Ongoing Transaction Monitoring Obligations: What Regulated Entities Must Do

The moment a customer is onboarded, the compliance obligation does not end. It intensifies.

Risk Management  ·  August 2026  ·  AML

The moment a customer is onboarded, the compliance obligation does not end.

The Regulatory Basis for Ongoing Monitoring

FATF Recommendation 10 requires regulated entities to conduct customer due diligence when establishing a business relationship. Recommendation 11 extends this obligation beyond onboarding. It states that regulated entities should conduct ongoing due diligence, including scrutiny of transactions undertaken throughout the course of the relationship to ensure that those transactions are consistent with the institution’s knowledge of the customer, their business, and their risk profile.

The two recommendations operate together. Recommendation 10 covers the initial verification of who the customer is. Recommendation 11 covers the continuous verification of whether the customer’s behaviour remains consistent with that identity.

FATF’s Guidance on the Risk-Based Approach clarifies that ongoing due diligence is not a separate process from initial CDD. It is an extension of the same obligation. The risk profile established at onboarding must be actively maintained, challenged, and updated as new information becomes available.

In national legislation, this obligation is typically transposed through AML and CTF laws. The specific frequency of periodic reviews, the triggers for enhanced scrutiny, and the documentation standards applied vary by jurisdiction. In Japan, the APTCP and FSA Guidelines require ongoing monitoring calibrated to customer risk. In the United Kingdom, the Money Laundering Regulations establish a risk-based framework for periodic review. In Australia, AUSTRAC guidance specifies ongoing customer due diligence obligations. Regulated entities must verify the specific requirements applicable to their own jurisdiction and licensing regime.

What Ongoing Monitoring Means Operationally

The operational substance of ongoing monitoring is broader than most compliance teams initially anticipate.

Transaction monitoring is the analysis of financial transactions to detect patterns consistent with money laundering, terrorism financing, or other financial crime. This includes both automated monitoring through transaction monitoring systems and manual review of transactions that fall outside automated detection parameters.

Periodic account review is the scheduled reassessment of a customer’s risk profile and the adequacy of the customer due diligence information held. This is distinct from transaction monitoring in that it examines the customer relationship holistically rather than individual transactions.

Triggered review occurs when specific events prompt an immediate reassessment of customer risk. Common triggers include a significant change in the nature or volume of transactions, a change in the customer’s ownership or control structure, information surfacing through adverse media screening, or a change in the customer’s country of residence or operations.

Re-screening obligations require that existing customers be checked against updated sanctions lists, PEP databases, and adverse media sources on a defined cycle or when triggered.

The common thread across all four components is that the obligation is continuous. A compliance programme that reviews customer risk only at onboarding and again on a fixed calendar schedule will not satisfy the standard set by FATF Recommendation 11.

Transaction Monitoring: Scope, Frequency, and Calibration

FATF does not prescribe a single monitoring frequency applicable to every customer. Recommendation 11 requires that ongoing due diligence be applied, with the intensity determined by the risk profile of the customer.

In practice, this creates a tiered model that most regulators and supervisors expect to see.

Risk TierPeriodic Review FrequencyTransaction MonitoringRe-screening Interval
Low-riskEvery 2-3 yearsThreshold-based; unusual activity vs stated profileAnnual
Standard-riskAnnual or biennialContinuous automatedAnnual
High-risk (PEP, high-risk jurisdiction, complex ownership)Every 6-12 monthsLower thresholds; smaller deviations generate alertsQuarterly (PEPs)
Critical-riskEvery 3-6 monthsSenior compliance sign-off on decisions; MLRO escalationQuarterly or more frequent

The calibration of transaction monitoring rules and thresholds is itself an ongoing obligation. What constitutes a reasonable threshold for a given customer segment is not a static determination. It must be reviewed as transaction patterns evolve, as new typologies emerge, and as the institution’s understanding of its own risk exposure deepens.

PEP, Sanctions, and Adverse Media Re-Screening Obligations

Screening obligations do not end at customer onboarding.

PEP re-screening is required when a customer is flagged as a politically exposed person. Regulated entities should re-screen existing customers against PEP databases when there is reason to believe the customer’s PEP status may have changed, when the customer’s profile changes materially, and on a periodic basis determined by the risk tier of the customer. For high-risk PEPs, quarterly re-screening is a common industry practice and is required by supervisors in several jurisdictions. For lower-risk PEPs, annual re-screening is typically considered the minimum.

Sanctions re-screening operates under a different logic. Sanctions lists change continuously as new designations are made and existing designations are removed or updated. Regulated entities are generally expected to re-screen their customer base against updated sanctions lists within a timeframe proportionate to the risk. In most jurisdictions, the obligation to ensure no customer appears on a sanctions list is treated as continuous, not periodic.

Adverse media refresh is increasingly expected by regulators as part of a mature ongoing due diligence programme. A customer whose risk profile appeared acceptable at onboarding may acquire adverse media associations that materially affect their risk classification.

