KYC Periodic Review Checklist Template

Onboarding gets the attention, but a customer file spends most of its life between reviews. When the refresh queue slips, high-risk files go stale quietly until an examiner pulls a sample.

A KYC periodic review, or KYC refresh, brings an existing customer’s due diligence back up to date. This free checklist is for KYC and financial crime teams at banks, payment firms, brokers, wealth managers and fintechs. It covers scheduled refreshes by risk tier and out-of-cycle reviews prompted by a trigger event, and shows only the steps each review needs. High-risk and PEP files get enhanced due diligence and senior management approval. Customers who ignore the outreach follow a defined restriction and exit path. The reviewer signs off, a second person checks the file, and the next review date is set before the checklist closes.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: September 2026

Onboarding, Scheduled Refresh and Trigger Review: Three Different Jobs

Onboarding due diligence starts from nothing: you identify and verify a new customer before the relationship begins. Our Customer Due Diligence Checklist covers that. A periodic review starts from a file that may be five years old. You collate what you hold, ask the customer only for what has changed or expired, and test whether the relationship still looks as it did at onboarding.

No major regime treats CDD as a one-off. US rules require risk-based updating of customer information, including beneficial ownership, under what is often called the “fifth pillar”. The UK’s Money Laundering Regulations 2017 require CDD for existing customers at appropriate times and when circumstances change. Only the EU sets a number: from 10 July 2027 its Anti-Money Laundering Regulation caps the gap between updates.

Onboarding CDD

Before the relationship starts

Starts from: no file.

Work: identify, verify, assess purpose, set the first risk rating.

Output: an approved or declined customer.

Scheduled refresh

Due by risk tier

Starts from: the existing file and last review.

Work: update what changed, re-screen, compare activity, re-rate.

Output: a confirmed rating and the next due date.

Trigger-event review

Opened out of cycle

Starts from: an ownership change, screening hit, adverse media or unusual activity.

Work: assess the event first, then refresh what it affects.

Output: a re-rated customer, a referral or an exit.

What the KYC Periodic Review Checklist Covers

Four phases run on every review. Three switch on only when the answers in earlier phases call for them: trigger events, non-response and enhanced due diligence.

Phase 1

Phase 1: Open the Review

Assigned to the KYC analyst who owns the file. The answers recorded here decide which later phases appear.

  • Open the review from the refresh queue — record the customer reference, the due date and how many days overdue the review is
  • Record the review type — a scheduled refresh from the risk-tier cycle, or a trigger-event review opened out of cycle
  • Record the customer risk rating and PEP status going into the review — High, Medium or Low, and whether anyone on the file is a PEP or PEP associate
  • Pull the current KYC file and the last review — documents, expiry dates, the last rating rationale and any conditions
  • Name the reviewer, QA checker and approver — the QA checker must not be the reviewer
Phase 2 — Trigger Events Only

Phase 2: Trigger-Event Assessment

Shown only when the review type is Trigger event. Scheduled reviews go straight to Phase 3.

  • Record what triggered the review and when it was identified — ownership or control change, adverse media, a sanctions or PEP hit, unusual activity, a dormant account reactivating or a material change in the business
  • Assess whether the trigger changes the risk profile — note what the event tells you that the file did not
  • Refer to the MLRO or BSA officer if the trigger suggests suspicion — before any customer contact, so outreach cannot tip the customer off
  • Set the scope and deadline of the review — a targeted update of the affected information, or a full refresh
Phase 3

Phase 3: Outreach & Information Refresh

  • Check what the file already holds before contacting the customer — verified identity need not be re-verified unless there are doubts or a change
  • Send the outreach request with a response deadline — ask only for what is missing, expired or out of date
  • Record whether the customer responded — attach what was received; a No opens the non-response phase
  • Refresh identity, address and occupation or business details — check document expiry and any change of name or residence
  • Confirm beneficial owners and control persons against the last review — record changes and verify any new owner
  • Update the purpose and expected activity of the relationship — products, volumes, geographies and counterparties
Phase 4 — No Response Only

Phase 4: Non-Response, Restriction & Exit

Shown only when the customer did not respond. Restrictions and exits follow the firm’s own non-response policy.

