What is Perpetual KYC (pKYC)? A Guide for Compliance Teams
Reviewed by: Tom Devlin, Managing Director at KYC360
Last Updated 28/08/26
Perpetual KYC (pKYC) is an approach to ongoing client due diligence that keeps client information and risk assessments current as relevant circumstances change. Rather than relying solely on fixed review dates, firms use ongoing data, screening and defined trigger events to determine when CDD should be reassessed. Neither FATF standards nor UK regulation prescribe an operating model called pKYC. It is an industry response to FATF’s risk-based due diligence standards and the ongoing monitoring requirements in the UK Money Laundering Regulations 2017.
How Perpetual KYC Differs from Periodic Review
Traditional periodic reviews refresh CDD according to a predetermined timetable, with intervals such as one, three or five years commonly determined by client risk. Perpetual KYC shifts the emphasis towards maintaining the client risk assessment as relevant information changes.
The distinction is broader than review frequency. A pKYC model connects client data, screening, risk assessment and workflow throughout the relationship. A material change can therefore affect the risk assessment and initiate proportionate action without waiting for the next scheduled review. Deloitte describes continuous KYC as focusing due diligence on “changes that affect risk decisioning”. Scheduled reviews can still operate as a backstop while firms develop confidence in event-driven controls. For a detailed comparison of review models, see event-driven KYC versus periodic review.
How pKYC Maps to Ongoing CDD Requirements
Regulatory frameworks do not require firms to adopt a model labelled pKYC, but they do require CDD to remain current and proportionate to risk. FATF Recommendation 10 calls for ongoing due diligence and current CDD information, while Regulation 28(11) of the Money Laundering Regulations 2017 requires ongoing monitoring and up-to-date CDD records.
From 10 July 2027, EU AMLR Article 26 adds maximum update intervals of one year for higher-risk clients to which the relevant enhanced due diligence measures apply and five years for other clients, alongside updates when relevant circumstances change or a relevant new fact becomes known. pKYC is one way firms can operationalise these requirements and standards.
What pKYC Controls Need to Evidence
The FCA’s April 2026 CDD review identified unclear periodic and event-driven review procedures, failures to follow review policies and weaknesses in version control. For pKYC, the practical implication is that detecting a change is only the start. Firms also need clear ownership, defined treatment rules and an audit trail showing what changed, how it was assessed and why the resulting action was appropriate. Clear KYC trigger events are one part of that control framework.
How pKYC Works in Practice
A useful way to think about perpetual KYC is as a living assessment of customer risk. Onboarding establishes the initial client view. pKYC then maintains that view by connecting new information to risk assessment and workflow throughout the client lifecycle. In practice, key elements need to work together:
A reliable customer baseline
Identity, ownership, screening results, documentation and initial risk decisions need to be captured accurately from the outset. KYC onboarding software can help create a structured baseline rather than leaving information across disconnected files and systems.
Ongoing risk signals
Once the initial client profile is established, firms need to monitor for information that could change their understanding of risk. An AML screening platform can identify changes in sanctions, PEP or adverse media exposure, while company and ownership data, document status and other trusted sources can highlight changes elsewhere in the client profile.
Materiality rules
Firms need to determine which changes could alter client risk and which can simply be recorded without creating unnecessary review work.
Proportionate treatment
A material event might result in an automated update, targeted check, client outreach, risk reassessment, EDD or a broader CDD refresh depending on policy and risk.
Decision evidence
The trigger, data source, assessment, action, approval and resulting risk decision need to remain traceable.
More Data Does Not Mean More Reviews
One of the most important design questions in pKYC is deciding what constitutes a material change. Not every new data point should create analyst work. A change to beneficial ownership, sanctions exposure or the nature of a client’s business may significantly alter the risk assessment. A minor administrative change may not.
Materiality rules allow firms to distinguish between those outcomes. They can also consider changes in combination. Several individually minor signals may become relevant when they occur together or indicate a wider change in the relationship. This makes calibration essential. Thresholds that are too broad risk creating large volumes of low-value alerts. Thresholds that are too narrow can leave meaningful changes outside the review process.
Data Quality and Provenance
A pKYC model is only as useful as the information feeding it. Adding more sources does not automatically produce a better understanding of risk. Firms need to know what a data source is intended to do, how reliable it is, how current it is and whether its provenance can be demonstrated.
A source might be appropriate for generating a trigger, validating a change detected elsewhere or enriching an analyst’s assessment. Those are different functions and should be treated accordingly. Data also needs to be connected back to the correct client and relationship. Changes in names, addresses, ownership structures and other attributes can otherwise create duplicate records or inconsistent views of the same client. A good pKYC approach therefore depends less on the sheer volume of data available than on whether the right data can be connected to the right client, assessed for materiality and turned into a defensible risk decision.
