Two Controls, Not One

Perpetual KYC isn't a faster calendar. It's a different architecture.

"Perpetual KYC" gets used loosely, but the idea behind it is specific. Periodic KYC refreshes a customer's file on a fixed schedule, every one, two, or three years depending on risk tier, whether or not anything about the relationship has actually changed. Event-driven review does the opposite: it fires when something specific happens, an address change, a new beneficial owner, an adverse media hit, a transaction pattern that breaks from the account's own history, regardless of where that customer sits in the review calendar. Perpetual KYC is what you get when a firm runs both continuously and treats neither as a substitute for the other. A firm that just shortens its periodic cycle from three years to one hasn't built perpetual KYC, it's built a faster version of the same clock, one that still says nothing about what happens between review dates.

The FCA's own findings, published 8 April 2026 from a multi-firm review of customer due diligence, enhanced due diligence, and ongoing monitoring controls, treat periodic and event-driven review as two separate things firms are expected to define and evidence [1]. Its central finding wasn't that firms lacked a review policy. It was that most policies didn't say enough: unclear on how often periodic reviews should actually happen, and unclear on what a firm is supposed to do once an event-driven trigger fires [1]. That's the thesis this guide works from. Most firms don't fail perpetual KYC because they never wrote a policy. They fail because the policy collapses two distinct controls into one undifferentiated idea, or defines neither with enough operational detail for a member of staff to follow it or an examiner to evidence that it was followed.

A real case, not a hypothetical one

In December 2025 the FCA fined Nationwide Building Society £44,078,500 for anti-financial crime systems and controls failings running from October 2016 to July 2021 [2]. That fine sits inside a wider pattern: since 2021, the FCA has imposed 13 fines totalling £300,767,526 on banks for anti-money laundering systems and controls failings [2]. For most of that period, in breach of its own policies, Nationwide had no process for carrying out either periodic or event-driven reviews of a large share of its personal current account customers [3]. The FCA's investigation also found Nationwide knew some customers were using personal accounts for business activity, in breach of the account's own terms, without the controls in place to manage that risk. One consequence: a single customer used ordinary personal current accounts to receive fraudulent Covid furlough payments, 24 separate payments totalling £27.3 million over 13 months, with £26.01 million of that landing in just eight days [2]. Nobody flagged it, because nothing was built to.

How to use this guide

Read the five patterns and the review cycle below first. Then work each scenario, make your call, and read why, both for the right answer and every wrong one. The knowledge check at the end pulls the same distinctions from new angles, including a question on the Nationwide case specifically. Do not skip ahead.

Five Patterns

Five patterns, five cards

Most perpetual KYC failures trace back to one of these five shapes. Learn to recognise them before the scenarios test them.

🎯
The Undefined Trigger
A policy that says review "when a material change occurs" without ever saying what counts isn't a control, it's a placeholder.

The FCA's review found firms with no shortage of policy language on event-driven review, and a real shortage of operational detail underneath it. "Material change" left undefined means two analysts can look at the same event, a customer's registered address moving from a family home to a serviced office, say, and reach opposite conclusions about whether it matters, with no documented basis for either. A trigger that isn't written down as a specific, named event is a trigger that only fires when someone happens to notice.

Risk
An undefined "material change" standard invites inconsistent, indefensible judgement calls.
Signal
Two analysts handling comparable events differently with no documented reason why.
Response
A fixed, documented list of trigger events and thresholds, not open-ended professional judgement.
The Frequency Vacuum
"Regularly" is not a review interval. It's the absence of one, dressed up as a policy.

The same FCA review flagged firms whose periodic review policy simply didn't state how often reviews for a given risk tier should actually happen. Without an explicit cadence, two customers with comparable risk profiles can drift years apart in review timing purely on analyst workload, with nothing in the file to say that's wrong. A risk-based approach only works if the frequency itself is tied to risk, not to whichever review happened to get picked up first.

Risk
"Regularly" as a review interval means some customers go years without a genuine refresh.
Signal
High-risk customers with review dates that vary wildly across a similar book.
Response
An explicit, risk-tiered cadence with a documented escalation when a review runs overdue.
🎭
The Business-on-a-Personal-Account
The account was never reclassified, because nothing was watching for the mismatch.

This is the specific gap the FCA cited in the Nationwide case: personal accounts carrying business-style activity, invoice-like payments in and out at volume, with no control layered on top designed to catch that mismatch. A personal account isn't inherently lower risk than a business one, it's simply monitored against a different baseline, and once real activity stops matching that baseline the classification itself becomes the thing worth reviewing.

