Anti-money laundering and counter-terrorism financing (AML/CTF) compliance does not end once you complete the initial Know Your Customer (KYC) check. For all Australian Tranche 2 entities—lawyers, accountants, real estate agents, conveyancers, TCSPs, precious metals dealers, and virtual asset service providers (VASPs)—ongoing customer monitoring is a continuous legal obligation.

Under Part A of your written AML/CTF Program, you must establish and maintain a transaction monitoring program designed to identify unusual or suspicious activity throughout the life of your relationship with a client. This guide outlines the best practices for implementing ongoing customer monitoring, identifying risk triggers, and executing periodic reviews.

What is Ongoing Customer Monitoring?

Ongoing customer monitoring (also referred to as ongoing Customer Due Diligence, or ongoing CDD) is the process of reviewing your clients' transactions and behaviour over time. The objective is to ensure that their activities remain consistent with your initial assessment of their business profile, source of wealth, and risk rating.

If a client's transaction patterns change suddenly or without a clear commercial explanation, your monitoring system must flag this activity for review, enabling your Compliance Officer to determine whether a Suspicious Matter Report (SMR) must be submitted to AUSTRAC.

Transaction Monitoring in Practice

A compliant transaction monitoring program does not require you to manually review every single email or invoice. Instead, you should implement a risk-based system that monitors for:

Periodic Reviews of Customer Info

You must establish a structured schedule for reviewing and updating your clients' KYC information. The frequency of these reviews should be based on the client's risk rating:

  1. High-Risk Clients (e.g., PEPs): Review and update KYC information and beneficial ownership details at least once every 12 months.
  2. Medium-Risk Clients: Review and update information every 2 to 3 years.
  3. Low-Risk Clients: Review at trigger events, or every 3 to 5 years.

Trigger Events: A trigger event is any change in the client's circumstances that increases their risk profile. Examples include a change in the company's beneficial ownership, a change in the nature of their business, or the client becoming a Politically Exposed Person (PEP).

When is Re-Verification Required?

You must re-verify a client's identity (essentially running the KYC process again) if:

Warning: If a client's passport or driver's licence has expired, you do not automatically need to re-verify their identity, provided their identity was verified when the document was current. However, if they conduct a new transaction under a trigger event, you must obtain and verify a current ID document.

Common Red Flags by Sector

Staff should monitor for sector-specific red flags:

Automate Your Ongoing Customer Monitoring

CompliDesk automatically screens your client database daily against PEP and sanctions lists, logs periodic reviews, and flags risk triggers. Sign up free today.

Get Started Free

Frequently Asked Questions

Is ongoing customer monitoring mandatory for all Tranche 2 entities?
Yes. Under Part A of the AML/CTF Program, all reporting entities must implement a transaction monitoring program and conduct ongoing customer due diligence. Compliance is not a one-off onboarding task.
What is the difference between transaction monitoring and ongoing CDD?
Transaction monitoring focuses on detecting unusual transaction patterns or activities. Ongoing CDD focuses on ensuring the client's structural information (like beneficial ownership, directors, and risk rating) remains accurate and up to date. Both are required.
How do I document ongoing monitoring to satisfy AUSTRAC requirements?
You must maintain a written record of all monitoring activities. This includes logging when periodic reviews were conducted, documenting the outcome of those reviews, and recording the reasons why any flagged transaction was or was not escalated to an SMR. All records must be kept for 7 years.

Related reading: Ongoing customer due diligence · AML risk assessment guide · Managing AML compliance for multiple clients · Frequently asked questions