Skip to main content
Category: AML and KYC

KYC Refresh

Also known as: Periodic KYC, Periodic KYC Review, KYC AutoRefresh
Simply put

KYC Refresh is the process by which a financial institution periodically reviews and updates the identity and risk information it holds about an existing customer after they have been onboarded. The frequency and depth of each review are typically driven by the customer's assessed risk level. It helps ensure that customer records stay accurate and current as the customer's circumstances or behavior change over time.

Formal definition

KYC Refresh refers to a periodic, risk-based update of customer information conducted as part of ongoing monitoring obligations. It involves the review, re-verification, and updating of customer identity, ownership, operational, and risk-related data maintained on previously onboarded clients, with cadence and scope generally calibrated to the customer's risk rating. It is distinct from KYC remediation (which addresses identified gaps or deficiencies in customer files) and sits on a continuum toward perpetual KYC, where data is maintained and updated in near real-time based on changes in customer behavior and circumstances rather than on fixed periodic cycles. Implementations may be manual, automated, or continuous.

Why it matters

Customer risk is not static. The information a financial institution collects at onboarding can become stale as customers change addresses, ownership structures shift, business activities evolve, or transaction behavior diverges from the profile originally established. KYC Refresh is intended to keep customer records accurate and current so that ongoing monitoring rests on reliable data rather than on a one-time snapshot taken at account opening. Without periodic review, an institution may continue treating a customer as low risk long after their circumstances have changed, weakening the effectiveness of downstream controls such as transaction monitoring and sanctions screening.

Because refresh activity is typically risk-based, the cadence and depth of review are calibrated to the customer's assessed risk rating, with higher-risk relationships generally reviewed more frequently and in greater depth. This helps institutions allocate limited due-diligence resources where they are most needed, though the trade-off is that a fixed periodic cycle can leave gaps between reviews during which material changes go undetected. That limitation is part of what drives interest in perpetual KYC, where data is maintained and updated in near real-time based on changes in customer behavior and circumstances rather than on fixed intervals.

KYC Refresh should be distinguished from KYC remediation, which addresses identified gaps or deficiencies in existing customer files, and from onboarding due diligence, which establishes the initial record. Treating these as interchangeable can obscure whether an institution is proactively maintaining current data or reactively fixing known deficiencies. The exact frequency and scope of refresh obligations depend on the institution's own risk-based policies and applicable regulatory requirements, which vary by jurisdiction and are outside the scope of this entry.

Who it's relevant to

Compliance and AML Officers
Responsible for defining risk-based refresh policies, setting review cadences by customer risk rating, and ensuring that ongoing monitoring rests on current data. They must also distinguish refresh activity from remediation of identified file deficiencies and align both with applicable regulatory obligations, which vary by jurisdiction.
Customer Due Diligence and KYC Analysts
Perform the review, re-verification, and updating of customer identity, ownership, operational, and risk-related information on previously onboarded clients. They apply deeper scrutiny to higher-risk relationships and escalate cases where a review surfaces gaps requiring remediation.
Financial Crime Technology and Operations Teams
Design and maintain the systems that support refresh, ranging from manual scheduling to automated tooling that reduces manual reviews, through to continuous perpetual-KYC approaches that update data in near real-time. They balance detection timeliness against operational cost and the residual gaps inherent in fixed periodic cycles.
Risk Management and Governance Functions
Oversee whether refresh cadence and scope remain proportionate to assessed customer risk, and monitor the trade-off between periodic reviews that can leave detection gaps between cycles and near-real-time approaches that aim to close them. They rely on current, accurate customer records to support wider risk decisioning.

Inside KYC Refresh

Periodic Re-verification
The scheduled review and re-validation of customer identity and business information collected during onboarding, intended to confirm that records remain current and accurate over the life of the relationship.
Risk-Based Cadence
The practice of setting refresh intervals according to the assessed risk of the customer or merchant, so that higher-risk relationships are reviewed more frequently than lower-risk ones. Exact intervals depend on the governing program, regulator, or internal policy rather than a single fixed standard.
Trigger-Based Review
Refresh activity prompted by specific events such as changes in ownership, business model, transaction patterns, or negative external information, rather than solely on a calendar schedule.
Data Sources and Evidence
The documentation and reference data used to confirm identity and business details during a refresh, which may include government identifiers, corporate registry information, and beneficial ownership details as required by the applicable program.
Recordkeeping and Audit Trail
Documentation of when a refresh was performed, what was reviewed, and the outcome, supporting demonstrable compliance and internal governance.

Common questions

Answers to the questions practitioners most commonly ask about KYC Refresh.

