A supplier you onboarded last March is now controlled by a sanctioned individual. The change happened in September. You don't know yet — your next review is scheduled for March. Six months of exposure, all of it sitting in a clean-looking compliance file.
This is the gap regulators have stopped tolerating. In 2025, the FCA fined Monzo £21.1m for failures across customer due diligence and ongoing monitoring. Nationwide was fined £44m in December for control failures that allowed £27.3m in COVID furlough fraud to slip through. Barclays was fined £42m. Revolut paid €3.5m to Lithuania's central bank for monitoring deficiencies. Coinbase paid €21m to the Central Bank of Ireland for failing its AML/CTF monitoring obligations between 2021 and 2025. Across the Atlantic, OKX paid more than $500m in February 2025. Block Inc. paid $40m in April.
None of these were onboarding failures. Every one of them was about what happened after onboarding — and how long it took the institution to notice.
That is the question this article answers: when periodic reviews stop being enough, and when continuous monitoring stops being a slogan and starts being a control.
What is Periodic KYB?
Periodic KYB is the traditional model. You verify a business at onboarding, then re-verify on a fixed schedule — typically annually for standard-risk customers, every six months or quarterly for higher-risk ones, and every two to five years for the lowest-risk segment.
The cycle is predictable:
- Collect — registration documents, proof of address, corporate filings.
- Verify — ownership, directors, beneficial owners.
- Screen — sanctions, PEP databases, watchlists, adverse media.
- Score — assign a risk rating.
- Document — store everything for audit.
- Wait — until the calendar says otherwise.
The model emerged from early AML regulations focused on the moment of onboarding. For decades, regulators accepted it. Auditors signed off. Whole compliance teams were structured around scheduled cycles.
It still has real advantages. The schedule is predictable, the costs are budgetable, the workload can be staffed, and batch processing works at scale. For a portfolio of low-risk, stable counterparties, periodic KYB is not broken.
The structural flaw is that it assumes nothing changes between reviews. A company you verified in January is not looked at again until the following January. In that window, beneficial owners can change, sanctions lists can update, directors can resign, adverse media can surface, and corporate status can shift. None of it triggers a review. The file sits untouched until the calendar moves it.
That gap is where most of the recent enforcement actions live.
What is Perpetual KYB?
Perpetual KYB — also called pKYB, continuous KYB monitoring, or event-driven KYB — replaces the calendar with the data. Reviews are not scheduled. They are triggered.
The logic:
- Connect — link customer records to live data sources: corporate registries, sanctions lists, adverse media feeds, ownership databases.
- Monitor — watch for material changes continuously.
- Detect — when a change happens (new UBO, director resignation, status change, sanctions hit), surface it.
- Alert — flag the change to the compliance team.
- Review — investigate and act.
There is no annual review date. The data tells you when to act.
Perpetual KYB is the operational extension of KYB into the lifecycle of a business relationship. Verification at onboarding establishes a baseline. Continuous monitoring keeps that baseline current. Together they form a single control, not two disconnected processes.
The Core Difference, in One Question
Periodic KYB asks: "Is this company still compliant based on our last review?"
Perpetual KYB asks: "Has anything changed since we last looked?"
One is backward-looking. The other is forward-looking. The difference shows up in how fast you catch a problem.
Both programs run for 12 months. The difference is how much of that year leaves you exposed to a change you haven't detected.
Where Most Teams Get the Implementation Wrong
Here is where the conversation usually goes off the rails. Vendors call their products "perpetual" or "real-time." Compliance teams switch on continuous monitoring expecting cleaner risk signals. Within a quarter, analysts are buried in alerts.
The problem is not perpetual KYB. The problem is how the change is detected.
Polling-based monitoring
Most "real-time" KYB tools use polling. The system queries registries on a schedule — every day, sometimes more — pulls a fresh snapshot of every company in your portfolio, and compares it to yesterday's snapshot. Any difference triggers an alert.
The flaw: registry data does not change in the way these systems assume. Formatting shifts. A field gets reformatted. A timestamp updates. Capitalisation changes when a registry runs a maintenance script. The underlying facts are identical, but the polling system sees a difference and fires.
| What changed in the data feed | Material risk? | Polling system fires? |
|---|---|---|
| "123 Main Street" → "123 Main St." | No | Yes |
| "John Smith" → "JOHN SMITH" | No | Yes |
| Date format "01/05/2025" → "2025-05-01" | No | Yes |
| Phone number spacing changed | No | Yes |
| Director field re-sorted alphabetically | No | Yes |
| New beneficial owner added | High | Yes |
| Director added to OFAC SDN list | Critical | Yes |
Five out of seven alerts are noise. Two are real risk signals. That ratio gets worse the bigger the portfolio.
