PLATFORM

The Liminal MCP brings verified market intelligence into your AI tools

Read More

Blog

Perpetual KYC has moved from if to how

September 2, 2026

perpetual-kyc-liminal-blog

For years, perpetual KYC lived in the same category as most compliance modernization ideas: widely endorsed, rarely funded. That era is over. In the Liminal Index for KYC in Banking 2026, 98.8% of banks said perpetual KYC is live, in rollout, or planned within the next 12 months. Among those furthest along, most completed the shift in under 6 months.

When adoption approaches 99%, the interesting question shifts from if to how, and the how is where most programs are struggling.

What perpetual KYC replaces

Perpetual KYC (pKYC) is the shift from reviewing customers on a fixed calendar to verifying them continuously, triggered by events: a change in ownership structure, a sanctions list update, a transaction pattern that breaks profile. Instead of rediscovering risk every 1, 3, or 5 years, the system refreshes the risk picture when something actually changes.

The periodic model it replaces was built for a slower threat. Today’s fraudsters generate documents, faces, and entire identities with AI, and our data shows what that does to a calendar-based process: 83% of banks manually review more than 10% of their KYC cases, most spending 30+ minutes per case, with customer-data mismatches (60%) and failed biometric or liveness checks (48%) as the top escalation triggers. Those are exactly the signals synthetic identities are engineered to produce, and fraud in financial services rose roughly 21% between 2024 and 2025, driven heavily by synthetic identity schemes.

Why the shift tipped now

Three forces converged on the same 24-month window.

Regulation set a deadline. The EU AMLR applies from July 2027, and AMLA’s 2026-2027 work programme commits to issuing risk and methodology guidelines by that date, which means supervisory expectations are getting more granular, not less. In the UK, the failure-to-prevent-fraud offence has been in force since September 2025, pushing firms to evidence reasonable, ongoing fraud prevention rather than point-in-time checks. Ongoing due diligence is becoming the supervisory default on both sides of the Channel.

Fraud raised the cost of waiting. Two-thirds of the buyers we surveyed now treat synthetic identity detection as a hard requirement, yet most rate their current stack as only partially equipped for synthetic identities and deepfakes. A periodic review cycle gives a synthetic identity years of runway before anyone looks again.

Economics closed the case. KYC budgets are growing 5.5% while vendor pricing rises 4.8%, so compliance leaders are funding the shift through efficiency, and nothing burns efficiency like analysts spending half an hour per manual review. Event-driven verification is how the math starts working.

The questions have changed

Talk to the teams actually implementing pKYC, and the whether-questions have been replaced by a harder set.

Which events warrant a refresh? Define triggers too broadly, and you’ve replaced an annual review backlog with a daily alert flood. Too narrowly, and you’ve built a periodic review with extra steps.

Which data sources earn their place? Every additional feed promises a signal and delivers some noise. The programs that work treat data quality as the gating criterion, which is consistent with what buyers told us: data quality ties compliance alignment as the top purchasing criterion, rated important by 94% of practitioners.

Can you explain the risk score? Regulators broadly accept automation and AI in KYC now, but acceptance comes with a governance bill: continuous scoring has to be explainable, validated, and monitored. Supervisors care less about whether a machine made the decision than about whether the institution can defend it.

Asked to rank purchasing criteria for the next 2 years, banks elevate analytical capabilities and automation the most, while data quality and ease of implementation recede, not because they matter less but because they’re now assumed of any credible vendor. Hygiene has become table stakes, and intelligence is where the differentiation happens.

The vendor stack is where this gets decided

Here’s the tension defining the 2026-2027 buying cycle: 87% of banks say they want a single, broad financial crimes compliance platform, yet the share of banks running 4 or more KYC vendors roughly doubled year over year. Buyers want consolidation and are living with sprawl, and the market is consolidating around them as slowing funding accelerates vendor roll-ups.

Something has to give, and the data says it will: 55% of banks rate KYC vendor switching as likely in the next 12 months, with a similar share planning to consolidate. That makes this the most open KYC selection cycle the market has seen, and it means the vendors winning the next 2 years are the ones that can prove perpetual monitoring, synthetic identity defense, and platform breadth rather than verification accuracy alone.

We evaluated 86 KYC vendors across product execution, strategy, and market presence to see which ones clear that bar. 20 did.

Key takeaways

  • Perpetual KYC is the operating standard, not the roadmap item: 98.8% of banks have pKYC live, in rollout, or planned within 12 months, and the EU AMLR makes ongoing due diligence a supervisory expectation by July 2027.
  • The implementation questions are the hard ones now: event trigger design, data source selection, and explainable risk scoring separate working programs from rebranded periodic review.
  • Analytics and automation are overtaking hygiene criteria: banks rank analytical capabilities and automation as the fastest-rising purchasing priorities for the next 2 years.
  • The switching window is open: 55% of banks rate a KYC vendor switch as likely in the next 12 months, while 87% push toward consolidated platforms.

Frequently asked questions

What is the difference between perpetual KYC and periodic KYC?

Periodic KYC reviews customers on a fixed schedule, typically every 1 to 5 years based on risk tier. Perpetual KYC replaces the calendar with event-driven triggers, refreshing a customer’s risk profile when something material changes: ownership, sanctions exposure, transaction behavior, or identity signals.

Is perpetual KYC required by regulators?

No regulation mandates pKYC by name, but the direction is unambiguous. The EU AMLR (applying July 2027) and the UK’s failure-to-prevent-fraud regime both push firms toward ongoing, evidence-based due diligence, which periodic review cycles struggle to satisfy.

How long does perpetual KYC take to implement?

Faster than most teams expect. Among banks in the Liminal Index for KYC in Banking 2026 that have already deployed pKYC, the majority completed the rollout in under 6 months.


The full analysis, including capability scorecards and analyst notes for the 20 leading KYC vendors, is in the Liminal Index for KYC in Banking 2026. -> Get Access to the Report

Want real-time, personalized insights?

Get full access to real-time competitor tracking, buyer signals, and personalized intelligence delivered straight into your workflow.

introducing-liminal-mcp

PLATFORM

The Liminal MCP is live

Query Liminal's verified market intelligence from the AI tools your teams already work in.

Read more