Ongoing Monitoring
Ongoing monitoring is the continuous process of scrutinising a customer relationship for changes in risk throughout its life, not just at onboarding. FATF Recommendation 10 requires it directly. The term gets used interchangeably with transaction monitoring constantly, but they’re not the same thing: transaction monitoring is one component inside the broader ongoing monitoring programme, which also includes periodic KYC refresh, PEP and sanctions re-screening, adverse media rechecks, and beneficial ownership reviews.
Key takeaways
- Ongoing monitoring is the continuous scrutiny of a customer relationship for changes in risk, required directly under FATF Recommendation 10.
- Transaction monitoring is one component; ongoing monitoring also includes periodic KYC refresh, PEP and sanctions re-screening, adverse media checks, and beneficial ownership reviews.
- FinCEN’s CDD Rule and UK Regulation 35 both sharpen FATF’s general principle into specific, jurisdiction-level requirements.
- Effective programmes run scheduled periodic reviews and trigger-event reviews together, not either mechanism alone.
- There’s no single mandated review interval; roughly 12 months without a documented rationale for extending it commonly draws examination scrutiny for high-risk customers.
- Perpetual KYC describes the practical end-state: near-real-time data accuracy rather than periodic snapshots.
- TD Bank’s $3.09 billion 2024 settlement illustrates how weak ongoing monitoring, not onboarding failures, drives some of the largest AML penalties on record.
On this page
What ongoing monitoring actually coversWhy it’s not just transaction monitoringThe regulatory basis beyond FATF’s general principleTwo mechanisms working together: schedule and triggerHow review frequency actually gets setPerpetual KYC: the direction the industry is headingWhy missing a status change matters more than it soundsWhat weak ongoing monitoring actually costsBuilding an ongoing monitoring programme that actually worksFAQsRead more
12 mo
Commonly expected maximum review interval for high-risk customers before a documented rationale is required
Source: Industry examination practice, risk-based per FATF Rec. 10
$3.09bn
TD Bank’s 2024 settlement, tied significantly to inadequate ongoing monitoring over roughly six years
What ongoing monitoring actually covers
Ongoing monitoring is the continuous process of scrutinising a customer relationship for changes in risk throughout its entire life, not a check performed once at onboarding and left alone afterward. FATF Recommendation 10 requires it directly: firms must conduct ongoing due diligence, analysing transactions to ensure they’re consistent with the institution’s knowledge of the customer, while keeping CDD records current through regular review, particularly for higher-risk relationships.
Why it’s not just transaction monitoring
These two terms get used interchangeably constantly, and that’s genuinely imprecise. Transaction monitoring is one specific component: flagging unusual payment patterns, sudden volume spikes, structuring, activity inconsistent with a customer’s stated purpose. Ongoing monitoring is the broader programme that wraps around transaction monitoring and adds periodic KYC refresh, PEP and sanctions re-screening, adverse media rechecks, and beneficial ownership reviews. A firm that only runs transaction monitoring and calls it ongoing monitoring has built roughly a third of what the term actually requires.
The regulatory basis beyond FATF’s general principle
FATF Recommendation 10 sets the international baseline, but specific implementing regulations sharpen it considerably. FinCEN’s CDD Rule, effective May 2018, requires covered US financial institutions to conduct ongoing monitoring on a risk basis and to maintain and update customer information accordingly, one of the rule’s four core elements. In the UK, Regulation 35 of the Money Laundering Regulations 2017 specifically requires firms to maintain risk-management systems capable of identifying when a customer’s PEP status changes during the relationship, not just at onboarding, and FATF Recommendation 12 requires enhanced ongoing monitoring for every PEP relationship specifically, alongside senior management approval to continue it.
Two mechanisms working together: schedule and trigger
Effective ongoing monitoring runs on two parallel mechanisms, not one. Periodic reviews happen on a defined schedule, more frequently for higher-risk customers, refreshing identity documentation, risk classification, and screening results at set intervals. Trigger-event reviews happen independent of any schedule, activated the moment something material changes: a large, unexplained transaction, a new beneficial owner, a jurisdiction change, an adverse media hit. A firm relying only on scheduled reviews misses risk that develops between review dates; a firm relying only on trigger events misses risk that develops so gradually no single event stands out.
How review frequency actually gets set
There’s no single FATF-mandated interval for periodic reviews; the requirement is proportionality to risk, not a fixed number. In practice, examiners commonly expect an institution extending its high-risk customer review interval beyond roughly 12 months to have a specific, documented rationale for doing so; without one, that gap becomes an examination finding. Lower-risk relationships can reasonably be reviewed less frequently, consistent with the same risk-based logic that governs simplified due diligence more broadly.
