Ongoing monitoring with risk-based updating is one of two parts of US customer due diligence that run for as long as a customer relationship does; the other is the customer risk profile. Around the difference in wording, the current US texts agree. None of them sets a schedule for refreshing customer information, and each ties the update to what monitoring finds.
The difference lands in the update trigger written into a bank’s procedures, which is where this part of customer due diligence is designed. The manual and FinCEN’s answer are the two texts a bank would draft that trigger from. Because no text gives a number of months, a refresh calendar is the bank’s own risk-based choice, and what examiners test is the process around it.
The four elements of customer due diligence
The Financial Crimes Enforcement Network (FinCEN) named four core elements of customer due diligence (CDD) in its final rule of May 11, 2016. These are the four customer due diligence requirements:
- customer identification and verification;
- beneficial ownership identification and verification;
- understanding the nature and purpose of customer relationships to develop a customer risk profile; and
- ongoing monitoring for reporting suspicious transactions and, on a risk basis, maintaining and updating customer information.
The first was already an anti-money laundering (AML) program requirement, and the second was new with the rule. FinCEN wrote that the third and fourth “are already implicitly required” for covered financial institutions to comply with their suspicious activity reporting requirements, and it amended the AML program rules to make them explicit. The rule took effect on July 11, 2016, and covered financial institutions had until May 11, 2018 to comply. FinCEN’s FAQs describe the result as an AML program with five minimum elements: a system of internal controls, independent testing, a designated compliance officer or individuals responsible for day-to-day compliance, training for appropriate personnel, and “appropriate risk-based procedures for conducting ongoing CDD.”
For banks, the third and fourth elements are written into 31 CFR 1020.210. In the text in force, as the eCFR displays it up to date as of September 30, 2026, paragraph (a)(2)(v) requires a bank regulated by a Federal functional regulator to have:
Appropriate risk-based procedures for conducting ongoing customer due diligence, to include, but not be limited to: (A) Understanding the nature and purpose of customer relationships for the purpose of developing a customer risk profile; and (B) Conducting ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information.
Customer information includes information on the beneficial owners of legal entity customers. For a bank lacking a Federal functional regulator, the same text appears at paragraph (b)(2)(v). The section took its current form in a FinCEN rule published on September 15, 2020 (85 FR 57137).
Beyond identity, then, customer due diligence in US banking rests on two program requirements that run for the whole relationship: the customer risk profile, and ongoing monitoring with risk-based updating. Both have been explicit in 31 CFR 1020.210 since FinCEN’s 2016 rule, as the general CDD element of a bank’s AML program. That element is separate from the special due diligence programs for correspondent accounts of foreign financial institutions and for private banking accounts at 31 CFR 1010.610 and 1010.620. The same element appears in the program rules for broker-dealers, mutual funds, futures commission merchants and introducing brokers; what follows concerns it as it applies to banks.
The customer risk profile, and whether it has to be a rating
FinCEN’s 2016 rule defines the customer risk profile by what it is for:
A customer risk profile refers to the information gathered about a customer at account opening used to develop a baseline against which customer activity is assessed for suspicious activity reporting. This may include self-evident information such as the type of customer or type of account, service, or product. The profile may, but need not, include a system of risk ratings or categories of customers.
The rule’s preamble describes the profile at work. Its information is used, among other sources, to identify transactions that are not of the sort the customer would normally be expected to engage in. It may be integrated into the institution’s automated monitoring system, and after a potentially suspicious transaction has been identified, it may be used as one means of deciding whether the activity is suspicious. FinCEN’s FAQs give examples of the activity the baseline covers, such as a customer’s expected use of wires or typical number of deposits in a month. That baseline is what transaction monitoring assesses the customer’s activity against.
Every customer and account needs a profile. FinCEN’s FAQs say that understanding the nature and purpose of the relationship to develop one “is required for all customers and accounts.” For certain lower-risk customers, the profile can rest on inherent or self-evident information, such as the type of customer, account, service or product, or on information obtained at first account opening, and the documentation needed varies with the type of customer, account, service or product.
