AMLA Consults on Guidelines for the Ongoing Monitoring of Business Relationships – What You Should Expect

AMLA konsultiert Leitlinien zur laufenden Überwachung von Geschäftsbeziehungen – Was auf Verpflichtete zukommt AMLA Consults on Guidelines for the Ongoing Monitoring of Business Relationships – What You Should Expect

On 3 June 2026, the European Anti-Money Laundering Authority (AMLA) launched a public consultation on its draft guidelines concerning the ongoing monitoring of business relationships. The consultation will run until 3 September 2026, with the final guidelines expected to be published in Q4 2026.

At first glance, this may appear to be yet another technical component of the new European AML package. In reality, however, the consultation addresses one of the core pillars of anti-money laundering compliance: how obliged entities are expected to monitor customer relationships after onboarding.

Ongoing Monitoring Becomes a Central Element of the AMLR

The draft guidelines are based on Article 26(5) AMLR, which requires AMLA to develop guidelines on the ongoing monitoring of business relationships and the monitoring of transactions conducted within those relationships.

Ongoing monitoring is already a fundamental obligation under existing AML frameworks. The AMLR, however, elevates this principle to a new level. Obliged entities are expected not only to assess individual transactions but to continuously analyse and evaluate the entire business relationship. AMLA explicitly describes ongoing monitoring as a cornerstone of the risk-based approach. Importantly, this risk-based approach is grounded in a clear operational foundation: the Business-Wide Risk Assessment (BWRA). It is not merely a formal compliance document but the explicit starting point for determining the calibration and intensity of all monitoring measures.

AMLA Consults on Guidelines for the Ongoing Monitoring of Business Relationships – What You Should Expect 1

More Than Transaction Monitoring

One particularly noteworthy aspect of the draft guidelines is that AMLA does not limit ongoing monitoring to traditional transaction monitoring. Deliberately, the guidelines refer to “activities” alongside “transactions” in recognition of the diversity of business models where not every relevant risk indicator arises from a transaction in the conventional sense.

Under the draft guidelines, obliged entities should continuously assess whether the business relationship remains consistent with the customer’s known profile, whether transactions and activities align with the customer information obtained, whether risk factors have changed, whether customer information remains current and plausible, and whether there are indications of unusual or suspicious activities.

In addition, monitoring measures should be capable of identifying risks related to the circumvention of targeted financial sanctions where such risks can reasonably be detected within the business relationship.

For practical implementation purposes, the guidelines distinguish between three monitoring layers:

  • Pre-Transaction Monitoring, focusing on assessments before a transaction is executed;
  • Real-Time Monitoring, conducted at the point of transaction execution; and
  • Post-Transaction Monitoring, aimed at pattern detection and behavioural analysis after a transaction has taken place.

The relevance of each monitoring layer depends on the role of the obliged entity, its business model and its actual access to transaction data.

The message is clear: customer monitoring is not a one-off onboarding exercise. The quality of ongoing customer monitoring is becoming a supervisory focus in its own right.

Particular Relevance for FinTechs and Payment Service Providers

For payment institutions, electronic money institutions and other FinTech firms, the consultation is likely to be of particular significance. Many of these business models rely heavily on digital processes and high levels of automation. The AMLA guidelines set out concrete expectations regarding the design of monitoring systems and the application of risk-based criteria in the monitoring of customer relationships.

Obliged entities will need to consider whether their existing monitoring scenarios are sufficiently customer-focused and dynamic, or whether they still largely rely on static KYC information obtained during onboarding. Are changes in customer behaviour systematically identified? Are customer records updated on a regular basis? And can thresholds, scenario logic and model decisions be explained and documented in a manner that is understandable to supervisors?

This issue is particularly relevant for automated and AI-supported monitoring tools. AMLA requires that outputs generated by such systems be explainable and verifiable. Obliged entities remain accountable for monitoring decisions and cannot simply rely on algorithmic outcomes. The same principle applies to third-party monitoring solutions: default settings should not be adopted without appropriate validation. Furthermore, where an obliged entity lacks sufficient understanding of how an external system operates, it should not rely on that tool for material monitoring decisions.

