Periodic Review

Also called Periodic Customer Review, Ongoing Due Diligence, Ongoing Monitoring Review, EDD Review Cycle

ComposedNot built

A periodic review is a scheduled, whole-relationship reassessment of an existing customer, done on a cadence set by how risky that customer is judged to be, not triggered by any single event. It's easy to conflate with Re-KYC, but the two answer different questions. Re-KYC asks "is the identity document we have on file still current and valid?", a narrower, document-level check. A periodic review asks the bigger question: "given everything we know about this customer today, does our current risk rating and level of scrutiny still make sense?", pulling in updated sanctions and PEP list checks, adverse media results, a look at whether transaction behavior still matches what was expected at onboarding, and, where a document has actually expired, a re-KYC as one component of the broader review.

The cadence itself is risk-tiered by design, not uniform: a customer flagged high-risk at onboarding (a politically exposed person, someone in a higher-risk industry or jurisdiction) typically gets reviewed annually or more often; a low-risk retail customer might go three to five years between reviews. Getting that tiering wrong in either direction is a real cost, too aggressive and compliance teams drown in reviews that rarely surface anything; too lax and genuine risk changes go unnoticed for years.

Who actually built this

FATF Recommendation 10 is the root obligation: due diligence must be ongoing, not a one-time event, with more frequent attention paid to higher-risk customers. The Wolfsberg Group, an association of major global banks that publishes some of the most widely referenced AML guidance in the industry, is the source most compliance programs actually build their review-cadence policy against, since FATF's Recommendations set the principle but leave the specific schedule to national regulators and institutions. The EU's Anti-Money Laundering Directives and Türkiye's MASAK regulations both require some form of periodic review as a licensing condition. None of it is Solidus's design.

Solidus today

Solidus has not built anything that performs, schedules, or tracks periodic reviews. That judgment, how risky is this customer today, and does the review cadence still fit, belongs to the compliance program of whichever regulated business holds the relationship. Solidus Verify's role, where it plays one at all, is upstream: it can supply a fresh identity-proofing result as an input to a review a bank or EMI runs itself, not the review or its scheduling logic.

See also

Re-KYC is the narrower, document-level refresh that's one component of a periodic review, not a substitute for it. Risk Scoring is what a periodic review re-evaluates. AML is the compliance program periodic review sits inside. Adverse Media Screening is one of the checks a thorough periodic review typically re-runs.

Where it comes from

Someone else specified this. Solidus assembles it.

Rooted in the same FATF Recommendation 10 "ongoing basis" due-diligence obligation as Re-KYC, but broader in scope. A periodic review looks at the whole customer relationship, not just whether an ID document is still current. The Wolfsberg Group's guidance on risk-based review cadence (commonly annual for high-risk customers, multi-year for lower-risk ones) is the industry-standard operationalization most banks and EMIs build their internal review schedules against. National AML regimes (the EU's AMLD series, Türkiye's MASAK) require it as a licensing condition. Solidus wrote none of this.

How to check this

Solidus has not built this. The entry explains the concept.

None. This entry states what has not been built, not what has.

Related

Periodic Review · Solidus Lexicon