, to check that they are consistent with what the entity knows about the customer, and to keep the customer data up to date. AMLA's consultation on Guidelines for ongoing monitoring adds the operational detail.
Three activities, one obligation
- Periodic review of the customer file at a frequency set by the risk classification. The Guidelines on customer risk classification and review frequency, already in final draft, give the reference points: more often for higher risk, with a maximum interval for the lowest risk.
- Event-driven review when something changes: a new beneficial owner, a change of country, a sanctions hit, an unusual transaction, adverse media. The AMLR makes these triggers explicit; a relationship cannot wait for its next scheduled review.
- Transaction monitoring that compares activity with the expected profile recorded at onboarding (Article 25) and updated since.
What the draft Guidelines change in practice
- The expected transaction profile stops being a free-text box. Monitoring must be able to compare actual activity with it, which means the profile needs structured values: expected volumes, countries, counterparties.
- Data quality becomes a monitoring obligation. A file with an expired identity document or a missing beneficial owner is a finding in itself.
- The link with reporting is direct: the outcome of a review that raises suspicion is a report under Article 69, on the new template.
Common gaps
Institutions often have periodic reviews that are calendar-driven but no reliable event feed; or transaction monitoring built on indicators of unusual activity rather than on the customer's expected profile; or a review process that updates the file without re-scoring the risk.
What to do now
- Inventory your review triggers: which events reach the review team automatically, which depend on someone noticing?
- Make the expected profile structured for new customers first, then backfill for higher-risk existing customers.
- Reconcile the review frequencies with the draft classification Guidelines and record the reasoning where you deviate.
The dashboard tracks the monitoring Guidelines under Ongoing monitoring; the readiness tracker covers periodic and event-driven review as separate blocks.