We have updated our Privacy Policy, click here for more information.
Thank you
Lead Business Services Analyst
First Derivative
The concept has been part of the financial crime conversation for a decade. What’s changed is whether firms can actually deliver it.
Perpetual KYC is the rare idea in financial crime compliance that almost nobody disputes, and that almost nobody has managed to deliver. For years it has been presented as the logical evolution of customer due diligence: if a customer’s risk can change at any moment, the process used to assess that risk should be capable of responding at any moment too.
Expansion into a new jurisdiction, a shift in ownership, an adverse media event, a change in transactional behaviour, these are all more meaningful signals than the simple passage of time. Yet most firms still anchor their reviews to a calendar: one, three or five years, regardless of what has actually changed.
And those changes aren’t rare. Moody’s analysis of company registry data found that 19% of EU companies had a change of registered address, and over 2% of UK companies had a change of ultimate beneficial owner, within a three-year window1 – material shifts that, under a fixed review cycle, can sit unassessed for years.
So why, after a decade of near-universal agreement, has perpetual KYC not become the industry standard? The barrier has never been regulatory or conceptual. It has always been operational. And it’s starting to close – not because ambition has changed, but because AI is finally capable of doing the one thing no amount of workflow automation ever could: telling genuine change from noise, at scale.
Periodic reviews get criticised for being disconnected from how risk actually moves – but they persisted for a practical reason, not a naive one. Financial institutions sit on enormous volumes of customer information: filings, sanctions updates, adverse media, transactional data. As firms connected more data sources, they didn’t get more clarity – they got more alerts and more work for teams already stretched thin.
The scale of that burden is well documented. According to the 2025 Financial Crime Benchmarking Survey, published by 1LoD and co-sponsored by First Derivative, 94% of banks identify high manual workloads as the key operating challenge in AML/KYC, and 60% rely on manual intervention for more than half of their processes.2 As one US financial crime leader put it: “TM, negative news screening, PEPs, screening, sanctions screening, periodic reviews – it’s not where we need it to be or where we want it to be.”
A decade of KYC technology investment made genuine progress – workflow platforms got faster, screening quicker, document collection more streamlined. But none of it touched the actual bottleneck as gathering information was never the hard part – determining whether it mattered was. Most institutions don’t have a data problem – they have an attention problem.
This is where AI earns its place at the centre of the perpetual KYC conversation. The relevant capability isn’t doing existing tasks faster – it’s AI’s ability to connect information across sources and assess whether new information actually changes a customer’s risk profile: precisely the judgment call that rules-based systems have never made well.
Graph-based entity resolution can trace beneficial ownership across thousands of corporate structures in a fraction of the time a human investigator would need, if they found the connection at all. Large language models can read an adverse media article in full, identify whether the individual named is the same entity as the customer on file, assess materiality against the existing risk profile, and surface a pre-assembled summary to an investigator – rather than simply flagging a keyword match for manual review. What previously required an experienced analyst to pull together across multiple systems can be presented, in context, before a human looks at the case.
Regulatory accountability still sits with the firm, not the algorithm, and explainability isn’t optional. Any AI-enabled operating model needs to be able to show a regulator not just what decision was reached, but why, and on what basis. But if investigators spend less time gathering and synthesising information, they can spend more of it on the judgment calls that genuinely need them.
Building an operating model around AI isn’t a single purchase decision. Drawing on our KYC transformation work with financial institutions globally, the firms that make the most progress treat it as a two-stage journey.
Stage one: get the foundations right. AI is only as good as the data, policy and governance it operates on. Feed it fragmented data and undocumented policy exceptions, and you don’t get perpetual KYC – you get perpetual noise. Foundation-building starts with a gap analysis across data, technology and operating model, combined with workshops with the teams who run KYC day to day.
Critically, it also means turning policy itself into something AI can act on consistently. Most due-diligence policies exist as long-form documents requiring a trained analyst to interpret – a form that AI can’t reliably reproduce unless policy has been translated into structured rules it can reference directly. Codifying policy this way, what we call ‘policy as code’, means moving the institutional knowledge that currently lives in the heads of experienced investigators into a form that can be applied consistently, audited transparently, and updated as regulations change. In our experience, it’s consistently the most high-leverage and most underestimated piece of groundwork at this stage.
Stage two: build the operating model that runs it. With the foundations in place, AI monitors data sources continuously, evaluates what has changed against defined policy, and routes anything requiring human judgment to the right person with the context already assembled. This is the critical distinction: perpetual KYC doesn’t mean reviewing every customer more often. It means continuous monitoring, not continuous investigation – most updates warrant no action, some warrant screening, a smaller number warrant escalation. Done well, scheduled review cycles compress or disappear, KYC teams spend their time on genuine risk, and regulatory conversations shift from defending a process to demonstrating a system – not because firms are assessing risk less rigorously, but because continuous monitoring identifies which customers genuinely need attention, and which don’t.
The destination hasn’t changed in a decade. What’s changed is that AI now gives firms a credible, structured path to it.
The same 1LoD survey found that 88% of firms say more than half of their AML/KYC processes still need to be automated, yet only 38% are currently using any AI or machine learning to do so.2 The gap between intent and execution is wide – and it’s precisely the gap that the right foundations work is designed to close.
The question is no longer whether perpetual KYC is achievable. AI has settled that. It’s what needs to be true in your organisation to get there. If you’re at the start of that journey, we offer a structured readiness assessment: a gap analysis across data, technology and operating model that turns your current state into a prioritised roadmap. If your foundations are already in place, we can help you design and pilot the AI-enabled operating model itself.
Whether you’re exploring perpetual KYC, evaluating your AI maturity, or defining a broader AI-enabled operating model, we’d be happy to discuss your current state and help build a roadmap to get you where you want to be.
Whether you’re looking to evaluate your current readiness with a structured gap analysis or ready to design and pilot an AI-enabled operating model, we are here to help you bridge the gap between intent and execution.
Nicola Magennis
Practice Lead
First Derivative LinkedIn profile Email
Lauren Onyeador
Practice Lead
First Derivative LinkedIn profile Email