A periodic review is a scheduled refresh of a customer's due diligence, timed by risk tier, to keep records and risk ratings current. It works as a safety net rather than the primary defense, catching what nothing else did between reviews.
What is a periodic review, in plain English?
A periodic review is a scheduled recheck of a customer's due diligence. On a set cadence, tied to how risky the customer is, the firm refreshes the information on file, re-runs screening, and confirms or updates the risk rating. High-risk customers are reviewed more often, such as yearly; lower-risk customers less often, such as every few years. The goal is to make sure records and ratings do not quietly go stale.
It is a calendar-based control. The trigger is the date, not an event. That makes it predictable and easy to plan around, and it guarantees that every customer gets looked at eventually, which matters for customers who generate little activity and would otherwise never resurface for a fresh look.
But because it fires on a schedule rather than on change, periodic review is a safety net, not the front line. Risk can shift long before the next scheduled date. The right design pairs periodic reviews with event-driven triggers, so the calendar catches the slow, quiet cases while triggers catch the ones that actually change.
How review cycles work by risk tier
Review frequency is driven by the customer's risk rating:
- High risk — Reviewed most often. Typically yearly, with the deepest refresh of information, screening, and source-of-funds or wealth checks.
- Medium risk — Reviewed on a middle cadence. A less frequent refresh that confirms the profile still holds and updates anything that changed.
- Low risk — Reviewed least often. A lighter, less frequent check, on the assumption that low-risk status is still evidenced.
- Any tier — Event triggers override the clock. A material change should pull the review forward rather than waiting for the scheduled date.
What it looks like in practice
In practice
A customer rated medium risk is due for a scheduled review in eighteen months. Four months after their last review, their transaction pattern shifts sharply toward high-value cross-border transfers, but because the firm relies only on the calendar, nobody re-examines the file until the scheduled date arrives.
By the time the periodic review runs, the risky activity has been going on for over a year. The review does eventually catch it and re-rates the customer, but the delay is the problem: waiting for the anniversary to notice something that started months earlier is too slow. The fix is an event-driven trigger that would have pulled the review forward when the behavior changed.
Why periodic review matters to operators
Periodic review guarantees nobody is forgotten. Some customers barely transact and never trip a monitoring alert, so without a scheduled recheck their files would age indefinitely. The calendar is what forces a fresh look at those quiet accounts and keeps records from drifting years out of date.
Its weakness is the same as its strength: it is tied to the clock. Calendar cycles alone leave stale, high-risk profiles unreviewed between dates and tend to build backlogs when volumes grow. The lesson operators take is that periodic review should be one layer, not the only one. Combine it with event-driven triggers and ongoing due diligence, and the schedule becomes a backstop rather than the sole thing looking.
What to watch for
- Stale high-risk files. A high-risk customer whose profile has not been refreshed since the last scheduled date, despite changing activity.
- Review backlogs. When due reviews pile up faster than the team can clear them, the control silently stops working.
- Calendar-only reliance. No event-driven triggers means risk that shifts between dates goes unnoticed until the next cycle.
- Rubber-stamp reviews. Reviews closed quickly without real re-assessment defeat the purpose and create an examination gap.
- Mismatched cadence. A review frequency that does not match the customer's true risk tier, either too rare or wastefully frequent.
Quick questions
How often should a periodic review happen?
It depends on risk tier. High-risk customers are typically reviewed yearly, with lower-risk customers reviewed less often. The cadence should be set by a risk-based approach rather than a single blanket interval.
How is periodic review different from ongoing due diligence?
Periodic review is calendar-based and point-in-time. Ongoing due diligence is continuous and event-driven, catching change as it happens. The two are complementary, with the review acting as a scheduled backstop.
Why is calendar-only review risky?
Because risk can shift long before the next scheduled date, leaving stale, high-risk profiles unreviewed in between and creating backlogs. Relying on the clock alone means problems that start mid-cycle go unnoticed for months.
What are event-driven triggers?
They are conditions that pull a review forward when something material changes, such as new adverse media, an ownership change, or a shift in behavior. They fill the gaps that a fixed calendar leaves open.
How does perpetual KYC change periodic review?
Perpetual KYC shifts the emphasis from fixed cycles to continuous, event-driven refresh. It aims to reduce reliance on the calendar and cut the backlogs that periodic-only models tend to accumulate.
Does a periodic review always change the risk rating?
No. Often it confirms the existing rating still holds. Its value is in verifying the profile is current, whether that means updating the rating or documenting that nothing material has changed.
Go deeper
- FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
- FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

