Skip to main content
Category: Customer Due Diligence

Perpetual KYC

Also known as: pKYC, perpetual KYC, continuous KYC, ongoing KYC
Simply put

Perpetual KYC (pKYC) is an approach to keeping customer information current by updating and re-verifying it continuously as a customer's behavior or circumstances change, rather than at fixed intervals. Instead of reviewing a customer's file only on a set schedule, the customer's data and risk profile are refreshed in real-time or near-real-time. This is intended to help firms maintain more accurate customer records and monitor changes in risk on an ongoing basis.

Formal definition

Perpetual KYC (pKYC) is an ongoing, dynamic approach to customer due diligence in which customer identity, profile, and risk information are continuously monitored and updated based on changes in the customer's behavior and circumstances, typically in real-time or near-real-time. It is generally positioned as an alternative to traditional periodic KYC refresh cycles (for example, scheduled reviews triggered by fixed time intervals or risk ratings), whereby updates are event-driven and triggered by observed changes rather than by the calendar. As described in the evidence, pKYC is characterized as a transformative or continuous methodology for maintaining accurate client data and monitoring risk across a customer network; it is an operational and technological practice rather than a defined regulatory obligation, and the underlying due diligence and record-keeping requirements it seeks to satisfy remain governed by the applicable AML/CFT regime in each jurisdiction. The exact scope, triggers, and cadence of a given pKYC implementation vary by firm and should be confirmed against the relevant regulatory framework and internal policy.

Why it matters

Traditional customer due diligence has often relied on periodic KYC refresh cycles, in which a customer's file is reviewed on a fixed schedule, commonly tied to a risk rating, so that higher-risk customers are reviewed more frequently than lower-risk ones. A recognized limitation of this model is that a customer's circumstances or behavior can change materially between scheduled reviews, leaving a firm's records out of date and its risk understanding stale in the interim. Perpetual KYC (pKYC) is positioned as a response to this gap, aiming to keep customer information and risk profiles current on a continuous, event-driven basis rather than only when the calendar dictates.

For obliged entities, maintaining accurate and up-to-date customer information and conducting ongoing monitoring are recurring themes across AML/CFT frameworks, though the specific obligations, and how they must be met, vary by jurisdiction and should be confirmed against the applicable regime. pKYC is an operational and technological practice intended to help firms satisfy these underlying due diligence and record-keeping requirements more responsively; it is not itself a defined regulatory obligation, and adopting a pKYC model does not change what the applicable law requires. Firms considering or implementing pKYC should therefore treat it as a means of managing and monitoring customer risk on a more timely basis, not as a control that guarantees the detection of financial crime.

Who it's relevant to

Compliance officers and MLROs
Those responsible for a firm's CDD and ongoing monitoring frameworks may consider pKYC as an alternative to periodic refresh cycles for keeping customer records and risk profiles current. They should assess how a pKYC model maps to the specific due diligence, ongoing monitoring, and record-keeping obligations under their applicable regime, recognizing that pKYC is a practice to support those obligations rather than a regulatory requirement in itself.
Financial intelligence and transaction monitoring analysts
Analysts may work with the near-real-time signals that a pKYC approach uses to detect changes in customer behavior and circumstances. Continuously updated customer profiles can inform investigative work, though such updates and alerts indicate changes to be reviewed and do not, on their own, establish wrongdoing.
Operations and onboarding teams
Teams that manage customer data and re-verification workflows are directly affected by a shift from scheduled reviews to continuous, event-driven updates, which changes how and when customer information is refreshed and maintained.
Technology, data, and vendor management functions
Because pKYC is described as a technology-enabled practice for continuously maintaining accurate client data and monitoring risk, these functions are relevant to designing, integrating, and governing the data feeds and systems that support real-time or near-real-time updates, including any third-party solutions.
Risk and audit professionals
Second- and third-line functions have an interest in how a pKYC implementation's triggers, scope, and cadence are defined and whether the approach continues to satisfy the firm's obligations under the applicable AML/CFT framework, since implementations vary by firm and should be validated against regulation and internal policy.

Inside pKYC

Continuous Monitoring Model
An approach to customer due diligence in which customer information and risk profiles are reviewed on an ongoing, event-driven basis rather than at fixed periodic intervals. This contrasts with traditional cyclical review schedules (for example, reviews scheduled by risk tier), though many programs operate a hybrid of the two.
Event-Driven Triggers
Predefined changes or events that prompt a reassessment of a customer, such as changes in beneficial ownership, transactional behavior inconsistent with the expected profile, adverse media, sanctions or PEP status changes, or updates to identifying information. Triggers are configured to reflect the obliged entity's risk assessment.
Data Integration and Quality
The consolidation of internal and external data sources (transaction data, screening results, registry information, adverse media feeds) into a usable customer view. The reliability of pKYC depends heavily on data accuracy, completeness, and timeliness.
Automation and Technology
The use of workflow automation, APIs to data providers, and analytics to identify changes and route cases for review. Automation supports scale but generally requires human review for material risk decisions, and outputs should be validated rather than treated as conclusive.
Dynamic Risk Rating
The recalculation of a customer's risk classification as new information becomes available, which may move a customer into higher-risk categories that could warrant enhanced due diligence (EDD) or lower-risk categories, subject to the applicable methodology.
Relationship to CDD and EDD Obligations
pKYC is an operating model for meeting ongoing due diligence and monitoring expectations; it does not create new obligations in itself. The underlying requirements to keep CDD information up to date derive from applicable regimes such as the EU AML framework, the UK Money Laundering Regulations, and the US Bank Secrecy Act and FinCEN rules, and from FATF standards, which are recommendations rather than binding law.