In highly digitalised business models, supervisors are likely to expect a more holistic analysis of customer, risk and transaction data.

A Unified Approach Across Financial and Non-Financial Sectors

Another notable feature is AMLA’s decision to adopt a cross-sectoral approach and to refrain from introducing sector-specific supplementary modules. The core principles are intended to apply equally to financial institutions and obliged entities in the non-financial sector.

AMLA emphasises the importance of practical applicability across all categories of obliged entities and expressly clarifies that proportionality does not mean lower standards. Smaller entities or those with less complex business models may rely on manual or semi-automated processes, provided those processes are effective in practice. The required level of protection must be maintained in all cases.

This horizontal approach also has practical implications for governance and documentation requirements. Obliged entities are expected to document the governance of their monitoring measures, including decision-making rationales, identified limitations and applied mitigation measures, within their internal policies and procedures.

The draft guidelines further require regular staff training. Employees involved in monitoring activities should be capable of critically assessing monitoring outcomes and escalating relevant risk indicators through established escalation channels.

Consultation as an Opportunity for the Industry

The consultation provides institutions and industry associations with an opportunity to influence future requirements at an early stage.

Particularly relevant issues are likely to include proportionality, technical feasibility and the distinction between ongoing monitoring, periodic reviews and traditional customer due diligence measures.

Certain topics remain unresolved. One example concerns the precise requirements for updating expired identification documents. The draft guidelines adopt a risk-based approach that does not require automatic re-collection of documents but instead calls for a documented assessment of the circumstances.

A similar approach applies to the newly introduced intermediate measure for situations involving missing customer information. Before terminating a business relationship, obliged entities may, under narrowly defined conditions, temporarily suspend or restrict transactions. This may prove to be a valuable option in practice, although it is subject to clearly defined requirements.

As the guidelines are likely to become a key reference point for supervisory interpretations of Article 26 AMLR, affected institutions should closely monitor the consultation process.

Ongoing Monitoring Will Become a Key AMLR Compliance Benchmark

Through its draft guidelines on ongoing monitoring, AMLA is providing further clarity on one of the central building blocks of the new European AML framework.

The message is straightforward: anti-money laundering compliance does not end at onboarding. Going forward, the continuous monitoring of the entire business relationship will play an even more prominent role. This extends beyond transaction monitoring and encompasses an integrated framework of customer profiling, behavioural analysis, technology governance and continuous review.

For FinTechs, payment service providers and other obliged entities, now is the right time to critically assess existing monitoring frameworks. AMLA’s guidelines are likely to become one of the most important reference documents for the practical design of monitoring and compliance systems under the AMLR.



By continuing, you accept our privacy policy.
You May Also Like
Neues Listungspaket und 21. EU-Sanktionspaket gegen Russland: Auswirkungen auf den Finanzsektor EU expands Russia sanctions lists and prepares 21st sanctions package
Read More

EU expands Russia sanctions lists and prepares 21st sanctions package

The EU's listing package of 15 June 2026 and the proposed 21st sanctions package significantly expand sanctions against Russia. Financial institutions will increasingly need to address indirect risks, third-country involvement and complex payment structures within their sanctions compliance frameworks.
Read More
Aktuelles rund um die Geldwäscheprävention im Fußballbereich Recent Developments on Anti-Money Laundering Compliance in the Football Sector
Read More

Recent Developments on Anti-Money Laundering Compliance in the Football Sector

Anti-money laundering compliance in professional football is no longer a future issue. Recent investigations involving a football club, growing EU regulation and new AMLA guidance underline the importance of preparing governance and compliance frameworks well ahead of the AMLR's entry into force.
Read More
Turbo-Zertifikate mit Beißkorb Turbo Certificates on a Leash
Read More

Turbo Certificates on a Leash

On 16 June 2026, BaFin’s general administrative order restricting the marketing, distribution and sale of turbo certificates enters into force. It establishes strict requirements for all distribution activities relating to turbo certificates directed at retail investors.
Read More