Customer onboarding is only the starting point of KYC compliance. Identity details, ownership structures, and transaction behaviour evolve over time, which makes re-KYC and periodic KYC review essential for maintaining accurate risk profiles. Without continuous updates, even well-verified customers can drift into higher-risk categories without detection.
Financial crime exposure increases when customer data becomes outdated. According to industry estimates, over 30 percent of compliance alerts are linked to stale or incomplete KYC records, showing how quickly risk signals degrade when ongoing monitoring is not supported by refreshed information.
A structured re-KYC process ensures that changes in occupation, jurisdiction, or beneficial ownership are captured before they impact AML screening accuracy. In many organisations, this is also referred to as a kyc refresh or kyc renewal process, depending on internal compliance terminology.
In this guide, we explain how re-KYC and periodic KYC reviews work, when they are required, and how event-driven updates help keep customer risk assessments accurate and aligned with real-world customer activity.
Binderr Re-KYC and Periodic KYC Review Software
The best re-KYC software should go beyond expiry reminders and unify verification, AML screening, risk reassessment and ongoing monitoring in one workflow.
Binderr is a unified platform for scheduled and event-driven KYC reviews, helping businesses keep customer data accurate in one place.
- Global identity verification: Verify passports, national identity cards and driving licences across 230+ countries and more than 11,000 document and ID types.
- Biometric verification: Use face matching and liveness detection to confirm that the person completing re-KYC matches the identity document.
- Fraud and deepfake detection: Identify manipulated documents, synthetic media and suspicious identity signals during customer re-verification.
- Business verification: Retrieve registry information, company status, directors, shareholders and corporate details across 200+ countries and 30,000+ data sources.
- UBO identification: Identify and verify the natural persons who ultimately own or control a business.
- AML rescreening: Screen customers, companies, directors and UBOs against sanctions, PEP, watchlist and adverse media sources.
What Is Re-KYC?
Re-KYC is the ongoing process of updating a customer’s KYC information, AML screening results, and risk profile during a business relationship to keep records accurate and compliant. It includes updating personal or business details, refreshing documents, re-verifying identity where needed, checking beneficial ownership, and re-screening against sanctions, PEP, and adverse media lists. This kyc refresh stage ensures that customer data remains current and reliable for ongoing monitoring.
It also involves reassessing risk, reviewing source of funds or wealth when required, and deciding whether standard CDD or EDD is needed. The outcome and next review date must be documented. Re-KYC is a targeted update, not a full repeat of onboarding, although in some cases it may resemble a full kyc renewal when significant changes are identified.
Run Your KYC Checks with Binderr
Why Are Periodic KYC Reviews Important?
Periodic KYC reviews are the backbone of effective re-KYC, ensuring customer information, risk profiles, and compliance records stay accurate over time. These periodic kyc review cycles support ongoing due diligence, strengthen KYC review frequency controls, and help detect changes in customer risk before they become regulatory issues.
In practice, they also function as a structured kyc refresh mechanism that keeps records aligned with real-world activity.
Keep Customer Information Accurate
Re-KYC keeps customer data up to date. Key details such as name, address, nationality, job, employer, contact information, and ID documents can change over time. For businesses, this also includes company details, directors, shareholders, beneficial owners, and services used. Keeping records current supports accurate KYC compliance and reduces risk from outdated information. This continuous updating process is often referred to as kyc renewal in operational workflows.
Identify Changes in Customer Risk
Customer risk can change during the relationship, making periodic KYC reviews essential. Risk may increase due to PEP status, sanctions exposure, adverse media, or regulatory issues. Other triggers include high-risk jurisdictions, business or ownership changes, unusual transactions, new products, or changes in source of funds or wealth. Identifying these changes keeps the risk profile accurate and ensures the re-kyc process reflects the customer’s current risk level.
Support Effective Ongoing Monitoring
Accurate customer data improves transaction monitoring. Expected activity, business purpose, occupation, and source-of-funds information help assess behaviour. If this data is outdated, alerts become harder to interpret and false positives increase. FATF guidance also emphasises the need to continuously monitor transactions to ensure they align with the customer’s known profile and risk level. Regular kyc refresh cycles ensure monitoring systems remain effective and reliable.
Maintain Defensible Compliance Records
Clear records are essential for proving a proper re-KYC review. Documentation should include updated information, evidence collected, screening results, and key risk factors. It should also capture any risk rating changes, EDD actions, and approval or escalation decisions. Including the reviewer name, completion date, and next review date ensures a complete audit trail for compliance. These records also demonstrate that periodic kyc review obligations and any kyc renewal actions have been properly completed.
