Periodic KYB vs Perpetual KYB: Which Approach Actually Protects Your Business in 2026

by Nicolae Buldumac
· 01/29/2026 07:43 · 12 min read
Periodic KYB vs Perpetual KYB: Which Approach Actually Protects Your Business in 2026

A supplier you onboarded last March is now controlled by a sanctioned individual. The change happened in September. You don't know yet — your next review is scheduled for March. Six months of exposure, all of it sitting in a clean-looking compliance file.

This is the gap regulators have stopped tolerating. In 2025, the FCA fined Monzo £21.1m for failures across customer due diligence and ongoing monitoring. Nationwide was fined £44m in December for control failures that allowed £27.3m in COVID furlough fraud to slip through. Barclays was fined £42m. Revolut paid €3.5m to Lithuania's central bank for monitoring deficiencies. Coinbase paid €21m to the Central Bank of Ireland for failing its AML/CTF monitoring obligations between 2021 and 2025. Across the Atlantic, OKX paid more than $500m in February 2025. Block Inc. paid $40m in April.

None of these were onboarding failures. Every one of them was about what happened after onboarding — and how long it took the institution to notice.

That is the question this article answers: when periodic reviews stop being enough, and when continuous monitoring stops being a slogan and starts being a control.

What is Periodic KYB?

Periodic KYB is the traditional model. You verify a business at onboarding, then re-verify on a fixed schedule — typically annually for standard-risk customers, every six months or quarterly for higher-risk ones, and every two to five years for the lowest-risk segment.

The cycle is predictable:

  1. Collect — registration documents, proof of address, corporate filings.
  2. Verify — ownership, directors, beneficial owners.
  3. Screen — sanctions, PEP databases, watchlists, adverse media.
  4. Score — assign a risk rating.
  5. Document — store everything for audit.
  6. Wait — until the calendar says otherwise.

The model emerged from early AML regulations focused on the moment of onboarding. For decades, regulators accepted it. Auditors signed off. Whole compliance teams were structured around scheduled cycles.

It still has real advantages. The schedule is predictable, the costs are budgetable, the workload can be staffed, and batch processing works at scale. For a portfolio of low-risk, stable counterparties, periodic KYB is not broken.

The structural flaw is that it assumes nothing changes between reviews. A company you verified in January is not looked at again until the following January. In that window, beneficial owners can change, sanctions lists can update, directors can resign, adverse media can surface, and corporate status can shift. None of it triggers a review. The file sits untouched until the calendar moves it.

That gap is where most of the recent enforcement actions live.

What is Perpetual KYB?

Perpetual KYB — also called pKYB, continuous KYB monitoring, or event-driven KYB — replaces the calendar with the data. Reviews are not scheduled. They are triggered.

The logic:

  • Connect — link customer records to live data sources: corporate registries, sanctions lists, adverse media feeds, ownership databases.
  • Monitor — watch for material changes continuously.
  • Detect — when a change happens (new UBO, director resignation, status change, sanctions hit), surface it.
  • Alert — flag the change to the compliance team.
  • Review — investigate and act.

There is no annual review date. The data tells you when to act.

Definition

Perpetual KYB is the operational extension of KYB into the lifecycle of a business relationship. Verification at onboarding establishes a baseline. Continuous monitoring keeps that baseline current. Together they form a single control, not two disconnected processes.

The Core Difference, in One Question

Periodic KYB asks: "Is this company still compliant based on our last review?"

Perpetual KYB asks: "Has anything changed since we last looked?"

One is backward-looking. The other is forward-looking. The difference shows up in how fast you catch a problem.

FIG 01 · RISK EXPOSURE WINDOWHow long you're exposed to a missed changeSame UBO change in month 4. Red = period when the change has happened but you don't know.M0M2M4M6M8M10M12Periodic KYBAnnual review cycleUBO changeOnboardChange happensDetected at next review8 months exposedPerpetual KYBEvent-driven monitoringUBO changeDetected same dayOnboardContinuous coverageNo exposure windowSource: Global Database analysis · 2026 · Assumes annual periodic review cycle

Both programs run for 12 months. The difference is how much of that year leaves you exposed to a change you haven't detected.

