governance

AMLA’s new consultation shows why ongoing monitoring is becoming a core operating layer for financial and digital asset businesses

On 3 June 2026, the European Anti-Money Laundering Authority launched a public consultation on draft Guidelines for the ongoing monitoring of business relationships.

The consultation is open until 3 September 2026, with a public hearing scheduled for 2 July 2026.

This may sound like a technical regulatory update, but the direction is important.

AMLA is putting renewed attention on what happens after a customer or business relationship has already been established. In other words, AML compliance is not only about onboarding, document collection or initial verification.

It is about continuous visibility.

From onboarding to lifecycle compliance

For years, many AML discussions focused heavily on the onboarding stage.

Identify the customer.
Collect the documents.
Verify the information.
Screen the parties.
Approve or reject the relationship.

These steps remain essential.

But they are only the beginning of the relationship, not the full compliance lifecycle.

A customer’s behaviour can change over time. Transaction patterns can shift. Products used by the customer can expand. Counterparties can change. Geographic exposure can evolve. A relationship that looked low-risk at the start may become more complex as activity develops.

This is why ongoing monitoring matters.

It connects the original customer risk assessment with actual behaviour over time.

The key question becomes simple:

Does the customer’s current activity still match the relationship that was approved?

What AMLA’s consultation is really about

AMLA describes ongoing monitoring as the process by which companies and professionals covered by AML rules maintain a clear and current understanding of a business relationship after it has been established.

That includes keeping customer information up to date and monitoring transactions and activities over time, so unusual or suspicious activity can be detected if it arises.

This is a practical concept, not only a legal one.

It means firms need more than a customer file. They need an operating model that connects customer risk profiles, transaction activity, review triggers, escalation workflows, records and reporting.

The consultation signals that AML expectations are becoming more operational.

Regulators are not only asking whether a firm has policies. They are asking whether those policies can be applied continuously inside real business activity.

Why this matters for payment and digital asset infrastructure

For payment companies, fintech platforms, crypto-asset service providers and digital asset infrastructure businesses, ongoing monitoring is especially important.

Modern payment rails can move value quickly, across different systems, jurisdictions, assets and counterparties. That creates operational advantages, but it also increases the need for visibility and control.

If a payment infrastructure business cannot see how activity evolves over time, it becomes harder to detect unusual behaviour, explain customer activity, reconcile flows, maintain records or support compliance review.

This is why monitoring cannot sit outside the product or payment workflow.

It needs to be designed into the operating layer.

A payment flow should not only move value. It should also create the right records, support reconciliation, provide visibility to internal teams and make exceptions reviewable.

Risk-based compliance needs data

The risk-based approach is a central part of AML compliance.

But risk-based compliance only works if risk assessments are connected to actual activity.

A customer risk rating that sits in a static file is not enough.

It needs to influence monitoring logic, review frequency, transaction controls, escalation rules and internal reporting.

That requires structured data.

Customer information, transaction records, payment references, wallet or account activity, counterparty details, settlement data and exception records need to be connected enough for compliance teams to understand what is happening.

Without that data layer, ongoing monitoring becomes manual, fragmented and difficult to evidence.

The operational lesson

The practical message from AMLA’s consultation is clear: AML compliance is becoming more continuous.

Firms should not think about compliance as a one-time gate at onboarding. They should think about it as a lifecycle process that follows the business relationship over time.

That has several implications.

Customer information needs to stay current.

Monitoring should reflect the nature of the customer, product, geography and transaction behaviour.

Escalation workflows should be clear.

Records should be complete enough to support review and audit.

Compliance teams should be able to explain not only why a relationship was approved, but also how it was monitored after approval.

This is particularly important for firms operating across payment rails, digital assets, cross-border settlement or platform-based financial services.

The more complex the operating environment, the more important continuous visibility becomes.

MetaNord’s view

At MetaNord, we see ongoing monitoring as part of the broader infrastructure layer around modern payments and digital assets.

New rails can create speed, flexibility and reach. But they also need visibility, controls and reliable operational records.

That is why compliance should not be added at the end of a payment workflow.

It should be designed into the workflow from the beginning.

The next phase of payment and digital asset infrastructure will not be defined only by faster settlement or better technology.

It will also be defined by whether those systems can operate with continuous visibility, practical controls and compliance-ready evidence.

Ongoing monitoring is where that shift becomes visible.

See where MetaNord fits in your payment workflow.

Review the systems around your payment flow, from provider connections through to reconciliation and operating handover.