Insights on Crypto Payments, Infrastructure, and Operations

KYC Refresh

Abbreviation: KYC

Pronunciation: K-Y-C ree-FRESH

Also known as: Periodic KYC review, Customer due diligence refresh, KYC

Definition

A KYC refresh is the periodic or trigger-based review and update of customer identity, beneficial ownership, business activity, risk rating, and supporting due diligence information. It differs from initial onboarding because the objective is to determine whether previously collected information remains accurate and whether new risk indicators require enhanced review or restrictions. Operationally, teams should set risk-based review frequencies, trigger refreshes after material changes, verify beneficial owners and business purpose, and update sanctions and adverse information checks.

Overview

A KYC refresh is the periodic or trigger-based review and update of customer identity, beneficial ownership, business activity, risk rating, and supporting due diligence information.

KYC Refresh is closely connected to Identity Fraud, Integration (Money Laundering), and Risk-Based Vulnerability Management (RBVM). It differs from initial onboarding because the objective is to determine whether previously collected information remains accurate and whether new risk indicators require enhanced review or restrictions.

Operational implementation should set risk-based review frequencies, trigger refreshes after material changes, verify beneficial owners and business purpose, update sanctions and adverse information checks, document outreach, and control overdue cases.

The principal failure modes include stale ownership data, unverifiable businesses, ignored transaction changes, excessive document collection, customer friction, and accounts remaining active after required information expires.

Useful measures include overdue refresh rate, completion time, risk-rating changes, beneficial-owner changes, exit decisions, and cases escalated for enhanced due diligence.

Operationally, teams should set risk-based review frequencies, trigger refreshes after material changes, verify beneficial owners and business purpose, and update sanctions and adverse information checks. Key risks include stale ownership data, unverifiable businesses, ignored transaction changes, and excessive document collection.

Implementation of KYC Refresh should map the periodic or trigger-based review and update of customer identity, beneficial ownership, business activity, risk rating, and supporting due diligence information to the applicable entity, product, customer, transaction, and jurisdictional scope. Evidence for periodic, beneficial ownership, and business activity should preserve the governing requirement, policy version, control execution, exception decision, owner, and review date. Material changes affecting the KYC Refresh context and periodic, beneficial ownership, and business activity should trigger reassessment instead of silent reuse of an outdated conclusion.

Key Takeaway

A KYC refresh is the periodic or trigger-based review and update of customer identity, beneficial ownership, business activity, risk rating, and supporting due diligence information.

Sources

  1. The FATF Recommendations — FATF (2026-08-03)
  2. Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs — FATF (2026-08-03)
  3. Regulation (EU) 2016/679, General Data Protection Regulation — European Union (2026-08-03)