TD Bank's $3 billion penalty for Bank Secrecy Act violations wasn't due to a single oversight. It stemmed from maintaining a static KYC program in a world where customer risk evolves daily. If you're still treating KYC as a one-time task, you're relying on a system regulators now see as inadequate.
This checklist guides you through transitioning from periodic reviews to continuous monitoring. It's about creating a system that detects risk changes before they lead to SAR failures.
Prerequisites
Before implementing perpetual KYC controls, ensure you have:
- Executive sponsorship with budget authority. Perpetual KYC requires vendor partnerships and system integration. You need someone who can approve contracts without waiting for the next planning cycle.
- Current KYC baseline documentation. Know what your existing program covers, where manual processes slow down reviews, and which customer segments trigger the most retrospective SARs.
- Access to your customer authentication and transaction monitoring systems. Perpetual KYC integrates with existing login sessions and transaction flows.
- Legal review of your customer privacy disclosures. You'll collect and verify data throughout the account lifecycle. Your terms of service must explain what you're monitoring and why.
Implementation Checklist
1. Map Your Current KYC Trigger Points
Document every instance your program verifies customer information: account opening, annual reviews, large transactions, address changes.
Done looks like: A process map showing every KYC checkpoint, the data collected at each point, and gaps where customer risk could change undetected.
2. Define Material Risk Changes
Specify events that should trigger immediate re-verification: address changes, sudden transaction pattern shifts, new counterparties in high-risk jurisdictions, PEP status changes, negative news hits.
Done looks like: A decision matrix with clear thresholds. "Three address changes in six months" triggers review. "Single wire to a sanctioned-country counterparty" triggers immediate escalation.
3. Select Your Perpetual KYC Technology Partner
Evaluate vendors offering real-time verification, automated negative news monitoring, and continuous PEP/sanctions screening. Many banks are dissatisfied with current systems lacking these capabilities.
Done looks like: A vendor contract specifying API response times, data refresh frequencies, and integration requirements with your core banking system. Proof-of-concept results should show the system can flag risk changes within hours.
4. Build Continuous Authentication into Session Management
Implement behavioral biometrics and device fingerprinting to re-verify identity throughout each login session. High-risk actions should trigger background verification checks.
Done looks like: Authentication logs showing verification events tied to specific actions, not just login. A customer adding a new external account should generate a verification entry even if they logged in an hour ago.
5. Automate Negative News and Adverse Media Screening
Replace manual searches with automated tools that scan news sources, court records, and regulatory filings daily. Your compliance team shouldn't manually search customer names.
Done looks like: A dashboard showing the last scan date for every customer, flagged articles with relevance scores, and a workflow for investigating hits. If a customer appears in a money laundering investigation today, your system should flag it tomorrow.
6. Configure Real-Time Sanctions and PEP List Monitoring
Set up continuous screening against OFAC, EU sanctions lists, and PEP databases. A customer's status can change overnight, and your system should reflect that.
Done looks like: Automated alerts when a customer or counterparty appears on a new sanctions list or is designated as a PEP. The alert should include the list source, effective date, and recommended action.
7. Update Customer Disclosures and Privacy Notices
Revise your terms to explain what data you collect throughout the account lifecycle and why. Transparency increases customer willingness to provide information.
Done looks like: Plain-language disclosures that mention continuous monitoring, the types of data sources you check, and how you use the information. Explain that you monitor for their protection and regulatory compliance.
8. Create Escalation Workflows for Automated Flags
Define who reviews alerts, what constitutes a false positive, and when to file a SAR. Automation only works with clear procedures for acting on findings.
Done looks like: A documented workflow showing alert severity levels, assigned reviewers, investigation timelines, and SAR filing criteria. Every alert should have an audit trail from detection to resolution.
9. Train Your Team on the New System
Your compliance staff needs to understand what the system monitors, how to interpret alerts, and when to escalate. They should know the difference between a system flag and a SAR-worthy event.
Done looks like: Training records showing each team member has completed system orientation, can demonstrate how to investigate a sample alert, and knows the escalation path for high-risk findings.
10. Establish Metrics for Continuous Improvement
Track false positive rates, time-to-investigation for alerts, SAR filing velocity, and customer friction indicators.
Done looks like: A monthly dashboard showing alert volume, investigation completion rates, and trend analysis. You should be able to show regulators that your system catches risk changes faster than your old periodic review process.
Common Mistakes
Treating Perpetual KYC as an IT Project. This is a compliance program transformation that uses technology. If IT drives implementation without compliance ownership, you'll build a system that generates alerts nobody investigates.
Failing to Integrate with Transaction Monitoring. Perpetual KYC and transaction monitoring should inform each other. A customer flagged for negative news should trigger enhanced transaction scrutiny. A suspicious transaction pattern should trigger immediate KYC re-verification.
Over-relying on Vendor Defaults. Your risk appetite and customer base are unique. The vendor's out-of-the-box thresholds won't match your needs. Configure the system based on your historical SAR triggers and false positive analysis.
Ignoring Customer Communication. If customers don't understand why you're requesting additional verification mid-relationship, they'll assume you've been breached or they're under investigation. Proactive explanation reduces friction and support costs.
Next Steps
Start with your highest-risk customer segments. If you serve MSBs, cryptocurrency exchanges, or international wire customers, implement perpetual monitoring there first. Prove the system works, refine your workflows, then expand to lower-risk populations.
Document everything. When examiners ask why you implemented perpetual KYC, your answer should reference specific deficiencies in your old program and measurable improvements in risk detection speed.
The shift to continuous monitoring isn't optional anymore. Regulators have made it clear that maintaining inadequate KYC systems carries criminal liability. Your choice is whether you implement perpetual KYC now or explain to your board why you didn't after the next enforcement action.



