Perpetual KYC for Private Funds: Replacing the Refresh Cycle With Event-Driven Reviews
Why a three-year review cycle fails a ten-year fund, which signals should trigger a refresh, how the event loop works, and why you still need a backstop.

Short Answer
Perpetual KYC (pKYC) keeps each investor's file current by reacting to changes as they happen (a sanctions designation, an ownership change, adverse media, a new bank account) instead of waiting for a scheduled review every one to three years. For private funds, where relationships last a decade and capital moves years after onboarding, it closes the blind spot between refresh cycles. It does not remove the need for a backstop review; it makes most reviews smaller and better targeted.
Key Takeaways
- A ten-year fund life means the investor who answers a capital call in year eight may not be the one you onboarded.
- pKYC runs on signals: list updates, registry changes, adverse media, payment details and investor notifications.
- Each signal is matched to affected investors and owners, re-scored against the rulebook, and either logged as no change or sent for a targeted refresh.
- Keep a risk-tiered backstop review. Regulators accept event-driven refresh as part of a risk-based approach, not as a replacement for any review.
- pKYC needs structured investor data. A PDF in a shared drive cannot be monitored.
What is perpetual KYC?
Traditional KYC has two moments: onboarding and periodic review. A low-risk investor might be reviewed every three years, a high-risk one every year. Between those dates, the file is assumed to be right.
Perpetual KYC replaces that assumption with monitoring. The firm watches for events that would change what it knows about an investor and refreshes only what changed, when it changes. The term comes from banking, where large institutions have spent years moving toward it. For private funds it is simpler to implement, because there are fewer investors and the events that matter are easier to define.
Why does periodic review fail private funds?
Figure 1. A three-year periodic cycle leaves a long window in which a designation, a new director or a change of bank goes unseen. Event-driven refresh acts on each change as it happens.
Three features of fund relationships make the gap expensive:
- Long life. A closed-end fund runs ten years or more, often with extensions. Investor circumstances change many times over that period.
- Deferred money. Most capital moves after onboarding, through calls and distributions. The risk is live long after the KYC file was signed off.
- Entity investors change quietly. An LP that is a holding company can change owners without telling you. Under OFAC's 50 Percent Rule, a change in ownership can make an investor blocked overnight.
Periodic review also produces a poor investor experience. Every cycle, the investor is asked to resubmit documents that have not changed. Investors stall, the team chases, and the review is late. Our guide to AML screening and watchlist checks describes the moments most programs never screen; pKYC is how you cover them.
What signals should trigger a refresh?
| Signal | Source | Typical action |
|---|---|---|
| Sanctions list update | OFAC, UN, EU, UK lists via your screening provider | Rescreen all investors and owners; disposition any new hit the same day |
| New PEP status | Screening provider | Re-rate risk; EDD if your methodology requires it |
| Adverse media | Screening provider, news monitoring | Assess relevance; re-rate or escalate |
| Ownership or control change | Corporate registries, investor notice, transfer requests | Updated ownership chart; screen new owners |
| New paying or receiving account | Administrator remittance data | Verify account holder against investor |
| Change of address or residence | Investor notice, mail returned | Check jurisdiction risk; update records |
| Expired identity document | File data | Request current document if required by your policy |
| Transfer of interest | Transfer request | Full onboarding of the transferee before consent |
Payment signals overlap with transaction monitoring, which becomes a formal obligation for covered advisers on January 1, 2028. Our article on transaction monitoring for investment advisers covers that side.
How does an event-driven refresh work in practice?
Figure 2. The pKYC loop. Most signals end at step three with no change, and that check is logged. Only real changes reach the investor and a reviewer.
- Signal. Something changes in a data source you monitor.
- Match. The system works out which investors, owners and controllers the signal touches. This step depends on having ownership structured as data, not as a chart in a PDF.
- Re-score. Your written risk rules decide whether the change moves the risk tier.
- Targeted refresh. If something needs updating, ask the investor only for that: the new owner's identity document, not the whole onboarding pack.
- Sign-off. A reviewer accepts the update, escalates to EDD, or recommends exit.
The no-change path matters as much as the change path. When an examiner asks how you knew an investor was still low risk in year five, a log showing that every list update was screened against them is a better answer than a review dated year three.
Does perpetual KYC replace periodic review?
No. Keep a backstop. Signals miss things: an investor's wealth can change without any public record, and a quiet change of control in a private company may not reach a registry for months. A light periodic confirmation catches what the signals cannot.
