To choose periodic review and ongoing monitoring software in 2026, evaluate it against seven criteria — event-driven triggers, live data and registry refresh, risk-based cadence, continuous sanctions and adverse-media re-screening, pre-population and automation, auditability, and integration — and treat perpetual KYC (pKYC) as the target operating model rather than faster calendar-driven reviews. The best tools do not just help you complete periodic reviews on time; they progressively remove the need for scheduled reviews altogether by reviewing each file the moment it changes.
This is a vendor-neutral buyer's guide for Chief Compliance Officers and Heads of KYC. It explains why periodic reviews have become a growing operational burden, the difference between periodic and perpetual KYC, the selection criteria that separate a genuine ongoing-monitoring platform from a workflow tool with a calendar, and how to measure whether a purchase actually pays back.
1. Why periodic reviews are a growing burden
The periodic review — re-verifying a client file on a one, three, or five-year cycle set by risk rating — was designed for a world where client data changed slowly and books of business were small. Neither assumption holds in 2026, and the model has become one of the largest, least scalable line items in a compliance budget.
Backlogs are structural, not accidental
Every client onboarded today creates a future review obligation. As a book grows, those obligations cluster: an institution that onboarded heavily three years ago faces a wall of three-year reviews falling due in the same window, regardless of team capacity. Because reviews compete with onboarding for the same analysts, they slip first when onboarding volumes spike. A backlog is therefore not an execution failure — it is a built-in property of scheduling review work by calendar rather than by risk.
Data goes stale between cycles
A review is accurate on the day it is signed and begins decaying immediately. A new beneficial owner, a fresh sanctions designation, an adverse-media hit, or a change of director may not be captured for months or years. For a client on a three-year cycle, the file can be up to 1,095 days out of date before anyone looks at it again — and in that window the institution is, in effect, banking a risk profile it no longer understands.
The economics do not scale
Performed manually, a single periodic review consumes 2 to 4 hours of analyst time: pulling current registry data, re-screening against sanctions and PEP lists, reconciling changes, and documenting the decision. Across a portfolio of thousands of relationships, the review function alone can absorb the majority of a team's capacity — while a loaded Swiss KYC analyst costs CHF 80,000 to 110,000 per year. Software is the only realistic way to break the linear link between book growth and headcount.
Regulators no longer accept a tick-box review
Supervisors have shifted from asking "does a review process exist?" to "can you demonstrate that risk was identified and acted on in a timely, evidence-based way?" A review dated eleven months before a client was sanctioned is hard to defend under that standard. The purchasing question has therefore changed: you are no longer buying a tool to complete reviews faster, but a control that can evidence ongoing monitoring of the business relationship.
2. Periodic vs perpetual KYC: what you are actually buying
Before comparing vendors, decide which operating model you are buying into. This is the single most important decision in the process, because it determines whether the software caps your future workload or merely reschedules it.
Periodic KYC reviews every file on a fixed calendar, whether or not anything has changed. Perpetual KYC (pKYC) replaces the calendar with continuous, event-driven due diligence: each file is connected to monitored data sources, changes are detected and scored for materiality as they happen, immaterial changes are closed automatically, and only material changes generate a task for an analyst. Nothing is reviewed on a date — everything is reviewed the moment it changes.
| Dimension | Periodic KYC | Perpetual KYC (pKYC) |
|---|---|---|
| Trigger for review | Calendar date | Material change (event) |
| Data currency | Stale between cycles | Near real-time |
| Analyst effort | Every file, every cycle | Only files that changed |
| Backlog risk | High and structural | Eliminated |
| Regulatory posture | Presence of a process | Demonstrable effectiveness |
The practical takeaway for a buyer: do not select a tool solely on how efficiently it clears a review queue. Select on whether it can shrink the queue itself. A deeper treatment of this shift is in our companion article on perpetual KYC and the end of periodic reviews. Even institutions that are not ready to abandon scheduled reviews should buy software capable of pKYC, so the migration is a configuration change rather than a re-procurement.
