What problem does it solve?
Banks review each customer's due diligence file on a fixed cycle; Fenergo describes periodic KYC as checks at set intervals, typically every year or every two years. Each review means re collecting documents, checking registries and ownership structures, rescreening and writing a conclusion, and for corporate clients it can take weeks of back and forth.
A review where nothing material has changed costs much the same effort as one that finds something, and it annoys customers with repeated requests for information the bank already has. At the same time, a real change, such as a new beneficial owner or a sudden shift in activity, can go unnoticed until the next scheduled review. When reviews fall behind schedule, the backlog of overdue files becomes a compliance risk in its own right.
- A Fenergo study found that more than half of financial institutions spend between 61 and 150 days on client KYC reviews, at an average cost of USD 2,200 per review.Ongoing Customer Due Diligence with Perpetual KYC (2026)
How does it work?
- Watch for triggers. The system monitors company registries, ownership changes, screening results, adverse media, transaction behaviour, contact detail changes and document expiry for every customer.
- Assess materiality. Each event is classified against the bank's trigger policy: ignore, refresh automatically, or open a review.
- Refresh straight through. Low risk changes (a new registry filing that confirms existing data, a renewed identity document) update the file automatically, with the source recorded.
- Prepare the review. Material events open a review with the file already assembled: what changed, current documents, registry extracts, screening results and a drafted summary with sources.
- Reach out only when needed. When information is missing, the customer gets one targeted request through the channel they use, and the analyst concludes and signs off the review.
- Audience
- Back office
- Autonomy
- Supervised agent
- Adoption
- Emerging
- Channels
- Internal tools, Email, Mobile app
What is it worth?
Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.
| KPI | Median | Reported range | Data points | Claimed by |
|---|---|---|---|---|
| Cost reduction | Too few to pool | 40% | 1 | 1 organization |
Value drivers: Compliance quality, Lower cost to serve, Customer experience, Risk and loss reduction.
Indicative value
A bank with 20,000 corporate and business clients under periodic review
USD 960,000 to USD 7 million
KYC review cost avoided per year
How this is calculated
Formula: reviews * costPerReview * avoidedShare. The low scenario uses every low input, the high scenario every high input.
| Input | Low | High | Basis |
|---|---|---|---|
| Periodic KYC reviews per year reviews, reviews per year | 6,000 | 8,000 | Editorial assumption for a mix of one, three and five year review cycles on 20,000 clients. |
| Cost of a periodic review costPerReview, USD per review | 800 | 2,200 | The high value is the average cost per client KYC review reported in a Fenergo study cited on this page; the low value is an editorial assumption for simpler files. |
| Share of review effort avoided by straight through refresh and prepared files avoidedShare, fraction of review cost | 0.2 | 0.4 | Conservative against the benchmarks on this page (JPMorgan Chase reports a 40% reduction in KYC unit cost since 2022 from AI and technology). Replace with results from your own pilot. |
What it leaves out: Leaves out the value of detecting material changes earlier, the effect on customer experience and attrition, backlog reduction, data costs and the cost of building the trigger monitoring.
Who already uses it?
5 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.
First National Bank of Omaha (FNBO)
United States · Banking · 2026
FNBO deployed Nasdaq Verafin's Agentic EDD Analyst and Agentic Sanctions Analyst, which remove manual information gathering across multiple systems for enhanced due diligence cases and sanctions alerts. The vendor reports that the bank spent 50% less time on these reviews and alerts and redirected investigator capacity to deeper analysis.
- Handling time reduction: 50%, per case, enhanced due diligence and sanctions alert reviews
"At First National Bank of Omaha, AI agents have begun taking on some of the work of human financial crime investigators, reducing the time that people spend on each case by 50%, according to bank executives."
Claimed by: independent
OCBC
Singapore · Banking · 2026
OCBC launched HELIOS in July 2026, an agentic AI platform that gathers intelligence on prospective private banking clients and completes most of the customer due diligence before a relationship manager engages them. OCBC says private banking accounts can now be opened in 15 business days, against an industry median of about six weeks, while relationship managers and review teams keep accountability for judgment and decisions. OCBC plans to extend HELIOS to ongoing monitoring of customer activity to detect changes in risk profiles. Bank of Singapore relationship managers use it in Singapore, Hong Kong and Dubai, with the rollout due to finish in the third quarter of 2026.
No outcome disclosed.
JPMorgan Chase
United States · Banking · 2025
At its 2025 Investor Day, JPMorgan Chase's Commercial and Investment Bank said it was using AI and technology across the client journey, including onboarding and know your customer processing, and reported a substantial fall in the unit cost of KYC since 2022. The disclosure covers KYC processing in general rather than event driven review specifically.
- Cost reduction: 40%, KYC unit cost, 2022 to 2025
"In KYC, for instance, we've seen a 40% reduction in unit cost since 2022 due to AI and technology enhancements."
Claimed by: organization
Origin Bank
United States · Banking · 2025
Origin Bank, a US bank with about USD 10 billion in assets, uses Nasdaq Verafin's agentic AI workforce for its enhanced due diligence reviews of high risk customers. Nasdaq Verafin's Digital EDD Analyst automates the bank's periodic EDD review process, closing low risk cases itself and escalating the rest. The vendor reports a large increase in the number of EDD reviews completed.
No outcome disclosed.
Deutsche Bank
Germany · Banking · 2020
Deutsche Bank used WorkFusion's AI automation for screening work in anti money laundering, including adverse media monitoring and PEP checks for new accounts and refresh screenings, which had required large teams to scan news reports manually. For the KYC programme as a whole, the vendor reports shorter handling times, about 25,000 cases handled per quarter and tens of thousands of hours saved each year.