Event-driven detection
Event-driven monitoring works the opposite way. Instead of polling registries on your behalf, the data provider collects registry data continuously into its own infrastructure. When a material change happens at the source — a new shareholder filed, a status updated to "dissolved," an officer resigned — the provider sees it as part of the underlying ingestion. Your portfolio gets an alert because something genuinely changed, not because a string got reformatted.
Strise — one of the more credible operators in the space — reports that most periodic reviews show no material change and that event-driven workflows can cut review workload by up to 90%. That number is consistent with what we see when clients move from polling-based vendors to a registry-collected feed: alert volume drops by an order of magnitude, and the alerts that remain are worth investigating.
Which model fits your portfolio?
"Periodic vs perpetual" is the wrong framing. The right framing is: which mix fits the portfolio you actually run? Two variables decide it — how much regulatory and counterparty risk sits in your book, and how often material attributes change across that book. Plot your portfolio on the matrix below and the answer is usually obvious.
Plot your portfolio on the matrix. Where most of your customers cluster tells you which model — or which hybrid — fits.
The honest summary: periodic KYB tells you what a company looked like at your last review. Perpetual KYB tells you what changed since then. One is a snapshot. The other is a feed. But the feed is only useful if it surfaces signal — not noise.
The KYB Risk Window: What Actually Happens Between Reviews
Every compliance program has a risk window. It is the time between when something changes and when you find out. With annual reviews, the window can stretch to 12 months. Quarterly reviews shrink it to three. It never closes completely.
Here is what can happen inside that window:
| Event | Risk if missed | How fast it can occur |
|---|---|---|
| Beneficial owner change | Exposure to sanctioned or high-risk individuals | Days (single share transfer) |
| Director resignation or appointment | Loss of visibility into who controls the entity | Immediate (board decision) |
| Company status change | Transacting with a dissolved or inactive entity | Days (registry update) |
| Sanctions list addition | Regulatory violation, financial penalty | Same day (OFAC, EU, UN updates) |
| Adverse media | Reputational and compliance risk | Hours (news cycle) |
| Jurisdiction change | Exposure to high-risk geography | Weeks (re-registration) |
| Merger or acquisition | Unknown new ownership structure | Weeks to months |
| Insolvency filing | Counterparty and credit risk | Days (court filing) |
None of these wait for your review calendar.
The standard scenario goes like this. You onboard a supplier in March. Clean verification. Low risk. Next scheduled review: the following March. In September, the majority shareholder sells to a foreign investor with indirect ties to a sanctioned entity. You don't know. Your records still show the original ownership. You keep transacting. Six months later, your annual review catches the change — or, more often, a regulator does.
That six-month gap is your exposure. Multiply it across a portfolio of thousands and the math gets uncomfortable.
What Regulators Actually Expect
The most common question we get from compliance leads is whether perpetual KYB is required by law. The honest answer is: not by name. But the language across major frameworks has shifted hard toward continuous oversight.
| Regulation | Jurisdiction | What it says about ongoing monitoring |
|---|---|---|
| FinCEN CDD Rule | United States | Requires "ongoing monitoring to identify and report suspicious transactions" and updating customer info on a risk basis |
| 6th Anti-Money Laundering Directive (6AMLD) | European Union | Mandates "ongoing monitoring of the business relationship including scrutiny of transactions" |
| Money Laundering Regulations 2017 | United Kingdom | Requires "ongoing monitoring of a business relationship" including keeping documents and information up to date |
| FATF Recommendation 10 | Global standard | CDD includes "ongoing due diligence on the business relationship and scrutiny of transactions" |
| OFAC Reporting, Procedures and Penalties Regulations | United States | Effective 21 March 2025, recordkeeping period extended from 5 to 10 years for sanctions-related transactions |
The pattern is consistent. Verification at onboarding is not enough. You are expected to maintain a current view throughout the relationship. Periodic reviews still satisfy the letter of the rule for low-risk relationships, but enforcement actions tell a different story.
