From the annual review to perpetual monitoring

Most compliance frameworks still carry a dangerous assumption baked in from the paper era: that a customer screened clean at onboarding stays clean until their next periodic review — one, three, sometimes four years later.

Most compliance frameworks still carry a dangerous assumption baked in from the paper era: that a customer screened clean at onboarding stays clean until their next periodic review — one, three, sometimes four years later.

Risk doesn’t keep that schedule.

The blind spot between reviews

A customer is onboarded in January, clean. In March they’re named in an enforcement action. In June they’re added to a sanctions list. Under a periodic-review model, none of that surfaces until their file happens to come up again — potentially years later. In the meantime, the institution has been transacting with a now-high-risk party and doesn’t know it.

That gap isn’t a theoretical weakness. It’s exactly where regulators find fault after the fact: “the information was public; why didn’t you act?”

Perpetual monitoring closes the gap

The fix is to stop treating screening as an event and start treating it as a state. Every customer is re-screened continuously against the same sources used at onboarding, and any change — a new sanction, a new adverse-media hit, a new enforcement record — raises an alert the day it appears.

SonarPulse does this with an opt-in perpetual monitoring engine:

Daily re-screening of enrolled customers against sanctions, PEP, media and enforcement sources. – Hit-diffing — it doesn’t just re-run the check, it detects what changed since last time, so analysts see new risk, not yesterday’s noise. – Consolidated alerts — a single digest of rating changes and new hits, plus an “Ongoing” dashboard view. – A daily adverse-media watch with per-hit category tagging (fraud, corruption, terror), so emerging press is caught, not just list updates.

Why “re-screen everything” finally works

Continuous monitoring used to be prohibitively expensive — because per-record data pricing meant every re-screen was billed again. When your coverage is built on aggregated official and open sources rather than a metered feed, the cost of screening a customer a thousand times is essentially the cost of screening them once. Perpetual monitoring stops being a premium add-on and becomes the default.

From reactive to defensible

The operational win is fewer surprises. The regulatory win is bigger: an institution that monitors continuously can show it acted on public information promptly, with a dated, auditable trail of what changed and when. That’s the difference between explaining a lapse and demonstrating a control.

Onboarding tells you who a customer was on day one. Perpetual monitoring tells you who they are today.

SonarPulse includes perpetual monitoring and daily media watch as part of the platform. Request a compliance health check.

Start with a compliance health check.

A working session with your compliance team, then a walkthrough against your own risk appetite: the lifecycle end to end, scoring weights set to your policy, and a review of the audit trail the system produces.

Or write to info@sonarpulse.mu