Perpetual KYC: the direction the industry is heading
Perpetual KYC describes the practical end-state ongoing monitoring is meant to approximate: customer data kept accurate through near-real-time updates that reflect changes in behaviour and circumstances as they happen, rather than accumulating drift between scheduled review cycles. It’s less a separate requirement than a description of what ongoing monitoring looks like when done well, continuously, rather than as a series of periodic snapshots.
Why missing a status change matters more than it sounds
A concrete illustration of the stakes: if a customer becomes a PEP partway through an existing relationship, election to office, a senior appointment, and a firm’s ongoing monitoring doesn’t catch it, that customer keeps being managed under whatever risk framework applied when they onboarded as an ordinary customer. A genuinely high-risk relationship continues receiving low-risk treatment indefinitely, exactly the kind of gap that shows up in enforcement findings tied to weak ongoing monitoring rather than a total absence of controls.
What weak ongoing monitoring actually costs
TD Bank’s $3.09 billion settlement with US authorities in 2024 involved more than $670 million in laundered funds moving through the bank over roughly six years, a pattern regulators tied significantly to inadequate ongoing monitoring rather than a failure to check identity at onboarding. That case is a useful reminder that the most expensive AML failures often aren’t about the initial check; they’re about what happens, or doesn’t happen, to a customer file for years afterward.
Building an ongoing monitoring programme that actually works
A working ongoing monitoring programme combines all its components deliberately rather than treating transaction monitoring as a stand-in for the whole thing: scheduled periodic reviews with documented, risk-based intervals; trigger-event logic that activates review independent of the calendar; PEP and sanctions re-screening on a cadence appropriate to how quickly each of those datasets actually changes; and a clear escalation path when any component surfaces a material change in risk, so a status change discovered mid-relationship actually reaches someone with authority to reclassify the relationship, not just gets logged and left.
Build ongoing monitoring into your policy
Generate a policy draft that documents scheduled review cadences and trigger-event escalation.
Frequently asked questions
What is ongoing monitoring?
Ongoing monitoring is the continuous process of scrutinising a customer relationship for changes in risk throughout its life, required directly under FATF Recommendation 10, rather than a check performed only at onboarding.
Is ongoing monitoring the same as transaction monitoring?
No. Transaction monitoring, flagging unusual payment patterns, is one component. Ongoing monitoring is the broader programme that also includes periodic KYC refresh, PEP and sanctions re-screening, adverse media checks, and beneficial ownership reviews.
What regulations require ongoing monitoring?
FATF Recommendation 10 sets the international baseline. FinCEN’s CDD Rule requires it as one of its four core elements in the US. UK Regulation 35 specifically requires monitoring for PEP status changes during a relationship.
How often should ongoing reviews happen?
There’s no single fixed interval; it should be proportionate to risk. Extending a high-risk customer’s review interval beyond roughly 12 months without a documented rationale is commonly flagged as an examination finding.
What is perpetual KYC?
Perpetual KYC describes keeping customer data accurate through near-real-time updates reflecting behaviour and circumstance changes as they happen, rather than relying only on periodic scheduled reviews.
What happens if ongoing monitoring misses a PEP status change?
The customer continues being managed under the lower-risk framework that applied at onboarding, even though their actual risk has genuinely increased, exactly the kind of gap regulatory enforcement findings frequently cite.
What did the TD Bank case reveal about ongoing monitoring?
TD Bank’s 2024 $3.09 billion settlement involved over $670 million laundered over roughly six years, a pattern regulators tied significantly to inadequate ongoing monitoring rather than a failure at initial onboarding.
Should ongoing monitoring rely on scheduled reviews or trigger events?
Both. Scheduled reviews catch risk that develops steadily between review dates on a documented cadence; trigger-event reviews catch material changes immediately, independent of the calendar. Relying on only one misses what the other is built to catch.
Read more: our ultimate guides, whitepapers and templates
Related guides and resources to help you act on what you just read.
Last reviewed July 19, 2026 · 10 min read · Written for compliance and risk professionals · By the WhoWiki editorial team
Key takeaway: Ongoing monitoring is the continuous process of scrutinising a customer relationship for changes in risk throughout its life, not just at onboarding. FATF Recommendation 10 requires it directly. The term gets used interchangeably with transaction monitoring constantly, but they’re not the same thing: transaction monitoring is one component inside the broader ongoing monitoring programme, which also includes periodic KYC refresh, PEP and sanctions re-screening, adverse media rechecks, and beneficial ownership reviews.