- Handling time reduction: up to 50%, range of 25 to 50%, across the whole KYC programme (screening and document processing)
"25–50% reduction in handling time"
Claimed by: vendor
How do you implement it?
A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.
Data you need
- Structured KYC files with data lineage per attribute
- Company registry, ownership and document expiry data feeds
- Screening, adverse media and transaction monitoring signals per customer
- A written trigger policy that defines material events
Systems to integrate
- Client lifecycle management or KYC platform
- Company registries and data providers
- Screening and transaction monitoring systems
- Customer channels for information requests (portal, app, email)
- Document management
Complexity: High
Needs reliable external data feeds, a trigger policy agreed with compliance and sometimes the regulator, and a customer lifecycle system that can take automated updates with an audit trail. AML rules such as MAS Notice 626 still expect regular account reviews, so the design needs a lighter backstop cycle alongside the triggers.
- 1
Write the trigger policy
Agree with compliance which events matter, for which customer types, and what each should cause. Check whether your regulator still expects fixed review cycles and design around it.
- 2
Fix the file first
Structure KYC data by attribute with its source and date. Event driven review is impossible when the file is a folder of PDFs.
- 3
Automate the assembly of reviews
Start by preparing scheduled reviews automatically (registry extracts, screening, draft summary). This saves time before any policy change.
- 4
Switch on triggers for one segment
Enable event driven reviews for one segment, run them in parallel with the calendar, and compare what each approach finds.
- 5
Extend straight through refresh
Allow automatic updates for low risk, well sourced changes and measure the error rate on a sample before widening.
Guardrails
- Material changes and every risk rating change need analyst sign off
- Automatic updates only from approved sources, with source and date recorded per attribute
- Logged reason why each trigger did or did not open a review
- Customer outreach limited to information the bank does not already hold
- A fallback to scheduled review for customers whose data feeds are incomplete
KPIs to instrument
- Share of trigger events refreshed straight through, and the error rate in sampling
- Time from trigger to completed review
- Overdue review backlog
- Customer outreach requests per review
- Material findings per review, compared with calendar reviews
Human in the loop
Analysts sign off every review opened by a material trigger and every change in risk rating. Compliance owns the trigger policy and reviews samples of events that were ignored or refreshed automatically.
Common failure modes
- Trigger storms
- Noisy feeds open thousands of trivial reviews. Tune materiality and measure the share of triggered reviews with a finding.
- Silent gaps
- A customer with no data feed never triggers and never gets reviewed. Keep a backstop review cycle.
- Regulatory mismatch
- The regulator still expects fixed cycles. Agree the approach and document it before switching off calendar reviews.
What are the risks and rules?
EU AI Act
Depends on design
Keeping customer due diligence files current is not listed in Annex III, so a back office system that assembles reviews for an analyst to decide is usually minimal risk. The design decides the rest: a conversational agent that asks customers for missing information must tell them they are interacting with an AI system (Article 50(1)); biometric verification that only confirms a person is who they claim to be is excluded from Annex III point 1(a), while remote biometric identification is high risk; and Article 5(1)(d) prohibits assessing the risk that a person will commit a criminal offence based solely on profiling, so behavioural triggers should open a review for a human rather than score the customer. GDPR applies to the collection and retention of KYC data, including Article 22 if an automated refresh leads to a decision with legal or similarly significant effect, such as closing an account.
Rules that apply
Guidance
- Guidelines on the use of remote customer onboarding solutions (European Banking Authority, Europe). Sets expectations for remote identity verification and data collection when customers are onboarded remotely; the guidelines cover onboarding, but they are a useful reference when KYC data is refreshed through remote channels.
- Notice 626 Prevention of Money Laundering and Countering the Financing of Terrorism, Banks (Monetary Authority of Singapore, Asia Pacific). Singapore's AML and CFT rules for banks, covering customer due diligence, regular account reviews and the monitoring and reporting of suspicious transactions.
- Principles for Using Artificial Intelligence and Machine Learning in Financial Crime Compliance (Wolfsberg Group, Global). Industry principles from 2022 for the accountable use of AI and machine learning in financial crime compliance programmes, covering legitimate purpose, proportionate use, design and technical expertise, accountability and oversight, and openness and transparency.
Controls to put in place
- Approved trigger policy under change control
- Attribute level source and date for every automated update
- Sampling of automatically refreshed files and ignored triggers
- Backstop review cycle for customers without reliable data feeds
- Audit trail of every review conclusion and sign off
Frequently asked questions
- Does perpetual KYC replace periodic reviews?
- Partly. Event driven reviews catch change sooner and let the bank skip work where nothing changed, but AML rules such as MAS Notice 626 still expect regular account reviews. A sound design keeps a lighter backstop cycle alongside the triggers, agreed with the regulator.
- What triggers a review in perpetual KYC?
- Typical triggers are changes of ownership or directors, new adverse media or sanctions results, unusual transaction behaviour, changes of address or country, and expiring documents. The bank's written trigger policy defines which ones matter for which customer types.
- Where does AI help most?
- In assembling the file and judging materiality: reading registry filings and documents, comparing them with what the bank holds, and drafting a summary so that the analyst decides rather than collects. JPMorgan Chase reports a 40% reduction in KYC unit cost since 2022 from AI and technology, and Nasdaq Verafin describes an agent that automates a bank's periodic enhanced due diligence review process, closing low risk cases itself and escalating the rest.
How to cite this page
Blits.ai AI Use Case Library, "AI for perpetual KYC and event driven customer due diligence", last verified 26 September 2026, https://www.blits.ai/ai-use-cases/perpetual-kyc. Licensed under CC BY 4.0. Method: how we verify use cases.
Changelog
- 27 September 2026: First published