Skip to main content
Category: Customer Due Diligence

Trigger Event Review

Also known as: Trigger Review, KYC Trigger Event Review, Event-Driven Review
Simply put

A Trigger Event Review is a fresh look at a customer's information that is prompted by a specific change, rather than by the routine schedule on which customers are normally reviewed. The change might be in the customer's behaviour, their transaction patterns, or outside information about them. Its purpose is to keep the institution's understanding of the customer accurate and up to date.

Formal definition

A Trigger Event Review is a Customer Due Diligence (CDD) reassessment conducted outside the periodic (calendar-driven) review cycle, prompted by a material change in a client's profile, behaviour, transaction patterns, or external circumstances. Such trigger events, which may include red flags or changes in customer behaviour, transaction activity, or external information, can prompt a standard CDD refresh and, where risk indicators warrant, an escalation to Enhanced Due Diligence (EDD) involving intensified scrutiny. The specific events that constitute triggers, and the resulting review obligations, are typically defined within an obliged entity's own risk-based CDD policies; the identification of a trigger event or the conduct of a review is an operational risk-management measure and does not itself establish wrongdoing. Exact requirements, thresholds, and scope should be confirmed against the applicable regulatory regime and internal procedures.

Why it matters

A customer's risk profile is not static. The information gathered when an account is opened can become outdated as behaviour changes, transaction patterns shift, or new external information emerges about the customer. Relying solely on periodic, calendar-driven reviews can leave gaps in which an institution's understanding of a customer no longer reflects reality. A Trigger Event Review addresses this by prompting a fresh look at customer information when a specific material change occurs, helping obliged entities keep their Customer Due Diligence (CDD) records accurate and current between scheduled reviews.

Maintaining an up-to-date understanding of the customer is central to a functioning risk-based approach. Where a trigger event surfaces indicators of elevated risk, it may prompt an escalation from a standard CDD refresh to Enhanced Due Diligence (EDD), involving more intensive scrutiny. This responsiveness is a risk-management measure intended to detect, deter, and mitigate financial crime risk; it is not a guarantee that risk has been eliminated, and the specific events that qualify as triggers are typically defined within each institution's own risk-based CDD policies rather than by a single universal rule.

It is important to distinguish the operational nature of these reviews from any inference of wrongdoing. The identification of a trigger event, or the conduct of a review in response to one, is an internal risk-management step. It does not itself establish that a customer has engaged in illicit activity. Exact obligations, thresholds, and the scope of what constitutes a trigger should always be confirmed against the applicable regulatory regime and the institution's internal procedures, which may differ by jurisdiction.

Who it's relevant to

CDD and KYC Analysts
Analysts responsible for maintaining customer records rely on trigger event processes to know when a customer file needs to be revisited outside the periodic cycle. They apply the institution's defined triggers to determine when a standard CDD refresh is required and when the case may warrant escalation for closer review.
Compliance Officers and MLROs
Those responsible for the AML program design the risk-based CDD policies that define what constitutes a trigger event and the resulting review obligations. They must ensure these policies keep the institution's understanding of its customers current and align with the applicable regulatory regime and internal risk appetite.
Financial Intelligence and Investigations Teams
Investigators may act on red flags or changes in transaction patterns that surface trigger events, and they conduct or support the intensified scrutiny that follows where enhanced review is warranted. They should treat a triggered review as a risk-management step, not as evidence that a customer has engaged in wrongdoing.
Risk and Audit Functions
Risk and internal audit professionals assess whether trigger event review processes operate as intended, whether triggers are being identified, reviews conducted, and escalations to Enhanced Due Diligence handled consistently with policy, and whether the controls appropriately manage rather than purport to eliminate financial crime risk.

Inside Trigger Event Review

Trigger Event
A specific, predefined occurrence that prompts an obliged entity to reassess a customer relationship outside of the regular periodic review cycle. Common triggers may include a material change in customer behavior, a significant change in transaction patterns, a change in beneficial ownership or control, a new adverse media or sanctions hit, or a change in the customer's risk profile. The precise list of events that qualify as triggers is generally set by the entity's own risk-based policies rather than by a single universal standard.
Event-Driven Refresh of CDD
The core activity of a trigger event review is to update or re-perform customer due diligence (CDD) information in response to the event, which may involve refreshing identification data, verifying updated beneficial ownership, and reassessing the customer risk rating. This is distinct from scheduled periodic reviews, which occur at set intervals regardless of any event.
Regulatory and Policy Basis
The expectation to conduct ongoing monitoring and to keep CDD information up to date is reflected in various frameworks, such as the FATF Recommendations (as standards), the EU AML Directives, the US Bank Secrecy Act and FinCEN rules, and the UK Money Laundering Regulations. However, the specific concept of a 'trigger event review' is typically an operational construct within an AML program rather than a uniformly defined legal term, and exact obligations vary by jurisdiction and should be confirmed against the applicable regime.
Risk Reassessment Outcome
The review may result in confirming the existing risk rating, escalating to enhanced due diligence (EDD), de-risking or exiting the relationship, or filing an internal report where suspicion arises. The outcome is a risk-management decision and does not, by itself, establish wrongdoing.
Documentation and Audit Trail
The event, the analysis performed, the information refreshed, and the resulting decision are generally recorded to evidence that the entity is managing risk on an ongoing basis and can demonstrate its rationale to regulators or auditors.

