Published: 01 October 2026
What is Perpetual KYC (pKYC)?
Perpetual KYC (pKYC) — sometimes called perpetual know your customer — is an approach to customer due diligence (CDD) that keeps risk assessments current by monitoring for material changes rather than reviewing on a fixed schedule.
Where traditional models trigger a review every one, three, or five years regardless of whether anything has changed, perpetual KYC acts on the data: when a trigger event occurs, reassessment begins. When nothing material has changed, no unnecessary work is created.
The term “perpetual KYC” is an industry label, not a regulatory prescription. Neither the Financial Action Task Force (FATF) nor UK regulators mandate a model called pKYC specifically. What they do require — under FATF Recommendation 10 and Regulation 28(11) of the UK Money Laundering Regulations 2017 — is that CDD remains ongoing, up to date, and proportionate to risk. pKYC is the operational framework many firms use to meet those obligations continuously rather than periodically.
Key Takeaways about Perpetual KYC
- pKYC shifts CDD from calendar-based review cycles to risk-event-driven reassessment.
- It is not a named regulatory requirement, but it operationalises ongoing CDD obligations under UK MLR 2017 and FATF Recommendation 10.
- Effective pKYC depends on accurate, verified identity data — poor data quality at onboarding undermines the entire model.
- From 10 July 2027, EU AMLR Article 26 introduces maximum update intervals (1 year for high-risk clients; 5 years for standard). pKYC is one way to meet this ahead of the deadline.
How pKYC Differs from Periodic KYC Review
The defining difference between periodic KYC and perpetual KYC is the trigger for reassessment. Periodic models put time in control: reviews happen because the calendar says they should. pKYC puts data in control: reviews happen because something material has changed. This does not mean periodic reviews are always wrong. Scheduled reviews can still function as a backstop, particularly while firms build confidence in their event-driven controls.
The table below captures the main operational differences:
| Periodic KYC | Perpetual KYC (pKYC) | |
|---|---|---|
| Review trigger | Fixed calendar interval | Material change or trigger event |
| Risk rating | Updated only at review point | Maintained continuously |
| Client experience | Batch refresh requests to all | Targeted, proportionate outreach |
| Role of analyst | Volume-driven scheduled review | Focus on material changes only |
How pKYC Works in Practice
Think of pKYC as a living client risk assessment — not a one-off event that needs to be repeated periodically, but a continuously maintained record that is updated when the data demands it. Three elements must work together.
1. A verified identity baseline at onboarding
The foundation of any perpetual KYC model is an accurate, verified view of who the customer is at the point of onboarding. Document verification and biometric KYC checks establish the baseline against which all future monitoring is calibrated. A weak or inaccurate initial identity record does not simply create a data quality problem — it undermines every downstream pKYC decision. If the identity data at the core of a risk file is unreliable, the monitoring built on top of it is unreliable too.
2. Trigger events that initiate reassessment
Firms define which data changes constitute a material trigger — sanctions exposure, changes of beneficial ownership, adverse media, PEP status updates, identity document expiry, or client-reported changes. Not every update should generate analyst work. Materiality rules distinguish the significant from the minor: a customer’s address change is not the same event as a new entry on a sanctions list. The pKYC model routes the right triggers to the right response.
3. Proportionate response
A material event does not automatically mean a full CDD refresh. Depending on the nature of the trigger and the firm’s risk policy, the response might be an automated data update, a targeted identity re-verification request, a risk reassessment, or a full file review. Critically, the response — and the reasoning behind it — must be documented. The FCA’s concern is not just whether firms detect changes, but whether they can show what they did and why.
Why Identity Verification Is Central to pKYC
Most published commentary on perpetual KYC focuses on AML screening, transaction monitoring, and CDD workflow orchestration. What is rarely addressed — and what matters most — is the role that identity verification plays in making the model work.
Identity data quality underpins the model
pKYC is only as reliable as the data feeding it. Inaccurate or unverified identity data creates false positives in monitoring, corrupt risk ratings, and an audit trail that cannot withstand regulatory scrutiny. Strong identity verification at onboarding — document checks, biometric facial comparison, liveness detection — creates the trusted baseline. Without it, ongoing monitoring is built on uncertain ground.
Identity re-verification at trigger events
Some pKYC triggers require more than a data update. They require confirming the customer is still who they claim to be. A change of beneficial ownership, an expired identity document, a flagged adverse media event, or a client-initiated data change may all warrant re-verification. Remote continuous identity verification allows firms to request and process this without requiring in-person attendance, preserving the efficiency benefits of pKYC while maintaining regulatory defensibility. This is the link between identity infrastructure and a functioning ongoing KYC programme.
Benefits and Challenges of Perpetual KYC
pKYC offers real operational advantages, but it is not a straightforward implementation. Understanding both sides is important before committing to the operating model change it requires.
Benefits
- Regulatory compliance is maintained continuously — not just at review dates.
- Faster detection of genuine risk changes: sanctions exposure, PEP status, ownership shifts.
- Reduced operational waste — targeted reviews instead of mass annual refresh cycles.
- Improved client experience — fewer blanket re-KYC requests disrupting the relationship.
Challenges
- No standardised industry model — governance frameworks must be built from scratch.
- High data quality requirements — poor data sourcing degrades the entire model.
Cultural change: moving from scheduled to event-driven requires new workflows, clear ownership, and a different definition of “done.” For firms currently managing KYC remediation backlogs, pKYC represents not just a technology change but a fundamental rethink of how ongoing due diligence is resourced and governed.
Frequently Asked Questions about pKYC
What is the perpetual KYC process?
Perpetual KYC (pKYC) is an ongoing, event-driven approach to customer due diligence. Instead of reviewing customers on a fixed schedule, it continuously monitors for trigger events — such as changes in sanctions status, PEP exposure, transaction anomalies, or business ownership changes — and initiates a proportionate review only when a relevant signal appears.
What are the benefits of perpetual KYC?
pKYC reduces the volume of unnecessary periodic reviews, lowers compliance costs, and catches risk signals in real time rather than at the next scheduled check. It improves the customer experience by minimising friction for low-risk clients while ensuring high-risk changes are acted on immediately.
What does perpetual KYC do differently than regular KYC?
Traditional KYC runs on a calendar cycle (e.g. annual or triennial refresh regardless of risk changes). pKYC replaces that fixed cadence with a dynamic model: the customer’s verified baseline stays in place until a trigger event warrants a re-check. Reviews are proportionate to the signal, not the calendar.
How to implement perpetual KYC?
Implementation typically involves four steps: (1) establish a verified identity baseline at onboarding; (2) integrate monitoring feeds — sanctions lists, adverse media, PEP databases, and internal transaction signals; (3) define trigger events and the proportionate response each warrants; (4) automate the re-verification workflow so that when a trigger fires, the right level of re-check is initiated without manual triage.
How does IDnow help with pKYC?
IDnow can provide the identity-verification and workflow-orchestration layer within a pKYC approach. At onboarding, businesses can establish identity using checks such as document verification and biometrics. Later, when a risk signal or business rule calls for further verification, the IDnow Trust Platform can help route the customer through an appropriate, risk-based verification journey. This can make identity refreshes more targeted and lower-friction, while working alongside the business’s monitoring, screening, and customer-risk processes. Get in touch with our experts to learn more.
