Event-Driven KYC Monitoring vs Periodic Reviews. What is the Difference?
Reviewed by: Tom Devlin, Managing Director at KYC360
Last Updated 11/08/26
A periodic review refreshes CDD on a fixed cycle, often every one, three or five years. Event-driven KYC triggers a CDD reassessment when a material change occurs, regardless of the last review date. FATF and UK regulation require risk-based ongoing due diligence, while EU AMLR Article 26 combines maximum update intervals with event-triggered reviews from July 2027.
How the Two Models Compare
The main difference between periodic and event-driven KYC is what prompts a review.
| Dimension | Manual Periodic Review | Event-Driven KYC |
| Trigger Logic | A calendar date based on the client’s risk tier | A material change that crosses a defined threshold |
| Risk Coverage | A detailed point-in-time refresh, with potential risk drift between dates | Ongoing monitoring for relevant changes between scheduled controls |
| Operational Effort | Cases are created because a review is due | Work is directed towards changes that may affect risk |
| Primary Evidence | Review record, refreshed CDD and approval decision | Trigger record, source data, reassessment and decision audit trail |
Periodic reviews provide a predictable control framework. A firm can segment clients by risk and determine when each file must be refreshed. The limitation is that the schedule and the client’s actual risk can move independently. A change in beneficial ownership or jurisdiction, new sanctions exposure or adverse media may arise months before the next review is due.
Event-driven KYC changes that logic. Rather than asking whether a review date has arrived, the firm asks whether something has changed that could affect the client’s risk assessment.
Deloitte describes continuous KYC as due diligence “focused on changes that affect risk decisioning, as opposed to a repapering exercise.” This does not mean removing periodic controls altogether. A risk-based model can retain scheduled reviews as a backstop while using event-driven reviews to address material changes between them.
What Regulators Say
Regulatory frameworks support the principle behind event-driven monitoring without prescribing a particular technology or operating model.
FATF Recommendation 10 requires ongoing due diligence throughout the business relationship, with the extent of CDD measures determined using a risk-based approach. UK MLR 2017 Regulation 28(11) similarly requires ongoing monitoring, including keeping CDD documents, data and information up to date.
The EBA’s ML/TF risk-factor guidelines require firms to apply CDD measures in a manner proportionate to the level of money laundering and terrorist financing risk. From 10 July 2027, EU AMLR Article 26 sets more explicit requirements. It sets maximum update intervals of one year for higher-risk clients and five years for other clients, while also requiring CDD to be updated when relevant circumstances change.
Taken together, these requirements support current, risk-sensitive CDD rather than reliance on a review date alone.
The Cost Case
Periodic reviews can create large volumes of work irrespective of whether a client’s circumstances have materially changed. PwC estimates that a complex corporate KYC review can require 62 hours of effort, compared with 105 minutes for a complex retail review. It also estimates KYC at around 3 percent of a bank’s operating cost base.
A calendar-driven model means review volumes tend to grow with the size of the client book. Event-driven KYC creates the opportunity to direct more analyst capacity towards material changes and higher-risk cases instead. That benefit depends on good data and carefully calibrated triggers. Poorly designed rules can simply replace a periodic-review backlog with an alert backlog.
The Risk Case: What Enforcement Shows
The consequences of failing to keep client risk current are illustrated directly by the FCA’s action against Nationwide Building Society. In December 2025, the FCA fined Nationwide £44.1 million for weaknesses in its financial crime systems and controls, including deficiencies in customer due diligence and customer risk assessment.
The FCA found that, for a substantial proportion of its client base, Nationwide had no effective process for undertaking either periodic or event-driven reviews. This delayed the refresh of existing CDD and compromised the firm’s ongoing understanding of client risk. Nationwide’s policies required risk-based periodic reviews, complemented by event-driven reviews, but the firm lacked the systems needed to implement those requirements.
The case does not demonstrate that event-driven KYC alone would have prevented the failings. It does, however, show why scheduled reviews cannot operate in isolation. Material changes in client risk can arise between review dates. A firm therefore needs to connect monitoring signals to action. A material change should be identified, assessed against defined thresholds, routed to the appropriate team and recorded in an audit trail that supports the resulting decision.
How to Transition from Periodic to Event-Driven KYC
Firms first need a reliable client record and connected inputs from processes such as KYC onboarding software and an AML screening platform. If ownership, screening, transactional and risk data remain fragmented, it is difficult to determine whether a change is genuinely material.
The next step is defining which KYC trigger events should prompt reassessment. These might include a change in beneficial ownership, PEP or sanctions exposure, adverse media, jurisdiction, risk score, business activity or expected versus actual transaction behaviour. Trigger thresholds then need to be proportionate. Not every data change should create a full review. Firms should determine whether an event requires no action, a targeted check, a risk reassessment or a broader CDD refresh.
Lower-risk cohorts can provide a practical starting point for a pilot. Scheduled and event-driven controls can run alongside one another while teams test trigger quality, false positives, workflow ownership and audit evidence. Firms can improve the model incrementally rather than treating periodic and event-driven KYC as an immediate binary choice. For more context, see why financial firms are adopting a Perpetual KYC approach.
The KYC360 Customer Lifecycle Management platform combined with Experian’s extensive consumer identity and business intelligence data supports ongoing monitoring and event-driven review across the client lifecycle.
FAQs
Periodic review refreshes CDD on a defined timetable linked to client risk. Event-driven KYC starts a reassessment when a material change occurs. The approaches can work together. Scheduled reviews provide a backstop, while event-driven controls respond to risk changes between those dates.
Neither FCA nor FATF prescribes a methodology called event-driven KYC. FATF requires ongoing due diligence on a risk-sensitive basis, while FCA expectations focus on effective ongoing monitoring and current CDD. Firms must evidence that their controls identify and respond to changing risk.
There is no universal saving. Results depend on portfolio mix, data quality, trigger design and existing manual effort levels.
From 10 July 2027, EU AMLR Article 26 requires CDD information to be updated when relevant client circumstances change or other specified events occur. It also sets maximum periodic update intervals of one year for higher-risk clients and five years for others.
Improve the client data foundation, then define material triggers and thresholds. Pilot suitable lower-risk cohorts, retain scheduled controls during validation, and preserve evidence of each trigger, assessment and decision. Refine segmentation and thresholds based on outcomes.
The KYC360 platform is an end-to-end solution offering slicker business processes with a streamlined, automated approach to Know Your Customer (KYC) compliance. This enables our customers to outperform commercially through operational efficiency gains whilst delivering improved customer experience and KYC data quality.
Consolidate your system stack and data vendor relationships with one platform to cover all Onboarding, Screening, Perpetual KYC (pKYC) and CLM tasks, with market-leading data sources pre-integrated under a single license agreement. Live risk scoring and automated data collection enables a shift from periodic to event-driven review, while providing a single actionable picture of real-time risk with all documents and data in one place.