Ongoing Monitoring
Ongoing monitoring is the practice of continuously reviewing information about a customer, provider, or third party over time, rather than checking it only once at the start of a relationship. The goal is to catch changes in risk or compliance status as they emerge and respond to them. The specific meaning and requirements vary considerably depending on the field and jurisdiction in which the term is used.
Ongoing monitoring refers to the continuous or routine assessment of an entity's data, activity, and compliance status throughout the duration of a relationship, in contrast to point-in-time onboarding or initial due diligence. In anti-money laundering (AML) and know-your-customer (KYC) contexts, it typically involves the periodic review of client information and the assessment of customers and their transactions for indicators of criminal activity such as money laundering or terrorist financing; in some jurisdictions this is a regulatory obligation (for example, as described in FINTRAC/CANAFE guidance in Canada). The term is also applied in third-party/vendor risk management to the continuous identification, assessment, and management of risks arising from external parties, and in provider/payer compliance contexts to the sustained review of provider data against regulatory and contractual requirements. Note that the evidence provided covers AML/KYC, third-party risk, and provider compliance uses; it does not establish a definition specific to AI governance or model risk management, where analogous concepts (such as ongoing model monitoring) exist but are governed by different frameworks and terminology not addressed in these sources.
Why it matters
Risk is not static. An entity that presents an acceptable risk profile at onboarding—a customer, a vendor, or a service provider—can change materially over the life of a relationship, whether through new ownership, changed behavior, regulatory action, or evolving transaction patterns. Ongoing monitoring exists because point-in-time due diligence captures only a single snapshot; without sustained review, an organization can remain exposed to risks that emerged after the initial assessment but were never detected. As the source material indicates, this is why ongoing monitoring is treated as a regulatory process within AML compliance regimes and as an essential practice in third-party risk management.
The stakes and the specific obligations differ substantially by context. In AML and KYC settings, ongoing monitoring supports the detection of indicators of criminal activity such as money laundering or terrorist financing, and in some jurisdictions it is a regulatory obligation—FINTRAC/CANAFE guidance in Canada, for example, describes it as a process that reporting entities must develop and use. In third-party and vendor risk management, it supports the continuous identification and management of risks arising from external parties. In provider and payer compliance, it supports sustained alignment of provider data with regulatory and contractual requirements. Because the underlying frameworks and legal requirements are distinct, professionals should be careful not to assume that the obligations from one domain transfer to another.
It is worth noting a scope limitation relevant to readers in AI governance and model risk management: the evidence for this entry concerns AML/KYC, third-party risk, and provider compliance uses. Analogous concepts—such as ongoing model monitoring for performance degradation or drift—exist in model risk practice but are governed by different frameworks and terminology and should not be conflated with the compliance-focused usage described here. Ongoing monitoring, in any of these contexts, reduces and manages exposure to emerging risk; it does not eliminate it.
Who it's relevant to
Inside Ongoing Monitoring
Common questions
Answers to the questions practitioners most commonly ask about Ongoing Monitoring.