From the annual review to perpetual monitoring

A compliance framework built around periodic reviews can carry an assumption worth testing: that a customer screened clean at onboarding stays clean until their next scheduled review.

Illustration for “From the annual review to perpetual monitoring”

A compliance framework built around periodic reviews can carry an assumption worth testing: that a customer screened clean at onboarding stays clean until their next scheduled review.

Risk doesn’t keep that schedule — and the law does not assume it does.

What the rule requires

EU anti-money-laundering law is a useful benchmark. Directive (EU) 2015/849 requires Member States to make obliged entities apply customer due diligence not only to all new customers but also to existing customers at appropriate times on a risk-sensitive basis, or when the relevant circumstances of a customer change (Article 14(5)). It also requires ongoing monitoring of the business relationship, including scrutiny of transactions and ensuring that the documents, data or information held are kept up to date (Article 13(1)(d)).

In other words, the review calendar is part of the answer, not all of it. Under that rule, a change in a customer’s circumstances is itself a trigger to apply due diligence again.

The blind spot between reviews

Consider a hypothetical. A customer is onboarded in January, clean. In March they are named in an enforcement action. In June they are added to a sanctions list. If the only trigger for looking again is the review date, none of that surfaces until the file comes up — and in the meantime the institution has been dealing with a customer whose risk has changed.

The lists themselves move on in the meantime. The UN Security Council’s Consolidated List page says the list was last updated on 4 September 2026 and supersedes all previous versions, and that a press release is issued after all changes to the respective sanctions list. OFAC describes its Sanctions List Service as giving access to the most up-to-date sanctions lists.

That gap is also an uncomfortable conversation after the event. The information was public, so why didn’t the firm act?

Perpetual monitoring closes the gap

The fix is to stop treating screening as an event and start treating it as a state. Re-screen continuously against the same sources used at onboarding, and treat any change — a new designation, a new adverse-media hit, a new enforcement record — as a prompt to look again, the day it appears.

How SonarPulse does it

This section describes SonarPulse’s own product.

SonarPulse does this with an opt-in perpetual monitoring engine:

  • Daily re-screening of enrolled customers against sanctions, PEP, media and enforcement sources.
  • Hit-diffing — it doesn’t just re-run the check, it detects what changed since last time, so analysts see new risk, not yesterday’s noise.
  • Consolidated alerts — a single digest of rating changes and new hits, plus an “Ongoing” dashboard view.
  • A daily adverse-media watch with per-hit category tagging (fraud, corruption, terror), so emerging press is caught, not just list updates.

Because SonarPulse’s coverage is built on aggregated official and open sources rather than a metered feed, screening a customer a thousand times costs essentially the same as screening them once. Perpetual monitoring is part of the platform, not a premium add-on.

Check what your contract charges for looking again

Whatever tools you use, find out how your data contract prices re-screening. If every monitoring pass is billed again, the contract, not your risk assessment, ends up deciding how often you look.

From reactive to defensible

The Directive requires customer due diligence records to be kept for five years after the end of the business relationship. An institution that monitors continuously, and records what changed and when, can show what it knew, when it knew it, and what it did. That’s the difference between explaining a lapse and demonstrating a control.

> Onboarding tells you who a customer was on day one. Perpetual monitoring tells you who they are today.

SonarPulse includes perpetual monitoring and daily media watch as part of the platform. [Learn more / request a demo].


Sources

This article draws on the following sources. Follow the links for the original text.

Start with a compliance health check.

A working session with your compliance team, then a walkthrough against your own risk appetite: the lifecycle end to end, scoring weights set to your policy, and a review of the audit trail the system produces.

Or write to info@sonarpulse.mu