Zenoo
Learn/What is perpetual KYC (pKYC)? A guide to…
Orchestration

What is perpetual KYC (pKYC)? A guide to continuous customer due diligence

Perpetual KYC replaces the calendar-based review with continuous, event-driven due diligence. Here is how it works, what regulators expect, and how to adopt it without replacing your vendors.

Last reviewed 18 June 202615 min read
In shortThe answer, first

Perpetual KYC (pKYC) keeps every customer's identity and risk profile current in near real time. Instead of refreshing records on a fixed one, three, or five year cycle, it monitors risk signals continuously and opens a targeted review the moment a material change occurs, such as a new sanctions listing, ownership change, or adverse media.

Key facts
  • Also called continuous, dynamic, or event-driven KYC, and extended to businesses as perpetual KYB.
  • It is event-driven, not a faster batch job: the review is triggered by the change, not the calendar.
  • It sits on top of an existing obligation, FATF Recommendation 10's ongoing due diligence duty.
  • Sumsub reports 76% of fraud attempts occur after onboarding, the exact window periodic review leaves blind.
  • It is an operating model assembled from data feeds, screening, monitoring, and case management, not a single product you buy.
  • It orchestrates the verification vendors you already use rather than replacing them.

What is perpetual KYC?

Perpetual KYC, or pKYC, is a customer due diligence model that keeps every customer's identity and risk profile current in near real time through automated, event-driven monitoring. It is also known as continuous KYC, dynamic KYC, event-driven KYC, and continuous customer due diligence, and when applied to businesses it becomes perpetual KYB.

Moody's defines it as "the practice of maintaining up-to-date customer and counterparty records through an automated, integrated workflow of data checks that take place in near real-time". Fenergo frames it as a continuous customer due diligence approach that monitors and updates customer identity and risk information in near real time.

The contrast with the traditional approach is simple. Periodic review takes a photograph of the customer at onboarding, then re-takes it years later on a fixed schedule. Perpetual KYC maintains a live view instead: a change in ownership, a new sanctions listing, adverse media, or unusual activity triggers a targeted review the moment it happens.

Common misconception
pKYC is not periodic review run more often
Perpetual KYC just means running your periodic review batch quarterly instead of annually, so you catch changes sooner.
Running the same batch more frequently is still periodic review and still misses events between runs. pKYC is event-driven: the review is triggered by a detected change in the customer's risk, not by a date on the calendar. That is a different control, not a faster version of the old one.

Perpetual KYC vs periodic KYC review

Under traditional customer due diligence, a firm performs its checks at onboarding, then re-performs them on a risk-based schedule: high-risk customers reviewed annually, medium every three years, low every five. The weakness is structural. A periodic cycle leaves long gaps in which a customer's risk can change unnoticed, and it wastes analyst effort re-reviewing thousands of customers whose risk has not changed while potentially missing the one whose risk changed the day after their last review.

DimensionPeriodic KYC reviewPerpetual KYC
What starts a reviewA date on a fixed calendarA detected, material change in risk
CadenceAnnual, three-yearly, or five-yearlyContinuous, near real time
DataA snapshot re-taken periodicallyA live view fed by continuous signals
Analyst timeSpent re-reviewing unchanged customersSpent only on genuine, risk-changing events
Blind spotThe gap between scheduled reviewsNarrower: limited by trigger-data availability
Regulatory fitMeets the letter, criticised on effectivenessAligns with event-driven expectations
Periodic review vs perpetual KYC
The trigger is the detected change, not a date on the calendar.
Periodic review
Yr 1Yr 3Yr 5
A snapshot re-taken on a fixed calendar. Risk can change unnoticed in the gaps, and 76% of fraud attempts occur after onboarding.
Perpetual KYC
A live view fed by continuous signals. A material change triggers a review the moment it happens, not at the next sweep.
Event-driven, not a faster batch job
Signal
Sanctions, PEP, ownership, adverse media, behaviour
Trigger
Is the change material?
Recalculate
Auto-clear or route to a case
Case + audit
Re-verify, escalate, or offboard

Why event-driven is not just a faster batch job

The crucial word is event-driven. As Finextra's Victor Mendez puts it, perpetual KYC architecture is event-driven, not a faster batch job. pKYC does not schedule a full re-verification of every customer on a timer. Instead the firm continuously ingests risk signals and only opens a review when a material change is detected.

