Onboarding a new wealth management client is already slow. A 2025 Capgemini analysis, cited in Backbase's research on wealth management onboarding, found that close to a third of firms take three months or longer to onboard an ultra-wealthy client. That's three months of paperwork before a relationship even properly starts, and it's only the beginning of the review cycle a client sits inside for as long as they stay a client.
The review clock resets slowly after onboarding
Once a client is onboarded, most banks assign a review frequency based on risk tier: roughly every year for higher-risk and politically exposed clients, and every three years or longer for everyone else. That cadence has been standard practice for years, and it exists for a defensible reason. Reviewing every client every month isn't a realistic use of compliance resources.
The tradeoff is real, though. A client's situation can shift substantially inside a three-year window, and the review process has no way to catch that shift until the scheduled date arrives.
What the gap actually costs
According to iDenfy's analysis of continuous monitoring, PwC's 2024 Financial Crime Report found that banks adopting continuous, event-driven KYC monitoring, an approach usually called perpetual KYC, cut their KYC maintenance costs by as much as 40%, largely by replacing blanket periodic reviews with checks triggered by an actual change.
The same analysis points to KYC-related spending industry-wide growing by roughly 140% over five years, up from about USD 9.2 billion in 2024, as regulatory pressure builds and manual review simply stops scaling.
Stale data is the core problem
The industry conversation about KYC tends to focus on fragmentation: client information scattered across CRM systems, core banking platforms, and inboxes. Fragmentation is real, but staleness is the sharper problem underneath it.
A bank's risk-based review model assumes a client's risk profile stays roughly stable between review dates but risk factors can change within moments, while a fixed review schedule may not revisit that client for years. A record can sit in a system, technically available, and still be out of date the moment something changes.
Regulators are shifting the expectation from periodic to continuous
This is showing up in regulatory guidance, too. Per The Compliance Digest, the UK's Financial Conduct Authority, the Financial Action Task Force, and Singapore's Monetary Authority have all moved toward expecting institutions to demonstrate ongoing, risk-responsive monitoring rather than static, calendar-based reviews. The direction is consistent across regulators: technical compliance with a review schedule isn't treated as sufficient on its own if it doesn't produce a genuinely current picture of the client.
Swiss institutions, which operate under FINMA's anti-money-laundering framework, sit inside the same broader shift.
What moving toward continuous monitoring actually requires
Few institutions are running full perpetual KYC today. Most banks can't simply decommission periodic reviews and replace them with a fully automated system in one step. The realistic path is incremental: start with high-risk triggers like adverse media and sanctions changes, then gradually expand into broader event-driven monitoring while keeping a compliance officer in the loop for material decisions.
The underlying requirement is a client picture that updates as new information arrives, whether that information comes from a core banking system, a CRM, or a client conversation. Without that continuously current picture, the shift from periodic to event-driven review isn't possible, regardless of how the policy is written.
Where this leaves compliance teams now
Similar research shows that modernizing KYC operations, including moving toward perpetual monitoring, ranks as one of the top outcomes compliance leaders want from AI, behind only reducing false positives and improving alert triage. The appetite for continuous, always-current client monitoring is already there. What's holding many institutions back isn't the idea. It's confidence that the underlying data and connected systems can actually support it.
Why Periodic KYC Reviews Are Costing Wealth Managers More Than They Realize
Onboarding a new wealth management client is already slow. A 2025 Capgemini analysis, cited in Backbase's research on wealth management onboarding, found that close to a third of firms take three months or longer to onboard an ultra-wealthy client. That's three months of paperwork before a relationship even properly starts, and it's only the beginning of the review cycle a client sits inside for as long as they stay a client.
The review clock resets slowly after onboarding
Once a client is onboarded, most banks assign a review frequency based on risk tier: roughly every year for higher-risk and politically exposed clients, and every three years or longer for everyone else. That cadence has been standard practice for years, and it exists for a defensible reason. Reviewing every client every month isn't a realistic use of compliance resources.
The tradeoff is real, though. A client's situation can shift substantially inside a three-year window, and the review process has no way to catch that shift until the scheduled date arrives.
What the gap actually costs
According to iDenfy's analysis of continuous monitoring, PwC's 2024 Financial Crime Report found that banks adopting continuous, event-driven KYC monitoring, an approach usually called perpetual KYC, cut their KYC maintenance costs by as much as 40%, largely by replacing blanket periodic reviews with checks triggered by an actual change.
The same analysis points to KYC-related spending industry-wide growing by roughly 140% over five years, up from about USD 9.2 billion in 2024, as regulatory pressure builds and manual review simply stops scaling.
Stale data is the core problem
The industry conversation about KYC tends to focus on fragmentation: client information scattered across CRM systems, core banking platforms, and inboxes. Fragmentation is real, but staleness is the sharper problem underneath it.
A bank's risk-based review model assumes a client's risk profile stays roughly stable between review dates but risk factors can change within moments, while a fixed review schedule may not revisit that client for years. A record can sit in a system, technically available, and still be out of date the moment something changes.
Regulators are shifting the expectation from periodic to continuous
This is showing up in regulatory guidance, too. Per The Compliance Digest, the UK's Financial Conduct Authority, the Financial Action Task Force, and Singapore's Monetary Authority have all moved toward expecting institutions to demonstrate ongoing, risk-responsive monitoring rather than static, calendar-based reviews. The direction is consistent across regulators: technical compliance with a review schedule isn't treated as sufficient on its own if it doesn't produce a genuinely current picture of the client.
Swiss institutions, which operate under FINMA's anti-money-laundering framework, sit inside the same broader shift.
What moving toward continuous monitoring actually requires
Few institutions are running full perpetual KYC today. Most banks can't simply decommission periodic reviews and replace them with a fully automated system in one step. The realistic path is incremental: start with high-risk triggers like adverse media and sanctions changes, then gradually expand into broader event-driven monitoring while keeping a compliance officer in the loop for material decisions.
The underlying requirement is a client picture that updates as new information arrives, whether that information comes from a core banking system, a CRM, or a client conversation. Without that continuously current picture, the shift from periodic to event-driven review isn't possible, regardless of how the policy is written.
Where this leaves compliance teams now
Similar research shows that modernizing KYC operations, including moving toward perpetual monitoring, ranks as one of the top outcomes compliance leaders want from AI, behind only reducing false positives and improving alert triage. The appetite for continuous, always-current client monitoring is already there. What's holding many institutions back isn't the idea. It's confidence that the underlying data and connected systems can actually support it.