en

Language

18 Jun 2026 in Q&A

What is Perpetual KYC (pKYC)? A Quick Explanation

Henry Patishman

Executive VP, Identity Verification solutions

In Brief: Perpetual KYC replaces routine file-refresh work with evidence-based review. Each risk event should leave the customer profile clearer than before: updated data, a justified risk level, and enough proof for compliance, QA, and audit teams to trust the decision.

KYC files tend to age: a document can expire, a customer can start using new products, or a risk match needs a closer look. If the KYC process only reacts at the next scheduled review, compliance teams may spend months working with customer information that no longer supports the risk rating.

Perpetual KYC, on the other hand, aims to address that gap, connecting ongoing monitoring with risk-based customer updates and re-verification.

This guide explains what perpetual KYC is, how it differs from the traditional KYC process, how perpetual KYC software turns relevant changes into review tasks, and where verified identity evidence fits into pKYC.

Subscribe

Subscribe to receive a bi-weekly blog digest from Regula

What is perpetual KYC?

Perpetual Know Your Customer (pKYC), also known as continuous KYC, is a risk-based KYC model in which a financial institution refreshes customer data and risk assessments when credible evidence shows a meaningful change.

The first record still comes from onboarding: identity verification, document checks, customer due diligence, beneficial ownership checks, screening, source-of-funds review, and an initial risk assessment. After onboarding, pKYC keeps that record current through perpetual KYC monitoring and updates customer information when policy calls for it.

A pKYC program watches for changes that may affect the risk level: 

  • a new sanctions or PEP hit, 

  • an expired or replaced ID, 

  • a changed beneficial owner, 

  • high-risk country exposure, 

  • new product use, 

  • behavior that stops matching the stated purpose of the relationship.

Depending on policy, the result may be no action, a data update, a customer request, enhanced due diligence, suspicious activity review, restricted access, or fresh identity checks.

Traditional vs. perpetual KYC

Onboarding KYC gives the institution its first verified view of the customer.

Perpetual KYC handles the part that comes later, when customer data, behavior, ownership, or external risk data changes.

 

Traditional KYC

Perpetual KYC

Review frequency

Fixed periodic KYC reviews by risk tier, policy, or law

Event- and risk-based review tasks, with scheduled checks kept where required

Main trigger

Calendar date, manual outreach, visible red flag

Change in customer information, risk level, ownership, sanctions or PEP status, adverse media, behavior, product use, geography, or document validity

Customer contact

Broad refresh campaigns that may ask for full document packs

Targeted requests tied to a specific data gap or risk change

Audit value

Limited, usually a pass/fail result

Stronger, with document images, personal data, match results, and liveness results

Risk assessments

Point-in-time ratings that may age between reviews

Customer risk profiles refreshed when meaningful evidence changes

Audit record

Review packages tied to due dates

Event history with source data, system result, analyst rationale, timestamp, and closure code

How does pKYC work?

Strong pKYC programs usually follow a simple rule: no alert should reach an analyst unless the policy explains why it may change the customer risk profile or why proof is needed. Before data feeds are connected, the team should define the trigger, source, threshold, owner, SLA, customer action, and permitted closure result.

Trigger

Usual case action

ID document expires or new ID is submitted

Request new proof, verify the document, update the file, restrict high-risk actions if policy requires it

New sanctions or PEP screening hit

Raise risk level, request extra context, or send to senior review

Beneficial owner or control change

Update ownership record, rerun risk assessment, apply enhanced due diligence (EDD) if risk increases

Activity outside expected use

Ask for explanation or proof, change risk rating, escalate to AML investigation where required

Device, selfie, or access anomaly

Step-up verification, temporary hold, fresh biometric check, fraud review

Important: Ideally, perpetual KYC software should filter the "noise" out before cases reach analysts. Typos, duplicates, and weak matches can go to QA; credible events that affect anti money laundering risk should go to review with the evidence attached.

What are the benefits of pKYC?

The efficiency of pKYC is often measured by quantitative and qualitative changes in analyst workload, customer contact rates, EDD volume, audit findings. Provided that the system functions well, KYC teams can expect:

  • Fewer no-change reviews. Periodic refresh queues often include customers whose customer risk profiles have not materially changed; perpetual KYC software can suppress or auto-close low-risk cases under approved rules and keep a QA sample.