The difference is what the periodic review asks for. Under pKYC it becomes a confirm-or-update exercise: here is what we hold, confirm it is still correct or tell us what changed. For most investors that takes minutes instead of a full resubmission.
| Risk tier | Event-driven | Backstop confirmation |
|---|---|---|
| Low | All signals | Every 3 years |
| Medium | All signals | Every 2 years |
| High | All signals, every hit reviewed by an analyst | Every year, plus full EDD refresh |
These intervals reflect common market practice. Set yours in the methodology, document the reasoning, and meet them. For high-risk investors, see our EDD guide for private fund investors.
What data does perpetual KYC need?
Event-driven refresh only works if each investor's file is structured. At minimum:
- Every natural person in the ownership and control chain, with identifiers (date of birth, nationality, address) good enough to resolve screening hits.
- Ownership percentages and control roles at each layer, so a change can be traced to the investors it affects.
- Expected paying and receiving accounts, so payment data can be compared.
- Current risk tier, the rule that set it, and the date of the last check.
- The evidence behind each fact, kept with the record.
Funds that keep KYC as a folder of PDFs per investor cannot run pKYC until they convert the core facts into data. That conversion is the real project, and it pays off well beyond pKYC: it is also what makes audits and LP due diligence questionnaires fast.
How do you roll out perpetual KYC at a fund?
- Days 1 to 30. Write the signal list and the action for each. Convert the core facts for your highest-risk investors into structured records.
- Days 31 to 60. Switch on ongoing screening for all investors and owners. Run the loop on high-risk investors and log every outcome.
- Days 61 to 90. Extend to the whole investor base. Replace the next scheduled periodic review with a confirm-or-update request.
Track four numbers: signals per month, share closed as no change, median time from signal to sign-off, and backstop confirmations completed on time.
What are the common mistakes?
- Screening the investor but not the owners. The sanctioned person is usually one layer down.
- No owner for alerts. Ongoing screening that nobody reviews is worse than none, because it proves you knew.
- Dropping the backstop. Signals do not catch everything.
- Full resubmission on every trigger. Ask only for what changed, or investors will ignore you.
Where Verifica fits
Verifica keeps each investor as a structured record: verified persons, ownership and control at every layer, and the evidence behind each fact. Ongoing screening against LSEG Risk Intelligence data runs on every investor and every owner, and a new hit or status change opens a review for your team. Refresh requests go to the investor for the specific item that changed, and every check, including the ones that found nothing, is timestamped in the file. Verifica is software, not a law firm, and your risk rules and decisions stay with your team.
Frequently Asked Questions
What is perpetual KYC?
An approach that keeps customer files current by responding to changes as they occur, such as sanctions designations, ownership changes or adverse media, rather than relying only on scheduled periodic reviews.
Is perpetual KYC required by regulators?
No regulation requires the term, but risk-based rules require ongoing due diligence and keeping customer information up to date. For U.S. advisers, the 2028 rule's ongoing customer due diligence element points the same way.
Does perpetual KYC replace periodic reviews for funds?
It should not replace them entirely. Keep a risk-tiered backstop confirmation, which under pKYC becomes a short confirm-or-update request rather than a full resubmission.
What events should trigger a KYC refresh for an LP?
Sanctions and PEP list changes, adverse media, ownership or control changes, new paying or receiving accounts, changes of residence, expired documents where policy requires, and transfers of fund interests.
How often should investors be rescreened against sanctions lists?
Every time the lists change. Screening only at onboarding and periodic review leaves gaps of years, and sanctions liability is strict.
Sources
- FinCEN, AML/CFT Program and SAR Filing Requirements for Registered Investment Advisers and Exempt Reporting Advisers, final rule, 89 Fed. Reg. 72156 (September 4, 2024), ongoing customer due diligence element.
- OFAC, Revised Guidance on Entities Owned by Persons Whose Property and Interests in Property Are Blocked (50 Percent Rule).
- OFAC, A Framework for OFAC Compliance Commitments (May 2019).
- FATF, Guidance for a Risk-Based Approach for the Securities Sector (2018).
Rodolfo Santos is a real estate compliance attorney with 10+ years of experience in cross-border transactions and the co-founder of Verifica, an AI-powered compliance platform for real estate professionals. He has closed over 150 property transactions worth more than €50 million.



