For most of the last two decades, keeping customer information current meant putting each customer on a calendar. High-risk clients were reviewed every year, everyone else every few years, and in between those dates the file effectively sat untouched. Regulators, and increasingly the fintechs themselves, have concluded that this periodic model leaves too much time in the dark. Perpetual KYC, sometimes written as pKYC, and the broader practice of ongoing customer due diligence replace the fixed calendar with continuous, event-driven review. This guide explains what that shift means for compliance leaders, what is driving it, and how to think about the operating model, without prescribing how to build the underlying systems.
This article is general information for fintech and compliance professionals and is not legal advice. Requirements vary by jurisdiction and change over time; confirm your specific obligations with qualified counsel and your regulator.
What Ongoing Due Diligence Actually Requires
The obligation to keep customer knowledge current is not new. The Financial Action Task Force, whose recommendations underpin most national regimes, has long expected firms to conduct ongoing due diligence throughout the business relationship, scrutinizing transactions to ensure they are consistent with what the firm knows about the customer, and keeping the underlying information up to date. The important word is “ongoing.” Due diligence is not a gate a customer passes once at onboarding; it is a continuous responsibility that lasts for the life of the relationship. Perpetual KYC is simply the operating model that takes this principle seriously, treating the customer profile as something that should reflect reality today rather than reality on the date of the last scheduled review.
Why the Periodic Model Is Breaking Down
The periodic refresh model has two structural weaknesses. First, it is blind between reviews. If a customer’s ownership changes, they appear on a sanctions list, or adverse media surfaces the day after their annual review, the firm may not notice for another twelve months. Risk does not wait for the calendar. Second, periodic review is enormously wasteful. It forces teams to re-examine large populations of customers on a fixed schedule regardless of whether anything has actually changed, consuming analyst time on low-value refreshes while genuinely changed profiles wait their turn. The result is the worst of both worlds: high cost and late detection. Event-driven review inverts this by focusing attention where something has actually changed, which is both more effective and, over time, more efficient.
The Shift to Event-Driven Review
Perpetual KYC reframes the question from “when is this customer next due?” to “what has changed about this customer, and does it matter?” Instead of a scheduled re-verification, a change in a relevant signal triggers a proportionate review. That signal might be a change in beneficial ownership, a new sanctions or watchlist hit, negative news, a shift in transactional behavior, or a reclassification of the jurisdiction the customer operates in. The profile becomes a living record that responds to events as they occur. This does not mean abandoning all time-based checks; rather, it layers continuous monitoring on top of a much lighter periodic backstop, so that the calendar becomes a safety net rather than the primary mechanism.
The EU Direction of Travel
The regulatory momentum behind this shift is clearest in the European Union. Under the EU Anti-Money Laundering Regulation and the accompanying sixth directive, which are set to apply from 10 July 2027, a single rulebook will replace much of the fragmented national patchwork that preceded it, and the new Anti-Money Laundering Authority based in Frankfurt will bring central supervision to the highest-risk institutions. The framework reinforces ongoing monitoring rather than one-off checks, and is widely reported to set maximum intervals for keeping customer information up to date, commonly described as no more than one year for higher-risk customers and up to five years for lower-risk ones, with additional event-driven updates whenever circumstances change. Firms should treat the exact thresholds and timelines as subject to confirmation against the final texts and any implementing guidance, but the direction is unmistakable: continuous, risk-based currency of customer information is becoming the expected norm rather than a leading-edge practice.
What Should Trigger a Review
A workable perpetual KYC model rests on a clear, documented set of triggers and a proportionate response to each. The table below illustrates common trigger categories and why they matter; the point is not to react to every event with a full refresh, but to match the depth of review to the significance of the change.
| Trigger | Example | Typical Response |
|---|---|---|
| Ownership change | New beneficial owner or control structure | Re-verify ownership and reassess risk |
| Screening hit | New sanctions, PEP, or watchlist match | Investigate, confirm or discount, escalate if needed |
| Adverse media | Credible negative news linked to the customer | Assess relevance and materiality |
| Behavioral change | Transactions inconsistent with the profile | Review activity and update expected behavior |
| Jurisdiction change | Customer or counterparties tied to higher-risk regions | Recalculate risk rating and due diligence level |
| Time backstop | No event but maximum interval reached | Lightweight confirmation that data remains current |
Designing these triggers is closely tied to how you rate customer risk in the first place, a subject covered in our guide to AML customer risk assessment and risk-based scoring. The quality of your onboarding checks also matters, because perpetual KYC keeps a profile current but cannot repair one that was weak at the start; our KYC verification guide covers that foundation.
