Use case

Perpetual KYC

Review driven by what changed rather than by the date. What replaces the periodic refresh cycle, which triggers actually warrant a review, and why a continuous model produces less work rather than more.

Last updated

Two colleagues reviewing data on a laptop in an office

Continuous review

No gaps, because nothing waits for a date.

  1. ContinuousWatchList changes, ownership changes, adverse media and behavioural signals monitored against the standing book.
  2. On changeTriggerA signal crosses the threshold your risk appetite sets. This is the moment a periodic model would have missed.
  3. ImmediatelyAssessEstablish whether the change is material to the customer's risk rating, or noise that should not consume an analyst.
  4. Where warrantedRefreshUpdate the file, re-rate the customer, and record what changed and why the rating moved.
Deliberately the opposite reading of the superannuation rail, which is mostly empty. Here every span is occupied, because a trigger can arrive at any point and is acted on when it does rather than at the next scheduled review.

Periodic review sets a date and checks the file when it arrives. The date has no relationship to the customer, so a change occurring the month after a review waits until the next one to be noticed, and a customer whose circumstances have not moved at all is reviewed anyway.

Perpetual KYC inverts that. The trigger is the change, and the review happens because something happened.

Why the diagram has no gaps

The superannuation rail on this site is mostly empty, because that page argues about a relationship where almost nothing occurs for decades. This one is the opposite reading of the same instrument: every span is occupied, because there is no waiting.

That is the whole distinction. A periodic model spends most of its time in a gap it created. A continuous one has no gap to be exposed in.

The step that decides whether this works

Monitoring continuously is straightforward. The difficulty is what happens next, because a model that treats every signal as a review request produces more work than the cycle it replaced and collapses within a quarter.

The materiality assessment is what prevents that. Most signals resolve there: noise, duplicates, changes with no bearing on risk. Only what survives becomes a refresh. Get that step right and total review volume falls, because effort stops being spent on customers whose circumstances have not moved.

The change that matters most is usually invisible

The single change most likely to alter a customer's risk is a change in who owns or controls it, and it rarely arrives as a customer notification. It shows up in a registry, in a filing, or not at all.

That makes ownership change detection the highest-value trigger in the set, and the one most likely to be absent from a programme that only watches names against lists.

What a supervisor asks under this model

Under a periodic model the question is easy: when was this customer last reviewed, and the answer is a date. Under a continuous model there is no such date, so the question becomes what coverage existed and what happened when things changed.

That is answerable, but only if the trigger history is retrievable per customer. Continuous coverage that cannot be evidenced looks, from the outside, exactly like no coverage.

For the underlying capability, see PEP and sanctions screening and transaction monitoring. For the ownership data the best trigger depends on, see Know Your Business. For what happens at the start of the relationship, see customer onboarding.

What we do.

Signals worth reacting to

A trigger model is only as good as its thresholds. Too sensitive and it recreates the alert fatigue it was meant to remove, too blunt and it misses the changes that mattered.

Ownership change detection

The change most likely to alter a customer's risk is a change in who controls it, and it usually happens without the customer telling you.

Materiality assessment

Not every change deserves a refresh. The assessment step exists to keep the population of full reviews small enough that they are done properly.

Rating that moves

A risk rating set at onboarding and never revisited is a record of what someone thought once. Under a continuous model it is a live position with a reason attached to every move.

Evidence of continuity

A supervisor asks when the customer was last reviewed. Under a periodic model the answer is a date. Under this one it is the last time something changed, which needs to be just as retrievable.

Highlights.

  • Review driven by change rather than by the calendar
  • Thresholds set to risk appetite rather than to vendor defaults
  • A materiality step, so refreshes stay rare enough to be done properly
  • Retrievable evidence of continuous coverage, not just of the last review date

Questions

Common questions about perpetual kyc.

Does perpetual KYC mean reviewing every customer constantly?
No, and that misunderstanding is why it is often resisted. Monitoring is continuous, but full review is not. The point of the materiality step is that most signals resolve without a refresh, so the number of full reviews falls compared with a periodic model that reviews a whole risk band whether or not anything changed.
Why does a periodic cycle miss things a continuous one catches?
Because the review date is chosen by the calendar rather than by the customer. An annual cycle checks the file on a date unrelated to anything that happened, and a change occurring one month after a review waits eleven months to be seen. The exposure is the gap, and a periodic model creates the gap by design.
Does this produce more work or less?
Less, provided the materiality step is real. Periodic review spends effort on files where nothing changed. Event-driven review spends it where something did. The saving comes from not refreshing customers who did not need it, which is most of them.
What triggers should actually cause a review?
List and designation changes, ownership or control changes, adverse media above a threshold, jurisdiction changes, and behavioural signals that do not fit the customer's profile. The specific thresholds are a risk appetite decision, and setting them too sensitively recreates the alert fatigue this model exists to remove.
How does this differ from the ongoing monitoring product?
The product page covers the monitoring capability itself. This page covers the operating model built on it, including the materiality assessment and what happens to the risk rating, which is where perpetual KYC succeeds or fails.

Talk to the MemberCheck team.

Get in touch and we'll walk you through how MemberCheck can help.