Learn more about the latest security and privacy threats
Back

Perpetual KYC vs Periodic KYC: Why Annual Reviews Don't Survive 2026 Audits

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published July 26, 2026 Updated August 8, 2026
Magnifying glass over a customer list representing perpetual versus periodic KYC review

Annual KYC reviews are a paper-era residue. See what FFIEC, the FCA and the EU AML framework actually require, and the cost of perpetual versus periodic.

Table of contents
  • The belief that an annual periodic review equals compliance is a paper-era residue, not a rule. Regulators ask for risk-based, ongoing due diligence, not a fixed calendar.
  • Perpetual KYC means continuous monitoring with event-driven re-verification, so a customer whose risk changes is reassessed when it changes, not at the next scheduled review.
  • The FFIEC manual, the FCA's systems-and-controls expectations, and the EU AML framework all frame customer due diligence as ongoing, which periodic review only loosely approximates.
  • Three trigger classes drive re-verification: internal (transaction patterns), external (sanctions and watchlist updates), and customer life events (address, employment, or beneficial-ownership changes).
  • A perpetual KYC stack is built from registry change-data-capture, sanctions-update feeds, and transaction-pattern alerts routed back into the KYC layer, not a once-a-year batch job.
  • Over a multi-year horizon, perpetual KYC often costs less than repeated full refreshes, while closing the risk windows that periodic review leaves open.

Perpetual KYC is continuous customer due diligence: instead of refreshing a customer's profile on a fixed calendar, the institution monitors for change and re-verifies when an event warrants it, a sanctions update, a transaction-pattern shift, or a life event. Regulators expect risk-based, ongoing due diligence, which a periodic annual review only loosely approximates.

TL;DR

The idea that an annual review keeps you compliant is one of the most expensive misconceptions in financial crime. No major regulator actually mandates a fixed calendar; they require risk-based, ongoing customer due diligence. Periodic review, refreshing every customer on a one-, two-, or three-year cycle regardless of change, is a workaround from the paper era, and it leaves long windows where a customer who became high-risk is still treated as low-risk.

Perpetual KYC replaces the calendar with continuous monitoring and event-driven re-verification. This guide defines periodic, trigger-based, and perpetual CDD, sets out what the FFIEC, the FCA, and the EU AML framework actually expect, explains why annual review became the default anyway, breaks down the three trigger classes, shows how a perpetual CDD stack is built, and compares the cost of perpetual versus periodic over a multi-year horizon.

10 min read. Last updated 9 September 2026.

What is the difference between periodic, trigger-based, and perpetual CDD?

The three models sit on a spectrum from calendar to continuous. Periodic KYC reviews each customer on a fixed schedule by risk tier, every one, two, or three years, regardless of whether anything changed. Trigger-based KYC reviews a customer when a specific event occurs, rather than on a schedule. Perpetual KYC combines continuous monitoring with those event triggers, so the customer's risk picture updates whenever new information arrives and a review fires automatically when something material changes.

The practical distinction is the gap between reviews. Under periodic review, a customer who turns high-risk the day after their annual check waits up to a year before anyone looks again. Perpetual KYC closes that gap by watching continuously and acting on change. It is the same principle behind perpetual KYC as a moving picture rather than a photograph: the assessment is alive, not a snapshot.

What do FFIEC, the FCA, and the EU AML framework actually require?

Read the rules and the calendar disappears. In the US, the FFIEC BSA/AML Examination Manual frames customer due diligence as ongoing, expecting institutions to monitor relationships and update customer information on a risk basis, not to perform a ritual annual refresh. In the UK, the FCA's systems-and-controls expectations and the Money Laundering Regulations require ongoing monitoring of business relationships, including keeping documents and information up to date. In the EU, the AML framework, now consolidating under the AML Regulation, requires ongoing monitoring of the business relationship and keeping customer due diligence current.

None of these says review every customer every twelve months. They say know your customer continuously and act on a risk basis. That is why an examiner who finds a stale, calendar-driven program with year-long blind spots can fault it even though boxes were ticked on schedule. Perpetual KYC is simply the operating model that actually matches what the regulators wrote, which is the through-line of our AML compliance software guidance.