The Business Case for Moving to pKYC
The operational case for pKYC is not simply about completing fewer reviews. It is about reducing the friction involved in maintaining an accurate client risk profile. In many compliance functions, analyst time can be absorbed by fragmented data, repeated reconciliation, duplicated client outreach and the manual triage of changes that ultimately have little impact on risk.
pKYC introduces its own implementation challenges. Deloitte identifies data availability; technology, tools and skilled staff; implementation cost; and evidence and documentation as four significant areas to address. Firms also need clear ownership of triggers, materiality rules and downstream workflows.
Where those foundations are in place, the potential benefit is a more targeted operating model. Firms may be able to reduce avoidable refresh activity and client outreach, direct analyst capacity towards higher-risk relationships and material changes, and respond more quickly when risk shifts. The objective is not simply fewer reviews, but more targeted intervention when risk or missing evidence requires it.
Getting Started with pKYC
Moving to pKYC should be treated as an operating-model change rather than a technology switch. Governance should develop alongside the technology. Compliance should define materiality, risk treatment and escalation requirements. Data and technology teams need responsibility for source quality, integration and system performance. Operations teams need clear ownership of review, outreach and resolution.
Training also matters. Staff need to understand why an event has been generated, what evidence is required and when a targeted review should become a wider reassessment. For a closer look at the operational and compliance drivers behind the shift, see why financial firms are adopting a Perpetual KYC approach.
Conclusion
Perpetual KYC is ultimately about maintaining a better-informed view of client risk throughout the relationship. Continuous monitoring is one component, but the effectiveness of the model depends on the quality of the underlying data, the definition of material change, proportionate treatment and the ability to evidence each resulting decision.
The KYC360 Customer Lifecycle Management platform, combined with Experian’s consumer identity and business intelligence capabilities, supports a living view of client risk by connecting onboarding, screening, ongoing data, risk assessment and configurable review workflows across the client lifecycle.
FAQs
Perpetual KYC, or pKYC, is an approach to ongoing CDD that keeps relevant client information and risk assessments current as material changes occur. Ongoing data and screening signals are assessed against defined rules to determine whether a change requires no further action, an update, a targeted check, client outreach, a risk reassessment or a broader CDD review.
No. FATF standards do not prescribe an operating model called perpetual KYC, nor does the FCA require firms to adopt pKYC specifically. FATF standards call for ongoing due diligence and current CDD information, while UK regulation requires ongoing monitoring and relevant documents and information to be kept up to date. pKYC is an industry approach that can support firms in meeting those standards and requirements.
The terms are often used closely together, but pKYC is useful to think of as the broader operating model. Event-driven KYC describes the mechanism by which a material change prompts reassessment. Perpetual KYC also includes the data foundation, risk assessment, materiality rules, workflows, governance and audit evidence needed to maintain an up-to-date view of client risk.
No. A well-designed pKYC model applies materiality rules to determine which changes could affect client risk. Some changes may require no further action or can be processed automatically, while others may require analyst review, client outreach, a changed risk rating or enhanced due diligence. The thresholds should reflect the firm’s risk appetite and policies.
From 10 July 2027, EU AMLR Article 26 requires obliged entities to keep relevant client information up to date. It sets maximum update intervals of one year for higher-risk clients subject to the specified enhanced measures and five years for other clients. Firms must also review and, where relevant, update information when client circumstances change or relevant new facts emerge.
The exact data depends on the firm, client type and risk model. Typical inputs can include identity and contact information, company and beneficial ownership data, sanctions and PEP screening, adverse media, document status and internal risk information. The priority should be reliable, current and traceable data that can be connected to the correct client and used for a defined risk purpose.
The regulatory frameworks discussed above do not prescribe a specific pKYC effectiveness scorecard. Firms can assess whether triggers identify material changes, the proportion of cases requiring manual intervention, false-positive levels, time to risk decision, additional information requests, overdue cases and the proportion of events that result in meaningful risk action. Measures should test both control effectiveness and operational performance.
The KYC360 platform is an end-to-end solution offering slicker business processes with a streamlined, automated approach to Know Your Customer (KYC) compliance. This enables our customers to outperform commercially through operational efficiency gains whilst delivering improved customer experience and KYC data quality.
Consolidate your system stack and data vendor relationships with one platform to cover all Onboarding, Screening, Perpetual KYC (pKYC) and CLM tasks, with market-leading data sources pre-integrated under a single license agreement. Live risk scoring and automated data collection enables a shift from periodic to event-driven review, while providing a single actionable picture of real-time risk with all documents and data in one place.