Annual KYC reviews are a paper-era residue. See what FFIEC, the FCA and the EU AML framework actually require, and the cost of perpetual versus periodic.
Table of contents
- The belief that an annual periodic review equals compliance is a paper-era residue, not a rule. Regulators ask for risk-based, ongoing due diligence, not a fixed calendar.
- Perpetual KYC means continuous monitoring with event-driven re-verification, so a customer whose risk changes is reassessed when it changes, not at the next scheduled review.
- The FFIEC manual, the FCA's systems-and-controls expectations, and the EU AML framework all frame customer due diligence as ongoing, which periodic review only loosely approximates.
- Three trigger classes drive re-verification: internal (transaction patterns), external (sanctions and watchlist updates), and customer life events (address, employment, or beneficial-ownership changes).
- A perpetual KYC stack is built from registry change-data-capture, sanctions-update feeds, and transaction-pattern alerts routed back into the KYC layer, not a once-a-year batch job.
- Over a multi-year horizon, perpetual KYC often costs less than repeated full refreshes, while closing the risk windows that periodic review leaves open.
Perpetual KYC is continuous customer due diligence: instead of refreshing a customer's profile on a fixed calendar, the institution monitors for change and re-verifies when an event warrants it, a sanctions update, a transaction-pattern shift, or a life event. Regulators expect risk-based, ongoing due diligence, which a periodic annual review only loosely approximates.
TL;DR
The idea that an annual review keeps you compliant is one of the most expensive misconceptions in financial crime. No major regulator actually mandates a fixed calendar; they require risk-based, ongoing customer due diligence. Periodic review, refreshing every customer on a one-, two-, or three-year cycle regardless of change, is a workaround from the paper era, and it leaves long windows where a customer who became high-risk is still treated as low-risk.
Perpetual KYC replaces the calendar with continuous monitoring and event-driven re-verification. This guide defines periodic, trigger-based, and perpetual CDD, sets out what the FFIEC, the FCA, and the EU AML framework actually expect, explains why annual review became the default anyway, breaks down the three trigger classes, shows how a perpetual CDD stack is built, and compares the cost of perpetual versus periodic over a multi-year horizon.
10 min read. Last updated 9 September 2026.
What is the difference between periodic, trigger-based, and perpetual CDD?
The three models sit on a spectrum from calendar to continuous. Periodic KYC reviews each customer on a fixed schedule by risk tier, every one, two, or three years, regardless of whether anything changed. Trigger-based KYC reviews a customer when a specific event occurs, rather than on a schedule. Perpetual KYC combines continuous monitoring with those event triggers, so the customer's risk picture updates whenever new information arrives and a review fires automatically when something material changes.
The practical distinction is the gap between reviews. Under periodic review, a customer who turns high-risk the day after their annual check waits up to a year before anyone looks again. Perpetual KYC closes that gap by watching continuously and acting on change. It is the same principle behind perpetual KYC as a moving picture rather than a photograph: the assessment is alive, not a snapshot.
What do FFIEC, the FCA, and the EU AML framework actually require?
Read the rules and the calendar disappears. In the US, the FFIEC BSA/AML Examination Manual frames customer due diligence as ongoing, expecting institutions to monitor relationships and update customer information on a risk basis, not to perform a ritual annual refresh. In the UK, the FCA's systems-and-controls expectations and the Money Laundering Regulations require ongoing monitoring of business relationships, including keeping documents and information up to date. In the EU, the AML framework, now consolidating under the AML Regulation, requires ongoing monitoring of the business relationship and keeping customer due diligence current.
None of these says review every customer every twelve months. They say know your customer continuously and act on a risk basis. That is why an examiner who finds a stale, calendar-driven program with year-long blind spots can fault it even though boxes were ticked on schedule. Perpetual KYC is simply the operating model that actually matches what the regulators wrote, which is the through-line of our AML compliance software guidance.
Why did the annual review become standard if the rules don't require it?
If the regulation asks for ongoing due diligence, why does so much of the industry run annual reviews? Because in the paper era, continuous was impossible. You could not monitor every customer in real time when files were physical and checks were manual, so firms approximated ongoing diligence with the most frequent cadence they could staff, often annual for high-risk and longer for lower-risk tiers. The calendar was a proxy for continuity, and over time the proxy got mistaken for the requirement.
The trouble is the proxy no longer holds up. Data is now continuous, registries publish changes, sanctions lists update constantly, and transactions stream in real time, so the technical excuse for the calendar is gone. An annual review in 2026 is not a best effort at ongoing diligence; it is a deliberate choice to ignore eleven months of change. Regulators increasingly see it that way, which is why periodic-only programs are aging badly in examinations.
What are the three trigger classes for perpetual CDD?
