Perpetual KYC, or pKYC, is a model of customer due diligence that replaces the fixed periodic review with continuous, event-driven monitoring. Instead of re-verifying a customer every one, three or five years, the compliance system refreshes that customer’s risk profile the moment the underlying data changes.
In October 2024, TD Bank agreed to pay US$3.088 billion to US authorities and became the first bank ever to plead guilty to conspiracy to commit money laundering, according to the ABA Banking Journal.
The finding behind it wasn’t exotic. TD’s transaction-monitoring programme had stayed “effectively static” from 2014 to 2022, and roughly 92% of its transaction volume, about $18.3 trillion, went unmonitored, as NPR reported. It checked its customers at onboarding and, for years, never really checked again.
That’s the gap perpetual KYC is built to close. Rather than review a customer on a fixed schedule, it monitors continuously.
What is perpetual KYC (pKYC)?
Perpetual KYC is an approach to customer due diligence in which a customer’s KYC record is kept current continuously, driven by changes in real-world data rather than by a scheduled refresh date. When a trigger fires, an ownership change, an adverse media hit, a new sanctions match, the customer’s risk score updates and, where needed, a review begins.
The perpetual KYC meaning matters because it describes a change of operating model, not a product you switch on. The obligation it serves, ongoing monitoring, is decades old. What’s new is doing it continuously and at scale, which mass manual reviews can’t.
Perpetual KYC vs periodic KYC: what actually changes?
Periodic KYC refreshes a customer file on a fixed cycle set by risk band: often annually for high-risk customers, every three years for medium, every five for low. Between those dates, the file can drift out of date while the customer’s behaviour moves on.
Perpetual KYC inverts the logic. The review isn’t scheduled, it’s provoked.
| Dimension | Periodic KYC | Perpetual KYC |
|---|---|---|
| Trigger for review | A calendar date | A change in the customer’s data |
| Data freshness | Accurate as at the last review | Continuously updated |
| Effort profile | Large batch reviews, mostly on unchanged files | Targeted reviews, only where something changed |
| Blind spot | The months between reviews | Narrowed to detection and response time |
| Typical enabler | Case-management workflow | KYC automation, data feeds, screening |
The real gain in perpetual KYC vs periodic KYC is that analyst effort follows risk. Most periodic reviews just confirm nothing has changed, which is expensive and teaches the team nothing. pKYC spends that time only where the data has actually moved.
How does perpetual KYC work? What triggers a review?
Perpetual KYC monitoring works by wiring a customer’s record to a set of external and internal data sources, then defining the events that count as material. When one of those events appears, the system re-scores the customer and routes the case. The vendor explainers from firms such as Moody’s and Fenergo tend to stop at “event-driven”, without saying which events.
The table below sets out the common triggers, the data source that surfaces each one, and the action it should prompt.
| Trigger event | Data source | Risk signal | Action |
|---|---|---|---|
| Beneficial owner changes | Corporate registries, filings | Control moves to a higher-risk party | Re-run CDD on the new owner |
| Adverse media appears | Media and screening feeds | Customer linked to financial crime | Escalate to analyst review |
| New sanctions or PEP match | Sanctions and PEP lists | Customer or connected party newly listed | Freeze, enhanced due diligence, consider a SAR |
| Address or jurisdiction shifts | KYC data, transactions | Move into a higher-risk country | Re-score risk, refresh enhanced due diligence |
| Transaction pattern breaks profile | Transaction monitoring | Activity inconsistent with expected behaviour | Investigate, file a SAR if warranted |
| Corporate filing or licence changes | Registries, regulators | Business activity no longer matches the file | Reassess the purpose of the relationship |
| Identity document expires | Internal KYC records | Verification lapses | Request refreshed documents |
What does a perpetual KYC system need?
Perpetual KYC due diligence at this speed isn’t a manual job, which is why the market for perpetual KYC software has grown around it. Six pieces do the work behind it.
| Component | What it does | Why it matters |
|---|---|---|
| Single customer view (entity resolution) | Resolves scattered records into one accurate picture of the customer and its beneficial owners | Get this wrong and everything downstream fires on noise |
| Live data feeds | Streams registries, sanctions and PEP lists, adverse media and transaction data in continuously | Replaces the once-a-year snapshot with a current one |
| Continuous screening | Runs sanctions, PEP and adverse-media checks against those feeds in real time | Catches a new listing the day it appears, not at the next review |
| Transaction monitoring | Watches behaviour against the customer’s expected profile | Turns a pattern break into a trigger |
| Risk-scoring layer | Decides which changes are material enough to act on | Where the programme is won or lost |
| Case management + straight-through processing | Clears low-risk changes automatically and routes only genuine ones to an analyst, with an audit trail | Keeps analysts on real cases, not noise |
Providers including Quantexa, ComplyAdvantage, NICE Actimize, Moody’s and Fenergo compete on how well these pieces connect, and the industry body ACAMS has published its own best-practice route. KYC automation makes the monitoring possible, but the components are only as good as the customer data feeding them.
What do regulators actually require?
No major regulator mandates “perpetual” KYC by name. What they require is ongoing, risk-based monitoring and customer data that stays current, and perpetual KYC is just the operating model firms are adopting to meet that as data volumes climb.
