Periodic Review Is Dead. It Just Doesn't Know It Yet.

Periodic review cycles guarantee outdated files. Discover why static KYC monitoring fails and how continuous risk assessment replaces broken compliance controls.

Sep 10, 2026arik oslerne1 min read
Periodic Review Is Dead. It Just Doesn't Know It Yet.

Periodic Review Is Dead. It Just Doesn't Know It Yet.

High-risk files every year, medium every two or three, low every five. An analyst opens a file that's been sitting untouched since the last cycle, discovers the world has moved on - directors changed, ownership restructured, documents expired - and spends hours reconstructing what happened and when. Multiply by the whole book, and periodic review becomes one of the largest cost lines in compliance.

Now ask the awkward question: what is this control actually for? It exists to ensure files reflect reality. And its core design guarantees they don't, because between reviews, which is almost all of the time, the file is officially allowed to be wrong.

A three-year review cycle isn't a monitoring program. It's a formal commitment to being up to three years out of date.

The design flaw

Risk changes on the world's schedule, not yours. The sanctions designation, the adverse media story, the ownership restructuring, the sudden change in transaction behaviour - these happen when they happen. A calendar-based control catches them, on average, half a review cycle late. For a medium-risk file on a three-year cycle, that's eighteen months of exposure as the baseline design assumption.

And the cost structure is exactly backwards. Periodic review spends the same effort on every file in the tranche - the 95% where nothing happened get the same full re-papering as the 5% where something did. You pay maximum cost for maximum staleness. It's hard to design a worse trade on purpose.

Everyone in the industry knows this. The cycle survives because it's auditable, budgetable, and traditional - the three great preservatives of broken process.

Perpetual KYC: the obvious idea that used to be impossible

The alternative has a name - perpetual KYC, or pKYC - and a simple logic: monitor continuously, act on events. Watch the registries, the screening lists, the adverse media, the document expiries, the transaction patterns. When something changes, refresh what changed, when it changed. When nothing changes, leave the file alone - and be able to prove you were watching.

Files stay current instead of averaging eighteen months stale. Effort concentrates on the files where reality moved. Risk response time drops from months to days.

So why doesn't everyone do this already? Because until recently it was operationally impossible. Continuous monitoring across thousands of files meant either an army of analysts refreshing constantly - the cost problem periodic review was invented to avoid - or crude automated alerts that buried the team in noise. The idea was always right. The economics weren't.

That's what changed. AI that can read a registry filing, compare it to the file, decide whether the change is material, and update the record - at machine cost, on every file, every day - turns pKYC from a conference-panel aspiration into an operating model.

The regulatory wind is blowing one direction

This isn't just an efficiency argument. Look at where the rulebooks are going: Europe's AMLA is right now consulting on guidelines for ongoing monitoring of business relationships under the new AML Regulation. The direction is unambiguous - supervisors increasingly expect files to reflect current reality, not last cycle's snapshot. "We would have caught it at the next review" is aging badly as a defence, and by the time the new regime bites in 2027, it may not be a defence at all.

The firms that move early get to design their transition. The firms that wait will have it designed for them, under deadline.

How to actually get there

Nobody flips a book of fifty thousand files to pKYC on a Tuesday. The realistic path:

1. Instrument before you transform

Start by switching on the monitoring feeds - registry changes, screening deltas, media, expiries - across the whole book, while keeping the periodic cycle running. You immediately learn how often reality actually changes per segment, which is the data every subsequent decision needs.

2. Kill the noise problem first

pKYC dies if every registry hiccup becomes an analyst task. The materiality filter: “is this change relevant to risk?” is the make-or-break component, and it's precisely where AI earns its keep: reading the change in context of the file and triaging like an experienced analyst rather than a keyword rule.

3. Convert by segment, prove the equivalence

Move a segment - say, low-risk entities - to event-driven refresh, and run the numbers against the periodic baseline: staleness, risk-event response time, cost per file. Take the evidence to your regulator relationship, not a philosophy. Supervisors respond better to measured equivalence than to enthusiasm.

4. Redeploy the reviews you kill

The analyst hours reclaimed from re-papering unchanged files are the budget for deeper work on the files that matter - the complex structures, the SOW gaps, the escalations. pKYC done right doesn't shrink the team's impact. It relocates it.

Where Steward fits

Steward was built AI-first around exactly this model: every file continuously watched, every change read and triaged in context, every refresh evidenced, with your team supervising decisions instead of performing archaeology. Not a dashboard bolted onto a periodic process - the replacement for the periodic process.