Ongoing AML monitoring is the continuous, risk-based process of keeping customer identity information current, watching the business relationship for changes that affect risk, and applying enhanced measures when that risk rises. It is not a periodic file review triggered by the calendar. Under the AML/CTF Act, you must re-screen for sanctions and PEP status, update know-your-customer (KYC) records when material changes occur, and escalate to a suspicious matter report where warranted.
TL;DR:
- Continuous monitoring should automatically detect changes in customer risk profiles through triggers like transaction spikes or new sanctions hits, rather than relying on fixed schedules.
- Operators must document every decision, review, and escalation step thoroughly, as incomplete records are considered non-compliance regardless of system performance.
- High-risk customers require tighter thresholds and faster responses, with automation and clear escalation protocols, to ensure timely action and regulatory adherence.
- Key metrics such as alert volume, SLA performance, backlog size, and SMR conversion rate enable effective oversight and ongoing tuning of the monitoring system.
- Automated platforms like AML Guard streamline the entire process, from re-screening and ownership tracing to audit trails, reducing manual effort and improving compliance reliability.
Table of Contents
- Why ongoing AML monitoring matters beyond box-ticking
- AUSTRAC expectations: what ongoing customer due diligence requires
- Core components every monitoring program needs
- How to implement risk-based, trigger-driven ongoing monitoring
- What to measure and report: MI and assurance for ongoing monitoring
- How AML Guard operationalises ongoing monitoring for Australian reporting entities
- Practitioner perspective: common pitfalls and quick fixes
- Get ongoing monitoring right without building it from scratch
- Sources
Why ongoing AML monitoring matters beyond box-ticking
A customer who looked low-risk at onboarding does not stay that way by default. Roles change, company structures shift, transaction patterns drift, and sanctions lists get updated weekly. Ongoing monitoring exists to catch that drift before it becomes an enforcement problem, not after.
Under sections 30, 32 and 39D of the Act you must monitor customers to identify, assess, manage and mitigate money laundering, terrorism financing and proliferation financing risk throughout the relationship, and your AML/CTF policies must deal with how you do it. See AUSTRAC’s reform guidance on ongoing customer due diligence. That duty links your onboarding KYC directly to your obligation to file a suspicious matter report when something does not add up.
Three things happen when ongoing monitoring works properly:
- Profile drift gets caught early, before a customer’s actual risk outpaces their recorded rating.
- Suspicious behaviour surfaces through pattern recognition, not luck.
- Supervisors see a documented chain from onboarding through to escalation, which is exactly what they look for in a review.
Get this wrong and the consequence is rarely a single missed transaction. It is a pattern of missed transactions that a regulator reconstructs months later, asking why nobody acted on the first one.
AUSTRAC expectations: what ongoing customer due diligence requires
AUSTRAC does not treat ongoing customer due diligence as separate from your broader AML/CTF program. It is the mechanism that keeps your risk assessment honest over time, and it carries three specific duties you need to run together, not in isolation.
- Keep customer information current. Update KYC records when a customer’s circumstances change, not on a fixed schedule.
- Monitor the relationship for risk-relevant change. Watch transaction behaviour, ownership structure and stated purpose for signs the original risk rating no longer fits.
- Apply enhanced measures when risk rises. Escalate to enhanced due diligence and, where there are reasonable grounds for suspicion, lodge a suspicious matter report.
Sanctions and PEP status are not static. A director who was clean at onboarding can appear on a sanctions list eighteen months later, and a screen taken once at intake goes stale the moment the underlying list updates. AUSTRAC expects entities to develop monitoring thresholds and triggers directly from their own ML/TF risk assessment, and to automate that monitoring wherever manual review would be too slow or too inconsistent to catch it.
Record-keeping is not an afterthought here. If you cannot show a supervisor how a monitoring decision was reached, on paper, you have not demonstrated compliance, regardless of what your systems actually caught.
Core components every monitoring program needs
Ongoing monitoring is not one control. It is a set of linked components, and a gap in any one of them breaks the chain from detection to decision.
- Transaction monitoring as the signal engine. Rules and thresholds flag unusual transaction patterns, generating the raw alerts that everything else responds to.
- Ongoing CDD as the decision engine. Every alert has to feed back into the customer’s risk profile. An alert with no documented outcome is a process failure, not a completed control.
- Automated re-screening with manual officer review. Systems re-check sanctions, PEP and adverse-media lists on a schedule, but a compliance officer reviews every match. Automation finds the hit; a person decides what it means.
- Beneficial ownership tracing. Companies, trusts and SMSFs need periodic ownership checks, because a change in control can shift a customer’s risk profile without a single transaction changing.
- Case management and escalation. Every flagged item needs a clear pathway to enhanced due diligence or a suspicious matter report, with a named approver responsible for the outcome.
Pro Tip: Treat every screening match as guilty until proven innocent by a documented officer decision. An unreviewed match sitting in a queue is functionally the same as no screening at all.
