Swootle Book a demo

Compliance / Swootle Research / 2026-07-18

EU AMLR Article 26 explained: relationship and transaction monitoring, customer-update intervals, event-led review and implementation controls.

EU AMLR Article 26: ongoing monitoring, customer updates and transactions

EU AMLR Article 26 requires obliged entities to monitor business relationships and customer transactions, keep relevant customer documents, data and information up to date, and review that information when risk or other relevant facts change. It is not a requirement to run one undifferentiated “perpetual KYC” process. Article 26 brings several related controls together, but customer-due-diligence refresh, transaction or activity monitoring, and targeted-financial-sanctions screening still have different purposes and evidence.

This guide explains the legal mechanics in plain language, then translates them into questions for compliance, operations and implementation teams. The governing text is Regulation (EU) 2024/1624 on EUR-Lex. AMLA has also opened a consultation on draft Article 26(5) guidelines. The consultation opened on 3 June 2026 and closes on 3 September 2026; the guidance is a DRAFT consultation and is not final.

What Article 26 actually covers

Article 26 is headed “Ongoing monitoring of the business relationship and monitoring of transactions performed by customers”. Paragraph 1 requires ongoing monitoring of the relationship, including transactions undertaken throughout it. The test is whether transactions are consistent with the obliged entity’s knowledge of the customer, the customer’s business activity and risk profile and, where necessary, information about the origin and destination of funds. It also requires the entity to detect transactions that need a more thorough assessment under Article 69(2).

That is a relationship-level obligation, not merely an alert queue. A usable operating model should let the firm understand what it knows about the customer, what activity it is assessing, what risk profile applies, which information was relevant, and why a transaction or activity was or was not escalated.

Paragraph 2 addresses the information side of ongoing monitoring. The relevant customer documents, data or information must be kept up to date. The update period depends on the risk posed by the business relationship and has an outer limit: one year for higher-risk customers to which Section 4 measures apply, and five years for all other customers.

Paragraph 3 adds event-led review. The customer information must be reviewed and, where relevant, updated when there is a change in the customer’s relevant circumstances, when the obliged entity has a legal obligation during the relevant calendar year to contact the customer for the purpose of reviewing beneficial-owner information or complying with Council Directive 2011/16/EU, or when the entity becomes aware of a relevant fact about the customer.

The exact control model

The following table separates the operative parts of Article 26 in the official EUR-Lex text so that a firm can map each one to an owner, workflow, data source and retained evidence.

Article 26 control Exact practical meaning Maximum or trigger Evidence a firm should be able to produce
Article 26(1): ongoing relationship monitoring Monitor the business relationship and the customer’s transactions throughout the relationship. Test consistency with knowledge of the customer, business activity, risk profile and, where necessary, origin and destination of funds. Runs throughout the relationship; activity that needs deeper assessment is identified for the Article 69(2) process. The activity or transaction assessed, relevant customer context, risk profile used, outcome, escalation and reviewer rationale.
Article 26(2): customer information updates Keep relevant customer documents, data and information up to date as part of ongoing monitoring. Update interval depends on relationship risk and must not exceed one year for higher-risk Section 4 customers or five years for all others. The information requested, what was supplied, what changed, review date, unresolved gaps and resulting decision.
Article 26(3): event-led review Review and, where relevant, update customer information after changed circumstances or a relevant fact, or when the specified legal obligation to contact the customer applies. Starts when the relevant circumstance, fact or legal contact obligation is identified; it does not wait for the periodic limit. Trigger, source, affected customer or relationship, targeted questions or documents, decision and any revised risk route.
Article 26(4): targeted-financial-sanctions verification Regularly verify whether the conditions in Article 20(1)(d) are met, with frequency proportionate to exposure and risk of non-implementation or evasion. Additional verification applies; for credit and financial institutions it also occurs on a new targeted-financial-sanctions designation. Screening or verification result, provider or source, match handling, review outcome and escalation where applicable.

The table is a control interpretation, not a substitute for reading the Regulation, applicable national measures or supervisory expectations. It is useful because it prevents a firm from treating “ongoing monitoring” as one feature that is either switched on or switched off.

Three controls that should not be collapsed

1. Customer-due-diligence refresh

CDD refresh keeps the firm’s understanding of the customer current. It may involve identity details, purpose and intended nature of the relationship, business activity, ownership and control, source or destination information where relevant, documents, and the risk factors used in the relationship assessment. The request should be proportionate to what changed or what the risk-based review requires.

