Skip to main content
Category: Customer Due Diligence

Periodic Review

Also known as: Scheduled KYC Review, Ongoing Customer Review
Simply put

A periodic review is a scheduled check that a financial institution carries out on an existing customer to make sure the information it holds is still accurate and that the customer's activity matches what the institution expects. Unlike a review triggered by a specific event, this type of review happens on a set timetable, which is often more frequent for customers considered higher risk. It is a way to keep customer records and risk assessments up to date over the life of the relationship.

Formal definition

In an AML/KYC context, a periodic review is the scheduled reassessment of an existing customer relationship, typically encompassing refreshed customer information, an updated risk profile, and a review of account and transaction activity against expected behavior. It forms part of the ongoing due diligence and monitoring components of a customer due diligence (CDD) program, and is generally distinguished from event-driven or trigger-based reviews, which are prompted by specific changes such as material transactions, adverse media, or profile updates. Review frequency is commonly calibrated on a risk-sensitive basis, with higher-risk customers reviewed more often; specific cycles, scope, and documentation requirements are set by the obliged entity's internal policies and by applicable regulatory frameworks, and exact expectations should be confirmed against the relevant regime. The term is used across multiple non-AML domains (for example, human rights peer review, computerized-system validation, and quality management), which are outside the scope of this definition.

Why it matters

Customer information collected at onboarding degrades over time. Circumstances change, ownership structures evolve, and activity patterns shift, meaning that a risk assessment accurate on day one can become stale and misleading. Periodic reviews address this by scheduling reassessments across the life of a relationship, so that the institution's records, risk ratings, and understanding of expected activity remain current rather than frozen at account opening. Without such reviews, an institution may be relying on outdated assumptions when monitoring transactions or responding to regulatory inquiries.

Because the review cadence is typically calibrated on a risk-sensitive basis, periodic reviews also operationalize the risk-based approach that underpins ongoing due diligence. Higher-risk customers are generally reviewed more frequently, concentrating resources where the potential for exposure is greatest, while lower-risk relationships may be reviewed on longer cycles. This helps an institution demonstrate to supervisors that it manages customer risk dynamically rather than treating due diligence as a one-time onboarding event. It is important to note, however, that a periodic review is a control to help detect and manage risk over time, not a guarantee that misconduct will be identified or prevented.

Who it's relevant to

Compliance Officers and CDD Program Owners
Those responsible for designing and maintaining a customer due diligence program set the review cycles, scope, and documentation standards for periodic reviews. They must calibrate frequency on a risk-sensitive basis and ensure the approach aligns with the institution's internal policies and applicable regulatory framework.
KYC Analysts and Relationship Review Teams
Analysts who execute periodic reviews refresh customer information, update risk profiles, and assess account and transaction activity against expected behavior. They are typically the first to identify discrepancies that may warrant further inquiry or escalation.
Transaction Monitoring and Financial Intelligence Analysts
Because periodic reviews assess activity against expected behavior, the outputs feed into and complement ongoing transaction monitoring. Analysts benefit from up-to-date risk profiles and refreshed expectations when evaluating whether activity is consistent with what is known about the customer.
Risk and Audit Functions
Risk and internal audit teams rely on periodic review records to demonstrate that customer risk is managed dynamically over the life of a relationship rather than only at onboarding. Documentation of scheduled reviews supports supervisory examinations and internal assurance over the ongoing due diligence process.

Inside Periodic Review

Refresh of Customer Due Diligence (CDD) Information
A periodic review typically involves re-verifying and updating the customer identification and due diligence information collected at onboarding, ensuring that records remain current and accurate. This generally includes confirming identity details, expected activity, and the purpose and intended nature of the relationship.
Reassessment of Customer Risk Rating
The review generally re-evaluates the risk classification assigned to the customer, taking into account changes in the customer's profile, behavior, geography, or products used. Under a risk-based approach, this reassessment may result in the customer being moved to a higher or lower risk category.
Beneficial Ownership Verification
Where applicable, the review typically confirms that beneficial ownership information remains accurate, distinguishing beneficial ownership from legal ownership. Changes in control or ownership structure may trigger further inquiry or updated documentation.
Screening Updates
Periodic reviews often incorporate refreshed sanctions screening and PEP screening, which are distinct exercises: sanctions screening tests against designated-party lists, while PEP screening identifies politically exposed persons. Screening may also cover adverse media as part of ongoing monitoring.
Review Trigger and Frequency
Reviews are commonly scheduled on a cycle calibrated to customer risk, higher-risk customers are typically reviewed more frequently than lower-risk ones. Reviews may also be event-driven, triggered by material changes in customer activity or profile rather than only by the calendar.
Transaction Activity Analysis
The review generally compares actual transaction behavior against the expected activity established at onboarding, helping to identify discrepancies that may warrant escalation, enhanced due diligence, or, where warranted, internal reporting.

Common questions

Answers to the questions practitioners most commonly ask about Periodic Review.

