Perpetual KYC replaces the calendar-based review with continuous, event-driven due diligence. Here is how it works, what regulators expect, and how to adopt it without replacing your vendors.
Perpetual KYC (pKYC) keeps every customer's identity and risk profile current in near real time. Instead of refreshing records on a fixed one, three, or five year cycle, it monitors risk signals continuously and opens a targeted review the moment a material change occurs, such as a new sanctions listing, ownership change, or adverse media.
Perpetual KYC, or pKYC, is a customer due diligence model that keeps every customer's identity and risk profile current in near real time through automated, event-driven monitoring. It is also known as continuous KYC, dynamic KYC, event-driven KYC, and continuous customer due diligence, and when applied to businesses it becomes perpetual KYB.
Moody's defines it as "the practice of maintaining up-to-date customer and counterparty records through an automated, integrated workflow of data checks that take place in near real-time". Fenergo frames it as a continuous customer due diligence approach that monitors and updates customer identity and risk information in near real time.
The contrast with the traditional approach is simple. Periodic review takes a photograph of the customer at onboarding, then re-takes it years later on a fixed schedule. Perpetual KYC maintains a live view instead: a change in ownership, a new sanctions listing, adverse media, or unusual activity triggers a targeted review the moment it happens.
Under traditional customer due diligence, a firm performs its checks at onboarding, then re-performs them on a risk-based schedule: high-risk customers reviewed annually, medium every three years, low every five. The weakness is structural. A periodic cycle leaves long gaps in which a customer's risk can change unnoticed, and it wastes analyst effort re-reviewing thousands of customers whose risk has not changed while potentially missing the one whose risk changed the day after their last review.
The crucial word is event-driven. As Finextra's Victor Mendez puts it, perpetual KYC architecture is event-driven, not a faster batch job. pKYC does not schedule a full re-verification of every customer on a timer. Instead the firm continuously ingests risk signals and only opens a review when a material change is detected.
This matters because the mechanism is different, not just the frequency. A quarterly batch still processes everyone on a clock and still leaves everyone unwatched between runs. An event-driven model watches the signals that actually change risk and acts on them individually, so a customer sanctioned on a Tuesday is reviewed on Tuesday, not at the next quarterly sweep.
A working pKYC model has five moving parts. Zenoo's own ongoing-monitoring framework describes essentially the same anatomy as five layers: automated screening, behavioural analysis, corporate structure tracking, jurisdictional risk monitoring, and automated risk recalculation. You can read that operational framework in full in the continuous compliance framework. The components below explain the mechanism itself.
pKYC is assembled from data feeds, screening, monitoring, decisioning, and case management. Leading firms unify their data and wire event-driven triggers across all of these rather than buying one product. The bigger exposure is also after onboarding, not at it: Sumsub reports 76% of fraud attempts occur after the KYC process, during day-to-day activity, which is exactly the window periodic review leaves blind.
Perpetual KYC sits on top of an obligation that already exists and is being tightened by every major regime. FATF Recommendation 10 sets the four core customer due diligence obligations: identify and verify the customer; identify and verify the beneficial owner; understand the purpose and intended nature of the relationship; and conduct ongoing due diligence on the relationship, scrutinising transactions and keeping records current. Most firms operationalise that last obligation as periodic reviews, but the duty itself is continuous.
In the EU, the 2024 AML package creates a single rulebook and a central authority, AMLA, which has been standing up in Frankfurt since mid-2025. The AML Regulation (Regulation (EU) 2024/1624) applies from 10 July 2027. AMLA guidance defines ongoing monitoring as keeping customer information up to date and continuously monitoring activity to detect unusual or suspicious activity as it arises, and introduces monitoring triggers even for low-risk customers. In 2026 AMLA opened a consultation on business-relationship monitoring guidelines.
In the UK, the FCA's April 2026 review of customer due diligence controls criticised firms that did not have enough detail on how often periodic reviews should take place and firms that failed to follow their own policies on when to conduct periodic reviews. It praised firms with documented, risk-tailored, independently tested controls. UK industry guidance from JMLSG, approved by HM Treasury, states that ongoing monitoring is not a once-a-year exercise.
In the US, FinCEN's CDD rule requires risk-based ongoing monitoring to identify and report suspicious activity and to update customer information on a risk basis. A February 2026 update clarified that firms verify beneficial ownership once and update it only when risk or new information warrants, rather than as a matter of course at every review. That is functionally an event-driven posture.
North America accounted for over 38% of the perpetual-KYC market in 2024, with banking, financial services, and insurance the leading adopters, according to market-research trackers. Mordor Intelligence projects the wider KYC market to grow from about USD 6.73bn in 2025 to roughly USD 16.31bn by 2031, a 15.88% compound annual growth rate over 2026 to 2031. These are vendor projections and should be read as forecasts rather than fact. Industry trackers describe pKYC as becoming the 2026 default operating model for customer due diligence.
The manual case that pKYC attacks is expensive. The average time to conduct a manual due-diligence check on a corporate customer is cited by ComplyAdvantage at 40.3 hours, and PwC estimated that a firm moving to pKYC could save 60% to 80%, about USD 14.4m a year for a medium-sized bank's corporate book and about USD 13.2m for its retail book. Fenergo reports that more than half of institutions spend 61 to 150 days on client KYC reviews at an average of USD 2,200 per review. Present these as the named provider's own figures, not as consensus.
