# Ongoing monitoring

**Ongoing monitoring is the continuing scrutiny of an established business relationship — its transactions and the customer's information — to check that activity stays consistent with what the firm knows about the customer and to keep due-diligence data up to date.** Under the AMLR, customer information must be refreshed at least once a year for higher-risk customers and at least every five years for all others.

*Also called:* ongoing due diligence, periodic review, customer refresh, perpetual KYC (when event-driven).

## Why it matters for PSPs and EMIs

Onboarding is a snapshot; a merchant's business, owners and sanctions exposure change afterwards. For payment and e-money institutions, ongoing monitoring combines two things: watching transactions against the expected profile, and refreshing the customer file when time passes or something changes.

## What the law says

- **The duty.** AMLR Art. 20(1)(f) and Art. 26(1): monitor the relationship, including transactions, to ensure consistency with the firm's knowledge of the customer, its business and risk profile and, where necessary, the origin and destination of funds; and detect transactions that need a closer assessment for possible reporting.
- **Refresh intervals.** AMLR Art. 26(2): the interval depends on risk and may not exceed 1 year for higher-risk customers subject to enhanced due diligence, and 5 years for all other customers.
- **Event-driven reviews.** AMLR Art. 26(3): also review when a customer's relevant circumstances change, when the firm must contact the customer about beneficial ownership during the year, or when it becomes aware of a relevant fact.
- **Sanctions.** AMLR Art. 26(4): verify regularly whether the customer or its owners are subject to targeted financial sanctions; credit and financial institutions also do so upon any new designation.
- **Guidance to come.** AMLR Art. 26(5): AMLA guidelines on ongoing monitoring. AMLA has consulted on a draft; on its overview of 28 September 2026 the guidelines were not yet final.
- **Current law.** Directive (EU) 2015/849, Art. 13(1)(d) and Art. 14(5), as transposed nationally.
- **International standard.** FATF Recommendation 10.

## How ProofVolt handles it

ProofVolt keeps every source, step and decision of a case in an append-only trail, so a later review starts from a record of what was established, from which source, and why.

## Related

- [Customer due diligence (CDD)](/glossary/customer-due-diligence/)
- [Sanctions screening](/glossary/sanctions-screening/)
- [Source of funds](/glossary/source-of-funds/)

Canonical: https://proofvolt.eu/glossary/ongoing-monitoring/
