NewsSEALSQ takes a majority stake in Wecan Group — a CHF 5M investment to accelerate our AI Compliance Co-Pilot.
Wecan
Back to blog
Insights11 min read· July 23, 2026

Perpetual KYC (pKYC): The End of Periodic Reviews

The periodic-review model is structurally broken: backlogs pile up, client data goes stale between cycles, and reviews become a tick-box exercise. Perpetual KYC replaces scheduled reviews with continuous, event-driven due diligence — and removes 70 to 90 percent of manual review work.

by Wecan

For decades, KYC has run on a calendar. Onboard a client, then schedule the next review — one, three, or five years out depending on risk rating. The assumption behind this model is that a client's risk profile stays broadly stable between reviews and that a scheduled snapshot is enough to keep the file current. In 2026, that assumption no longer holds — and regulators know it.

Client circumstances change continuously: a new beneficial owner, a fresh sanctions designation, an adverse-media hit, an unusual transaction pattern. A periodic model can only detect these changes on the next scheduled date, which may be years away. The result is stale files, growing backlogs, and reviews that too often become a tick-box exercise rather than a genuine reassessment of risk.

This article explains why the periodic model is structurally broken, what perpetual KYC (pKYC) actually is, the triggers that drive it, and how compliance leaders at banks and External Asset Managers (EAM) can migrate from a periodic to a perpetual model — with the numbers to justify the shift.

1. Why the periodic-review model is structurally broken

The periodic review is not a bad idea in principle. The problem is that its logic collapses under real-world conditions.

Backlogs are built into the model

Every client onboarded today generates a future review obligation. As a book of business grows, those obligations accumulate and cluster. A bank or EAM that onboarded heavily three years ago faces a wall of three-year reviews falling due in the same window — regardless of whether the team has the capacity to absorb them. Because periodic reviews compete with onboarding for the same analysts, reviews are the first thing to slip when onboarding volumes spike. Backlogs are not an execution failure; they are a structural feature of scheduling review work by calendar rather than by risk.

Data goes stale between cycles

A review dated today is accurate today. Tomorrow it begins to decay. Ownership changes, directorships shift, a counterparty is added to a sanctions list, negative press appears — none of it is captured until the next scheduled review. For a client on a three-year cycle, the file can be up to 1,095 days out of date before anyone looks at it again. In the intervening period, the institution is, in effect, banking a risk profile it no longer understands.

Reviews become a tick-box exercise

When analysts face a queue of reviews under deadline pressure, and most files show no obvious change, the review degrades into confirmation rather than reassessment. The box is ticked, the date is reset, the file moves on. This is precisely the behaviour regulators are now targeting: the presence of a review process is no longer accepted as evidence that risk is actually being managed.

The economics do not scale

A single periodic review consumes 2 to 4 hours of analyst time when performed manually — pulling current registry data, re-screening, reconciling changes, documenting the decision. Multiply that across a portfolio of thousands of relationships and the review function alone can consume the majority of a compliance team's capacity, leaving little room for the higher-risk cases that genuinely deserve scrutiny.

2. What perpetual KYC actually is

Perpetual KYC (pKYC) replaces the scheduled review with continuous, event-driven due diligence. Instead of asking "when is this file next due?", pKYC asks "has anything changed that requires action?" — and answers it every day, automatically, across the entire portfolio.

The mechanism is straightforward in concept. Each client file is connected to a set of monitored data sources. The system continuously watches those sources for material changes. When a change is detected, it is scored for relevance and risk. Immaterial changes are logged and closed automatically; material changes generate a targeted, evidence-rich task for a human analyst. Nothing is reviewed on a calendar — everything is reviewed the moment it changes.

The shift in operating logic

The distinction matters because it inverts the workload. Under a periodic model, analysts review every file on schedule regardless of whether anything has changed — so most effort is spent confirming non-events. Under pKYC, analysts only ever look at files where something has genuinely happened. The vast majority of the portfolio, which is not changing at any given moment, requires no manual attention at all.

