For decades, KYC has run on a calendar. Onboard a client, then schedule the next review — one, three, or five years out depending on risk rating. The assumption behind this model is that a client's risk profile stays broadly stable between reviews and that a scheduled snapshot is enough to keep the file current. In 2026, that assumption no longer holds — and regulators know it.
Client circumstances change continuously: a new beneficial owner, a fresh sanctions designation, an adverse-media hit, an unusual transaction pattern. A periodic model can only detect these changes on the next scheduled date, which may be years away. The result is stale files, growing backlogs, and reviews that too often become a tick-box exercise rather than a genuine reassessment of risk.
This article explains why the periodic model is structurally broken, what perpetual KYC (pKYC) actually is, the triggers that drive it, and how compliance leaders at banks and External Asset Managers (EAM) can migrate from a periodic to a perpetual model — with the numbers to justify the shift.
1. Why the periodic-review model is structurally broken
The periodic review is not a bad idea in principle. The problem is that its logic collapses under real-world conditions.
Backlogs are built into the model
Every client onboarded today generates a future review obligation. As a book of business grows, those obligations accumulate and cluster. A bank or EAM that onboarded heavily three years ago faces a wall of three-year reviews falling due in the same window — regardless of whether the team has the capacity to absorb them. Because periodic reviews compete with onboarding for the same analysts, reviews are the first thing to slip when onboarding volumes spike. Backlogs are not an execution failure; they are a structural feature of scheduling review work by calendar rather than by risk.
Data goes stale between cycles
A review dated today is accurate today. Tomorrow it begins to decay. Ownership changes, directorships shift, a counterparty is added to a sanctions list, negative press appears — none of it is captured until the next scheduled review. For a client on a three-year cycle, the file can be up to 1,095 days out of date before anyone looks at it again. In the intervening period, the institution is, in effect, banking a risk profile it no longer understands.
Reviews become a tick-box exercise
When analysts face a queue of reviews under deadline pressure, and most files show no obvious change, the review degrades into confirmation rather than reassessment. The box is ticked, the date is reset, the file moves on. This is precisely the behaviour regulators are now targeting: the presence of a review process is no longer accepted as evidence that risk is actually being managed.
The economics do not scale
A single periodic review consumes 2 to 4 hours of analyst time when performed manually — pulling current registry data, re-screening, reconciling changes, documenting the decision. Multiply that across a portfolio of thousands of relationships and the review function alone can consume the majority of a compliance team's capacity, leaving little room for the higher-risk cases that genuinely deserve scrutiny.
2. What perpetual KYC actually is
Perpetual KYC (pKYC) replaces the scheduled review with continuous, event-driven due diligence. Instead of asking "when is this file next due?", pKYC asks "has anything changed that requires action?" — and answers it every day, automatically, across the entire portfolio.
The mechanism is straightforward in concept. Each client file is connected to a set of monitored data sources. The system continuously watches those sources for material changes. When a change is detected, it is scored for relevance and risk. Immaterial changes are logged and closed automatically; material changes generate a targeted, evidence-rich task for a human analyst. Nothing is reviewed on a calendar — everything is reviewed the moment it changes.
The shift in operating logic
The distinction matters because it inverts the workload. Under a periodic model, analysts review every file on schedule regardless of whether anything has changed — so most effort is spent confirming non-events. Under pKYC, analysts only ever look at files where something has genuinely happened. The vast majority of the portfolio, which is not changing at any given moment, requires no manual attention at all.
This is why early adopters report removing 70 to 90 percent of manual periodic-review work. The work does not disappear — it is redirected from re-confirming static files to investigating real changes. Perpetual KYC does not lower the standard of due diligence; it raises it, because a risk is acted on when it emerges rather than whenever the calendar next permits.
3. The triggers that drive perpetual KYC
A pKYC programme is only as good as the signals it monitors. Effective triggers fall into five categories.
Registry and corporate-structure changes
Continuous monitoring of commercial and beneficial-ownership registries surfaces changes to directors, shareholders, registered addresses, and legal status. A change in the ownership chart of a corporate client is one of the highest-value triggers, because it can alter who ultimately controls the relationship.
Sanctions and watchlist updates
Sanctions and PEP lists change constantly. Under a periodic model, a client sanctioned the day after their review remains unscreened against that designation for up to the full review cycle. Perpetual re-screening tests the entire portfolio against every list update as it happens, closing that exposure window to hours.
Adverse media
Negative news — investigations, indictments, regulatory actions, reputational events — is a leading indicator of risk that periodic reviews systematically miss between cycles. Continuous adverse-media monitoring, filtered by AI to suppress irrelevant matches, turns this from a point-in-time check into a live signal.
Transaction anomalies
Behaviour is often the first thing to change. A dormant account that suddenly becomes active, transfers inconsistent with a client's stated profile, or exposure to a newly high-risk jurisdiction are all triggers that should prompt a due-diligence refresh — not wait for the next scheduled date.
Ownership and control changes
Beyond registry filings, changes in ultimate beneficial ownership — including through layered or offshore structures — must trigger a re-verification of the UBO. This is directly relevant to the Swiss reforms taking effect in 2026, which require intermediaries to identify the natural person ultimately controlling a legal entity regardless of how many layers sit above them.
