Join our Newsletter — 33% off our NHI Course

What happens when a business relies on a one-time KYC check instead of ongoing due diligence?

A one-time check leaves the institution blind to later risk changes. A customer who looked low risk at onboarding may begin moving funds in new ways, opening exposure to money laundering, fraud, or sanctions risk. Without periodic review, the business can miss the point where the relationship should be escalated, restricted, or reported to compliance teams.

Why a One-Time KYC Check Stops Being Enough

A one-time KYC check only tells you what the customer looked like at onboarding. That is useful for initial risk acceptance, but it is not a durable view of behaviour, ownership, or purpose. Over time, customer activity, counterparties, geography, product use, and adverse news can change in ways that materially alter the institution’s AML and sanctions exposure.

In practice, the weakness is not simply that the file goes stale. It is that the business can keep treating a relationship as low risk after the facts have changed. FATF Recommendations — AML and KYC Framework makes ongoing customer due diligence a core part of the control model because customer risk is dynamic, not static.

What Changes After Onboarding

Ongoing due diligence is what catches the change events that initial onboarding cannot predict. A customer may begin sending funds to new jurisdictions, create unusual transaction patterns, add beneficial owners, change business activity, or become linked to adverse media or sanctions exposure. Any of those can shift the risk profile enough to justify enhanced review, account restrictions, or filing an internal escalation.

The point is not to review everyone constantly at the same depth. The point is to have a process that re-evaluates customers when risk triggers appear, or at defined intervals based on the relationship’s profile. That is why a one-time KYC check becomes a blind spot once the customer’s behaviour no longer matches the original profile. EBA AML/CFT Guidance is relevant here because it reflects the expectation that customer due diligence remains active through the life of the relationship.

Why This Creates Compliance and Detection Gaps

When review is not periodic or event-driven, suspicious activity can build for weeks or months before anyone notices. That creates a detection gap, but also an accountability gap: the business may be unable to show that it had a reasonable basis for continuing the relationship once the customer’s risk changed. The same problem affects sanctions screening, fraud monitoring, and beneficial ownership changes, because each of those can make a previously acceptable customer materially different.

Operationally, this means teams should not treat onboarding as the control outcome. They should treat it as the starting point for customer risk management. FinCEN is a useful reference point for the reporting and AML expectations that follow when suspicious patterns emerge and the institution must decide whether escalation is warranted.

Risk and Threat Considerations

A one-time KYC process creates exposure to laundering, fraud, sanctions evasion, and hidden ownership changes because it assumes the customer’s risk remains stable after onboarding. That assumption fails most often where transaction behaviour changes gradually, which is exactly how many abusive relationships avoid attention.

Failure mechanism: the control only verifies identity and purpose once, then stops testing whether later activity still fits the original risk profile. That lets higher-risk behaviour accumulate without triggering review, escalation, or case management.

Impact: the institution can miss suspicious activity, continue servicing a customer it would now reject or restrict, and face regulatory, financial, and reputational consequences when the gap is discovered.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy Ongoing KYC depends on a lifecycle risk strategy for changing customer exposure.
Recommendation — Define customer review triggers and review intervals in the enterprise risk strategy.
NIST SP 800-53 Rev 5 AU-6 — Audit Record Review, Analysis, and Reporting Periodic review and escalation rely on analysing activity for suspicious change patterns.
IA-12 — Identity Proofing KYC begins with identity proofing, but the question is about why proofing alone is insufficient.
AC-2 — Account Management Ongoing due diligence affects whether customer access or service should continue unchanged.
Recommendation — Review account activity and escalate anomalies that change the customer risk picture. Use identity proofing as onboarding input, then pair it with ongoing customer due diligence. Reassess account status when customer risk changes and restrict or disable access as needed.
ISO/IEC 27001:2022 A.5.7 — Threat intelligence Adverse media, sanctions shifts, and typologies are part of ongoing customer risk awareness.
Recommendation — Feed new threat and typology information into periodic customer review decisions.

Practitioner Guidance

What to verify: confirm that the KYC process is tied to review triggers, not just onboarding completion. The practical test is whether the business can point to a documented reason why a customer stayed low risk despite material changes in activity, geography, ownership, or adverse information.

Decision rule: if a customer’s behaviour no longer matches the original risk assessment, treat the case as a due diligence update rather than a simple monitoring alert. The response should be able to move from review to restriction or escalation without waiting for a separate “periodic review” calendar event.

Practitioner takeaway: one-time KYC is acceptable only as an initial control; it becomes unsafe when the organisation confuses “known at onboarding” with “known now.” The control objective is continuous risk awareness, not a permanent clearance stamp.