This is why early adopters report removing 70 to 90 percent of manual periodic-review work. The work does not disappear — it is redirected from re-confirming static files to investigating real changes. Perpetual KYC does not lower the standard of due diligence; it raises it, because a risk is acted on when it emerges rather than whenever the calendar next permits.

3. The triggers that drive perpetual KYC

A pKYC programme is only as good as the signals it monitors. Effective triggers fall into five categories.

Registry and corporate-structure changes

Continuous monitoring of commercial and beneficial-ownership registries surfaces changes to directors, shareholders, registered addresses, and legal status. A change in the ownership chart of a corporate client is one of the highest-value triggers, because it can alter who ultimately controls the relationship.

Sanctions and watchlist updates

Sanctions and PEP lists change constantly. Under a periodic model, a client sanctioned the day after their review remains unscreened against that designation for up to the full review cycle. Perpetual re-screening tests the entire portfolio against every list update as it happens, closing that exposure window to hours.

Adverse media

Negative news — investigations, indictments, regulatory actions, reputational events — is a leading indicator of risk that periodic reviews systematically miss between cycles. Continuous adverse-media monitoring, filtered by AI to suppress irrelevant matches, turns this from a point-in-time check into a live signal.

Transaction anomalies

Behaviour is often the first thing to change. A dormant account that suddenly becomes active, transfers inconsistent with a client's stated profile, or exposure to a newly high-risk jurisdiction are all triggers that should prompt a due-diligence refresh — not wait for the next scheduled date.

Ownership and control changes

Beyond registry filings, changes in ultimate beneficial ownership — including through layered or offshore structures — must trigger a re-verification of the UBO. This is directly relevant to the Swiss reforms taking effect in 2026, which require intermediaries to identify the natural person ultimately controlling a legal entity regardless of how many layers sit above them.

4. From periodic to perpetual: a phased migration path

No institution moves from periodic to perpetual overnight. A staged migration lets a compliance team build confidence, validate triggers, and demonstrate control to auditors at each step.

Phase 1 — Continuous screening overlay

Keep periodic reviews in place, but add continuous sanctions, PEP, and adverse-media screening across the whole portfolio. This delivers the single biggest risk reduction first, without changing the review process itself.

Phase 2 — Event-driven triggers on high-risk clients

Connect registry and transaction-anomaly triggers for the highest-risk segment. High-risk clients move to a fully event-driven model, while lower-risk tiers remain on a periodic schedule as a safety net.

Phase 3 — Portfolio-wide event-driven review

Extend event-driven triggers across all risk tiers. The periodic schedule becomes a long-stop backstop rather than the primary control — a file is reviewed when it changes, and only reviewed on a calendar if, exceptionally, no trigger has fired for a very long time.

Phase 4 — Perpetual by default

Periodic reviews are retired as the primary mechanism. The portfolio is under continuous surveillance; analyst effort is fully redirected to investigating triggered events and genuinely complex cases. The audit trail shifts from "we reviewed on schedule" to "we detected, assessed, and acted on every material change."

5. The numbers: periodic reviews versus perpetual KYC

The operational case is decisive. The table below compares a manual periodic-review model with a perpetual model powered by Wecan Comply, per file and at portfolio level.

Metric Manual periodic reviews Perpetual KYC (Wecan) Improvement
Time per review event 2–4 hours 20–45 min −70%
Data latency (worst case) Up to review cycle (1–3 yrs) Near real-time −99%
Manual review effort (portfolio) Baseline Down 70–90% −70 to −90%
Sanctions re-screening frequency At review only Continuous Continuous
Adverse-media coverage Point-in-time Continuous Continuous
Review backlog risk High Eliminated
False positive rate 90–99% 20–25% −75 pts

The second row is the one regulators care about most: under a periodic model the worst-case data latency equals the full review cycle, whereas under pKYC it collapses to near real-time.