A rating is one way to express a profile, and it is optional. According to FinCEN’s August 2020 FAQs, covered institutions are not required to use a specific method or categorization to establish a customer risk profile, and they are not required or expected to automatically categorize as “high risk” the products or customer types listed in government publications. The program must still be detailed enough to distinguish between significant variations in customer risk. There are no prescribed categories for customer risk classification, and their number and detail can vary.
The examination manual, issued by the Federal Financial Institutions Examination Council (FFIEC), uses the other common name. It says a bank should understand the money laundering and terrorist financing risks of its customers, “referred to in the rule as the customer risk profile. This concept is also commonly referred to as the customer risk rating.” In the manual, the factors for a customer risk profile are “substantially similar” to the risk categories the bank considers for its overall risk profile: products and services, customers and entities, and geographic locations. Actual or anticipated activity in the customer’s account “can be a key factor.” The assessment of a single customer and the bank’s overall risk profile thus draw on substantially similar categories, applied at two different levels.
Examiners look at the process more than at individual results. The manual says they “should primarily focus on whether the bank has effective processes to develop customer risk profiles,” and may review individual customer risk decisions to test that process. A bank with an established and effective decision process that followed its procedures should not be criticized for individual decisions unless the decision affects the effectiveness of the overall CDD program or comes with evidence of bad faith or other aggravating factors.
In a joint statement in July 2022, the Federal Reserve Board, the Federal Deposit Insurance Corporation (FDIC), FinCEN, the National Credit Union Administration (NCUA) and the Office of the Comptroller of the Currency (OCC) said that no customer type presents “a single level of uniform risk,” that banks must apply a risk-based approach to CDD, including when developing their customers’ risk profiles, and that the manual’s sections on particular customer types are not intended to signal that those types are uniformly higher risk.
How often KYC has to be updated
None of the current US texts on the general CDD element, as of October 3, 2026, sets an interval for refreshing customer information. That holds for 31 CFR 1020.210, FinCEN’s 2016 preamble, its consolidated FAQs, the manual’s Customer Due Diligence overview and its nine examination procedures, the 2022 joint statement, FinCEN’s February 2026 order, and the 2026 program proposals, which keep the obligation unchanged. What the texts define instead is a trigger. The update follows from what monitoring brings to light, the institution must decide in its procedures whether and when to update on the basis of risk, and a periodic review is a choice the institution makes.
Under FinCEN’s 2016 preamble, an institution “must update the customer information” when it detects information about a customer in the course of its normal monitoring, including a change in beneficial ownership information, that is “relevant to assessing or reevaluating the risk posed by the customer.” The preamble’s examples are a significant and unexplained change in the customer’s activity, such as cross-border wire transfers for no apparent reason, and a significant change in the volume of activity without explanation. The same passage says the provision “does not impose a categorical requirement” to update customer information, beneficial ownership information included, on a continuous or periodic basis: “the updating requirement is event-driven, and occurs as a result of normal monitoring.”
FinCEN’s FAQ F.6, issued on August 3, 2020, answers the scheduling question directly: “There is no categorical requirement that financial institutions update customer information on a continuous or periodic schedule.” The same answer calls the requirement risk based and ties it to normal monitoring, and it leaves periodic review to the institution, which “may choose” to review customer information on a regular or periodic basis. When monitoring brings to light a change relevant to assessing the customer’s risk, the institution must update the information and, where that information is relevant to the risk of the relationship, should reassess the customer risk profile or rating under its own procedures, which is how a finding from case management reaches the profile.
Under FAQ F.4, from the same August 2020 set, covered institutions “must establish policies, procedures, and processes for determining whether and when, on the basis of risk, to update customer information to ensure that customer information is current and accurate.” For beneficial ownership, FAQ B.18, from April 2018, adds that a periodic review is not by itself a trigger to obtain or update the information. Absent a risk-related trigger, that is left to institutions’ discretion, to be exercised “as often as they deem appropriate.”
