Skip to main content
Category: Customer Due Diligence

Ongoing Due Diligence

Also known as: ODD, Ongoing Monitoring, Ongoing Customer Due Diligence
Simply put

Ongoing due diligence is the continuous process of monitoring a customer relationship after it has been established, rather than checking a customer only once at onboarding. It involves reviewing a customer's transactions and activity over time to understand their behavior and to help detect and manage risks such as money laundering and terrorist financing. It is a component of the broader customer due diligence process and is not a one-off event.

Formal definition

Ongoing due diligence is the element of the customer due diligence (CDD) process that requires obliged entities to conduct continuous monitoring of a business relationship, including scrutiny of transactions to assess whether they are consistent with the entity's knowledge of the customer and the customer's risk profile. It typically encompasses keeping customer information, documentation, and risk assessments current over the life of the relationship, and calibrating the intensity of monitoring to assessed risk. As a component of CDD (which may itself incorporate KYC processes), ongoing due diligence supports the detection, deterrence, and management of money laundering and terrorist financing risk, but it does not by itself guarantee prevention or establish wrongdoing. Specific obligations, triggers for review, and record-keeping requirements vary by jurisdiction and by the category of obliged entity, and exact requirements should be confirmed against the applicable regulation; in the United States, for example, ongoing monitoring obligations for covered financial institutions arise under the FinCEN CDD Rule.

Why it matters

Ongoing due diligence addresses a fundamental limitation of onboarding checks: a customer's risk profile is not static. A relationship that appeared low-risk at account opening can change as the customer's behavior, ownership, business lines, or transaction patterns evolve. Without continuous monitoring, an obliged entity relies on a snapshot that becomes progressively less reliable over the life of the relationship, leaving money laundering and terrorist financing risk undetected and unmanaged. Ongoing due diligence exists to keep the institution's understanding of its customers current and to scrutinize activity against that understanding over time.

Because it is a component of the broader customer due diligence process rather than a one-off event, ongoing due diligence is where many transaction-based red flags first surface and where information gathered at onboarding is tested against real behavior. It supports the detection, deterrence, and management of financial crime risk, but it is important to recognize its limits: monitoring does not by itself guarantee prevention, and a transaction that is inconsistent with a customer's profile is a basis for further review, not proof of wrongdoing.

The specific obligations attached to ongoing due diligence differ by jurisdiction and by the category of obliged entity. In the United States, for example, ongoing monitoring obligations for covered financial institutions arise under the FinCEN CDD Rule, which clarifies and strengthens customer due diligence requirements for institutions such as banks, mutual funds, and brokers or dealers in securities. Other regimes impose their own triggers, intensity expectations, and record-keeping requirements, and exact obligations should be confirmed against the applicable regulation rather than assumed to be uniform across regimes.

Who it's relevant to

Compliance officers and AML program managers
Those responsible for designing and maintaining an AML program must ensure ongoing due diligence is embedded across the customer lifecycle, that monitoring intensity is risk-calibrated, and that information and risk assessments are kept current. For U.S. covered financial institutions, program design should account for ongoing monitoring obligations arising under the FinCEN CDD Rule, while programs operating in other jurisdictions should be built against the applicable local requirements.
Covered financial institutions
In the United States, the CDD Rule applies to categories of institutions including banks, mutual funds, and brokers or dealers in securities, among others. These entities carry ongoing monitoring responsibilities as part of their CDD obligations. The precise scope and application depend on the institution's category and should be confirmed against the rule and any other regimes to which the institution is subject.
Financial intelligence analysts and transaction monitoring teams
Analysts who review alerts and scrutinize transactions rely on ongoing due diligence to compare observed activity against the institution's knowledge of the customer and their risk profile. They are typically the first to identify activity that is inconsistent with expectations, which may warrant further review, though such inconsistency is a basis for investigation, not a determination of wrongdoing.
Risk and audit functions
Teams responsible for risk assessment, quality assurance, and internal audit assess whether ongoing due diligence is being performed consistently, whether monitoring is appropriately calibrated to risk, and whether documentation and record-keeping meet the requirements of the applicable regulation.