The outer intervals in Article 26(2) are important planning constraints, not a complete review design. A higher-risk customer in scope for Section 4 measures cannot be left more than one year between updates, while other customers cannot be left more than five years. Event-led reviews can arise earlier. A refresh flow should therefore record both the periodic reason and the event or fact that caused a targeted review.

2. Transaction and activity monitoring

Transaction or activity monitoring looks at what the customer does in the relationship. Article 26 asks whether transactions are consistent with the firm’s knowledge of the customer, business activity and risk profile, and where necessary with information about the origin and destination of funds. It is not satisfied by asking the customer to confirm a static profile once a year.

The execution method will vary by sector and business model. It may involve internal data, an external transaction-monitoring system, manual review, risk-based rules, or a combination. The important control question is how an activity or transaction becomes an assessment, how relevant customer context is made available, when deeper assessment is required, and how the outcome is retained. A workflow can support the intake, questions, escalation and decision record without being the runtime that observes every transaction.

3. Screening and targeted-financial-sanctions verification

Screening is a separate control boundary. Article 26(4) addresses regular verification of whether the conditions in Article 20(1)(d) are met and says that the frequency should reflect exposure to the risks of non-implementation or evasion of targeted financial sanctions. It also says that this does not replace the obligation to apply targeted financial sanctions or stricter requirements under other Union or national law.

In practice, a screening provider may return a possible match or status change. That result still needs a documented review, disposition and escalation path. Screening is not the same as a CDD refresh, because a clear screening result does not prove that ownership, purpose or business activity information is current. It is also not the same as transaction monitoring, because a name-list result does not by itself assess whether activity is consistent with the relationship.

The same customer record can connect all three controls, but the record should preserve which control ran, why it ran, what evidence or result it used, and who decided what happened next.

A practical Article 26 design starts with a relationship record and makes the control states visible. At onboarding, the firm establishes the initial customer understanding and risk profile. During the relationship, activity-monitoring inputs and screening results may create work. At a periodic or event-led review, the customer receives only the questions and document requests needed for the approved scope. A reviewer assesses the new information, updates the relevant risk context, and records whether the relationship continues, needs more evidence, requires approval or should be escalated.

This does not mean every review must be a full re-onboarding journey. A changed director may require an entity and relationship update, evidence of authority and a screening review. An expired document may need a replacement request and a reviewer check. A new service may require questions about purpose, expected activity and risk. A relevant transaction-monitoring concern may need a case assessment rather than a generic customer questionnaire. The design should distinguish these paths while preserving their relationship to the same customer context.

For each path, define the trigger, scope, data owner, customer communication, evidence request, reviewer role, decision options, escalation route, retention rule and next action. If a provider or event source is outside the workflow, document the handoff and the result that must return. A generic API or an alert notification is not, by itself, evidence that the Article 26 control is complete.

Transition status and the AMLA consultation

Regulation (EU) 2024/1624 is in force, but Article 90 says that it applies from 10 July 2027. The exception is for obliged entities referred to in Article 3, points (3)(n) and (o), for which it applies from 10 July 2029. Firms should confirm whether their entity type falls within that exception rather than assuming that every business shares the later date.

AMLA’s Article 26(5) consultation opened on 3 June 2026 and closes on 3 September 2026 at 23:59 CEST. Its draft material covers general principles, keeping customer information up to date, and the transaction and activity monitoring framework. It is useful for planning and consultation responses, but it is not final guidance and should not be presented as a settled supervisory interpretation. Keep the implementation register dated, record assumptions, and revisit the design when final material and relevant competent-authority expectations are available.

Implementation questions for compliance and operations

Before selecting or configuring a system, ask:

  • Which customer documents, data and information are relevant for each service, relationship type and risk level?
  • Which customers are subject to Section 4 higher-risk measures, and how is the one-year maximum update interval calculated and evidenced?
  • How is the five-year maximum for all other customers controlled without relying on an unowned spreadsheet?
  • Which changed circumstances and relevant facts require an immediate or targeted review?
  • How will the firm identify the specified legal obligation to contact a customer for beneficial-owner information or Council Directive 2011/16/EU purposes?
  • What data source or team owns transaction and activity monitoring, and what exact result must be handed into review?
  • Which screening or targeted-financial-sanctions provider is used, what does it return, and who handles possible matches?
  • Can reviewers see the prior context, new submission, provider result, decision, approval and unresolved gap together?
  • Which decisions require senior approval, a deeper Article 69 assessment, a restriction, or escalation to the compliance officer?
  • What will be retained, exported and reviewed by management or a competent authority?

