Event-Driven KYC Monitoring vs Periodic Reviews. What is the Difference?
Reviewed by: Tom Devlin, Managing Director at KYC360
Last Updated 27/08/26
A KYC trigger event is a material change in a client’s profile, behaviour or external circumstances that should prompt a Customer Due Diligence (CDD) reassessment outside the normal review cycle. UK MLR 2017 requires firms to apply CDD when circumstances relevant to a client’s risk assessment change and to keep CDD information up to date through ongoing monitoring.
The Regulatory Framework for Trigger Events
The UK MLRs do not prescribe a fixed list of KYC trigger events or a statutory maximum review interval. Instead, Regulation 27 requires CDD at appropriate times on a risk-based basis and when a firm becomes aware that relevant client circumstances have changed. Regulation 28(11) requires ongoing monitoring, including reviewing existing records and keeping CDD current.
The FCA Financial Crime Guide reinforces that approach. It describes regular periodic reviews alongside procedures for event-driven reviews as good practice, and says firms should update CDD and reassess risk where monitoring indicates material changes to a client profile. From 10 July 2027, EU AMLR Article 26 sets more explicit requirements. It combines maximum update intervals with additional updates when relevant circumstances change or a relevant new fact is identified.
These controls can sit within a broader perpetual KYC model. For a direct comparison of the operating models, see event-driven KYC versus periodic review. For a closer look at the operational and compliance drivers behind this shift, see why financial firms are adopting a Perpetual KYC approach.
Common categories of KYC trigger events
Common trigger categories include:
1. Sanctions list changes
A new sanctions designation affecting a client, beneficial owner or other relevant party can materially alter the risk assessment and may require immediate sanctions action. Where a designated person owns or controls an entity, sanctions restrictions may also extend to that entity. Continuous screening through an AML screening platform can help firms identify these changes and route potential matches for assessment.
2. PEP status changes
If a client or beneficial owner becomes a politically exposed person, the firm should reassess the relationship and apply the measures required under Regulation 35. These include appropriate risk-management procedures, senior management approval, adequate measures to establish source of wealth and source of funds, and enhanced ongoing monitoring. Learn more about how to conduct effective PEP screening.
3. Adverse media
Credible adverse media can change the risk picture even where there has been no formal regulatory designation. New information involving fraud, corruption, organised crime or other relevant financial crime concerns should be assessed against the client profile and the firm’s risk appetite. The FCA Financial Crime Guide expects CDD and risk assessments to be updated where monitoring indicates material changes. For more information, see our guide on how to conduct effective adverse media monitoring .
4. Change of beneficial ownership
A change in ownership or control is a clear trigger for reassessment. Regulation 27 specifically identifies an indication that the identity of a client or beneficial owner has changed as a factor firms should consider when determining whether further CDD is required. A reliable baseline created through KYC onboarding software helps firms assess subsequent changes against the information originally collected.
5. Change of business activity or transaction pattern
A change in the purpose or intended nature of the relationship, or activity inconsistent with what the firm knows about the client, can indicate a changed risk profile. The signal may originate from another control, including transaction monitoring, but the KYC response should assess whether existing CDD and the client’s risk rating remain appropriate under the ongoing monitoring requirements in Regulation 28.
6. Jurisdiction risk changes
A client moving into a new jurisdiction, expanding into a higher-risk market or becoming exposed to a jurisdiction whose risk status has changed should prompt reassessment. Since 30 June 2026, Regulation 33 has required EDD and enhanced ongoing monitoring for relevant relationships and transactions involving persons established in a FATF Call for Action country. Other geographic risk factors continue to inform firms’ wider risk-based assessments.
7. Expired documentation
Document expiry does not automatically mean identity must be re-verified. HMRC guidance notes that re-verification is not generally required unless existing evidence is no longer adequate or reliable. Depending on the document and why it is held, however, an up-to-date copy may be needed to ensure the client record remains current.
