← Blog · Compliance
Perpetual KYC: Replacing Calendar Reviews With Event Triggers

Most KYC programs still refresh customer files on a fixed schedule: low-risk every 36 months, medium every 24, high every 12. The logic is administrative, not analytical. A customer whose behavior changed 11 months ago sits unreviewed until the calendar says otherwise, while a dormant account consumes analyst time simply because its date came up. Perpetual KYC (pKYC) replaces that cadence with a model where changes in data — not the passage of time — decide when a file needs attention.
Why Periodic Reviews Fail
The core weakness of scheduled reviews is latency. Risk is continuous; review is discrete. A customer can incorporate a new entity, appear in adverse media, or shift transaction patterns the day after a review closes, and the file stays green for up to three years.
The second weakness is cost distribution. Under fixed cycles, analyst hours are spread evenly across the book regardless of where risk actually sits. Industry estimates put manual periodic reviews at 30 to 90 minutes each, and a large share produce no change at all. You pay full price to confirm that nothing happened.
- Stale data: Information verified years ago is treated as current.
- Batch pressure: Reviews cluster at quarter-end, degrading quality under volume.
- No prioritization: A dormant retail account and a fast-growing corporate flow follow the same clock.
What an Event Actually Is
Perpetual KYC works only if you define events precisely enough to trigger action but narrowly enough to avoid alert floods. An event is any observed change in an attribute that could move a customer's risk rating. These fall into a few categories:
- Identity changes: new name, address, nationality, or document expiry.
- Ownership changes: a shift in beneficial owners, directors, or corporate structure in KYB cases.
- Screening hits: a new sanctions, PEP, or adverse-media match from ongoing rescreening.
- Behavioral changes: transaction volume, velocity, geography, or counterparty profile deviating from the established baseline.
- External signals: registry filings, regulatory actions, or expired verification artifacts.
Each trigger should carry a severity and a defined workflow: some resolve automatically, some request a single confirming data point from the customer, and only a subset escalate to full manual review. The goal is to route effort by materiality rather than by date.
The Data and Consent Problem
pKYC assumes you can re-verify without forcing the customer through onboarding again. That is a data-freshness and consent challenge as much as a technical one. Continuous screening against watchlists is straightforward. Refreshing a document or confirming an address usually requires reaching the customer — and if that interaction is heavy, you have simply moved the friction, not removed it.
This is where a conversational channel changes the economics. A short, targeted request over Telegram or WhatsApp — "Your ID document expires next month, please confirm your current one" — collects exactly the field that changed and nothing else. That aligns with data minimization: you re-verify the specific attribute the event flagged rather than re-collecting the entire file. Pair this with configurable retention so that superseded documents are deleted on schedule once the new artifact is verified, keeping the record current without accumulating stale copies.
Moving From Batch to Continuous
Few teams can flip to full pKYC overnight, and regulators generally expect a documented, risk-based rationale rather than a specific technology. A phased path tends to hold up better:
- Start with screening: move sanctions and PEP checks from periodic to daily or real-time rescreening first.
- Layer behavioral triggers: connect transaction monitoring output to the review queue so anomalies open a file automatically.
- Automate low-severity resolution: let confirmed non-matches and unchanged attributes close without an analyst.
- Retire the calendar last: keep a long-interval backstop review until your event coverage is demonstrably complete.
Document your event taxonomy, thresholds, and escalation logic. Perpetual KYC is defensible only when you can show why a given change did — or did not — trigger action. Treat the trigger library itself as a controlled artifact, versioned and reviewed, the way you would any other part of your compliance framework.
General information, not legal advice. Talk to your compliance counsel for guidance on your specific obligations.