← All articles
Compliance Operations13 minOctober 2026

How to Update Existing Investor KYC Records: A Periodic Review Playbook

What the rules actually require, how often to review each risk tier, which events should trigger an immediate refresh, and a confirm-or-resubmit process that keeps investors from redoing onboarding every cycle.

RS
Rodolfo SantosReal Estate Compliance Attorney & Co-Founder, Verifica
How to Update Existing Investor KYC Records: A Periodic Review Playbook

Short Answer

To update existing investor KYC records, set a review date for every investor based on risk (for example, yearly for high risk and every three to five years for others), refresh immediately when a trigger event occurs, and run each refresh the same way: pull the file, decide what is stale, have the investor confirm pre-filled data or resubmit only what changed, re-screen, re-rate risk, approve and log the result.

Key Takeaways

  • US rules require updating customer information "on a risk basis", not on a fixed calendar. The EU AMLR sets hard maximums from 10 July 2027: 1 year for higher-risk customers, 5 years for everyone else.
  • Most funds need both models: a periodic cycle by risk tier and event-driven reviews that restart the clock.
  • Ownership changes, transfers, new subscriptions, sanctions or PEP hits and unusual activity should open a review the same week, not at the next scheduled date.
  • Investors should confirm data that is still valid and resubmit only what has changed or expired. FinCEN guidance says re-certification is not required when information is up to date and accurate.
  • Non-response needs a written escalation ladder. Any restriction on distributions or transfers has to rest on your fund documents and applicable law.

Most of a fund's KYC exposure sits in files that were complete on the day of subscription and have aged since. Directors change, investors move country, passports expire, and a holding company that was clean in 2022 picks up a sanctioned shareholder in 2026. This guide covers keeping the record current. For the screening controls themselves, see AML Screening and Watchlist Checks.


What do the rules actually require when updating KYC records?

Every major framework requires ongoing due diligence on existing customers, but only some set a maximum interval. In the US the duty is risk-based with no fixed schedule; the EU AMLR adds hard caps from 10 July 2027; the UK and Cayman require risk-based periodic reviews whose frequency the firm sets.

United States. The FinCEN program rules for banks, broker-dealers and mutual funds require "appropriate risk-based procedures for conducting ongoing customer due diligence", including "ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information" (31 CFR 1020.210). FinCEN's 2020 guidance is explicit that "there is no categorical requirement that financial institutions update customer information on a continuous or periodic schedule". The update duty is triggered when monitoring surfaces a change relevant to risk, although institutions "may choose to review customer information on a regular or periodic basis".

Investment advisers are not yet covered. FinCEN's 2024 rule for registered and exempt reporting advisers copies the same ongoing CDD language into 31 CFR 1032.210(b)(5)(ii) and leaves beneficial ownership collection to a later rulemaking. A January 2, 2026 final rule moved its effective date to January 1, 2028, and FinCEN intends to revisit its substance first (background here). Meanwhile OFAC compliance never pauses, which is why a stale record matters even without a CDD rule (see OFAC Sanctions Screening for U.S. Private Funds).

European Union. Article 26(2) of Regulation (EU) 2024/1624 requires obliged entities to keep customer documents, data and information up to date, and says the period between updates "shall not in any case exceed" 1 year for higher-risk customers subject to enhanced due diligence and 5 years for all other customers. Article 26(3) adds event-driven reviews: a change in the customer's relevant circumstances, a legal obligation to contact the customer during the year about beneficial owners or under the tax cooperation directive (Directive 2011/16/EU), or a relevant fact the firm becomes aware of. The regulation applies from 10 July 2027. AMLA consulted on draft guidelines on ongoing monitoring until 3 September 2026; they are not final, so treat the draft as direction of travel (our AMLA 2026 overview covers the authority).

United Kingdom. The Money Laundering Regulations 2017 require CDD on existing customers "at other appropriate times... on a risk based approach" and when the firm becomes aware that relevant circumstances have changed (reg. 27(8)). Ongoing monitoring includes "undertaking reviews of existing records and keeping the documents or information obtained for the purpose of applying customer due diligence measures up-to-date" (reg. 28(11)). There is no statutory interval.

Cayman Islands and FATF. CIMA's February 2020 amendments to its AML Guidance Notes expect firms to "demonstrate a periodic review of all customers", with frequency set by the firm on risk, and to update CDD at the scheduled date or on a trigger event, "whichever is earlier". All of these frameworks rest on FATF Recommendation 10, which requires ongoing due diligence on the business relationship and keeping CDD information up to date, particularly for higher-risk customers.

