AMLA Ongoing Monitoring: What KYC Systems Must Do

AMLA's draft ongoing monitoring guidelines, published June 3, redefine KYC obligations under Article 26 AMLR. Here's your compliance checklist.

Emily Carter
By Emily CarterAI Strategy Consultant at Joinble
·10 min read
Share
AMLA Ongoing Monitoring: What KYC Systems Must Do
imageUse this imagedownloadDownload

The EU Anti-Money Laundering Authority put out, on 3 June 2026, a consultation on draft guidelines that deal with ongoing monitoring of business relationships. Nobody was amending a rule already on the books. It was AMLA's first detailed attempt, in operational language and for the whole EU, to pin down what "ongoing monitoring" actually obliges every obliged entity to do.

The window for comments ends on 3 September 2026. A public hearing sits on the calendar for 2 July 2026. Finished guidelines are expected in Q4 2026; they will dictate how identity verification systems have to behave well ahead of 10 July 2027, the date the AMLR applies in full.

This paper sits among the roughly 23 Level 2 and Level 3 measures AMLA still has to issue before the AMLR can be enforced in full. High-level principles are what directors and legal counsel usually debate. This consultation is not that. It is written for operators — the compliance teams that run KYC systems — and it tells them, in concrete terms, what ongoing monitoring has to produce.

What the Guidelines Cover

Article 26(5) of the Anti-Money Laundering Regulation is the organising hook. The draft splits into three parts that lock together:

Part Content
General principles Applies to both guidelines; establishes proportionality and the risk-based framework
Guideline 1 Keeping customer information up to date
Guideline 2 Transaction and activity monitoring framework

General Principles: Risk-Based and Technologically Neutral

Technological neutrality is the opening move, and it has operational weight from the first page. AMLA names no required toolkit. A system can be manual, automated, or semi-automated, provided it delivers "the effective identification and escalation of ML/TF risks in line with Article 26 of AMLR."

That reads like room to manoeuvre. It is also a bar. A stack that cannot show effective escalation fails the test, no matter how sophisticated it looks. Outcomes are what count. Inputs are not.

Proportionality runs through the whole sector. AMLR-obliged firms stretch from large cross-border banks to crowdfunding platforms and football clubs. The guidelines scale the duties by risk appetite, customer classification, and the character of the business relationship. A small crowdfunding platform will not carry the same operational load as a Tier 1 CASP with 500,000 users. Both still have to document that their monitoring reaches the threshold.

A wider picture of AMLA's supervisory stance and enforcement powers is in AMLA: the EU's new AML authority and what it demands of CASPs.

Guideline 1: Keeping Customer Information Current

What happens once onboarding is finished is the subject of the first guideline — one of the least examined duties in KYC.

Most talk about identity verification still clusters around the opening check: document verification, liveness detection, sanctions screening. Guideline 1 is about the duty that continues after that, the duty to keep the file accurate. Under the draft, update intervals follow customer risk:

  • High-risk customers: review period capped at one year
  • Standard customers: review period capped at five years
  • Trigger-based updates: required when the firm becomes aware of a relevant new fact or change in circumstances — regardless of scheduled review timing

Country-risk movement is treated as a textbook trigger in this model. FATF grey-listing of a jurisdiction is a new risk fact; it has to reach the affected customer profiles without a pause for the next diary review. Iraq and Bosnia-Herzegovina were added in the FATF June 2026 grey list update, which is a working specimen of the external events Guideline 1 expects firms to turn into process.

The words "relevant new fact" were left wide on purpose. A shift in business activity, a new beneficial-ownership structure, an adverse-media hit, an anomalous transaction pattern — any of those can count as a trigger. The compliance function needs a documented method for spotting them and acting on them.

A large share of firms still keep static customer records and review them only on a calendar. That arrangement does not meet Guideline 1 under AMLA's framework. Event-driven, real-time due diligence is the market name for the alternative: perpetual KYC. The operational and commercial reasons for adopting it are now tied to the regulatory ones.

Guideline 1 and the AMLA CDD technical standards have to be read as a pair. What identity data must be gathered at onboarding is set by the CDD RTS. How often that data is refreshed, and on what facts a refresh is forced, is set by Guideline 1. The full lifecycle duty for customer identity is the two of them together.

Guideline 2: Transaction and Activity Monitoring

Transactions and customer activity across the life of the relationship are the second guideline's subject.

AMLA's draft names no transaction-velocity thresholds, no value caps, and no behavioural-analytics models. What it does set is a structural duty: obliged entities have to run a monitoring framework that can pick up patterns that do not match the customer's known profile and push those inconsistencies into review.

The framework has to contain these pieces:

  • Baseline establishment: the firm must maintain an understanding of the customer's expected behavior — transaction types, volumes, frequencies, counterparties
  • Deviation detection: unusual activity relative to that baseline triggers review
  • Escalation pathway: anomalies must reach the appropriate level of the compliance function within a defined timeframe
  • Documentation: monitoring logic, thresholds, and escalation records must be auditable

Process neutrality is the design choice. AMLA does not mandate a particular transaction-monitoring product. It does mandate that whatever sits in place can show those four elements in a form a supervisor could check.

Who Is Newly Covered

The ongoing monitoring guidelines reach every obliged entity under the AMLR. That net includes sectors that never faced EU-level AML monitoring at this degree of formality.

