One of the most common misconceptions in AML compliance is the belief that screening a customer once, at the point of onboarding, is enough to satisfy a business's obligations. It is not. A customer who presents no financial crime risk on the day they are onboarded may become a sanctioned individual, a Politically Exposed Person, or the subject of adverse media weeks, months, or years later. This is the fundamental distinction between once-off AML screening and continuous AML monitoring, and understanding it is essential for any South African business with AML obligations.
This guide explains the difference between the two approaches, why once-off screening alone is insufficient, and what South African law actually requires.
For a foundational explanation of what AML screening involves, refer to our guide: What is AML Screening? PEP, Sanctions & Adverse Media Explained.
What is Once-Off AML Screening?
Once-off AML screening, also known as point-in-time screening, is the process of screening a customer against AML risk indicators at a single moment, typically during onboarding. It checks whether the customer appears on any sanctions lists, is a Politically Exposed Person, or features in adverse media at that specific point in time.
Once-off screening establishes a customer's risk profile at the start of the relationship. It answers the question: based on the information available today, does this customer present a financial crime risk? This is an essential first step, and for many lower-risk relationships it forms the foundation of the due diligence process. However, it captures only a single snapshot in time.
What is Continuous AML Monitoring?
Continuous AML monitoring, also known as ongoing monitoring, is the process of repeatedly re-screening a customer throughout the entire life of the business relationship. Rather than checking a customer's risk profile only once, continuous monitoring re-checks it on an ongoing basis, automatically detecting any change in the customer's status.
Continuous monitoring answers a different and equally important question: has anything changed since this customer was onboarded? If a customer is added to a sanctions list, becomes a PEP, appears in adverse media, or begins transacting in a way that departs from their established pattern, continuous monitoring detects it and raises an alert. This transforms AML compliance from a single event into an ongoing control that operates for as long as the customer relationship lasts.
Once-Off Screening vs Continuous Monitoring: The Key Differences
The two approaches differ across several important dimensions.
- On timing, once-off screening occurs at a single point, usually at onboarding. Continuous monitoring occurs repeatedly throughout the relationship.
- On what they detect, once-off screening detects risk that exists at the moment of the check. Continuous monitoring detects risk that emerges at any time after onboarding, which is precisely the risk that once-off screening cannot see.
- On the question they answer, once-off screening confirms whether a customer is safe to onboard today. Continuous monitoring confirms whether a customer remains within acceptable risk parameters over time.
- On their limitations, once-off screening becomes outdated the moment it is completed, because a customer's circumstances can change immediately afterwards. Continuous monitoring addresses this by keeping the risk assessment current.
- On their relationship to each other, the two are not alternatives but complementary stages of a single compliance lifecycle. Once-off screening establishes the baseline, and continuous monitoring maintains it.
Why Once-Off Screening Alone is Not Enough
The central weakness of relying on once-off screening is simple: risk is not static. A customer's circumstances, associations, and status can change at any time, and a clean screen at onboarding provides no protection against risk that emerges later.
Consider a customer who is onboarded with a clean AML screen. Six months later, that customer is appointed to a senior government position, making them a Politically Exposed Person who now requires Enhanced Due Diligence. Or consider a customer who, a year after onboarding, is added to an international sanctions list. Without continuous monitoring, a business would have no way of knowing about either change, and would continue to do business with a customer who now presents a serious compliance risk. The business would, in effect, be in breach of its obligations without even being aware of it.
This is why compliance does not end at onboarding. Increasingly, the point at which South African AML compliance fails is not onboarding but the period afterward, when monitoring, risk tracking, and reporting are treated as disconnected from the original due diligence rather than as a continuous control. For high-risk customers in particular, the obligation to maintain ongoing scrutiny is continuous. For a detailed explanation of how to handle high-risk clients, refer to our guide: How to Conduct Enhanced Due Diligence on High-Risk Clients in South Africa.
What Does FICA Require?
In South Africa, continuous monitoring is not optional. The Financial Intelligence Centre Amendment Act (FICA) requires Accountable Institutions to conduct ongoing due diligence and monitoring of their business relationships, not merely to screen customers at onboarding.
This obligation forms part of the broader customer due diligence framework that FICA establishes. Accountable Institutions must monitor transactions on an ongoing basis to ensure they are consistent with the institution's knowledge of the customer, keep customer information current, and detect and report suspicious activity. Suspicious Transaction Reports must be submitted to the Financial Intelligence Centre, and the obligation to monitor applies throughout the relationship, not just at its start. For an explanation of which businesses carry these obligations, refer to our guide: What is an Accountable Institution? FICA Obligations Unpacked.
The regulatory stakes are significant and rising. Following South Africa's removal from the FATF greylist on 24 October 2025, with the next FATF mutual evaluation due to begin in late 2026, enforcement intensity is expected to remain elevated. The FIC has increasingly emphasised that compliance controls must be demonstrably effective across the full customer lifecycle, and an institution that screens once but fails to monitor continuously is exposed on precisely this point.
How Continuous Monitoring Works in Practice
In practice, continuous AML monitoring is made possible by automation. Manually re-screening an entire customer base on a regular basis would be impractical for all but the smallest businesses. Automated monitoring solves this by continuously re-checking customers against updated sanctions, PEP, and adverse media databases, and by flagging any change for review.
When a customer's status changes, an automated monitoring system raises an alert that routes to the relevant compliance team for assessment and action. This allows a business to respond promptly to emerging risk, such as escalating a newly identified PEP to Enhanced Due Diligence or taking appropriate action when a customer is sanctioned. Automated monitoring can also incorporate transaction monitoring, which flags activity that deviates from a customer's established behavioural pattern. For a detailed explanation of the screening components that underpin monitoring, including PEP, sanctions, and adverse media checks, refer to our guide: What is AML Screening? PEP, Sanctions & Adverse Media Explained.
Which Approach Does Your Business Need?
For practically every Accountable Institution, the answer is both. Once-off screening and continuous monitoring are not competing options but sequential stages of a complete AML programme. Once-off screening establishes the customer's risk profile at onboarding, and continuous monitoring keeps that profile current for the life of the relationship.
The depth and frequency of monitoring should be calibrated to risk under South Africa's Risk-Based Approach. Lower-risk customers may be monitored less frequently, while higher-risk customers, including foreign PEPs, require continuous and detailed monitoring. What no Accountable Institution can do, however, is treat onboarding screening as the end of its obligations. FICA treats AML compliance as an ongoing duty, and a compliant business must do the same.
AML Screening and Monitoring Solutions for South African Businesses
As South Africa's leading provider of world-class AML screening and monitoring solutions, ThisIsMe gives businesses the tools they need to screen customers at onboarding and monitor them continuously thereafter. Our AML solutions screen against comprehensive sanctions, PEP, and adverse media databases, and our ongoing monitoring automatically re-screens your customer base, raising alerts the moment a customer's risk profile changes. This ensures that your AML compliance operates as a continuous control across the full customer lifecycle, exactly as FICA requires. To experience our full suite of AML screening and monitoring solutions and find out how we can serve your business, contact our team here.