FrameworkUpdate dutyFixed maximum interval?
US FinCEN program rules (banks, broker-dealers, mutual funds)Maintain and update customer information on a risk basisNo. Update on risk-relevant change; periodic review optional
US Investment Adviser AML Rule (31 CFR 1032.210)Same ongoing CDD languageNo. Effective January 1, 2028, subject to further FinCEN revision
EU AMLR Art. 26 (from 10 July 2027)Keep documents, data, information up to date, plus event-driven reviewYes: 1 year for higher risk, 5 years for others
UK MLR 2017 regs. 27 and 28Review existing records and keep CDD up to date on a risk basisNo
CIMA Guidance Notes (Cayman)Periodic review of all customers, earlier on a triggerNo. Frequency set by the firm

Periodic review, trigger-based review or perpetual KYC: which should a fund use?

Use periodic review as the floor and event-driven review on top of it. Perpetual KYC is a way of running event-driven review continuously with automated data feeds, not a replacement for having a documented review cycle.

Periodic review is a scheduled refresh of the full investor record at an interval set by risk tier. Its strength is coverage: every file gets looked at, including the quiet ones. As the Mauritius Financial Services Commission put it in June 2026, a purely trigger-based framework lets clients "go unchecked for extended periods".

Event-driven (trigger) review is a targeted refresh started by something that happened, such as a new beneficial owner or a sanctions alert. It catches risk when it changes, if you can detect the event.

Perpetual KYC (pKYC) is continuous monitoring of investor records against external data, such as sanctions and PEP lists, adverse media and company registries, so that event-driven reviews open automatically. It shrinks the work at the periodic date, because much of the file has already been refreshed. It does not remove the need for one under the EU AMLR, which caps the interval regardless of how quiet the account has been.

PeriodicEvent-drivenPerpetual (pKYC)
What starts itCalendar date by risk tierA detected change or alertAutomated data feeds, continuously
CoverageEvery investorOnly investors with a detected eventEvery investor, for the data the feeds cover
Main weaknessRisk can change between datesMisses events you cannot seeFeeds do not cover everything (source of funds, purpose of investment)
Best useFloor for all investorsOverlay for material changesMakes event detection reliable and periodic reviews lighter

How often should investor KYC be reviewed?

A defensible default is every 12 months for high-risk investors, every three years for medium risk and no longer than five years for low risk. Whatever you choose must be written in your policy, tied to your risk rating methodology and applied consistently.

These intervals are policy choices, not US law. They sit inside the EU AMLR caps (1 and 5 years) and match the only regulator-set schedule I found published this year: the Mauritius FSC's guidelines, effective 8 June 2026, require reviews at least once a year for high risk, every three years for medium risk and every four years for low risk. If an EU administrator or AIFM sits in your chain, expect its policies to adopt the AMLR caps.

Two rules make the cycle work in practice. First, a trigger review that covers the full record restarts the clock, so the next periodic date runs from the trigger review. Second, a change in risk rating moves the investor to the new tier's cycle immediately; an investor re-rated high in month 30 does not wait until year 3.

Review cycle by investor risk tier

Figure 1. An illustrative review policy. The 1-year and 5-year outer limits are the EU AMLR Art. 26(2) caps; the 3-year medium tier mirrors the FSC Mauritius 2026 guidelines. A full trigger review restarts the clock for that investor.


Which events should trigger an immediate KYC review?

Any event that could change who the investor is, who controls it, where its money comes from or how risky it is should open a review without waiting for the scheduled date. In a fund, that mostly means ownership changes, new money, transfers, jurisdiction changes, screening hits, expired documents and unusual activity.

CIMA and AMLA's draft guidelines publish similar lists, built around ownership changes, jurisdiction changes, new PEP status, adverse information and behavior that does not fit the profile. Both stress that no list is complete, so train the people who talk to investors to recognize a trigger when they hear one.

Trigger eventRequired actionTiming
Change of ownership or control of an entity investor (new beneficial owner, controller, director or signatory)Identify and verify the new parties, update the ownership map, re-screen everyone in the structure, re-rate riskBefore the next capital movement
New subscription, capital increase or follow-on commitmentConfirm the existing record is current, refresh anything past its review date, confirm source of funds for the new moneyBefore accepting the funds
Transfer of an interest (secondary sale, transfer to an affiliate, trust or estate)Onboard the transferee as a new investor; close out and document the transferor's fileBefore the GP consents to the transfer
Change of address, residence or jurisdiction of incorporationUpdate the record, re-screen, re-assess country risk; apply EDD if the new jurisdiction is higher riskWithin your policy window, typically days
Potential sanctions matchHold activity, adjudicate the alert; for a true match to a US-blocked person, block and report to OFACSame day; OFAC report within 10 business days
New PEP status or material adverse mediaVerify the finding, re-rate risk, apply EDD and senior approval where your policy requiresPromptly, before the next distribution or call
Expired identity documentDecide on risk whether to re-collect now or at the next review or interactionRisk-based
Unusual activity (payment from an unrelated third party, new bank account in a different country, redemption out of profile)Investigate, refresh source of funds, escalate; consider a suspicious activity report where you are subject to that dutyBefore processing the instruction

