The future of periodic reviews

On this page
Compliance teams can spend hours on a periodic review only to find that little or nothing has changed. Across a bank with hundreds of thousands of business customers, those reviews keep coming and the workload keeps piling up. But most of that work doesn’t have to wait for a scheduled review.
Capgemini estimates that going from calendar-based reviews to perpetual Know Your Customer (KYC) can eliminate 70–90% of periodic-review work.
AI offers a way to get there by evaluating customer information throughout the lifecycle and addressing issues when customer risk changes. If more work happens between scheduled reviews, periodic reviews may eventually no longer be needed.
What periodic reviews look like today
A periodic review typically involves the following stages, each of which can add time and manual work:
1. Find the file and define the requirements. Analysts locate the customer file, sometimes across legacy and newer formats, and determine what needs to be reviewed. Context can be difficult to reconstruct when another team handles the original onboarding. Analysts may also have to read through years of previous work to reconstruct the customer’s history.
2. Review for enhanced due diligence (EDD). Analysts review the evidence and conduct additional checks, often across several tools. Some may spend time checking documents that aren’t needed for the review.
3. Request and review additional information. If more information is needed, analysts request it from the customer and review the response. The request for information (RFI) process alone can take days.
4. Get approval. A separate quality assurance (QA) team may review the work before approving the case, adding another handoff.
Why the workload keeps growing
Duna’s conversations with 12 European financial institutions show how much work periodic reviews can create. Ten raised periodic reviews, remediation, or re-KYC as a challenge, and two said periodic reviews cost them more than onboarding.
Part of the problem is that analysts have to revisit decisions made years earlier. A high-risk factor can trigger another review even if the bank’s risk appetite has changed. The analyst may still have to review the customer more broadly to determine if the original concern still applies.
That level of work isn’t always needed. Draft guidance from the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) states that periodic reviews don’t always need the same depth and intensity. Banks can determine which information, data, or documents need updating based on the customer’s risk profile.
The guidance also notes that blanket requirements, such as automatically collecting expired documents regardless of risk, can create unnecessary operational and financial costs.
How AI changes scheduled reviews
AI agents can do most of the investigative work before a periodic review reaches an analyst, collecting and assessing individual pieces of evidence.
Within Duna’s AI-native compliance infrastructure, agents work alongside the policy engine, which evaluates the evidence against the bank’s policy. The policy engine identifies requirements that have been met, directs AI to investigate outstanding issues, and routes cases to an analyst when needed.
For banks, AI also needs to be bank-grade. A compliance team has to be able to show an internal auditor or supervisor how a decision was reached, the evidence behind it, and that the decision is repeatable. Duna preserves the evidence behind each decision and how it contributed to the outcome so the decision can be explained later.
This changes the review in three important ways:
1. Valid evidence can be reused. A policy may have changed since the customer’s last review, but that doesn’t mean all of the information needs to be collected again. Evidence already on file can be continuously evaluated against the current policy. For example, if a bank changes its periodic-review policy three years after onboarding, evidence from a passport already on file can be reused as long as it’s still valid. An out-of-date passport would require the customer to submit a new one.
2. The analyst starts with everything needed to conduct the review. Instead of collecting and reviewing basic information, the analyst can see what already satisfies the policy and which specific points still require investigation. A review might arrive with two issues to check rather than an entire customer record to reassess. That lets analysts focus only on issues that require their judgment.
3. Customer risk stays current between reviews. New information that comes in throughout the customer lifecycle can be evaluated as it arrives. For example, ongoing screening can detect a new sanctions or adverse-media hit, allowing the customer’s risk to be reassessed when the change occurs rather than waiting for the next scheduled review.
Responding to risk as it changes
Every institution in Duna’s research that discussed the issue wants to move from a fixed one-, three- or five-year cycle toward reviews triggered by an event such as change of address, ownership, sector code, or an alert. Findings also show that banks are already testing and using event-driven models, with perpetual KYC emerging as a strategic goal.
Duna’s findings also show why banks want to make that change, noting that events can uncover risks that scheduled reviews miss. The harder problem is deciding which changes should trigger a review. That requires the bank to define its policy first.
Regulation still puts limits on how far banks can move away from scheduled updates. When the EU Anti-Money Laundering Regulation (AMLR) takes effect in 2027, banks will be required to keep customer information up to date, with no more than one year between updates for certain higher-risk customers, and five years for others (Article 26(2)). The regulation also requires customer information to be reviewed when relevant circumstances change (Article 26(3)).
Banks can use these requirements as an opportunity to rethink the periodic-review cycle rather than simply adding more data collection to the process they already have.
Preparing for a future without periodic reviews
Periodic reviews tie compliance work to fixed points in time. AI changes that by allowing evidence to be evaluated and risk to be reassessed throughout the customer lifecycle.
Handling changes as they happen leaves less work for the next scheduled review. Eventually, banks may no longer need periodic reviews as we know them today.
Learn how Duna’s AI-native compliance infrastructure helps financial institutions move toward more targeted, event-driven reviews. Get in touch.