The FCA’s 2026 CDD review found that some firms lacked clarity about what staff should do when an event-driven review occurs. A practical implication of these findings is operational: firms need to define not only what constitutes a trigger, but also the action, responsibility and escalation path that follows.
How to Evidence a Trigger Event Response to a Regulator
A trigger event should leave a clear audit trail. Firms should record what changed, when it was detected and which system or source identified it. The review record should then show what information was checked, who completed the assessment and whether the client’s risk rating or due diligence requirements changed.
The resulting decision should also be documented, including any additional CDD, EDD, screening or approval undertaken. In its 2026 CDD review, the FCA identified firms that could not demonstrate an audit trail of reviews or changes because their documentation lacked version control.
Where required information cannot be obtained, firms should record the steps taken, why the evidence was unavailable and the rationale for the resulting decision. This approach is also reflected in the Wolfsberg Group’s Source of Wealth and Source of Funds guidance, which emphasises documenting unavailable evidence and any mitigating controls applied.
What Enforcement Shows About Missed Triggers
The FCA’s action against Nationwide Building Society provides a direct example of what can happen when review processes fail to keep client risk current. In December 2025, the FCA fined Nationwide £44.1 million for weaknesses in its financial crime controls. For a substantial proportion of its client base, Nationwide lacked appropriate systems to deliver internally required periodic and event-driven reviews. The FCA Final Notice found that work to deliver an event-driven review process, outside new account openings, had still not been completed by the end of the relevant period.
The case shows why identifying a trigger is only the first step. Firms also need controls that connect the signal to a defined review process, update CDD and risk assessments where necessary, and preserve evidence of the resulting decision.
Conclusion
Effective trigger-event KYC depends on more than identifying that something has changed. Firms need clear thresholds, defined review workflows and an auditable record of how each material event was assessed and resolved.
The KYC360 Customer Lifecycle Management platform, combined with Experian’s extensive consumer identity and business intelligence data, supports configurable workflows for scheduled and unscheduled KYC trigger events, linking onboarding, screening and ongoing monitoring across the client lifecycle.
FAQs
A KYC trigger event is a material change in a client’s circumstances, risk profile or external environment that prompts a CDD reassessment outside the normal review schedule. Examples include changes in beneficial ownership, PEP or sanctions status, adverse media, business activity, jurisdiction or other information that may affect the firm’s assessment of financial crime risk.
UK MLR 2017 does not provide an exhaustive list of automatic triggers. It requires firms to apply CDD when circumstances relevant to a client’s risk assessment change. Relevant events can include changes in beneficial ownership, unusual activity, a change in the purpose of the relationship, new PEP or sanctions exposure, and other information that could materially affect risk.
Under UK MLR 2017, review frequency should be risk-based rather than determined by a single statutory interval. Firms should also review CDD when relevant circumstances change. From 10 July 2027, EU AMLR Article 26 sets maximum update intervals of one year for higher-risk clients and five years for other clients, alongside event-triggered updates.
Record the trigger, when and how it was detected, the information reviewed and the person responsible for the assessment. The record should also show the resulting risk decision, any additional CDD or EDD measures, approvals and changes to the client risk rating. The FCA’s 2026 CDD findings reinforce the importance of clear version control so the sequence of reviews and decisions can be reconstructed.
A periodic review takes place according to a defined schedule, usually determined by the client’s risk level. A trigger event review takes place outside that schedule because something material has changed. The approaches can operate together, with scheduled reviews providing a backstop and event-driven reviews allowing firms to respond when relevant risks change between review dates.
The KYC360 platform is an end-to-end solution offering slicker business processes with a streamlined, automated approach to Know Your Customer (KYC) compliance. This enables our customers to outperform commercially through operational efficiency gains whilst delivering improved customer experience and KYC data quality.
Consolidate your system stack and data vendor relationships with one platform to cover all Onboarding, Screening, Perpetual KYC (pKYC) and CLM tasks, with market-leading data sources pre-integrated under a single license agreement. Live risk scoring and automated data collection enables a shift from periodic to event-driven review, while providing a single actionable picture of real-time risk with all documents and data in one place.