Where Most Teams Get the Implementation Wrong

Here is where the conversation usually goes off the rails. Vendors call their products "perpetual" or "real-time." Compliance teams switch on continuous monitoring expecting cleaner risk signals. Within a quarter, analysts are buried in alerts.

The problem is not perpetual KYB. The problem is how the change is detected.

Polling-based monitoring

Most "real-time" KYB tools use polling. The system queries registries on a schedule — every day, sometimes more — pulls a fresh snapshot of every company in your portfolio, and compares it to yesterday's snapshot. Any difference triggers an alert.

The flaw: registry data does not change in the way these systems assume. Formatting shifts. A field gets reformatted. A timestamp updates. Capitalisation changes when a registry runs a maintenance script. The underlying facts are identical, but the polling system sees a difference and fires.

What changed in the data feedMaterial risk?Polling system fires?
"123 Main Street" → "123 Main St."NoYes
"John Smith" → "JOHN SMITH"NoYes
Date format "01/05/2025" → "2025-05-01"NoYes
Phone number spacing changedNoYes
Director field re-sorted alphabeticallyNoYes
New beneficial owner addedHighYes
Director added to OFAC SDN listCriticalYes

Five out of seven alerts are noise. Two are real risk signals. That ratio gets worse the bigger the portfolio.

Event-driven detection

Event-driven monitoring works the opposite way. Instead of polling registries on your behalf, the data provider collects registry data continuously into its own infrastructure. When a material change happens at the source — a new shareholder filed, a status updated to "dissolved," an officer resigned — the provider sees it as part of the underlying ingestion. Your portfolio gets an alert because something genuinely changed, not because a string got reformatted.

Strise — one of the more credible operators in the space — reports that most periodic reviews show no material change and that event-driven workflows can cut review workload by up to 90%. That number is consistent with what we see when clients move from polling-based vendors to a registry-collected feed: alert volume drops by an order of magnitude, and the alerts that remain are worth investigating.

Which model fits your portfolio?

"Periodic vs perpetual" is the wrong framing. The right framing is: which mix fits the portfolio you actually run? Two variables decide it — how much regulatory and counterparty risk sits in your book, and how often material attributes change across that book. Plot your portfolio on the matrix below and the answer is usually obvious.

FIG 02 · DECISION MATRIXWhich model fits your portfolio?Match the monitoring approach to portfolio risk and how often counterparties change.PORTFOLIO RISKHighMidLowPORTFOLIO CHANGE RATEStableMixedVolatileLOW RISK · STABLEPeriodicworks fineAnnual or biennial reviewscover the gap. Auditorsaccept the model.e.g. low-volume domestic suppliersHIGH RISK · STABLEHybridperiodic + sanctions/UBO triggersQuarterly reviews on schedule.Continuous monitoring on theattributes that move the needle.e.g. PEP-linked entities, regulated counterpartiesLOW RISK · VOLATILEHybridevent-driven for ownership and statusLight periodic review, but youneed real-time signals onthe attributes that change often.e.g. fast-growing SMB merchant baseHIGH RISK · VOLATILEPerpetual KYBnon-negotiablePeriodic alone leaves you inenforcement-action territory.Continuous detection is the floor.e.g. crypto exchanges, cross-border B2B fintechSource: Global Database analysis · 2026 · Plot your portfolio's centre of mass to identify the right model

Plot your portfolio on the matrix. Where most of your customers cluster tells you which model — or which hybrid — fits.

The honest summary: periodic KYB tells you what a company looked like at your last review. Perpetual KYB tells you what changed since then. One is a snapshot. The other is a feed. But the feed is only useful if it surfaces signal — not noise.

The KYB Risk Window: What Actually Happens Between Reviews

Every compliance program has a risk window. It is the time between when something changes and when you find out. With annual reviews, the window can stretch to 12 months. Quarterly reviews shrink it to three. It never closes completely.

Here is what can happen inside that window:

EventRisk if missedHow fast it can occur
Beneficial owner changeExposure to sanctioned or high-risk individualsDays (single share transfer)
Director resignation or appointmentLoss of visibility into who controls the entityImmediate (board decision)
Company status changeTransacting with a dissolved or inactive entityDays (registry update)
Sanctions list additionRegulatory violation, financial penaltySame day (OFAC, EU, UN updates)
Adverse mediaReputational and compliance riskHours (news cycle)
Jurisdiction changeExposure to high-risk geographyWeeks (re-registration)
Merger or acquisitionUnknown new ownership structureWeeks to months
Insolvency filingCounterparty and credit riskDays (court filing)

None of these wait for your review calendar.

