Every review in the queue has an owner
Start reviews by hand, on a recurring schedule for a batch, or through the API from the system that holds your due dates. An overdue high-risk file shows up as an overdue checklist, not an exam finding.
A KYC periodic review, or KYC refresh, brings an existing customer’s due diligence back up to date. This free checklist is for KYC and financial crime teams at banks, payment firms, brokers, wealth managers and fintechs. It covers scheduled refreshes by risk tier and out-of-cycle reviews prompted by a trigger event, and shows only the steps each review needs. High-risk and PEP files get enhanced due diligence and senior management approval. Customers who ignore the outreach follow a defined restriction and exit path. The reviewer signs off, a second person checks the file, and the next review date is set before the checklist closes.
Onboarding due diligence starts from nothing: you identify and verify a new customer before the relationship begins. Our Customer Due Diligence Checklist covers that. A periodic review starts from a file that may be five years old. You collate what you hold, ask the customer only for what has changed or expired, and test whether the relationship still looks as it did at onboarding.
No major regime treats CDD as a one-off. US rules require risk-based updating of customer information, including beneficial ownership, under what is often called the “fifth pillar”. The UK’s Money Laundering Regulations 2017 require CDD for existing customers at appropriate times and when circumstances change. Only the EU sets a number: from 10 July 2027 its Anti-Money Laundering Regulation caps the gap between updates.
Starts from: no file.
Work: identify, verify, assess purpose, set the first risk rating.
Output: an approved or declined customer.
Starts from: the existing file and last review.
Work: update what changed, re-screen, compare activity, re-rate.
Output: a confirmed rating and the next due date.
Starts from: an ownership change, screening hit, adverse media or unusual activity.
Work: assess the event first, then refresh what it affects.
Output: a re-rated customer, a referral or an exit.
Four phases run on every review. Three switch on only when the answers in earlier phases call for them: trigger events, non-response and enhanced due diligence.
Assigned to the KYC analyst who owns the file. The answers recorded here decide which later phases appear.
Shown only when the review type is Trigger event. Scheduled reviews go straight to Phase 3.
Shown only when the customer did not respond. Restrictions and exits follow the firm’s own non-response policy.
Shown when the customer is High risk or a PEP going into the review, or is re-rated High in Phase 5.
The reviewer signs first. A different person completes the QA check, and a returned file goes back to the reviewer.
Most firms set review cycles by risk tier. The cycles below are common industry practice, not law: US and UK rules set no fixed interval and leave the timing to your risk assessment.
| Risk tier | Typical cycle in practice | What the review includes | Who approves |
|---|---|---|---|
| High, including PEPs | Every year | Full refresh, re-screening, activity review, EDD with source of wealth and funds | Senior management, to continue; plus QA |
| Medium | Every 2–3 years | Update of changed information, re-screening, activity review | Reviewer, plus QA |
| Low | Every 3–5 years | Confirmation of key details, re-screening | Reviewer; QA by sample |
| Any tier, trigger event | Within the deadline your policy sets | The information the event affects, or a full refresh if the risk has changed | As for the resulting tier |
The second table maps each part of the review to its main source. Your obligations depend on your firm type and regulator, so treat the table as a starting point, not legal advice.