On expired passports, AMLA's draft rejects automatic re-collection. It asks firms to weigh the customer's risk, the issuing country, how long the document has been expired and whether the identity details are in doubt, and then decide whether the update is needed "without delay" or can wait until "the next scheduled customer information review or at the next occasion on which the customer interacts with the obliged entity".

Trigger event decision flow

Figure 2. A trigger-event decision flow. Questions are asked in order of severity, so a single event that is both a sanctions alert and an ownership change is handled as a sanctions alert first. The OFAC reporting window is set by 31 CFR 501.603.


How do you refresh an investor KYC record, step by step?

Run every refresh, periodic or triggered, through the same seven steps. The step that saves the most investor time is the third: ask the investor to confirm what you already hold and resubmit only what has changed or expired.

  1. Pull the current record. Retrieve the last approved file: identity data, ownership chart, risk rating and its rationale, screening history, source of funds, open alerts and the date and scope of the last review. If the last file cannot be located or is incomplete, treat the review as remediation (see the backlog section below).
  2. Determine scope. List each data element and mark it valid, stale, expired or missing. Scope depends on tier and on why the review was opened. AMLA's draft lets firms lighten periodic reviews of low-risk customers with no new activity, for example by checking business registries, running PEP and adverse media screening and confirming internally that the purpose of the relationship has not changed. A trigger review scopes to what the trigger touched, plus anything already past due.
  3. Pre-fill and ask the investor to confirm or resubmit. Send the investor their own data, pre-filled, and ask them to attest that it is still accurate or correct it. Request new documents only for elements that changed, expired or are needed for a higher-risk rating. FinCEN's 2018 FAQs say the rule "does not require re-certification when the information is up-to-date and accurate". AMLA's draft accepts customer confirmation but asks firms to consider, on risk, whether to verify it independently and whether the person confirming has authority to do so.
  4. Verify what changed. New identity documents go through the same authenticity and liveness checks as at onboarding. FinCEN draws no distinction between verifying a beneficial owner at account opening and after a trigger: the elements are the same.
  5. Re-screen everyone in the file. Run sanctions, PEP and adverse media screening on the investor and every related party, including beneficial owners, controllers and signatories, not only the named investor.
  6. Re-rate risk. Apply your methodology to the refreshed facts. If the rating changes, record why and move the investor to the new review cycle and due diligence level.
  7. Approve and log. A reviewer other than the preparer signs off; high-risk files go to the senior approver your policy names. Store what was confirmed, what was resubmitted, the screening results, the new rating and the next review date in one timestamped record. That record is what an examiner will ask for; How to Build a Defensible AML Audit Trail covers what it should contain.

Refresh workflow with confirm or resubmit branching

Figure 3. The refresh workflow. Steps 3 and 4 (confirm or resubmit, then verify) happen element by element, so one file can mix both branches: an investor might confirm their address and resubmit an expired passport.


What should you do when an investor doesn't respond to a KYC refresh?

Follow a written escalation ladder with fixed intervals and record every attempt. If the investor still does not respond, apply only the restrictions your fund documents and the applicable law allow, and decide with counsel whether the relationship can continue.

A workable ladder, with intervals you set in the policy:

  1. Initial request with a deadline and a short list of exactly what is needed (see boosting KYC response rates on form design).
  2. Two reminders through different channels: email, then the investor portal or a call from investor relations.
  3. Escalation to the relationship owner at the GP, or to the investor's adviser or placement agent where there is one.
  4. Formal notice citing the provision of the subscription agreement or LPA under which the investor agreed to provide information the fund needs for AML and sanctions compliance, and stating what will happen if the information is not received.
  5. Restriction, if your documents allow it. Depending on the fund, that can mean refusing to accept new commitments, declining to register transfers, or holding distributions or redemption proceeds. Whether you can do any of this depends on the LPA, the subscription documents and the law of the fund's domicile. Withholding money an investor is contractually owed without that basis creates a different problem.
  6. Exit decision. Some frameworks require it. The UK MLR require a firm that cannot apply CDD to "terminate any existing business relationship with the customer" (reg. 31). AMLA's draft says EU obliged entities may temporarily suspend or restrict activity after "repeated and reasonable steps" to obtain information, but "termination should follow" if they ultimately cannot comply.

