Skip to main content
Category: Monitoring & Drift

Ongoing Monitoring

Also known as: Continuous Monitoring, Continuous Review
Simply put

Ongoing monitoring is the practice of continuously reviewing information about a customer, provider, or third party over time, rather than checking it only once at the start of a relationship. The goal is to catch changes in risk or compliance status as they emerge and respond to them. The specific meaning and requirements vary considerably depending on the field and jurisdiction in which the term is used.

Formal definition

Ongoing monitoring refers to the continuous or routine assessment of an entity's data, activity, and compliance status throughout the duration of a relationship, in contrast to point-in-time onboarding or initial due diligence. In anti-money laundering (AML) and know-your-customer (KYC) contexts, it typically involves the periodic review of client information and the assessment of customers and their transactions for indicators of criminal activity such as money laundering or terrorist financing; in some jurisdictions this is a regulatory obligation (for example, as described in FINTRAC/CANAFE guidance in Canada). The term is also applied in third-party/vendor risk management to the continuous identification, assessment, and management of risks arising from external parties, and in provider/payer compliance contexts to the sustained review of provider data against regulatory and contractual requirements. Note that the evidence provided covers AML/KYC, third-party risk, and provider compliance uses; it does not establish a definition specific to AI governance or model risk management, where analogous concepts (such as ongoing model monitoring) exist but are governed by different frameworks and terminology not addressed in these sources.

Why it matters

Risk is not static. An entity that presents an acceptable risk profile at onboarding—a customer, a vendor, or a service provider—can change materially over the life of a relationship, whether through new ownership, changed behavior, regulatory action, or evolving transaction patterns. Ongoing monitoring exists because point-in-time due diligence captures only a single snapshot; without sustained review, an organization can remain exposed to risks that emerged after the initial assessment but were never detected. As the source material indicates, this is why ongoing monitoring is treated as a regulatory process within AML compliance regimes and as an essential practice in third-party risk management.

The stakes and the specific obligations differ substantially by context. In AML and KYC settings, ongoing monitoring supports the detection of indicators of criminal activity such as money laundering or terrorist financing, and in some jurisdictions it is a regulatory obligation—FINTRAC/CANAFE guidance in Canada, for example, describes it as a process that reporting entities must develop and use. In third-party and vendor risk management, it supports the continuous identification and management of risks arising from external parties. In provider and payer compliance, it supports sustained alignment of provider data with regulatory and contractual requirements. Because the underlying frameworks and legal requirements are distinct, professionals should be careful not to assume that the obligations from one domain transfer to another.

It is worth noting a scope limitation relevant to readers in AI governance and model risk management: the evidence for this entry concerns AML/KYC, third-party risk, and provider compliance uses. Analogous concepts—such as ongoing model monitoring for performance degradation or drift—exist in model risk practice but are governed by different frameworks and terminology and should not be conflated with the compliance-focused usage described here. Ongoing monitoring, in any of these contexts, reduces and manages exposure to emerging risk; it does not eliminate it.

Who it's relevant to

AML and KYC compliance officers
Those responsible for anti-money laundering and know-your-customer programs use ongoing monitoring to routinely assess customers and their transactions for indicators of criminal activity such as money laundering or terrorist financing. In some jurisdictions this is a regulatory obligation—for example, as described in FINTRAC/CANAFE guidance in Canada—so the specific requirements should be confirmed against the applicable local regime.
Third-party and vendor risk managers
Professionals managing external relationships apply ongoing monitoring to continuously identify, assess, and manage risks arising from third parties, allowing them to detect and respond to emerging problems throughout the relationship rather than relying only on an initial assessment.
Provider and payer compliance teams
Teams overseeing provider data use ongoing monitoring to sustain the review of that data and compliance status over time, supporting continued alignment with payer and regulatory requirements as circumstances change.
Auditors and second-line reviewers
Those evaluating whether monitoring programs operate as intended benefit from understanding that ongoing monitoring is a recurring, over-time process distinct from point-in-time onboarding due diligence, and that its specific obligations vary by domain and jurisdiction rather than following a single universal standard.

Inside Ongoing Monitoring

Performance monitoring
Ongoing tracking of a model's outputs against expected or benchmarked results to detect deterioration over time. As commonly defined in model risk management, this addresses model performance degradation, which is distinct from model risk itself.
Input and data drift detection
Assessment of whether the distribution of input data or the underlying population has shifted relative to the data on which the model was developed. Such drift can undermine a model's continued validity even when its internal logic is unchanged.
Benchmarking and outcomes analysis
Comparison of model outputs to alternative models, challenger approaches, or realized outcomes to evaluate whether the model continues to perform within acceptable tolerances.
Threshold and trigger definitions
Pre-established limits, tolerances, or escalation criteria that, when breached, prompt review, revalidation, or remediation. These convert monitoring signals into actionable governance decisions.
Governance and accountability linkage
The organizational assignment of who monitors, who reviews results, and who acts on findings. This is where ongoing monitoring intersects with AI governance, though the monitoring activity itself is typically situated within model risk management processes.
Documentation and reporting
Recording of monitoring results, exceptions, and follow-up actions to support internal review, audit by an independent line of defense, and, where applicable, regulatory examination.