AMLA singled out these newly covered types:

  • Crowdfunding service providers
  • Investment migration operators
  • Football clubs and agents
  • Credit intermediaries
  • Non-financial mixed-activity holding companies
  • Certain crypto-asset service providers
  • Traders in high-value goods

For firms in sectors newly obliged under the AMLR, the consultation carries extra urgency. They have not had to design transaction-monitoring frameworks at this level of formality before. The July 2 public hearing is still a chance to test AMLA's reading before the text is locked.

Crypto-asset service providers sit under a stacked duty. The MiCA Travel Rule requirements from 1 July 2026 govern how transaction data moves between CASPs. What has to happen inside the firm after that data arrives is governed by AMLA's ongoing monitoring guidelines. Both apply at once.

The Architecture Gap This Exposes

Verification and monitoring are not the same job. That structural split is what the guidelines bring into the open, and a large number of compliance teams have not closed it yet.

Verification happens in episodes. A customer sends a document. A system reviews it. A decision is taken. The episode has a beginning and an end.

Monitoring does not stop. Onboarding does not close the relationship. Transactions keep arriving. Circumstances shift. Fresh risks appear. Article 26 of the AMLR requires obliged entities to follow that relationship across its whole span — not only the moment it started.

Most legacy KYC stacks were built for verification. They take documents, run checks, and emit a pass or a fail. They were not built to hold a living risk profile that refreshes on trigger events, marks anomalous patterns, and escalates findings on its own.

That is the architecture gap the guidelines will put on display. A firm that clears the CDD check at onboarding but cannot show an ongoing-monitoring capability is not compliant with Article 26. The guidelines say so in terms.

The move from a single verification event to continuous, intelligence-driven monitoring is no longer a slide-deck ambition. It is a regulatory requirement. Joinble's AI Agents are built on that operating model: they watch customer relationships without a pause, pick up changes in real time, and escalate anomalies without waiting for the next scheduled review cycle.

What Compliance Teams Should Do Now

The consultation shuts on 3 September 2026. Final guidelines arrive in Q4 2026. The AMLR applies in full from 10 July 2027. That leaves approximately 13 months between the finished text and full compliance — a span that sounds generous and is not.

Audit your current customer data maintenance process. Write down how often customer information is reviewed, which events force an unscheduled review, and whether those events are watched by automation or by people.

Map your transaction monitoring coverage. List the customer types, transaction channels, and business lines that existing monitoring logic already covers. Put the gaps on paper.

Assess your escalation pathway. Which roles receive anomaly alerts? Inside what window? Are those pathways written in a form a supervisor could inspect?

Respond to the consultation. AMLA is actively asking newly obliged entities for comments. If the firm sits in one of the listed categories, taking part is a chance to influence the finished wording and a visible signal to supervisors that the organisation is engaged.

Begin infrastructure conversations now. If the current system cannot support trigger-based customer-data updates and documented escalation paths, vendor talks should start before the guidelines are final — not after.

Sweden's Finansinspektionen made the price of these gaps concrete on 17 June 2026, when it fined Ikano Bank SEK 140 million for the same structural failures: customer records left uncurrent, regulatory typology guidance never turned into controls, and EDD fields missing across the book. The Ikano Bank AML fine is now an enforcement reference for the failures AMLA's guidelines are written to stop.

FAQ

What are AMLA's ongoing monitoring guidelines? A draft issued June 3, 2026 under Article 26(5) of the AMLR. The text sets out how obliged entities have to keep customer information current and how they have to watch transactions across the life of the business relationship. The finished guidelines are expected in Q4 2026.

When do the guidelines apply? The AMLR applies from 10 July 2027. Gap assessment and infrastructure planning should start at once, given the approximately 13-month span expected between the finished guidelines and full application.

Who is covered? Every entity obliged under the AMLR: banks, payment institutions, crypto-asset service providers, crowdfunding platforms, investment migration operators, football clubs, credit intermediaries, and traders in high-value goods.

What does Guideline 1 require? Customer information has to stay current on a risk-based timetable — a one-year maximum for high-risk customers, a five-year maximum for standard customers — plus trigger-based updates as soon as a relevant change in circumstances arises.

What does Guideline 2 require? A framework for monitoring transactions and activity that includes a documented customer baseline, detection of deviations, a defined escalation pathway, and records a supervisor can audit.

Can firms use manual monitoring processes? Yes. Technological neutrality is the stance of AMLA's guidelines. Manual, automated, and semi-automated methods are all allowed. A purely manual process is, however, unlikely to meet the continuous and trigger-based character of the duty at scale for most obliged entities.

Emily CarterEmily Carter
Share

Related Articles

iGaming KYC Under AMLR: The 2027 Compliance Wake-Up
Compliance07 Sep, 2026

iGaming KYC Under AMLR: The 2027 Compliance Wake-Up

The EU AMLR's €2,000 gambling threshold takes effect July 2027. Deepfake attacks in iGaming surged 700% in 2026. Here's what operators must do now.

EU AI Act Article 50: Deepfake Rules Live—KYC Impact
Compliance03 Sep, 2026

EU AI Act Article 50: Deepfake Rules Live—KYC Impact

EU AI Act Article 50 entered force on 2 August 2026. Here's what the deepfake disclosure mandate means for KYC compliance and fraud defence.

DORA and KYC: Identity Vendors Are Now ICT Third Parties
Compliance31 Aug, 2026

DORA and KYC: Identity Vendors Are Now ICT Third Parties

DORA's ICT third-party rules apply to KYC vendors from 2025. Here's what financial firms must audit, contract, and monitor to stay compliant in 2026.