  • Send a final reminder and record the escalation date — by a second channel where possible
  • Apply restrictions in line with the non-response policy — for example no new products or limits on outgoing payments
  • Consider whether the non-response is itself suspicious — refer to the MLRO or BSA officer where it is
  • Recommend exit where due diligence cannot be completed — UK and EU rules require the relationship to end; in the US the firm’s procedures set the exit criteria
Phase 5

Phase 5: Re-Screen & Reassess Risk

  • Re-screen the customer, beneficial owners and connected parties for sanctions — against every list the firm applies, with each potential match dispositioned
  • Re-screen for PEP status and adverse media — a new PEP or credible adverse finding changes the rest of the review
  • Compare expected activity with actual activity since the last review — explain material differences or refer them
  • Check alerts and internal referrals since the last review — never disclose open cases to the customer
  • Reassess and record the customer risk rating — with a written rationale; a rating raised to High switches on Phase 6
Phase 6 — High Risk & PEP Only

Phase 6: Enhanced Due Diligence

Shown when the customer is High risk or a PEP going into the review, or is re-rated High in Phase 5.

  • Refresh source of wealth and source of funds evidence — corroborate it rather than relying on the customer’s word alone
  • Review transactions in more depth for the period — look for patterns the monitoring rules would not flag
  • Record the EDD findings and the residual risk — and why the relationship is or is not acceptable
  • Obtain senior management approval to continue the relationship — required for PEPs in the UK and EU, and firm policy for other high-risk customers
  • Set enhanced monitoring measures until the next review — tighter thresholds, interim reviews or limits
Phase 7

Phase 7: Decision, Sign-Off & QA

The reviewer signs first. A different person completes the QA check, and a returned file goes back to the reviewer.

  • Record the review outcome — retain, retain with conditions, restrict or exit
  • Set the next review date from the new risk rating — so the customer re-enters the queue on the right cycle
  • Update the customer record and monitoring profile — in the core, screening and monitoring systems
  • Reviewer sign-off — the file is complete and the rationale recorded
  • Four-eyes QA check of the review — a second person checks the evidence and the rating decision
  • Log QA findings for the monthly MI pack — overdue reviews and QA failures feed the AML programme review

Refresh Cycles and the Rules Behind Them

Most firms set review cycles by risk tier. The cycles below are common industry practice, not law: US and UK rules set no fixed interval and leave the timing to your risk assessment.

Risk tier Typical cycle in practice What the review includes Who approves
High, including PEPsEvery yearFull refresh, re-screening, activity review, EDD with source of wealth and fundsSenior management, to continue; plus QA
MediumEvery 2–3 yearsUpdate of changed information, re-screening, activity reviewReviewer, plus QA
LowEvery 3–5 yearsConfirmation of key details, re-screeningReviewer; QA by sample
Any tier, trigger eventWithin the deadline your policy setsThe information the event affects, or a full refresh if the risk has changedAs for the resulting tier

The second table maps each part of the review to its main source. Your obligations depend on your firm type and regulator, so treat the table as a starting point, not legal advice.

Requirement United States United Kingdom EU from 10 July 2027 Phase
Keep customer information up to dateRisk-based ongoing CDD, e.g. 31 CFR 1020.210(a)(2)(v)(B) for banksMLR 2017 reg. 28(11)AMLR Art. 26(1)–(2)3, 5
Fixed refresh intervalNone; FinCEN’s 2020 CDD FAQs call updating risk-basedNone; existing customers “at other appropriate times”, reg. 27(8)At most 1 year for EDD customers, 5 years for others, Art. 26(2)7
Review when circumstances changeUpdate when monitoring reveals a relevant changeReg. 27(8)(b) and (9)Art. 26(3)1–2
Beneficial ownership31 CFR 1010.230; since February 2026, re-identify when reliability is in doubt or risk requires it (FIN-2026-R001)Reg. 28(4)Art. 20(1)(b)3
Sanctions re-screeningRisk-based, per OFAC’s 2019 compliance frameworkRisk-based; frequency set by the firmRegular checks, and on every new designation for financial institutions, Art. 26(4)5
Enhanced due diligenceRisk-based; enhanced scrutiny for senior foreign political figures in private banking, 31 CFR 1010.620(c)Reg. 33Art. 346
PEP: senior management approval to continueNo general PEP rule; risk-based per the agencies’ August 2020 joint statementReg. 35(5)Art. 42(1)6
CDD cannot be completedFirm’s own proceduresEnd the relationship and consider a disclosure, reg. 31End the relationship and consider a report, Art. 214