This matters because the mechanism is different, not just the frequency. A quarterly batch still processes everyone on a clock and still leaves everyone unwatched between runs. An event-driven model watches the signals that actually change risk and acts on them individually, so a customer sanctioned on a Tuesday is reviewed on Tuesday, not at the next quarterly sweep.

How perpetual KYC works: the five components

A working pKYC model has five moving parts. Zenoo's own ongoing-monitoring framework describes essentially the same anatomy as five layers: automated screening, behavioural analysis, corporate structure tracking, jurisdictional risk monitoring, and automated risk recalculation. You can read that operational framework in full in the continuous compliance framework. The components below explain the mechanism itself.

  1. 1A single, current customer or entity record. pKYC only works if customer data is unified and standardised so it can feed onboarding, screening, monitoring, case management, and reporting from one source rather than sitting in silos. For businesses, this includes the beneficial-ownership graph, not just the named account holder.
  2. 2Continuous risk-signal feeds. The system subscribes to the sources that can change a risk score: sanctions and watchlist updates, PEP status changes, adverse media, corporate-registry filings covering ownership, directors, and dissolution, jurisdiction risk changes, and transaction and behaviour signals. These arrive as a stream, not a nightly batch.
  3. 3Event triggers and rules. Defined triggers decide when a signal is material. A trigger fires when a customer appears on a new sanctions list, becomes a PEP, shows unusual transaction patterns, has an ownership change, or generates an adverse-media hit.
  4. 4Automated risk recalculation and routing. When a trigger fires, the customer's risk is recalculated. Low-confidence or immaterial changes are auto-cleared through straight-through processing, while genuinely risk-changing events are routed to a case for analyst review. What can be automated should be, so analysts spend time only on cases with real risk.
  5. 5Case management, remediation, and an audit trail. A material event opens a case with a workflow, such as re-verify a document, request updated ownership, escalate, or offboard, and records who did what and when, so the firm can evidence its decision to a supervisor.
Note
It is an operating model, not a single box

pKYC is assembled from data feeds, screening, monitoring, decisioning, and case management. Leading firms unify their data and wire event-driven triggers across all of these rather than buying one product. The bigger exposure is also after onboarding, not at it: Sumsub reports 76% of fraud attempts occur after the KYC process, during day-to-day activity, which is exactly the window periodic review leaves blind.

What the rules say: FATF, EU, UK, and US

Perpetual KYC sits on top of an obligation that already exists and is being tightened by every major regime. FATF Recommendation 10 sets the four core customer due diligence obligations: identify and verify the customer; identify and verify the beneficial owner; understand the purpose and intended nature of the relationship; and conduct ongoing due diligence on the relationship, scrutinising transactions and keeping records current. Most firms operationalise that last obligation as periodic reviews, but the duty itself is continuous.

In the EU, the 2024 AML package creates a single rulebook and a central authority, AMLA, which has been standing up in Frankfurt since mid-2025. The AML Regulation (Regulation (EU) 2024/1624) applies from 10 July 2027. AMLA guidance defines ongoing monitoring as keeping customer information up to date and continuously monitoring activity to detect unusual or suspicious activity as it arises, and introduces monitoring triggers even for low-risk customers. In 2026 AMLA opened a consultation on business-relationship monitoring guidelines.

In the UK, the FCA's April 2026 review of customer due diligence controls criticised firms that did not have enough detail on how often periodic reviews should take place and firms that failed to follow their own policies on when to conduct periodic reviews. It praised firms with documented, risk-tailored, independently tested controls. UK industry guidance from JMLSG, approved by HM Treasury, states that ongoing monitoring is not a once-a-year exercise.

In the US, FinCEN's CDD rule requires risk-based ongoing monitoring to identify and report suspicious activity and to update customer information on a risk basis. A February 2026 update clarified that firms verify beneficial ownership once and update it only when risk or new information warrants, rather than as a matter of course at every review. That is functionally an event-driven posture.

  • FATF Recommendation 10: the ongoing due diligence obligation that pKYC operationalises.
  • EU AML package (AMLR, 6AMLD, AMLA): AMLR applies from 10 July 2027, with AMLA guidance pushing continuous monitoring and low-risk triggers.
  • UK FCA April 2026 review and JMLSG: ongoing monitoring is not a once-a-year exercise, and event-driven review procedures must be followed.
  • US FinCEN CDD rule and February 2026 update: risk-based ongoing monitoring, with beneficial ownership verified once and updated on trigger.