Operating Model Implications
Moving to perpetual KYC is less a technology purchase than an operating model change, and decision-makers should plan for three practical realities. The first is data. Continuous monitoring is only as good as the data feeding it; if beneficial ownership, screening, and transaction information live in disconnected systems, event detection will be patchy. The second is alert volume. Watching for change across the whole customer base surfaces far more signals than an annual review ever did, which makes prioritization and false-positive management essential rather than optional. Without disciplined tuning and clear escalation, teams can drown in low-value alerts. The third is workflow and accountability. Every triggered review needs a clear owner, a defined response, and an auditable record of the decision, so that the firm can demonstrate to regulators not just that it detected a change but that it responded appropriately. Related monitoring disciplines are explored in our guides to adverse media screening and AML transaction monitoring.
The Role, and Limits, of Technology
Perpetual KYC is impractical at scale without automation, and this is where regulatory technology earns its place: connecting data sources, watching for changes continuously, and routing meaningful events to analysts. Increasingly, machine learning is used to reduce noise by filtering out immaterial changes and highlighting the ones that genuinely warrant attention. But technology has a firm limit that leadership must respect: it can detect and prioritize, but the judgment about whether a change materially alters a customer’s risk, and what to do about it, remains a human and accountable decision. Automated systems that quietly close alerts or refresh profiles without a defensible rationale create their own regulatory exposure. The goal is to let technology handle scale and surface signal, while people retain ownership of the decisions that matter.
Common Pitfalls
Several traps recur when firms make this transition. One is treating perpetual KYC as a badge rather than a discipline, announcing continuous monitoring while the underlying triggers and responses remain undefined. Another is over-triggering, where poorly calibrated signals generate so many reviews that analysts are overwhelmed and genuine risks are lost in the noise. A third is neglecting documentation, so that even where the firm responds well to a change, it cannot later evidence why it reached a particular conclusion. A fourth is assuming a tool alone solves the problem, when in reality the operating model, data quality, and governance around the tool determine whether it delivers. Avoiding these traps is less about sophistication and more about clarity: know what you are watching for, know how you will respond, and be able to show your work.
Frequently Asked Questions
Does perpetual KYC eliminate periodic reviews entirely?
Not usually. Most models keep a lightweight time-based backstop to confirm that data remains current even when no event has been detected, while relying on continuous, event-driven monitoring as the primary mechanism. The calendar becomes a safety net rather than the main driver.
Is this only relevant to firms operating in the EU?
No. While EU reforms are a prominent driver, ongoing due diligence is a longstanding FATF expectation reflected in many regimes worldwide. The move toward continuous, risk-based currency of customer information is a global direction of travel, not a purely European one.
Will perpetual KYC reduce our compliance costs?
It can, but not automatically. By focusing effort on customers whose profiles have actually changed, it reduces wasted low-value reviews; however, it also surfaces more signals, so the savings depend heavily on disciplined tuning, good data, and effective false-positive management.
Conclusion
Perpetual KYC and ongoing customer due diligence represent a shift in mindset as much as in tooling: from a customer file that is periodically refreshed to a living profile that responds to change as it happens. The regulatory direction, most visibly in the European Union but rooted in longstanding global standards, points firmly toward continuous, risk-based due diligence. For decision-makers, the priorities are clear triggers, strong data, disciplined alert management, and human accountability for the decisions that matter, with technology deployed to handle the scale rather than to replace the judgment. Firms that treat this as a genuine operating model change, not a label, will be better positioned for both the coming rules and the risks they are designed to catch. To assess how a perpetual KYC approach could fit your compliance operations, speak with our team about an approach tailored to your business.