What is ongoing monitoring?
How firms check that a customer's activity still matches what they know, when KYC must be refreshed, and what CySEC expects from monitoring systems.
By the ExamPass CY editorial teamLast reviewed 5 min read
Topic 11 of 14 · all topics in this chapter
- 1When CDD is required
- 2What CDD involves
- 3When CDD must be completed
- 4Verifying individuals
- 5Verifying companies and organisations
- 6Customer economic profile
- 7Beneficial ownership registers
- 8Simplified due diligence
- 9Enhanced due diligence and PEPs
- 10CDD by sector
- 11Ongoing monitoring
- 12Reliance on third parties
- 13Group-wide AML policies
- 14Prohibited practices and data use
Short answer
Ongoing monitoring is the fourth CDD measure. Throughout the relationship, the firm scrutinises transactions to confirm they match what it knows about the customer, their business, their risk profile and, where needed, their source of funds, and it keeps the customer's documents and data up to date. CySEC expects regular reviews of customer files at intervals set by risk, more intensive checks on high-risk customers, a fresh look after material changes such as new directors or owners, and periodic comparison of actual activity with the expected turnover.
Monitoring duties at a glance
| Point | Rule |
|---|---|
| Legal duty | Scrutinise transactions for consistency with the customer's profile, and keep documents, data and information current |
| Customer records | Kept fully up to date; validity and adequacy checked regularly, especially for high-risk customers; a set review timeframe; each review's outcome recorded in the customer file |
| Missing information found later | Collect it and complete the economic profile |
| Significant transaction out of line with the usual pattern | Re-check the adequacy of identity and economic profile data |
| Material change in legal status | Re-check identity and profile data, for example after new directors or secretary, shareholders or beneficial owners, registered office, trustees, company or trading name, main trading partners or major new activities |
| Material change in how the account works | Re-check identity and profile data, for example after new authorised persons, or a request for a new account for new investment services or financial instruments |
| Investigations | Carried out by appointed staff, recorded in a separate memo in the customer file, and reported internally to the AML Compliance Officer where suspicion arises |
Source: Law 188(I)/2007, Article 61(1)(d); CySEC Directive, paragraphs 18 and 26.
Why does ongoing monitoring matter?
CDD at onboarding describes what the customer should be doing; monitoring checks whether they are. Without a clear picture of the customer's economic profile and normal account activity, a firm cannot recognise transactions that fall outside the pattern, and so cannot meet its legal duty to report suspicious transactions to MOKAS.
Monitoring covers both halves of the relationship: the customer's KYC data, which must stay current, and the transactions, which must keep making sense against that data. See What is a customer's economic profile?
Terms used in this note
- Ongoing monitoring
- Scrutiny of a customer's transactions throughout the relationship, and updating of their records, to make sure activity stays consistent with what the firm knows.
- Dormant account
- An account with no customer activity for a long period; unexpected movement on it is a warning sign.
- AML Compliance Officer
- The senior officer who receives internal reports of suspicion and decides whether to report to MOKAS.
When must customer information be refreshed?
Records must stay complete throughout the relationship. The firm checks the validity and adequacy of identification data regularly, with most attention on high-risk customers, sets out in its procedures how often reviews happen, and records the outcome of each review on a separate note in the customer file. If it discovers along the way that reliable information is missing, it collects it and completes the profile.
Certain events call for a fresh check straight away: a significant transaction that looks unusual against the customer's normal pattern and profile; a material change to the customer's legal status, such as new directors or secretary, new shareholders or beneficial owners, a new registered office, new trustees, a change of company or trading name, or new principal trading partners or major business activities; and a material change in how the account is operated, such as new authorised signatories or a request to open an account for new investment services or instruments.
What should transaction monitoring achieve?
The method and intensity of monitoring follow the level of risk, but at a minimum it must identify all high-risk customers so they can be watched more closely, detect transactions that do not fit the economic profile, establish the source and origin of funds credited to accounts, and have appointed staff investigate anything unusual. Findings go on a separate memo in the customer file, and where suspicion arises the matter is reported internally to the AML Compliance Officer.
Monitoring also compares actual account movements, at regular intervals, with the turnover declared at onboarding, and covers customers who have no contact with the firm and dormant accounts that suddenly move.
Where appropriate for the nature, scale and complexity of the business, CySEC expects automated systems that give the board and the AML Compliance Officer timely information. Such systems add up activity across related accounts and flag what stands out, using limits for particular types of account or transaction, such as cash deposits and withdrawals. They can also help identify missing KYC data. Significant differences are investigated and the results recorded.
How to think about it
Think baseline and deviation. The economic profile is the baseline, and every transaction is measured against it. Keep the baseline current by reviewing files regularly and at once after material changes. When something deviates, investigate, write it up in the file and, if suspicion remains, report it to the AML Compliance Officer.
Common mistakes
Monitoring only high-risk customers. Every customer's data is kept up to date and reviewed at intervals set by risk; high-risk customers get more intensive checks.
Waiting for the next scheduled review after a change of directors or owners. A material change triggers a fresh check of the customer's data.
Looking at each account on its own. Movements across related accounts are added up to reveal patterns.
Investigating without a record. Results go on a separate memo in the customer's file.
Ignoring dormant accounts. Unexpected movement on a dormant account should be flagged.
Legal references
- The Prevention and Suppression of Money Laundering and Terrorist Financing Law of 2007 (Law 188(I)/2007), as amended (opens in a new tab)
Article 61(1)(d) (ongoing monitoring) · Article 64(4) (examining unusual transactions) · Article 69 (internal reporting)
- CySEC Directive for the Prevention and Suppression of Money Laundering and Terrorist Financing, as amended (opens in a new tab)
Paragraph 18 (reviewing customer data) · Paragraph 26 (monitoring accounts and transactions)
- Regulation (EU) 2024/1624 (Anti-Money Laundering Regulation), applying from 10 July 2027 (opens in a new tab)
Article 26
Practise this topic
Test what you just read
The Chapter 6 pack has 152 exam-style questions, 15 of them on this topic. Every question has a hint before you answer and a full explanation after.
Or revise the numbers first with 18 free Chapter 6 flashcards →