Short answer
Customer due diligence should be updated when the customer's circumstances change, when the firm doubts the veracity or adequacy of information obtained previously, when ownership, screening status, activity or jurisdictional exposure changes in a risk-relevant way, and at review points the firm sets on a risk-sensitive basis. The depth of the update should be proportionate to what changed.
What the rules and guidance say
HMRC's guidance for supervised businesses describes customer due diligence as including customer and beneficial owner checks where applicable, understanding ownership and control, understanding the purpose and intended nature of the relationship, ongoing monitoring, record keeping and updating information on change. Its ongoing monitoring guidance describes keeping customer due diligence and beneficial ownership information current, transaction monitoring, and acting on triggers such as changed circumstances, unusual activity, relevant geographic risk changes and doubts about previously obtained information.
The Money Laundering Regulations 2017 provide the statutory framework. The FCA's April 2026 findings on customer due diligence processes and controls observed, among other weaknesses, insufficient detail in procedures covering periodic and event-driven reviews. That is an observation about the firms reviewed rather than a uniform rule, and requirements vary by sector and supervisor. This page is general information, not legal or compliance advice.
Practical implications
Most firms translate this into four update routes.
- Event-driven update. Prompted by a monitored signal such as an ownership change, a new screening match, a change of legal status or a material change in activity. See KYC trigger events.
- Scheduled review. A backstop by risk band so that no file stands indefinitely without human attention.
- Doubt-driven review. Prompted by the firm's own concern about the adequacy or accuracy of what it holds, including defects found through quality assurance.
- Programme remediation. Where a cohort is found to be deficient, handled as a scoped programme rather than case by case. See KYC remediation.
Each route should define what is re-performed, within what timescale, and what evidence the update leaves behind, including where the conclusion was that nothing further was required.
Agora practitioner interpretation
The practical failure point is rarely the policy. It is that the firm has no mechanism to learn that something changed. A policy stating that files are updated on change of ownership has little value if nothing monitors ownership between reviews.
We would also record non-updates explicitly. Where a signal was evaluated and no update was required, that conclusion is part of the audit trail and is frequently what a reviewer asks for first.
Primary sources
- HMRC AMLG11411, ongoing monitoring (updated 16 July 2026)
- HMRC AMLG11300, customer due diligence (updated 16 July 2026)
- FCA, Firms' customer due diligence processes and controls: our findings (8 April 2026)
- The Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017
Frequently asked questions
Does every change require a full CDD refresh?
No. Proportionate practice scopes the update to what changed and what it affects. A new beneficial owner requires identification, verification, screening and a risk reassessment; a change of correspondence address usually requires a recorded data update only.
What if the firm doubts information it obtained previously?
Doubt about the veracity or adequacy of previously obtained information is itself a reason to revisit due diligence. HMRC guidance identifies doubts about previously obtained information among the circumstances that should prompt action under ongoing monitoring.
Should activity that does not match the recorded expectation prompt an update?
Yes, where the divergence is material. Either the activity is explained and the recorded purpose and intended nature should be updated, or it is unexplained and the relationship warrants further review and possible escalation.
Related resources
Remediation and ongoing KYC
KYC Trigger Events: When Should Customer Due Diligence Be Reviewed?
Regulatory answer
Does UK regulation require periodic KYC reviews?
Remediation and ongoing KYC
KYC Remediation: How to Modernise Customer File Remediation
CDD and onboarding
Enhanced Due Diligence (EDD): Triggers, Evidence and Controls
Next step
Keeping files current without a full refresh
See scoped, triggered updates and their evidence trail in the Agora Due Diligence Platform.