Global enforcement penalties actually fell 18% in 2025 to $3.8B according to Fenergo's annual review — but the regional shift matters more than the headline. North American fines dropped 58%, while EMEA fines rose 767% and APAC rose 44%. The largest single penalty of 2025, $985m, went to a Swiss bank from French authorities. Translation: the geography of enforcement is changing. Where you operate matters.
What Recent Enforcement Actions Actually Say
Below are the enforcement cases worth understanding. Read past the headlines and look at the failure mode.
| Organisation | Date | Penalty | What actually went wrong |
|---|---|---|---|
| TD Bank | Oct 2024 | $3.09B | 92% of transactions ($18.3T) unmonitored Jan 2018–Apr 2024. Transaction monitoring program "effectively static" 2014–2022. First U.S. bank to plead guilty to money-laundering conspiracy. |
| OKX (Aux Cayes Fintech) | Feb 2025 | $500M+ | Allowed users to trade without adequate KYC; facilitated billions in suspicious transactions. |
| Block Inc. (Cash App) | Apr 2025 | $40M | NYDFS found AML screening lapses. Onboarding outpaced compliance growth. Earlier $80M state-money-transmitter settlement in January 2025. |
| Robinhood | Apr 2025 | $45M | Failed to report suspicious activity in a timely manner; cybersecurity and identity-theft control gaps. |
| Revolut | Apr 2025 | €3.5M | Lithuanian central bank fine for deficiencies in monitoring business relationships and operations. |
| Monzo Bank | Jul 2025 | £21.1M | FCA: weaknesses across CDD, ongoing monitoring, treatment of high-risk customers, and SAR filing. Growth outpaced compliance maturity. |
| Barclays | Jul 2025 | £42M | FCA: serious weaknesses in identifying and managing financial crime risk in two high-risk client relationships. |
| Coinbase (Ireland) | 2025 | €21M | Central Bank of Ireland: breaches of AML/CTF monitoring obligations 2021–2025. |
| Nationwide | Dec 2025 | £44M | FCA: transaction monitoring failures that enabled £27.3m of COVID furlough fraud. |
Look at what these cases share. They are not onboarding failures. They are not even necessarily intent failures. They are monitoring failures: institutions that verified at onboarding and then could not see — or did not act on — what changed afterward. The regulators in 2025 are no longer asking "Did you verify?" They are asking "When did you know?"
Different geographies, different sectors, identical failure mode: monitoring breakdowns after onboarding.
The next section walks through the full pipeline — collection, storage, resolution, digitisation, propagation. The short version: changes surface the day they happen at the registry, not when your calendar says it's time to check. Every data point is timestamped and traceable, so your audit trail answers the question regulators actually ask: when did you know?
How Global Database approaches Perpetual KYB
Most of this article has talked about what perpetual KYB should do. This section is what we actually do — the data path from a registry filing in one country to a same-day update on every customer in your portfolio.
The whole pipeline is built around one principle: your team should never need to ask a registry "anything new?" If something moved, you should already know.
The whole loop runs daily. Your team stops asking the registry "anything new?" — we tell you when there is.
Step 1 — Pulled at source, every day
We connect directly to over 400 official government registries. Daily ingestion. No aggregators in the middle, no scrapers, no resold third-party feeds. Each data point is tagged with the registry it came from and the timestamp it was retrieved.
This is the difference between knowing a director changed and knowing the registry filing is dated 14 March, was published by Companies House, and was retrieved by us at 06:42 UTC the same day. Auditors care about the second version.
Step 2 — Stored on EU-jurisdiction infrastructure
The data sits on Hetzner servers in Germany. GDPR-aligned by default. When your DPO or your auditor asks where the underlying data lives — a question that comes up more often in 2026 than it used to — the answer is short: Frankfurt, with a German data-processing contract.
Step 3 — Mapped, normalised, enriched
A new filing on its own is just a new row. The work happens in the resolution layer: matching that filing to the company already in our graph, reconciling the names and identifiers across jurisdictions, updating the ownership chain, and merging it with the existing record. By the time the data reaches you, the change is already in context — not floating loose.
Step 4 — Filed accounts digitised with OCR + AI
A lot of registry-filed financial accounts arrive as PDFs or scanned documents. They get extracted into structured fields automatically — balance sheet, P&L, cash flow, ratios. In some jurisdictions you get up to 20 years of digitised history. Credit and risk teams use this to track financial trajectory; compliance teams use it to flag anomalies.