According to the manual, a bank’s procedures “should establish criteria for when and by whom customer relationships will be reviewed,” including updating customer information and reassessing the risk profile, and should indicate who in the organization is authorized to change a customer’s risk profile. The manual lists seven factors that may be relevant to when a review is appropriate:
- significant and unexplained changes in account activity;
- changes in employment or business operation;
- changes in ownership of a business entity;
- red flags identified through suspicious activity monitoring;
- law enforcement inquiries and requests, such as criminal subpoenas, National Security Letters and section 314(a) requests;
- results of negative media search programs;
- the length of time since customer information was gathered and the profile assessed.
The last is the only time-based factor of the seven, and the manual attaches no length of time to it. For higher risk profile customers, it asks for more frequent review without giving an interval: their information and transactions “should be reviewed more closely at account opening and more frequently throughout the term of their relationship with the bank.” The manual also says the ongoing monitoring element does not impose a categorical requirement to update customer information on a continuous or periodic basis, and that a bank “may establish” policies for determining whether and when, on the basis of risk, periodic reviews should be conducted.
FinCEN wrote in 2016 that its requirements “represent a floor, not a ceiling,” and that institutions may do more in circumstances of heightened risk. A periodic review calendar for ongoing due diligence sits above that floor. Whether to run one, and at what intervals, is the bank’s risk-based choice.
What examiners test instead of a schedule
With no schedule to check, examination tests the process: whether customer information reaches the profile and the baseline used in transaction monitoring, who may change a rating, and when more information is collected for higher-risk customers.
The manual states the expectation. A bank “is expected to use the customer information and customer risk profile in its suspicious activity monitoring process” to understand the transactions a customer would normally be expected to engage in, “as a baseline against which suspicious transactions are identified.” Its CDD policies should contain a clear statement of responsibilities, “including procedures, authority, and responsibility for reviewing and approving changes to a customer’s risk profile, as applicable.”
The examination procedures for the section, as displayed on October 3, 2026, turn those expectations into tests:
- Procedure 1 asks whether the bank’s written procedures let it use customer information and the customer risk profile as that baseline.
- Procedure 2 asks whether the bank has effective processes to develop customer risk profiles that identify the specific risks of individual customers or categories of customers.
- Procedure 4 tests the statement of authority to change a customer’s risk profile.
- Procedure 5 asks whether the bank’s policies for identifying higher-risk customers include “whether and/or when, on the basis of risk, it is appropriate to obtain and review additional customer information.”
- Procedure 8, transaction testing, has examiners select a sample of customer information and determine whether the bank “effectively incorporates customer information, including beneficial ownership information for legal entity customers, into the customer risk profile.” The sample can be taken while examiners review transactions or accounts for possible suspicious activity.
None of the nine procedures sets or tests a review frequency.
Under FinCEN’s FAQ F.7, issued on April 3, 2018 and updated on May 6, 2026, an institution may use its existing monitoring processes for the monitoring and updating obligations if those processes let it meet the rule. The answer quotes the 2016 preamble: “current industry practice to comply with existing expectations for SAR reporting should already satisfy this proposed requirement.”
The 2022 joint statement describes what the manual is: it “provides guidance to examiners for carrying out BSA/AML examinations and assessing a bank’s compliance with the BSA; it does not establish requirements for banks.” The requirements examiners assess are FinCEN’s. After FinCEN added CDD to its program rules in 2016, the Federal Reserve and the other banking agencies did not adopt CDD requirements in their own program rules, and they examine their banks for compliance with FinCEN’s, as the Federal Reserve Board recounted in its July 2026 proposal.
