From the annual review to perpetual monitoring
A compliance framework built around periodic reviews can carry an assumption worth testing: that a customer screened clean at onboarding stays clean until their next scheduled review.
A compliance framework built around periodic reviews can carry an assumption worth testing: that a customer screened clean at onboarding stays clean until their next scheduled review.
Risk doesn’t keep that schedule — and the law does not assume it does.
What the rule requires
EU anti-money-laundering law is a useful benchmark. Directive (EU) 2015/849 requires Member States to make obliged entities apply customer due diligence not only to all new customers but also to existing customers at appropriate times on a risk-sensitive basis, or when the relevant circumstances of a customer change (Article 14(5)). It also requires ongoing monitoring of the business relationship, including scrutiny of transactions and ensuring that the documents, data or information held are kept up to date (Article 13(1)(d)).
In other words, the review calendar is part of the answer, not all of it. Under that rule, a change in a customer’s circumstances is itself a trigger to apply due diligence again.
The blind spot between reviews
Consider a hypothetical. A customer is onboarded in January, clean. In March they are named in an enforcement action. In June they are added to a sanctions list. If the only trigger for looking again is the review date, none of that surfaces until the file comes up — and in the meantime the institution has been dealing with a customer whose risk has changed.
The lists themselves move on in the meantime. The UN Security Council’s Consolidated List page says the list was last updated on 4 September 2026 and supersedes all previous versions, and that a press release is issued after all changes to the respective sanctions list. OFAC describes its Sanctions List Service as giving access to the most up-to-date sanctions lists.
That gap is also an uncomfortable conversation after the event. The information was public, so why didn’t the firm act?
Perpetual monitoring closes the gap
The fix is to stop treating screening as an event and start treating it as a state. Re-screen continuously against the same sources used at onboarding, and treat any change — a new designation, a new adverse-media hit, a new enforcement record — as a prompt to look again, the day it appears.
How SonarPulse does it
This section describes SonarPulse’s own product.
SonarPulse does this with an opt-in perpetual monitoring engine:
- Daily re-screening of enrolled customers against sanctions, PEP, media and enforcement sources.
- Hit-diffing — it doesn’t just re-run the check, it detects what changed since last time, so analysts see new risk, not yesterday’s noise.
- Consolidated alerts — a single digest of rating changes and new hits, plus an “Ongoing” dashboard view.
- A daily adverse-media watch with per-hit category tagging (fraud, corruption, terror), so emerging press is caught, not just list updates.
Because SonarPulse’s coverage is built on aggregated official and open sources rather than a metered feed, screening a customer a thousand times costs essentially the same as screening them once. Perpetual monitoring is part of the platform, not a premium add-on.
Check what your contract charges for looking again
Whatever tools you use, find out how your data contract prices re-screening. If every monitoring pass is billed again, the contract, not your risk assessment, ends up deciding how often you look.
From reactive to defensible
The Directive requires customer due diligence records to be kept for five years after the end of the business relationship. An institution that monitors continuously, and records what changed and when, can show what it knew, when it knew it, and what it did. That’s the difference between explaining a lapse and demonstrating a control.
> Onboarding tells you who a customer was on day one. Perpetual monitoring tells you who they are today.
SonarPulse includes perpetual monitoring and daily media watch as part of the platform. [Learn more / request a demo].
Sources
This article draws on the following sources. Follow the links for the original text.