← Blog · Compliance
Perpetual KYC: Replacing Calendar Reviews With Event Triggers

Most KYC programs still refresh customer files on a fixed clock: high-risk customers every 12 months, medium every 24, low every 36. The calendar is easy to audit but poorly correlated with actual risk. A low-risk customer can turn into a mule three days after onboarding, and a fixed 36-month cycle will not notice until 2029. Perpetual KYC (pKYC) replaces the calendar with events, refreshing a record when something observable changes.
Why the Calendar Fails
Fixed-period review has two costs. The first is wasted work: analysts re-verify thousands of stable, dormant, low-value accounts because a date arrived, not because anything changed. Studies of large banks routinely find that 90%+ of periodic reviews close with no material update. The second cost is missed risk: the interval between reviews is dead time. If a customer's risk profile shifts in month two of a 36-month cycle, you carry stale KYC for nearly three years.
The calendar also creates uneven workload. Reviews cluster around onboarding anniversaries, producing backlogs that push teams to rush files near quarter-end. Neither the coverage nor the throughput is optimized — only the audit story is tidy.
What Counts as an Event
Event-driven refresh means defining, in advance, the signals that justify a re-check. These fall into a few families:
- Behavioral: a dormant account resuming activity, a spike in transaction volume or velocity, first outbound transfer to a high-risk jurisdiction, or a pattern change flagged by transaction monitoring.
- Data-driven: a new sanctions or PEP list hit against the existing name, adverse media surfacing, or a change in registered address or beneficial ownership for a business customer.
- Customer-initiated: a request to raise limits, change contact details, add a new payout method, or update the phone number tied to the account.
- Document expiry: the ID used at onboarding reaching its expiry date, which is a genuine calendar event but tied to the document, not an arbitrary interval.
Each event maps to a proportionate response. A limit increase might trigger a source-of-funds question; a new list hit triggers full screening; a phone number change triggers a possession check. Not every event demands a full re-onboarding.
The Data Minimization Angle
Perpetual KYC sounds like more surveillance, and it can be if implemented carelessly. The privacy-preserving version is narrower, not broader. You monitor a small, defined set of triggers rather than continuously vacuuming behavioral data. When an event fires, you request only the specific artifact that resolves it — not a fresh copy of every document on file.
Chat-based verification fits this model. When a trigger fires, the customer receives a targeted request in the same channel they already use, completes one step, and the record updates. There is no need to re-collect an entire dossier. Configurable retention matters here too: if an event-driven check produces a new document, retention clocks should apply per artifact, so re-verified data does not accumulate indefinitely. The goal is a current file that holds the minimum needed to justify the current risk rating.
Making the Transition Auditable
Regulators expect you to show why you reviewed a file when you did. Moving off the calendar does not remove that obligation; it changes what you document. Instead of a review date, you record the triggering event, the rule that classified it, the response taken, and the outcome. This produces a richer trail than a periodic tick-box: each entry has a cause.
A workable path is hybrid. Keep a long-stop review interval as a backstop — say, every 36 months for low-risk customers — but let events drive most refreshes in between. Over time, as trigger coverage improves, the backstop fires rarely. The result is a program where effort follows risk, stale files shrink, and every review can answer the question examiners actually ask: what changed, and what did you do about it?
General information, not legal advice. Talk to your compliance counsel for guidance on your specific obligations.