Common questions

Answers to the questions practitioners most commonly ask about pKYC.

Does perpetual KYC mean customer due diligence is fully automated and no longer requires human review?
No. Perpetual KYC (pKYC) refers to an approach that continuously monitors and refreshes customer information as events and data changes occur, rather than relying solely on fixed periodic review cycles. While automation is central to making this operationally feasible, it does not remove the need for human judgment. Material changes, elevated-risk scenarios, and events that trigger enhanced due diligence generally still require analyst review and documented decision-making. pKYC is better understood as a shift in how and when review is triggered, moving from calendar-driven to event- and risk-driven, rather than the elimination of human oversight.
Is perpetual KYC a specific regulatory requirement that obliged entities must adopt?
Generally, no. pKYC is an operational and technological model rather than a defined regulatory obligation. Many AML frameworks, such as the FATF Recommendations as standards, and their implementation through instruments like the EU AML Directives, the US Bank Secrecy Act and associated FinCEN rules, or the UK Money Laundering Regulations, typically require ongoing monitoring of the business relationship and keeping CDD information up to date. pKYC is one way obliged entities may seek to meet those ongoing monitoring and record-currency expectations, but adopting it as a named methodology is generally a business decision, not a mandated one. Specific expectations should be confirmed against the applicable regime and supervisory guidance.
What data sources typically feed a perpetual KYC process?
A pKYC process generally draws on a combination of internal and external data. Internal sources may include transaction activity, changes in product usage, and customer-provided updates. External sources can include corporate registries, beneficial ownership data, sanctions and PEP screening feeds, adverse media, and other third-party data providers. The aim is to detect changes that may alter a customer's risk profile so that CDD records can be refreshed and, where warranted, escalated. The completeness and reliability of these sources should be assessed, as gaps can limit the effectiveness of the model.
How does perpetual KYC change the role of periodic reviews?
Under a traditional model, customers are typically reviewed at fixed intervals tied to risk rating. A pKYC approach aims to replace or supplement these fixed cycles with event-driven triggers, so reviews occur when meaningful changes are detected rather than only on a schedule. In practice, many institutions operate a hybrid model, retaining some periodic review elements, particularly for higher-risk relationships, while layering continuous monitoring on top. Firms generally need to define clearly what constitutes a trigger event and how such events map to review and escalation actions.
What are common implementation challenges when moving to perpetual KYC?
Typical challenges include data quality and integration across fragmented systems, defining and calibrating trigger events to avoid excessive false positives, managing alert volumes, and ensuring that automated processes remain explainable and auditable. Governance considerations include documenting the rationale for triggers, maintaining oversight of automated decisions, and demonstrating to supervisors how the approach meets ongoing monitoring expectations. Firms also generally need to manage the transition without creating gaps in coverage while legacy periodic processes are retired or reconfigured.
How should a firm evidence the effectiveness of a perpetual KYC program to supervisors?
Firms are generally expected to be able to demonstrate that their approach keeps CDD information current and detects changes relevant to customer risk. This typically involves documenting the design and calibration of trigger logic, maintaining audit trails of alerts, decisions, and escalations, and evidencing human oversight where required. Management information on coverage, alert handling, and outcomes can help show that the model is functioning as intended. Because pKYC is a means of meeting ongoing monitoring expectations rather than a standalone requirement, effectiveness should be evidenced against the specific obligations of the applicable regime, and no single control should be presented as guaranteeing the prevention of financial crime.

Common misconceptions

pKYC is a specific regulatory requirement that obliged entities must adopt.
pKYC is an operational and technology-driven approach, not a defined regulatory mandate. Regimes such as the EU AML framework, the UK Money Laundering Regulations, and US BSA/FinCEN rules generally require that CDD information be kept up to date and that monitoring occur on an ongoing basis, but they typically do not prescribe pKYC as the method. Firms may meet these expectations through periodic reviews, event-driven reviews, or a hybrid, subject to the applicable regulation.
Implementing pKYC eliminates the need for periodic reviews and for human analysts.
Continuous, event-driven monitoring may reduce reliance on fixed-cycle reviews, but many programs retain periodic reviews as a control and to satisfy supervisory expectations. Automation supports detection and prioritization; material risk decisions generally still require human judgment, and automated triggers or matches do not by themselves establish wrongdoing.
pKYC guarantees that financial crime and out-of-date customer records will be prevented.
pKYC is a measure to detect, deter, and manage risk more responsively; it does not guarantee prevention. Its effectiveness depends on data quality, trigger design, and calibration, and no single control eliminates money laundering or terrorist financing risk.

Best practices

Base trigger design on the firm's own risk assessment, ensuring that event-driven reviews capture material changes such as shifts in beneficial ownership, transactional behavior, adverse media, and sanctions or PEP status changes.
Invest in data quality and integration, since the reliability of continuous monitoring depends on accurate, complete, and timely internal and external data sources.
Retain human review for material risk decisions and treat automated alerts, triggers, and screening matches as prompts for investigation rather than as conclusions of wrongdoing.
Consider a hybrid model that combines event-driven monitoring with retained periodic reviews where appropriate to meet supervisory expectations and provide a control baseline.
Ensure dynamic risk ratings feed appropriately into CDD and EDD workflows, so that customers moving into higher-risk categories receive the enhanced measures required under the applicable regime.
Document the methodology, trigger logic, and governance of the pKYC model, and confirm that the approach satisfies the ongoing due diligence and monitoring obligations of each relevant jurisdiction rather than assuming a single global standard applies.