The next table models the analyst-capacity impact for a mid-sized book of 5,000 client relationships, a common EAM or private-bank scale.

Item Manual periodic model Perpetual KYC (Wecan)
Reviews handled per analyst per month 15–25 files 80–120 trigger events
Annual review-hours required (5,000 files) ~15,000 hours ~2,000–4,500 hours
Analyst FTEs to clear the book 8–10 FTE 1.5–3 FTE
Loaded cost of that capacity CHF 700k–1.1m CHF 150k–330k
Portfolio kept continuously current No Yes
Year-1 net ROI of migration ~200–260%

An analyst working manually clears 15 to 25 review files per month; the same analyst working triggered events in Wecan handles 80 to 120 — a 4 to 5 times capacity gain. For a 5,000-relationship book, that is the difference between a review function that needs 8 to 10 FTE and one that needs 1.5 to 3 — while simultaneously keeping every file current instead of once every few years.

6. Regulatory fit in 2026

The regulatory direction of travel in 2026 aligns almost perfectly with perpetual KYC.

From presence-of-controls to demonstrable effectiveness

The defining shift is away from a tick-box standard — "does a review process exist?" — toward demonstrable effectiveness — "can you show that risk was identified and acted on in a timely, evidence-based way?" A periodic review dated eleven months before a client's sanctioning is hard to defend under this standard. A pKYC audit trail showing the designation was detected and actioned within hours is exactly what supervisors now expect.

The Swiss reforms

The revised AMLO-FINMA, out for consultation from 1 October 2026, reinforces the requirement to understand client structure and, through revised rules on payable-through accounts and sub-accounts, expects intermediaries to hold current due-diligence information on end clients — an ongoing obligation, not a point-in-time one, and directly relevant to EAMs. In parallel, the Legal Entities Transparency Act (LETA) and the revised AMLA introduce a federal beneficial-ownership register and require intermediaries to identify the natural person ultimately in control regardless of layered offshore structures. Keeping UBO information current is far more achievable under continuous monitoring than under a multi-year review cycle.

The EU dimension

The EU AML package, with the new Anti-Money Laundering Authority (AMLA) and its direct supervisory powers, emphasises ongoing monitoring of the business relationship and documented, risk-based due diligence. Continuous, event-driven due diligence is the most direct way to evidence that ongoing obligation.

Traceable, evidence-based decisions

Across all of these frameworks, the common thread is auditability: every decision must be traceable to the evidence and the moment it was made. A pKYC platform records each trigger, the data behind it, the assessment, and the action taken — producing exactly the evidence-based, time-stamped decision trail that demonstrable effectiveness requires.

7. How Wecan enables perpetual KYC

Wecan Comply is built for continuous due diligence rather than calendar-driven reviews. Every client file is connected to live registry, sanctions, PEP, adverse-media, and transaction-monitoring feeds. Changes are detected as they happen, scored for materiality by AI contextual analysis, and either closed automatically or escalated to an analyst as a pre-populated, evidence-rich task — with the change since the last known state clearly flagged.

Because AI contextual scoring reduces the false-positive rate from an industry-standard 90–99 percent to 20–25 percent, analysts spend their time on genuine changes rather than noise. Every detection, assessment, and decision is time-stamped and logged, producing the traceable, evidence-based audit trail that 2026 supervision demands.

The migration is designed to be phased, not disruptive: institutions can begin with a continuous screening overlay on top of their existing reviews and move toward a perpetual-by-default model at their own pace, demonstrating control to auditors at every step. The outcome is a compliance function that is both more effective and materially less expensive — one that acts on risk the moment it emerges, keeps every file current, and finally retires the backlog for good.

See Wecan in action. In 30 minutes.

A live walkthrough on real KYC scenarios — no slides, no commitment. Just see if it fits your context.