Common questions

Answers to the questions practitioners most commonly ask about Trigger Event Review.

Is a trigger event review the same as a scheduled periodic review?
No. A trigger event review is prompted by a specific change or occurrence relating to a customer or their activity, whereas a periodic review is conducted at predetermined intervals based on the customer's risk rating. The two are complementary rather than interchangeable: a trigger event may prompt an out-of-cycle review that does not reset or replace the next scheduled periodic review, and many programs run both. The precise interplay between the two should be defined in an obliged entity's own CDD policies, consistent with the ongoing monitoring expectations of the applicable regime.
Does a trigger event mean the customer has done something wrong or that a SAR must be filed?
No. A trigger event is an operational prompt to review and, where appropriate, refresh customer due diligence information; it is not in itself an indication of wrongdoing. The purpose of the review is to reassess whether the customer's risk profile and CDD information remain accurate and adequate. Whether any suspicious activity report or equivalent filing is warranted is a separate determination governed by the applicable suspicion threshold and reporting regime, and it depends on the findings of the review rather than on the occurrence of the trigger itself.
What types of events typically function as triggers for an out-of-cycle review?
Common examples cited in AML programs include a change in beneficial ownership or control, a significant change in the customer's transaction patterns or expected activity, a change of address or jurisdiction, a new adverse media or sanctions or PEP screening result, or the customer entering a new product or higher-risk relationship. This list is illustrative rather than exhaustive, and the specific triggers an obliged entity adopts should be calibrated to its own risk assessment and documented in policy, consistent with the ongoing monitoring expectations of the relevant framework.
How should trigger events be detected and routed for review in practice?
Detection generally relies on a combination of automated monitoring (for example, transaction monitoring alerts and screening system hits) and manual inputs (for example, information disclosed by relationship staff or received from the customer). Once identified, a defined workflow should route the event to the appropriate team with a documented timeframe for completion and clear ownership. The mix of automated and manual detection, and the escalation path, will vary by the size, systems, and risk profile of the obliged entity.
What should be documented when a trigger event review is conducted?
As a matter of good practice and to support auditability, records typically capture what event prompted the review, when it was identified, what CDD information was reviewed or refreshed, any change to the customer's risk rating, the rationale for conclusions reached, and any onward actions such as escalation or referral for suspicion assessment. Retention of these records should follow the record-keeping obligations of the applicable regime, the precise duration and scope of which should be confirmed against the relevant regulation.
How do trigger event reviews fit within a wider risk-based ongoing monitoring framework?
Trigger event reviews are one component of ongoing monitoring, working alongside risk-based periodic reviews and continuous transaction monitoring to help keep CDD information current and to detect, deter, and manage financial crime risk. They are a mechanism for responding to change between scheduled reviews rather than a standalone control, and no single element guarantees prevention of financial crime. The design, frequency, and thresholds for these reviews should be proportionate to assessed risk and aligned with the ongoing due diligence expectations of the applicable framework.

Common misconceptions

A trigger event review is the same as a scheduled periodic review.
They are related but not identical. A periodic review occurs at set intervals based on the customer's risk rating, whereas a trigger event review is prompted by a specific occurrence and takes place outside the regular cycle. In practice the two are complementary components of ongoing monitoring rather than interchangeable processes.
A trigger event, or the alert that prompts a review, is proof that the customer has committed a crime.
A trigger event is a signal to reassess risk, not evidence of criminality. It may lead to further review, EDD, or an internal report, but a match, alert, or refreshed risk rating does not by itself establish wrongdoing. Any determination of criminal conduct is a matter for the appropriate authorities.
The list of trigger events is fixed and identical across all firms and jurisdictions.
There is generally no single universal list. What constitutes a trigger event is typically defined within an entity's own risk-based policies, informed by applicable frameworks such as the FATF Recommendations, EU AML Directives, US BSA/FinCEN rules, or UK Money Laundering Regulations, which diverge in detail. Specific requirements should be confirmed against the applicable regulation.

Best practices

Maintain a clearly documented, risk-based policy that defines what qualifies as a trigger event, and review that list periodically so it remains aligned with the entity's risk appetite and applicable jurisdictional requirements.
Integrate trigger event reviews with ongoing monitoring systems so that relevant occurrences, such as adverse media hits, changes in beneficial ownership, or shifts in transaction patterns, can flow into the review process in a timely manner.
Ensure trigger event reviews complement, rather than replace, scheduled periodic reviews, and clearly distinguish the two within procedures to avoid gaps in coverage.
Where a trigger event elevates the customer's risk profile, apply enhanced due diligence measures proportionate to the risk, and document the rationale for any escalation, de-risking, or exit decision.
Record the event, the analysis conducted, the CDD information refreshed, and the outcome to create a defensible audit trail that demonstrates ongoing risk management to regulators and auditors.
Confirm the precise obligations, thresholds, and expectations against the specific regulation applicable to the entity's jurisdiction and sector, rather than assuming a single global standard applies.