| Requirement | United States | United Kingdom | EU from 10 July 2027 | Phase |
|---|---|---|---|---|
| Keep customer information up to date | Risk-based ongoing CDD, e.g. 31 CFR 1020.210(a)(2)(v)(B) for banks | MLR 2017 reg. 28(11) | AMLR Art. 26(1)–(2) | 3, 5 |
| Fixed refresh interval | None; FinCEN’s 2020 CDD FAQs call updating risk-based | None; existing customers “at other appropriate times”, reg. 27(8) | At most 1 year for EDD customers, 5 years for others, Art. 26(2) | 7 |
| Review when circumstances change | Update when monitoring reveals a relevant change | Reg. 27(8)(b) and (9) | Art. 26(3) | 1–2 |
| Beneficial ownership | 31 CFR 1010.230; since February 2026, re-identify when reliability is in doubt or risk requires it (FIN-2026-R001) | Reg. 28(4) | Art. 20(1)(b) | 3 |
| Sanctions re-screening | Risk-based, per OFAC’s 2019 compliance framework | Risk-based; frequency set by the firm | Regular checks, and on every new designation for financial institutions, Art. 26(4) | 5 |
| Enhanced due diligence | Risk-based; enhanced scrutiny for senior foreign political figures in private banking, 31 CFR 1010.620(c) | Reg. 33 | Art. 34 | 6 |
| PEP: senior management approval to continue | No general PEP rule; risk-based per the agencies’ August 2020 joint statement | Reg. 35(5) | Art. 42(1) | 6 |
| CDD cannot be completed | Firm’s own procedures | End the relationship and consider a disclosure, reg. 31 | End the relationship and consider a report, Art. 21 | 4 |
Some of this is moving. FinCEN’s April 2026 proposal would place ongoing CDD under the internal controls pillar without, FinCEN says, changing its substance; at the time of writing it is a proposal, not a final rule. AMLA consulted until September 2026 on guidelines on ongoing monitoring and had not issued final guidelines when this page was last reviewed. Until the AMLR applies, EU firms follow national law implementing Directive (EU) 2015/849, which requires CDD for existing customers at appropriate times on a risk-sensitive basis. In the UK, amendments in force from 30 June 2026 (S.I. 2026/621) changed the country trigger for EDD in reg. 33 to FATF “call for action” countries.
Start reviews by hand, on a recurring schedule for a batch, or through the API from the system that holds your due dates. An overdue high-risk file shows up as an overdue checklist, not an exam finding.
Conditional logic reads the review type, the risk rating and the outreach answer. A low-risk refresh stays short; a PEP with new adverse media gets the trigger assessment, EDD and approval automatically.
Senior management approval and the four-eyes QA check are assigned to named people, and each records Approved or Returned. Screening results and source of wealth evidence sit on the task they support, and the trail exports with timestamps.
CheckFlow is not a KYC platform, screening tool or case manager, and it does not replace them. It runs the review workflow around them: who does each step, what was decided and who approved it. Our guide to financial services workflow automation explains where periodic reviews sit next to perpetual KYC, and the financial services overview shows other workflows run the same way.
New customers go through the Customer Due Diligence Checklist at onboarding and then join the refresh queue. Overdue periodic reviews are one of the numbers the MLRO checks in the AML Compliance Programme Review Checklist, and CheckFlow’s compliance checklist software covers the wider compliance calendar.
It is a scheduled check that an existing customer’s due diligence is still accurate and the risk rating still fits. The reviewer updates changed information, re-screens the customer and its owners, compares activity with what was expected, applies enhanced due diligence where the risk is high, and records a decision and the next review date. It is also called a KYC refresh.
It depends on the risk and the jurisdiction. US and UK rules set no fixed interval: FinCEN’s guidance says updating is risk-based and prompted by monitoring, and the UK regulations require reviews at appropriate times on a risk basis. Many firms review high-risk customers yearly, medium-risk every two to three years and low-risk every three to five. From 10 July 2027 the EU AMLR sets a ceiling: at least every year for customers under enhanced due diligence and at least every five years for everyone else.
Common triggers are a change in ownership or control, a sanctions or PEP screening hit, credible adverse media, activity that does not match the customer’s profile, a dormant account becoming active and a material change in the business. The UK regulations name changes of identity or beneficial owner, inconsistent transactions and a changed purpose as factors; the EU AMLR requires an update whenever relevant circumstances change. Where a trigger suggests suspicion, refer it internally before contacting the customer.
Most firms send reminders, then restrict the account under a written non-response policy, then exit. In the UK, regulation 31 of the MLRs requires a firm that cannot apply CDD to end the relationship and consider a disclosure; the EU AMLR has an equivalent rule in Article 21. US rules leave it to the firm’s own procedures. Record each step and who approved it.
Perpetual KYC uses data feeds, such as registry changes and screening alerts, to trigger reviews when something changes rather than on a date. It can shorten the queue, but someone still assesses the change, updates the file and signs off. EU firms should note that the AMLR’s maximum intervals apply from July 2027 whether or not a trigger fires.
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.