Where the manual and FinCEN part ways
The manual’s Customer Due Diligence section is out of step with FinCEN’s current texts in two respects: it words the update requirement differently from FinCEN’s current answer, and it cites a paragraph of the regulation that no longer exists.
According to the FFIEC’s change history log, the section was last revised on May 11, 2018, the rule’s compliance date. The manual was revised again on April 15, 2020, February 25, 2021, June 21, 2021, December 1, 2021, August 2, 2023 and February 27, 2026, and none of those revisions included the section. The most recent removed references to reputation risk from five other sections.
As displayed on October 3, 2026, the section words the update requirement this way:
The requirement to update customer information is event-driven and occurs as a result of normal monitoring. Should the bank become aware as a result of its ongoing monitoring that customer information, including beneficial ownership information, has materially changed, it should update the customer information accordingly. Additionally, if this customer information is material and relevant to assessing the risk of a customer relationship, then the bank should reassess the customer risk profile/rating and follow established bank policies, procedures, and processes for maintaining or changing the customer risk profile/rating.
For the first sentence, the manual cites FinCEN’s 2016 preamble at 81 FR 29399, the page on which FinCEN wrote that an institution “must update” customer information when it detects information relevant to assessing or reevaluating the risk posed by the customer.
On August 3, 2020, FinCEN, “in consultation with the federal functional regulators,” issued guidance with an answer that follows the manual’s three sentences:
The requirement to update customer information is risk based and occurs as a result of normal monitoring. Should the financial institution become aware as a result of its ongoing monitoring of a change in customer information (including beneficial ownership information) that is relevant to assessing the risk posed by the customer, the financial institution must update the customer information accordingly. Additionally, if this customer information is relevant to assessing the risk of a customer relationship, then the financial institution should reassess the customer risk profile/rating and follow established financial institutions policies, procedures, and processes for maintaining or changing the customer risk profile/rating.
That answer is F.6 in FinCEN’s consolidated CDD Rule FAQs, labeled “Issued August 3, 2020” and carrying no 2026 update in the set FinCEN re-issued on May 6, 2026. Side by side, the two texts differ in four places:
| Where they differ | FFIEC manual, Customer Due Diligence section (last revised May 11, 2018) | FinCEN FAQ F.6 (issued August 3, 2020; re-issued May 6, 2026) |
|---|---|---|
| How the requirement is described | “event-driven” | “risk based” |
| What prompts the update | customer information that “has materially changed” | “a change in customer information … that is relevant to assessing the risk posed by the customer” |
| The verb | “should update” | “must update” |
| When the profile is reassessed | customer information that is “material and relevant” | customer information that is “relevant” |
Both texts say “should reassess”; they part ways on the update itself. The manual keeps “event-driven,” FinCEN’s own phrase from 2016, which the 2020 answer replaced with “risk based.” On the verb and on what prompts the update, the 2020 answer agrees with the preamble page the manual cites, and the manual’s own sentences do not.
The citations have drifted too. The section’s footnotes cite the element as 31 CFR 1020.210(b)(5), (b)(5)(i) and (b)(5)(ii). In the regulation as the eCFR displays it, up to date as of September 30, 2026, paragraph (b) covers banks lacking a Federal functional regulator and runs from (1) to (3), and the element is at (a)(2)(v) and (b)(2)(v). Other current texts cite the paragraph in force. FinCEN’s February 2026 order cites 31 CFR 1020.210(a)(2)(v)(B), the 2022 joint statement cites 1020.210(a)(2)(v), and so does the manual’s own “Introduction – Customers” section, added on December 1, 2021.
In a bank’s written procedures, this shows up in two places. An update trigger drafted from the manual adds a materiality threshold and says “should”; one drafted from FinCEN’s answer has no materiality threshold and says “must.” And a policy that cites (b)(5) cites a paragraph that is not in the regulation; the element appears at (a)(2)(v), or at (b)(2)(v) for a bank without a Federal functional regulator.
