# KYC Periodic Reviews and EDD Refresh at Commercial Banks: The Risk-Rated Cadence, the Adverse-Media Signal, and Where the AI Agent Actually Adds Time

*July 10, 2026 · 13 min read · Pranay Shetty*

> The BSA/AML compliance program every commercial bank runs treats onboarding KYC as the ceremony and periodic KYC refresh as the graveyard shift. The FFIEC BSA/AML Exam Manual's expectations for ongoing customer due diligence, the risk-rated review cadence, and the enhanced due diligence obligations for higher-risk customers are the operational anchor for a periodic-refresh program that most banks run at a pace that lags the exam expectation. The AI agent's contribution to the refresh loop and where the human reviewer's judgment still has to be the answer.

## The Program Every Bank Runs and Nobody Fully Staffs

Every commercial bank runs a periodic-KYC-refresh program because the [FFIEC BSA/AML Examination Manual](https://bsaaml.ffiec.gov/manual) says the bank has to, and because [31 CFR 1020.210](https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1020/subpart-B/section-1020.210) requires the bank's compliance program to include ongoing customer due diligence. The refresh program looks at existing customers at a cadence set by the customer's risk rating, verifies that the information the bank has on file is current, gathers additional information where enhanced due diligence is required, and updates the customer's risk rating based on the refreshed picture.

The refresh program is, at most banks, chronically behind. The onboarding-KYC program is well-staffed because it is the gating condition for new revenue, and every new commercial-banking account produces the intake work the compliance team has to complete for the relationship to open. The refresh program is the ongoing work that produces no new revenue, competes for the same staff, and gets deferred whenever the onboarding queue is deep. The examiner's review of the refresh program's completion rate against the risk-rated cadence is the specific finding that produces the specific consent order or MRA the bank does not want.

We build the AI agent that runs on commercial-banking customer relationships and participates in the KYC refresh loop at banks. The architecture below is what we run to close the refresh backlog, to redirect the compliance staff's time from information gathering to judgment, and to produce the audit file that supports the bank's ongoing-CDD posture at the exam.

## What 31 CFR 1020.210 and the FFIEC Manual Actually Ask For

The BSA compliance program requirement at 31 CFR 1020.210 includes the "fifth pillar" that FinCEN added in the 2016 CDD Rule: risk-based procedures for conducting ongoing customer due diligence, including understanding the nature and purpose of customer relationships to develop a customer risk profile, and conducting ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information. The rule text is short; the operational content the FFIEC Manual builds on it is where the work is.

The [FFIEC BSA/AML Manual's Customer Due Diligence section](https://bsaaml.ffiec.gov/manual/AssessingComplianceWithBSARegulatoryRequirements/03) sets the expectation for the risk-rated review cadence. Low-risk customers are typically reviewed every three years; medium-risk customers every two years; high-risk customers annually; and specific categories (money service businesses, cash-intensive businesses, non-bank financial institutions, foreign correspondent accounts, and specific enumerated high-risk categories) may require more frequent review or continuous monitoring depending on the specific facts. The cadence is the bank's, not the rule's; the rule expects the bank to set a cadence and to follow it.

The refresh's content is the same set of information the bank collected at onboarding: identifying information about the customer and the beneficial owners, the nature and purpose of the account and the anticipated activity, the source of funds and source of wealth for the customer's transactions, and the customer's ongoing relationship with entities that may implicate the bank's exposure (parent companies, affiliated entities, principal counterparties, foreign operations). The refresh's job is to verify that the information the bank has is current and to identify any changes that would affect the customer's risk rating.

The enhanced due diligence for high-risk customers extends the refresh content. EDD adds source-of-wealth documentation, principal-owner background verification, adverse-media screening at a specific depth, and transaction-pattern review against the anticipated activity. EDD is where the refresh program's staffing pressure is most acute, because EDD reviews take more time per customer and the higher-risk customers require them at the shortest cadence.

## The Risk-Rating Framework and Where the Rating Actually Comes From

The customer risk rating is the anchor for the refresh cadence and the EDD threshold, and the rating's derivation is a specific analytical exercise the bank runs at onboarding and updates at each refresh. The typical risk-rating framework combines several factor categories: customer type (individual, entity, government, financial institution, non-profit), geographic risk (jurisdictions the customer operates in), product and service risk (accounts held, credit facilities, foreign exchange, trade finance), industry risk (SIC/NAICS category and the specific business activity), and transaction pattern risk (volume, velocity, counterparty concentration, cross-border activity).

