TartanHQ Logo – Powering Seamless Enterprise Workflows with APIs and AI

Enterprise & Industry Insights

Enterprise & Industry Insights

Perpetual KYC needs perpetual CPV - and most compliance teams haven't made the connection

Perpetual KYC needs perpetual CPV - and most compliance teams haven't made the connection

Perpetual KYC needs perpetual CPV - and most compliance teams haven't made the connection

Rohan Mahajan

Rohan Mahajan

10 Min

10 Min

Build Connected Systems with Tartan

Automate workflows with integrated data across your customer applications at scale

For Chief Compliance Officers, KYC programme leads, and financial crime heads at banks and financial institutions who are investing in pKYC programmes and discovering that the contact layer is the gap nobody budgeted for.

The shift toward perpetual KYC (pKYC) is one of the most significant operational transformations in financial services compliance over the last three years. Instead of the traditional periodic review cycle, where customer records are updated every one, three, or five years depending on risk tier, pKYC replaces the batch cycle with continuous refresh.

Customer identities and profiles are updated in real time based on external triggers: beneficial ownership changes, sanctions list additions, adverse media events, changes in transaction behaviour.

The promise of pKYC is compelling and genuine. Large financial institutions currently spend up to $30 million annually on KYC when onboarding new clients, with over half spending between 61 and 150 days to complete client KYC reviews.

pKYC compresses that cycle dramatically - spreading the verification work continuously rather than concentrating it in expensive batch review periods. It also improves risk sensitivity: a high-risk event triggers an immediate review rather than waiting for the next scheduled cycle.

But most pKYC programmes have a structural gap that the compliance industry has not yet fully confronted. They refresh identity documents, beneficial ownership structures, sanctions screening, and adverse media. They do not continuously verify whether the contact points in the customer record - the phone number, the address, the email - are still active, still reachable, and still belong to the customer they are associated with.

A perpetual KYC programme with stale contact points is not perpetual KYC. It is a programme that knows who the customer is but cannot reliably reach them when something changes - which defeats a central purpose of the exercise.

What pKYC is actually refreshing - and what it is not

To understand the gap, it helps to map what most pKYC programmes are actually refreshing continuously versus what they treat as a one-time capture at onboarding.

What pKYC programmes typically refresh:

  • Sanctions and PEP screening - continuous rescreening against updated lists

  • Adverse media monitoring - real-time alerting on negative news events

  • Beneficial ownership changes - triggered updates when ownership structure changes (see how KYB verification in India struggles with exactly this problem)

  • Transaction behaviour - ongoing monitoring for pattern changes that suggest risk

  • Identity document expiry - alerts when documents approach expiry for renewal

What most pKYC programmes treat as static after onboarding:

  • Mobile phone number - verified once at account opening, not rechecked

  • Residential address - captured at onboarding, updated only if the customer self-reports a change

  • Email address - collected at registration, not validated for ongoing activity or ownership

  • Employment and income contact details - captured for creditworthiness assessment, not maintained

The asymmetry is striking. pKYC programmes invest heavily in refreshing the risk intelligence dimensions of a customer profile - sanctions, ownership, adverse media - while treating the contact dimensions as static facts captured once and trusted indefinitely. But contact data decays. Phone numbers are ported, abandoned, or reassigned. Addresses change as customers move. Email addresses are deactivated or handed over when employment changes.

A customer who has moved three times since account opening, changed their phone number twice, and changed employers is a customer whose contact record is almost certainly stale - even while their identity document, sanctions status, and beneficial ownership are perfectly current. The pKYC programme knows their risk profile has not changed. It does not know it cannot reach them.

Why this matters specifically for pKYC - not just generally

Stale contact data is a problem in any customer lifecycle programme. The reason it is a specifically acute problem in pKYC relates to what pKYC is designed to do when a risk event occurs.

The value of pKYC over periodic KYC is the ability to respond immediately when something changes.

A customer is added to a sanctions list. An adverse media event surfaces. A beneficial ownership change triggers a re-evaluation. The pKYC programme identifies the event in real time and initiates the appropriate response - which, in most cases, includes contacting the customer for enhanced due diligence, requesting updated documentation, or escalating for relationship review.

That contact step is where the stale contact data gap becomes operationally critical. The pKYC programme has identified the risk event correctly and immediately. The compliance team is ready to act. They attempt to reach the customer at the contact details in the record. The phone number is no longer in service. The email bounces. The address returns mail. The immediate response that pKYC was designed to enable is delayed by a manual search for current contact details - which takes days and may not succeed.

In a regulatory context, this delay is not acceptable. If the risk event is a sanctions match, the institution has a regulatory obligation to act immediately. A gap in contact data that delays that action is a compliance failure - not because the pKYC programme missed the event, but because the contact infrastructure could not support the response the event required.

"Some of the most advanced firms are shifting toward perpetual KYC, where customer identities and profiles are constantly refreshed based on real-time data feeds, behavioural analytics, and external triggers. The missing dimension in most of these programmes is whether the customer can actually be reached at the contact details on file when any of those triggers fire."

The regulatory requirement that makes this explicit

In India, the connection between perpetual-style KYC and contact point verification is not just a best practice observation. It is a regulatory requirement.

The RBI's KYC Master Direction, most recently amended in August 2025, includes specific provisions around contact point verification as part of periodic KYC address updates. When a customer updates their postal address during a KYC refresh, the new address must be verified through positive confirmation within two months - and contact point verification is explicitly listed as one of the accepted verification methods.

