Single Blog

  • Home
  • Periodic Review vs Ongoing Monitoring in AML
Periodic Review vs Ongoing Monitoring in AML

Periodic Review vs Ongoing Monitoring in AML

September 6, 2026

A client file can look complete at onboarding and still become a source of material AML exposure months later. The question of periodic review vs ongoing monitoring is therefore not a choice between two alternative controls. Both are necessary parts of a risk-based AML framework, but they serve different purposes, operate on different timetables and produce different evidence for regulators.

For compliance officers, MLROs and operational leaders, the objective is clear: maintain customer due diligence that remains accurate, proportionate and capable of supporting defensible decisions throughout the business relationship.

Periodic review vs ongoing monitoring: the core distinction

Periodic review is a planned reassessment of a client relationship at defined intervals. It tests whether the information and risk assessment held on file remain current, sufficient and appropriate. A periodic review commonly considers changes to ownership and control, beneficial owners, source of wealth or source of funds information, expected activity, sanctions and PEP status, adverse media, and the client’s overall risk rating.

Ongoing monitoring is the continuous process of identifying information or activity that may require the relationship to be reassessed before its next scheduled review date. It includes scrutiny of transactions and behaviour against the expected activity profile, as well as consideration of external events such as sanctions designations, negative news, corporate changes or changes in a client’s jurisdictional exposure.

The distinction matters because a scheduled review cannot compensate for a failure to react to a material event, while alerts and event-driven checks do not replace a full, documented refresh of the client record. A high-risk relationship reviewed annually may still require immediate action if its ownership changes, transaction activity becomes inconsistent with its profile or credible adverse media emerges.

What periodic reviews are designed to achieve

A periodic review gives the firm a structured point at which to challenge assumptions made at onboarding. It should not be treated as an administrative request for updated documents. The reviewer needs to assess whether the client remains within the organisation’s risk appetite and whether the rationale for continuing the relationship is adequately evidenced.

The frequency should reflect risk. Higher-risk clients, including certain PEP relationships, complex legal structures, clients linked to higher-risk jurisdictions or those with unusual anticipated activity, will generally require more frequent and deeper review. Lower-risk relationships may justify longer cycles where the risk assessment, controls and regulatory requirements support this approach.

A meaningful review normally revisits the purpose and intended nature of the relationship, verifies relevant identification and beneficial ownership information, refreshes screening where required, and compares actual activity with what the firm expected at onboarding. It should also record whether the risk rating remains appropriate and whether enhanced due diligence, restrictions or senior management approval are needed.

The output is more than an updated expiry date. It is an auditable decision: continue the relationship on its existing basis, apply additional controls, reclassify the risk, escalate for investigation or exit the relationship. Clear reasoning is vital, particularly where the available information is incomplete or risk indicators have increased.

Ongoing monitoring is an operational control, not a calendar event

Ongoing monitoring keeps the client risk assessment responsive between reviews. In practice, it combines automated and manual controls. Transaction monitoring may identify patterns that are inconsistent with a customer’s known business, while screening systems can identify potential sanctions, PEP or adverse media matches. Relationship managers, client services teams and operations staff may also identify changes through direct contact with the client.

Not every alert warrants the same response. A risk-based programme defines how alerts are triaged, investigated, escalated and closed, with sufficient evidence to demonstrate why the outcome was reasonable. Poorly calibrated systems can generate excessive false positives, causing teams to focus on alert volumes rather than risk. Conversely, overly narrow rules can leave meaningful activity undetected.

Ongoing monitoring also extends beyond transactions. A new director, a revised shareholding structure, an unexpected change in payment counterparties or a public allegation of financial crime may each be a trigger event. The appropriate response depends on materiality. It may be a targeted refresh of a specific document, a reassessment of source of wealth, enhanced monitoring or a full out-of-cycle review.

The key principle is timeliness. A firm should not wait for the next review cycle where it has information that calls the existing CDD record or risk assessment into question.

Where firms commonly create avoidable gaps

A frequent weakness is treating periodic review and ongoing monitoring as separate workstreams with no shared client record. The monitoring team may close an alert without updating the risk assessment, while the review team may not see a history of relevant alerts, investigations or changes in expected activity. This leads to fragmented decision-making and weak management information.

Another issue is using fixed review cycles without documenting why they are proportionate. A three-year cycle may be reasonable for some lower-risk relationships, but not simply because it is administratively convenient. The firm should be able to demonstrate how client risk, product risk, delivery channels, geography and transaction profile inform its review schedule.

There is also a tendency to confuse screening with ongoing monitoring. Screening is an essential control, but it does not by itself establish whether a client’s behaviour is consistent with the stated purpose of the relationship. Equally, transaction monitoring without a well-defined expected activity profile is unlikely to produce reliable outcomes.

Finally, firms can undermine sound controls through unclear ownership. If nobody is accountable for obtaining outstanding information, deciding whether a trigger is material or escalating a relationship that has exceeded its review date, the process will fail under pressure.

Building a connected review and monitoring framework

An effective framework begins with a clear client risk methodology. The methodology should set out the factors that influence risk ratings, the events that require reassessment and the review intervals associated with each risk category. It should be tailored to the business model rather than copied from a generic policy.

The second requirement is a reliable flow of information. Monitoring outcomes, screening results, client communications and changes identified by front-line teams should feed into the central client file. This allows reviewers to see the full relationship history and ensures that decisions made during an investigation are reflected in the next periodic review.

Governance should define who performs each activity, who can approve exceptions and when matters must be referred to the MLRO or senior management. For higher-risk decisions, a documented escalation route protects both the business and the individuals responsible for the relationship.

Firms also need evidence that controls work in practice. Useful management information may include overdue review volumes, high-risk review completion rates, alert ageing, trigger events raised and resolved, risk-rating movements, recurring documentation gaps and the outcomes of quality assurance testing. These indicators help management identify whether a process is merely operating or is genuinely effective.

Choosing the right response to a trigger event

A trigger event should not automatically result in a full remediation exercise. Proportionality remains essential. If a low-risk corporate client changes a non-controlling director, a focused update may be sufficient. If a beneficial owner is replaced, transaction values rise sharply or negative media raises credible concerns about predicate offences, a deeper reassessment may be necessary.

The decision should be based on what has changed, whether the change affects the original risk rationale and whether existing CDD remains reliable. Documenting this judgement is as important as collecting new evidence. Regulators will assess not only whether information was obtained, but whether the firm understood its relevance and acted appropriately.

For organisations operating across multiple products or jurisdictions, consistency is particularly important. A central policy can establish minimum standards, but procedures should allow for local legal requirements, product-specific risks and practical differences in available data. This is where tailored controls and tested escalation routes provide more value than a uniform checklist.

A well-designed programme does not make every client relationship burdensome. It directs scrutiny where it is needed, keeps lower-risk work proportionate and gives decision-makers a clear record of why the firm accepted, retained, restricted or exited a relationship. That discipline turns periodic reviews and ongoing monitoring from compliance tasks into controls that protect reputation, support accountable growth and stand up to regulatory scrutiny.