Perpetual KYC: event-driven customer due diligence

Perpetual KYC replaces the three-year review cycle with updates that happen when something changes. The surprise for most teams is that German law never asked for the cycle in the first place: the GwG requires continuous monitoring of the business relationship, and the fixed interval was the industry's way of operationalizing it. KYC in Germany covers the onboarding duties; the subject here is what happens afterwards.

A compliance specialist compares corporate registry filings after a recorded ownership change.

The duty that perpetual KYC implements

Section 10(1) number 5 of the Geldwäschegesetz requires the continuous monitoring of the business relationship, including the transactions carried out in it, and the updating of the documents, data and information obtained, at a frequency appropriate to the risk. The words that matter are continuous and risk-appropriate.

Nothing in that provision names an interval. BaFin's interpretation and application guidance on the GwG sets the expectation as risk-based and not calendar-based, which means an institution choosing a fixed cycle has to justify the cycle, and an institution moving to event-driven updates is not asking for an exemption. It is implementing the provision more directly than the cycle did.

Why the periodic cycle fails on its own terms

A three-year cycle has a structural defect: a customer whose risk changes in month four is reviewed 32 months later, and a customer whose risk never changes consumes a full review anyway. The reviews also arrive in a block, which is why KYC remediation runs as a project with contractors instead of as a process.

The customer notices too. A periodic review asks for documents the institution already holds, because the request is generated by the calendar and not by a gap. This is the practical argument that gets perpetual KYC funded, and it is why the first measurable outcome is usually a drop in outreach volume and not a change in risk coverage.

The events that trigger a review

Four groups of trigger carry most of the work. Customer data changes: a new address, a change of legal form, a new authorized representative, a change in beneficial ownership. Relationship changes: a new product, a new country in the payment flows, a corporate restructuring that puts a new parent above the customer.

Behavioral triggers come from the monitoring system: turnover outside the expected range for the stated purpose, a counterparty in a higher-risk jurisdiction, a pattern the scenarios flagged even after the alert was closed. And external triggers arrive without the customer doing anything: an adverse media hit, a sanctions or PEP list change, an insolvency filing, a registry update. Transaction monitoring is the source of the third group.

The Transparenzregister discrepancy report as an outside trigger

German law supplies a trigger the institution does not control. Section 23a of the GwG obliges an entity that notices a discrepancy between the beneficial ownership information in the Transparenzregister and what it established in its own due diligence to report that discrepancy to the registering authority.

For a perpetual KYC design this is a two-way connection: the register is a data source for the trigger, and the institution's own finding creates a reporting duty of its own. A design that reads the register once at onboarding and never again misses both sides. KYC in Germany covers the register and the identification duties around it.

What the data layer has to deliver

Perpetual KYC is a data problem before it is a compliance one. The institution needs one view of the customer across its products and entities, because a change recorded in one system has to reach the review in another. It needs the ownership structure resolved, so that a change two levels above the customer is visible as a change to this customer.

It also needs lineage. When an update arrives from an external source, the institution has to know which source said what and when, because the next question from an auditor is why the file says what it says. Where the matching of a customer against external records is automated, the matching itself becomes a model with a validation duty, which model validation covers.

Data protection limits on continuous screening

Continuous monitoring runs into purpose limitation. Article 5 of the GDPR requires personal data to be collected for specified purposes and processed in a way compatible with them, and to be adequate, relevant and limited to what is necessary. Monitoring carried out to meet the GwG duty has a legal basis; the same data reused for marketing or pricing does not inherit it.

Two design consequences follow. Screening scope is documented against the AML purpose, which rules out collecting everything available about a customer because it might be useful. And retention follows the AML retention rules and not the lifetime of the system, so a perpetual process still has to delete.

What the AMLR changes from 2027

Regulation (EU) 2024/1624, the AMLR, applies from July 10, 2027 and harmonizes the customer due diligence rules that are national today, with technical standards from AMLA underneath. The continuous monitoring duty does not disappear; it stops being a German provision and becomes an EU one, applied the same way in every member state.

For an institution building perpetual KYC now, the useful preparation is to keep the triggers and the review logic separate from the national legal references, so that the rulebook can be re-pointed without rebuilding the process. AMLA in Frankfurt covers the authority and the EU AML package the three instruments.

What is perpetual KYC?

Perpetual KYC is customer due diligence that updates when something changes instead of on a fixed review cycle. Triggers come from customer data changes, changes in the relationship, behavior flagged by transaction monitoring, and external sources such as registry, sanctions and adverse media updates. In Germany it implements the continuous monitoring duty in section 10(1) number 5 GwG, which sets no interval.

Does the GwG require a three-year KYC review cycle?

No. The GwG requires continuous monitoring and updating at a frequency appropriate to the risk, and names no interval. The three-year and five-year cycles widely used are an industry convention and a reading of risk-based practice, not a statutory requirement. An institution may use a cycle, and then it has to be able to justify the length it chose for each risk class.

Does perpetual KYC mean no reviews at all?

No. Most designs keep a long-interval backstop review for the lowest-risk population, because the absence of any trigger over several years is itself worth confirming, and keep a shorter cycle for high-risk relationships on top of the event-driven updates. What disappears is the mid-risk block review that produced the remediation projects.

What does perpetual KYC cost to run?

The cost moves more than it falls. Outreach to customers and manual file rebuilds go down; data integration, external data subscriptions and the ongoing validation of the matching and scoring logic go up. The figure to watch is the share of triggers that close without human work, because a trigger set that sends everything to an analyst reproduces the periodic review with extra steps.

Perpetual KYC and Finance Loop

Finance Loop is the meeting place for the KYC leads, data teams and money laundering officers rebuilding these processes in German institutions. Finance Loop events bring the people designing event-driven reviews together with the supervisors who will read the result.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.