KibiPay
HomeBlog › AML

Perpetual KYC and Ongoing Monitoring

6 min read AML
KYCAMLMonitoring
Perpetual KYC and Ongoing Monitoring

Traditional Know Your Customer practice reviews each customer on a fixed schedule — high-risk customers perhaps annually, low-risk every few years. The trouble is obvious: a customer's circumstances can change the day after a review, and the risk stays invisible until the next scheduled refresh. Perpetual KYC (pKYC) is the industry's answer — replacing the periodic calendar with continuous, event-driven monitoring so the customer risk picture is always current.

The problem with periodic review

Periodic KYC has two failure modes. First, it is stale: risk that emerges mid-cycle goes undetected, sometimes for years. Second, it is inefficient: firms re-verify enormous numbers of customers on a schedule regardless of whether anything has actually changed, generating vast manual workloads and customer friction for reviews that mostly confirm the status quo. Large institutions have spent heavily on periodic refresh backlogs that add little real risk insight.

What perpetual KYC changes

Perpetual KYC flips the model from time-driven to event-driven. Instead of asking "has it been a year?", it asks "has something material changed?" The customer profile is continuously compared against incoming signals, and only a genuine change triggers work. When nothing has changed, no review is generated; when something has, review happens immediately rather than waiting for a calendar date.

Trigger events

The engine of pKYC is the trigger event — a change that warrants re-assessing a customer's risk. Common triggers include:

Each trigger is risk-weighted, so a minor address change is handled differently from a fresh sanctions match.

The data and technology backbone

Perpetual KYC only works if the underlying data flows in continuously. That means integrating feeds such as corporate registries, sanctions and PEP data, adverse-media monitoring, and internal transaction monitoring into a single view of the customer. Automation does the heavy lifting: matching incoming events to customer records, resolving obvious non-issues automatically, and escalating genuine changes to analysts. The goal is not to remove humans but to point their attention only at cases that truly need judgement — turning a mountain of scheduled reviews into a focused queue of meaningful events.

Benefits and pitfalls

Done well, pKYC delivers both better risk coverage and lower cost: risk is caught when it emerges, and effort is spent only where something changed. But it introduces its own challenges. Data quality becomes critical — noisy or poorly matched feeds generate false triggers that overwhelm analysts. Governance must define exactly which events are triggers and how each is handled, so the approach remains explainable to regulators. And firms must avoid the trap of a system that generates alerts nobody can action; continuous monitoring without the capacity to resolve triggers is worse than a well-run periodic model.

Where the industry is heading

Regulators broadly encourage effective ongoing monitoring, and many now view a well-implemented perpetual model as best practice rather than a novelty. The direction of travel is clear: away from the arbitrary review calendar and toward a living risk profile that updates as reality does. For builders, the design implication is to treat KYC not as an onboarding gate that closes behind the customer, but as a continuous process wired into every relevant data source across the customer lifecycle.

Implementing pKYC incrementally

Few firms flip to perpetual KYC overnight; most get there in stages. A practical path starts by digitising and centralising customer data so a single, current profile exists to monitor at all. Next, firms wire in the highest-value trigger sources first — sanctions and PEP screening and internal transaction monitoring — since these carry the sharpest risk. Entity resolution and match tuning come next, because poor matching is the fastest way to bury analysts in false triggers. Finally, automation is layered on to auto-clear obvious non-issues and route only genuine changes for human review. Treating it as a phased programme, with clear metrics on trigger volumes and resolution times, avoids the trap of switching on continuous monitoring before the organisation can absorb the alerts it produces.

Key takeaways

See these rails in motion

KibiPay connects UK Faster Payments, Bacs, CHAPS, Mojaloop mobile money and Solana behind one API, with ISO 20022 messaging and real-time fraud & AML screening.

Open the live console How it works