What changed in 2026
Two 2026 developments make a bank’s ongoing due diligence procedures matter more without changing what they must do. For an institution that uses the relief in FinCEN’s February order, those procedures take on a second job, and the program proposals would restate the obligation in new places while keeping its substance.
The order is FIN-2026-R001, issued by FinCEN on February 13, 2026. It lets a covered institution limit identification and verification of a legal entity customer’s beneficial owners to three circumstances, the third being “as needed based on a covered financial institution’s risk-based procedures for conducting ongoing customer due diligence.” Using the relief is at the institution’s discretion. For an institution that uses it, the procedures that decide when customer information is updated also decide, under that third circumstance, when beneficial owners are identified and verified again. The order also states that institutions “must comply with all other applicable AML/CFT requirements under the BSA, including the obligation to conduct ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information.”
FinCEN then re-issued its CDD FAQs as one consolidated set, bringing together the sets of 2016, 2018 and 2020 and aligning them with the order. The updates are dated May 6, 2026. The answers on the profile and on updating customer information, F.1, F.2, F.4, F.5 and F.6, carry no 2026 update.
The second development is a set of program proposals. FinCEN’s proposed rule on anti-money laundering and countering the financing of terrorism (AML/CFT) programs, issued on April 7, 2026 and published in the Federal Register on April 10, 2026 (RIN 1506-AB72), would place ongoing CDD under internal policies, procedures and controls, at proposed 31 CFR 1020.210(b)(1)(iii), and “retain these ongoing CDD obligations without alteration.” FinCEN says the change “is not intended to have any effect on the substance of ongoing CDD obligations.” Comments closed on June 9, 2026.
The proposal would also add institution-level “risk assessment processes” that evaluate the risks of the institution’s business activities, “including products, services, distribution channels, customers, and geographic locations,” and that are updated “promptly upon any change that the financial institution knows or has reason to know significantly changes the institution’s ML/TF risks.” Those processes assess the institution, with customers as one category of its risk, and belong with the AML program and its bank-wide risk assessment. The customer risk profile assesses one customer and sets the baseline that customer’s activity is monitored against.
The OCC, FDIC and NCUA proposed corresponding changes to their own rules on April 10, 2026. On July 9, 2026, the Federal Reserve Board proposed to add CDD as a required component of its own program rule, saying the addition “would mirror FinCEN’s existing rule” and “should not alter current compliance practices”; comments closed on September 8, 2026. On updating the risk assessment processes, the Board is “not prescribing any particular time frame.”
No final program rule from FinCEN or the banking agencies had been published in the Federal Register as of October 3, 2026. As proposed, FinCEN’s rule would change the paragraph a bank’s procedures cite for ongoing customer due diligence and, by FinCEN’s account, leave the obligation itself as it is.
Next read: KYC and KYB compliance systems
Source register
S1. Office of the Federal Register — Electronic Code of Federal Regulations — 31 CFR 1020.210, Anti-money laundering program requirements for banks, text as displayed up to date as of September 30, 2026; current form from 85 FR 57137, September 15, 2020. Supports: the ongoing customer due diligence element for banks with and without a Federal functional regulator; beneficial ownership information as customer information; the paragraph numbering in force.
S2. Financial Crimes Enforcement Network — Final rules — Customer Due Diligence Requirements for Financial Institutions, 81 FR 29398, May 11, 2016. Supports: the four core elements and their origin; the effective and compliance dates; the definition of the customer risk profile and its use in monitoring; the duty to update customer information on a relevant change; the absence of a periodic requirement; the requirements as a floor.
S3. Financial Crimes Enforcement Network — Guidance — CDD Rule FAQs, consolidated and re-issued, with updates dated May 6, 2026 (PDF). Supports: the dates of the rule; the five minimum program elements; the profile for all customers and accounts, and optional ratings; the profile as a baseline; no prescribed method or categories; whether and when to update; no categorical schedule, and the duty to update and reassess; periodic reviews and beneficial ownership; use of existing monitoring processes; the consolidation and its alignment with the February 2026 order.