Sanctions are different. If the reason for the review is a confirmed match to a blocked person, OFAC rules apply whatever the investor does, and whatever the fund documents say. Non-response to a routine refresh is an AML recordkeeping problem; a confirmed sanctions match is a legal prohibition.

Either way, document the chase. CIMA expects policies to set out the remedial steps when CDD documentation is not on file, and AMLA's draft points to the AMLR duty to record the efforts made and any decision to terminate.


How do you clear a backlog of out-of-date investor KYC files?

Treat a backlog as a time-boxed remediation project: inventory every file, rank by risk and by how soon money moves, use lighter reviews for low-risk files, and report progress against a fixed end date.

Backlogs build up after fund launches, administrator changes and acquisitions. Mauritius gave its licensees one year from 8 June 2026 to bring existing customers onto the new review frequencies, which is a reasonable benchmark for a remediation window.

  1. Inventory. One row per investor: risk tier, last review date, review due date, missing or expired elements, related parties, and the next expected capital call, distribution or transfer.
  2. Prioritize. High-risk and overdue first, then any investor with a cash movement in the next 90 days, then the rest by how far overdue they are.
  3. Clear what needs no investor contact. Re-screen the whole book at once and check company registries for ownership changes.
  4. Batch the outreach. Combine requests with an existing touchpoint, such as the annual report or tax self-certification cycle. The AMLR itself lists a legal obligation to contact the customer under the tax cooperation directive as a review trigger.
  5. Report weekly to the CCO: files closed, files open by tier, non-responders in escalation, and the projected completion date.

Which KPIs show that a KYC review program is working?

Track whether reviews happen on time, how long they take, how much investor effort they need and whether they find anything.

  • On-time completion rate by risk tier, and the count of overdue reviews by age band (0 to 30, 31 to 90, over 90 days).
  • Trigger-to-review time: days from event detection to completed review, reported separately for sanctions alerts.
  • Cycle time: days from opening a review to approval, split into time waiting on the investor and time with your team.
  • Investor response rate and the number of investors at each step of the escalation ladder.
  • Confirm-versus-resubmit ratio: the share of data elements confirmed rather than re-collected. A high resubmit rate on low-risk files usually means the scope rules are too broad.
  • Outcome rate: share of reviews that changed a risk rating, found a new beneficial owner or produced an escalation. A review program that never finds anything deserves a second look.
  • Quality assurance findings from a sample of completed files checked by a second reviewer.

Where Verifica fits in a KYC refresh program

Verifica runs the refresh through the same guided flow used at onboarding: smart forms tailored to the investor type, completed from a phone or laptop, with document authenticity checks, biometric liveness and UBO mapping for companies, trusts and fund-of-funds structures.

Screening runs on LSEG Risk Intelligence, which draws on more than 100,000 credible sources and is used by more than 300 global financial institutions. Ongoing monitoring keeps investors screened between reviews (continuous monitoring and enhanced reports are priced before activation). Once checks complete, Verifica generates the updated KYC file in under 60 seconds, with a timestamped, exportable audit trail. Anything that needs judgment is flagged to a human reviewer rather than auto-approved. Verifica is software, not a law firm: your team sets the review intervals, risk thresholds and escalation policy, and signs off on each file.


Frequently Asked Questions

How often should investor KYC records be updated?

Most funds review high-risk investors every 12 months, medium-risk investors every three years and low-risk investors no less often than every five years, and refresh any file immediately when a trigger event occurs. US rules do not fix a schedule. The EU AMLR caps the interval at one year for higher-risk customers and five years for others from 10 July 2027. Write your chosen intervals into your AML policy.

Is there a US legal requirement to refresh KYC on a fixed schedule?

No. FinCEN rules require institutions to maintain and update customer information on a risk basis, and FinCEN guidance from 2020 says there is no categorical requirement to update on a continuous or periodic schedule. Updates are required when monitoring reveals a risk-relevant change. Investment advisers are not yet covered by FinCEN CDD rules; the adviser AML rule takes effect January 1, 2028.

What is the difference between periodic KYC review and perpetual KYC?

Periodic review refreshes every investor file at a set interval based on risk. Perpetual KYC monitors files continuously against external data, such as sanctions lists, PEP data, adverse media and company registries, and opens a review when something changes. It makes periodic reviews lighter, but it does not cover everything, such as source of funds, and does not remove regulatory maximum intervals.