The core obligation is consistent from one jurisdiction to the next.
| Jurisdiction | Instrument | What it requires on ongoing monitoring |
|---|---|---|
| Global standard | FATF Recommendation 10 | Conduct ongoing due diligence and scrutinise transactions throughout the relationship; keep CDD data current; calibrate frequency to risk |
| United Kingdom | MLR 2017, reg 28(11) and the FCA | Monitor on a risk-sensitive basis, keep CDD information up to date, and apply enhanced ongoing monitoring where risk is higher |
| European Union | AMLR, Reg (EU) 2024/1624, Art 26 | Monitor business relationships continuously under a single, directly applicable rulebook, supervised by AMLA in Frankfurt from 1 July 2025 |
| United Arab Emirates | Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 (which replaced Decree-Law 20/2018 and Cabinet Decision 10/2019) | All customers subject to ongoing monitoring throughout the relationship, enhanced for high risk, with reduced frequency permitted for low risk |
For firms operating across the UAE and the wider Gulf, the direction is clear. The Central Bank of the UAE, the DFSA in the DIFC and the FSRA in ADGM all run on the same risk-based logic, and UAE supervisors have made ongoing monitoring a live examination priority rather than a box on an onboarding form. A firm licensed in Dubai and passporting behaviour from a group system built for a single market is exactly the mismatch examiners look for.
The EU raises the bar again. Because the AMLR applies directly in all 27 member states, a bank can no longer arbitrage the softest national transposition, and AMLA’s forthcoming guidelines on ongoing monitoring will set expectations on review frequency and escalation triggers centrally.
What are the benefits, and the costs?
The benefits of perpetual KYC are real and easy to state. The risk picture stays current, so a customer who turns risky is caught in days rather than years. Analyst effort concentrates where data has changed instead of being spent re-reviewing dormant files.
The mass annual refresh is the single largest drain on a KYC team, and the numbers show why. In 2023 the average corporate KYC review cost $2,598 and took 95 days, according to a Fenergo survey of more than 1,100 banking executives. Run that across a whole book on a fixed cycle, most of it on customers whose risk hasn’t moved, and the bill is enormous. Perpetual KYC spends it only where the data actually changed.
The costs are just as real, and vendor material tends to skip them.
The first is alert fatigue. Wire a record to more data feeds and it will generate more alerts, most of them false positives. A pKYC programme that floods analysts with noise is worse than a periodic one, because the signal drowns. Tuning the risk model to fire only on material change is the hard part, and it’s ongoing work, not a setup task.
The second is data privacy. Continuous monitoring pulls continuously on personal data, which runs into the data-minimisation principle in the UK and EU GDPR regimes. Firms have to justify what they collect and how long they keep it, and “we monitor everything, always” isn’t a defensible answer to a regulator on either side.
The third is data quality. Perpetual KYC inherits the state of a firm’s customer records, and a live feed built on stale or fragmented data just surfaces bad information faster.
How do you roll out perpetual KYC?
For an MLRO, most of the difficulty in perpetual KYC is in the rollout rather than the purchase. The programmes that work tend to move through four stages instead of flipping a switch.
First, fix the foundations. Perpetual KYC inherits the state of a firm’s customer records, so the single customer view and the data feeding it come before any monitoring. A live feed built on poor data just makes the problem worse.
Second, start narrow. Pick the highest-risk segment, define a small set of genuinely material triggers, and prove the model catches real change without burying the team.
Third, tune for false positives. This is the alert-fatigue problem, and it’s ongoing work, not a one-off setup. Thresholds need calibrating so the system fires on a material change rather than every routine update.
Fourth, govern it. Document the rules, put model oversight in place, and get senior sign-off, because the risk-based approach the regulators expect has to be evidenced. Only then does the programme widen to the rest of the book.
The common mistake is the reverse: switching on every feed for every customer on day one, then drowning in false positives. Done well, perpetual KYC keeps a file current without that noise, but only when the risk logic behind it is doing real work.
FAQs
What is perpetual KYC?
Perpetual KYC, or pKYC, is a customer due diligence model that keeps a customer’s KYC record current continuously, updating the risk profile when real-world data changes rather than on a fixed review cycle.
What is the difference between perpetual KYC and periodic KYC?
Periodic KYC reviews a customer on a scheduled cycle set by risk band. Perpetual KYC reviews the customer when a trigger fires, such as an ownership change or a sanctions match, so the file stays current between what would have been review dates.
Does perpetual KYC replace periodic reviews entirely?
In practice it reduces them rather than abolishing them. Most firms still run a backstop review for the highest-risk customers, with event-driven monitoring doing the continuous work in between.
Is perpetual KYC a regulatory requirement?
No regulator mandates “perpetual” KYC by name. The FATF, the UK, the EU and the UAE all require ongoing, risk-based monitoring and up-to-date customer data, and perpetual KYC is the operating model firms use to meet that obligation at scale.
What is perpetual KYC software?
It’s the stack that automates continuous monitoring: data feeds, sanctions, PEP and adverse-media screening, transaction monitoring, and a scoring layer that decides which changes warrant a review. The tooling enables pKYC, but the risk model determines whether it works.
Next read
For how continuous monitoring connects to the wider compliance stack, see the Compliance hub.