the end of periodic reviews: reimagining KYC for an AI-first world


If risk can change overnight, should KYC reviews happen only once a year?

For decades, periodic reviews have been the foundation of customer due diligence programmes. Customer records are refreshed at predefined intervals, risk profiles are reassessed, and institutions work through established compliance cycles.

Today, customer risk can change between review cycles. Beneficial ownership structures may shift, sanctions and adverse media events can emerge unexpectedly, and compliance teams must interpret growing volumes of information while balancing regulatory expectations and operational efficiency.

According to Nasdaq's 2025 Financial Crime Management Technology report, 90% of financial professionals have observed an increase in AI-driven attacks, highlighting how rapidly risk conditions can evolve and reinforcing the need for customer due diligence programmes.

Financial institutions are therefore reconsidering whether calendar-driven reviews can keep pace with today's risk environment. As risk signals emerge faster and across more channels, customer due diligence must become more responsive and intelligence-led.

At Infosys BPM, our Financial Crime Compliance experts help financial institutions strengthen risk visibility and support timely responses through AI-powered customer due diligence.


Why KYC needs a new operating model

Traditional KYC programmes classify customers by risk and assign review frequencies accordingly. While this creates consistency, it also ties investigative activity to a timetable. Reviews may occur even when little has changed, while significant risk events may arise months before the next assessment.

As portfolios grow, considerable effort is spent reviewing customers whose risk profiles remain stable, while ownership changes, sanctions updates, or adverse media developments can emerge between review cycles. The challenge is identifying material changes quickly enough to act.

Addressing this challenge requires a more intelligent approach to identifying, prioritising, and assessing changing risk signals.


How AI is changing customer due diligence

AI-powered KYC supports a holistic assessment of customer risk. Machine learning and natural language processing can analyse structured and unstructured data, comparing new information with customer profiles to highlight changes that merit review.

Entity resolution plays an important role. AI can help identify relationships between customers, beneficial owners, directors, subsidiaries, and related entities across systems and jurisdictions, providing analysts with broader risk context.

AI can also support triage. Instead of treating every data change as equally important, models can help distinguish administrative updates from events with risk implications. Analysts can focus on validating material changes, documenting decisions, and escalating higher-risk cases.

Human oversight remains essential. Explainable outputs, governance controls, and auditable decision trails help ensure consistent, regulator-ready assessments while enabling faster decision-making on risks.

Regulatory expectations are evolving alongside these technological capabilities. FINRA's 2025 Regulatory Oversight Report identifies anti-money laundering, sanctions compliance, fraud prevention, cyber-enabled crime, and AI governance among its key priorities, underscoring the need for customer due diligence frameworks that combine AI-driven intelligence with strong governance, transparency, and human oversight.


From scheduled reviews to perpetual KYC

Perpetual KYC moves customer due diligence from calendar-led reviews to event-driven reassessment by triggering action when material changes affect a customer's risk profile.

For example, a change in beneficial ownership, a sanctions update, an adverse media event, or a shift in customer behaviour can trigger targeted reassessment, enabling a proportionate response instead of a blanket refresh.

This model requires more than continuous monitoring. Onboarding, customer due diligence, screening, transaction monitoring, and investigations need to exchange information through a connected intelligence ecosystem.

Insights generated at one stage should enrich the customer profile and aid in decision-making elsewhere, creating a clearer view of how risk evolves over time.

To advance this transition, FCC leaders should focus on three priorities:

  • Define material events and thresholds that trigger reassessment, review, or escalation.
  • Connect customer, ownership, screening, transaction, and external intelligence across the due diligence lifecycle.
  • Establish governance that keeps AI-supported decisions transparent, explainable, auditable, and subject to human oversight.

The future of KYC lies in aligning review activity with risk activity. Institutions that combine event-driven processes, connected data, governed AI, and specialist judgement can focus resources more effectively and respond earlier to emerging concerns.

Periodic reviews will continue where required, while perpetual KYC provides the continuous visibility needed for a more resilient, intelligence-led financial crime compliance framework.