Ongoing monitoring under AMLR, Regulation (EU) 2024/1624 vs UK MLR2017
[Updated September 2026]
Ongoing monitoring comparisons for UK firms with EU offices
Both the UK MLRs and EU AMLR require firms to keep client information current and scrutinise activity throughout the business relationship. The AMLR adds fixed review ceilings; one year for higher-risk clients subject to EDD and five years for all others, alongside event-driven reviews.
It also requires CDD to cover all products and services and relevant information from the client’s other group relationships to inform monitoring. This points towards the need for a connected view of the client across engagements, entities and the obligated firm as a whole.
AMLA’s draft guidance reinforces this direction. Monitoring should identify risks that emerge only when activity, relationships and behaviour are considered together over time. Firms may use manual or automated controls, but must be able to demonstrate that their systems, data and processes are effective.
Ref:
UK MLRs 2017
AMLR 2024
Operational implication
Core duty
Firms must scrutinise engagements throughout the business relationship and keep CDD information current.
Same as MLRs but AMLR draft guidance extends the practical focus to included transactions, activities, behaviour and relevant events.
Monitoring workflows need to bring relevant changes from matter teams, finance, screening and onboarding into the client’s AML record.
Products and services
Regulation 28 applies across the business relationship but does not explicitly include all-products-and-services wording.
Where a relationship covers more than one product or service, CDD must cover all of them. Draft guidance says monitoring should support a holistic understanding of client behaviour.
Client monitoring will need to connect all related matters / engagements and services across practice / business areas.
Group relationships
The group must maintain policies covering customer, account and transaction information and ensure relevant information is shared appropriately.
Information from a client’s other group relationships must be used in monitoring. The draft RTS specifies sharing across common clients, beneficial owners and connected client groups, covering relevant CDD, services, activity, risk and adverse information. Equivalent requirements may extend to qualifying networks and partnerships.
EU monitoring may need a group-wide client view, connecting clients, beneficial owners, matters and services across offices. This requires controlled data sharing, traceable decisions and clear local responsibility.
Scheduled reviews
CDD is refreshed on a risk-based basis, with no fixed statutory maximum.
Maximum 1 year for higher-risk clients and 5 years for all others, alongside event-driven reviews. Draft guidance identifies changes in ownership, behaviour, finances, funding, PEP status, adverse information and geographic exposure as possible triggers. Draft guidance also confirms that the depth of review remains risk-based.
EU client records need hard data-age controls alongside risk- and event-based review triggers.
Patterns over time
Transactions must be scrutinised throughout the relationship, but the MLRs do not prescribe how activity must be aggregated.
Draft guidance says monitoring should detect risks that emerge only when transactions and activities are considered together over time, including linked, repeated, split or aggregated behaviour.
Firms need connected client history across matters / engagements, relationships and transactions to identify patterns that individual files may not reveal.
Source of funds
SoF is revisited on a risk-based basis, particularly where activity is inconsistent with the firm’s knowledge of the client, their business or risk profile.
Transactions and activities must be monitored against the client’s profile, including the origin and destination of funds where necessary. Draft guidance says firms should test whether SoF remains consistent with the expected profile and obtain additional information where existing CDD does not sufficiently explain it.
EU monitoring may need fund-flow information kept live and reusable, covering destination as well as source. Mismatches between expected and actual funding should trigger review.
Complex or unusual transactions
For unusually complex or unusually large transactions,, firms must examine the background and purpose and increase monitoring.
Article 34 requires the origin and destination of funds and the purpose to be examined for complex, unusually large, unusually patterned or apparently purposeless transactions.
EU investigation workflows need explicit fields and evidence for the origin and destination of funds, not only the purpose and nature.
Frequently asked questions
Our monitoring programme is periodic and risk-tiered. Is that compliant under AMLR?
For higher-risk clients, probably not. AMLR Article 26 requires transactions to be scrutinised throughout the business relationship, not at fixed intervals. For a complex PE-backed client across multiple practice groups, that implies something closer to continuous monitoring. The AMLA RTS will set the floor. Periodic-only is the architecture that will require remediation.
What is the cross-matter visibility problem AMLR creates for large law firms?
AMLR Article 26 applies the monitoring obligation to the business relationship — the client, not the matter. It explicitly prohibits product-siloed monitoring: where a client has relationships across multiple service lines, monitoring must cover all of them as a unified picture. A firm whose compliance infrastructure is matter-level, with no aggregated client view, cannot demonstrate that the obligation is met.
What does the SRA's evidence-led supervision approach mean for ongoing monitoring specifically?
Inspectors ask to see the file, not the policy. A monitoring policy that says "high-risk clients reviewed annually" stands or falls on the audit trail in the matter file showing when the review occurred, what was reviewed, and what was decided. SRA 2024-25: 39% of client and matter risk assessments were rated ineffective, and a further 16% were missing or incomplete. AMLR Article 26 adds a mandatory intermediate category between normal and suspicious that must also be visible in that trail.
AMLR requires that information from group relationships must be used in monitoring, not merely be available. What does that require?
Where a client has relationships with other EU offices in the same group, Article 26 requires that information from those relationships be actively incorporated into the monitoring picture. An ownership change flagged in Frankfurt needs to be visible to the monitoring function in Paris. Firms operating office-level compliance systems with no shared client intelligence layer are non-compliant with this from day one of AMLR.