Static KYC Is Giving Way to Perpetual Customer Risk Monitoring

Periodic KYC reviews are increasingly being challenged by a more dynamic model of customer risk management: perpetual KYC, or pKYC. The shift reflects a basic problem with calendar-based reviews. A customer assessed as low risk at onboarding can change materially before the next scheduled refresh through a new beneficial owner, a director change, a sanctions or PEP exposure, adverse media, a new address or a change in transaction behaviour.
KPMG Singapore describes pKYC as an ongoing, data-driven approach that moves firms away from fixed manual review cycles toward continuously refreshed customer information and risk profiles. The objective is not to remove periodic reviews entirely, but to make customer due diligence more responsive to events that actually change risk.
From scheduled reviews to event-driven triggers
In a pKYC model, the question changes from “is this customer due for review?” to “has something changed that requires reassessment?” Typical triggers can include changes in directors or beneficial ownership, new sanctions or PEP matches, adverse media, inconsistencies in identity information, unusual transaction patterns or other changes to the customer’s expected profile.
The value becomes greater when these signals are assessed together rather than in isolation. A beneficial-owner change may be routine. The same change combined with adverse media and unusual transaction activity may justify an immediate CDD refresh, enhanced due diligence or escalation.
RegTech providers are increasingly building this model into broader financial-crime workflows. ZIGRAM, for example, combines entity risk management, screening and transaction monitoring within its AML platform, with continuous monitoring signals feeding back into the customer risk view. This reflects a broader industry trend toward linking KYC, screening, transaction behaviour and case management rather than treating them as separate controls.
Data quality and governance remain the constraint
Moving to pKYC requires more than increasing screening frequency. Firms need reliable corporate-registry, sanctions, PEP, adverse-media and transaction data; clear materiality thresholds; risk-based triggers; automated workflows; human review for consequential decisions; and an audit trail showing what changed, how the risk assessment was updated and what action followed.
KPMG also cautions that there is no single pKYC operating model. The appropriate design depends on regulatory obligations, risk appetite, customer profile and operational maturity. For many firms, the practical transition is therefore gradual: first improve data quality and ownership, then define event triggers, connect monitoring sources and move toward exception-based review.
For AML teams, the key implication is that customer risk is increasingly being treated as a continuously changing state rather than a score that remains valid until the next scheduled review. Periodic review still has a role, but it is becoming a backstop rather than the only mechanism for keeping CDD current.