Where perpetual KYC stands in 2025 to 2026

North America accounted for over 38% of the perpetual-KYC market in 2024, with banking, financial services, and insurance the leading adopters, according to market-research trackers. Mordor Intelligence projects the wider KYC market to grow from about USD 6.73bn in 2025 to roughly USD 16.31bn by 2031, a 15.88% compound annual growth rate over 2026 to 2031. These are vendor projections and should be read as forecasts rather than fact. Industry trackers describe pKYC as becoming the 2026 default operating model for customer due diligence.

The manual case that pKYC attacks is expensive. The average time to conduct a manual due-diligence check on a corporate customer is cited by ComplyAdvantage at 40.3 hours, and PwC estimated that a firm moving to pKYC could save 60% to 80%, about USD 14.4m a year for a medium-sized bank's corporate book and about USD 13.2m for its retail book. Fenergo reports that more than half of institutions spend 61 to 150 days on client KYC reviews at an average of USD 2,200 per review. Present these as the named provider's own figures, not as consensus.

Honest scope
How to read the numbers on this page

Market-size and saving figures come from named vendors and analysts such as Mordor Intelligence, PwC, ComplyAdvantage, Fenergo, and Moody's. We present each as an attributed range or forecast, never as an industry-wide certainty. Zenoo's own metrics are drawn only from its metrics registry and are clearly labelled as the platform's figures.

Benefits and the honest challenges

The benefits of moving to continuous due diligence are concrete: lower cost per customer over time, fewer false positives to work through, analyst effort concentrated on real risk, and a much faster response when a customer's risk actually changes. But the model is not free of friction, and the honest challenges below decide whether a programme succeeds.

  • Benefit: analyst time on real risk. Effort shifts away from re-reviewing unchanged customers and towards genuine, risk-changing events.
  • Benefit: faster risk response. A new sanctions listing or ownership change is picked up in near real time rather than at the next scheduled review.
  • Benefit: fewer false positives. AI-driven name matching and entity resolution suppress near-duplicate alerts so analysts see material change.
  • Challenge: jurisdictional mandates. Some jurisdictions still require periodic reviews, so many firms run a hybrid, event-driven where they can and a lighter periodic backstop where law requires it.
  • Challenge: data quality. pKYC exposes poor or siloed source data rather than fixing it. EY reports data quality is the top execution challenge for almost 65% of institutions.
  • Challenge: legacy systems. Feeding signals into triggers requires unified, connected data, which is hard where records sit in disconnected legacy tools.

How AI enables continuous monitoring

AI is what makes continuous, event-driven due diligence feasible at scale. Used defensively, it filters the noise so analysts see material changes rather than thousands of near-duplicate alerts, detects change automatically through behavioural analytics and continuous screening, automates the routine while drafting resolution notes and outreach, and improves detection of synthetic and manipulated identities that static onboarding checks miss.

Moody's reports that its AI review can cut false positives by up to 80%. Present any provider's reduction figure as that provider's own attributed claim, not an industry norm.

AI on the defender’s side
Where Zenoo's AI agents genuinely apply

Zenoo runs 10 specialised AI agents plus an automated pipeline. In a pKYC context the honest mapping is: alert-disposition triage pre-classifies up to 80% of screening alerts with high confidence, cutting per-alert disposition from 20 to 45 minutes down to 2 to 3 minutes. Model optimisation typically reduces false positives by 15% to 30%, and most teams see up to a 95% reduction within 90 days on the platform. When an event fires, automated re-research returns a KYB dossier in under 60 seconds and individual due diligence in under 45 seconds, versus 2 to 4 hours and 1 to 3 hours manually, and risk is recalculated in under 30 seconds. Zenoo cites per-alert investigation moving from an industry benchmark of 22 hours to 12 minutes; that is the platform's own figure, not an industry-wide pKYC claim.

How AI is weaponised against KYC controls

The same generative AI that powers detection is turned against the controls pKYC is meant to keep current. In January 2024 a finance worker at engineering firm Arup joined a video call with people he believed were the CFO and colleagues; all were AI-generated deepfakes. He made 15 transfers totalling about USD 25.6m (HKD 200m) in a single day. Arup's chief information officer described it as technology-enhanced social engineering: it did not go through the firewall, it went through a person.