S4. Federal Financial Institutions Examination Council — BSA/AML Examination Manual — Customer Due Diligence — Overview, as displayed October 3, 2026. Supports: the profile as what is commonly called the customer risk rating; customer risk factors; differentiation without required categories; examiners’ focus on process; authority to change a risk profile; use of the profile in suspicious activity monitoring; closer and more frequent review of higher risk profile customers; review criteria and the seven review factors; the manual’s wording of the update requirement; its citations to 31 CFR 1020.210(b)(5).
S5. Federal Financial Institutions Examination Council — BSA/AML Examination Manual — Customer Due Diligence — Examination Procedures, as displayed October 3, 2026. Supports: the nine examination procedures, including the profile as a baseline, authority to change a risk profile, additional information for higher-risk customers and transaction testing; the absence of a review frequency.
S6. Federal Financial Institutions Examination Council — Change history log — FFIEC BSA/AML Examination Manual Change History Log, February 27, 2026. Supports: the last revision of the Customer Due Diligence section on May 11, 2018; the dates and scope of later revisions, including February 27, 2026; the date the “Introduction – Customers” section was added.
S7. Board of Governors of the Federal Reserve System, Federal Deposit Insurance Corporation, Financial Crimes Enforcement Network, National Credit Union Administration and Office of the Comptroller of the Currency — Joint statement — Joint Statement on the Risk-Based Approach to Assessing Customer Relationships and Conducting Customer Due Diligence, July 6, 2022. Supports: no customer type presenting a single level of uniform risk; risk-based customer risk profiles; the manual as guidance for examiners that does not establish requirements for banks; the citation to 31 CFR 1020.210(a)(2)(v).
S8. Financial Crimes Enforcement Network — Order — Exceptive Relief from Requirement to Identify and Verify Beneficial Owners at Each Account Opening, FIN-2026-R001, February 13, 2026. Supports: the three circumstances for identifying beneficial owners, including the institution’s ongoing due diligence procedures; discretion to use the relief; the continuing obligation to maintain and update customer information; the citation to 31 CFR 1020.210(a)(2)(v)(B).
S9. Financial Crimes Enforcement Network — Guidance — Frequently Asked Questions Regarding Customer Due Diligence (CDD) Requirements for Covered Financial Institutions, FIN-2020-G002, August 3, 2020. Supports: issuance in consultation with the federal functional regulators; the original text of the answers on customer risk profiles and on updating customer information.
S10. Federal Financial Institutions Examination Council — BSA/AML Examination Manual — Introduction – Customers, as displayed October 3, 2026. Supports: the section’s citation of 31 CFR 1020.210(a)(2)(v).
S11. Financial Crimes Enforcement Network — Fact sheet — Proposed Rule to Fundamentally Reform Financial Institution AML/CFT Programs, April 7, 2026. Supports: the date of the proposal and its comment deadline; the placement of ongoing CDD under internal policies, procedures and controls with no intended effect on its substance; institution-level risk assessment processes and their update standard.
S12. Financial Crimes Enforcement Network — Proposed rule — Anti-Money Laundering and Countering the Financing of Terrorism Programs, 91 FR 18704, April 10, 2026 (RIN 1506-AB72). Supports: the proposal to retain ongoing CDD obligations without alteration at proposed 31 CFR 1020.210(b)(1)(iii).
S13. Board of Governors of the Federal Reserve System — Proposed rule — Anti-Money Laundering and Countering the Financing of Terrorism Programs, 91 FR 42363, July 9, 2026 (Docket No. R-1835). Supports: the banking agencies’ examination of FinCEN’s CDD requirements; the proposal to add CDD to the Board’s program rule without changing compliance practice; the April 10, 2026 proposals of the OCC, FDIC and NCUA; no prescribed time frame for updating risk assessment processes; the comment deadline.

