Blog
Periodic Review: The Compliance Obligation That Doesn't End at Onboarding
August 26, 2026
Onboarding a client is not the end of your KYC obligations — it is the beginning of them. Once a client passes through your onboarding process, you are required to make a risk assessment of that client: What geography are they from? Are there any hits from an AML point of view? Are they a politically exposed person, or connected to one? A range of factors comes into play when deciding whether to proceed with an onboarding, and those same factors determine how you classify the client — high risk, medium risk, or low risk.

That classification then drives a second decision: at what point should the client be required to go through a refresh of their KYC? This is the periodic review.
Setting the cadence
A common approach is to tie the review cadence directly to the risk rating. For example:
- High risk — review every year
- Medium risk — review every two years
- Low risk — review every three years
The higher the risk, the more frequently you look. Bear in mind, however, that a client's risk profile is not static. It may change from the outset, and when it does, the cadence of periodic review should change with it. A low-risk client who relocates to a high-risk jurisdiction is no longer a low-risk client — and their review schedule should reflect that.
Why periodic review matters
So how do you maintain compliance, and how do you manage your risks effectively over the lifetime of a client relationship?
If you don't have a periodic review process in place, you may, in effect, forget about your clients. Over time, those clients change — their residency, their address, their circumstances — and you may be entirely unaware of it. We live in a world where people regularly move from one jurisdiction to another, and that movement has direct consequences for your risk classification.
Periodic review is the mechanism that surfaces clients in a very large database and ensures you hold the most accurate details for each of them. When a client is asked to complete their periodic review, they may confirm that they have changed their address, or even their country of residency. Without the review, you would never know.
There is a second reason periodic review is essential: your own onboarding procedures and policies will change over the lifecycle of a client. Regulations evolve, and so do your internal requirements. Requesting clients to refresh their KYC is a way of bringing your existing client population into compliance with new requirements — without having to take them through a costly and disruptive remediation exercise.
Automating periodic review with Blockpass
At Blockpass, we have developed an automated periodic review feature that can be enabled directly within your KYC dashboard. Once enabled, it notifies each client ahead of the anniversary of their periodic review, giving them the opportunity to update their profile before the deadline arrives.
The process is fully automated and runs in the background — emails are sent to your users on schedule, without you having to lift a finger. Your compliance obligations are met, your client data stays current, and your team stays focused on the exceptions rather than the routine.
Periodic review isn't optional. But with the right tooling, it doesn't have to be a burden either.

