Industry Intel - Conference Recaps and Thought Leadership Article

Vital4 KYC Is a Signal Not a Snapshot

The periodic customer review is in supervised retreat. In 2026, continuous, event-driven KYC has become the default — and the calendar-driven refresh now reads as a control weakness rather than a control.

A review is a photograph. Risk is a live feed.

For two decades, customer due diligence ran on a calendar. You onboarded a customer, assigned a risk rating, and scheduled the next look — a year out for higher risk, three or five years out for everyone else. In between, the file simply sat. A customer onboarded cleanly in 2023 might not be looked at again until 2026, no matter what changed in the meantime.

The flaw in that model is not subtle. A periodic review is a photograph, and it starts going stale the moment it is taken. Risk is not a photograph. It is a live feed — a director changes, ownership shifts, a name appears on a new sanctions list, transaction behavior diverges from the stated purpose of the account. In a calendar-driven model, none of that is visible until the next scheduled review, which may be years away.

The periodic review answers a question no one is really asking: what was true about this customer at some point in the past.

The calendar is now the control weakness

Three pressures have converged to end the periodic model’s reign. The cost of running periodic reviews has climbed relentlessly alongside customer volumes. The quality of the resulting data has been openly questioned by regulators and financial-intelligence units. And the gap between “what we knew at last review” and “what is true today” has been exploited often enough that the periodic refresh now reads as a control weakness rather than a control.

The supervisory direction reflects it. The UK FCA’s 2026 review of customer due diligence flagged unclear review procedures and firms failing to follow their own policies. The EU’s incoming AML framework pairs event-driven updates with hard backstops. And in the United States, the move toward effectiveness-based supervision rewards programs that keep customer risk current — not ones that simply file a refreshed form on schedule. The 2026 question is no longer whether to move to perpetual KYC. It is how to sequence the migration and how to demonstrate it to a supervisor.

Event-driven, with a backstop

Perpetual KYC is often described as “continuous,” which makes it sound like you re-verify everyone constantly. That is not what it means, and misunderstanding it is how implementations fail. Perpetual KYC is an operating model in which a defined set of trigger events — not a calendar — determines when a customer’s due diligence is reassessed. Event-driven review is the mechanism; perpetual KYC is the model around it.

The triggers come from two directions. Internal signals: a change in directors or beneficial ownership, a document reaching expiry, transaction activity that departs from the expected profile. External signals: a new sanctions designation, a PEP status change, an adverse-media hit on the customer or a party connected to them. When a material trigger fires, a review happens then — not eighteen months later.

And it does not mean abandoning periodic review entirely. The mature model is event-driven first, with a risk-based periodic backstop for higher-risk relationships — exactly the structure the EU is codifying. The calendar stops being the primary control and becomes the safety net.

 

It is a data problem before it is a workflow problem

Here is what a decade of these programs has taught: perpetual KYC succeeds or fails at the data layer, not the workflow layer. A trigger framework is only as good as the signal feeding it. If your sanctions, PEP, and adverse-media data is stale, batch-updated, or noisy, then “event-driven” simply means you react late and often to the wrong things. Continuous monitoring built on intermittent data is not continuous at all.

Three data capabilities separate a real perpetual-KYC program from a rebranded periodic one:

  1. Always-on external signal. Sanctions, PEP, and adverse-media changes have to reach you as they happen, not in a monthly batch. The value of an event-driven model collapses if the events arrive late.
  2. Entity resolution that connects the change to the customer. A new designation on the other side of the world is only a trigger if you can reliably connect it to the customer — or the beneficial owner — sitting in your book. Resolving the world’s changes to your customers is the hard part.
  3. A documented trail of why each review fired. Under an effectiveness standard, you must be able to show a supervisor why a review occurred, what was assessed, and what decision closed it. That record has to be built as it happens, not reconstructed later.

Sequencing the migration

No institution flips from periodic to perpetual overnight, and regulators do not expect a big bang. What they expect is a defensible sequence:

  1. Define your triggers before your technology. Decide which internal and external events genuinely change a customer’s risk. A trigger framework that fires on everything is just noise with a new name.
  2. Wire in real-time data first. The signal layer is the foundation. Connect always-on sanctions, PEP, and adverse-media monitoring before you rebuild the case workflow around it.
  3. Keep a risk-based periodic backstop. Retain scheduled reviews for your highest-risk relationships as a safety net, and let event-driven monitoring carry the rest.
  4. Instrument the whole loop. Capture why each review fired, what was assessed, and how it closed — so the program can be demonstrated, not just described.

Continuous monitoring needs continuous data

Every part of perpetual KYC traces back to the same requirement: current, source-verified data, resolved to the right customer, delivered as things change. That is the layer that turns an event-driven ambition into an event-driven reality — and it is the layer that takes the longest to build well.

VITAL4

See How Vital4 Powers Event-Driven KYC

REQUEST A DEMO