The standard scenario goes like this. You onboard a supplier in March. Clean verification. Low risk. Next scheduled review: the following March. In September, the majority shareholder sells to a foreign investor with indirect ties to a sanctioned entity. You don't know. Your records still show the original ownership. You keep transacting. Six months later, your annual review catches the change — or, more often, a regulator does.

That six-month gap is your exposure. Multiply it across a portfolio of thousands and the math gets uncomfortable.

What Regulators Actually Expect

The most common question we get from compliance leads is whether perpetual KYB is required by law. The honest answer is: not by name. But the language across major frameworks has shifted hard toward continuous oversight.

RegulationJurisdictionWhat it says about ongoing monitoring
FinCEN CDD RuleUnited StatesRequires "ongoing monitoring to identify and report suspicious transactions" and updating customer info on a risk basis
6th Anti-Money Laundering Directive (6AMLD)European UnionMandates "ongoing monitoring of the business relationship including scrutiny of transactions"
Money Laundering Regulations 2017United KingdomRequires "ongoing monitoring of a business relationship" including keeping documents and information up to date
FATF Recommendation 10Global standardCDD includes "ongoing due diligence on the business relationship and scrutiny of transactions"
OFAC Reporting, Procedures and Penalties RegulationsUnited StatesEffective 21 March 2025, recordkeeping period extended from 5 to 10 years for sanctions-related transactions

The pattern is consistent. Verification at onboarding is not enough. You are expected to maintain a current view throughout the relationship. Periodic reviews still satisfy the letter of the rule for low-risk relationships, but enforcement actions tell a different story.

Worth Noting

Global enforcement penalties actually fell 18% in 2025 to $3.8B according to Fenergo's annual review — but the regional shift matters more than the headline. North American fines dropped 58%, while EMEA fines rose 767% and APAC rose 44%. The largest single penalty of 2025, $985m, went to a Swiss bank from French authorities. Translation: the geography of enforcement is changing. Where you operate matters.

What Recent Enforcement Actions Actually Say

Below are the enforcement cases worth understanding. Read past the headlines and look at the failure mode.

OrganisationDatePenaltyWhat actually went wrong
TD BankOct 2024$3.09B92% of transactions ($18.3T) unmonitored Jan 2018–Apr 2024. Transaction monitoring program "effectively static" 2014–2022. First U.S. bank to plead guilty to money-laundering conspiracy.
OKX (Aux Cayes Fintech)Feb 2025$500M+Allowed users to trade without adequate KYC; facilitated billions in suspicious transactions.
Block Inc. (Cash App)Apr 2025$40MNYDFS found AML screening lapses. Onboarding outpaced compliance growth. Earlier $80M state-money-transmitter settlement in January 2025.
RobinhoodApr 2025$45MFailed to report suspicious activity in a timely manner; cybersecurity and identity-theft control gaps.
RevolutApr 2025€3.5MLithuanian central bank fine for deficiencies in monitoring business relationships and operations.
Monzo BankJul 2025£21.1MFCA: weaknesses across CDD, ongoing monitoring, treatment of high-risk customers, and SAR filing. Growth outpaced compliance maturity.
BarclaysJul 2025£42MFCA: serious weaknesses in identifying and managing financial crime risk in two high-risk client relationships.
Coinbase (Ireland)2025€21MCentral Bank of Ireland: breaches of AML/CTF monitoring obligations 2021–2025.
NationwideDec 2025£44MFCA: transaction monitoring failures that enabled £27.3m of COVID furlough fraud.

Look at what these cases share. They are not onboarding failures. They are not even necessarily intent failures. They are monitoring failures: institutions that verified at onboarding and then could not see — or did not act on — what changed afterward. The regulators in 2025 are no longer asking "Did you verify?" They are asking "When did you know?"