Do investors have to resubmit all their documents at every KYC review?

No. A well-run refresh sends investors their existing data, pre-filled, and asks them to confirm it or correct it. New documents are requested only for information that changed, expired or is needed because the investor's risk rating went up. FinCEN guidance states that re-certification is not required when information is up to date and accurate, though higher-risk files may justify independent verification of what the investor confirms.

Does an expired passport make an investor KYC record non-compliant?

Not automatically. Identity was verified when the document was valid. AMLA draft guidelines published in June 2026 propose a risk-based approach: weigh the investor's risk, the issuing country, how long the document has been expired and any doubts about identity, then re-collect it immediately or at the next scheduled review or investor interaction. Your policy should state which approach you follow and apply it consistently.

What happens if an investor does not respond to a KYC refresh request?

Follow a written escalation ladder: reminders, escalation to the relationship owner, then formal notice under the subscription documents. If there is still no response, apply only the restrictions your fund documents and governing law permit, such as declining transfers or new commitments. UK rules require ending the relationship where CDD cannot be completed, and EU draft guidance treats restriction as temporary before termination. Record every attempt.

What events should trigger an immediate investor KYC review?

Common triggers are a change in the ownership or control of an entity investor, a new subscription or capital increase, a transfer of the fund interest, a change of residence or jurisdiction, a sanctions, PEP or adverse media hit, an expired identity document and unusual activity such as payments from unrelated third parties. A full trigger review should restart the investor's periodic review clock.

When do the EU AMLR rules on updating customer information apply?

Regulation (EU) 2024/1624 applies from 10 July 2027. From that date, Article 26 requires obliged entities to update customer information at intervals of no more than one year for higher-risk customers under enhanced due diligence and five years for all other customers, and to review earlier when relevant circumstances change. AMLA consulted on supporting guidelines on ongoing monitoring until 3 September 2026.


Sources

  1. 31 CFR 1020.210, Anti-money laundering program requirements for banks (FinCEN regulation, via Cornell Legal Information Institute, accessed October 2026)
  2. 31 CFR 1010.230, Beneficial ownership requirements for legal entity customers (FinCEN regulation, via Cornell LII, accessed October 2026)
  3. Frequently Asked Questions Regarding Customer Due Diligence Requirements for Financial Institutions, FIN-2018-G001 (FinCEN, April 3, 2018), Questions 13 to 17
  4. Frequently Asked Questions Regarding Customer Due Diligence (CDD) Requirements for Covered Financial Institutions, FIN-2020-G002 (FinCEN, August 3, 2020), Question 3
  5. Anti-Money Laundering/Countering the Financing of Terrorism Program and Suspicious Activity Report Filing Requirements for Registered Investment Advisers and Exempt Reporting Advisers, final rule (FinCEN, Federal Register, September 4, 2024)
  6. Delaying the Effective Date of the AML/CFT Program and SAR Filing Requirements for Registered Investment Advisers and Exempt Reporting Advisers (FinCEN, Federal Register, January 2, 2026)
  7. 31 CFR 501.603, Reports of blocked property (OFAC regulation, via Cornell LII, accessed October 2026)
  8. Regulation (EU) 2024/1624 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing (Official Journal of the EU, June 19, 2024), Articles 26 and 90
  9. Consultation Paper: Draft Guidelines on ongoing monitoring of a business relationship under Article 26(5) of Regulation (EU) 2024/1624 (AMLA, June 3, 2026)
  10. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, regulation 27 (legislation.gov.uk)
  11. Money Laundering Regulations 2017, regulation 28 (legislation.gov.uk)
  12. Money Laundering Regulations 2017, regulation 31 (legislation.gov.uk)
  13. Guidance Notes (Amendments) on the Prevention and Detection of Money Laundering and Terrorist Financing in the Cayman Islands: Ongoing Monitoring (Cayman Islands Monetary Authority, February 2020)
  14. Guidelines on Frequency of Customer Due Diligence (Financial Services Commission, Mauritius, June 5, 2026)
  15. International Standards on Combating Money Laundering and the Financing of Terrorism & Proliferation: The FATF Recommendations, Recommendation 10 and Interpretive Note (FATF, as amended)
Rodolfo Santos

Rodolfo Santos is a real estate compliance attorney with 10+ years of experience in cross-border transactions and the co-founder of Verifica, an AI-powered compliance platform for real estate professionals. He has closed over 150 property transactions worth more than €50 million.

See a full check run
on a real file.

Identity, documents, and screening in one engine, start to report.

Request a demo