Learn more about the latest security and privacy threats

Review desk

KYC periodic review and refresh desk

The file was built at onboarding and it was good. Three years on, nobody has confirmed the address, the ownership or the risk rating still hold, and the review cycle has quietly become a backlog with a date on it. This desk works that cycle continuously instead of annually.

Periodic review · falling due 3 changes CHECKED AGAINST THE FILE YOU HOLD Registered address Unchanged Directors Unchanged Beneficial ownership New owner above your threshold Sanctions and PEP screening New designation on a related party Identity document Expired since last review Declared activity Unchanged Refreshed risk profile prepared AWAITING YOUR APPROVAL

In short: KYC periodic review, also called ongoing due diligence or KYC refresh, is the work of re-verifying existing customers on a schedule or when something changes. Zyphe runs it as an operated desk: agents pull the file you already hold, re-run the checks your policy requires for that risk tier, and compare the result against what was decided last time. The output is a diff, not a fresh dossier, so your reviewer reads what actually changed. Your team approves the refreshed risk profile, which AMLR Article 18(3)(c) reserves to your firm.

Desk description last reviewed 2026-08-20.

What arrives at this desk?

The work this desk takes off your team, stated as the queue it actually receives.

Scheduled reviews falling due

Customers reaching their review date under your risk tiering, in the volume your cycle actually produces rather than the volume your team can absorb.

Trigger-event reviews

A change of control, a new director, an address change, a new designation touching the customer, or activity that falls outside the profile they declared.

Remediation backlogs

Files built to a standard that has since moved, or inherited from a book you acquired, where the gap is known and the re-papering has never had an owner.

Post-migration re-papering

Customers carried across from a previous provider whose evidence you hold but did not gather, and cannot fully vouch for.

How does the KYC periodic review and refresh desk work?

Five steps, the same way every time, because consistency is what an audit is actually testing for.

  1. 1

    Pull the file you already hold

    The agent starts from what was decided at onboarding or at the last review, and on what evidence, so the review measures change rather than starting from a blank page.

  2. 2

    Re-run what your policy requires

    Identity, address, corporate registry, ownership and screening checks are re-run to the depth your policy sets for that risk tier, not to a single depth applied to everybody.

  3. 3

    Diff against the file

    The output is the delta. Unchanged items are marked unchanged and take none of your reviewer's attention. This is the step that turns a periodic review from a re-read into a decision.

  4. 4

    Flag what actually matters

    A new beneficial owner, a designation on a related party, an expired identity document, a registry filing that contradicts what you hold, or activity outside the declared profile.

  5. 5

    Prepare the refreshed file

    Findings, evidence and dates are assembled into a file your reviewer can approve, with any exception listed explicitly rather than left as a silent gap.

What we prepare, and what you approve.

Agent-prepared, human-approved is not a hedge in the marketing copy. It is the shape EU law requires, and it is the reason this desk can be bought by a regulated firm at all.

What the Zyphe agent prepares, and what your team approves, at each stage of the review
Stage The agent prepares Your team approves
Re-verification Re-runs the checks and records the source and date of each Accepts the evidence, or asks for more
What changed Produces the diff and flags the material changes Decides which changes matter
Refreshed risk profile Assembles everything bearing on the rating Sets the refreshed risk profile AMLR Art. 18(3)(c)
The relationship Prepares the file for a decision Decides whether to continue, restrict or exit AMLR Art. 18(3)(d)
Review policy Applies the cycles and triggers you defined Owns and approves the review policy itself AMLR Art. 18(3)(b)

Why the split is drawn there

Article 18 of Regulation (EU) 2024/1624, the EU anti-money laundering regulation that applies from 10 July 2027, permits obliged entities to outsource tasks to service providers, and requires the supervisor to be notified before the provider starts. Article 18(2) then treats the service provider as part of the obliged entity, leaves the entity fully liable, and requires it to be able to demonstrate to its supervisor that it understands the rationale behind the activities the provider carries out. Article 18(3) lists tasks that cannot be outsourced under any circumstances. Every one of them sits on your side of this table.

That demonstrability requirement is the reason each case leaves this desk with its reasoning written out rather than with a score. A confidence number cannot be explained to a supervisor. A rationale can.

What this desk will not do

  • Set your review cycles or trigger definitions
  • Decide the refreshed risk rating
  • Waive a missing document or an unmet standard
  • Offboard a customer
  • Mark a file complete when evidence is missing

What do you actually receive?

A decision-ready file, in the systems you already run.

  • A diff, not a dossier: what changed since the last review, and what did not
  • Refreshed evidence with its source and the date it was obtained
  • The cycle worked continuously rather than in an annual scramble
  • Exceptions listed explicitly, with what is missing and what would close it

The software behind this desk

If you would rather run the work yourself than have it operated, these are the same capabilities as a product surface.

Frequently asked questions about KYC periodic review and refresh.

What is a KYC periodic review?

A KYC periodic review is a scheduled re-examination of an existing customer to confirm that the identity, ownership, activity and risk information on file is still accurate and still supports the risk rating you assigned. It sits alongside trigger-based reviews, which happen when something specific changes, and together they make up ongoing due diligence.

How often do customers have to be reviewed?

The EU framework requires ongoing monitoring and keeping customer documents and data up to date on a risk-sensitive basis rather than fixing one universal interval. In practice that means your policy sets the cycles by risk tier and defines the trigger events, and your supervisor will test whether you applied your own policy consistently. Under AMLR Article 18(3)(b), approving that policy is not a task you can outsource.

What is perpetual KYC, and is this the same thing?

Perpetual KYC replaces fixed review dates with continuous, event-driven review: the file updates when something changes rather than when a calendar date arrives. This desk supports either model. The reason teams move toward the perpetual version is usually operational rather than philosophical, because a fixed annual cycle concentrates the entire book's review work into a period nobody is staffed for.

Can you clear a remediation backlog?

Yes, and it is one of the more common ways teams start, because a backlog is a well-defined finite slice rather than an open-ended commitment. It runs alongside the live cycle so current reviews do not age while the backlog is worked, and every remediated file carries the same written reasoning as a new one.

Do customers have to be contacted during a review?

Usually far less often than teams assume. Most of what a periodic review confirms can be re-established from registries, screening sources and the records you already hold. Customer outreach is reserved for the items that genuinely cannot be refreshed from a source, which keeps the friction on your book proportionate to the risk.

Book a demo

Put the KYC periodic review and refresh queue on a desk.

Book a demo and bring a real slice of your queue. We will work it, show you the files, and you will see exactly what your team still has to approve.