Risk
A personal account used for business activity, with no control designed to catch it.
Signal
High-volume, invoice-like payments on an account onboarded and monitored as personal.
Response
Flag the mismatch and reassess the account's classification, don't wait for a volume threshold to act.
🕳️
The Undocumented Escalation
A "no action needed" decision with no record of how it was reached looks identical to a review that never happened.

The FCA's review specifically cited firms failing to evidence what EDD steps were actually taken, and failing to show when senior management sign-off was required. An analyst clearing an adverse media hit as immaterial might be making the right call, but if nothing records what was checked, what was concluded, and whether escalation was needed, an examiner, or a future analyst on the same file, has no way to tell that from a review that simply didn't happen.

Risk
An undocumented "no action needed" decision is indistinguishable from a review that never happened.
Signal
EDD triggers closing out with no record of what was checked or concluded.
Response
Record the trigger, the check, the conclusion, and any sign-off, every time, including when the answer is no action.
🏷️
The Relabelled Batch Job
Calling a shorter periodic cycle "perpetual KYC" doesn't make it one.

A genuinely event-driven system ingests triggers as they happen and routes them for review in something close to real time. A firm that just tightens its periodic cycle, annual instead of biennial, say, has built a faster batch job, not perpetual monitoring. Reviews still only run on scheduled dates, and nothing fires in between when a real change actually occurs. The two are easy to conflate on a slide deck and very different in what they actually catch.

Risk
Calling a shorter periodic cycle "perpetual KYC" without building real event-driven infrastructure.
Signal
Reviews still run on a calendar, just a tighter one, nothing fires between cycles when a real change happens.
Response
Build genuine trigger ingestion and event-driven routing, not a faster version of the same clock.
The Review Cycle

The review cycle, end to end

Four stages, no branching. The scenarios below carry the decision nuance, this is the sequence a case moves through once either kind of review actually fires.

Stage 1 · Detect
A defined trigger fires
Adverse media, ownership change, a transaction pattern shift, or a customer-initiated update.
Stage 2 · Assess
Risk-based review against the current profile
Judged against the customer's current risk profile, not the triggering event in isolation.
Stage 3 · Act
Re-score, escalate, request, or close
Proportionate to what's actually found, not a fixed response regardless of severity.
Stage 4 · Evidence
Record it, whether or not anything changed
What triggered it, what was reviewed, the conclusion, and any sign-off required or obtained.
🎯
Scenario 01 · Defining what counts as a trigger
The Undefined Trigger
The Undefined Trigger
⚖️
What do you do? Make the call

A firm's policy says review is triggered "when a material change occurs" but never defines what counts. A customer's registered address changes from a family home to a serviced office. No one flags it, nothing in the policy says this kind of change counts.

Scenario 02 · Setting a real review cadence
The Frequency Vacuum
The Frequency Vacuum
⚖️
What do you do? Make the call

Policy says periodic reviews happen "regularly" for high-risk customers, no stated interval. Two analysts on the same team review comparable high-risk customers, one at 8 months, one at 22.

🎭
Scenario 03 · Personal account, business activity
The Business-on-a-Personal-Account
The Business-on-a-Personal-Account
⚖️
What do you do? Make the call

A personal current account shows regular, high-volume, invoice-style payments in and out, consistent with business activity. The account was onboarded and is monitored as personal, with no business-activity control layered on top.

🕳️
Scenario 04 · Documenting a "no action" decision
The Undocumented Escalation
The Undocumented Escalation
⚖️
What do you do? Make the call

An EDD trigger fires, an adverse media hit on a customer. An analyst reviews it, decides it isn't material, and moves on. No record exists of what was reviewed, what was concluded, or whether senior management sign-off was required.

Knowledge Check
Five questions. Would you make the same call the scenarios above just walked you through?
1. What did the FCA's 8 April 2026 review find was commonly missing from firms' CDD/EDD policies?
2. Genuine event-driven perpetual KYC architecture requires what, beyond a shorter periodic cycle?
3. What specific control gap did the FCA cite in the Nationwide £44m fine that relates directly to perpetual KYC?
4. Why is documentation required even when an EDD review concludes "no action needed"?
5. Under a risk-based approach, review frequency should be based on what?
0/5
Frequently Asked