The scale is rising. Sumsub's 2025 to 2026 data separates two figures that are often conflated: deepfakes made up about 7% of global fraudulent activity in 2025, and were the joint-largest of the top first-party fraud schemes at 11%. The 11% is a share among top first-party schemes only, not a share of all global fraud. Some markets saw extreme spikes, with US deepfake fraud up about 1,100% and the Maldives up about 2,100% year on year in Q1 2025. Synthetic-identity document fraud rose over 300% in the US, and synthetic identities appeared in about 21%, or one in five, of first-party frauds.

AI as the threat
A stale annual record is the ideal environment for deepfakes

pKYC is not a silver bullet against deepfakes or synthetic identities. But with 76% of fraud attempts occurring after onboarding, attackers pass the initial check and then abuse the dormant-review window that periodic KYC leaves open. Continuous, event-driven monitoring shortens the window in which a compromised or synthetic identity can operate undetected. The detection itself still comes from specialist vendors; the value of pKYC is watching the whole lifecycle, not just the front door.

What the future looks like

Industry outlooks for 2026 describe perpetual KYC as the emerging default operating model, with periodic review reframed as a backstop. Supervisors will increasingly ask why a firm is not event-driven. Writing for GARP, Ty Francis of LRN Corp. argues that regulatory escalation means AI-driven transaction monitoring, automated risk scoring, and real-time data analytics will be non-negotiable for firms to keep pace; the phrasing is his, not a direct regulator quotation.

From 10 July 2027 the EU AML Regulation harmonises customer due diligence across member states, with AMLA guidance pushing continuous monitoring and low-risk triggers, so firms will need pKYC-style capability to comply consistently. Agentic AI is expected to move from triage to action, progressing cases with full context and auditability under human oversight for material decisions. Perpetual KYB matures alongside pKYC, driven by graph-based data unification. And with deepfake and synthetic-identity fraud rising sharply and getting cheaper, tolerance for stale records keeps shrinking. Forecasts of adoption pace vary by source and should be attributed, not stated as fact.

How to move to perpetual KYC without replacing your vendors

You do not need to rip out your verification, screening, or data providers to adopt pKYC. The practical path is to unify your data, map the events that matter, wire your existing feeds into triggers, and put a clean audit trail around the result. The checklist below is a readiness sequence.

  1. 1Unify the customer record. Standardise data so onboarding, screening, monitoring, and case management read from one source, including the beneficial-ownership graph for entities.
  2. 2Map your triggers. Decide which signals are material: new sanctions listing, PEP status change, ownership change, adverse media, anomalous transactions, jurisdiction risk change.
  3. 3Wire the feeds. Connect your existing sanctions, PEP, adverse-media, registry, and identity providers as continuous streams rather than nightly batches.
  4. 4Set straight-through thresholds. Define what is auto-cleared and what is routed to an analyst, so continuous does not mean always drowning.
  5. 5Define escalation. Set the case workflow for a material event: re-verify, request updated ownership, escalate, or offboard.
  6. 6Evidence the audit trail. Record who did what, when, and why so a supervisor can test the control, and keep a lighter periodic backstop where a jurisdiction still mandates it.
Honest scope
Where Zenoo fits, and where it does not

Zenoo is an orchestration platform: your vendors plus Zenoo, never a replacement. It connects the providers you already use into one continuous, event-driven workflow with routing, failover, cost control, and a single audit trail. Its Marketplace offers 240+ check types at Enterprise tier and 50+ at Professional, so sanctions, PEP, adverse-media, registry, and identity signals feed one flow rather than 6 to 8 stitched-together tools. Its alert-disposition and model-optimisation agents cut the false positives that stall pKYC programmes, its KYB and risk agents re-run due diligence in seconds on a trigger, and it records 32 immutable audit event types across 8 categories with a 209-country risk database at 16 indicators each. What Zenoo does not do: it does not itself verify identities, screen names, supply sanctions or PEP data, detect deepfakes, or run biometric liveness; those come from your chosen vendors. It cannot fix poor or siloed source data, and it does not remove any legal obligation to run periodic reviews where a jurisdiction mandates them.