3. The selection criteria: a 2026 evaluation framework
Use the seven criteria below as an evaluation scorecard. Score each vendor on each row, and weight the rows that matter most to your risk profile. The framework is deliberately vendor-neutral; several platforms can satisfy it, and the point is to compare like with like rather than to react to demos.
| Criterion | What to look for | Why it matters |
|---|---|---|
| Event-driven triggers | Configurable triggers on ownership, directorship, jurisdiction, and transaction anomalies — not just a review calendar | Turns "review on date" into "review on change"; the foundation of pKYC |
| Data refresh & registries | Live connections to commercial and beneficial-ownership registries, auto-refresh of client attributes | Removes manual data-pulling; keeps files current between reviews |
| Risk-based cadence | Configurable review frequency by risk tier, with automatic re-tiering when scores change | Aligns effort with risk; supports a defensible risk-based approach |
| Sanctions & adverse-media re-screening | Continuous, portfolio-wide re-screening against every list update, with AI relevance filtering | Closes the exposure window from years to hours; controls false positives |
| Pre-population & automation | Auto-assembled review packs, change-since-last-state flagging, straight-through closure of immaterial events | Cuts the per-review time from hours to minutes |
| Auditability & effectiveness | Time-stamped record of every trigger, the underlying data, the assessment, and the action | Evidences demonstrable effectiveness for supervisors |
| Integration | APIs and connectors to core banking, CRM, onboarding, and case-management systems | Avoids a data silo; makes monitoring part of the lifecycle, not a bolt-on |
Reading the scorecard
Three rows are non-negotiable in 2026. Event-driven triggers are what separate a monitoring platform from a workflow tool with a calendar; without them, you are buying a faster way to do the same stale-data reviews. Continuous sanctions and adverse-media re-screening is the single biggest risk reducer, and its value depends heavily on AI relevance filtering — raw screening that returns 90 to 99 percent false positives simply moves the burden rather than removing it, so ask each vendor for their post-filtering false-positive rate. Read our primer on adverse-media screening before you sit through demos. Auditability is what turns the whole system into a regulatory asset rather than an operational convenience.
Questions to put to every vendor
- Can a review be triggered by a registry or ownership change with no calendar date involved?
- What is your false-positive rate after AI filtering, and how is relevance scored?
- How much of a review pack is pre-populated automatically versus assembled by the analyst?
- Can immaterial changes be closed straight-through, and is that closure logged and auditable?
- Does the audit trail capture the data behind each decision and the moment it was made?
- Which registries and internal systems do you connect to out of the box, and via what APIs?
4. How to move from periodic to perpetual
The right software lets you migrate in stages rather than in a single disruptive switch. A phased path builds confidence, validates triggers, and demonstrates control to auditors at each step — and it should be possible within a single platform, without re-buying.
Phase 1 — Continuous screening overlay
Keep periodic reviews in place, but add continuous sanctions, PEP, and adverse-media screening across the whole portfolio. This delivers the biggest single risk reduction first, without changing the review process itself.
Phase 2 — Event-driven triggers on high-risk clients
Connect registry and transaction-anomaly triggers for the highest-risk segment. High-risk clients move to a fully event-driven model, while lower-risk tiers stay on a periodic schedule as a safety net.
Phase 3 — Portfolio-wide event-driven review
Extend triggers across all risk tiers. The periodic schedule becomes a long-stop backstop rather than the primary control: a file is reviewed when it changes, and only reviewed on a calendar if, exceptionally, no trigger has fired for a very long time.
Phase 4 — Perpetual by default
Retire periodic reviews as the primary mechanism. The portfolio is under continuous surveillance and analyst effort is fully redirected to triggered events and genuinely complex cases. The audit narrative shifts from "we reviewed on schedule" to "we detected, assessed, and acted on every material change."
A key buying signal: the vendor should be able to show you each of these phases as a configuration state, not as a separate product or a future roadmap item.
