Ask a small Irish firm how it monitors clients and the most common answer is some version of "we review the file every year or two". That answer quietly merges two different obligations into one — and the gap between them is where compliance failures live. Ongoing monitoring and periodic review are related but distinct duties, they exist under the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 today, and they carry straight through into the EU's AML Regulation (the AMLR, Regulation (EU) 2024/1624) when it applies on 10 July 2027. If your programme only does one of them, it is doing half the job.
What is ongoing monitoring?
Ongoing monitoring is continuous attention to the relationship while it is live. It has two strands:
- Scrutinising activity. Watching the transactions and instructions flowing through the relationship and asking whether they are consistent with what you know about the client — their business, their risk profile, their stated purpose in engaging you. The bookkeeping client whose turnover triples with no visible reason; the conveyancing client whose deposit arrives from an unconnected third party; the company-services client whose dormant entity suddenly starts moving funds.
- Keeping CDD current. Making sure the documents, data and information underpinning the relationship do not go stale — and refreshing them when something tells you they have.
The defining feature is that ongoing monitoring is event-driven and always on. It is not something you do to a file in an annual sitting; it is the discipline of noticing, in the ordinary course of work, when reality stops matching the file.
What is a periodic review?
A periodic review is scheduled. On a cycle set by the client's risk tier — shorter for higher risk, longer for lower — you deliberately re-open the file and re-check it: is the identity and verification evidence still current, has beneficial ownership changed, do screening results need refreshing, is the risk rating still right, and does the activity you have seen since the last review still fit the client's profile?
The defining feature here is that the review happens whether or not anything has caught your eye. It is the safety net under ongoing monitoring: the mechanism that catches slow drift no single event ever flagged.
Why does the distinction matter in practice?
Because each duty fails differently, and each failure is invisible to the other:
| Ongoing monitoring | Periodic review | |
|---|---|---|
| Trigger | Events, anomalies, changes | The calendar |
| Cadence | Continuous | By risk tier |
| Catches | The sudden and the suspicious | The slow and the stale |
| Typical failure | Nobody escalates what they see | Reviews are scheduled but never done |
A firm that only does annual reviews can process a suspicious transaction in month two and not look at it until month twelve. A firm that relies only on alert staff can carry a ten-year-old passport copy on a perfectly quiet file forever. Supervisors can test both failures easily: one by asking what happened after a specific event, the other by asking for the review log.
Where do trigger events fit?
Trigger events are the bridge between the two duties: specific occurrences that force an out-of-cycle review regardless of the calendar. A workable small-firm trigger list includes a change in beneficial ownership or control, a new screening hit (sanctions, PEP or adverse media), a transaction materially out of pattern, a change in the client's business or jurisdictional footprint — including a country moving onto the EU high-risk third-country list — and expiry of identity documents. When a trigger fires, the file gets a review now, and the periodic clock restarts.
If monitoring surfaces actual suspicion, monitoring turns into reporting: Suspicious Transaction Reports are dual-reported in Ireland, to FIU Ireland via the goAML portal and to the Revenue Commissioners via ROS.
What does the AMLR expect from 10 July 2027?
The AMLR carries both duties into the directly applicable EU rulebook and raises the evidential stakes around them. Records must be retained for 5 years and then deleted, so your monitoring and review trail needs to live somewhere systematic. FIU information requests must be answered within 5 working days, which assumes your files are current and retrievable. And the prescribed compliance roles — a board-level compliance manager and a compliance officer of sufficiently high standing — give the review backlog a named owner. A review schedule with no owner is how backlogs become findings.
What to do now
- Separate the two duties in your written procedures: define ongoing monitoring, define periodic review, and stop using one word for both.
- Set review cycles by risk tier and write them down — then check how many reviews are currently overdue.
- Adopt a short trigger-event list and train staff that a trigger means a review now, not a note for later.
- Give the review schedule a named owner and a standing slot, so it survives busy months.
- Record every review and every escalation decision, including "reviewed, no change" — the trail is the evidence.
Where CompliDesk fits
CompliDesk Ireland runs both halves for you: trigger-based flags on client activity and screening changes, plus a review schedule that surfaces what is due and records what was done. See pricing for what that costs a small firm.
General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.