Compliance teams can spend hours on a periodic review only to find that little or nothing has changed. Across a bank with hundreds of thousands of business customers, those reviews keep coming and the workload keeps piling up. But most of that work doesn’t have to wait for a scheduled review.
Capgemini estimates that going from calendar-based reviews to perpetual Know Your Customer (KYC) can eliminate 70–90% of periodic-review work.
AI offers a way to get there by evaluating customer information throughout the lifecycle and addressing issues when customer risk changes. If more work happens between scheduled reviews, periodic reviews may eventually no longer be needed.
What periodic reviews look like today
A periodic review typically involves the following stages, each of which can add time and manual work:
1. Find the file and define the requirements. Analysts locate the customer file, sometimes across legacy and newer formats, and determine what needs to be reviewed. Context can be difficult to reconstruct when another team handles the original onboarding. Analysts may also have to read through years of previous work to reconstruct the customer’s history.
2. Review for enhanced due diligence (EDD). Analysts review the evidence and conduct additional checks, often across several tools. Some may spend time checking documents that aren’t needed for the review.
3. Request and review additional information. If more information is needed, analysts request it from the customer and review the response. The request for information (RFI) process alone can take days.
4. Get approval. A separate quality assurance (QA) team may review the work before approving the case, adding another handoff.
Why the workload keeps growing
Duna’s conversations with 12 European financial institutions show how much work periodic reviews can create. Ten raised periodic reviews, remediation, or re-KYC as a challenge, and two said periodic reviews cost them more than onboarding.
Part of the problem is that analysts have to revisit decisions made years earlier. A high-risk factor can trigger another review even if the bank’s risk appetite has changed. The analyst may still have to review the customer more broadly to determine if the original concern still applies.
That level of work isn’t always needed. Draft guidance from the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) states that periodic reviews don’t always need the same depth and intensity. Banks can determine which information, data, or documents need updating based on the customer’s risk profile.
The guidance also notes that blanket requirements, such as automatically collecting expired documents regardless of risk, can create unnecessary operational and financial costs.
How AI changes scheduled reviews
AI agents can do most of the investigative work before a periodic review reaches an analyst, collecting and assessing individual pieces of evidence.
Within Duna’s AI-native compliance infrastructure, agents work alongside the policy engine, which evaluates the evidence against the bank’s policy. The policy engine identifies requirements that have been met, directs AI to investigate outstanding issues, and routes cases to an analyst when needed.
For banks, AI also needs to be bank-grade. A compliance team has to be able to show an internal auditor or supervisor how a decision was reached, the evidence behind it, and that the decision is repeatable. Duna preserves the evidence behind each decision and how it contributed to the outcome so the decision can be explained later.
This changes the review in three important ways:
1. Valid evidence can be reused. A policy may have changed since the customer’s last review, but that doesn’t mean all of the information needs to be collected again. Evidence already on file can be continuously evaluated against the current policy. For example, if a bank changes its periodic-review policy three years after onboarding, evidence from a passport already on file can be reused as long as it’s still valid. An out-of-date passport would require the customer to submit a new one.
2. The analyst starts with everything needed to conduct the review. Instead of collecting and reviewing basic information, the analyst can see what already satisfies the policy and which specific points still require investigation. A review might arrive with two issues to check rather than an entire customer record to reassess. That lets analysts focus only on issues that require their judgment.
3. Customer risk stays current between reviews. New information that comes in throughout the customer lifecycle can be evaluated as it arrives. For example, ongoing screening can detect a new sanctions or adverse-media hit, allowing the customer’s risk to be reassessed when the change occurs rather than waiting for the next scheduled review.
Responding to risk as it changes
Every institution in Duna’s research that discussed the issue wants to move from a fixed one-, three- or five-year cycle toward reviews triggered by an event such as change of address, ownership, sector code, or an alert. Findings also show that banks are already testing and using event-driven models, with perpetual KYC emerging as a strategic goal.
Duna’s findings also show why banks want to make that change, noting that events can uncover risks that scheduled reviews miss. The harder problem is deciding which changes should trigger a review. That requires the bank to define its policy first.
Regulation still puts limits on how far banks can move away from scheduled updates. When the EU Anti-Money Laundering Regulation (AMLR) takes effect in 2027, banks will be required to keep customer information up to date, with no more than one year between updates for certain higher-risk customers, and five years for others (Article 26(2)). The regulation also requires customer information to be reviewed when relevant circumstances change (Article 26(3)).
Banks can use these requirements as an opportunity to rethink the periodic-review cycle rather than simply adding more data collection to the process they already have.
Preparing for a future without periodic reviews
Periodic reviews tie compliance work to fixed points in time. AI changes that by allowing evidence to be evaluated and risk to be reassessed throughout the customer lifecycle.
Handling changes as they happen leaves less work for the next scheduled review. Eventually, banks may no longer need periodic reviews as we know them today.
Learn how Duna’s AI-native compliance infrastructure helps financial institutions move toward more targeted, event-driven reviews. Get in touch.
Continue reading
Industries
Customers
Company
Resources

Industries
Customers
Company
Resources

Industries
Customers
Company
Resources