When Is Re-KYC Required?
Re-KYC is required whenever a customer’s information, behaviour, or risk profile may no longer reflect their current relationship with your business. It ensures your KYC records stay accurate, compliant, and aligned with ongoing AML obligations.
Scheduled Periodic Reviews
Businesses typically set periodic KYC review intervals based on a customer’s overall risk profile, product usage, jurisdiction, and transaction behaviour, ensuring that higher-risk relationships are reviewed more frequently than low-risk ones. These KYC periodic reviews are also shaped by internal policies and regulatory expectations, helping firms maintain up-to-date customer due diligence (CDD) records and reduce AML exposure.
By aligning review frequency with risk-based KYC principles, organisations can proactively identify changes in customer information, ownership, or activity before they become compliance issues. In many compliance frameworks, this structured cycle is also described as a kyc refresh or kyc renewal process, depending on the depth of review required.
Event-Driven Reviews
An event-driven KYC review is triggered immediately when a material change, risk signal, or AML alert is detected, rather than waiting for the next scheduled periodic review date. This ensures that any significant updates such as sanctions hits, PEP status changes, unusual transaction patterns, or ownership shifts are addressed in real time through a full re-KYC process.
By acting on these triggers promptly, businesses strengthen ongoing monitoring, maintain regulatory compliance, and prevent outdated customer data from impacting risk assessments. In more severe cases, this may escalate into a full kyc renewal where the entire customer profile must be revalidated.
What Events Should Trigger an Immediate KYC Review?
Not every customer change can wait for a scheduled periodic KYC review, especially when new risk signals emerge.
Certain events require an immediate re-KYC process or KYC refresh to ensure customer information, risk profiles, and AML screening results remain accurate and up to date.
Customer Identity Changes
Customer identity changes are key re-KYC triggers in any periodic KYC review, as they directly impact customer due diligence accuracy and AML compliance. A change of legal name, nationality, or residency can signal a shift in risk exposure, while expired or newly issued identification documents require re-verification under the re-KYC process or KYC renewal cycle.
Material address changes, inconsistent identity details, or failed biometric and liveness checks may indicate identity fraud or data issues. Any doubts about previously collected information should prompt an immediate KYC refresh, updated identity verification, and enhanced screening to maintain an accurate customer risk profile.
Business and Ownership Changes
Business and ownership changes are key triggers for a KYC periodic review because they can affect control, risk exposure, and beneficial ownership. New directors, shareholders, or authorised representatives require updated KYB checks and ownership mapping.
Restructuring, nominee arrangements, or legal form changes can obscure control and should be reassessed under EDD. Changes in trading name, business activity, or major events like mergers, acquisitions, or insolvency also require a re-KYC review or KYC renewal to maintain accurate AML risk assessment and compliance.
AML Screening Alerts
AML screening alerts are high-priority triggers in any re-KYC workflow, as they often indicate financial crime or regulatory risk. A sanctions match, new PEP status, or watchlist alert requires immediate escalation and enhanced due diligence. Adverse media, regulatory enforcement actions, or criminal allegations can significantly impact the customer risk rating and must be reviewed within ongoing AML monitoring.
Even indirect links to sanctioned or high-risk parties should prompt a KYC refresh, updated screening, and reassessment of the customer’s compliance profile to ensure alignment with FATF-based AML obligations.
Transaction and Behavioural Changes
Transaction and behavioural changes are key indicators that a customer’s risk profile may no longer match their onboarding data, making them important triggers for a periodic KYC review. Activity that deviates from the expected profile, sudden transaction spikes, or exposure to higher-risk jurisdictions can signal changing financial behaviour.
Unexplained cross-border payments, use of new products, or structuring patterns may suggest layering or evasion. Repeated sub-threshold transactions, increased use of cash, cryptoassets, or complex corporate structures should prompt enhanced monitoring, updated due diligence, and a full re-KYC review or KYC renewal to reassess AML risk.
Relationship Changes
Relationship changes can quickly alter a customer’s risk profile and may require an immediate re-KYC or event-driven KYC review. Requests for higher-risk products, higher account limits, or reactivation of dormant accounts can change expected activity. Expansion into new markets or changes in service channels may also increase risk exposure.
Customer complaints revealing inaccurate information, or law-enforcement and regulatory requests, are strong triggers to refresh KYC data. These events usually lead to updated screening, risk reassessment, and enhanced due diligence to maintain AML compliance and accurate customer profiling.