Perpetual KYC works because it reacts to defined triggers, and those fall into three classes. Internal triggers come from the customer's own activity: a change in transaction volume, new counterparties or geographies, or patterns inconsistent with their established profile. External triggers come from the world: a sanctions or watchlist update that newly matches the customer, adverse media, or a regulatory change. Customer-life-event triggers come from changes to the customer's identity or circumstances: a new address, a change of employment, an expired document, or a shift in beneficial ownership for a business.
Designing perpetual KYC means wiring each class into the monitoring layer so the relevant review fires automatically and is evidenced. The transaction monitoring layer feeds the internal triggers, sanctions feeds drive the external ones, and identity and registry data surface the life events. The art is calibrating thresholds so genuine change triggers a review without burying analysts in noise.
How do you build a perpetual CDD stack?
A perpetual KYC stack is an integration problem more than a single product. At the data layer it ingests change: change-data-capture from corporate registries so an ownership shift is detected, a sanctions-update feed so new matches surface immediately, and transaction-pattern alerting from monitoring. At the decision layer it routes those signals back into the KYC profile, recalculating risk and firing a review when a threshold is crossed. At the action layer it re-verifies the customer where needed, ideally without re-collecting everything from scratch.
Reusable identity makes the action layer efficient: when a re-verification is triggered, a customer with a reusable credential can confirm their current status without a full re-onboarding, and the underlying data stays under a customer-held key rather than copied into every system, which is the model behind decentralised KYC. Built this way, perpetual KYC is continuous by design, and the audit trail of what triggered each review assembles itself, which is exactly what neobanks running a single customer base need.
How do the costs of perpetual CDD and periodic refresh compare?
The instinct is that continuous monitoring must cost more than an annual review. Over a multi-year horizon, the opposite is often true, because periodic refresh re-does full reviews on a schedule whether or not anything changed, while continuous monitoring only acts when a trigger fires.
| Dimension | Periodic KYC | Perpetual KYC |
|---|---|---|
| Cadence | Fixed calendar, full re-review | Continuous monitoring, event-driven review |
| Work per cycle | Full refresh of every customer | Targeted re-verification only on triggers |
| Risk window | Up to the full review interval | Closed as soon as change is detected |
| Analyst effort | Bursts of bulk re-review | Steady, focused on real changes |
| Audit posture | Schedule-based, can be stale | Trigger-evidenced, current |
Periodic review spends effort on customers whose risk has not changed and ignores customers whose risk changed mid-cycle, which is the worst of both. Perpetual KYC concentrates effort where change actually happens, so over five years it typically reduces wasted re-reviews while closing the risk windows, a better return on both cost and exposure.
When is periodic review still acceptable?
Perpetual is the right default, but it is not the only acceptable model everywhere, and honesty matters. For genuinely low-risk, low-activity customers, a risk-based periodic review at a sensible interval can be defensible, provided it is justified by a documented risk assessment rather than applied by default. Dormant accounts with no activity may not need continuous monitoring in the same way an active high-risk customer does, though they still need handling when they reactivate.
The mistake is not periodic review itself; it is applying a uniform calendar to everyone and calling it compliance. The defensible posture is risk-based: continuous, trigger-driven monitoring for customers and segments where risk can change quickly, and proportionate periodic checks where it genuinely cannot, with the rationale documented either way. If you want to model the cost and risk trade-off for your book, model your perpetual CDD cost.
The bottom line
The annual review survives because it once had to, not because the rules demand it. The FFIEC, the FCA, and the EU AML framework all ask for ongoing, risk-based customer due diligence, and a calendar-driven refresh with eleven-month blind spots is an increasingly hard thing to defend in an examination. Perpetual KYC is simply the operating model that matches the regulation in an era when data is continuous.
Wire in the three trigger classes, route them back into the KYC profile, re-verify efficiently with reusable identity, and keep proportionate periodic checks only where risk genuinely cannot change quickly. Over a multi-year horizon you spend less on pointless re-reviews and close the windows where risk actually hides.
Model your perpetual CDD cost, or see how it works.
Related resources
- Perpetual KYC: from photograph to video
- AML transaction monitoring in 2026
- AML compliance software in 2026
- KYC for neobanks: perpetual CDD
- Decentralised KYC
- KYC software
- How it works
Cited sources
- FFIEC BSA/AML Examination Manual, ongoing customer due diligence: https://bsaaml.ffiec.gov/manual
- Financial Conduct Authority, financial crime and ongoing monitoring: https://www.fca.org.uk/firms/financial-crime
- EU Anti-Money Laundering Regulation and AMLA: https://www.amla.europa.eu/about-amla_en
- FATF Recommendations: https://www.fatf-gafi.org/en/topics/fatf-recommendations.html
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.