  • Faster risk correction. When a PEP hit, UBO change, high-risk country exposure, or unusual transaction pattern changes the risk level, the file can move into review before the next scheduled date.

  • Sharper ongoing due diligence. Continuous KYC monitoring links identity evidence, screening, behavior, ownership, and case history, which helps compliance teams spot gaps between expected and observed activity.

  • Better customer experience. Targeted outreach asks for the missing proof or confirmation, rather than a full KYC pack when only one field changed.

  • Cleaner regulatory compliance evidence. Each event carries source data, timestamp, scoring result, analyst rationale, and closure code, so audit teams can test the decision path without rebuilding it from emails.

  • Better risk management staffing. Compliance teams can reserve deeper review for high-risk customers, complex legal entities, EDD cases, and unresolved AML concerns.

Where pKYC programs can fail

Before expanding a pKYC program, check for these weak points:

  • Trigger lists are too broad.

  • Data sources are not rated for reliability and freshness.

  • Auto-closure rules lack policy approval.

  • Customer requests do not say exactly which proof is missing.

  • Identity risk events have no re-verification path.

  • QA samples do not test closed cases, overrides, and customer complaints.

pKYC rollout plan for compliance teams

Start with one customer group and a trigger set small enough to test.

  1. Pick one segment, such as digital retail onboarding, fintech accounts, money services businesses, private banking, or cross-border corporate customers.

  2. Choose three to five triggers: document expiry, sanctions or PEP hit, adverse media, UBO change, high-risk jurisdiction change, or behavior outside expected activity.

  3. Write one rule sheet per trigger: data source, threshold, owner, SLA, customer message, closure codes, and escalation route.

  4. Add identity re-verification for triggers tied to document trust, face match, account takeover risk, or high-risk product access.

  5. Track false positives, analyst minutes per case, customer outreach rate, risk-rating changes, escalations, and cases closed without customer contact.

This makes your perpetual KYC monitoring system easier to test: fewer stale files, fewer unnecessary customer requests, faster risk reassessment, and cleaner audit records.

A final word on perpetual KYC

The real test of perpetual KYC is whether it changes the quality of decisions, not whether it adds more monitoring. A strong system will prompt the compliance team to act only when necessary: important data changed, the current risk rating may no longer hold, proof is missing, and others.

That is why pKYC changes how KYC reviews are prioritized. The age of a file still matters, but it should not be the main reason to reopen it when stronger signs of risk are available: new ownership, changed behavior, a fresh PEP match, an expired document, unusual product use, or identity data that no longer matches the original customer record.

In that model, Regula IDV Platform gives KYC specialists a way to manage identity beyond onboarding, with features that are especially relevant for ongoing identity lifecycle management:

  • centralized customer profiles that keep verification results, documents, biometrics, device history, and audit logs tied to the same customer record;

  • event-based re-verification when a document expires, customer data changes, or suspicious activity calls for step-up verification;

  • recurring compliance checks that help review identity evidence at required intervals;

  • biometric re-authentication and liveness checks to confirm that the same person is returning;

  • AML, PEP, sanctions, and database checks within configurable workflows;

  • historical identity, geolocation, and device data that can support risk scoring and enhanced due diligence.

Book Your Discovery Call

Let’s talk about making your ID verification faster, smarter, and fully integrated.

FAQ

What are the main benefits of implementing perpetual KYC in financial services?

Financial institutions gain fresher customer information, faster risk reassessment, fewer blanket KYC reviews, sharper case ranking, and more defensible audit records. The biggest gain comes from matching review depth to the risk level, so compliance teams spend analyst time on customers whose profile, ownership, transaction behavior, or external risk data has changed.

Is pKYC the same as continuous KYC monitoring?

Continuous KYC monitoring gathers the evidence: transaction patterns, screening hits, adverse media, data changes, and identity risk indicators. pKYC uses that evidence to update customer information, rerun risk assessments, create cases, record decisions, and change the customer risk profile when policy calls for it.

Does pKYC remove periodic KYC reviews?

pKYC does not remove periodic KYC reviews, because laws, supervisors, and internal policy may still require scheduled checks or maximum update periods. pKYC adds an earlier path for material change, so the file can be reviewed when risk changes rather than only when a calendar date arrives.

On our website, we use cookies to collect technical information. In particular, we process the IP address of your location to personalize the content of the site

Cookie Policy rules