FIG 03 · ENFORCEMENTAll cited inadequate ongoing monitoringSelected 2024–2025 fines, USD equivalent. Onboarding was not the issue.USD · log scale$3B$1B$300M$100M$30M$3.09BTD BankOct 2024$500M+OKXFeb 2025£44MNationwideDec 2025$45MRobinhoodApr 2025£42MBarclaysJul 2025$40MBlock Inc.Apr 2025£21.1MMonzoJul 2025Sources: FinCEN, FCA, NYDFS, Central Bank of Ireland, Bank of Lithuania · 2024–2025

Different geographies, different sectors, identical failure mode: monitoring breakdowns after onboarding.

How Global Database Solves This
Registry-sourced data, event-driven monitoring

The next section walks through the full pipeline — collection, storage, resolution, digitisation, propagation. The short version: changes surface the day they happen at the registry, not when your calendar says it's time to check. Every data point is timestamped and traceable, so your audit trail answers the question regulators actually ask: when did you know?

How Global Database approaches Perpetual KYB

Most of this article has talked about what perpetual KYB should do. This section is what we actually do — the data path from a registry filing in one country to a same-day update on every customer in your portfolio.

The whole pipeline is built around one principle: your team should never need to ask a registry "anything new?" If something moved, you should already know.

FIG 04 · GLOBAL DATABASE PIPELINEFrom registry filing to your alert queueFive steps. Same day. No polling on your side.1COLLECTPulled at source, every dayData is taken directly from 400+ official government registries.No aggregators, no scrapers, no resold third-party feeds.2STOREEU-jurisdiction infrastructureHetzner data centres in Germany. GDPR-aligned by default.Sovereignty matters when an auditor asks where the data lives.3RESOLVEMapped, normalised, enrichedNew filings are matched to existing records. Names, addresses,and identifiers are resolved across jurisdictions.4DIGITISEFiled accounts extracted with OCR + AIFinancial statements filed as PDFs or scans become structuredfields — up to 20 years of history in some jurisdictions.5PROPAGATE · OUTPUTSame-day update to every monitored entityWhen a registry filing changes a company in your portfolio, thechange lands the same day — via API webhook, bulk feed, or platform alert.PRICING MODELPay once. Unlimited updates for every monitored company across the year.Source: Global Database infrastructure · 2026

The whole loop runs daily. Your team stops asking the registry "anything new?" — we tell you when there is.

Step 1 — Pulled at source, every day

We connect directly to over 400 official government registries. Daily ingestion. No aggregators in the middle, no scrapers, no resold third-party feeds. Each data point is tagged with the registry it came from and the timestamp it was retrieved.

This is the difference between knowing a director changed and knowing the registry filing is dated 14 March, was published by Companies House, and was retrieved by us at 06:42 UTC the same day. Auditors care about the second version.

Step 2 — Stored on EU-jurisdiction infrastructure

The data sits on Hetzner servers in Germany. GDPR-aligned by default. When your DPO or your auditor asks where the underlying data lives — a question that comes up more often in 2026 than it used to — the answer is short: Frankfurt, with a German data-processing contract.

Step 3 — Mapped, normalised, enriched

A new filing on its own is just a new row. The work happens in the resolution layer: matching that filing to the company already in our graph, reconciling the names and identifiers across jurisdictions, updating the ownership chain, and merging it with the existing record. By the time the data reaches you, the change is already in context — not floating loose.

Step 4 — Filed accounts digitised with OCR + AI

A lot of registry-filed financial accounts arrive as PDFs or scanned documents. They get extracted into structured fields automatically — balance sheet, P&L, cash flow, ratios. In some jurisdictions you get up to 20 years of digitised history. Credit and risk teams use this to track financial trajectory; compliance teams use it to flag anomalies.

Step 5 — Same-day update, unlimited, across your portfolio

This is where the model diverges sharply from periodic KYB. Under a periodic program, you'd schedule lookups against every monitored company on a calendar, paying per call, hoping the timing aligns with reality. With Global Database, every company you monitor automatically receives the update the same day a filing changes any of the following:

FIG 05 · WHAT WE MONITOREvery attribute that can changeIf a registry filing moves it, you get the update the same day.COMPANY IDENTITYCompany nameStatusRegistered addressWebsiteEmailPhoneCONTROL & OWNERSHIPDirector / officer changesNew director appointmentsShareholder changesNew shareholder filingsGroup structure changesNew group appointmentsRISK & FINANCIALSFiled financial accountsCompany status(active / dissolved / liquidating)PEP and sanctions hitsFREQUENCYSame day a filing hits the registry. No throttle, no per-call cost.Source: Global Database coverage · 2026

A periodic-only program would need scheduled lookups to catch any of these. We push them as they happen.

