Continuous KYC vs Periodic Review: What Banks Should Know

via GlobePRwire
ⓘ This article is third-party content and does not represent the views of this site. We make no guarantees regarding its accuracy or completeness.


A periodic review re-checks a customer on a fixed schedule, while continuous KYC watches for changes and triggers a review when something relevant happens. The main U.S. rule on this point asks for ongoing monitoring and for customer information to be updated when monitoring reveals something relevant, so most banks end up combining the two: continuous signals to catch change, and a periodic review as the backstop

What Is a Periodic KYC Review?

A periodic review is a scheduled refresh of what the bank knows about a customer. The customer is re-assessed at set intervals, and the file is updated if anything has changed.

How Periodic Reviews Work

Most institutions tier customers by risk and review higher-risk customers more often than lower-risk ones. An analyst gathers documents, checks ownership and activity, screens against watchlists, and records the outcome. The approach is easy to explain to an examiner because the calendar is the control.

Where Periodic Reviews Fall Short

The weakness is the gap between reviews. A change in ownership, a sanctions designation, or a damaging news story can arrive the week after a review and sit unnoticed until the next one. Reviews also take heavy analyst time, and they often send customers a refresh request even when nothing has changed.

What Is Continuous KYC?

Continuous KYC, sometimes called perpetual KYC, monitors customers on an ongoing basis instead of waiting for a date on the calendar. Specific signals trigger a review of the affected customer.

Signals Worth Watching

Common triggers include changes in beneficial ownership or company registry filings, new sanctions or watchlist entries, adverse media, changes in directors or senior management, and unusual account activity. The point is not to collect every signal but to surface the ones that change a customer's risk profile.

A Trigger Starts a Review, Not a Decision

A continuous system should raise a flag with evidence attached. A person still decides whether the change matters, whether to ask the customer for more information, and whether to escalate. Treating an alert as a verdict is how banks end up with unexplained account closures.

What Do the Rules Actually Require?

In the United States, FinCEN's customer due diligence rule, issued in final form in May 2016, added what practitioners call the fifth pillar of an AML program. According to a Kelley Drye summary, it requires risk-based procedures for ongoing customer due diligence, including understanding the nature and purpose of customer relationships to develop a customer risk profile, and conducting ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information.

The update requirement is described as event-driven. A Covington analysis says it is triggered by information that arises in the normal course of monitoring, not by a fixed update calendar. In practice, that means the rule does not name continuous KYC or periodic review as the required method. It asks for a risk-based process that keeps customer information current. Other jurisdictions and individual regulators set their own expectations, so check the guidance that applies to your institution.

Continuous KYC vs Periodic Review: Side by Side

Where Do the Two Approaches Work Best Together?

A hybrid model fits how most banks are organized. Continuous monitoring covers the customers where a missed change would hurt most, such as higher-risk relationships, complex ownership structures, and exposure to higher-risk jurisdictions. A lighter periodic review remains as a backstop for the whole book, which also protects against any signal source that fails silently.

The practical design questions are simple. Which customers sit in which tier, which signals count as triggers, who owns each alert, and how long a review should take. Writing those answers down makes the program easy to defend.

How Do You Avoid Alert Overload?

Continuous monitoring fails when it produces more alerts than people can read. Four habits keep it workable. Tune triggers to materiality, so a minor address change does not rank with a new sanctions match. Require every alert to carry the source that raised it, so reviewers do not have to rediscover the evidence. Route alerts by risk tier, so the riskiest ones reach senior reviewers first. And record why alerts were dismissed, because a documented dismissal is as important to an examiner as a documented escalation.

Measure the results too. The share of alerts that lead to a changed risk rating, and the time from signal to decision, tell you whether the monitoring is helping or just creating noise.

How Are Teams Building Continuous Monitoring?

There are three common routes. Some banks extend their existing screening and transaction monitoring rules to cover more signals. Others buy a screening platform that supplies data feeds and alerting. A third route is a custom AI agent that runs on a schedule and attaches a source to every finding. Grep, for example, builds custom agents for compliance oversight and runs always-on Monitors for ongoing screening instead of one-time checks, with output designed to be traceable and auditable. 

The test is the same whichever route you choose: can an examiner follow each alert back to the evidence behind it?

Final Thoughts

Continuous KYC and periodic review answer different questions. One asks whether it is time to look again, and the other asks whether anything has changed. Banks that combine them, tie each alert to evidence, and document their decisions can show examiners a process that is both current and defensible.

Frequently Asked Questions (FAQs)

What is continuous KYC?

Continuous KYC is the ongoing monitoring of customers for changes that affect risk, such as ownership, sanctions, adverse media, or management changes, with reviews triggered by those changes instead of a calendar.

Is continuous KYC required by regulators?

In the U.S., the customer due diligence rule requires ongoing monitoring and risk-based updating of customer information, but it does not name continuous KYC as the method. Check your own regulator's guidance.

Does continuous KYC replace periodic review?

Not usually. Many banks keep a lighter periodic review as a backstop and use continuous monitoring for higher-risk customers.

What triggers a KYC refresh?

Typical triggers are a change in beneficial ownership, a new sanctions or watchlist match, adverse media, a change in directors or management, or unusual account activity.

How do you reduce false alerts?

Tune triggers to materiality, attach sources to every alert, route by risk tier, and track how many alerts lead to a changed risk rating.



Report this content

If you believe this article contains misleading, harmful, or spam content, please let us know.

Report this article