Perpetual KYC

    Perpetual KYC without the back-book review campaigns.

    Stop refreshing files on a calendar. ComplianceSuite watches every customer and UBO continuously — registries, PEP/sanctions, adverse media, transactions — and opens a case only when something material changes. Regulator-defensible under EU AMLR Art. 26, FATF R.10, FCA, DNB and MAS.

    • 55–70% lower KYC review workload
    • 80+ pre-built event triggers
    • Diff-only case files, not full re-reviews
    • Safety-net scheduled review still available

    Definition

    What is perpetual KYC (pKYC)?

    Perpetual KYC — also called pKYC, continuous KYC or event-driven KYC — replaces the traditional periodic-review model with continuous, trigger-based updates. Instead of touching a file every 1, 3 or 5 years, the platform re-checks every customer against source data every day and opens a case only when something material has changed.

    EU Regulation 2024/1624 Article 26 and FATF Recommendation 10 require ongoing due diligence — not a specific refresh cadence. The DNB and UK FCA have explicitly encouraged event-driven KYC where firms can demonstrate their trigger framework covers material change.

    See our guides to KYC, EDD and AML glossary.

    Capabilities

    What's included.

    Continuous data enrichment

    Daily registry, PEP, sanctions and adverse-media re-checks on every customer and UBO in the book. No batch cycles.

    Event-driven triggers

    80+ pre-built triggers across data, risk, behaviour and corporate events. Custom triggers in a visual editor.

    Severity-based routing

    Auto-approve minor changes, route material changes to analysts, block on critical events. Full audit trail on every path.

    Diff-only case files

    Analysts see only what changed and why — with the source, timestamp and confidence — instead of re-reading the whole file.

    Regulator-defensible

    Trigger framework documented, all decisions timestamped and immutable, one-click export of the refresh history per customer.

    Safety-net review

    Configurable scheduled review (e.g. annual for high-risk) runs alongside triggers so nothing falls through. Belt-and-braces.

    How it works

    Four steps to continuous KYC.

    1. Ingest baseline KYC

    Import current KYC/KYB records via API or bulk. Map to canonical schema. Establish the baseline risk score and file completeness.

    2. Wire event triggers

    Registry feeds, PEP/sanctions/adverse-media, transaction stream and internal signals connect to the trigger framework. 80+ triggers ready out-of-the-box.

    3. Auto-route by severity

    Trigger fires → diff computed → severity classified → auto-approve, analyst queue or block. Every path logged.

    4. Re-risk-score continuously

    Every refresh re-runs the risk model. Score changes surface on dashboards; MI feeds board reports and regulator responses on demand.

    Example triggers

    Three triggers, three real refreshes.

    TriggerScenarioAction
    PEP status addedExisting retail customer appointed as ministerial adviser; picked up from parliamentary appointment feedAuto-refresh: PEP tier assigned, EDD case opened, senior-management approval requested. Time from source publication to case: 4 hours.
    New UBO on corporate customerKYB customer files new shareholder register; UBO ≥25% is a new individual in a high-risk jurisdictionAuto-refresh: new UBO screened for PEP/sanctions/adverse-media, structure chart updated, analyst reviews resolution certificate. Case opens in <1 hour of registry filing.
    Sanction listing on existing customerOFAC adds an existing customer's UBO to SDN list at 14:02 UTCReal-time block on all outbound payments, case escalated to MLRO, freezing decision within 30 minutes, STR filed same day.

    Regulatory coverage

    Where perpetual KYC is expressly supported.

    RegimeScopePosition
    FATF Recommendation 10Global standardOngoing due diligence with scrutiny of transactions and ensuring customer data is kept up-to-date. Explicitly risk-based; does not mandate periodic cycles.
    EU AMLR (Reg. 2024/1624) Art. 26EU 27Ongoing monitoring and risk-based updating of customer information. Event-driven refresh permitted where the trigger framework demonstrably covers material changes.
    UK FCA FCG Ch. 3United KingdomCustomer information kept current on a risk-sensitive basis; FCA supportive of trigger-based and perpetual KYC approaches for firms with adequate MI.
    DNB Good Practices (NL)NetherlandsDNB has published good-practice guidance encouraging event-driven KYC over rigid periodic cycles, subject to documented trigger framework.
    MAS AML/CFT Notice 626SingaporeOngoing monitoring and periodic review on a risk-sensitive basis. MAS supports data-driven, event-triggered refresh models.
    HKMA AML Guideline §4Hong KongRegular review of customer files; event-triggered updates expected for material changes in customer profile or risk.

    Frequently asked questions.

    What is perpetual KYC (pKYC)?

    Perpetual KYC — also called pKYC, continuous KYC or event-driven KYC — replaces the traditional periodic refresh cycle (every 1/3/5 years by risk tier) with continuous, event-triggered updates. Whenever a customer's data changes at a source (new address, new UBO, PEP status, sanction listing, adverse media, transaction anomaly), the KYC file is refreshed automatically and re-risk-scored.

    Why is periodic KYC being replaced?

    Periodic KYC creates two problems: (1) risk blind spots between reviews — a customer can become a PEP or be sanctioned the day after their review and stay undetected for 3 years; (2) massive back-book review campaigns that consume 30–50% of analyst capacity. FCA, DNB, MAS and the ECB have publicly encouraged the shift to event-driven / perpetual KYC.

    Is perpetual KYC regulatorily accepted?

    Yes. FATF Recommendation 10 requires ongoing due diligence, not periodic file refresh specifically. The EU AMLR (Reg. 2024/1624 Art. 26) explicitly permits risk-based, event-driven refresh where the firm can demonstrate the trigger framework covers material changes. UK FCA, DNB (Netherlands), MAS and HKMA have issued supportive guidance.

    What events trigger a KYC refresh?

    Data-change events (new address, name change, new director/UBO), risk events (new PEP status, sanction listing, adverse media hit), behavioural events (transaction pattern change, threshold breach, new corridor), corporate events (M&A, restructuring, insolvency), and scheduled events (annual for high-risk customers as a safety net). All configurable per risk tier.

    How does perpetual KYC integrate with our existing KYC file?

    ComplianceSuite ingests the current KYC record via API or bulk import, maps it to the canonical schema, then enriches with continuous data feeds (registries, PEP/sanctions/adverse-media, transaction stream). Changes generate a case with the diff, source, confidence and recommended action.

    What happens when a trigger fires?

    The platform opens a lightweight refresh case with only the changed data (not the full file), auto-classifies severity, requests any missing evidence, and routes to the appropriate queue. Low-severity changes (address update) auto-approve; material changes (new UBO, PEP status) route to analyst; critical events (sanction listing) block the customer pending review.

    How does this affect analyst workload?

    ComplianceSuite pKYC customers report a 55–70% reduction in KYC review workload after 6 months. Analysts stop working stale files and instead review only material changes, with source evidence pre-fetched.

    Does perpetual KYC apply to KYB and UBOs?

    Yes — arguably more valuable for KYB. UBO changes, director changes, and adverse media on any UBO trigger a refresh. Registry filings across 240+ jurisdictions are monitored daily for the entities you onboarded.

    Retire the back-book review campaign.

    We'll model your customer base, wire the top 20 triggers, and show projected review-workload reduction — usually in one session.