FAQ

Isn't perpetual KYC just periodic KYC on a shorter cycle? +
No. A firm that re-points its periodic reviews onto legacy systems with a shorter clock has perpetual KYC in name only. Genuine event-driven design means trigger ingestion, risk-signal routing, and real-time re-scoring, a different architecture, not a faster version of the same one.
What's the actual FCA expectation here? +
Its 8 April 2026 findings treat periodic and event-driven review as two distinct controls and expect firms to define both clearly, with enough operational detail that staff know what to do and reviewers can evidence it happened.
Do small firms need a fully automated event-driven system? +
Not necessarily automated technology, but they do need clearly defined triggers and a documented process for acting on them. The FCA's finding was about clarity and evidence, not a specific technology.
What's the actual difference between periodic and event-driven review? +
Periodic review runs on a schedule set by risk tier, regardless of activity. Event-driven review fires on a specific occurrence, regardless of schedule. Neither substitutes for the other.
What exactly happened at Nationwide? +
Between October 2016 and July 2021, in breach of its own policies, Nationwide had no process for undertaking either periodic or event-driven reviews of a large number of its personal current account customers. One consequence surfaced by the FCA's investigation: a single customer used ordinary personal accounts to receive 24 fraudulent Covid furlough payments totalling £27.3 million over 13 months, with £26.01 million of that landing in just eight days. The FCA fined Nationwide £44,078,500 in December 2025.
Quick Reference

At a glance

Five patterns, the risk that makes each one look routine, the signal that actually gives it away, and the response that fits.

🎯
The Undefined Trigger
A policy that says review "when a material change occurs" without ever saying what counts isn't a control, it's a placeholder.
Risk
An undefined "material change" standard invites inconsistent, indefensible judgement calls.
Signal
Two analysts handling comparable events differently with no documented reason why.
Response
A fixed, documented list of trigger events and thresholds, not open-ended professional judgement.
The Frequency Vacuum
"Regularly" is not a review interval. It's the absence of one, dressed up as a policy.
Risk
"Regularly" as a review interval means some customers go years without a genuine refresh.
Signal
High-risk customers with review dates that vary wildly across a similar book.
Response
An explicit, risk-tiered cadence with a documented escalation when a review runs overdue.
🎭
The Business-on-a-Personal-Account
The account was never reclassified, because nothing was watching for the mismatch.
Risk
A personal account used for business activity, with no control designed to catch it.
Signal
High-volume, invoice-like payments on an account onboarded and monitored as personal.
Response
Flag the mismatch and reassess the account's classification, don't wait for a volume threshold to act.
🕳️
The Undocumented Escalation
A "no action needed" decision with no record of how it was reached looks identical to a review that never happened.
Risk
An undocumented "no action needed" decision is indistinguishable from a review that never happened.
Signal
EDD triggers closing out with no record of what was checked or concluded.
Response
Record the trigger, the check, the conclusion, and any sign-off, every time, including when the answer is no action.
🏷️
The Relabelled Batch Job
Calling a shorter periodic cycle "perpetual KYC" doesn't make it one.
Risk
Calling a shorter periodic cycle "perpetual KYC" without building real event-driven infrastructure.
Signal
Reviews still run on a calendar, just a tighter one, nothing fires between cycles when a real change happens.
Response
Build genuine trigger ingestion and event-driven routing, not a faster version of the same clock.
Quick Reference

Summary snapshot

The full guide in one image, for quick reference or sharing.

Perpetual KYC summary infographic showing periodic review and event-driven review as two controls converging into perpetual KYC, the detect, assess, act, evidence cycle, five failure patterns and their responses, and the FCA's GBP44,078,500 fine against Nationwide for having no process for either control. ⬇️ Download summary
Two Controls, Evidenced Separately

The FCA didn't ask for perpetual KYC by name. It asked firms to prove both controls actually run.

FinCrimeRadar's Scenario Lab puts the same investigative decisions in front of you under real time pressure and partial information, free, no signup required.

Want to practise the decisions rather than read about them? Free. No account needed. Work real cases under time pressure and partial information.
Open the Scenario Lab →
Verification

Sources

Each numbered claim above is checked against the specific source below it. Figures without a bracketed number are illustrative scenario detail, not verified facts.

  1. Financial Conduct Authority, Firms' customer due diligence processes and controls: our findings (multi-firm review), 8 April 2026. fca.org.uk/publications/good-and-poor-practice/firms-customer-due-diligence-processes-and-controls-our-findings
  2. Financial Conduct Authority, FCA fines Nationwide £44m for failings in financial crime controls (press release), 12 December 2025. fca.org.uk/news/press-releases/fca-fines-nationwide-44m-failings-financial-crime-controls
  3. Financial Conduct Authority, Final Notice: Nationwide Building Society, 12 December 2025. fca.org.uk/publication/final-notices/nationwide-building-society-2025.pdf