MemberCheck provides the screening infrastructure to support PEP re-screening, sanctions list refresh, and adverse media monitoring as part of an ongoing compliance programme. Regulated entities remain responsible for determining the frequency, scope, and escalation procedures applicable to their own risk framework.

Documentation and Audit Trail Requirements

A monitoring programme that cannot demonstrate its decisions is a programme that cannot defend itself.

FATF Recommendation 11 requires ongoing due diligence and scrutiny of transactions. Both Recommendations 11 and 12 require that the results of enhanced due diligence and enhanced monitoring be documented. The documentation obligation is not limited to the outcome of a monitoring decision. It extends to the rationale for the decision and the evidence on which it was based.

This means that for every risk tier assignment, every periodic review outcome, every triggered review, and every escalation or non-escalation of a monitoring concern, the compliance record must show what information was reviewed, what the risk assessment concluded, and who made the determination.

FATF mutual evaluation reports have identified documentation deficiencies as among the most common findings in the monitoring domain.

Common Regulatory Findings on Monitoring from FATF MERs

Inadequate calibration of transaction monitoring rules. Institutions that apply the same monitoring thresholds to all customers regardless of risk profile are not applying a risk-based approach as required by Recommendation 11.

Absence of outcome testing. Regulators increasingly expect institutions to test whether their transaction monitoring actually detects the patterns it is designed to detect.

Insufficient documentation of monitoring decisions. Evaluators specifically check whether periodic reviews are evidenced, whether triggered reviews are documented, and whether the rationale for risk-tier assignments is recorded.

Failure to update customer risk profiles. A risk profile that is not updated is a risk profile that is not maintained.

Inadequate coverage of new monitoring triggers. Institutions with manual or fragmented compliance processes are more likely to exhibit this deficiency.

Technology Infrastructure Expectations

Regulators understand that the scale of transaction data makes manual monitoring functionally impossible. Their expectation is not that institutions avoid technology, but that the technology deployed is adequate for the monitoring obligations it is expected to fulfil.

System coverage is the first expectation. A transaction monitoring system that does not receive all relevant transaction data is not fulfilling its function.

Threshold calibration is the second. Static thresholds that have never been reviewed since system implementation do not constitute a risk-based monitoring programme.

Model validation is an expectation that has become increasingly prominent as AI-assisted transaction monitoring systems have become more prevalent. Where machine learning models are used, the institution must be able to explain how the model works, what its known limitations are, and how those limitations are managed.

Data quality underpins all of the above. A monitoring system is only as effective as the transaction data it receives.

Audit trail functionality is a technology-level documentation obligation. Systems should record every monitoring decision, every alert, every disposition, and every override with timestamps and user identifiers.

FraudShield provides transaction monitoring infrastructure designed to support these requirements. Regulated entities must ensure that their technology infrastructure is deployed in a manner that meets their specific regulatory obligations.


Frequently Asked Questions

FATF Recommendation 10 and the accompanying guidance do not prescribe a fixed review interval. The standard requires that periodic reviews be conducted at timeframes appropriate to the risk profile of the customer. National regulators in individual jurisdictions may specify minimum intervals.
Transaction monitoring is the analysis of individual and aggregate transactions to detect patterns consistent with financial crime. Ongoing due diligence is the broader obligation to maintain current knowledge of the customer. Transaction monitoring is one component of ongoing due diligence.
A customer’s risk profile should be updated when new information materially affects the customer’s risk classification. This includes new adverse media associations, changes in PEP status, changes in the customer’s business activities, and changes in the customer’s ownership or control structure.
For each alert, the compliance record should include the alert details, the analyst’s assessment, the decision made, the rationale for that decision, and the identity of the person making the decision.

Conclusion

Ongoing transaction monitoring is not a compliance task that can be completed once and filed. It is a continuous operational obligation that runs alongside every customer relationship for its entire duration.

The regulatory framework, anchored by FATF Recommendations 10 and 11, requires that monitoring be dynamic, risk-proportionate, documented, and regularly tested. The most common deficiencies identified in FATF evaluations, including inadequate calibration, absent outcome testing, insufficient documentation, and failure to update risk profiles, are all addressable through a structured approach to programme design and governance.

Regulated entities remain responsible for determining the specific obligations applicable in their own jurisdiction, for calibrating their monitoring programmes to their own customer risk profile, and for maintaining the documentation and testing evidence that demonstrates programme effectiveness to their supervisor.

Ongoing Transaction Monitoring Obligations: A Compliance Guide

Ongoing transaction monitoring is a continuous legal obligation under FATF Recommendation 11, not a one-time onboarding task. This guide explains what regulated entities must do, by when, and at what intensity.

Speak to our team

This article was accurate at the time of publication in August 2026 and is intended for general informational purposes only. It does not constitute legal, regulatory or compliance advice. Organisations should seek qualified professional guidance in relation to their specific obligations.