Back to Articles
Thought Leadership5 min read

AMLA’s Monitoring Consultation Has Closed. Keep the Review Calendar.

AMLA’s consultation on draft ongoing monitoring guidelines closed on 3 September 2026. For management companies and TCSPs, the practical task is to run periodic and event-driven reviews side by side, reuse evidence that is still valid and write down when a review date may move.

Fredrik Gröndahl
A metal flip calendar beside a long row of upright cream cards on a stone table, with one orange card at the front

On 3 September 2026, the consultation on the Anti-Money Laundering Authority’s draft guidelines on ongoing monitoring of business relationships closed. AMLA opened it on 3 June, held a public hearing on 2 July and has said it will issue final guidelines in the fourth quarter of 2026. Until then, the text remains a draft.

The guidelines are developed under Article 26(5) of the Anti-Money Laundering Regulation. They cover two duties: keeping customer information up to date, and monitoring transactions and activity. This article focuses on the first, because it is where management companies, fund administrators and trust and company service providers carry the most manual work.

Two kinds of review, one customer file

The draft describes keeping information current through periodic reviews and event-driven reviews, both applied on a risk-based approach. It would be easy to read that as a choice. It is better read as two controls that cover different failures.

Consider a hypothetical fund structure reviewed every three years. Eight months after its last review, a new controlling shareholder appears in a registry filing. An event-driven review catches the change. The periodic review then catches what no single event reveals: a business activity that drifted slowly, or a source of wealth explanation that no longer matches the relationship.

The draft lists the kinds of change that should prompt a review, including changes in identity, ownership or legal status, unusual behaviour or transactions, adverse media or a change in politically exposed person status, and changes in financial situation or business activity. A firm that relies only on those signals depends on every one of them reaching the file. A firm that relies only on the calendar will learn about most of them late.

A row of scheduled cream cards with one orange card inserted midway, showing an event-driven review within a periodic schedule
A row of scheduled cream cards with one orange card inserted midway, showing an event-driven review within a periodic schedule

Write down what an event review does to the date

The practical question every team will face is simple: when an event-driven review is completed, does the next periodic review date move? Published summaries of the draft do not describe a rule for this, and firms should not wait for the final text to decide.

There are defensible answers either way. A full review triggered by an ownership change may cover everything a periodic review would, which could justify resetting the clock. A narrow review of one adverse media hit covers far less, and moving the date would leave the rest of the file older than the schedule suggests.

The policy should therefore tie any change to the scope of the review actually performed. Record which parts of the file were refreshed, who approved moving the date and why. A supervisor reading the file later should be able to see that the calendar moved because the evidence moved with it, not because a review was convenient to close.

Reuse what is still valid

The draft points towards a risk-based view of document refresh rather than automatic re-collection when a document expires. It asks firms to consider the customer’s risk level, the risk of the issuing country and whether the updated document is relevant. It also recognises several ways to obtain current information, including official registers, commercial and open sources, confirmation from the customer and information from other obliged entities.

For a firm with hundreds of client entities, that matters. Asking every customer to resubmit a full pack at each review creates delay and fatigue without improving the file. A review that confirms which items remain accurate, refreshes only what changed and records the source used for each is both faster and easier to defend.

Reuse needs discipline. Each retained item should show when it was last confirmed and against what. Evidence that was never verified at the start does not become reliable because it has been carried forward three times.

A folder of retained cream cards secured with a brass clip, with a fresh card added on top and two outdated cards set aside
A folder of retained cream cards secured with a brass clip, with a fresh card added on top and two outdated cards set aside

Proportionate does not mean optional

The draft allows firms to adjust review intensity for low-risk customers where there is no new activity. That is a useful allowance for dormant or simple relationships. It is not permission to stop reviewing them. The lighter review still needs a date, an owner and a record of what was checked.

For transaction and activity monitoring, commentary on the draft notes that non-financial firms may use proportionate alternative measures, such as structured assessments of customer behaviour, and that monitoring frameworks should be explainable, tested and documented. The same expectations are a sensible standard for the review calendar itself.

What to do before the final text

The AMLR applies from 10 July 2027, and the final guidelines are expected well before then. That leaves time to prepare without guessing at wording that may still change. Four steps hold up under most plausible outcomes:

  • List the events that trigger a review for each customer type, and the source expected to reveal each one.
  • Set a written rule for when an event-driven review may move the periodic date, linked to its scope.
  • Record, for every retained document or data point, when it was last confirmed and how.
  • Define what a lighter review of a low-risk, inactive relationship must still contain.

Fidify’s earlier analysis of perpetual KYC readiness argued that continuous monitoring depends on structured customer data. AMLA’s draft points the same way, while keeping the periodic review in place. Firms that treat the calendar and the triggers as one system will be ready for whichever final wording arrives.

Sources and further reading

Anti-Money Laundering Authority, AMLA consults on draft Guidelines for ongoing monitoring of business relationships, consultation open 3 June to 3 September 2026. The guidelines remain draft; final guidelines are expected in Q4 2026.

CMS, AMLA publishes draft guidelines on ongoing monitoring under Article 26(5) AMLR, 10 August 2026.

Related Fidify analysis: Perpetual KYC: What It Means and Whether Your Firm Is Ready.