Periodic Review
A periodic review is a scheduled check that a financial institution carries out on an existing customer to make sure the information it holds is still accurate and that the customer's activity matches what the institution expects. Unlike a review triggered by a specific event, this type of review happens on a set timetable, which is often more frequent for customers considered higher risk. It is a way to keep customer records and risk assessments up to date over the life of the relationship.
In an AML/KYC context, a periodic review is the scheduled reassessment of an existing customer relationship, typically encompassing refreshed customer information, an updated risk profile, and a review of account and transaction activity against expected behavior. It forms part of the ongoing due diligence and monitoring components of a customer due diligence (CDD) program, and is generally distinguished from event-driven or trigger-based reviews, which are prompted by specific changes such as material transactions, adverse media, or profile updates. Review frequency is commonly calibrated on a risk-sensitive basis, with higher-risk customers reviewed more often; specific cycles, scope, and documentation requirements are set by the obliged entity's internal policies and by applicable regulatory frameworks, and exact expectations should be confirmed against the relevant regime. The term is used across multiple non-AML domains (for example, human rights peer review, computerized-system validation, and quality management), which are outside the scope of this definition.
Why it matters
Customer information collected at onboarding degrades over time. Circumstances change, ownership structures evolve, and activity patterns shift, meaning that a risk assessment accurate on day one can become stale and misleading. Periodic reviews address this by scheduling reassessments across the life of a relationship, so that the institution's records, risk ratings, and understanding of expected activity remain current rather than frozen at account opening. Without such reviews, an institution may be relying on outdated assumptions when monitoring transactions or responding to regulatory inquiries.
Because the review cadence is typically calibrated on a risk-sensitive basis, periodic reviews also operationalize the risk-based approach that underpins ongoing due diligence. Higher-risk customers are generally reviewed more frequently, concentrating resources where the potential for exposure is greatest, while lower-risk relationships may be reviewed on longer cycles. This helps an institution demonstrate to supervisors that it manages customer risk dynamically rather than treating due diligence as a one-time onboarding event. It is important to note, however, that a periodic review is a control to help detect and manage risk over time, not a guarantee that misconduct will be identified or prevented.
Who it's relevant to
Inside Periodic Review
Common questions
Answers to the questions practitioners most commonly ask about Periodic Review.