To choose periodic review and ongoing monitoring software in 2026, evaluate it against seven criteria — event-driven triggers, live data and registry refresh, risk-based cadence, continuous sanctions and adverse-media re-screening, pre-population and automation, auditability, and integration — and treat perpetual KYC (pKYC) as the target operating model rather than faster calendar-driven reviews. The best tools do not just help you complete periodic reviews on time; they progressively remove the need for scheduled reviews altogether by reviewing each file the moment it changes.
This is a vendor-neutral buyer's guide for Chief Compliance Officers and Heads of KYC. It explains why periodic reviews have become a growing operational burden, the difference between periodic and perpetual KYC, the selection criteria that separate a genuine ongoing-monitoring platform from a workflow tool with a calendar, and how to measure whether a purchase actually pays back.
1. Why periodic reviews are a growing burden
The periodic review — re-verifying a client file on a one, three, or five-year cycle set by risk rating — was designed for a world where client data changed slowly and books of business were small. Neither assumption holds in 2026, and the model has become one of the largest, least scalable line items in a compliance budget.
Backlogs are structural, not accidental
Every client onboarded today creates a future review obligation. As a book grows, those obligations cluster: an institution that onboarded heavily three years ago faces a wall of three-year reviews falling due in the same window, regardless of team capacity. Because reviews compete with onboarding for the same analysts, they slip first when onboarding volumes spike. A backlog is therefore not an execution failure — it is a built-in property of scheduling review work by calendar rather than by risk.
Data goes stale between cycles
A review is accurate on the day it is signed and begins decaying immediately. A new beneficial owner, a fresh sanctions designation, an adverse-media hit, or a change of director may not be captured for months or years. For a client on a three-year cycle, the file can be up to 1,095 days out of date before anyone looks at it again — and in that window the institution is, in effect, banking a risk profile it no longer understands.
The economics do not scale
Performed manually, a single periodic review consumes 2 to 4 hours of analyst time: pulling current registry data, re-screening against sanctions and PEP lists, reconciling changes, and documenting the decision. Across a portfolio of thousands of relationships, the review function alone can absorb the majority of a team's capacity — while a loaded Swiss KYC analyst costs CHF 80,000 to 110,000 per year. Software is the only realistic way to break the linear link between book growth and headcount.
Regulators no longer accept a tick-box review
Supervisors have shifted from asking "does a review process exist?" to "can you demonstrate that risk was identified and acted on in a timely, evidence-based way?" A review dated eleven months before a client was sanctioned is hard to defend under that standard. The purchasing question has therefore changed: you are no longer buying a tool to complete reviews faster, but a control that can evidence ongoing monitoring of the business relationship.
2. Periodic vs perpetual KYC: what you are actually buying
Before comparing vendors, decide which operating model you are buying into. This is the single most important decision in the process, because it determines whether the software caps your future workload or merely reschedules it.
Periodic KYC reviews every file on a fixed calendar, whether or not anything has changed. Perpetual KYC (pKYC) replaces the calendar with continuous, event-driven due diligence: each file is connected to monitored data sources, changes are detected and scored for materiality as they happen, immaterial changes are closed automatically, and only material changes generate a task for an analyst. Nothing is reviewed on a date — everything is reviewed the moment it changes.
| Dimension | Periodic KYC | Perpetual KYC (pKYC) |
|---|---|---|
| Trigger for review | Calendar date | Material change (event) |
| Data currency | Stale between cycles | Near real-time |
| Analyst effort | Every file, every cycle | Only files that changed |
| Backlog risk | High and structural | Eliminated |
| Regulatory posture | Presence of a process | Demonstrable effectiveness |
The practical takeaway for a buyer: do not select a tool solely on how efficiently it clears a review queue. Select on whether it can shrink the queue itself. A deeper treatment of this shift is in our companion article on perpetual KYC and the end of periodic reviews. Even institutions that are not ready to abandon scheduled reviews should buy software capable of pKYC, so the migration is a configuration change rather than a re-procurement.
3. The selection criteria: a 2026 evaluation framework
Use the seven criteria below as an evaluation scorecard. Score each vendor on each row, and weight the rows that matter most to your risk profile. The framework is deliberately vendor-neutral; several platforms can satisfy it, and the point is to compare like with like rather than to react to demos.
| Criterion | What to look for | Why it matters |
|---|---|---|
| Event-driven triggers | Configurable triggers on ownership, directorship, jurisdiction, and transaction anomalies — not just a review calendar | Turns "review on date" into "review on change"; the foundation of pKYC |
| Data refresh & registries | Live connections to commercial and beneficial-ownership registries, auto-refresh of client attributes | Removes manual data-pulling; keeps files current between reviews |
| Risk-based cadence | Configurable review frequency by risk tier, with automatic re-tiering when scores change | Aligns effort with risk; supports a defensible risk-based approach |
| Sanctions & adverse-media re-screening | Continuous, portfolio-wide re-screening against every list update, with AI relevance filtering | Closes the exposure window from years to hours; controls false positives |
| Pre-population & automation | Auto-assembled review packs, change-since-last-state flagging, straight-through closure of immaterial events | Cuts the per-review time from hours to minutes |
| Auditability & effectiveness | Time-stamped record of every trigger, the underlying data, the assessment, and the action | Evidences demonstrable effectiveness for supervisors |
| Integration | APIs and connectors to core banking, CRM, onboarding, and case-management systems | Avoids a data silo; makes monitoring part of the lifecycle, not a bolt-on |
Reading the scorecard
Three rows are non-negotiable in 2026. Event-driven triggers are what separate a monitoring platform from a workflow tool with a calendar; without them, you are buying a faster way to do the same stale-data reviews. Continuous sanctions and adverse-media re-screening is the single biggest risk reducer, and its value depends heavily on AI relevance filtering — raw screening that returns 90 to 99 percent false positives simply moves the burden rather than removing it, so ask each vendor for their post-filtering false-positive rate. Read our primer on adverse-media screening before you sit through demos. Auditability is what turns the whole system into a regulatory asset rather than an operational convenience.
Questions to put to every vendor
- Can a review be triggered by a registry or ownership change with no calendar date involved?
- What is your false-positive rate after AI filtering, and how is relevance scored?
- How much of a review pack is pre-populated automatically versus assembled by the analyst?
- Can immaterial changes be closed straight-through, and is that closure logged and auditable?
- Does the audit trail capture the data behind each decision and the moment it was made?
- Which registries and internal systems do you connect to out of the box, and via what APIs?
