Most onboarding processes get this part right: screen the customer, check the entity, run the sanctions list, file the result. What happens after that is usually nothing, until the next scheduled review, which might be a year away.
That gap is the actual problem. Sanctions lists change constantly. A counterparty that was clean at onboarding can appear on a list six weeks later, and if nobody's rechecking, that change sits unnoticed until the next periodic review picks it up, which could be well after the exposure started. APRA, AUSTRAC, and ASIC all frame the underlying expectation the same way: monitoring is meant to be ongoing, not a single event that happens once and gets filed away.
Why most compliance teams don't do this already
The reason most compliance teams don't do this already isn't that they don't understand the obligation. It's that manually rerunning checks across an entire customer base on any kind of regular schedule doesn't scale past a fairly small number of relationships. Somebody has to remember to do it, decide how often, and actually carry it out, every time, for every entity.
What continuous monitoring actually means
CMaaS automates that recheck, staying in sync with each underlying source's own release schedule, and firing an alert when something changes rather than waiting for the next scheduled review to catch it. The distinction that matters isn't the exact frequency, it's that the customer base gets watched continuously instead of periodically, which is the actual gap between a point in time check and something that holds up as ongoing monitoring.
Compliance Monitoring as a Service
Requires a Professional plan subscription. Base tier covers up to 100 monitored entities (USD $650 or AUD $975/month), with additional entity blocks available. Also included in Professional+.
Get Started View Documentation Full Product Details