AML screening and monitoring UK - two distinct MLR 2017 obligations, onboarding gate versus continuous monitoring feed

AML Screening and Monitoring: The Real Difference (UK)

Before diving into the distinction between AML Screening and Monitoring, it’s worth recognising why these two terms are so often conflated. Many UK platforms invest heavily in onboarding checks because they’re visible, well-defined and straightforward to demonstrate during implementation.

Ongoing monitoring, by contrast, is a continuous operational capability that depends on live transaction data, alerting and reviewing workflows long after a client has been approved. 

The key to building a compliance programme that reflects what AML screening and monitoring actually require under MLR 2017, rather than stopping at customer onboarding, is understanding where the AML screening process ends and monitoring begins.

TL;DR: MLR 2017 splits into two obligations, not one: a screening check at intake, and scrutiny of transactions for as long as the relationship runs. UK platforms consistently build the first and treat the second as optional. It isn’t optional; it’s just harder to demo, so it gets built last, if at all.

“The pattern I keep seeing across compliance teams is that AML gets treated as a single checkbox. A clean sanctions result at onboarding gets filed, and everyone moves on. Nobody goes back to look at how that client’s transactions actually behave over time, because that side of the build never got scoped in the first place.” – Paul, Compliance Lead at Finexer

Not sure if your monitoring layer is a live process or a folder of clean files from onboarding?

Talk to Finexer about what a continuous transaction feed actually looks like underneath your AML programme.

Get 15 minutes with the team. 

Screening and Monitoring Aren’t the Same Obligation

A regulated platform onboards a new client, runs a sanctions and PEP check, gets a clean result, and marks the file complete. Under the Money Laundering Regulations 2017, that’s the start of the obligation, not the end of it.

MLR 2017 requires businesses to scrutinise transactions throughout the relationship, not just at the point of onboarding. A platform that built a solid AML screening process but never built the monitoring layer behind it has satisfied roughly half of what the regulation actually asks for.

That gap doesn’t surface in a demo or a sales conversation. It surfaces during a regulatory review, or after a client’s transaction pattern has quietly diverged from what onboarding suggested, for months, with nobody watching.

What a Solution Needs: Screening and Monitoring as Two Builds

AML screening as onboarding gate versus AML monitoring as continuous transaction feed architecture

Five requirements separate a platform that treats screening and monitoring as one job from one that builds them as the two distinct workflows MLR 2017 actually requires.

  1. Onboarding screening depth – Does the platform check sanctions, PEP, and adverse media lists at the point of onboarding, against live databases rather than a static list updated infrequently?
  2. Continuous transaction visibility – After onboarding, does the platform see ongoing account activity, or does the file close the moment the initial check passes?
  3. Pattern and exception detection – Can the platform flag a transaction pattern that diverges from what onboarding established, or does monitoring only happen when someone manually decides to look?
  4. Audit-ready evidence for both stages – Can the platform produce evidence of the onboarding check and the ongoing monitoring separately, for an SRA, FCA, or internal audit?
  5. Re-screening triggers – Does the platform re-check sanctions and PEP status periodically during the relationship, not just once at intake?

Most platforms handle the first requirement reasonably well, because it’s the one regulators ask about first. Very few build the second, third, and fifth without a live transaction data layer underneath the onboarding tool.

AML Screening vs AML Monitoring: What MLR 2017 Actually Requires

StageAML Screening (Onboarding)AML Monitoring (Ongoing)
When it happensOnce, at client intakeContinuously, for the life of the relationship
What it checksIdentity, sanctions, PEP, adverse mediaTransaction patterns, account activity, behavioural changes
MLR 2017 basisCustomer due diligence (CDD)Ongoing scrutiny of transactions throughout the relationship
Typical failure modeStatic list, checked once, never re-runNo mechanism at all beyond periodic manual review
Evidence requiredScreening result at intakeAudit trail of continuous monitoring activity

The Gap: Why Monitoring Quietly Lapses After Onboarding

AML monitoring gap after onboarding - clean screening in January followed by unmonitored transaction pattern shift by June

Every platform that builds AML screening well shares the same blind spot once onboarding passes: the file gets marked complete, and nothing continues watching it.

A client passes sanctions and PEP screening in January. By June, their transaction pattern has shifted meaningfully, larger deposits, new counterparties, activity that doesn’t match the profile established at intake, and nobody has looked, because monitoring was never built as an ongoing process, only as a one-time gate.

Real ongoing monitoring requires a continuous feed of account activity, not a periodic manual pull of statements. Without that live layer, the AML screening process ends where the actual regulatory exposure begins.

Finexer’s Verification: The Data Layer Behind Both Stages

Finexer Verification and AIS as the data layer underneath AML screening and ongoing monitoring for UK platforms

Platforms building AML screening and monitoring need one thing underneath both stages: verified bank data that doesn’t stop the moment onboarding is marked complete.

  • Bank-based name verification at onboarding: real-time match against bank records, not a submitted form
  • Facial recognition with similarity score: selfie checked against passport or driving licence
  • Document data extraction: structured data pulled directly from the ID document
  • AIS transaction data for ongoing monitoring, delivered via webhook rather than periodic manual review
  • Almost all UK banks covered
  • FCA-authorised AISP and PISP (FRN925695)
  • Usage-based pricing

What Is the AML Screening Process?

The AML screening process is the set of checks a business runs at client onboarding to establish identity and assess money laundering risk before the relationship begins.

It covers customer due diligence, identity verification, and sanctions, PEP, and adverse media checks, all performed once at intake rather than continuously. Under MLR 2017, screening on its own is not the complete obligation; it’s the entry point to a relationship that then requires ongoing monitoring for as long as it continues, which is where most platforms’ compliance builds actually stop short.

What are AML checks in the UK?

AML checks in the UK include customer due diligence (CDD), identity verification, sanction and PEP list screening, source-of-funds verification, and ongoing transaction monitoring under the Money Laundering Regulations 2017. Platforms use verified bank data accessed through Open Banking to automate these compliance requirements.

What are the AML regulations in the UK?

UK AML regulations under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 require businesses to verify client identities, assess money laundering risks, conduct ongoing transaction monitoring, and report suspicious activity to the National Crime Agency.

What is the AML screening procedure?

AML screening procedure involves customer identification, risk assessment, source-of-funds verification using verified bank transaction data, ongoing monitoring of financial activity, and suspicious activity reporting when required. Platforms automate this process using Open Banking APIs rather than manual document collection.

Can Open Banking support AML compliance?

Yes, Open Banking provides FCA-authorised access to verified bank transaction data. Platforms retrieve financial information through secure APIs enabling AML screening and monitoring with bank-authenticated evidence supporting source-of-funds verification and ongoing compliance workflows.

Why do platforms need verified transaction data for AML?

Money Laundering Regulations require businesses to verify customer financial activity and conduct ongoing monitoring. Verified transaction data accessed through Open Banking provides bank-authenticated evidence that manual screenshots and PDF uploads cannot deliver for compliance purposes.

See how Finexer’s UK-exclusive focus provides 99% bank coverage without multi-market complexity.

About the Author

Paul Lucraft
Paul Lucraft

Paul Lucraft is a payments industry strategist and advisor with more than two decades of experience across banking, card networks, and financial services infrastructure. His expertise covers fraud prevention, payment risk management, financial strategy, and the operational development of card payment systems. He previously held senior roles at Mastercard Europe where he served as General Manager for the UK and Ireland, overseeing fraud risk, operational governance, and payment network strategy across the region. Earlier in his career, Paul worked at Lloyds TSB and TSB Bank leading fraud strategy, credit collections, and card business finance operations.