Inside ODD

Ongoing Transaction Monitoring
The continuous scrutiny of transactions undertaken throughout a business relationship to ensure they are consistent with the obliged entity's knowledge of the customer, their business and risk profile, and, where necessary, the source of funds. This is typically distinct from one-off checks performed at onboarding and is generally required for obliged entities under regimes such as the EU AML Directives, the UK Money Laundering Regulations, and FinCEN rules implementing the US Bank Secrecy Act, though the precise form and thresholds vary by jurisdiction.
Keeping CDD Information Current
The obligation to keep documents, data, and information collected under Customer Due Diligence up to date, so that the customer's risk profile remains accurate over the life of the relationship. This typically includes reviewing and refreshing identification data, beneficial ownership information, and the purpose and intended nature of the relationship. Ongoing due diligence is a component of the broader CDD framework rather than a substitute for initial CDD or Enhanced Due Diligence.
Risk-Based Review Cycles
Periodic or event-driven reviews of the customer relationship, with frequency and intensity calibrated to assessed risk. Higher-risk relationships, such as those involving Politically Exposed Persons or higher-risk jurisdictions, are generally subject to more frequent and more intensive review than lower-risk relationships. These cycles are a means to detect, deter, and manage financial crime risk, not a guarantee that misconduct will be prevented.
Trigger Events
Circumstances that prompt a review or update outside of scheduled cycles, such as a significant change in transaction behaviour, a change in beneficial ownership, adverse media, a sanctions or PEP screening hit, or a change in the customer's stated purpose. Trigger events help ensure the customer profile reflects current information between periodic reviews.
Escalation and Reporting Interface
The operational link between ongoing due diligence and internal escalation processes. Where monitoring identifies activity inconsistent with the known profile, it may lead to internal investigation and, where the applicable threshold of suspicion is met, the filing of a Suspicious Activity Report (SAR) or Suspicious Transaction Report (STR) as required in the relevant jurisdiction. Identifying an anomaly or generating an alert does not, in itself, establish wrongdoing.

Common questions

Answers to the questions practitioners most commonly ask about ODD.

Is ongoing due diligence the same as periodically refreshing a customer's KYC records?
Not exactly. Periodic KYC refresh, sometimes called periodic review, is one component of ongoing due diligence, but it is not the whole of it. Ongoing due diligence generally comprises two broad elements: keeping customer identification and risk information current (which the periodic refresh supports), and scrutinising transactions and activity over the course of the relationship to ensure they remain consistent with the obliged entity's knowledge of the customer, their business, and their risk profile. Treating ongoing due diligence as a calendar-driven document update alone can miss the transaction-monitoring dimension. Many frameworks, reflecting FATF's risk-based approach, also expect reviews to be triggered by events or changes in risk rather than solely by a fixed schedule. Exact expectations vary by jurisdiction and should be confirmed against the applicable regime.
Does ongoing due diligence mean every customer must be reviewed on the same fixed cycle?
Generally, no. Under a risk-based approach, the frequency and intensity of ongoing due diligence are typically expected to vary with the assessed risk of the customer and relationship, rather than applying a single uniform cycle to all customers. Higher-risk relationships may warrant more frequent and more thorough scrutiny, while lower-risk relationships may be reviewed less often, subject to the applicable rules. Some regimes and internal policies do set outer time limits or minimum review frequencies, so a fixed cycle may operate as a backstop rather than the primary driver. The precise requirements differ across jurisdictions and obliged-entity types and should be verified against the relevant regulation and supervisory guidance.
What events typically trigger an ongoing due diligence review outside the scheduled cycle?
In many programs, event-driven or trigger-based reviews supplement scheduled reviews. Common triggers include material changes in the customer's profile or behaviour, unusual or unexpected transactions identified through monitoring, changes in beneficial ownership or control, adverse media or new sanctions or PEP screening matches, a change in the customer's risk rating, or the customer's involvement in a filed suspicious activity or transaction report. The specific triggers an obliged entity adopts should be documented in its policies and calibrated to its risk assessment. Note that a trigger or an alert prompts review; it does not by itself establish wrongdoing.
How does transaction monitoring fit within ongoing due diligence?
Transaction monitoring is a core operational element of ongoing due diligence. It is the process of scrutinising transactions and activity across the life of the relationship to assess whether they are consistent with the obliged entity's knowledge of the customer, their expected activity, and their risk profile. Monitoring may be automated, manual, or a combination, and it can generate alerts for investigation. Where activity appears unusual or potentially suspicious, it may feed into the suspicious activity or transaction reporting process, subject to the applicable reporting regime. Monitoring is a measure to detect and manage risk; it does not guarantee that all illicit activity is identified, and an alert is not proof of criminality.
Should customer risk ratings be updated as part of ongoing due diligence, and how?
Typically, yes. Ongoing due diligence often includes reassessing and, where appropriate, updating a customer's risk rating as new information emerges through reviews, monitoring, screening, or external developments. An updated risk rating may in turn change the frequency and depth of subsequent due diligence, and could move a relationship into or out of enhanced due diligence. Firms generally document the rationale for rating changes to support auditability and supervisory review. The specific factors and methodology should align with the obliged entity's risk assessment and the requirements of the applicable jurisdiction.
What outcomes can result from an ongoing due diligence review?
Depending on findings, outcomes may include confirming that the relationship remains within the expected risk profile with no further action, updating customer information or beneficial ownership details, revising the risk rating, escalating to enhanced due diligence, requesting additional documentation or source-of-funds or source-of-wealth information, or escalating internally for consideration of a suspicious activity or transaction report under the applicable regime. In some cases firms may consider restricting or exiting the relationship, subject to legal and regulatory constraints and any tipping-off considerations. These are operational compliance outcomes; none of them, including a filed report, constitutes a finding of criminal wrongdoing.

