A review calendar assumes change accumulates at a predictable rate. It does not. A customer can be unchanged for six years and then acquire a new ultimate owner, a new jurisdiction and a press mention in the same fortnight.
Triggers arrive without order, sometimes several at once, and often not at all. Nothing on the rail above has a fixed position, which is the point: a mechanism that fires on dates cannot catch events that ignore them.
The interval that decides everything
The largest span on the rail is not the review. It is the gap between a change happening and your firm detecting it.
Nothing in the review process shortens that gap. It is set by detection sources: whether you watch ownership registries, whether media monitoring covers the right languages and thresholds, whether jurisdiction status changes reach your system automatically. A firm with excellent review procedures and poor detection is slow in the only place that matters.
Why change of control leads the list
It alters who is actually behind the customer, and it is the change least likely to be volunteered. Ownership moves in registries and filings. A customer whose ultimate beneficial owner changed last quarter presents a materially different risk from the one you assessed, while appearing identical in your own records.
Everything else on the trigger list is either observable in the customer's behaviour or announced by a public authority. This one is neither, unless you are looking for it.
Materiality is what makes the model affordable
Detection without an assessment step produces a queue of reopened files nobody has capacity to work properly, and the usual outcome is that reviews get shallower rather than fewer.
The assessment exists to keep the population of full reviews small. Most detections should resolve there, which is not a failure of the trigger design but the reason it is sustainable.
Ratings that move need reasons
A risk rating that changes with no recorded cause cannot be distinguished later from one that changed by accident, and a rating that never changes at all is a record of a single opinion formed at onboarding.
Attaching the trigger to the rating move is what makes the history legible: not just that the customer is now high risk, but which event made them so and when.
For the operating model this sits inside, see perpetual KYC. For detection of the leading trigger, see Know Your Business. For the components, see adverse media checks and jurisdiction risk checks.