5. Measuring the impact
Build the business case on a small number of hard metrics, and require the vendor to commit to them during a proof of value. The ranges below are what mature ongoing-monitoring deployments deliver, and they are consistent with the figures we use across our ROI analysis.
| Metric | Manual periodic reviews | With ongoing-monitoring software | Improvement |
|---|---|---|---|
| Time per review event | 2–4 hours | 20–45 min | −70% |
| Manual review effort (portfolio) | Baseline | Down 70–90% | −70 to −90% |
| Reviews / trigger events per analyst / month | 15–25 files | 80–120 events | ~4–5× |
| Data latency (worst case) | Up to review cycle (1–3 yrs) | Near real-time | −99% |
| Sanctions & adverse-media re-screening | At review only | Continuous | Continuous |
| Post-filter false-positive rate | 90–99% | 20–25% | −75 pts |
The headline numbers to hold a vendor to are the first three rows. Per-review time should fall from 2 to 4 hours to 20 to 45 minutes, manual review effort across the portfolio should drop by 70 to 90 percent, and a single analyst's throughput should rise from 15 to 25 files a month to 80 to 120 trigger events — a four to five-fold capacity gain. Against a loaded analyst cost of CHF 80,000 to 110,000, that capacity shift is what produces a typical year-one net ROI of 200 to 260 percent with payback in three to four months. If a vendor cannot model these outcomes for your book during evaluation, treat that as a red flag.
6. Frequently asked questions
What is a periodic KYC review?
A periodic KYC review is a scheduled re-verification of an existing client's due-diligence file — confirming identity, beneficial ownership, source of wealth, risk rating, and screening status — carried out at a fixed interval determined by the client's risk classification rather than by any specific event.
How often are periodic reviews required?
Frequency is risk-based, not fixed by a single rule. Typical practice is annually for high-risk clients, every two to three years for medium-risk, and every four to five years for low-risk, with the exact cadence set by the institution's risk-based approach and supervisory expectations. The direction of travel in 2026 is away from fixed intervals and toward event-driven review.
What is the difference between periodic and perpetual KYC?
Periodic KYC reviews every file on a calendar regardless of whether anything changed; perpetual KYC (pKYC) reviews a file the moment a material change is detected and closes immaterial changes automatically. Periodic KYC produces stale data and structural backlogs; perpetual KYC keeps every file near real-time current and removes 70 to 90 percent of manual review work.
Can periodic reviews be automated?
Yes. Automation covers data refresh from registries, continuous sanctions and adverse-media re-screening, pre-population of review packs, straight-through closure of immaterial changes, and automatic re-tiering when risk scores change. Human analysts remain in the loop for material changes and complex judgment, but the routine confirmation of unchanged files is largely eliminated.
What triggers an event-driven review?
Common triggers include a change of beneficial owner or director, a new sanctions or PEP designation, an adverse-media hit, a change of registered address or legal status, exposure to a newly high-risk jurisdiction, and transaction anomalies such as a dormant account becoming active or transfers inconsistent with the client's stated profile.
Is ongoing monitoring a regulatory requirement?
Ongoing monitoring of the business relationship is a core expectation under Swiss AMLA (LBA / GwG / LRD) and the revised OBA-FINMA / GwV-FINMA, and under the EU AML package with the new Anti-Money Laundering Authority. Regulators increasingly expect demonstrable, evidence-based effectiveness rather than the mere presence of a review process — which is precisely what continuous, event-driven monitoring provides.
7. How Wecan fits
Measured against the seven criteria above, Wecan Comply is built for continuous due diligence rather than calendar-driven reviews — but the framework matters more than any single vendor, and it should be applied evenly to every option on your shortlist. Where Wecan is designed to score well is on the three non-negotiable rows: configurable event-driven triggers connected to live registry, sanctions, PEP, adverse-media, and transaction-monitoring feeds; AI contextual scoring that cuts the false-positive rate from an industry-standard 90 to 99 percent to 20 to 25 percent; and a time-stamped, evidence-rich audit trail that records every trigger, the underlying data, the assessment, and the action taken.
Just as importantly, the four migration phases are configuration states within one platform: an institution can start with a continuous screening overlay on top of its existing periodic reviews and move toward perpetual-by-default at its own pace, treating each step as evidence of control for auditors. Whichever vendor you choose, the goal is the same — a monitoring function that acts on risk the moment it emerges, keeps every file current, and finally retires the backlog for good.