The rating is a summary of the factors weighted against the bank's specific risk appetite, and the rating's specific value determines the customer's placement in the low/medium/high tier. The rating is the input to the refresh cadence and to the EDD requirement, and the rating's accuracy is the operational basis for the whole refresh program.

The agent's contribution to the rating is the aggregation of the specific factor inputs and the production of the rating value. The specific factors the agent aggregates include transaction-pattern data from the customer's account activity, adverse-media signals from open-source and vendor sources, entity-relationship data from the beneficial-ownership file, sanctions screening from the [OFAC framework](/blog/ofac-sanctions-screening-ai-agents-50-percent-rule), and the customer's own responses to the refresh questionnaire.

The rating's actual value is the human reviewer's judgment. The agent produces the factor inputs and the recommended rating; the reviewer confirms the rating or adjusts based on the specific facts the reviewer's judgment applies. The rating is not automated; the reviewer's judgment is the specific analytical output of the refresh, and the rating is signed off by the reviewer.

## The Refresh Questionnaire and the Customer-Facing Interaction

The refresh's information-gathering step interacts with the customer to confirm existing information, to gather updated information, and to identify any changes that require documentation. The interaction is a customer-facing operational touch, and the touch's quality is a specific customer-relationship factor for the commercial-banking relationship.

The traditional refresh questionnaire has been a paper or PDF form the relationship manager sent to the customer with a request to complete and return. The completion rate on the traditional form is low, the response time is long, and the follow-up cycle to close the refresh takes weeks or months per customer. The refresh program's completion delay against the risk-rated cadence is often driven by the customer's response delay rather than by the bank's internal work.

The agent's refresh interaction is structured to reduce the customer's friction. The agent pre-fills the questionnaire with the information the bank already has on file, presents the questionnaire to the customer through the customer's preferred channel (secure message, phone call, portal), and confirms the specific information the customer needs to update. The customer's response is captured directly, the follow-up questions are asked in the same interaction, and the refresh is closed in a single conversation or two rather than in a multi-week correspondence cycle.

The customer's experience of the refresh moves from a compliance interruption to a routine account-review touch. The commercial customer whose refresh is completed in one interaction, whose relationship manager has been informed of the refresh's completion, and whose account continues without disruption is a customer whose commercial-banking relationship is not being harmed by the compliance-required activity. The customer whose refresh is a source of friction is a customer who may consider whether the relationship is worth the friction, and the commercial-banking retention consequence is real.

## The Adverse-Media Signal and Where Automation Adds Real Value

Adverse-media screening is one of the specific refresh activities where the agent adds meaningful value, because the volume of open-source media the agent can process is much larger than the human reviewer's capacity would allow. The screening looks for coverage of the customer, the customer's principals, and the customer's counterparties that would indicate a change in the customer's risk profile: enforcement actions, criminal charges, civil litigation, regulatory findings, adverse news about business operations, or public reporting on the customer's involvement in specific activities.

The screening's operational challenge is the false-positive rate. Common names, general news coverage that mentions the customer without adverse content, and coverage of similarly-named entities all produce noise the reviewer has to filter through. The agent's screening applies specific filters to reduce the noise: entity-resolution to distinguish the specific customer from similar entities, sentiment and topic classification to filter out neutral coverage, and specific pattern recognition on the categories of adverse content the review is looking for.

The reviewer's job in the screening is not to read every piece of coverage the agent surfaces; it is to review the coverage the agent has identified as most likely relevant. The agent produces the ranked and classified coverage list; the reviewer evaluates the specific pieces the classification highlights and forms the judgment on the customer's risk profile change. The reviewer's time is applied to judgment rather than to the volume review.

The [FinCEN 2020 CDD-Rule preamble](https://www.federalregister.gov/documents/2018/05/11/2018-10108/customer-due-diligence-requirements-for-financial-institutions) specifically identifies adverse-media screening as an appropriate component of the ongoing CDD process, and the FFIEC Manual discusses the expectation that the bank's screening is proportionate to the customer's risk profile. The agent's ability to run screening at higher frequency for higher-risk customers is one of the specific operational improvements the AI program brings.