Is a periodic review the same as a trigger-based or event-driven review?
No. A periodic review is a scheduled refresh of customer due diligence information carried out at set intervals, typically calibrated to the customer's assessed risk rating. A trigger-based (or event-driven) review is prompted by a specific occurrence, such as a material change in the customer's circumstances, unusual transaction activity, adverse media, or a change in beneficial ownership. Many AML programs operate both approaches in parallel: the periodic cycle provides a baseline cadence, while trigger events prompt reviews outside that cycle. They are complementary controls, not substitutes, and the presence of one does not remove the obligation to maintain the other where the applicable framework or internal policy calls for it.
Does completing a periodic review confirm that a customer is not involved in financial crime?
No. A periodic review is a control designed to keep customer due diligence information current and to help detect, deter, and manage financial crime risk over the life of a relationship. It does not verify a customer's innocence or guarantee that illicit activity is absent. A completed review, a clean screening result, or the absence of alerts does not establish that a customer is free of wrongdoing, just as it does not establish wrongdoing. The review is an ongoing monitoring measure that supports risk management; conclusions about criminal conduct are a separate matter determined through other processes and, ultimately, the criminal law.
How is the frequency of periodic reviews typically determined?
Frequency is generally set on a risk-sensitive basis, with higher-risk customers reviewed more often and lower-risk customers reviewed at longer intervals. The specific cadences are usually defined in an obliged entity's internal policies rather than fixed uniformly across jurisdictions. Because requirements around ongoing monitoring and keeping CDD information up to date vary by regime, firms should align their review cycles with the applicable regulations and supervisory expectations, and confirm any specific intervals against those sources rather than assuming a single global standard applies.
What information is typically refreshed during a periodic review?
A periodic review typically revisits the core elements of customer due diligence to confirm they remain accurate and current. This may include customer identification and verification details, beneficial ownership information, the nature and intended purpose of the relationship, expected versus actual activity, screening for sanctions and politically exposed person status, and adverse media, alongside a reassessment of the customer's risk rating. The exact scope depends on the customer's risk profile and the firm's policies, and firms should note that beneficial ownership is distinct from legal ownership and both may need to be re-confirmed where relevant.
How should a firm handle a periodic review when the customer does not respond to information requests?
Where a customer fails to provide requested information needed to complete a review, firms generally follow escalation procedures set out in their policies, which may include repeated outreach, restrictions on activity, or consideration of exiting the relationship. In many jurisdictions, an inability to maintain adequate and current due diligence information can affect whether a firm can continue to satisfy its ongoing monitoring obligations. Any decision about restricting or terminating a relationship should be documented and made in line with the applicable regulatory framework and the firm's internal governance; specific obligations should be confirmed against the relevant regime.
How is the completion of periodic reviews typically evidenced and governed?
Firms generally maintain records demonstrating that reviews were performed on schedule, what was assessed, the outcome, and any resulting changes to risk rating or actions taken. Management information on overdue or completed reviews is often reported through governance and oversight structures. Robust record-keeping supports both supervisory examination and internal quality assurance. The specific record-keeping periods and documentation expectations vary by jurisdiction and should be confirmed against the applicable regulations rather than assumed to be identical across regimes.

Common misconceptions

A periodic review is a one-size-fits-all annual exercise applied uniformly to every customer.
Under a risk-based approach, review frequency and intensity generally vary by customer risk rating. Higher-risk relationships are typically reviewed more often and in greater depth, while lower-risk customers may be reviewed on a longer cycle. Exact frequencies are set by an institution's policies within its applicable regulatory framework rather than by a single universal rule.
Periodic review is the same as ongoing monitoring, so having one means the other is covered.
Periodic review is a point-in-time refresh of due diligence conducted on a cycle or trigger, whereas ongoing monitoring is a continuous process of scrutinizing transactions and behavior throughout the relationship. They are complementary but distinct measures, and neither substitutes for the other.
Escalation or a change in risk rating during a review establishes that the customer has engaged in wrongdoing.
A review outcome such as a risk upgrade, an alert, or an internal escalation is a risk-management signal to investigate further, it does not establish criminal conduct. Any determination of wrongdoing is a separate matter, and reviews function to detect and manage risk rather than to prove illegality.

Best practices

Calibrate review frequency and depth to the customer's risk rating, reviewing higher-risk relationships more often and more thoroughly, consistent with a documented risk-based approach.
Combine scheduled periodic reviews with event-driven triggers so that material changes in a customer's activity, ownership, or profile prompt an off-cycle review rather than waiting for the next scheduled date.
Verify that CDD data, beneficial ownership information, and screening results are refreshed as part of each review, treating sanctions screening and PEP screening as separate exercises.
Compare actual transaction activity against the expected activity established at onboarding, and document the rationale for any discrepancies, risk-rating changes, or escalations.
Maintain clear, auditable records of each review, including what was checked, findings, and outcomes, so the process can be evidenced to internal audit and, where relevant, supervisors.
Confirm applicable review requirements, thresholds, and timing against the specific regulations governing the institution, since obligations vary across jurisdictions and by type of obliged entity.