The pricing model matters here. With periodic verification you pay per lookup — and most of those lookups return "nothing changed," which is the most expensive answer in compliance. With Global Database's perpetual model, you pay once for the relationship and get unlimited updates across the year. Your cost per actual material finding goes down. Your cost per "we checked, nothing happened" goes to zero.

In Practice

A compliance team monitoring 5,000 suppliers under a periodic program might run 5,000 scheduled lookups per quarter — 20,000 calls a year, of which fewer than 200 return a meaningful change. With Global Database, those 200 changes surface the day they happen. The remaining 19,800 calls don't exist, because no one had to make them.

The Hybrid Reality: Most Mature Programs Don't Pick One

Vendor marketing tends to frame periodic vs. perpetual as a binary. The teams actually getting this right run a hybrid. Different attributes change at different speeds and carry different materiality. Treat them differently.

AttributeVolatilityRight monitoring approach
Sanctions / watchlist hitsSame-dayContinuous, immediate alert
Beneficial ownershipDays to weeks when it changesEvent-driven (registry change detection)
Directors / officersDays to weeksEvent-driven
Company status (active/dissolved)DaysEvent-driven
Adverse mediaHoursContinuous feed with NLP filtering
Financial filings (annual accounts)AnnualPeriodic refresh aligned to filing cycle
Business model / activity changesSlow but material when they happenPeriodic refresh + transaction-pattern triggers
Relationship attestation (do we still want this customer?)AnnualPeriodic, risk-based

The right design uses trigger-based monitoring for high-volatility, high-materiality attributes and reserves the periodic review for things that don't move fast — and for the human attestation that the relationship still makes sense at all.

Building a Perpetual KYB Program That Actually Works

Switching is not a software upgrade. The teams who try to bolt continuous monitoring onto a stale data foundation end up with the same problem in faster cycle times. The four pillars that matter:

1. Data quality at source

If the underlying data is stale, aggregated, or scraped, monitoring just amplifies the rot. What to look for: data sourced direct from government registries (not aggregators), updated as registries update, with full ownership chains and standardised formatting across jurisdictions. If your provider can't tell you which registry a specific data point came from and when it was last fetched, your audit trail has a hole in it.

2. Detection method, not just frequency

The honest test: ask your vendor whether they detect changes at the source or compare daily snapshots. If it's the latter, factor in the cost of analyst time spent on noise. A "real-time" tool that fires on formatting changes is not actually real-time — it is just fast and wrong.

3. Configurable materiality

Not every change needs a same-day alert. A robust program lets you set thresholds per change type (alert on UBO change >10%, ignore changes <5%), per jurisdiction (immediate escalation for sanctioned geographies, batch review for stable ones), and per entity type (stricter monitoring for PEP-linked entities). Without configuration, every change gets equal weight, which defeats the entire point.

4. Workflow integration

Detection without action is just timestamped noise. The alert needs to land in your case-management system, update the entity's risk score, generate the audit log entry, and route to the right analyst tier. If your team is copy-pasting alerts into a separate ticketing tool, you've automated detection and re-introduced manual work somewhere else.

Diagnostic

Ask your current vendor three questions. One: "Where does this specific data point come from, and when was it last updated at source?" Two: "What percentage of the alerts you generated for our portfolio last quarter resulted in a material finding?" Three: "Can I configure which changes generate alerts and which don't?" The answers tell you whether you have a perpetual KYB system or a polling system in marketing clothing.

Related Reading on Global Database

Start using registry-sourced KYB data

Pick the channel that fits your team

Same data, same registries, same updates. Three delivery models depending on whether you're an engineer wiring it into onboarding, a platform enriching a portfolio, or a compliance lead who needs a workspace.

Bulk data

For platforms & large enterprises

Full-portfolio enrichment, structured feeds, and reseller licensing. Built for scale: millions of companies, recurring deltas.

Volume pricing · custom contracts

Request a quote

Online platform

For compliance teams

Web workspace to search, monitor, and investigate. No code, no integration. Set materiality thresholds and receive alerts as registries change.

