Customer due diligence is the initial and periodic process of identifying customers, verifying identities, understanding ownership and purpose, and assigning risk. Ongoing monitoring is the continuous review of transactions and behaviour after onboarding to spot unusual patterns and update risk assessments. Together, they cover both entry into the relationship and surveillance throughout its lifecycle, which is essential for effective AML control.
Why This Matters for Security Teams
customer due diligence and ongoing monitoring are often discussed together, but they serve different control objectives. Due diligence is the gatekeeping function: it establishes who the customer is, whether the relationship is lawful, and what level of risk is acceptable at onboarding. Ongoing monitoring is the control that proves the relationship still makes sense over time, especially when transaction patterns, ownership, geography, or behavioural signals change. For AML teams, separating these functions is essential to avoid blind spots in escalation, sanctions screening, and suspicious activity reporting.
That distinction matters because weak onboarding cannot be fixed by strong monitoring alone, and strong onboarding can become stale if monitoring is treated as a box-ticking exercise. Current guidance from the FATF Recommendations — AML and KYC Framework places both within a risk-based model, where controls should be proportionate to customer type, product, and exposure. For security leaders, the practical question is whether identity, transaction, and behavioural data are connected well enough to surface risk when it emerges. In practice, many institutions discover gaps in monitoring only after unusual activity has already passed through an otherwise compliant onboarding process.
How It Works in Practice
Customer due diligence typically happens before or at the start of a relationship. It includes identifying the customer, verifying beneficial ownership where relevant, understanding the expected purpose of the account, and assigning an initial risk rating. enhanced due diligence is used for higher-risk cases such as politically exposed persons, complex ownership structures, or cross-border activity. The output is a documented baseline that tells the institution what normal should look like.
Ongoing monitoring starts after onboarding and continues for the life of the relationship. It uses transaction monitoring, sanctions and watchlist screening, adverse media review where appropriate, and periodic reviews to compare actual behaviour against the expected profile. It is not just a fraud-detection layer. It is also a risk-management process that can trigger updated due diligence, account restrictions, or suspicious activity reporting when patterns change. Industry practice increasingly treats customer behaviour, device signals, and payment rails as complementary inputs, although there is no universal standard for this yet.
- Due diligence answers: who is this customer, why are they here, and how risky are they?
- Ongoing monitoring answers: does their activity still match the expected relationship?
- Due diligence is mostly identity and relationship formation; monitoring is lifecycle surveillance and refresh.
- Monitoring findings often feed back into due diligence when risk indicators change materially.
For organisations with digital onboarding, the identity control layer matters as much as the AML workflow. If verification is weak, monitoring inherits bad data and false confidence. If monitoring rules are too rigid, they create alert fatigue and hide genuine anomalies. In practice, these controls tend to break down when customer records, payment data, and alert management sit in separate systems because the investigator cannot reconstruct a full behavioural picture.
Common Variations and Edge Cases
Tighter monitoring often increases alert volume and investigative overhead, requiring organisations to balance detection depth against operational capacity. That tradeoff is especially visible in correspondent banking, crypto-asset services, and high-volume digital platforms, where legitimate activity can look unusual at scale. Best practice is evolving toward risk-based tuning rather than one-size-fits-all thresholds.
One common edge case is when periodic due diligence is mistaken for ongoing monitoring. Periodic review updates the customer file, but it does not replace continuous transaction surveillance. Another is when monitoring is performed without a reliable customer profile, which makes exception handling inconsistent and weakens case decisions. Where identity verification is remote or synthetic identity risk is elevated, the link between onboarding assurance and lifecycle monitoring becomes even more important.
For teams mapping controls to policy, FATF sets the baseline expectation, but local rules may demand stricter refresh intervals, deeper beneficial ownership checks, or stronger evidence trails. The operational aim is not to choose one control over the other. It is to make sure due diligence creates a defensible starting point and ongoing monitoring keeps that starting point current.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63 and NIST CSF 2.0 set the technical controls, while DORA and PCI DSS v4.0 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | IAL2 | Identity proofing quality affects how reliable AML onboarding data will be. |
| NIST CSF 2.0 | GV.RM-01 | Risk management is central to deciding review depth and alert escalation. |
| DORA | Operational resilience matters when AML monitoring depends on continuously available data and workflows. | |
| PCI DSS v4.0 | Financial transaction oversight is relevant where AML monitoring overlaps with payment environments. |
Build resilient monitoring processes so investigations and alerting continue during disruption.
Related resources from NHI Mgmt Group
- What is the difference between customer identification and customer due diligence in AML compliance?
- What is the difference between customer due diligence and strong customer authentication here?
- What is the difference between customer identification and customer due diligence in Thailand compliance programmes?
- Why does enhanced due diligence need ongoing monitoring after onboarding?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 1, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org