KYC Refresh
KYC Refresh is the process by which a financial institution periodically reviews and updates the identity and risk information it holds about an existing customer after they have been onboarded. The frequency and depth of each review are typically driven by the customer's assessed risk level. It helps ensure that customer records stay accurate and current as the customer's circumstances or behavior change over time.
KYC Refresh refers to a periodic, risk-based update of customer information conducted as part of ongoing monitoring obligations. It involves the review, re-verification, and updating of customer identity, ownership, operational, and risk-related data maintained on previously onboarded clients, with cadence and scope generally calibrated to the customer's risk rating. It is distinct from KYC remediation (which addresses identified gaps or deficiencies in customer files) and sits on a continuum toward perpetual KYC, where data is maintained and updated in near real-time based on changes in customer behavior and circumstances rather than on fixed periodic cycles. Implementations may be manual, automated, or continuous.
Why it matters
Customer risk is not static. The information a financial institution collects at onboarding can become stale as customers change addresses, ownership structures shift, business activities evolve, or transaction behavior diverges from the profile originally established. KYC Refresh is intended to keep customer records accurate and current so that ongoing monitoring rests on reliable data rather than on a one-time snapshot taken at account opening. Without periodic review, an institution may continue treating a customer as low risk long after their circumstances have changed, weakening the effectiveness of downstream controls such as transaction monitoring and sanctions screening.
Because refresh activity is typically risk-based, the cadence and depth of review are calibrated to the customer's assessed risk rating, with higher-risk relationships generally reviewed more frequently and in greater depth. This helps institutions allocate limited due-diligence resources where they are most needed, though the trade-off is that a fixed periodic cycle can leave gaps between reviews during which material changes go undetected. That limitation is part of what drives interest in perpetual KYC, where data is maintained and updated in near real-time based on changes in customer behavior and circumstances rather than on fixed intervals.
KYC Refresh should be distinguished from KYC remediation, which addresses identified gaps or deficiencies in existing customer files, and from onboarding due diligence, which establishes the initial record. Treating these as interchangeable can obscure whether an institution is proactively maintaining current data or reactively fixing known deficiencies. The exact frequency and scope of refresh obligations depend on the institution's own risk-based policies and applicable regulatory requirements, which vary by jurisdiction and are outside the scope of this entry.
Who it's relevant to
Inside KYC Refresh
Common questions
Answers to the questions practitioners most commonly ask about KYC Refresh.