FIRMCY Insights

A draft, and a deadline

Regulator commentary · all insights
A draft, and a deadline

A Cyprus compliance officer who has wanted someone at EU level to say what ongoing monitoring actually requires now has a text to read and a window to argue with it. It is not a rulebook. AMLA published the draft Guidelines on ongoing monitoring of a business relationship under Article 26(5) of Regulation (EU) 2024/1624 on 3 June 2026; the consultation is open until 3 September 2026; the final guidelines, AMLA says, will be issued in Q4 2026. Everything below is a proposal.

The mandate is Article 26(5) AMLR, which requires AMLA to issue guidelines specifying how obliged entities should perform ongoing monitoring of a business relationship, including the monitoring of the transactions and activities carried out in the context of such relationship. AMLA preferred a fully horizontal structure to horizontal parts plus sector-specific sections, and a principle-based approach to a prescriptive one, reasoning that prescriptive rules tend to encourage formalistic, tick-the-box compliance. The draft states outcomes and leaves the tools to you.

The general principles come first. Obliged entities should conduct ongoing monitoring including regular risk-based reviews and updates to customer information, and should also monitor transactions and activities to identify unusual or suspicious behaviour requiring further assessment. Monitoring should not be limited to transaction monitoring but should also capture relevant activities, behaviours and events. Article 26(2) AMLR sets the maximum periods of time for updating customer information for both higher-risk customers and all the other customers, and the draft adds that obliged entities should decide whether more frequent updates are needed based on the customer's risk profile, and that a review carried out earlier than scheduled can reset the timeline for the next required update.

Guideline 1 covers keeping documents, data or information up to date, through periodic and event-driven reviews. Its most practical proposal concerns expired identity documents, passports or equivalent, which are not required to be re-collected by default, but only where justified on the basis of a proper risk assessment. AMLA preferred this to automatic updating of all expired documents, on the view that the expiry of an identity document does not, in itself, necessarily indicate an increased risk of ML or TF. Where an update is judged necessary, the entity should determine, based on the level of risk, whether the document needs to be updated without delay or at the next scheduled review or next customer interaction.

Guideline 2 covers the transaction and activity monitoring framework. Monitoring may be manual, automated or semi-automated, as long as it is explainable, regularly tested, properly documented, and proportionate to the size, nature, complexity, transactions and activities volume, and risk exposure of the obliged entity. Entities that structurally have limited or no access to transaction and activity data, or that do not process transactions, should adjust the framework and apply proportionate alternative measures, while ensuring the limitations do not result in gaps. Such limitations should not, in themselves, be considered a deficiency, provided they are understood, documented and appropriately mitigated. Automated and advanced analytical tools, including AI, should be considered where they enhance the identification and escalation of ML/TF risks, but their use is neither mandatory nor, in itself, an indicator of effectiveness.

Proportionality, the paper says, should not be understood as implying lower or weaker standards for smaller obliged entities. Size is one factor alongside the overall risk profile, the complexity and scale of activities and operations, the business model and the nature of the business.

Read it against your own file, then write. The date is 3 September 2026.

Not legal advice. Verify against the primary source before acting.

Sources

Published 21 August 2026 · Regulator commentary
Drafted with AI assistance. Reviewed, edited and approved before publication by a named person at Ioannou & Sharpe LLC, who takes editorial responsibility for its content. Approved by Harris Sharpe, 24 August 2026.

Screen against the current lists in seconds

FIRMCY screens names against all of the lists above — plus a worldwide PEP database and adverse media — with fuzzy matching and an audit-ready report for every check. New organisations get 100 free credits, no card required.

Start screening free Free PEP & sanctions check FATF high-risk countries Weekly AML briefing Live on Telegram ↗
© 2026 Ioannou & Sharpe LLC · VAT CY60007091D · Griva Digeni, Limassol Center, Block B, 3rd Floor, Office 304, 3095 Limassol, Cyprus · [email protected]
Not legal advice. FIRMCY publishes this analysis for general informational purposes; verify against the primary sources before acting.