Common misconceptions

Ongoing due diligence is the same as re-running onboarding KYC on a fixed schedule.
Ongoing due diligence is broader and more dynamic than periodic re-verification of identity. It combines keeping CDD information current with continuous transaction monitoring and event-driven reviews, calibrated to risk. Fixed periodic refreshes are one element, but relying on them alone can miss changes that occur between review dates, which is why trigger-based reviews are typically expected.
A monitoring alert or an anomaly detected during ongoing due diligence proves the customer is laundering money.
An alert, an unusual transaction, or a screening match is an indicator that warrants further review, not evidence of a criminal offence. Typologies and red flags are not exhaustive and are not proof of criminality. Only after internal assessment, and where the applicable threshold of suspicion is reached, may a SAR or STR be warranted, and even a filing does not establish wrongdoing.
Ongoing due diligence requirements are identical across all jurisdictions and obliged entities.
While the FATF Recommendations set out ongoing due diligence as a standard, they are standards rather than binding law. The specific obligations, review frequencies, and monitoring expectations derive from each jurisdiction's implementing framework, such as the EU AML Directives, the UK Money Laundering Regulations, or FinCEN rules under the US Bank Secrecy Act, and they differ in scope and detail. Exact requirements should be confirmed against the applicable regulation.

Best practices

Calibrate the frequency and depth of periodic reviews to the assessed risk of each relationship, applying more frequent and intensive review to higher-risk customers such as PEPs or those linked to higher-risk jurisdictions.
Define and document trigger events that prompt out-of-cycle reviews, so that material changes in transaction behaviour, beneficial ownership, or adverse information are addressed promptly rather than waiting for the next scheduled review.
Ensure transaction monitoring is benchmarked against the documented expected purpose and nature of the relationship, and periodically reassess those expectations as part of keeping CDD information current.
Maintain clear escalation pathways linking monitoring outputs to internal investigation and, where the applicable threshold of suspicion is met, to SAR or STR filing, while avoiding treating alerts or matches as conclusions of wrongdoing.
Keep CDD records, including beneficial ownership and identification data, up to date, and retain an audit trail of reviews, decisions, and rationale to demonstrate the risk-based approach to regulators.
Confirm the specific ongoing due diligence obligations, thresholds, and monitoring expectations against the framework applicable in each jurisdiction of operation rather than assuming a single global standard applies.