Anti-money laundering and counter-terrorism financing (AML/CTF) compliance does not end once you complete the initial Know Your Customer (KYC) check. For all Australian Tranche 2 entities—lawyers, accountants, real estate agents, conveyancers, TCSPs, precious metals dealers, and virtual asset service providers (VASPs)—ongoing customer monitoring is a continuous legal obligation.
Under Part A of your written AML/CTF Program, you must establish and maintain a transaction monitoring program designed to identify unusual or suspicious activity throughout the life of your relationship with a client. This guide outlines the best practices for implementing ongoing customer monitoring, identifying risk triggers, and executing periodic reviews.
What is Ongoing Customer Monitoring?
Ongoing customer monitoring (also referred to as ongoing Customer Due Diligence, or ongoing CDD) is the process of reviewing your clients' transactions and behaviour over time. The objective is to ensure that their activities remain consistent with your initial assessment of their business profile, source of wealth, and risk rating.
If a client's transaction patterns change suddenly or without a clear commercial explanation, your monitoring system must flag this activity for review, enabling your Compliance Officer to determine whether a Suspicious Matter Report (SMR) must be submitted to AUSTRAC.
Transaction Monitoring in Practice
A compliant transaction monitoring program does not require you to manually review every single email or invoice. Instead, you should implement a risk-based system that monitors for:
- Transactions that are unusually large or complex compared to the client's typical activity.
- Transactions involving high-risk jurisdictions, tax havens, or countries subject to sanctions.
- **Structuring:** Multiple transactions conducted just below reporting thresholds (such as cash deposits or transfers just under $10,000).
- Unexplained third-party payments made on behalf of the client.
Periodic Reviews of Customer Info
You must establish a structured schedule for reviewing and updating your clients' KYC information. The frequency of these reviews should be based on the client's risk rating:
- High-Risk Clients (e.g., PEPs): Review and update KYC information and beneficial ownership details at least once every 12 months.
- Medium-Risk Clients: Review and update information every 2 to 3 years.
- Low-Risk Clients: Review at trigger events, or every 3 to 5 years.
Trigger Events: A trigger event is any change in the client's circumstances that increases their risk profile. Examples include a change in the company's beneficial ownership, a change in the nature of their business, or the client becoming a Politically Exposed Person (PEP).
When is Re-Verification Required?
You must re-verify a client's identity (essentially running the KYC process again) if:
- You suspect that the client's existing identity information is inaccurate or out of date.
- A material trigger event occurs (such as a company restructure that introduces new beneficial owners).
- You form a suspicion of money laundering or terrorism financing.
Warning: If a client's passport or driver's licence has expired, you do not automatically need to re-verify their identity, provided their identity was verified when the document was current. However, if they conduct a new transaction under a trigger event, you must obtain and verify a current ID document.
Common Red Flags by Sector
Staff should monitor for sector-specific red flags:
- Legal: Sudden requests to change the settlement destination of trust funds, or the introduction of anonymous third-party funders.
- Real Estate: Buyers requesting to purchase property in the name of a third party without a clear legal relationship.
- Accounting: A client's business receiving large loans from unknown offshore entities.
- Precious Metals: A customer repeatedly buying gold using cash amounts of $9,500 to avoid the $10,000 reporting threshold.
- VASPs: A user suddenly transferring large volumes of digital assets to private wallets immediately after onboarding.
Automate Your Ongoing Customer Monitoring
CompliDesk automatically screens your client database daily against PEP and sanctions lists, logs periodic reviews, and flags risk triggers. Sign up free today.
Get Started FreeFrequently Asked Questions
Related reading: Ongoing customer due diligence · AML risk assessment guide · Managing AML compliance for multiple clients · Frequently asked questions