Ongoing AML monitoring for Tranche 2 firms

Ongoing AML monitoring for Tranche 2 firms

What ongoing CDD requires under the Act, why trigger-driven monitoring beats calendar reviews, and how to evidence every escalation decision.

AML/CTF Compliance 2 September 2026 8 min read AML Guard

Ongoing AML monitoring is the continuous, risk-based process of keeping customer identity information current, watching the business relationship for changes that affect risk, and applying enhanced measures when that risk rises. It is not a periodic file review triggered by the calendar. Under the AML/CTF Act, you must re-screen for sanctions and PEP status, update know-your-customer (KYC) records when material changes occur, and escalate to a suspicious matter report where warranted.


TL;DR:


Table of Contents

Why ongoing AML monitoring matters beyond box-ticking

A customer who looked low-risk at onboarding does not stay that way by default. Roles change, company structures shift, transaction patterns drift, and sanctions lists get updated weekly. Ongoing monitoring exists to catch that drift before it becomes an enforcement problem, not after.

Under sections 30, 32 and 39D of the Act you must monitor customers to identify, assess, manage and mitigate money laundering, terrorism financing and proliferation financing risk throughout the relationship, and your AML/CTF policies must deal with how you do it. See AUSTRAC’s reform guidance on ongoing customer due diligence. That duty links your onboarding KYC directly to your obligation to file a suspicious matter report when something does not add up.

Three things happen when ongoing monitoring works properly:

Get this wrong and the consequence is rarely a single missed transaction. It is a pattern of missed transactions that a regulator reconstructs months later, asking why nobody acted on the first one.

AUSTRAC expectations: what ongoing customer due diligence requires

AUSTRAC does not treat ongoing customer due diligence as separate from your broader AML/CTF program. It is the mechanism that keeps your risk assessment honest over time, and it carries three specific duties you need to run together, not in isolation.

Sanctions and PEP status are not static. A director who was clean at onboarding can appear on a sanctions list eighteen months later, and a screen taken once at intake goes stale the moment the underlying list updates. AUSTRAC expects entities to develop monitoring thresholds and triggers directly from their own ML/TF risk assessment, and to automate that monitoring wherever manual review would be too slow or too inconsistent to catch it.

Record-keeping is not an afterthought here. If you cannot show a supervisor how a monitoring decision was reached, on paper, you have not demonstrated compliance, regardless of what your systems actually caught.

Core components every monitoring program needs

Ongoing monitoring is not one control. It is a set of linked components, and a gap in any one of them breaks the chain from detection to decision.

  1. Transaction monitoring as the signal engine. Rules and thresholds flag unusual transaction patterns, generating the raw alerts that everything else responds to.
  2. Ongoing CDD as the decision engine. Every alert has to feed back into the customer’s risk profile. An alert with no documented outcome is a process failure, not a completed control.
  3. Automated re-screening with manual officer review. Systems re-check sanctions, PEP and adverse-media lists on a schedule, but a compliance officer reviews every match. Automation finds the hit; a person decides what it means.
  4. Beneficial ownership tracing. Companies, trusts and SMSFs need periodic ownership checks, because a change in control can shift a customer’s risk profile without a single transaction changing.
  5. Case management and escalation. Every flagged item needs a clear pathway to enhanced due diligence or a suspicious matter report, with a named approver responsible for the outcome.

Pro Tip: Treat every screening match as guilty until proven innocent by a documented officer decision. An unreviewed match sitting in a queue is functionally the same as no screening at all.

How to implement risk-based, trigger-driven ongoing monitoring

Calendar reviews feel orderly, but they miss the customer who changes risk profile the week after the annual review closes. AUSTRAC does not prescribe a fixed review interval, and building your program around one misses the point of the obligation.

Build triggers from your own risk assessment instead:

Calibrate intensity by risk tier. High-risk customers need tighter thresholds and faster disposition; low-risk customers can run on lighter-touch, mostly automated checks, freeing your team’s attention for where it counts. AUSTRAC allows simplified ongoing CDD where the customer’s ML/TF risk is low, enhanced CDD is not required, and your AML/CTF policies deal with it: less intensive monitoring, and reverifying KYC information less frequently.

Set a disposition service level agreement for every alert tier, name an approver for each, and write down the escalation rule before you need it in a crisis. Retain every decision, every re-screening result, and every rationale in a record that cannot be quietly edited after the fact.

Firms that lack event-driven procedures and named approvers consistently perform worse under supervision, while firms that document their decisions and run assurance cycles perform better. The difference is almost never the detection technology; it is whether someone owned the decision and wrote down why.

What to measure and report: MI and assurance for ongoing monitoring

Senior management and auditors do not want a narrative. They want numbers that show the control is actually operating, and they want to see it tested independently rather than just self-reported.

Metric What it tells you
Alert volume by rule Whether a rule is over-triggering (noise) or under-triggering (blind spot)
Disposition SLA performance Whether alerts are actioned within the timeframe your policy sets
Backlog size and age Whether your team is keeping pace with alert volume
SMR conversion rate The proportion of escalated cases that result in a suspicious matter report

Rule tuning should follow both a regular cadence and specific trigger events, such as a new typology emerging in your customer base. Independent testing, separate from the team running day-to-day monitoring, is what turns these metrics from an internal dashboard into evidence a regulator will actually credit.

How AML Guard operationalises ongoing monitoring for Australian reporting entities

Turning these obligations into daily practice is where most programs stall, particularly for firms managing ongoing CDD monitoring Australia-wide across dozens or hundreds of active files. AML Guard was built specifically for this operational layer.

The audit trail is tamper-evident, not tamper-proof. That distinction matters when a supervisor asks how you know a record has not been altered after the fact.

Practitioner perspective: common pitfalls and quick fixes

Practitioner perspective: common pitfalls and quick fixes — overview diagram

Calendar-only reviews fail because risk does not wait for an anniversary date. A customer’s ownership can change in March and sit unreviewed until the scheduled check in November, and that gap is exactly where problems hide.

Partial coverage is the other recurring failure: sanctions re-screening running but beneficial ownership left static, or transaction alerts generated but never linked back to the customer’s CDD file. Fix it fast by triaging your existing alert types against your risk assessment, naming an approver for each escalation path, and setting a short SLA for high-risk dispositions, even before the rest of the program is fully rebuilt.

Get ongoing monitoring right without building it from scratch

Most reporting entities do not fail ongoing monitoring because they misunderstand the obligation. They fail because building trigger-driven re-screening, officer review workflows and a seven-year audit trail from spreadsheets and email is slower and more error-prone than any manual process can sustain. AML Guard runs that entire chain automatically, so your compliance officer reviews decisions instead of chasing them.

AML Guard dashboard showing scheduled re-screening and officer decisions

AML Guard serves real estate agencies, buyers agents and property developers, conveyancers, law firms, accounting practices, and trust and company service providers, the full range of Tranche 2 reporting entities now subject to the AML/CTF Act. Scheduled re-screening, beneficial ownership tracing, and a tamper-evident record of every decision come built into the platform, aligned to AUSTRAC’s expectations rather than adapted from a generic compliance tool. If your current monitoring still runs on calendar reminders and manual list checks, book a demo to see how a trigger-driven system handles the same obligations with far less manual effort.

Sources

See How AML Guard Works

Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.

Book a Demo
This article is for general information purposes only and does not constitute legal advice. Firms should obtain independent professional advice on their specific AML/CTF obligations.
Last reviewed: 2 September 2026.