Some of this is moving. FinCEN’s April 2026 proposal would place ongoing CDD under the internal controls pillar without, FinCEN says, changing its substance; at the time of writing it is a proposal, not a final rule. AMLA consulted until September 2026 on guidelines on ongoing monitoring and had not issued final guidelines when this page was last reviewed. Until the AMLR applies, EU firms follow national law implementing Directive (EU) 2015/849, which requires CDD for existing customers at appropriate times on a risk-sensitive basis. In the UK, amendments in force from 30 June 2026 (S.I. 2026/621) changed the country trigger for EDD in reg. 33 to FATF “call for action” countries.

Why Run KYC Periodic Reviews in CheckFlow?

1

Every review in the queue has an owner

Start reviews by hand, on a recurring schedule for a batch, or through the API from the system that holds your due dates. An overdue high-risk file shows up as an overdue checklist, not an exam finding.

2

Only the steps that apply

Conditional logic reads the review type, the risk rating and the outreach answer. A low-risk refresh stays short; a PEP with new adverse media gets the trigger assessment, EDD and approval automatically.

3

Approvals and QA you can show an examiner

Senior management approval and the four-eyes QA check are assigned to named people, and each records Approved or Returned. Screening results and source of wealth evidence sit on the task they support, and the trail exports with timestamps.

CheckFlow is not a KYC platform, screening tool or case manager, and it does not replace them. It runs the review workflow around them: who does each step, what was decided and who approved it. Our guide to financial services workflow automation explains where periodic reviews sit next to perpetual KYC, and the financial services overview shows other workflows run the same way.

New customers go through the Customer Due Diligence Checklist at onboarding and then join the refresh queue. Overdue periodic reviews are one of the numbers the MLRO checks in the AML Compliance Programme Review Checklist, and CheckFlow’s compliance checklist software covers the wider compliance calendar.

Frequently Asked Questions

What is a KYC periodic review?

+

It is a scheduled check that an existing customer’s due diligence is still accurate and the risk rating still fits. The reviewer updates changed information, re-screens the customer and its owners, compares activity with what was expected, applies enhanced due diligence where the risk is high, and records a decision and the next review date. It is also called a KYC refresh.

How often should KYC be refreshed?

+

It depends on the risk and the jurisdiction. US and UK rules set no fixed interval: FinCEN’s guidance says updating is risk-based and prompted by monitoring, and the UK regulations require reviews at appropriate times on a risk basis. Many firms review high-risk customers yearly, medium-risk every two to three years and low-risk every three to five. From 10 July 2027 the EU AMLR sets a ceiling: at least every year for customers under enhanced due diligence and at least every five years for everyone else.

What events should trigger an out-of-cycle KYC review?

+

Common triggers are a change in ownership or control, a sanctions or PEP screening hit, credible adverse media, activity that does not match the customer’s profile, a dormant account becoming active and a material change in the business. The UK regulations name changes of identity or beneficial owner, inconsistent transactions and a changed purpose as factors; the EU AMLR requires an update whenever relevant circumstances change. Where a trigger suggests suspicion, refer it internally before contacting the customer.

What happens if a customer does not respond to a KYC refresh request?

+

Most firms send reminders, then restrict the account under a written non-response policy, then exit. In the UK, regulation 31 of the MLRs requires a firm that cannot apply CDD to end the relationship and consider a disclosure; the EU AMLR has an equivalent rule in Article 21. US rules leave it to the firm’s own procedures. Record each step and who approved it.

Does perpetual KYC replace periodic reviews?

+

Perpetual KYC uses data feeds, such as registry changes and screening alerts, to trigger reviews when something changes rather than on a date. It can shorten the queue, but someone still assesses the change, updates the file and signs off. EU firms should note that the AMLR’s maximum intervals apply from July 2027 whether or not a trigger fires.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Clear the Refresh Queue Before the Examiner Samples It

Free trial — no credit card required.