Why did the annual review become standard if the rules don't require it?

If the regulation asks for ongoing due diligence, why does so much of the industry run annual reviews? Because in the paper era, continuous was impossible. You could not monitor every customer in real time when files were physical and checks were manual, so firms approximated ongoing diligence with the most frequent cadence they could staff, often annual for high-risk and longer for lower-risk tiers. The calendar was a proxy for continuity, and over time the proxy got mistaken for the requirement.

The trouble is the proxy no longer holds up. Data is now continuous, registries publish changes, sanctions lists update constantly, and transactions stream in real time, so the technical excuse for the calendar is gone. An annual review in 2026 is not a best effort at ongoing diligence; it is a deliberate choice to ignore eleven months of change. Regulators increasingly see it that way, which is why periodic-only programs are aging badly in examinations.

What are the three trigger classes for perpetual CDD?

Perpetual KYC works because it reacts to defined triggers, and those fall into three classes. Internal triggers come from the customer's own activity: a change in transaction volume, new counterparties or geographies, or patterns inconsistent with their established profile. External triggers come from the world: a sanctions or watchlist update that newly matches the customer, adverse media, or a regulatory change. Customer-life-event triggers come from changes to the customer's identity or circumstances: a new address, a change of employment, an expired document, or a shift in beneficial ownership for a business.

Designing perpetual KYC means wiring each class into the monitoring layer so the relevant review fires automatically and is evidenced. The transaction monitoring layer feeds the internal triggers, sanctions feeds drive the external ones, and identity and registry data surface the life events. The art is calibrating thresholds so genuine change triggers a review without burying analysts in noise.

How do you build a perpetual CDD stack?

A perpetual KYC stack is an integration problem more than a single product. At the data layer it ingests change: change-data-capture from corporate registries so an ownership shift is detected, a sanctions-update feed so new matches surface immediately, and transaction-pattern alerting from monitoring. At the decision layer it routes those signals back into the KYC profile, recalculating risk and firing a review when a threshold is crossed. At the action layer it re-verifies the customer where needed, ideally without re-collecting everything from scratch.

Reusable identity makes the action layer efficient: when a re-verification is triggered, a customer with a reusable credential can confirm their current status without a full re-onboarding, and the underlying data stays under a customer-held key rather than copied into every system, which is the model behind decentralised KYC. Built this way, perpetual KYC is continuous by design, and the audit trail of what triggered each review assembles itself, which is exactly what neobanks running a single customer base need.

How do the costs of perpetual CDD and periodic refresh compare?

The instinct is that continuous monitoring must cost more than an annual review. Over a multi-year horizon, the opposite is often true, because periodic refresh re-does full reviews on a schedule whether or not anything changed, while continuous monitoring only acts when a trigger fires.

DimensionPeriodic KYCPerpetual KYC
CadenceFixed calendar, full re-reviewContinuous monitoring, event-driven review
Work per cycleFull refresh of every customerTargeted re-verification only on triggers
Risk windowUp to the full review intervalClosed as soon as change is detected
Analyst effortBursts of bulk re-reviewSteady, focused on real changes
Audit postureSchedule-based, can be staleTrigger-evidenced, current

Periodic review spends effort on customers whose risk has not changed and ignores customers whose risk changed mid-cycle, which is the worst of both. Perpetual KYC concentrates effort where change actually happens, so over five years it typically reduces wasted re-reviews while closing the risk windows, a better return on both cost and exposure.

When is periodic review still acceptable?

Perpetual is the right default, but it is not the only acceptable model everywhere, and honesty matters. For genuinely low-risk, low-activity customers, a risk-based periodic review at a sensible interval can be defensible, provided it is justified by a documented risk assessment rather than applied by default. Dormant accounts with no activity may not need continuous monitoring in the same way an active high-risk customer does, though they still need handling when they reactivate.