Step 5 — Same-day update, unlimited, across your portfolio
This is where the model diverges sharply from periodic KYB. Under a periodic program, you'd schedule lookups against every monitored company on a calendar, paying per call, hoping the timing aligns with reality. With Global Database, every company you monitor automatically receives the update the same day a filing changes any of the following:
A periodic-only program would need scheduled lookups to catch any of these. We push them as they happen.
The pricing model matters here. With periodic verification you pay per lookup — and most of those lookups return "nothing changed," which is the most expensive answer in compliance. With Global Database's perpetual model, you pay once for the relationship and get unlimited updates across the year. Your cost per actual material finding goes down. Your cost per "we checked, nothing happened" goes to zero.
A compliance team monitoring 5,000 suppliers under a periodic program might run 5,000 scheduled lookups per quarter — 20,000 calls a year, of which fewer than 200 return a meaningful change. With Global Database, those 200 changes surface the day they happen. The remaining 19,800 calls don't exist, because no one had to make them.
The Hybrid Reality: Most Mature Programs Don't Pick One
Vendor marketing tends to frame periodic vs. perpetual as a binary. The teams actually getting this right run a hybrid. Different attributes change at different speeds and carry different materiality. Treat them differently.
| Attribute | Volatility | Right monitoring approach |
|---|---|---|
| Sanctions / watchlist hits | Same-day | Continuous, immediate alert |
| Beneficial ownership | Days to weeks when it changes | Event-driven (registry change detection) |
| Directors / officers | Days to weeks | Event-driven |
| Company status (active/dissolved) | Days | Event-driven |
| Adverse media | Hours | Continuous feed with NLP filtering |
| Financial filings (annual accounts) | Annual | Periodic refresh aligned to filing cycle |
| Business model / activity changes | Slow but material when they happen | Periodic refresh + transaction-pattern triggers |
| Relationship attestation (do we still want this customer?) | Annual | Periodic, risk-based |
The right design uses trigger-based monitoring for high-volatility, high-materiality attributes and reserves the periodic review for things that don't move fast — and for the human attestation that the relationship still makes sense at all.
Building a Perpetual KYB Program That Actually Works
Switching is not a software upgrade. The teams who try to bolt continuous monitoring onto a stale data foundation end up with the same problem in faster cycle times. The four pillars that matter:
1. Data quality at source
If the underlying data is stale, aggregated, or scraped, monitoring just amplifies the rot. What to look for: data sourced direct from government registries (not aggregators), updated as registries update, with full ownership chains and standardised formatting across jurisdictions. If your provider can't tell you which registry a specific data point came from and when it was last fetched, your audit trail has a hole in it.
2. Detection method, not just frequency
The honest test: ask your vendor whether they detect changes at the source or compare daily snapshots. If it's the latter, factor in the cost of analyst time spent on noise. A "real-time" tool that fires on formatting changes is not actually real-time — it is just fast and wrong.
3. Configurable materiality
Not every change needs a same-day alert. A robust program lets you set thresholds per change type (alert on UBO change >10%, ignore changes <5%), per jurisdiction (immediate escalation for sanctioned geographies, batch review for stable ones), and per entity type (stricter monitoring for PEP-linked entities). Without configuration, every change gets equal weight, which defeats the entire point.
4. Workflow integration
Detection without action is just timestamped noise. The alert needs to land in your case-management system, update the entity's risk score, generate the audit log entry, and route to the right analyst tier. If your team is copy-pasting alerts into a separate ticketing tool, you've automated detection and re-introduced manual work somewhere else.
Ask your current vendor three questions. One: "Where does this specific data point come from, and when was it last updated at source?" Two: "What percentage of the alerts you generated for our portfolio last quarter resulted in a material finding?" Three: "Can I configure which changes generate alerts and which don't?" The answers tell you whether you have a perpetual KYB system or a polling system in marketing clothing.
Related Reading on Global Database
Start using registry-sourced KYB data
Pick the channel that fits your team
Same data, same registries, same updates. Three delivery models depending on whether you're an engineer wiring it into onboarding, a platform enriching a portfolio, or a compliance lead who needs a workspace.
API
For engineering teams
Modular endpoints for verification, ownership, UBO, financials, and monitoring. Wire it into your onboarding stack and case-management tools.
From $0.10 per company · pay per call
Read the API docsBulk data
For platforms & large enterprises
Full-portfolio enrichment, structured feeds, and reseller licensing. Built for scale: millions of companies, recurring deltas.