The workflow and control design can be explored against a representative scenario in the EU AML workflows guide. For a product discussion, see ongoing monitoring workflows and book a demo.

Where Swootle can fit

Swootle can provide a configurable workflow layer for the parts of Article 26 that require structured questions, document requests, branches, relationship information, risk decisions and human review. Teams can use the customer portal to collect a targeted refresh, configure questions and document requests for the relevant path, collect and relate entity or relationship information, apply configured risk logic, and route a case for human review or approval. Reusable refresh workflows can retain new submissions and the decision context that resulted from them.

That is workflow support, not a claim that Swootle performs every upstream or downstream control natively. External KYC, KYB and screening execution is provider-dependent. Workflow initiation, scheduling, event detection, transaction-monitoring runtime, provider selection and integrations are implementation responsibilities unless separately confirmed for the proposed deployment. Swootle should not be treated as claiming a native scheduler, automatic enrolment, continuous-monitoring runtime, native PEP/sanctions/adverse-media monitoring, universal ownership resolution, a complete immutable audit ledger or a complete export history. Confirm the handoffs, sources, retention and export requirements in the implementation plan.

Read the perpetual KYC software guide for the commercial category boundaries, or use the demo route to test a representative refresh and review scenario.

Frequently asked questions

Does Article 26 require annual KYC for everyone?

No. It requires relevant customer documents, data and information to be kept up to date at risk-based intervals, with a maximum of one year for higher-risk Section 4 customers and five years for all other customers. Event-led review can require action sooner.

Does the five-year interval mean a low-risk customer can be ignored for five years?

No. Five years is an outer limit for the update period for customers outside the specified higher-risk category. Changes in relevant circumstances, a relevant fact or the specified legal contact obligation can require review earlier. Transaction and activity monitoring and targeted-financial-sanctions verification remain separate ongoing controls.

Is Article 26 the same as perpetual KYC?

No. Perpetual KYC is a market term for an operating model that keeps customer understanding current through refresh and event-led work. Article 26 is the legal requirement. A product or workflow marketed as perpetual KYC still needs to be mapped to the precise CDD, transaction-monitoring and sanctions-verification controls.

Is the AMLA Article 26 guidance final?

No. The AMLA consultation opened on 3 June 2026 and closes on 3 September 2026. The published material is draft consultation guidance, so firms should monitor the final outcome and relevant competent-authority communications.

When does the AMLR apply?

The Regulation generally applies from 10 July 2027. Article 3, points (3)(n) and (o), have the specified later application date of 10 July 2029. Confirm the entity classification and any other applicable transition requirements with qualified advisers.

Can a workflow product prove compliance with Article 26?

No product can replace the firm’s legal analysis, control ownership or accountable judgement. A workflow can make requests, branches, evidence, review and decisions more consistent and inspectable. The firm still needs to define policy, supply or connect relevant data, operate provider and monitoring arrangements, retain appropriate records, and test whether the implemented process meets its obligations.

Review and maintenance

Swootle Compliance Research reviewed this page against the official EUR-Lex text and AMLA consultation page on 4 August 2026. Read about the team’s compliance-operations background. This editorial review is not a named legal opinion; firms should use qualified advisers for their own interpretation and implementation.

Disclaimer

This page is general information for research and implementation planning. It is not legal advice, a complete interpretation of Regulation (EU) 2024/1624, final AMLA guidance, or a substitute for advice from qualified counsel and the relevant competent authorities. Requirements may depend on the entity, service, Member State, sector and other applicable Union or national measures. Check the current EUR-Lex text and AMLA consultation page before finalising controls.

This guide was materially updated on 4 August 2026. Its original publication date remains 18 July 2026.

Put the guide into practice

Map Article 26 controls to a representative workflow

Bring one anonymised representative case. We will map the customer request, evidence, exceptions and accountable decision, then identify whether Swootle fits the operating model.

Book a workflow review

Review enterprise pricing