How to implement risk-based, trigger-driven ongoing monitoring
Calendar reviews feel orderly, but they miss the customer who changes risk profile the week after the annual review closes. AUSTRAC does not prescribe a fixed review interval, and building your program around one misses the point of the obligation.
Build triggers from your own risk assessment instead:
- Transaction volume or value spikes against the customer’s expected activity.
- A new sanctions or PEP hit on the customer or a connected party.
- A change in beneficial ownership, directorship or trustee structure.
- Adverse media naming the customer or an associated entity.
Calibrate intensity by risk tier. High-risk customers need tighter thresholds and faster disposition; low-risk customers can run on lighter-touch, mostly automated checks, freeing your team’s attention for where it counts. AUSTRAC allows simplified ongoing CDD where the customer’s ML/TF risk is low, enhanced CDD is not required, and your AML/CTF policies deal with it: less intensive monitoring, and reverifying KYC information less frequently.
Set a disposition service level agreement for every alert tier, name an approver for each, and write down the escalation rule before you need it in a crisis. Retain every decision, every re-screening result, and every rationale in a record that cannot be quietly edited after the fact.
Firms that lack event-driven procedures and named approvers consistently perform worse under supervision, while firms that document their decisions and run assurance cycles perform better. The difference is almost never the detection technology; it is whether someone owned the decision and wrote down why.
What to measure and report: MI and assurance for ongoing monitoring
Senior management and auditors do not want a narrative. They want numbers that show the control is actually operating, and they want to see it tested independently rather than just self-reported.
| Metric | What it tells you |
|---|---|
| Alert volume by rule | Whether a rule is over-triggering (noise) or under-triggering (blind spot) |
| Disposition SLA performance | Whether alerts are actioned within the timeframe your policy sets |
| Backlog size and age | Whether your team is keeping pace with alert volume |
| SMR conversion rate | The proportion of escalated cases that result in a suspicious matter report |
Rule tuning should follow both a regular cadence and specific trigger events, such as a new typology emerging in your customer base. Independent testing, separate from the team running day-to-day monitoring, is what turns these metrics from an internal dashboard into evidence a regulator will actually credit.
How AML Guard operationalises ongoing monitoring for Australian reporting entities
Turning these obligations into daily practice is where most programs stall, particularly for firms managing ongoing CDD monitoring Australia-wide across dozens or hundreds of active files. AML Guard was built specifically for this operational layer.
- Scheduled automatic re-screening runs against sanctions, PEP and adverse-media sources, with every result and every officer decision logged in a seven-year tamper-evident audit trail.
- End-to-end coverage spans identity verification, sanctions and PEP screening, beneficial ownership determination on a company’s ACN with trusts and SMSFs reached through their corporate trustee, and suspicious matter report workflows in one linked system.
- REX CRM integration pushes compliance status indicators, not sensitive CDD data, so a file’s status is visible without duplicating your existing systems.
- A client-pays option lets the transaction party fund their own verification check, credited back against the firm’s subscription.
The audit trail is tamper-evident, not tamper-proof. That distinction matters when a supervisor asks how you know a record has not been altered after the fact.
Practitioner perspective: common pitfalls and quick fixes

Calendar-only reviews fail because risk does not wait for an anniversary date. A customer’s ownership can change in March and sit unreviewed until the scheduled check in November, and that gap is exactly where problems hide.
Partial coverage is the other recurring failure: sanctions re-screening running but beneficial ownership left static, or transaction alerts generated but never linked back to the customer’s CDD file. Fix it fast by triaging your existing alert types against your risk assessment, naming an approver for each escalation path, and setting a short SLA for high-risk dispositions, even before the rest of the program is fully rebuilt.
Get ongoing monitoring right without building it from scratch
Most reporting entities do not fail ongoing monitoring because they misunderstand the obligation. They fail because building trigger-driven re-screening, officer review workflows and a seven-year audit trail from spreadsheets and email is slower and more error-prone than any manual process can sustain. AML Guard runs that entire chain automatically, so your compliance officer reviews decisions instead of chasing them.

AML Guard serves real estate agencies, buyers agents and property developers, conveyancers, law firms, accounting practices, and trust and company service providers, the full range of Tranche 2 reporting entities now subject to the AML/CTF Act. Scheduled re-screening, beneficial ownership tracing, and a tamper-evident record of every decision come built into the platform, aligned to AUSTRAC’s expectations rather than adapted from a generic compliance tool. If your current monitoring still runs on calendar reminders and manual list checks, book a demo to see how a trigger-driven system handles the same obligations with far less manual effort.
Sources
- Overview of ongoing customer due diligence (Reform) | AUSTRAC
- AML/CTF Act 2006 (Cth) | Federal Register of Legislation
Recommended
- AML Compliance Pricing in Australia: 2026 Comparison
- AML/CTF Compliance Checklist for Real Estate Agents: What You Need Before 1 July 2026
- AML/CTF Program Documents for Tranche 2
- What Is an AML/CTF Program? A Plain-English Guide for Property Professionals
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.