Market-size and saving figures come from named vendors and analysts such as Mordor Intelligence, PwC, ComplyAdvantage, Fenergo, and Moody's. We present each as an attributed range or forecast, never as an industry-wide certainty. Zenoo's own metrics are drawn only from its metrics registry and are clearly labelled as the platform's figures.
The benefits of moving to continuous due diligence are concrete: lower cost per customer over time, fewer false positives to work through, analyst effort concentrated on real risk, and a much faster response when a customer's risk actually changes. But the model is not free of friction, and the honest challenges below decide whether a programme succeeds.
AI is what makes continuous, event-driven due diligence feasible at scale. Used defensively, it filters the noise so analysts see material changes rather than thousands of near-duplicate alerts, detects change automatically through behavioural analytics and continuous screening, automates the routine while drafting resolution notes and outreach, and improves detection of synthetic and manipulated identities that static onboarding checks miss.
Moody's reports that its AI review can cut false positives by up to 80%. Present any provider's reduction figure as that provider's own attributed claim, not an industry norm.
Zenoo runs 10 specialised AI agents plus an automated pipeline. In a pKYC context the honest mapping is: alert-disposition triage pre-classifies up to 80% of screening alerts with high confidence, cutting per-alert disposition from 20 to 45 minutes down to 2 to 3 minutes. Model optimisation typically reduces false positives by 15% to 30%, and most teams see up to a 95% reduction within 90 days on the platform. When an event fires, automated re-research returns a KYB dossier in under 60 seconds and individual due diligence in under 45 seconds, versus 2 to 4 hours and 1 to 3 hours manually, and risk is recalculated in under 30 seconds. Zenoo cites per-alert investigation moving from an industry benchmark of 22 hours to 12 minutes; that is the platform's own figure, not an industry-wide pKYC claim.
The same generative AI that powers detection is turned against the controls pKYC is meant to keep current. In January 2024 a finance worker at engineering firm Arup joined a video call with people he believed were the CFO and colleagues; all were AI-generated deepfakes. He made 15 transfers totalling about USD 25.6m (HKD 200m) in a single day. Arup's chief information officer described it as technology-enhanced social engineering: it did not go through the firewall, it went through a person.
The scale is rising. Sumsub's 2025 to 2026 data separates two figures that are often conflated: deepfakes made up about 7% of global fraudulent activity in 2025, and were the joint-largest of the top first-party fraud schemes at 11%. The 11% is a share among top first-party schemes only, not a share of all global fraud. Some markets saw extreme spikes, with US deepfake fraud up about 1,100% and the Maldives up about 2,100% year on year in Q1 2025. Synthetic-identity document fraud rose over 300% in the US, and synthetic identities appeared in about 21%, or one in five, of first-party frauds.
pKYC is not a silver bullet against deepfakes or synthetic identities. But with 76% of fraud attempts occurring after onboarding, attackers pass the initial check and then abuse the dormant-review window that periodic KYC leaves open. Continuous, event-driven monitoring shortens the window in which a compromised or synthetic identity can operate undetected. The detection itself still comes from specialist vendors; the value of pKYC is watching the whole lifecycle, not just the front door.
Industry outlooks for 2026 describe perpetual KYC as the emerging default operating model, with periodic review reframed as a backstop. Supervisors will increasingly ask why a firm is not event-driven. Writing for GARP, Ty Francis of LRN Corp. argues that regulatory escalation means AI-driven transaction monitoring, automated risk scoring, and real-time data analytics will be non-negotiable for firms to keep pace; the phrasing is his, not a direct regulator quotation.
From 10 July 2027 the EU AML Regulation harmonises customer due diligence across member states, with AMLA guidance pushing continuous monitoring and low-risk triggers, so firms will need pKYC-style capability to comply consistently. Agentic AI is expected to move from triage to action, progressing cases with full context and auditability under human oversight for material decisions. Perpetual KYB matures alongside pKYC, driven by graph-based data unification. And with deepfake and synthetic-identity fraud rising sharply and getting cheaper, tolerance for stale records keeps shrinking. Forecasts of adoption pace vary by source and should be attributed, not stated as fact.
You do not need to rip out your verification, screening, or data providers to adopt pKYC. The practical path is to unify your data, map the events that matter, wire your existing feeds into triggers, and put a clean audit trail around the result. The checklist below is a readiness sequence.
Zenoo is an orchestration platform: your vendors plus Zenoo, never a replacement. It connects the providers you already use into one continuous, event-driven workflow with routing, failover, cost control, and a single audit trail. Its Marketplace offers 240+ check types at Enterprise tier and 50+ at Professional, so sanctions, PEP, adverse-media, registry, and identity signals feed one flow rather than 6 to 8 stitched-together tools. Its alert-disposition and model-optimisation agents cut the false positives that stall pKYC programmes, its KYB and risk agents re-run due diligence in seconds on a trigger, and it records 32 immutable audit event types across 8 categories with a 209-country risk database at 16 indicators each. What Zenoo does not do: it does not itself verify identities, screen names, supply sanctions or PEP data, detect deepfakes, or run biometric liveness; those come from your chosen vendors. It cannot fix poor or siloed source data, and it does not remove any legal obligation to run periodic reviews where a jurisdiction mandates them.
Zenoo turns the vendors you already use into one continuous, event-driven workflow: routing, failover, automated re-research on a trigger, and one immutable audit trail. Your vendors plus Zenoo, never a replacement.