Common questions

Answers to the questions practitioners most commonly ask about Ongoing Monitoring.

Is ongoing monitoring the same as revalidating a model?
No. These are distinct activities that professionals frequently blur. Ongoing monitoring typically refers to the routine, often continuous tracking of a model's performance, inputs, outputs, and operating conditions after deployment. Revalidation, by contrast, is a more comprehensive, periodic assessment that reexamines a model's conceptual soundness, assumptions, and fitness for purpose. In many model risk frameworks, monitoring findings can trigger revalidation, but monitoring does not replace it. Treating one as a substitute for the other is a common error.
Does ongoing monitoring only mean checking whether a model's accuracy is still high?
Not exactly. Performance metrics such as accuracy are one component, but ongoing monitoring is generally broader than tracking model performance alone. It commonly includes watching for input data drift, changes in population or usage, stability of outputs, breaches of predefined thresholds, and shifts in the operating environment. It is also important to distinguish model performance degradation, which describes a decline in how well a model performs, from model risk more broadly, which concerns the potential for adverse consequences from model use. Monitoring supports the identification of both, but reducing it to an accuracy check understates its scope.
What kinds of metrics or signals are typically tracked in ongoing monitoring?
Programs commonly track a combination of performance indicators (such as measures of predictive quality), input and data-related signals (such as distributional shift or data quality issues), output stability, and operational indicators (such as processing errors or usage patterns). The specific set depends on the model type, its purpose, and the risk it presents. There is no single universally mandated list of metrics; selection is typically driven by the model's use case and the organization's risk framework.
How are monitoring thresholds and triggers typically set?
Thresholds are generally established in advance so that monitoring results can be compared against defined tolerance levels, with breaches prompting escalation, investigation, or remediation. In many frameworks, thresholds are calibrated to the model's risk rating, materiality, and intended use, and may distinguish warning levels from action levels. Because appropriate thresholds are context-specific and can drift as conditions change, they are typically documented and periodically reviewed rather than fixed permanently.
Who is usually responsible for performing ongoing monitoring?
Responsibilities are often allocated across lines of defense, though the precise arrangement varies by organization. In many structures, model owners or developers in the first line perform or oversee day-to-day monitoring, while an independent function in the second line reviews or challenges monitoring practices and results. Internal audit in the third line may assess whether monitoring is being conducted as intended. These roles should be separated rather than collapsed; the specifics depend on the organization's governance model and are not standardized across all sectors.
How often should ongoing monitoring be conducted?
Frequency is typically driven by the model's risk level, materiality, and how rapidly its inputs or operating environment may change. Some signals may be tracked continuously or in near real time, while others are reviewed on a periodic cadence. Higher-risk or fast-changing models generally warrant more frequent monitoring. There is no single universally required interval; frequency is commonly defined in policy and adjusted based on observed conditions and monitoring results.

Common misconceptions

Ongoing monitoring is the same as periodic revalidation.
The two are related but distinct. Ongoing monitoring is a continuous or recurring surveillance activity that watches for deterioration and triggering conditions, whereas revalidation is a more comprehensive reassessment often prompted by monitoring findings, elapsed time, or material change. Monitoring frequently informs when revalidation is warranted, but it does not replace it.
A model that passes ongoing monitoring is proven to be free of risk.
Monitoring reduces and helps manage model risk; it does not eliminate it. Monitoring can detect that performance has degraded or that inputs have drifted, but residual risk typically remains even where thresholds are met, and monitoring is limited by the metrics, data, and triggers actually implemented.
Ongoing monitoring only measures model performance.
Performance degradation is one focus, but monitoring as commonly framed can also cover data drift, changes in use, control effectiveness, and conditions relevant to model risk more broadly. Treating monitoring as a pure accuracy check narrows its intended scope.

Best practices

Define monitoring metrics, thresholds, and escalation triggers in advance, and document the rationale so that breaches lead to predetermined actions rather than ad hoc judgment.
Distinguish monitoring for performance degradation from monitoring for input and population drift, and track both, since a model can drift without an immediate visible performance drop.
Assign clear accountability for who conducts monitoring, who reviews results, and who acts on findings, keeping monitoring activity separable from independent review consistent with a lines-of-defense structure.
Use monitoring outputs to inform, but not substitute for, decisions about revalidation, recalibration, or model retirement.
Record monitoring results, exceptions, and remediation to create an auditable trail suitable for independent review and, where applicable, regulatory examination.
Scope monitoring to the model's intended use and note its limitations explicitly, recognizing that monitoring reduces and manages risk rather than confirming its absence.