The mistake is not periodic review itself; it is applying a uniform calendar to everyone and calling it compliance. The defensible posture is risk-based: continuous, trigger-driven monitoring for customers and segments where risk can change quickly, and proportionate periodic checks where it genuinely cannot, with the rationale documented either way. If you want to model the cost and risk trade-off for your book, model your perpetual CDD cost.

The bottom line

The annual review survives because it once had to, not because the rules demand it. The FFIEC, the FCA, and the EU AML framework all ask for ongoing, risk-based customer due diligence, and a calendar-driven refresh with eleven-month blind spots is an increasingly hard thing to defend in an examination. Perpetual KYC is simply the operating model that matches the regulation in an era when data is continuous.

Wire in the three trigger classes, route them back into the KYC profile, re-verify efficiently with reusable identity, and keep proportionate periodic checks only where risk genuinely cannot change quickly. Over a multi-year horizon you spend less on pointless re-reviews and close the windows where risk actually hides.

Model your perpetual CDD cost, or see how it works.

Cited sources

  • FFIEC BSA/AML Examination Manual, ongoing customer due diligence: https://bsaaml.ffiec.gov/manual
  • Financial Conduct Authority, financial crime and ongoing monitoring: https://www.fca.org.uk/firms/financial-crime
  • EU Anti-Money Laundering Regulation and AMLA: https://www.amla.europa.eu/about-amla_en
  • FATF Recommendations: https://www.fatf-gafi.org/en/topics/fatf-recommendations.html
Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

Not a defined statutory term, but it describes what regulators actually require: ongoing, risk-based customer due diligence. The FFIEC manual, the FCA's expectations, and the EU AML framework all frame due diligence as continuous rather than calendar-driven. Perpetual KYC is the industry name for operating that way, with continuous monitoring and event-triggered re-verification rather than a fixed annual review.

No single firm owns the concept; it emerged as data and monitoring made continuous due diligence feasible, and major banks and vendors adopted the language as they moved off batch annual reviews. What matters is not who coined it but that it aligns operations with the ongoing-monitoring expectation regulators have always had, which the paper era could only approximate with a calendar.

It depends on your customer base and data integration, but over a multi-year horizon perpetual CDD often costs less than repeated full periodic refreshes, because it only re-verifies on triggers rather than re-reviewing everyone on a schedule. The larger saving is risk reduction: closing the blind windows that periodic review leaves, which is where enforcement and losses concentrate.

Yes. Because regulators require ongoing, risk-based due diligence rather than a specific calendar, continuous monitoring with event-triggered review satisfies the expectation directly, often better than periodic review. The key is that your approach is risk-based and documented. Confirm specifics with your supervisor, but no major framework prohibits it, and several effectively point toward it.

Dormant accounts carry different risk from active ones, so continuous transaction monitoring has little to act on while they are inactive. A risk-based perpetual model still watches external triggers like sanctions updates and handles reactivation as an event that fires re-verification. The point is to treat dormancy as a risk state with its own handling, not to exempt the account from due diligence entirely.

They are used interchangeably. Perpetual customer due diligence, or perpetual CDD, is the broader compliance term for continuous, event-driven due diligence, while continuous monitoring emphasises the identity-verification side of it. In practice both describe the same operating model: monitor continuously, re-verify on triggers, and keep the customer's risk picture current rather than refreshing on a calendar.

Three classes of trigger: internal, such as a change in transaction volume, geography, or pattern; external, such as a sanctions or watchlist match or adverse media; and customer life events, such as an address change, new employment, an expired document, or a beneficial-ownership shift. Wiring these into monitoring makes re-verification automatic and evidenced rather than dependent on a scheduled review.

For most active and higher-risk customers, yes, continuous monitoring supersedes the calendar. For genuinely low-risk, low-activity segments, a documented, risk-based periodic check can still be appropriate as a backstop. The defensible model is not one or the other applied uniformly, but a risk-based blend: perpetual where risk can change quickly, proportionate periodic checks where it genuinely cannot.

See why teams switch to Zyphe

Privacy-first KYC that verifies identity without holding your customers' PII — reusable credentials, usage-based pricing, no central honeypot.

Book a demo