Streamline Your Re-KYC Process
How to Complete the Re-KYC Process
Re-KYC, also referred to as KYC renewal, is more than a routine check; it is a structured re-KYC process that keeps customer data accurate, risk profiles up to date, and compliance aligned with regulatory expectations.
A well-executed periodic KYC review ensures effective KYC review frequency management, strengthens re-KYC compliance, and supports continuous AML monitoring across the customer lifecycle. A KYC refresh is often embedded within this process to ensure data remains current between full reviews.
Step 1. Identify the Reason for the Review
The first step in the re-KYC process is to clearly identify why the review is being initiated. This may be periodic KYC review, event-driven KYC review, alert-driven investigation, remediation activity, account reactivation requirements, or a trigger from internal policy or regulatory obligations. Recording the exact trigger ensures a clear audit trail and supports KYC compliance and governance requirements.
It is also important to log the date the trigger was identified, as this helps demonstrate timely action in line with AML compliance expectations. Proper classification of the review type ensures the correct level of customer due diligence (CDD) or enhanced due diligence (EDD) is applied throughout the process.
Step 2. Review the Existing Customer File
The next step in the periodic KYC review is to assess the existing customer file in full. This includes onboarding data, current customer risk rating, previous review outcomes, screening history, transaction monitoring alerts, and any prior EDD findings or exceptions. This ensures a complete understanding of the customer’s historical risk profile.
Reviewing the file also helps identify gaps or inconsistencies in KYC documentation and ensures that all prior compliance decisions are still valid. This step is essential for maintaining accurate ongoing customer due diligence (OCDD) and supporting effective risk-based decision-making.
Step 3. Determine What Information Must Be Updated
At this stage of the re-KYC process, a risk-based approach should be used to determine what information needs updating. Not every review requires full document resubmission; instead, focus on missing data, expired documents, and information impacted by the review trigger or changes in customer behaviour.
Additional updates may be required where customer risk assessment indicates increased exposure, such as changes in ownership, activity patterns, or jurisdictional risk. This ensures the KYC refresh is proportionate, efficient, and aligned with regulatory expectations.
Step 4. Contact the Customer
When contacting the customer, clearly explain the purpose of the KYC periodic review and why updated information is required. Include what documents are needed, submission deadlines, accepted formats, and how their data will be processed in line with data protection and AML compliance requirements.
It is important to avoid any communication that could constitute tipping off, especially where an alert-driven KYC review or potential investigation is involved. Clear, professional communication helps maintain trust while ensuring compliance with re-KYC requirements.
Step 5. Verify Updated Identity Information
The final step involves verifying updated identity information using appropriate KYC verification methods based on the customer’s risk level. This may include document verification, database checks, biometric face matching, liveness detection, and address verification to ensure authenticity and accuracy.
Where necessary, manual review and cross-checking against reliable independent sources should be performed to strengthen identity verification outcomes. This step ensures the customer’s profile remains accurate and supports effective ongoing AML monitoring and risk management.
Step 6. Refresh Business and Beneficial Ownership Information
For legal-entity customers, re-KYC requires a full refresh of KYB and beneficial ownership data to ensure the customer profile remains accurate. This includes verifying registration status, registered address, directors, shareholders, authorised representatives, and any changes in corporate structure.
It is also essential to confirm direct and indirect ownership, identify all natural-person beneficial owners, and validate ownership percentages and control mechanisms. This ensures compliance with KYB verification, beneficial ownership identification, and ongoing customer due diligence requirements.
Step 7. Repeat AML Screening
AML screening must be repeated for the customer and all relevant connected parties, including sanctions, PEP status, watchlists, criminal databases, and adverse media. This ensures updated risk intelligence is captured during the periodic KYC review or re-KYC process.
Screening should not be limited to the named customer alone. It must extend to directors, beneficial owners, authorised representatives, and related entities to ensure full AML compliance and accurate risk assessment.
Make AML Screening Easier with Binderr
Step 8. Review Transactions and Customer Behaviour
A key part of the re-KYC process is comparing actual transaction behaviour against the expected profile established at onboarding. This includes reviewing products used, transaction values, frequency, counterparties, geographic exposure, and purpose of activity.
It is also important to reassess source of funds, occupation, and business activities to identify inconsistencies. This supports ongoing transaction monitoring and helps detect potential financial crime risks or changes in customer behaviour.
Step 9. Update the Customer Risk Assessment
The customer risk assessment must be recalculated using updated information from identity checks, AML screening, and transaction analysis. Key factors include geography, industry, ownership complexity, PEP or sanctions exposure, and product risk.
The updated risk score should clearly explain whether risk has increased, decreased, or remained stable. This ensures transparency in the KYC review process and supports defensible AML compliance decisions.
