What triggers a KYC review? AMLA's event list for fund administrators and ManCos
Fredrik Gröndahl7 min readThought Leadership

A KYC review is triggered when something relevant about the customer changes, not only when the calendar says so. AMLA's draft guidelines on ongoing monitoring group those changes into four kinds: changes in identity, ownership or legal status; unusual behaviour or transactions; adverse media or PEP status; and changes in financial situation or business activity.
These are event-driven reviews, also called trigger-based reviews. Together with the periodic review, they make up ongoing monitoring (the AMLR's term), which the market also calls perpetual KYC, pKYC or continuous KYC. This piece is written for compliance teams at fund administrators, management companies and corporate service providers, where most of the existing guidance, written for banks, fits badly.
The draft guidelines were consulted on from 3 June to 3 September 2026, and final guidelines are expected in the fourth quarter of 2026. Everything below that refers to the guidelines refers to the draft, as summarised by CMS.
What the AMLR itself says triggers a review
Before the guidelines, there is the regulation. Article 26(3) of the AMLR requires firms to review, and where relevant update, customer information in three situations: when the relevant circumstances of a customer change, when the firm has a legal obligation in that calendar year to contact the customer to review beneficial ownership information or to comply with Council Directive 2011/16/EU, and when the firm becomes aware of a relevant fact about the customer.
That third limb matters more than it looks. It means a review is owed as soon as the firm knows something, whoever in the firm knows it. A relationship manager who hears about a new controlling shareholder over lunch has, in the regulation's terms, made the firm aware.
Article 26(2) sets the backstop: whatever happens, the file is updated at least every year for higher-risk customers and at least every five years for everyone else. Triggers sit on top of that schedule. They never replace it.
AMLA's four trigger groups, in fund and ManCo terms
The draft names the groups but, sensibly, leaves the examples to the firm. This is how they translate for our clients. The examples and the sources in the table are our reading, not AMLA's text.
| Trigger group (AMLA draft) | Examples at a fund administrator, ManCo or CSP | Where it usually surfaces | What the review re-checks |
|---|---|---|---|
| Identity, ownership or legal status | New controlling shareholder or UBO, change of directors, redomiciliation, merger, change of legal form | Registry filings, beneficial ownership registers, client notifications, corporate secretarial records | Ownership and control chain, verification of new persons, customer risk rating |
| Unusual behaviour or transactions | Subscriptions or redemptions out of line with the profile, payments from unexpected third parties or countries, unusual instructions | Transfer agency and payment monitoring, staff escalation | Purpose and intended nature, source of funds, whether a suspicion needs escalating |
| Adverse media or PEP status | New negative news on the client or a related person; a director or UBO becomes, or stops being, a PEP | Screening alerts, news monitoring | Disposition of the hit, need for enhanced due diligence, risk rating |
| Financial situation or business activity | New business line, new countries of operation, sharp change in size, financial distress | Financial statements, client correspondence, public news | Purpose and intended nature, source of wealth, country exposure |
A trigger is only as good as the source that reveals it
The list is the easy part. The hard part is that every trigger depends on a source reaching the file. A UBO change that sits in a registry nobody checks has not triggered anything. It has simply made the file wrong.
So the useful exercise is not to copy AMLA's list into the policy. It is to write, for each customer type and each trigger, the source that is expected to reveal it and how often that source is checked. Screening covers adverse media and PEP changes well. Ownership changes in a multi-layered fund structure often surface only at the next periodic review, which is exactly the gap event-driven review is meant to close.
A KYC file is a snapshot. Risk is a film. The trigger map is what tells you how many frames you are missing.
What a triggered review has to cover
A trigger does not require a full re-onboarding. The draft's approach is risk-based throughout, and a review of one adverse media hit can reasonably stay narrow. What it cannot do is stay undocumented. The record should show what triggered the review, which parts of the file were re-checked, what changed, and who signed off.
Two points from the AMLR make this broader than it first appears. Recital 71 says the update obligation applies to the business relationship as a whole, not to individual products or services. For a fund administrator providing several services to the same client, a trigger picked up in one service line is a trigger for the relationship.
And a triggered review affects the calendar. Whether it resets the next periodic review date should depend on its scope, a question we covered in ongoing monitoring under AMLR Article 26.
Two things that are not automatic triggers
An expired document is not, on its own, a trigger for re-collection. The draft takes a risk-based approach and asks firms to weigh the customer's risk level, the risk of the issuing country and whether a new document would add relevant information. For a low-risk client whose identity is not in doubt, a passport expiring in the file is a data point, not an event.
A client who does not respond is not a reason to leave the review open indefinitely either. Where updated information cannot be obtained, the draft allows firms to temporarily suspend or restrict the relationship before terminating it under Article 21 of the AMLR, provided the risk is managed in the meantime. Either way, the file should show the attempts made and the decision taken.
Regulators grade evidence, not effort. A trigger that was noticed, reviewed and recorded is worth more than a thorough review nobody can reconstruct.
Fidify's platform works with the screening data a firm already has and keeps the dated record of what triggered each review, what was checked and against what. If you want to see how that looks for your client base, talk to our team.
Frequently asked questions
What triggers a KYC review under the AMLR?
Article 26(3) requires a review when a customer's relevant circumstances change, when the firm must contact the customer that year about beneficial ownership or tax information exchange, and when the firm becomes aware of a relevant fact. AMLA's draft guidelines group the practical triggers into identity, ownership or legal status; unusual behaviour or transactions; adverse media or PEP status; and financial situation or business activity.
Does an expired passport trigger a KYC review?
Not automatically under AMLA's draft guidelines. Firms should weigh the customer's risk, the issuing country's risk and whether a new document would add relevant information before re-collecting.
Does a trigger-based review replace the periodic review?
No. Article 26(2) still sets a maximum of one year between updates for higher-risk customers and five years for all others, and triggers sit on top of that schedule.
What should a triggered review record?
What triggered it, which parts of the file were re-checked, what changed, and who approved the outcome. If the review moves the next periodic date, the record should also say why.
What if the client does not provide updated information?
The draft guidelines allow firms to temporarily suspend or restrict the relationship before terminating it under Article 21 of the AMLR, provided the risk is managed. The attempts and the decision should be on file.
Sources and further reading
Anti-Money Laundering Authority, AMLA consults on draft Guidelines for ongoing monitoring of business relationships, consultation open 3 June to 3 September 2026.
CMS, AMLA publishes draft guidelines on ongoing monitoring under Article 26(5) AMLR, 10 August 2026. Source for the trigger groups, the expired-documents approach, the suspension point and the expected Q4 2026 final date.
Regulation (EU) 2024/1624 (the AMLR), Articles 21 and 26 and Recital 71.
Leitner and Associates, Updating obligations under Article 26(2) AMLR. Summary of Article 26(2), 26(3) and Recital 71.


