SardineCon SF/2026

Learn More

What is Perpetual KYC (pKYC)?

SUBSCRIBE

Perpetual KYC is an event-driven model that continuously refreshes customer due diligence as the underlying data changes, instead of on fixed periodic cycles. It aims to keep risk ratings current in near real time and cut the review backlogs that calendar-based models pile up.

What is pKYC, in plain English?

Perpetual KYC refreshes a customer's due diligence whenever their data actually changes, rather than on a fixed clock. Instead of waiting for a scheduled review date, the model listens for events: new adverse media, a change in beneficial ownership, a shift in transaction behavior, an address update. When one fires, it triggers a targeted re-assessment of that customer, keeping the risk rating current in near real time.

The design replaces the calendar with triggers. Traditional periodic review looks at every customer on a cycle, whether or not anything changed, which wastes effort on stable customers and can be too slow for volatile ones. pKYC flips that: it reviews the customers who changed, when they changed, and leaves the unchanged ones alone until they do.

Its promise is fewer stale profiles and smaller review backlogs. But the whole model depends on the quality of the data feeding it and the tuning of the triggers. Get those right and it focuses analyst effort exactly where risk moved; get them wrong and it simply generates a different kind of busywork.

Periodic KYC versus perpetual KYC

What changes

Periodic KYC

Perpetual KYC

Trigger

A scheduled date by risk tier.

An actual change in the underlying data.

Coverage

Every customer on a cycle, changed or not.

Only the customers who changed, when they changed.

Freshness

Current only as of the last review date.

Current in near real time.

Failure mode

Backlogs and stale profiles between dates.

Noisy triggers flooding analysts with low-value reviews.

What it looks like in practice

In practice

A bank moves a segment of customers onto a perpetual KYC model. One customer, previously stable, suddenly shows a new director added to their corporate registry filing and a fresh negative-news article naming that director. Both events fire triggers, and the customer is queued for immediate re-assessment rather than waiting two more years for their scheduled review.

An analyst reviews the change, confirms the adverse media is relevant, and re-rates the customer higher with enhanced monitoring. Meanwhile, thousands of unchanged customers generate no reviews at all, so the team's effort concentrates on the handful that genuinely shifted. The same model would fail if the triggers were noisy, flooding the queue with irrelevant filing changes that mean nothing.

Why pKYC matters to operators

Periodic models force a trade-off between freshness and workload: review everyone often and drown in effort, or review less often and let profiles go stale. pKYC tries to escape that by tying effort to change. Done well, it reviews the customers who actually moved and keeps risk ratings current in near real time, which is exactly what ongoing due diligence is supposed to achieve.

The catch is that the model is only as good as its triggers. Noisy or poorly calibrated triggers flood analysts with low-value reviews, trading a backlog problem for an alert-fatigue problem. The value lives entirely in how well the triggers separate real change from noise, which is why data quality and trigger tuning are the real work of a pKYC program, not the technology label.

What to watch for

  • Trigger noise. Poorly tuned triggers that fire on immaterial changes will bury analysts and erode the model's advantage.
  • Data quality gaps. The model depends on clean, timely source data; stale or wrong inputs produce missed or false triggers.
  • Coverage blind spots. A change with no data feed behind it produces no trigger, so the profile silently stays stale.
  • Analyst capacity. If real triggers arrive faster than the team can work them, backlogs reappear in a new form.
  • Regulatory alignment. The model still has to demonstrate customers are reviewed appropriately, so trigger logic must be documented and defensible.

Quick questions

How is pKYC different from periodic review?

Periodic review refreshes every customer on a fixed schedule. pKYC refreshes customers when their underlying data changes, so it is event-driven rather than calendar-driven and keeps ratings current in near real time.

Does pKYC replace periodic review entirely?

Not always. Many firms run pKYC as the primary mechanism while keeping a periodic backstop for customers or data sources that produce few change signals. The mix depends on data coverage and risk appetite.

What counts as a trigger?

Any material change in the customer's data: new adverse media, an ownership or director change, a shift in transaction behavior, a change of address or jurisdiction, or a new screening hit. Good programs define these carefully.

What is the biggest risk with pKYC?

Trigger tuning. Noisy triggers flood analysts with low-value reviews, while missed triggers leave real change undetected. The whole value of the model sits in separating meaningful change from noise.

How does data quality affect pKYC?

Heavily. Because the model reacts to changes in data, stale, incomplete, or inaccurate source data leads to missed or false triggers. Clean, timely inputs are a precondition, not a nice-to-have.

How does pKYC relate to ongoing due diligence?

pKYC is a way to operationalize ongoing due diligence. It automates the continuous, event-driven refresh that ongoing due diligence calls for, rather than relying on manual attention or fixed cycles.

Go deeper

  • FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

What to know alongside Perpetual KYC (pKYC)