EU law lets five years pass before you recheck who owns a customer.
EU law caps the gap between customer information updates at five years, or one for higher risk. AMLA’s operational guidelines are still in draft.
Article 26 of the EU anti-money laundering regulation sets outer limits on how stale customer information may become: one year for higher risk customers, five years for everyone else. A company’s owners and directors can change many times inside that window. The rules that would close the gap are still in draft.
The outer limit is five years
Article 26(2) of Regulation (EU) 2024/1624 says the gap between updates of customer information shall not exceed one year for higher risk customers, or five years for all others.
Those are ceilings, not schedules
The period must depend on the risk posed by the business relationship. Five years is the longest permitted gap for a low risk customer, not a recommended cycle.
Three events force a review in between
Article 26(3): a change in the customer’s relevant circumstances, a legal obligation to contact them about beneficial ownership, or becoming aware of a relevant fact.
The regulator’s words are periodic and event-driven
AMLA describes the model as periodic and event-driven reviews applied on a risk-based approach. Continuous monitoring is required for transactions, not for customer information.
The detail is still being written
AMLA published draft guidelines on 3 June 2026. The consultation closes on 3 September 2026. Article 26(5) had set a deadline of 10 July 2026.
Company data moves faster than the floor
Directors resign, shareholdings transfer and entities are struck off continuously. Nothing about a five-year ceiling makes a four-year-old ownership record accurate.
A business verification is accurate on the day it is done and decays from then on
Verifying a business means establishing who owns and controls it. Under EU anti-money laundering law that means identifying the beneficial owner, the real human being behind the company. Unlike a person’s identity, that answer is not stable: shares change hands, directors resign, holding structures are reorganised and companies are struck off.
The consequence is specific. An obliged entity, meaning a firm the anti-money laundering rules apply to, can complete a perfect check on Monday and hold a false picture by the following quarter. Nothing failed. The world moved.
That is the difference between verifying a person and verifying a company. A passport photograph and a date of birth stay true. A shareholder register does not. Any rule about how often to look again is therefore doing more work in business verification than it does in individual identity checks, which is what makes the numbers in Article 26 worth reading closely.
The same problem shows up wherever a regime pulls in sectors that hold long customer relationships, as AUSTRAC’s Tranche 2 reforms do in Australia.
Article 26 sets a ceiling on staleness, not a monitoring schedule
Article 26(2) of Regulation (EU) 2024/1624 makes the period between updates of customer information depend on the risk posed by the business relationship. It then sets a hard cap. The gap "shall not in any case exceed" one year for higher risk customers, or five years for all others.
The regulation is the EU’s single anti-money laundering rulebook, known as AMLR, and it applies directly in every member state rather than being transposed into national law first.
Read the sentence carefully, because the structure matters more than the numbers. The period "shall be dependent on the risk posed by the business relationship". The one and five year figures are the point past which a gap becomes unlawful regardless of risk. A firm that reviews every low risk customer on a five-year cycle has not satisfied Article 26(2); it has satisfied the ceiling and skipped the risk assessment that determines the actual interval.
It is also worth being precise about what "ongoing monitoring" covers. Article 26(1) requires monitoring of the business relationship including the transactions carried out during it. Continuous observation applies to transactions and activity. Customer information, including who owns the company, is governed by the review cycle instead. The distinction matters when a review does surface something, because that is the point at which a reporting obligation with its own deadlines can begin.
Three events require a review before the clock runs out
Article 26(3) of Regulation (EU) 2024/1624 requires an obliged entity to review and update customer information when any of three things happens, regardless of where the periodic cycle stands. AMLA calls these event-driven reviews, as distinct from the predefined intervals of a periodic review.
The three triggers, in the regulation’s own words, are:
- "there is a change in the relevant circumstances of a customer"
- the entity has "a legal obligation in the course of the relevant calendar year to contact the customer for the purpose of reviewing any relevant information relating to the beneficial owners", or to comply with Council Directive 2011/16/EU on administrative cooperation in taxation
- "they become aware of a relevant fact which pertains to the customer"
The first and third are broad by design and place the burden on noticing. A change in circumstances only triggers a review if someone registers that it happened, and a firm becomes aware of a relevant fact only if something surfaces it. Neither obligation specifies where to look.
AMLA’s draft addresses one concrete case. During an update under Article 26(2), or an event-driven review under Article 26(3), obliged entities "should assess whether expired identity documents, passports or equivalent should be updated, including for natural persons or beneficial owners in respect of a legal entity". Beneficial owners of a company are named explicitly.
The operational standard is open for comment until 3 September 2026
The Authority for Anti-Money Laundering and Countering the Financing of Terrorism, known as AMLA, published a 57-page consultation paper on 3 June 2026 setting out draft guidelines on ongoing monitoring. Responses are due by 3 September 2026. A public hearing was held on 2 July 2026.
Two dates sit beside each other in the record. Article 26(5) of AMLR states that "by 10 July 2026, AMLA shall issue guidelines on ongoing monitoring of a business relationship". The consultation on the draft does not close until 3 September 2026. As at 28 July 2026 the guidelines remain in draft.
What the draft proposes is a two-part structure. The first part covers keeping customer documents, data and information up to date "through both so called periodic and event-driven reviews, applied in line with a risk-based approach". The second covers designing and testing a framework to detect unusual transactions and activity, which may include pre-transaction checks, real-time monitoring or post-transaction review depending on the business.
