Customer due diligence should be reviewed when something happens that makes the existing file potentially out of date or unreliable. In UK practice that means changes in the customer, its ownership or control, its screening status, its behaviour or its jurisdictional exposure, plus any internal doubt about information previously obtained.
On this page
What counts as a trigger
A trigger is not simply any change in the data. It is a change that plausibly affects one of the conclusions the firm reached: who the customer is, who ultimately owns or controls it, what the relationship is for, what risk it presents, and whether the measures applied remain adequate. Defining triggers against those five conclusions keeps the set focused and explainable.
Regulatory basis, stated carefully
HMRC's anti-money laundering guidance for supervised businesses describes ongoing monitoring as including keeping customer due diligence and beneficial ownership information current, scrutinising transactions for consistency with the firm's knowledge of the customer, and acting on triggers such as changed circumstances, unusual activity, relevant geographic risk changes and doubts about previously obtained information. It also describes customer due diligence as including customer and beneficial owner checks where applicable, understanding ownership and control, understanding purpose and intended nature, and updating on change.
The FCA's April 2026 review of customer due diligence processes and controls observed that some firms' procedures gave insufficient detail on periodic and event-driven reviews. Those findings describe the firms reviewed rather than a uniform rule for all businesses, and requirements differ by sector and supervisor. This page is general information, not legal or compliance advice.
A practical trigger taxonomy
Grouping triggers into six families makes the set easier to govern, test and report on than a flat list of dozens of rules.
Customer and entity change
- Change of legal name, legal form or company status
- Change of registered or trading address
- Change of directors, officers or authorised signatories
- Dissolution, insolvency or strike-off action
- Group restructuring or acquisition
Ownership and control change
- New or removed beneficial owner above the applicable threshold
- Change in the ownership chain above the immediate parent
- Introduction of nominee, trust or bearer arrangements
- Discrepancy identified against a public register
Screening and public information
- New sanctions, PEP or watchlist match on an existing party
- Change in PEP status, including a new political role
- Credible adverse media relating to financial crime
- Regulatory or law enforcement action against the customer
Behaviour and transactions
- Activity materially inconsistent with the recorded expected pattern
- New product, channel or counterparty type outside the original scope
- Unexplained volume, value or velocity change
- Transaction monitoring alerts clustering on one relationship
Geographic and external risk
- New exposure to a higher-risk jurisdiction
- Change in a jurisdiction's risk classification in the firm's methodology
- Change in the firm's own business-wide risk assessment
Internal doubt and control outcomes
- Doubt about the veracity or adequacy of information previously obtained
- Quality assurance defect found on a related file or cohort
- Expiry of a document or a time-limited verification result
- Remediation or backlog identification
Detection design
Each trigger needs a named source, an evaluation rule and a materiality threshold. Without thresholds, a trigger set generates volume that the operation cannot work, and unworked queues are worse evidence than no queue at all.
- Source. Where the signal comes from: a registry feed, a screening provider, transaction monitoring, customer outreach, an internal control outcome.
- Evaluation. The comparison performed, such as a change against the last recorded value, or a new match above a defined score.
- Materiality. The point at which change matters, for example a change in ownership percentage that crosses the applicable threshold rather than any movement.
- Coverage monitoring. Alerting when a feed stops, arrives late or returns an unexpected volume. Silent failure is the most common way a trigger model quietly stops working.
Agora practitioner interpretation
We would treat trigger configuration as a controlled change like any other financial crime control: documented rationale, approval, pre-release testing against representative cases, version history and post-release monitoring. The FCA's 2026 findings specifically called out weak version control, and trigger logic is exactly the sort of artefact that tends to be edited without a record.
Proportionate response
Match the depth of the review to what changed. A useful convention is three tiers.
- Data refresh. Update the record and log the change. Suitable for non-risk-bearing attribute changes.
- Scoped review. Re-perform the affected checks only, for example verify and screen a new beneficial owner and reassess the customer risk rating. See customer risk assessment.
- Full review or escalation. Re-perform the whole file where the change undermines the basis of the original assessment, or where enhanced due diligence is now engaged.
Where a change concerns a beneficial owner and the firm identifies a discrepancy against the relevant public register, obliged entities have discrepancy obligations to consider, both when establishing a relationship and during ongoing due diligence.
Common pitfalls
- A trigger list in policy that no system actually evaluates.
- Triggers defined without thresholds, producing unworkable volume.
- Every trigger scoped as a full refresh, which slows response to the ones that matter.
- No record of signals that were evaluated and dismissed.
- Manual triggers dependent on a single person noticing something.
- No reconciliation between triggers fired, reviews opened and reviews completed.
Where technology helps
Signal monitoring, rule evaluation, review routing, evidence assembly and trigger performance reporting are all well suited to automation, and CDD automation describes the boundaries. The accountable judgement of whether the resulting file is adequate stays with a person. The Agora Due Diligence Platform supports perpetual KYC and case reporting with configuration under the firm's control.
Primary sources
- HMRC AMLG11411, ongoing monitoring (updated 16 July 2026)
- HMRC AMLG11300, customer due diligence (updated 16 July 2026)
- FCA, Firms' customer due diligence processes and controls: our findings (8 April 2026)
- GOV.UK, report a discrepancy about a beneficial owner on the PSC register
Frequently asked questions
What is a KYC trigger event?
A trigger event is a change or observation that makes existing customer due diligence potentially out of date or unreliable, and so prompts a review. Typical examples include a change of beneficial ownership, a change of legal status or address, a new screening match, activity inconsistent with the expected pattern, a change in jurisdictional exposure, or doubt about information previously obtained.
Are trigger events set out in UK regulation?
The statutory framework requires firms to keep due diligence information current and to conduct ongoing monitoring on a risk-sensitive basis. HMRC guidance describes triggers such as changed circumstances, unusual activity, relevant geographic risk changes and doubts about previously obtained information. The detailed trigger set a firm operates is its own risk-based design decision.
Should every trigger cause a full KYC refresh?
No. Proportionate design scopes the review to what changed and what that change affects. A new beneficial owner requires verification, screening and a risk reassessment of that party. A change of correspondence address may only require a data update and a record of the change.
How quickly should a trigger be worked?
Firms should set timescales by trigger severity and be able to evidence performance against them. Sanctions-related matches are normally handled on an immediate basis under separate obligations, while lower-severity data changes are typically worked within a defined service level.
What evidence should a triggered review leave behind?
The signal received and its source, the rule that evaluated it, the configuration version in force, the scope of the review performed, the checks carried out, the conclusion reached, who reached it and when, and any override with a recorded reason.
Related resources
Remediation and ongoing KYC
Periodic KYC vs Perpetual KYC: What UK Firms Need to Know
Ownership and KYB
Beneficial Ownership and KYB: A Practical UK Guide
Regulatory answer
When should existing customer due diligence be updated?
CDD and onboarding
Customer Risk Assessment: A Practical CDD Framework
Where the technology fits
Agora is a technology provider: the platform supports the control described above, and your own teams operate it and hold the accountable decisions.
Next step
Want triggers that actually fire?
See how monitored signals, trigger rules and scoped reviews are configured and evidenced in one platform.