What Is Perpetual KYC? From One-Time Checks to Continuous Verification
One-time KYC verifies a moment in time. Perpetual KYC keeps that evidence current — here's how scheduled and event-driven reviews actually work.
Perpetual KYC is a risk-based operating model that keeps customer information, evidence, and decisions current after onboarding through scheduled and event-driven reviews.
VOVE ID helps fintech teams design identity workflows that continue after the first approval. The gap appears when a customer is verified once, then the business treats that snapshot as permanently reliable while documents expire, ownership changes, risk signals move, and customer activity changes.
A single approval is a moment in time, not a permanent status.
Direct answer
Perpetual KYC does not mean an always-on universal identity check. It means the team defines when customer due diligence must be refreshed, which events trigger a review, who owns the case, and what evidence records the outcome. The cadence and triggers must follow the firm's risk assessment and applicable rules.
As of August 12, 2026, the FATF Recommendations call for records collected in customer due diligence to be kept up to date and relevant, particularly for higher-risk customers. In the EU, Regulation (EU) 2024/1624 is scheduled to apply from 10 July 2027; teams should continue to follow the rules that apply to them now and obtain legal advice on local implementation.
One-time onboarding: a decision made with a time limit
Initial KYC answers a narrow question: can the firm establish enough confidence to begin or continue a relationship under its policy? The NIST identity-proofing model separates resolution, validation, and verification. It is a useful way to document what the original decision actually established.
It does not establish that every fact will remain current. A document can expire. A customer's address, role, ownership, expected activity, or risk profile can change. A sanctions or PEP-screening result can require a different review at a later point.
This means one thing: the initial KYC file is the beginning of an evidence record, not the end of it.
For the underlying framework, see our KYC requirements explained.
This guide covers the individual-customer side of the lifecycle. For the equivalent model on business customers — ownership, directors, and registry changes — see our Perpetual KYB Monitoring guide.
The four review paths: scheduled, event-driven, screening, and activity-led
Scheduled refresh. A team reviews a customer record on a risk-based cadence. Higher-risk relationships may need a shorter review cycle than lower-risk relationships. The cadence is a policy decision supported by the firm's risk assessment; it is not a universal vendor setting.
Event-driven review. A review begins because the firm learns something material: a document expiry, a reported change in customer details, an ownership or control change for a business, or a policy change that affects the customer's eligibility. The event must create a case, not disappear into an inbox.
Screening-led review. New or changed screening information can require human assessment. The right response is not automatically an exit or an approval. It is a documented decision using the customer context, applicable requirements, and the team's escalation policy.
Activity-led review. Customer activity can show that the original risk profile no longer fits. Transaction monitoring and KYC are related but distinct controls: monitoring can create a reason to revisit the customer record; it does not replace evidence collection, identity review, or an accountable decision.
The FATF's approach ties ongoing due diligence to both scrutiny of the relationship and keeping CDD records current. Treating these paths as one queue lets a team see why a review occurred and what decision closed it.

A realistic failure: the customer file remains approved while the context moves
A cross-border payments fintech onboards an SME with complete documents and an expected low-risk activity profile. The original case is approved and the record is stored.
Months later, the customer updates its directors, the original proof of address reaches the team's policy expiry point, and activity begins to differ from the stated purpose of the account. The information is scattered across account management, a document store, and a monitoring queue.
No owner can see the full change history or determine which evidence must be refreshed. The team either asks for everything again or does nothing until a review forces the issue.
This is not a one-time-KYC failure. It is a lifecycle-control failure.
How VOVE ID fits: make re-review a controlled case
VOVE ID supports identity verification, biometric liveness, face matching, AML screening, KYB, and transaction monitoring across a broad range of document types and countries (exact figures available on request), and can flag document-template inconsistencies, invalid MRZ checksums, barcode or QR inconsistencies, and image manipulation on re-review.
The platform does not decide a firm's review cadence or risk policy. Teams should define their own event taxonomy, escalation rules, evidence requirements, and review ownership, then confirm the relevant VOVE ID configuration and workflows for their use case. Screening runs on a customer-configurable basis, and where a compliance team has sufficient evidence on file, manual review may support an approval decision without a full re-collection.
The operational target is one auditable case record: why the review started, which evidence was considered, who decided, what changed, and when the next review is due. That target reduces both unnecessary re-collection and unexplained stale files.
Practical perpetual KYC checklist
Policy and segmentation
- Define customer-risk segments and a documented review cadence for each.
- Specify the events that require a KYC, KYB, screening, or compliance review.
- Set the evidence threshold and decision owner for every review type.
Data and workflow
- Record the original evidence, its relevant expiry or refresh point, and the basis of the initial decision.
- Route scheduled and event-driven triggers into one accountable case workflow.
- Preserve the trigger, evidence, reviewer action, rationale, and next review date.
Operations and assurance
- Separate transaction-monitoring alerts from identity refresh tasks while linking relevant cases.
- Test escalation paths for changed ownership, changed risk, expiring evidence, and unresolved information.
- Review overdue cases, policy exceptions, and repeat triggers as management information.
FAQ
Is perpetual KYC the same as continuous monitoring?
No. Perpetual KYC is the wider customer-lifecycle model for keeping CDD information and decisions current. Continuous or transaction monitoring can provide a trigger, but it does not by itself refresh identity evidence or close a KYC case.
How often should KYC be refreshed?
There is no responsible universal interval. The review schedule should be risk-based and align with the rules, risk assessment, customer type, products, and events relevant to the firm.
What triggers an event-driven KYC review?
Common examples include an evidence expiry, changed customer details, a business ownership change, a risk signal, or activity that no longer fits the recorded profile. The firm should document which events matter and who acts on them.
Does perpetual KYC mean asking every customer for documents repeatedly?
No. The purpose is targeted refresh and documented review. A good workflow requests the evidence needed for the trigger and risk decision instead of restarting every case from zero.
Conclusion
Perpetual KYC isn't a background process running silently in the dark. It's a set of decisions — when to look again, what triggered the look, and who signs off on what comes next.
Teams need a risk-based cadence, useful triggers, clear review ownership, and a case record that explains each decision made along the way.
This article is intended for general informational purposes only and does not constitute legal, financial, or regulatory advice. KYC/KYB/AML requirements may vary depending on jurisdiction, industry, and specific business circumstances. For up-to-date and binding compliance obligations, readers should refer to the relevant regulatory authorities or consult qualified professionals.