Key takeaways
  • Also called continuous, dynamic, or event-driven KYC, and extended to businesses as perpetual KYB.
  • It is event-driven, not a faster batch job: the review is triggered by the change, not the calendar.
  • It sits on top of an existing obligation, FATF Recommendation 10's ongoing due diligence duty.
  • Sumsub reports 76% of fraud attempts occur after onboarding, the exact window periodic review leaves blind.
  • It is an operating model assembled from data feeds, screening, monitoring, and case management, not a single product you buy.
  • It orchestrates the verification vendors you already use rather than replacing them.

Frequently asked questions

What is perpetual KYC (pKYC)?

Perpetual KYC is a customer due diligence model that keeps every customer's identity and risk profile current in near real time through automated, event-driven monitoring, rather than refreshing records on a fixed one, three, or five year cycle. A change such as a new sanctions listing or ownership change triggers a targeted review the moment it happens.

How is perpetual KYC different from periodic KYC review?

Periodic review re-checks customers on a fixed calendar and leaves gaps between reviews in which risk can change unnoticed. Perpetual KYC is event-driven: a review is triggered by a detected, material change in the customer's risk rather than by a date, so it catches change as it happens and concentrates analyst effort on customers whose risk has actually moved.

Is perpetual KYC the same as ongoing monitoring?

They overlap but are not identical. Ongoing due diligence is the underlying obligation, for example FATF Recommendation 10. Perpetual KYC is a specific way of delivering it: continuous, automated, event-driven monitoring across the whole customer lifecycle, rather than the periodic reviews many firms have historically used to satisfy the same obligation.

Do regulators require perpetual KYC?

No regime names pKYC as mandatory, but every major regime tightens the ongoing due diligence obligation it delivers. FATF Recommendation 10 requires ongoing due diligence, the EU AML Regulation applies from 10 July 2027 with AMLA guidance pushing continuous monitoring, the UK FCA and JMLSG say monitoring is not a once-a-year exercise, and the US FinCEN CDD rule requires risk-based ongoing monitoring.

What triggers a review under perpetual KYC?

A trigger fires when a signal is material: a customer appears on a new sanctions list, becomes a PEP, shows unusual transaction patterns, has an ownership or director change, is affected by a corporate-registry filing, faces a jurisdiction risk change, or generates an adverse-media hit. Immaterial changes are auto-cleared; genuine risk-changing events are routed to an analyst.

How much can perpetual KYC save compared with periodic reviews?

Figures come from named providers and should be read as their own estimates. ComplyAdvantage cites a manual corporate due-diligence check at 40.3 hours, and PwC estimated a firm moving to pKYC could save 60% to 80%, about USD 14.4m a year for a medium-sized bank's corporate book. Fenergo reports over half of institutions spend 61 to 150 days per review at USD 2,200 each.

Does perpetual KYC replace my existing KYC vendors?

No. pKYC is an operating model that orchestrates the verification, screening, and data vendors you already use into a continuous, event-driven workflow. An orchestration platform such as Zenoo connects those providers with routing, failover, and a single audit trail, but the identity verification, name screening, and sanctions or PEP data still come from your chosen vendors.
ZenooWhere this fits, honestly

Zenoo turns the vendors you already use into one continuous, event-driven workflow: routing, failover, automated re-research on a trigger, and one immutable audit trail. Your vendors plus Zenoo, never a replacement.

Sources

Last reviewed 18 June 2026. Every statistic is traceable to a named source.
  1. 01Fenergo, Perpetual KYC (pKYC) guide to ongoing due diligence
  2. 02FATF Recommendations (2012, updated), Recommendation 10
  3. 03FCA, Firms' customer due diligence processes and controls: our findings (April 2026)
  4. 04EUR-Lex, AML Regulation (EU) 2024/1624
  5. 05Sumsub Identity Fraud Report 2025 to 2026
  6. 06GARP, Always-On Compliance: Perpetual KYC
  7. 07ComplyAdvantage, What is perpetual KYC (pKYC)?
  8. 08Moody's, Perpetual KYC (pKYC) software solutions
  9. 09Finextra, Perpetual KYC architecture is event-driven, not a faster batch job
  10. 10Moody's, AI review cuts false positives by up to 80%
  11. 11FinCEN, CDD Rule FAQs and February 2026 update
  12. 12Mordor Intelligence, KYC Market Size and Trends Report 2031
  13. 13Sumsub, Synthetic identity document fraud surges 300% in the US
  14. 14CNN Business, Arup deepfake scam loss (May 2024)
  15. 15Zenoo, Ongoing monitoring: a continuous compliance framework
Was this helpful?
Share