What's Happening?
Perpetual Know Your Customer (pKYC) is gaining traction as an operational framework for continuous customer due diligence (CDD), shifting from periodic reviews to risk-event-driven reassessments. While 'perpetual KYC' is an industry term and not a specific
regulatory mandate, it serves to operationalize ongoing CDD obligations as required by the Financial Action Task Force (FATF) Recommendation 10 and Regulation 28(11) of the UK Money Laundering Regulations 2017. These regulations require CDD to be ongoing, up-to-date, and proportionate to risk. Unlike traditional models that trigger reviews on fixed schedules, pKYC initiates reassessment only when material changes or trigger events occur, such as sanctions exposure, changes in beneficial ownership, or adverse media. Effective pKYC relies heavily on accurate and verified identity data established at onboarding, as poor data quality can undermine the entire model.
Why It's Important?
The adoption of pKYC is highly significant for the U.S. financial industry, as it represents a proactive approach to combating financial crime, including money laundering and terrorist financing. Traditional periodic KYC reviews can leave gaps, allowing illicit activities to go undetected between review cycles. pKYC, by continuously monitoring for material changes, offers a more dynamic and effective way to identify and mitigate risks in real-time. This enhanced vigilance is crucial for U.S. financial institutions to comply with stringent regulations from FinCEN and other bodies, reducing their exposure to legal and reputational risks. Furthermore, by focusing on data-driven reassessments, pKYC can lead to more efficient allocation of compliance resources, moving away from blanket reviews to targeted interventions. This can improve the overall integrity of the U.S. financial system, making it harder for criminals to exploit vulnerabilities and fostering greater trust among stakeholders.
What's Next?
Financial institutions in the U.S. and globally are expected to increasingly explore and implement pKYC models to meet their ongoing CDD obligations. This will involve significant investment in technology, particularly in areas like identity verification, data analytics, and automated monitoring systems. Firms will need to define clear trigger events that initiate reassessment and develop proportionate responses based on the nature of the change and their risk policies. The EU AMLR Article 26, effective July 10, 2027, which introduces maximum update intervals for client information, will further drive the adoption of continuous monitoring approaches like pKYC. The focus will be on establishing a verified identity baseline at onboarding, implementing robust trigger event detection, and ensuring proportionate responses. The industry will likely see continued innovation in identity verification technologies and data orchestration platforms to support the seamless operation of pKYC frameworks.
Beyond the Headlines
The shift towards pKYC signifies a deeper evolution in the philosophy of financial crime prevention, moving from a static, snapshot-based approach to a dynamic, continuous one. This change is not merely technological but also cultural, requiring financial institutions to rethink their workflows, data management, and risk assessment strategies. The reliance on accurate, verified identity data at onboarding underscores the foundational importance of digital identity infrastructure in the modern financial ecosystem. The ethical implications revolve around balancing privacy concerns with the need for continuous surveillance to prevent illicit activities. As pKYC models become more sophisticated, questions may arise about the extent of data collection and monitoring, and how to ensure that such systems are used responsibly and without bias. The long-term impact could be a more resilient and secure financial system, but one that also demands a higher degree of transparency and data integrity from all participants.