Subscription · per-seat pricing

See platform pricing

Not sure which fits? Talk to our team — 20 minutes, no slides.

Frequently Asked Questions

What is perpetual KYB monitoring?

Perpetual KYB is the continuous, event-driven verification of a business customer after onboarding. Instead of re-verifying on a fixed schedule, the system tracks ownership, directors, status, sanctions, and adverse media, and triggers a review only when something material changes. It is also called pKYB, continuous KYB, or event-driven KYB. The aim is to close the gap between onboarding verification and the next scheduled review.

What is the difference between periodic KYB and perpetual KYB?

Periodic KYB reviews business customers on a fixed schedule — typically annually or quarterly. Perpetual KYB monitors continuously and reviews when data changes. Periodic tells you what a company looked like at your last review. Perpetual tells you what changed since then. The difference shows up in detection speed: 12 months vs. hours, depending on the source.

Is perpetual KYB legally required?

Not by name. No major framework — FinCEN CDD, 6AMLD, UK MLRs, FATF Recommendation 10 — uses the term "perpetual KYB." But all of them require ongoing monitoring of the business relationship, including keeping customer information up to date. Periodic reviews satisfy the literal rule for low-risk relationships. They increasingly fail the practical test when enforcement actions reference detection gaps rather than onboarding errors.

How often should KYB reviews be conducted?

Match frequency to risk. Low-risk: every 24–36 months. Medium-risk: annually. High-risk: every six months or less. Very high-risk relationships (PEP exposure, complex offshore structures, sanctions-adjacent jurisdictions): continuous monitoring is the more defensible model. Most regulators expect a documented risk-based approach rather than a uniform calendar.

What is the KYB risk window?

The time between when a material change happens to a counterparty and when your compliance team finds out. With annual reviews, the window can stretch to 12 months. With continuous monitoring done well — registry-direct, event-driven — it collapses to the same day. Recent enforcement actions — Monzo, Barclays, Nationwide, TD Bank — consistently cite that gap as the failure point.

What causes alert fatigue in continuous KYB monitoring?

Polling-based detection. Most "real-time" KYB tools query registries on a daily schedule and flag any data difference, including formatting noise: address reformatting, capitalisation changes, timestamp refreshes, alphabetical re-sorting of director lists. Analysts spend hours dismissing non-material differences and start to deprioritise the queue. Event-driven detection — where changes are identified at the registry source rather than inferred from snapshot diffs — typically reduces alert volume by 80–90%.

What events should trigger a KYB review?

The high-priority triggers: new beneficial owner, director appointment or resignation, company status change, sanctions list addition, adverse media, jurisdiction change, merger or acquisition, insolvency filing. The lower-priority triggers: business activity reclassification, address change, contact update. Effective programs treat these differently — same-day alert for sanctions, batched review for non-material updates.

What is the difference between event-driven and polling-based KYB monitoring?

Polling-based monitoring queries registries on a fixed schedule (usually daily) and flags any difference between today's snapshot and yesterday's. Event-driven monitoring detects actual changes at the registry source as part of continuous data ingestion. Polling treats every diff as a potential change. Event-driven only surfaces what genuinely changed. Both can be marketed as "continuous" — only one reduces analyst workload.

How much can perpetual KYB reduce compliance workload?

Industry estimates put the saving at 50–90% of routine review labour, depending on the maturity of the previous program and the quality of change detection. Oliver Wyman put periodic file reviews at 30–40% of large-bank AML/CFT budgets in 2024. Strise reports up to 90% review-workload reduction for clients moving from periodic to event-driven. The catch: the savings only materialise if the change detection is event-driven. Polling-based "perpetual" tools often increase workload by adding noise on top of the original review cadence.

Should I run periodic KYB and perpetual KYB together?

For most mature programs, yes. Different attributes move at different speeds. Sanctions, ownership, directors, and status changes belong on event-driven monitoring. Annual financial filings, full relationship attestation, and risk-rating reviews still benefit from a scheduled cadence. The hybrid approach — continuous monitoring for high-volatility data, periodic refresh for low-volatility attributes — is what most regulators implicitly expect when they reference a "risk-based approach."

Related posts

View more