Volume pricing · custom contracts
Request a quoteOnline platform
For compliance teams
Web workspace to search, monitor, and investigate. No code, no integration. Set materiality thresholds and receive alerts as registries change.
Subscription · per-seat pricing
See platform pricingNot sure which fits? Talk to our team — 20 minutes, no slides.
Frequently Asked Questions
What is perpetual KYB monitoring?
Perpetual KYB is the continuous, event-driven verification of a business customer after onboarding. Instead of re-verifying on a fixed schedule, the system tracks ownership, directors, status, sanctions, and adverse media, and triggers a review only when something material changes. It is also called pKYB, continuous KYB, or event-driven KYB. The aim is to close the gap between onboarding verification and the next scheduled review.
What is the difference between periodic KYB and perpetual KYB?
Periodic KYB reviews business customers on a fixed schedule — typically annually or quarterly. Perpetual KYB monitors continuously and reviews when data changes. Periodic tells you what a company looked like at your last review. Perpetual tells you what changed since then. The difference shows up in detection speed: 12 months vs. hours, depending on the source.
Is perpetual KYB legally required?
Not by name. No major framework — FinCEN CDD, 6AMLD, UK MLRs, FATF Recommendation 10 — uses the term "perpetual KYB." But all of them require ongoing monitoring of the business relationship, including keeping customer information up to date. Periodic reviews satisfy the literal rule for low-risk relationships. They increasingly fail the practical test when enforcement actions reference detection gaps rather than onboarding errors.
How often should KYB reviews be conducted?
Match frequency to risk. Low-risk: every 24–36 months. Medium-risk: annually. High-risk: every six months or less. Very high-risk relationships (PEP exposure, complex offshore structures, sanctions-adjacent jurisdictions): continuous monitoring is the more defensible model. Most regulators expect a documented risk-based approach rather than a uniform calendar.
What is the KYB risk window?
The time between when a material change happens to a counterparty and when your compliance team finds out. With annual reviews, the window can stretch to 12 months. With continuous monitoring done well — registry-direct, event-driven — it collapses to the same day. Recent enforcement actions — Monzo, Barclays, Nationwide, TD Bank — consistently cite that gap as the failure point.
What causes alert fatigue in continuous KYB monitoring?
Polling-based detection. Most "real-time" KYB tools query registries on a daily schedule and flag any data difference, including formatting noise: address reformatting, capitalisation changes, timestamp refreshes, alphabetical re-sorting of director lists. Analysts spend hours dismissing non-material differences and start to deprioritise the queue. Event-driven detection — where changes are identified at the registry source rather than inferred from snapshot diffs — typically reduces alert volume by 80–90%.
What events should trigger a KYB review?
The high-priority triggers: new beneficial owner, director appointment or resignation, company status change, sanctions list addition, adverse media, jurisdiction change, merger or acquisition, insolvency filing. The lower-priority triggers: business activity reclassification, address change, contact update. Effective programs treat these differently — same-day alert for sanctions, batched review for non-material updates.
What is the difference between event-driven and polling-based KYB monitoring?
Polling-based monitoring queries registries on a fixed schedule (usually daily) and flags any difference between today's snapshot and yesterday's. Event-driven monitoring detects actual changes at the registry source as part of continuous data ingestion. Polling treats every diff as a potential change. Event-driven only surfaces what genuinely changed. Both can be marketed as "continuous" — only one reduces analyst workload.
How much can perpetual KYB reduce compliance workload?
Industry estimates put the saving at 50–90% of routine review labour, depending on the maturity of the previous program and the quality of change detection. Oliver Wyman put periodic file reviews at 30–40% of large-bank AML/CFT budgets in 2024. Strise reports up to 90% review-workload reduction for clients moving from periodic to event-driven. The catch: the savings only materialise if the change detection is event-driven. Polling-based "perpetual" tools often increase workload by adding noise on top of the original review cadence.
Should I run periodic KYB and perpetual KYB together?
For most mature programs, yes. Different attributes move at different speeds. Sanctions, ownership, directors, and status changes belong on event-driven monitoring. Annual financial filings, full relationship attestation, and risk-rating reviews still benefit from a scheduled cadence. The hybrid approach — continuous monitoring for high-volatility data, periodic refresh for low-volatility attributes — is what most regulators implicitly expect when they reference a "risk-based approach."