For sole proprietorship accounts where full documentation cannot be furnished, CPV is specified as the mechanism for establishing that the business genuinely operates from the declared address. This is the same gap Tartan has written about in the context of address verification mistakes in loan underwriting: a clean-looking document on file is not the same as a verified, current address.

These provisions reflect a regulatory recognition that address currency cannot be maintained through self-reporting alone. Customers do not reliably update their address when they move. The onus is on the regulated entity to verify. Contact point verification is the mechanism the regulator has sanctioned for doing so - and the most recent amendment strengthens rather than relaxes this requirement.

For institutions building pKYC programmes in India, the regulatory position is unambiguous: contact point currency is part of KYC compliance, not separate from it. A pKYC programme that refreshes sanctions, beneficial ownership, and adverse media but does not maintain contact point currency is an incomplete programme by the regulator's own definition.

The risk dimensions of contact data staleness in pKYC

Beyond the operational and regulatory arguments, contact data staleness in a pKYC programme creates specific risk exposures that are distinct from the general problem of stale contact records.

Identity continuity risk. If a customer's phone number has been reassigned to a different person since onboarding, communications sent to that number - including OTPs, account alerts, and compliance notifications - are reaching someone who is not the customer. In a pKYC context, this means that risk-triggered communications may be delivered to the wrong person, and responses received may not be from the customer they are attributed to.

The identity continuity that pKYC is designed to maintain is compromised at the contact layer.

Alert fatigue and false escalation risk. When a pKYC programme flags a risk event and initiates outreach through stale contact details, the outreach fails. The failure may be logged as a non-response, which in many compliance workflows triggers an escalation. The escalation consumes compliance team resource on a case that is not genuinely high-risk - the customer was simply unreachable because their contact details are outdated. At scale, stale contact data creates a systematic inflation of the compliance team's false escalation rate, consuming capacity that should be directed at genuine risk events.

Beneficial ownership verification risk. For corporate customers, contact data staleness affects the institution's ability to reach beneficial owners for confirmation when ownership changes trigger a review. A beneficial owner whose contact details have not been updated since the entity was onboarded may have changed their phone number, moved address, or changed email provider. The pKYC trigger fires correctly. The outreach to the beneficial owner fails. The review stalls. The regulatory obligation remains unmet. This is one of the reasons KYB in India needs verified, current business data rather than a one-time snapshot from onboarding.

What perpetual CPV looks like in a pKYC programme

Perpetual CPV is not a separate programme running alongside pKYC. It is a contact data maintenance layer integrated into the pKYC infrastructure - running continuously against the same customer record that pKYC is refreshing on other dimensions.

The implementation has three components that together provide continuous contact data currency.

Trigger-based CPV at risk events. Every time the pKYC programme identifies a risk event that will require customer outreach, it runs a CPV check before initiating the outreach. Is the phone number currently active? Does it belong to a live subscriber? Is the address currently deliverable? This check takes milliseconds, costs a fraction of the outreach it enables, and eliminates the failure mode of risk-triggered outreach going to stale contact points. Tartan's approach to digital CPV for detecting profile fraud in lending is built on the same principle: verify at the moment it matters, not on a fixed schedule.

Scheduled periodic CPV at defined intervals. Contact data decays continuously but not uniformly. A programme that runs CPV checks on each customer record at defined intervals - say, every six months for standard-risk customers, every three months for higher-risk tiers - catches the gradual decay that trigger-based checks would miss between risk events. The interval should be calibrated to the decay rate observed in the institution's specific customer base - not assumed from generic benchmarks.

Self-reported change verification. When a customer self-reports a contact change - updates their phone number in the mobile app, requests a new card at a new address, changes their email in account settings - the change triggers an immediate CPV check. Not as a friction-adding step, but as a validation that the new contact details are real before they replace the verified existing ones. This prevents the contact update mechanism from being used to install fraudulent contact details on a legitimate customer record. Tartan's broader KYC suite for corporate and individual verification is designed to plug checks like this directly into the onboarding and monitoring flow, rather than bolting them on separately.

The gap is closeable - and not closing it is getting more expensive

The institutions that have connected their pKYC programme to continuous contact point verification are operationally and regulatorily ahead of those that have not - in a specific, measurable way. Their escalation rate from failed outreach is lower. Their response time to risk-triggered compliance actions is faster.

Their regulatory examination answers are cleaner because the contact record in the system reflects current reality rather than the customer's details from onboarding three years ago.

The institutions that have not made this connection are running pKYC programmes that are sophisticated on the risk intelligence dimensions and fragile on the contact dimensions. The fragility does not show in normal operations. It shows at exactly the moment when pKYC needs to work - when a risk event fires and the institution needs to reach a customer immediately and cannot.

Perpetual KYC without perpetual CPV is a programme that knows more than it ever has about its customers' risk profiles and less than it should about where to find them. That asymmetry is not a design feature. It is the gap that the next programme upgrade needs to close.

One platform. Across workflows.

One platform. Across workflows.

Tartan helps teams integrate, enrich, and validate critical customer data across workflows, not as a one-off step but as an infrastructure layer.

Tartan helps teams integrate, enrich, and validate critical customer data across workflows, not as a one-off step but as an infrastructure layer.

Tartan helps teams integrate, enrich, and validate critical customer data across workflows, not as a one-off step but as an infrastructure layer.