SardineCon SF/2026

Learn More

O que é Customer lifecycle management?

SUBSCRIBE

Customer lifecycle management is keeping a customer's identity, risk, and due diligence current from onboarding, through ongoing review and trigger events, all the way to offboarding. Risk does not sit still, so the record cannot either, and the gaps between stages are where stale risk hides.

What is lifecycle management, in plain English?

Customer lifecycle management is the discipline of keeping the customer record accurate for the whole relationship, not just at the start. It spans onboarding, ongoing due diligence, periodic and event-triggered reviews, re-rating, and eventually offboarding when the relationship ends. The idea is that identity, risk, and diligence are living things that need maintaining, not a form you complete once.

The reason it exists is simple: risk does not stand still. A customer who looked low risk at signup can change ownership, launch new products, move into new markets, or shift their behavior in ways that raise their risk. If the record does not move with them, the firm is managing a customer who no longer exists, using controls tuned for a version of them that is out of date.

The danger lives in the gaps between stages. Onboarding data that never reaches monitoring; reviews that happen but never trigger a re-rating; material changes handled in one system and never fed back into risk assessment. Good lifecycle management makes sure that events like new products, ownership shifts, or big behavioral changes flow back into re-assessment rather than getting handled in isolation and forgotten.

The customer lifecycle, stage by stage

  1. Onboard — Establish the baseline. Verify identity, assess risk, and capture expected activity as the starting record.
  2. Monitor — Watch against the baseline. Ongoing monitoring compares real activity with what was expected at onboarding.
  3. Review — Refresh on cycle or trigger. Periodic reviews and trigger events, like ownership or behavior changes, prompt a re-look.
  4. Re-rate — Update the risk. Findings feed back into the risk rating, which resets the level of control the customer gets.
  5. Offboard — Close it out cleanly. When the relationship ends, records are retained and any residual risk is documented.

What it looks like in practice

In practice

A customer onboards as a sole trader running a modest online shop and is rated low risk. Two years on, the business is acquired by an overseas holding company and starts sending large cross-border payments. Each of those facts sits in a different system: the ownership change in one, the new payments in another.

In a firm with weak lifecycle management, neither triggers a re-rating, and the customer keeps being treated as a low-risk local shop. In a firm with strong lifecycle management, the ownership change is a trigger event that pulls the file into review, the risk is re-assessed against the new reality, and the controls catch up with the customer instead of lagging years behind.

Why it matters to operators

Lifecycle management is what stops a program from silently decaying. Every control downstream, monitoring thresholds, review frequency, the level of diligence, is tuned to the customer's current risk. If the risk record is frozen at onboarding, those controls are calibrated for a customer who may have changed completely, and the firm will not know until something goes wrong.

For operators, the practical work is closing the handoffs. A customer who looked low risk at signup can drift into high risk without anyone noticing unless the process forces material changes back into re-assessment. The goal is a system where new products, ownership shifts, and behavioral changes automatically pull the file back into review, so the record ages with the customer rather than freezing at the moment they joined.

What to watch

  • Onboarding-to-monitoring gaps. Baseline data captured at signup that never reaches the systems meant to watch the account.
  • Reviews without re-rating. Periodic reviews that get done but never actually change the customer's risk tier.
  • Isolated changes. Ownership or product changes handled in one system and never fed back into risk assessment.
  • No trigger events. Reliance on fixed review cycles only, so risk that shifts between cycles goes unseen.
  • Messy offboarding. Relationships closed without documenting residual risk or retaining the records regulators expect.

Quick questions

How is lifecycle management different from onboarding?

Onboarding is one stage, the start. Lifecycle management covers the whole relationship: onboarding, ongoing monitoring, reviews, re-rating, and offboarding. It treats the customer record as something to maintain, not complete once.

What is a trigger event?

A material change that should prompt a review outside the normal cycle: a shift in ownership, a new product, a big change in behavior, or new adverse information. Trigger events catch risk that moves between scheduled reviews.

Why not just rely on periodic reviews?

Because risk can change in a week and a review may be a year away. Periodic reviews plus trigger events together give both regular refresh and fast response when something material happens.

Where does stale risk usually hide?

In the gaps between stages: data that never crosses from one system to another, reviews that never re-rate, and changes handled in isolation. Closing those handoffs is the core of good lifecycle management.

How does it relate to perpetual KYC?

Perpetual KYC is a way of executing lifecycle management continuously, using event-driven updates instead of fixed periodic cycles, so the record refreshes as changes happen rather than on a calendar.

Why does offboarding matter?

Closing a relationship still carries obligations: retaining records, documenting why the relationship ended, and capturing any residual risk. A sloppy exit can leave gaps that surface in a later investigation.

Go deeper

  • FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

O que saber junto com Customer lifecycle management