Is KYC Refresh a PCI DSS requirement?
No. KYC Refresh is a customer due diligence and anti-money-laundering (AML) concept, not a PCI DSS control. PCI DSS governs the protection of cardholder data and the security of the cardholder data environment, while KYC and its periodic refresh are driven by AML/CFT regulatory frameworks and, for acquirers and processors, by card brand and network onboarding rules. The two may operate in the same organization, but a KYC Refresh does not satisfy or map to any PCI DSS requirement, and confirming AML obligations should be done against the applicable regulatory regime rather than the PCI DSS standard.
Does completing a KYC Refresh mean the customer or merchant is not committing fraud?
No. A KYC Refresh is intended to keep identity, ownership, and risk-profile information current; it may help identify changes in circumstances or previously undetected risk indicators, but it does not detect or prevent fraud on its own. Fraud types such as account takeover, first-party or friendly fraud, chargeback fraud, and synthetic identity fraud can persist despite up-to-date KYC records. KYC Refresh is one input into a broader risk program and should be treated as helping reduce risk, not eliminating it, with known limitations including false negatives where refreshed data still appears legitimate.
How often should a KYC Refresh be performed?
Refresh frequency is typically risk-based rather than fixed, with higher-risk customers reviewed more often than lower-risk ones, subject to the applicable regulatory framework and any card brand or network onboarding rules. Many programs also trigger event-driven refreshes on changes such as beneficial ownership, business model, or transaction behavior. Because timing obligations vary by jurisdiction and by the governing rules, the specific cadence and triggers should be confirmed against the current applicable regulations and network requirements rather than assumed.
What information is typically reviewed during a KYC Refresh?
A refresh generally revisits the identity and ownership information collected at onboarding, such as legal identity, beneficial ownership, business activity, and expected transaction profile, and compares it against current data and risk indicators. When any payment card data is involved in supporting workflows, it should be handled under the same data-protection controls as elsewhere, distinguishing cardholder data that may be stored under defined controls from sensitive authentication data that must not be stored after authorization. The exact fields reviewed depend on the governing framework and the institution's risk-based procedures.
How should a KYC Refresh be integrated with ongoing transaction monitoring?
KYC Refresh and transaction monitoring are complementary but distinct. Refresh updates the customer risk profile, while monitoring evaluates activity against that profile on an ongoing basis; changes surfaced by monitoring can trigger an event-driven refresh, and a refreshed profile can recalibrate monitoring thresholds. Because both detection processes involve false-positive and false-negative trade-offs, they are typically tuned together rather than relied on in isolation, with the specific integration approach determined by the institution's program and applicable regulatory expectations.
How can a KYC Refresh program be evidenced for regulators or network reviews?
Programs generally maintain records showing when refreshes were due, when they were performed, what was reviewed, and how any risk changes were dispositioned, so that the risk-based rationale can be demonstrated. Where card brand or network onboarding rules apply to acquirers or processors, evidence expectations may differ from those under AML/CFT regulators, and these rules change and vary by region. The specific documentation and retention expectations should be confirmed against the current applicable regulatory framework and network rules rather than assumed.

Common misconceptions

KYC Refresh is a PCI DSS requirement.
KYC and customer due diligence obligations arise from anti-money-laundering and know-your-customer regulatory frameworks and card brand or acquirer program rules, which are separate from PCI DSS. PCI DSS focuses on protecting cardholder data and does not define KYC refresh procedures. Practitioners should confirm the specific governing framework rather than assuming PCI DSS applies.
A KYC Refresh only needs to happen on a fixed periodic schedule.
Refresh is intended to be both periodic and event-driven. Relying solely on a calendar interval may miss material changes; trigger-based reviews are meant to complement scheduled cadences. Exact intervals and triggers vary by program, region, and internal policy.
Completing a KYC Refresh guarantees a customer or merchant is not engaged in fraud.
A refresh helps reduce the risk of outdated or inaccurate records and may mitigate certain risks such as undetected ownership changes, but it does not eliminate fraud. It is one control among several and carries trade-offs, including the possibility of false assurance if underlying data sources are themselves incomplete or manipulated.

Best practices

Define refresh cadence on a risk-based basis, applying more frequent reviews to higher-risk customers or merchants, and confirm intervals against the applicable regulatory and program requirements rather than a single fixed number.
Establish event-based triggers, such as changes in ownership, business model, or transaction behavior, that initiate a refresh independent of the scheduled cadence.
Maintain a clear audit trail documenting when each refresh occurred, what was reviewed, and the outcome, to support demonstrable compliance and internal governance.
Verify refreshed information against reliable and independent data sources, and treat discrepancies as items requiring further investigation rather than automatic clearance.
Keep KYC refresh processes distinct from PCI DSS controls in policy and documentation, mapping each activity to its actual governing framework to avoid conflating separate obligations.
Treat KYC Refresh as one layer within a broader risk and fraud program, acknowledging its limitations and combining it with other monitoring and detection controls.