Mateusz Pniewski

CEO @ TransactionLink

Perpetual KYC: How AI Can Replace Periodic Reviews in Bank Compliance

AI-driven perpetual KYC lets banks reassess customer risk as it changes, potentially eliminating 70-90% of periodic-review work.

Compliance teams often put hours into a scheduled KYC review, only to discover that nothing significant has changed. For banks serving hundreds of thousands of business customers, these reviews never stop, and the backlog keeps growing. Yet much of this work doesn't need to wait for a fixed date on the calendar.

Capgemini estimates that shifting from calendar-based reviews to perpetual Know Your Customer (KYC) could remove 70-90% of periodic-review effort.

AI makes this shift possible by assessing customer information across the whole customer lifecycle and flagging issues as soon as a customer's risk profile changes. As more work gets done between scheduled reviews, the periodic review itself could eventually become unnecessary.

How Periodic KYC Reviews Work Today

A typical periodic review moves through several stages, and each one adds time and manual effort:

  1. Locating the file and scoping the review. Analysts track down the customer file, which may be spread across legacy and modern systems, and work out what needs checking. If a different team handled onboarding, the context is hard to rebuild. Analysts may also need to read through years of earlier case notes to understand the customer's history.
  2. Carrying out enhanced due diligence (EDD). Analysts examine the evidence and run further checks, frequently switching between multiple tools. Some end up verifying documents that the review doesn't actually require.
  3. Requesting and assessing more information. When gaps remain, analysts send a request for information (RFI) to the customer and then evaluate the reply. The RFI stage alone can stretch over several days.
  4. Securing sign-off. A separate quality assurance (QA) team may check the work before the case is approved, which adds one more handoff.

‍

Why Periodic Review Workloads Keep Growing

Duna's conversations with 12 European financial institutions reveal how heavy this burden has become. Ten named periodic reviews, remediation, or re-KYC as a key challenge, and two reported that periodic reviews cost more than onboarding.

One reason is that analysts frequently have to reopen decisions made years ago. A high-risk factor can prompt a fresh review even when the bank's risk appetite has since shifted. The analyst may then need to reassess the customer broadly to establish whether the original concern still holds.

This depth of effort isn't always justified. Draft guidance from the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) says periodic reviews need not always be equally deep or intensive. Banks can decide which information, data, or documents need refreshing according to the customer's risk profile.

The guidance also warns that blanket rules, such as automatically collecting expired documents irrespective of risk, can generate unnecessary operational and financial costs.

‍

How AI Transforms Scheduled KYC Reviews

AI agents can carry out most of the investigative work before a periodic review lands with an analyst, gathering and assessing individual pieces of evidence.

Within Duna's AI-native compliance infrastructure, these agents operate alongside a policy engine that tests the evidence against the bank's own policy. The engine confirms which requirements are already satisfied, sends AI to investigate anything outstanding, and escalates cases to an analyst when human judgment is needed.

For banks, AI must also meet a bank-grade standard. Compliance teams need to show internal auditors or supervisors how a decision was made, what evidence supported it, and that the outcome is repeatable. Duna records the evidence behind every decision and how it shaped the result, so each decision can be explained after the fact.

This changes the review process in three key ways:

  1. Valid evidence can be reused. A policy update since a customer's last review doesn't mean every piece of information must be gathered again. Evidence already on file can be continuously checked against the current policy. For instance, if a bank amends its periodic-review policy three years after onboarding, a passport on file can be reused as long as it remains valid. An expired passport would require the customer to provide a new one.
  2. Analysts begin with the full picture. Rather than collecting and checking basic information, the analyst sees what already meets policy and which specific points need investigation. A review might reach them with two open issues instead of an entire customer record to reassess, so their time goes to the questions that require judgment.
  3. Customer risk stays up to date between reviews. New information arriving during the customer lifecycle can be evaluated immediately. Ongoing screening, for example, can pick up a new sanctions or adverse-media hit and trigger a risk reassessment at that moment instead of at the next scheduled review.

‍

Event-Driven KYC: Responding to Risk as It Changes

Every institution in Duna's research that addressed the topic wants to move away from fixed one-, three-, or five-year cycles toward reviews triggered by events such as a change of address, ownership, or sector code, or by an alert. The findings also show that banks are already piloting and using event-driven models, with perpetual KYC emerging as a strategic objective.

Duna's research also explains the motivation: events can expose risks that scheduled reviews miss. The harder question is which changes should trigger a review, and answering it requires the bank to define its policy first.

Regulation does limit how far banks can move away from scheduled updates. When the EU Anti-Money Laundering Regulation (AMLR) applies from 2027, banks must keep customer information current, with no more than one year between updates for certain higher-risk customers and five years for others (Article 26(2)). The regulation also requires customer information to be reviewed whenever relevant circumstances change (Article 26(3)).

Banks can treat these requirements as a chance to rethink the periodic-review cycle instead of layering additional data collection onto their existing process.

‍

Preparing for a Future Without Periodic Reviews

Periodic reviews anchor compliance work to fixed points in time. AI breaks that link by enabling evidence to be evaluated and risk to be reassessed across the entire customer lifecycle.

When changes are handled as they occur, less work remains for the next scheduled review. In time, banks may no longer need periodic reviews as we know them today.

‍

The End of Periodic Due Diligence