Step 10. Apply CDD or EDD Measures
Where the updated risk profile indicates higher risk, enhanced due diligence (EDD) or additional customer due diligence (CDD) measures should be applied. This may include source of funds verification, source of wealth checks, and additional identity or ownership evidence.
Other measures may include senior management approval, more frequent monitoring, shorter KYC review cycles, and restrictions on certain products or transactions. These controls align with FATF recommendations for higher-risk relationships and strengthened AML compliance.
Simplify the Re-KYC Process with Binderr
A re-KYC process may include identity and business verification, UBO checks, AML screening, risk reassessment, and compliance approval. Using separate providers increases manual work and weakens audit trails.
Binderr streamlines the process from the initial review trigger to the final compliance decision.
- Automatically schedule reviews according to customer risk level.
- Trigger event-driven reviews when sanctions, PEP or adverse media risk changes.
- Verify updated identity documents using AI-powered checks.
- Refresh company registration, directors and shareholder information.
- Rescreen customers and connected parties against AML databases.
- Update risk scores using new customer and screening information.
- Trigger EDD workflows when risk thresholds are exceeded.
What Information and Documents Should Be Updated?
Keeping customer records accurate is a core part of the re-KYC process and every periodic KYC review or KYC renewal cycle. A proper KYC refresh ensures that identity, business and ownership information remains current, supporting ongoing AML compliance requirements and reducing risk exposure over time.
Updating identity, business and ownership information ensures your customer information update and KYC document update remain aligned with ongoing AML compliance requirements. In many organisations, this is also referred to as a structured KYC renewal process, especially when customer files are fully revalidated after significant changes or at defined intervals.
Individual Customers
- Legal name and any previous names
- Date and place of birth
- Nationality and residential address
- Tax residency and contact details
- Occupation and employer
- Purpose of relationship and expected activity
- Identity and address verification documents
- Source of funds and wealth (if required)
- PEP status declaration
Business Customers
- Legal and trading names, registration number, legal form
- Incorporation details and operating addresses
- Core business activities and licences
- Tax information
- Directors, shareholders, authorised representatives
- Beneficial owners and group structure
- Expected transactions and countries of operation
- Source of business funds and key financial information
How Often Should KYC Be Reviewed?
There is no one-size-fits-all answer to KYC review frequency, as modern compliance relies on a risk-based approach rather than fixed timelines.
A periodic KYC review, re-KYC, KYC refresh, or KYC renewal process should be scheduled based on customer risk level, regulatory expectations, and ongoing monitoring signals to ensure information remains accurate and up to date.
Customer risk level | Illustrative internal review cycle | Additional requirement |
High risk | Every 6 to 12 months | Review sooner when a material trigger occurs |
Medium risk | Every 1 to 3 years | Continue event-driven monitoring |
Low risk | Every 3 to 5 years | Review sooner if risk indicators change |
Dormant or inactive | Before reactivation where appropriate | Confirm identity, status and intended activity |
PEP or equivalent elevated-risk relationship | According to applicable EDD policy | Apply enhanced and more frequent monitoring |
These intervals are examples of an internal risk-based policy, not universal legal deadlines. Businesses must follow the requirements that apply to their jurisdiction, sector, regulator and customer risk profile.
Detect Customer Risk Changes Between Periodic Reviews with Binderr
A scheduled periodic KYC review is an important compliance checkpoint, but customer risk can change before the next cycle, such as becoming a PEP, appearing on sanctions lists, receiving adverse media, or linking to restricted entities.
Binderr combines AML screening, ongoing monitoring and dynamic risk assessment to support continuous KYC compliance.
- Sanctions monitoring: Detect new matches against relevant international sanctions lists.
- PEP monitoring: Identify when a customer, director or UBO becomes politically exposed.
- Watchlist monitoring: Track new regulatory, law-enforcement or financial-crime risk indicators.
- Adverse media monitoring: Detect negative news linked to fraud, corruption, money laundering, criminal activity or regulatory enforcement.
- Connected-party monitoring: Monitor directors, shareholders, UBOs and other relevant parties, not only the named customer.
- Real-time alerts: Notify compliance teams when new risk information is detected.
How to Automate Re-KYC and Periodic Reviews
Re-KYC doesn’t have to be a manual, time-consuming compliance burden when it can run as a structured, automated workflow.
With the right system in place, periodic reviews, risk updates, and customer screening can be continuously triggered, tracked, and completed with minimal operational friction, supporting both KYC refresh and full KYC renewal processes where required.