On frequency the draft declines to set a number. It says the frequency and extent of updates "should be risk-based", taking into account the customer’s risk level and overall risk profile, and the information already held. The outer limits in Article 26(2) remain the only fixed figures.
For a firm building a review cycle now, the practical position is that the boundaries are fixed and the method is not. That is a familiar shape: the duty exists in the regulation, the specification is being written separately, and the same pattern is visible in the FCC’s work on identity checks for phone companies.
If you are responding
The consultation window is open for another five weeks
AMLA lists its specific questions in section 5.2 of the consultation paper. It says comments are most useful when they respond to a stated question, give a clear rationale, provide supporting evidence, and describe alternative regulatory choices AMLA should consider. Responses close on 3 September 2026. All contributions are published afterwards unless confidentiality is requested.
Key takeaways
- Five years is a ceiling, not a cycle. Article 26(2) makes the interval depend on risk. The one and five year figures are the points beyond which a gap is unlawful whatever the risk assessment says.
- Customer information and transactions are governed differently. Continuous monitoring applies to transactions and activity. Customer information, including beneficial ownership, runs on periodic review plus triggers.
- Two of the three triggers depend on noticing. A change in circumstances and becoming aware of a relevant fact both require something to surface first. Article 26(3) does not say where to look.
- The method is still open. AMLA’s draft guidelines set no frequency beyond the Article 26(2) limits, and the consultation runs to 3 September 2026.
Using Didit for the review cycle Article 26 describes
Article 26 needs two different things at two different moments, and they map to different checks. Business Verification (KYB) establishes ownership and control at onboarding and can be re-run at a periodic review, returning the current register position rather than the one captured last time. Company AML Screening and Person AML cover the sanctions and politically exposed person checks on the entity and on the people behind it. Key People Extraction pulls the directors and officers a review has to look at.
Published rates are $2.00 per Business Verification (KYB) bundle, $0.20 per KYB Documents check, and $0.20 for Company AML Screening or Person AML. Key People Extraction is free. Current module prices are listed on the pricing page.
What none of this decides is when to look. Four things stay with the obliged entity: setting the review interval, judging whether a change in circumstances is material, deciding what counts as a relevant fact, and recording why an interval was chosen. Article 26(2) makes the period a function of that entity’s own risk assessment. Re-running a check is a task; deciding it was due is a judgement, and the regulation puts that judgement on the firm.
Common questions
How often does AMLR require you to update customer information?
Article 26(2) of Regulation (EU) 2024/1624 says the period between updates depends on the risk of the business relationship and shall not in any case exceed one year for higher risk customers, or five years for all other customers. Those are outer limits, not recommended intervals. A shorter cycle may be required by the risk.
Does AMLR require continuous or perpetual monitoring of customer information?
Not of customer information. Article 26 sets periodic review at risk-based intervals, plus event-driven review when a trigger in Article 26(3) occurs. AMLA describes this as periodic and event-driven reviews applied in line with a risk-based approach. Continuous monitoring applies to transactions and activities, which is a separate obligation.
What events trigger a review under Article 26(3)?
Three. A change in the relevant circumstances of a customer. A legal obligation during the calendar year to contact the customer to review beneficial ownership information, or to comply with Council Directive 2011/16/EU. And becoming aware of a relevant fact pertaining to the customer.
Are AMLA’s ongoing monitoring guidelines final?
No. AMLA published a consultation paper on the draft guidelines on 3 June 2026 and the consultation closes on 3 September 2026. Article 26(5) of AMLR set a deadline of 10 July 2026 for AMLA to issue them. As at 28 July 2026 the guidelines remain in draft.
Related reading
- The FCC wants phone companies to run bank-style KYC — A duty written into the rules years ago, with the specification arriving separately.
- AUSTRAC Tranche 2 for dealers in precious metals & stones — What customer due diligence looks like for a sector entering an AML regime for the first time.
- Regulators are asking prediction markets about identity, not trading — The same question arriving in a sector that has largely operated without it.
- The new AUSTRAC SMR form (2026) — What happens after a review surfaces something that looks wrong.
Sources
- Regulation (EU) 2024/1624 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing — EUR-Lex · Article 26 · 31 May 2024
- Consultation Paper: Draft Guidelines on ongoing monitoring of a business relationship under Article 26(5) of Regulation (EU) 2024/1624 — AMLA, Frankfurt am Main · 3 June 2026
- Consultation on the draft Guidelines on ongoing monitoring of a business relationship — AMLA · open until 3 September 2026
Who wrote this
Tuan Nguyen — Growth · Didit
Writes about identity verification, fraud and compliance at Didit. This piece was written from the text of Article 26 and AMLA’s own consultation paper rather than from secondary summaries. The regulation’s own vocabulary is periodic and event-driven review, and that is the vocabulary used here.
Last reviewed 28 July 2026 against the sources above
Related articles
- Europe's deepfake rule is now in force, and it lands on the tool, not the fraud
- AI is now on both sides of the gambling identity check
- The stablecoin identity rule covers issuance and redemption, not what happens next
- Egypt is absorbing the cost of a KYC refresh instead of passing it to the customer
- Unico Partners with Didit to Expand Access to State-of-the-Art Identity Verification for SMEs in Brazil
- Didit vs Onfido: coverage, pricing, automation, and migration