EU AML Regulations 2027

Ongoing monitoring under AMLR, Regulation (EU) 2024/1624 vs UK MLR2017

[Updated September 2026]

Ongoing monitoring comparisons for UK firms with EU offices

Both the UK MLRs and EU AMLR require firms to keep client information current and scrutinise activity throughout the business relationship. The AMLR adds fixed review ceilings; one year for higher-risk clients subject to EDD and five years for all others, alongside event-driven reviews.

It also requires CDD to cover all products and services and relevant information from the client’s other group relationships to inform monitoring. This points towards the need for a connected view of the client across engagements, entities and the obligated firm as a whole.

AMLA’s draft guidance reinforces this direction. Monitoring should identify risks that emerge only when activity, relationships and behaviour are considered together over time. Firms may use manual or automated controls, but must be able to demonstrate that their systems, data and processes are effective.

Ref:

 

Frequently asked questions

Our monitoring programme is periodic and risk-tiered. Is that compliant under AMLR?

For higher-risk clients, probably not. AMLR Article 26 requires transactions to be scrutinised throughout the business relationship, not at fixed intervals. For a complex PE-backed client across multiple practice groups, that implies something closer to continuous monitoring. The AMLA RTS will set the floor. Periodic-only is the architecture that will require remediation.

What is the cross-matter visibility problem AMLR creates for large law firms?

AMLR Article 26 applies the monitoring obligation to the business relationship — the client, not the matter. It explicitly prohibits product-siloed monitoring: where a client has relationships across multiple service lines, monitoring must cover all of them as a unified picture. A firm whose compliance infrastructure is matter-level, with no aggregated client view, cannot demonstrate that the obligation is met.

What does the SRA's evidence-led supervision approach mean for ongoing monitoring specifically?

Inspectors ask to see the file, not the policy. A monitoring policy that says "high-risk clients reviewed annually" stands or falls on the audit trail in the matter file showing when the review occurred, what was reviewed, and what was decided. SRA 2024-25: 39% of client and matter risk assessments were rated ineffective, and a further 16% were missing or incomplete. AMLR Article 26 adds a mandatory intermediate category between normal and suspicious that must also be visible in that trail.

AMLR requires that information from group relationships must be used in monitoring, not merely be available. What does that require?

Where a client has relationships with other EU offices in the same group, Article 26 requires that information from those relationships be actively incorporated into the monitoring picture. An ownership change flagged in Frankfurt needs to be visible to the monitoring function in Paris. Firms operating office-level compliance systems with no shared client intelligence layer are non-compliant with this from day one of AMLR.