Most compliance conversations focus on the front door: onboarding a customer, verifying identity, and screening at the point of entry. But a customer relationship can last for years, and the information gathered at onboarding does not stay accurate. People move, businesses change ownership, risk profiles shift, and regulatory expectations evolve. Keeping customer due diligence current over the life of the relationship is the job of periodic review and KYC remediation, and for many fintechs it is where compliance quietly falls behind. This guide explains what remediation and periodic review are, why backlogs form, and how decision-makers should think about managing them, without treating them as a one-off clean-up project.
This article is general information, not legal or regulatory advice. Requirements vary by jurisdiction and change over time; confirm specifics with your regulator and qualified advisers.
Periodic Review and Remediation: What They Are
Periodic review is the scheduled re-examination of an existing customer’s due diligence to confirm that the information on file is still accurate and that the assigned risk rating still holds. Higher-risk customers are typically reviewed more often than lower-risk ones. Remediation is the corrective work that follows: closing gaps, refreshing outdated documents, and bringing records that no longer meet current standards back into line.
The two are related but distinct. Periodic review is a routine, forward-looking rhythm that keeps a portfolio current. Remediation is usually a response to a known deficiency, such as a policy change, a regulatory finding, or the discovery that a set of records was never collected properly in the first place. Both differ from perpetual monitoring, which watches for change continuously; review and remediation act at defined points to correct what monitoring or policy has flagged.
Why Backlogs Form
Backlogs rarely come from negligence. They form because the volume of review work grows with the customer base while the capacity to do it does not. A fintech that onboards quickly can accumulate a large population of customers who all become due for review within a compressed window. Add a policy change that raises the standard for existing records, and a substantial share of the book suddenly needs remediation at once. Manual, document-heavy processes make each case slow, and cases that require contacting customers for missing information stall whenever the customer does not respond.
The danger is that a backlog is not a neutral queue. Every overdue review represents a customer whose risk may have changed without the firm noticing. A backlog is therefore an accumulation of unmeasured risk, not merely a productivity problem, and regulators tend to treat a large, unexplained backlog as a signal that the wider control environment is under strain.
Why This Belongs on the Leadership Agenda
Remediation and review backlogs are easy to deprioritize because they are invisible to customers and produce no new revenue. That is precisely why they need leadership attention. Left alone, a backlog compounds: this quarter’s overdue reviews join next quarter’s, and the population that has drifted from its true risk rating grows. The cost of clearing it rises the longer it waits, and the reputational and regulatory exposure grows with it. Treating review capacity as a permanent operational commitment, sized to the portfolio, prevents the backlog from forming rather than paying to clear it repeatedly.
There is also a link to how risk is assessed in the first place. If the original risk ratings that drive review frequency are inconsistent, the review schedule itself will be misaligned. Our guide to AML customer risk assessment and risk-based scoring covers the foundation that determines how often each customer should be revisited.
How to Think About Managing the Work
The instinct when facing a backlog is to throw people at it until it clears. That helps in the short term but does nothing to stop it returning. A more durable approach separates two goals: clearing the existing backlog and preventing the next one. For the existing backlog, prioritization by risk matters more than working chronologically; the highest-risk overdue cases carry the most exposure and should be worked first, even if they are not the oldest.
| Criterion | What good looks like | Why it matters |
|---|---|---|
| Risk-based prioritization | Highest-risk overdue cases worked first, not simply oldest-first | Concentrates effort where unmeasured risk is greatest |
| Clear triggers | Defined events and schedules that create a review, consistently applied | Prevents cases from silently becoming overdue |
| Data reuse | Existing verified information reused where still valid | Avoids re-collecting data the firm already holds, speeding each case |
| Customer outreach handling | A defined path for non-responsive customers, including escalation | Stops cases stalling indefinitely on missing information |
| Capacity sized to portfolio | Ongoing review capacity planned against expected volume | Prevents the backlog from re-forming after clearance |
| Auditability | Decisions and their rationale recorded consistently | Demonstrates control and supports regulatory scrutiny |
Prevention is largely about moving from event-driven catch-up to a steady, predictable rhythm. When reviews are triggered reliably and worked continuously, the population never accumulates into a crisis. This is the operating model behind perpetual KYC and ongoing customer due diligence, which reduces the reliance on large periodic sweeps by keeping records current as change occurs.
The Quality Trap: Speed Versus Rigor
Under backlog pressure, the tempting shortcut is to clear cases quickly by doing shallow reviews. This creates a worse problem: a backlog that looks cleared on paper but leaves the underlying risk unexamined. A review that ticks a box without genuinely confirming that information and risk are current provides false assurance, which is arguably more dangerous than an honest backlog because no one is looking anymore. Managing the tension between throughput and depth, and being explicit about what a review must actually establish, is central to doing this well. Consistency of process is what allows speed without sacrificing rigor.
Common Pitfalls
A few patterns recur. The first is treating remediation as a one-time project rather than building the ongoing capacity that stops backlogs returning. The second is working the backlog oldest-first instead of by risk, spending effort on low-risk cases while high-risk ones wait. The third is clearing cases superficially to hit a number, trading a visible backlog for an invisible one. The fourth is letting cases stall on non-responsive customers with no escalation path. The fifth is failing to record the rationale for decisions, so the work cannot later be shown to have been done properly.
Frequently Asked Questions
How often should periodic reviews happen? Frequency is generally driven by customer risk rating, with higher-risk customers reviewed more often. The specific intervals depend on your risk framework and applicable expectations in your jurisdiction.
Is a backlog automatically a compliance breach? Not necessarily, but a large or unexplained backlog signals weak control and invites scrutiny. What matters is whether the firm understands the exposure, is managing it on a risk basis, and can evidence a credible plan.
Can technology solve the backlog? Tooling helps by automating triggers, reusing data, and streamlining outreach, but it cannot substitute for adequate capacity and sound judgment. Technology reduces effort per case; it does not remove the need to size review capacity to the portfolio.
Conclusion
KYC remediation and periodic review are where the promises made at onboarding are kept over time. Backlogs form quietly, accumulate unmeasured risk, and become more expensive the longer they are left. The durable answer is not a heroic clean-up but a steady operating model: risk-based prioritization, reliable triggers, sensible reuse of existing information, and review capacity sized to the portfolio. Handled this way, keeping customer due diligence current becomes a routine discipline rather than a recurring crisis.
To review how your firm manages periodic review and remediation, and where backlogs may be building, the team at DanuSoft can help you assess your approach.