Ongoing monitoring — the AMLR Article 26 duty
Ongoing monitoring is usually read as “run the transaction monitoring system”. Article 26 asks for three things, and that is only one of them. Regulation (EU) 2024/1624 requires monitoring of the business relationship as well as of transactions, requires customer information to be kept up to date on a risk-driven cycle, and — for groups — requires information from other relationships within the group to be taken into account. Each is separately testable.
1. Monitoring against what you know
Article 26(1) sets the benchmark precisely: obliged entities must conduct ongoing monitoring of business relationships, including transactions undertaken throughout the relationship, to ensure those transactions are consistent with the entity’s knowledge of the customer, the customer’s business activity and risk profile and, where necessary, with information about the origin and destination of the funds — and to detect transactions requiring more thorough assessment under Article 69(2).
That framing has a consequence for model design. Monitoring is benchmarked against the firm’s own knowledge of the customer, so a scenario set that is identical for every customer is not, by itself, discharging the article. The expected-activity profile captured at onboarding is what the monitoring is supposed to be measured against.
2. Every product in the relationship
Where a business relationship covers more than one product or service, Article 26(1) requires that customer due diligence measures cover all of those products and services. In a firm that has grown by adding products — an account, then cards, then FX, then a credit line — this is the provision that catches monitoring configured per product rather than per customer.
3. Keeping the information current
Article 26(2) requires the relevant documents, data or information of the customer to be kept up to date, and sets the cadence by risk: the period between updates depends on the risk posed by the business relationship, with an outer limit fixed by the Regulation rather than left to the firm.
| Element | Article 26 requirement |
|---|---|
| Benchmark | Consistency with the firm’s knowledge of the customer, their business activity and risk profile |
| Coverage | All products and services in the relationship |
| Group | Information on the customer’s relationships elsewhere in the group, including with non-obliged undertakings |
| Refresh | Risk-driven periodicity, subject to the Regulation’s outer limit |
| Output | Detection of transactions for more thorough assessment under Article 69(2) |
FAQ
Is ongoing monitoring the same as transaction monitoring?
No. Transaction monitoring is part of it. Article 26 also requires monitoring of the relationship itself and keeping customer information current, and those are assessed separately by supervisors.
How often must customer information be refreshed?
On a cycle driven by the risk of the relationship, subject to the outer limit the Regulation sets. A fixed periodic-review calendar with no risk differentiation does not reflect the article.
Do we have to look at group relationships?
Yes, where the customer is also a customer of other entities in the group — expressly including group undertakings that are not themselves subject to AML/CFT requirements.
Related: Enhanced due diligence · The customer risk profile · AMLR outsourcing


