Short answer
UK requirements do not set one universal fixed interval for reviewing customer due diligence. They require firms to keep due diligence information up to date and to conduct ongoing monitoring on a risk-sensitive basis. Most firms meet that through a combination of review cycles set by risk rating and event-driven reviews prompted by change, with the cadence documented and justified against their own risk assessment.
What the rules and guidance say
The Money Laundering Regulations 2017 set the statutory framework for customer due diligence and ongoing monitoring in the UK. HMRC's guidance for supervised businesses describes ongoing monitoring as including keeping customer due diligence and beneficial ownership information current, scrutinising transactions for consistency with the firm's knowledge of the customer, and acting on triggers such as changed circumstances, unusual activity, relevant changes in geographic risk and doubts about information previously obtained.
In April 2026 the FCA published findings from a multi-firm review of firms' customer due diligence processes and controls, covering CDD, EDD and ongoing due diligence. Among the weaknesses it observed were procedures that gave insufficient detail on periodic and event-driven reviews, failure to record purpose and intended nature, insufficient evidence of enhanced due diligence, and weak independent assurance and version control. Stronger practice it described included risk-tailored due diligence, documented EDD steps and regular independent testing.
Three distinctions matter when reading those sources together. Statutory requirements are binding. Supervisor guidance explains how a supervisor expects requirements to be met. Published findings describe practice observed in the firms reviewed and do not apply identically to every firm in every sector. This page is general information, not legal or compliance advice.
Practical implications
- A firm needs a documented review model, not simply a habit. The intervals, the risk bands they attach to and the reasoning behind them should be written down.
- The model needs both scheduled and event-driven elements. A calendar alone does not satisfy the expectation that information stays current between review dates.
- Procedures should be specific about what each type of review covers and who concludes it. Generic wording was among the weaknesses the FCA described.
- Performance against the model must be evidenced: reviews due, reviews completed, overdue ageing, triggers fired and worked.
- The model should be independently tested, including whether triggers detect what they are supposed to detect.
Agora practitioner interpretation
We would treat the review interval as a control parameter with a stated rationale and a version history, in the same way as a screening threshold. The common failure is not choosing the wrong interval; it is being unable to show why the interval was chosen, when it last changed, and whether the operation has actually met it.
Firms shortening intervals to appear conservative often create backlogs that leave them in a materially weaker position than a longer, properly evidenced cycle supported by working triggers. See periodic versus perpetual KYC.
Primary sources
- FCA, Firms' customer due diligence processes and controls: our findings (8 April 2026)
- HMRC AMLG11411, ongoing monitoring (updated 16 July 2026)
- HMRC AMLG11300, customer due diligence (updated 16 July 2026)
- The Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017
Frequently asked questions
Is there a fixed statutory interval for KYC reviews in the UK?
No single universal interval is set for all firms and all customers. The framework requires that due diligence information is kept up to date and that ongoing monitoring is conducted on a risk-sensitive basis, which leaves the cadence for the firm to design and justify.
Do firms still need periodic reviews if they run event-driven review?
Event-driven review can carry most of the load where data coverage and trigger design are strong, but most firms retain a backstop interval by risk band so that no customer file goes indefinitely without human attention. The choice should be documented and evidenced either way.
What did the FCA observe about review procedures in 2026?
In its April 2026 findings on firms' customer due diligence processes and controls, the FCA observed weaknesses including insufficient detail in procedures covering periodic and event-driven reviews, alongside weak independent assurance and version control.
Related resources
Remediation and ongoing KYC
Periodic KYC vs Perpetual KYC: What UK Firms Need to Know
Remediation and ongoing KYC
KYC Trigger Events: When Should Customer Due Diligence Be Reviewed?
Regulatory answer
When should existing customer due diligence be updated?
Governance and assurance
KYC Quality Assurance: Designing Effective QC and Independent Testing
Next step
Designing a review model you can evidence
See how review cadence, triggers and evidence capture are configured in the Agora platform.