Blog Login
KYC

What Is Perpetual KYC (pKYC)? A Guide for Fintechs

A

Anzar Dewani

21 hours ago

Perpetual KYC replaces periodic customer reviews with continuous, event-driven monitoring. This guide explains how pKYC works, how it differs from traditional KYC refresh cycles, and whether your fintech should adopt it.

What Is Perpetual KYC (pKYC)? A Guide for Fintechs

Traditional KYC works in snapshots: you verify a customer at onboarding, then review them again at fixed intervals — every one, two, or three years depending on their risk level. The problem is obvious: a customer's circumstances can change dramatically between reviews, and your compliance program won't know until the next scheduled check.

Perpetual KYC (pKYC) is the solution: instead of periodic reviews, it uses continuous, event-driven monitoring to keep customer profiles current in real time.

What Is Perpetual KYC (pKYC)?

Perpetual KYC is an approach to ongoing customer due diligence where customer profiles are updated continuously — triggered by specific events or data changes rather than by a fixed calendar schedule.

Instead of reviewing all customers in a given risk tier every 12 months, a pKYC system monitors for changes that matter — a news article, a sanctions list update, a change in transaction behavior, an adverse media hit — and triggers a review only when there's a signal that something has changed.

How pKYC Differs From Traditional KYC Refresh

 

Traditional KYC Refresh

Perpetual KYC (pKYC)

Review trigger

Calendar-based (e.g., annually)

Event-based (risk signal detected)

Coverage

All customers in a risk tier

Only customers with changed risk signals

Data currency

Information may be stale between reviews

Information kept current in near real-time

Efficiency

Resource-intensive for low-risk customers

Resources concentrated where risk is changing

Technology requirement

Lower

Higher — requires data integration

What Triggers a pKYC Review?

In a pKYC model, reviews are triggered by risk-relevant events:

  • Sanctions list changes: Customer name or associated entity appears on an updated sanctions list
  • Adverse media hits: A new news article links the customer to financial crime, regulatory action, or legal proceedings
  • PEP status change: Customer becomes — or ceases to be — a Politically Exposed Person
  • Transaction behavior change: A material deviation from the customer's expected transaction pattern triggers a profile update
  • Customer-provided information changes: The customer updates their address, business information, or other profile data
  • Ownership structure change: A business customer undergoes a change in ownership or beneficial ownership

The Technology Behind pKYC

pKYC requires more sophisticated infrastructure than periodic reviews:

  • Continuous data feeds: Real-time or near-real-time connections to sanctions lists, adverse media databases, and PEP registries
  • API integrations: Your core KYC platform must be able to receive triggers from external data sources and your transaction monitoring system
  • Automated workflow routing: When a trigger is detected, the system should automatically route the customer for review — with context about what changed
  • Case management: A structured workflow for analysts to review triggered cases and document decisions

Is pKYC Right for Your Fintech?

pKYC offers significant advantages in efficiency and risk coverage — but it requires investment. Consider adopting pKYC if:

  • Your customer base is large enough that periodic reviews create significant operational burden
  • Your product involves high-risk customer segments (PEPs, high-net-worth individuals, business accounts) where circumstances can change rapidly
  • You already have a mature CDD program and are looking to optimize it
  • Your regulator or sponsor bank has indicated that your periodic review program isn't keeping pace with risk

For smaller fintechs or those with lower-risk customer bases, a well-structured periodic review program using CDD and EDD tiers may be sufficient and more practical to implement.

Regulatory Perspective on pKYC

Regulators haven't mandated pKYC, but they have increasingly emphasized the need for ongoing, risk-sensitive customer due diligence — which is precisely what pKYC delivers. The FFIEC BSA/AML Examination Manual emphasizes that CDD should be ongoing, not just at onboarding. pKYC is the most advanced implementation of that expectation. It also positions well for bank sponsor due diligence audits and regulatory examinations. Your transaction monitoring program and your ongoing KYC program should work in concert.

Frequently Asked Questions

Does pKYC replace periodic reviews entirely?

In a mature pKYC model, event-based monitoring can reduce the need for scheduled periodic reviews significantly. However, many institutions run a hybrid model — pKYC for ongoing monitoring with a periodic backstop review to catch anything that wasn't triggered by an event.

How does pKYC interact with transaction monitoring?

They are complementary. Transaction monitoring flags suspicious behavior in payment flows. pKYC monitors customer identity and profile data for changes. Both feed into a unified risk picture.

Is pKYC available off-the-shelf?

A growing number of KYC platforms and regtech vendors offer pKYC capabilities. Evaluating these is part of your KYC provider selection process.

 

This article is for educational purposes only and does not constitute legal or compliance advice. Regulations vary by jurisdiction and change frequently. Consult a qualified compliance professional or legal counsel for guidance specific to your business.

 

Talk to the ComplyOne team to get started.

Share this article:

Related Articles