Re-KYC
Also called Re-verification, KYC Refresh, Periodic Re-verification, Refresh KYC
Re-KYC, short for "re-Know-Your-Customer", is the process of re-running some or all of an identity check on a customer a business has already onboarded, instead of checking them only once at signup. It runs on two triggers: periodic (a scheduled refresh, every one to a few years, depending on how risky the customer's profile is judged to be) and event-driven (something changes that forces an off-cycle refresh regardless of schedule: an ID document expires, a customer moves country, a transaction pattern looks unusual, or a name surfaces in adverse media).
The reason it exists at all is that a KYC check is a snapshot, not a permanent fact. A passport verified today expires in ten years; the person's risk profile, income, and behavior can change well before that. Regulators treat "verified once, never checked again" as an unacceptable AML control gap, so re-KYC isn't optional housekeeping, it's a mandated part of keeping an account, not just opening one. For the customer on the receiving end, though, it's usually indistinguishable from onboarding all over again: another document scan, another selfie, another wait, for a business that already has a complete file on them.
Who actually built this
FATF's Recommendation 10, the global baseline for customer due diligence, requires ongoing review and updating of existing customer records, "in particular for higher risk categories of customers." National regimes turn that principle into concrete practice: the EU's Anti-Money Laundering Directives and Türkiye's MASAK regulations both make periodic and trigger-based re-verification a condition of holding a financial license. The Wolfsberg Group's published guidance is the industry-standard operationalization most banks build their internal refresh schedules against, commonly annual review for high-risk customers, multi-year intervals for lower-risk ones. None of this is Solidus's design; it's decades of AML policy a regulated entity has to satisfy regardless of which verification vendor it uses.
Solidus today
Solidus is not a bank, EMI, or licensed financial institution, and runs no re-KYC program for anyone. That decision, when a given customer needs re-verification, and what should trigger an off-cycle one, belongs entirely to the regulated entity holding the account. What Solidus does build sits upstream of that decision: a credential format with a machine-readable validity window a relying party could use to key its own refresh policy off of. No Solidus customer has connected that to a live re-KYC workflow yet.
See also
KYC is the original check re-KYC repeats. Periodic Review is the broader, whole-relationship review that re-KYC's document refresh sits inside. Credential Portability is the actual wedge here: the honest bet is that a reusable credential can shrink how often re-KYC needs a full re-scan, not that it removes the obligation to review the customer at all.
Where it comes from
Someone else specified this. Solidus assembles it.
FATF Recommendation 10 requires financial institutions to conduct customer due diligence "on an ongoing basis," reviewing and updating existing records, "particularly for higher risk categories." That's the regulatory root of re-KYC. National regimes translate it into concrete practice: the EU's Anti-Money Laundering Directives and, in Türkiye, MASAK's regulations both require periodic and trigger-based re-verification as a condition of holding a financial license. The Wolfsberg Group, an association of major global banks that publishes widely-adopted AML guidance, has been influential in turning "ongoing basis" into specific refresh-cadence practice. Solidus wrote none of this and does not run a re-KYC program for anyone; it is not a regulated financial institution.
How to check this
Solidus has not built this. The entry explains the concept.
None. This entry states what has not been built, not what has.