Why is Ongoing Monitoring Necessary?
The risk process does not end once KYC or customer onboarding is complete.
A customer may appear low-risk during onboarding. However, over time, their transaction behavior may change, they may start using a new device, log in from different countries, transact with new counterparties, or their screening results may be updated.
Therefore, evaluating customer risk solely on day one is not enough.
Ongoing Monitoring is a continuous surveillance approach that ensures customer, transaction, and risk signals are re-evaluated over time.
The goal is not to constantly check every customer manually, but to make it visible when there is a significant change in their risk profile.
What is Ongoing Monitoring?
Ongoing Monitoring is the tracking of new data and behaviors that emerge after customer onboarding, based on specific risk rules.
In this process, not only financial transactions but also various signals can be evaluated together, such as:
- transaction history,
- customer profile,
- device changes,
- IP and location,
- counterparty relationships,
- sanctions and PEP results,
- linked accounts,
- risk score changes.
As a result, risk assessment is no longer a static outcome generated during onboarding.
Why is the Initial KYC Check Not Enough?
Information gathered during customer onboarding only reflects the situation at that specific moment.
For example, a customer:
- may not be on any sanctions lists,
- may not appear as a PEP,
- may have a low transaction volume,
- may not carry any obvious risk signals.
However, this picture can change a few months later.
The individual might be added to a new PEP registry, start transacting in different countries, or exhibit behavior that deviates significantly from their past patterns.
Therefore, what matters in an AML/CFT approach is not just "knowing your customer", but also being able to track how they change over time.
What Changes Does Ongoing Monitoring Track?
Every institution has a different risk policy.
However, several key areas typically stand out within the scope of Ongoing Monitoring.
Changes in Transaction Behavior
A customer's normal transaction behavior forms a specific pattern over time.
For example, if a user who previously made low-value and infrequent transactions suddenly starts high-volume transfers within a short period, this may warrant an investigation.
Similarly, behavioral changes such as:
- increased transaction frequency,
- transfers to new countries,
- addition of new beneficiaries,
- rapid, repetitive transactions
can be used in risk assessment.
Updating Screening Results
Sanctions, PEP, and watchlist data are not static.
New individuals and entities can be added to lists, existing records can be updated, or new matches can emerge.
Therefore, a one-time screening performed during onboarding may not be sufficient.
Thanks to Ongoing Monitoring, customers or related parties can be re-evaluated against updated lists.
At this point, Fuzzy Matching supports the investigation of potential matches between different spellings or similar names.
Device, IP, and Location Changes
Risk does not consist of transaction data alone.
A user's behavior, such as:
- logging in with a new device,
- using a different IP,
- transacting from a previously unseen location,
- changing multiple devices in a short period
can also be significant.
These signals do not always indicate high risk on their own.
However, they become meaningful when evaluated alongside transaction behavior and other risk indicators.
Why Should Risk Scores Be Dynamic?
The risk level assigned to a customer during onboarding should not remain the same forever.
Risk can change over time.
Therefore, Real-Time Risk Scoring ensures that the risk level is re-evaluated as new signals emerge.
For example:
- a new screening match,
- unusual transaction behavior,
- a high-risk location,
- linked accounts
can trigger a re-evaluation of customer risk.
This allows teams to act based on up-to-date risk signals rather than relying solely on static customer segments.
Why is Network & Relationship Analysis Important?
Some risks are not visible when looking at a single customer in isolation.
For example, different accounts might be linked through:
- the same device,
- the same IP,
- the same phone number,
- the same counterparty,
- similar transfer chains.
In such cases, even if the customer's own profile appears normal, the relationships around them may be risky.
Network & Relationship Analysis helps evaluate these connections together.
When used in conjunction with Ongoing Monitoring, it becomes possible to track not just the changes in a single customer, but also the evolution of the network they belong to over time.
Why is Ongoing Monitoring Valuable for False Positives?
Not every change indicates risk.
It can be perfectly normal for a customer to use a new device or transact from a different city.
Therefore, the purpose of Ongoing Monitoring is not to generate an alert for every single change.
The real goal is to evaluate different signals together to distinguish changes that require investigation from those that do not.
This approach can help reduce the number of unnecessary alerts and allow teams to focus on more meaningful risks.
How Does Truvali Support the Ongoing Monitoring Process?
Truvali does not treat Ongoing Monitoring as a standalone, isolated check, but as a framework where different risk capabilities on the platform work together.
Real-Time Transaction Monitoring
Financial and non-financial events can be evaluated during the transaction flow.
New behaviors can be analyzed alongside customer history and other risk signals.
Sanctions, PEP & Watchlist Screening
Customers and related parties can be re-evaluated against sanctions, PEP, watchlist, and internal lists.
Following list updates, new matches can be incorporated into the investigation process.
Real-Time Risk Scoring
As new events and risk signals emerge, the risk level of the customer or related entity can be re-evaluated.
Dynamic Rule & Scenario Engine
Institutions can create Ongoing Monitoring scenarios based on their own risk policies.
Specific time intervals, customer segments, transaction types, device, IP, location, and other conditions can be utilized within the same scenario.
Network & Relationship Analysis
Relationships between the customer and linked accounts, devices, IPs, phone numbers, and transactions can be analyzed together.
Alerts & Case Management
Risk changes requiring investigation can be routed to the alert or case management workflow.
Teams can track relevant events, risk justifications, historical records, and notes under the same case.
When Should Ongoing Monitoring Be Triggered?
There is no single correct time.
Ongoing Monitoring can be triggered:
- when a new transaction occurs,
- when a customer profile changes,
- when screening lists are updated,
- when a new risk signal is generated,
- during specific periodic reviews.
The structure here should be determined based on the institution's customer profile, risk appetite, and operational policy.
Frequently Asked Questions
What is Ongoing Monitoring?
Ongoing Monitoring is the re-evaluation over time of transactions, behavior, screening, and other risk signals that emerge after customer onboarding.
Is Ongoing Monitoring only used for AML?
No. In addition to AML/CFT processes, it can also be used in fraud detection, customer risk assessment, and screening operations.
Does Ongoing Monitoring generate an alert for every change?
No. Alert generation depends on the rules and risk thresholds defined by the institution. The goal is not to turn every change into an alarm, but to isolate risks that require investigation.
Can Truvali re-evaluate screening results?
Yes. Customers and related parties included in the institution's screening process can be re-evaluated against updated sanctions, PEP, watchlist, and internal lists.
Does Ongoing Monitoring completely eliminate manual review?
No. The system prioritizes risk signals and supports investigation processes. The final evaluation and decision remain with the institution's authorized teams.