Ongoing Monitoring: Why Perpetual KYC Beats the Remediation Cycle
Ongoing KYC monitoring vs. one-time checks: why continuous oversight prevents costly compliance gaps and regulatory penalties.

Ongoing Monitoring: Why Perpetual KYC Beats the Remediation Cycle
A client approved at onboarding is not a fixed fact. Ownership changes, sanctions lists move, adverse media appears, and a low-risk investor can become a high-risk one without any of that showing up in a file that was last touched two years ago. Ongoing monitoring AML programmes exist precisely because point-in-time KYC checks describe a customer at a single moment, and that moment expires the day it is captured.
For Heads of Compliance, MLROs and COOs at asset managers, this is not a theoretical problem. It is the gap between passing a regulatory exam on paper and actually knowing who your investors and counterparties are today. This article sets out what ongoing monitoring means in practice, how supervisory expectations have shifted, and why firms that let monitoring lapse end up paying for it twice: once in the cost of the remediation exercise, and once in the credibility they lose with their regulator.
What Has Changed From the Regulators
The direction of travel across FATF-aligned regimes is consistent: continuous, risk-based ongoing due diligence, not a fixed periodic refresh cycle. FATF's standards on customer due diligence require firms to conduct ongoing due diligence on the business relationship, scrutinise activity throughout the relationship, and keep customer information up to date, with the intensity of that monitoring scaled to risk. That baseline has not changed. What has shifted is how supervisors interpret and enforce it.
In the UK, the Money Laundering Regulations require firms to apply ongoing monitoring as a core part of customer due diligence, not an optional extra layered on top of onboarding. The FCA's supervisory focus has increasingly moved towards whether firms can demonstrate that monitoring is genuinely risk-sensitive and event-driven, rather than whether a firm can point to a review that technically happened on schedule. A file refreshed on time but blind to a sanctions designation that landed six months earlier does not satisfy a risk-based approach; it satisfies a calendar.
Across the EU, the direction is similar. Successive anti-money laundering directives have reinforced ongoing due diligence obligations, and the creation of a dedicated EU-level anti-money laundering authority, AMLA, established under Regulation (EU) 2024/1620 and based in Frankfurt, points towards more consistent AML standards across member states. AMLA began operating in 2025 and will start directly supervising a small group of around 40 higher-risk financial institutions operating across borders from 2028. Most firms, including the asset managers, AIFMs and fund administrators this affects, will remain under their national supervisors, but under a single EU rulebook designed to close the gaps between member states that have allowed standards, including on ongoing monitoring, to drift.
The practical upshot for asset managers, AIFMs, private credit funds and fund administrators is this: a periodic review policy that only refreshes files every one, two or three years, with no mechanism to catch changes in between, is increasingly hard to defend as genuinely risk-based. Supervisors are asking firms to show that their monitoring would catch a change the day it happens, not the day the file is next scheduled to be opened.
The Remediation Trap: Why Monitoring Lapses Cost More Than They Save
This is where the real cost of weak ongoing monitoring shows up, and it rarely shows up gradually. It shows up all at once, in the form of a back-book AML remediation exercise.
Remediation happens when a firm, a regulator, an auditor or an acquirer discovers that a population of existing customer files has fallen behind: reviews overdue, screening not refreshed against current lists, risk ratings that no longer reflect reality. At that point the firm cannot simply pick up monitoring going forward; it has to go back and reconstruct current knowledge across every affected file, often hundreds or thousands of them, under time pressure and often under a regulator's or investor's watch.
A remediation exercise is expensive in ways a periodic review budget never accounts for. It requires temporary staff or a third-party remediation vendor, senior compliance time diverted from everything else, and a project structure to track and evidence progress, often reported to the regulator on a schedule the firm does not control. Investor relationships suffer too: institutional LPs, banks and depositaries that receive a sudden wave of document requests during a remediation drive read it correctly, as a sign that ongoing due diligence was not actually ongoing. That is a harder story to tell a fund-of-funds or a family office than a smooth annual refresh would have been.
Firms tend to treat remediation as a one-off, unfortunate event. It is better understood as the predictable output of a monitoring gap left open long enough. Compliance teams have a name for what happens when the same population of files falls behind again a few years after the last clean-up, because the underlying process, periodic and manual, has not changed: perpetual remediation. Continuous monitoring breaks that cycle because it removes the gap that remediation exists to close. A change in a customer's status is caught and reviewed near the point it occurs, so there is no accumulated backlog waiting to become someone else's expensive problem.
Set against the cost of a remediation project, spread across a back book that has quietly gone stale, continuous monitoring is the cheaper and lower-risk path by a wide margin. It converts an unpredictable, disruptive, all-at-once cost into a steady, absorbable operating one.
Continuous Monitoring as the Way Out of the Remediation Cycle
The firms that avoid the remediation trap are the ones that stopped treating KYC refresh as a scheduled event and started treating it as a continuous state. That requires monitoring that runs in the background of the relationship: automatic re-screening against sanctions, PEP and adverse media data as those lists change, not just when a review falls due, and a way of surfacing a genuine change of circumstances, a new UBO, a changed structure, a fresh adverse media hit, as it happens rather than at the next scheduled checkpoint.
This is the model behind Steward's platform: onboarding is the start of the relationship with a customer's KYC file, not the end of it. Once onboarding completes, Steward keeps monitoring, re-screening against sanctions, PEP and adverse media data as it updates, and flags a change of circumstances for review rather than waiting for the next periodic date to roll around. Continuous monitoring changes what reaches the analyst and when, not who decides.
If your firm is still running KYC refresh on a fixed calendar, Steward scales with the size of the book you need to keep current, and the team can walk through what continuous monitoring would look like on your book. Book a demo to see it against your own file population.
Related Insights

The AML AI Readiness Gap in North America
North American firms allocate funds to AI for AML, yet 54% use 8-10 fragmented systems. Why AI adoption isn't the same as operational readiness.

AML Red Flags for Payroll and Annex 1 Firm
Identify AML red flags in payroll and Annex 1 firms: understand sector-specific risks, connect anomalies to customer context, and build effective controls.

How to Set Up AML Controls for a UK Business
A practical operating model for building AML controls that work across payroll and Annex 1 businesses