Automated Review Scheduling
Automated review scheduling links each customer’s KYC review dates directly to their risk rating, ensuring high-risk profiles are reviewed more frequently while low-risk customers follow longer cycles. The system sends automated reminders before due dates, escalates overdue re-KYC cases to compliance leads, and automatically places them into structured review queues for efficient handling.
When a customer’s risk increases due to new AML screening results or behavioural changes, the schedule dynamically shortens, supporting risk-based KYC review frequency and ensuring continuous compliance without manual tracking. This also ensures that both KYC refresh and KYC renewal cycles are triggered appropriately based on risk.
Dynamic Information Collection
Dynamic information collection workflows adapt the re-KYC process by requesting tailored evidence based on customer type, risk rating, jurisdiction, product usage, review trigger, and previous responses. For example, a high-risk corporate client in a high-risk jurisdiction may be asked for enhanced due diligence documents, while a low-risk individual may only need updated ID and address proof.
This ensures the periodic KYC review remains proportionate, efficient, and aligned with AML compliance requirements while reducing unnecessary friction for lower-risk customers, whether during a routine KYC refresh or a full KYC renewal.
Automated Identity Verification
Automated identity verification streamlines the re-KYC process by validating customer documents through OCR and data extraction, ensuring accuracy and consistency of submitted information. It combines biometric face matching and liveness detection to confirm the individual is genuine, while fraud indicators and global database checks help identify synthetic or stolen identities.
Address verification further strengthens customer due diligence by confirming residency details, making automated re-KYC both faster and more reliable for ongoing AML compliance and supporting both KYC refresh and KYC renewal workflows.
Continuous AML Screening
Continuous AML screening ensures customers are regularly checked against sanctions lists, PEP databases, global watchlists, and adverse media sources throughout the business relationship. Monitoring alerts automatically flag changes in risk status, while rescreening of connected parties such as beneficial owners, directors, and associates ensures full coverage.
This ongoing customer due diligence approach supports event-driven KYC reviews and helps institutions detect emerging financial crime risks in real time, often triggering a KYC refresh or full KYC renewal when risk thresholds are breached.
Dynamic Risk Scoring
Dynamic risk scoring continuously updates a customer’s risk profile by incorporating new AML screening results, ownership changes, transaction behaviour, and refreshed KYC information. Each data point adjusts the overall risk rating, ensuring that re-KYC decisions reflect the customer’s current exposure rather than static onboarding data.
This enables more accurate periodic KYC reviews, supports event-driven reassessments, and ensures that enhanced due diligence is triggered automatically when risk thresholds are exceeded, including during KYC refresh and KYC renewal events.
Case Management and Audit Trails
Case management and audit trails centralise all customer KYC and re-KYC activities into a single system, ensuring full visibility and control for compliance teams. It enables structured review assignments, approval workflows, and secure storage of all supporting evidence, while maintaining detailed decision records and change history for every customer.
Integrated alert management and reporting tools ensure regulatory readiness, making it easier to demonstrate compliance during audits and support efficient AML investigations across both KYC refresh and KYC renewal cycles.
Binderr: Your Complete Re-KYC, CDD and EDD Solution
Re-KYC is part of ongoing due diligence that starts at onboarding and continues through periodic reviews, event-driven updates, enhanced checks, and continuous monitoring.
Binderr brings these activities into one complete compliance solution:
- KYC: Verify individuals using AI-powered document verification, biometrics, liveness and fraud detection.
- KYB: Verify businesses through global company registries and reliable corporate data sources.
- UBO checks: Identify, verify and screen the individuals who ultimately own or control a company.
- AML screening: Screen individuals and businesses against sanctions, PEP, watchlist and adverse media sources.
- Ongoing monitoring: Receive alerts when customer or connected-party risk changes.
- Case management: Assign reviews, manage alerts and record compliance decisions.
Bottom Line
Re-KYC and periodic KYC reviews, including structured KYC refresh and KYC renewal cycles, are essential to keep customer information, screening results and risk profiles up to date as circumstances change. Effective programmes combine scheduled and event-driven reviews to ensure AML controls remain appropriate and risk-based.
Each review should refresh key customer data, rerun AML screening and reassess risk, with clear documentation for audit purposes. Increasingly, organisations are using automation to make this process faster, more consistent and easier to manage at scale, especially across ongoing KYC refresh and full KYC renewal workflows.
Binderr Services connects customer verification, AML screening, risk assessment and ongoing monitoring in one platform, helping teams manage re-KYC efficiently and in line with regulatory expectations, including continuous KYC refresh and structured KYC renewal processes.



