How often should you run AML screening? Ongoing monitoring frequency explained
AML screening is not a one-time check completed at onboarding, it is a continuing obligation, because sanctions lists, PEP status, and adverse-media coverage all change after a customer relationship begins. There is no single fixed frequency FINTRAC prescribes; instead, the expectation is that screening frequency reflects the risk of the customer and the pace at which the underlying lists change. This guide explains what drives screening frequency, the difference between batch and continuous approaches, and how to set a cadence that holds up under examination.
AML screening frequency is how often a customer or transaction is re-checked against sanctions, PEP, and adverse-media lists after the initial onboarding screen. Because lists and customer circumstances both change over time, a single screen at onboarding only reflects risk as of that moment. FINTRAC does not mandate one universal frequency; the requirement is that a compliance program's monitoring, including screening cadence, be reasonably designed and risk-based, which is the standard Bill C-12 reinforced across every FINTRAC-regulated program.
Is onboarding screening enough on its own?
A customer who passes sanctions, PEP, and adverse-media screening on day one is not permanently cleared. Sanctions lists are updated on an ongoing basis as new designations are issued, a person can newly assume a public role that makes them a PEP, and adverse media can surface about a customer at any point after onboarding. Treating the onboarding screen as sufficient on its own leaves a program blind to exactly the changes screening exists to catch.
What drives screening frequency?
- Customer risk rating. The risk tier your AML risk assessment assigns should set how often that customer is re-screened, with high-risk relationships re-screened more often, or continuously, and low-risk relationships on a longer cycle.
- List update frequency. Sanctions lists can change with little notice, particularly around new ministerial directives, so a program's re-screening cadence needs to keep pace with how often the underlying lists actually change.
- Nature of the relationship. A one-time transaction has a different monitoring profile than an ongoing account relationship that persists for years.
- Regulatory posture and sector. Sectors under heavier scrutiny, or with a recent history of enforcement activity, generally warrant a more conservative, more frequent cadence.
Batch re-screening or continuous monitoring: which should you run?
Batch re-screening runs an entire customer book against updated lists on a fixed schedule, daily, weekly, or otherwise. It produces a large alert spike every time it runs, since the whole book is matched at once, which floods reviewers on run day and then goes quiet until the next cycle. It also leaves an exposure window open: a customer who becomes a sanctions match the day after a batch run would not be caught until the next scheduled run, which could be days or weeks away. Continuous monitoring instead applies matching to each relevant change as it happens, whether a list update or a change in customer data, producing a steadier, more manageable queue and closing that exposure window to close to real time.
How do you set a risk-based screening cadence?
A defensible cadence is not one fixed number applied to every customer. A workable structure looks like this: continuous or daily re-screening for high-risk relationships and any PEP or previously escalated customer, a shorter periodic cycle, such as weekly, for medium-risk relationships, and a longer periodic cycle, aligned with your standard review schedule, for low-risk relationships. Whatever structure is chosen, it should be written into policy, tied explicitly to the risk ratings your risk assessment produces, and revisited when the risk assessment itself is updated.
How does BriteBase run ongoing screening?
Our screening system re-screens continuously against refreshed sanctions, PEP, and adverse-media lists rather than on a fixed batch cycle, so new matches surface for disposition close to when they actually occur rather than at the next scheduled run. Agentic entity resolution is applied to every change as it happens, which keeps the resulting queue prioritized and manageable instead of producing periodic floods. The detail on how each list type is screened sits on the screening software page, and the product itself is on the AML screening solution page.
FAQ
Does FINTRAC set a required AML screening frequency?
No. FINTRAC does not prescribe a single universal frequency for AML screening. The requirement is that a compliance program's monitoring, including its re-screening cadence, be reasonably designed and risk-based, the standard Bill C-12 reinforced across every FINTRAC-regulated program. In practice that means frequency should track two things: the risk of the customer and the pace at which the underlying lists change. Higher-risk customers and relationships warrant more frequent, or continuous, re-screening than lower-risk ones, because a single screen only reflects risk as of the moment it runs. Sanctions lists are updated on an ongoing basis, PEP status can change when someone assumes a public role, and adverse media can surface at any time, so a cadence that made sense at onboarding can quietly fall behind. Whatever frequency you choose, it needs to be defensible under examination, which means tied to your risk ratings rather than picked arbitrarily.
Is screening only required at onboarding?
No. Onboarding screening is the starting point, not the whole obligation. Sanctions lists, PEP status, and adverse media all change after a customer relationship begins, so screening is a continuing obligation rather than a one-time check. A customer who clears every list on day one is not permanently cleared: new sanctions designations are issued on an ongoing basis, a person can newly assume a public role that makes them a PEP, and negative news can surface about a customer at any point after onboarding. Treating the onboarding screen as sufficient on its own leaves a program blind to exactly the changes screening exists to catch, which is why ongoing re-screening against refreshed lists matters. The question is not whether to re-screen after onboarding but how often, and that cadence should follow the customer's risk tier rather than a single schedule applied uniformly across the book.
What is the difference between batch and continuous screening?
Batch re-screening runs an entire customer book against updated lists on a fixed schedule, whether daily, weekly, or otherwise. Because the whole book is matched at once, it produces a large alert spike every time it runs, flooding reviewers on run day and then going quiet until the next cycle. It also leaves an exposure window open: a customer who becomes a sanctions match the day after a batch run would not be caught until the next scheduled run, which could be days or weeks away. Continuous monitoring instead applies matching to each relevant change as it happens, whether a list update or a change in customer data. That produces a steadier, more manageable queue rather than periodic floods, and it closes the exposure window to close to real time. The two approaches answer the same obligation, but continuous monitoring catches a new match far nearer to when it actually occurs.
How should screening frequency be set across a customer book?
By risk tier, not by one fixed number applied to every customer. A defensible structure ties re-screening frequency directly to the ratings your AML risk assessment produces. In practice that looks like continuous or daily re-screening for high-risk relationships and any PEP or previously escalated customer, a shorter periodic cycle such as weekly for medium-risk relationships, and a longer periodic cycle, aligned with your standard review schedule, for low-risk relationships. The reasoning is that higher-risk relationships change faster and carry more consequence if a new match is missed, so they justify a tighter cadence. Whatever structure you choose should be written into policy, tied explicitly to the risk ratings rather than set arbitrarily, and revisited whenever the risk assessment itself is updated. That way the cadence moves with the risk it is meant to track, and an examiner can see why each tier is re-screened as often as it is.
Does screening cadence need to be documented?
Yes. An examiner will look for evidence of not just that re-screening occurs, but how the frequency was set, whether it is tied to the customer's risk ratings, and whether it is applied consistently across the book. Documenting the cadence is what turns a sensible practice into a defensible one: the expectation under the reasonably designed, risk-based standard is that you can explain your frequency and justify it, not simply assert that you re-screen. That means writing the cadence into policy, mapping each tier to the risk ratings your risk assessment produces, and recording that the policy is actually followed in practice. It also means revisiting the documented cadence when the risk assessment changes, so the two never drift apart. An examiner who asks how often you re-screen, and why that frequency is appropriate for a given customer, should be able to find the answer in your written program rather than in individual reviewers' heads.
Sources
Move from periodic batches to continuous screening.
Book a demo and we will show you ongoing screening that re-checks every customer as lists change, with a risk-based cadence and a recorded disposition on every alert.
Book a demo
