What’s ongoing monitoring of a client?

Ongoing monitoring of a client is a core part of your anti-money laundering (AML) obligations for the length of your business relationships.
Unlike initial checks, it’s continuous. It means keeping transactions and customer information under review over time so that you can spot changes that might indicate rising risk or criminal activity.
When you first onboard a client, you gather information to identify them and assess their risk. But that’s only a snapshot of a point in time. People, businesses and circumstances change.
Ongoing monitoring builds on that initial due diligence so your picture of the client stays current throughout the relationship.
What ongoing monitoring involves
FATF’s Recommendation 10 sets out ongoing monitoring as two linked elements:
1. Reviewing transactions
You should keep track of customer transactions across the life of the relationship, looking to ensure the activity you see fits with your knowledge of:
- who the customer is;
- their business profile or purpose; and
- the risk they present.
This includes flagging activity that’s unusual in volume, size or destination, and taking a closer look at where funds came from if there’s reason to do so.
2. Keeping records and customer data up to date
You also need to revisit the information you hold on clients, checking that identity, beneficial ownership and risk assessments remain accurate.
If something has changed (for example, a change in the beneficial owner, business structure or transaction patterns) you should refresh your documentation and update your risk rating.
Together these elements mean you aren’t just compliant at onboarding but remain so throughout the life of the relationship.
When ongoing monitoring applies
Ongoing monitoring applies to business relationships. According to FATF, this is a relationship that carries some element of duration, even without a fixed end date.
If you’re carrying out an occasional transaction only, and there’s no expectation of further work, ongoing monitoring doesn’t apply. However, your other AML obligations do.
Where a business relationship does exist, ongoing monitoring continues for as long as that relationship is in place. That means keeping the client under review while you’re acting for them, and stopping only when the relationship has genuinely ended.
Why ongoing monitoring matters
Initial customer due diligence gives you a baseline. But risk isn’t static. Ongoing monitoring helps you:
- ensure your understanding of the customer stays accurate;
- spot and respond to behavioural changes or suspicious patterns; and
- update risk assessments promptly when triggers occur.
For example, if transaction activity suddenly changes in volume or destination, or if you learn that a beneficial owner has changed, you need to reassess whether your previous checks still hold true.
This ongoing vigilance makes your risk-based approach effective and helps you identify and mitigate potential harms such as money laundering, terrorist financing or proliferation financing.
Taking a risk-based approach
FATF’s risk-based approach requires that the extent and frequency of ongoing monitoring reflects the level of risk posed by each client.
High-risk clients, such as those with complex ownership or politically exposed persons (PEPs), require more frequent and detailed reviews. Lower-risk clients may need less frequent scrutiny.
A one-size-fits-all annual review doesn’t align with a risk-based approach, because it fails to account for differences in risk profiles or changes in activity. Good monitoring processes should be tailored to the risk indicators you’ve identified in your client base.
How to demonstrate effective monitoring
When regulators or supervisors review your controls, you’ll need to show records that demonstrate you are:
- reviewing transaction activity in line with how you’ve assessed risk;
- updating customer information when triggers occur;
- adjusting risk assessments where appropriate; and
- recording decisions and actions you’ve taken.
Supervisors will look for evidence that you’ve embedded ongoing monitoring in your policies, controls and procedures. The emphasis is on proportionality. The amount and frequency of monitoring should match the risk faced.
Common pitfalls to avoid
Getting ongoing monitoring right isn’t just about ticking a box. Common issues include:
- applying the same monitoring frequency for all clients regardless of risk;
- failing to link unusual transactions back to risk assessments or customer profiles;
- not updating customer data after significant changes in behaviour or circumstances;
- not re-screening existing clients when a PEP or sanctions list updates, so risk that only shows up after onboarding goes unnoticed;
- carrying out the review but not recording the reasoning behind it, so there’s nothing to show a supervisor beyond “we looked”;
- flagging something unusual once and moving on, rather than feeding it back into the client’s risk rating.
Avoiding these pitfalls helps ensure your ongoing monitoring is both effective and defensible.
Final thoughts
Ongoing monitoring is an essential part of your AML framework: understanding how your clients evolve, spotting the indicators that risk has increased, and keeping accurate records as you go.
A staff concern about a client is a reason to flag it to whoever holds the money laundering reporting function in your business, often called an MLRO, not necessarily to file a report with your financial intelligence unit straight away.
Monitoring that’s tailored to risk, backed by solid documentation, is what lets you demonstrate compliance with FATF’s standards when a supervisor reviews your business.
What others have said
Making compliance easier