## The Beneficial-Ownership Refresh and the Ownership-Chain Update

The [CDD Rule's beneficial-ownership collection at 31 CFR 1010.230](/blog/fincen-boi-cdd-corporate-transparency-act-ai-commercial-banking) is a specific piece of the refresh program. The rule at 1010.230(b)(3) requires the bank to update beneficial-ownership information on a risk-based basis, and the update includes the specific changes to the ownership structure or to the identified beneficial owners.

Ownership-chain changes are more common than banks often assume. A commercial customer whose parent structure has been through an acquisition, a reorganization, a new investment round, or a management change may have beneficial owners at the customer's account level that have changed since the original CDD collection. A customer whose ownership was captured accurately at onboarding and has not been refreshed for two years may have a beneficial-ownership file that no longer reflects the actual ownership.

The agent's refresh of the beneficial-ownership file confirms the ownership structure the customer previously provided, gathers documentation of any changes, and updates the ownership chain in the CDD file with the specific evidence of the change. The chain-multiplication analysis is rerun against the updated ownership, and any changes to the identified beneficial owners are noted with the specific rationale.

The refresh's beneficial-ownership component is one of the specific components where the agent's structured intake reduces the reviewer's time meaningfully. The reviewer's job is to confirm the analysis rather than to gather the information, and the specific complex-ownership cases the reviewer needs to look at are the specific cases the agent's intake flags for review.

## The Transaction-Pattern Review and the Anticipated-Activity Comparison

The refresh's transaction-pattern review compares the customer's actual account activity to the anticipated activity the customer described at onboarding (and updated at previous refreshes). The comparison identifies specific divergences: transaction volumes above or below the anticipated range, counterparty patterns different from the anticipated set, cross-border activity different from the anticipated geography, or product usage different from the anticipated scope.

The divergence is not itself a finding; it is a signal that the customer's account activity has evolved and that the customer's risk profile may have changed. The refresh conversation with the customer explores the divergence: has the customer's business grown or shifted, are there new counterparties or new lines of business, has the customer's geographic footprint expanded, and does the customer's description of the anticipated activity need to be updated.

The customer's answers to the divergence questions produce the refreshed anticipated-activity description and, potentially, the specific EDD triggers for a higher-risk classification. A customer whose activity has expanded into a higher-risk geography or into a higher-risk industry is a customer whose risk rating may need to change and whose refresh cadence and EDD requirements may need to intensify.

The agent's transaction-pattern review runs on the account activity data the bank already has, identifies the specific divergences at a specific threshold, and structures the refresh conversation with the customer to explore each divergence. The reviewer's judgment on the risk-rating implication of the specific divergences is the analytical output of the pattern review.

## The Suspicious-Activity Interaction and Where the Refresh Feeds SAR Filing

The refresh's outputs feed the bank's suspicious-activity monitoring program at the specific points where the refresh identifies information that changes the SAR analysis. A customer whose refresh identifies a specific change in ownership involving a person of concern, a customer whose transaction pattern review identifies specific activity that would be reportable under the [BSA SAR framework](/blog/ai-agents-bsa-aml-sar-narratives-transaction-monitoring), or a customer whose adverse-media signal identifies specific activity that warrants investigation all feed the SAR-analysis workflow.

The interaction is one-way from the refresh to the SAR analysis; the SAR analysis's own outputs feed back into the customer's risk rating and future refresh cadence but do not affect the current refresh's completion. The refresh's completion is a specific analytical milestone; the SAR analysis is a separate analytical process that runs on the same customer data.

The agent's coordination between the refresh and the SAR analysis produces a clean handoff of the specific signals from one to the other, with the reviewer's judgment on each analysis being the operational output. The SAR investigation may or may not produce a filing; the refresh's identification of the signals is what starts the analysis.

## The Enhanced Due Diligence Triggers and What "Enhanced" Actually Means

Enhanced due diligence at [1010.220(b)](https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1010/subpart-C/section-1010.220) and in the FFIEC Manual applies to specific higher-risk customer categories and to specific higher-risk relationships. The categories include foreign correspondent accounts subject to specific EDD requirements under [1010.610](https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1010/subpart-F/section-1010.610), private banking accounts for non-US persons under [1010.620](https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1010/subpart-F/section-1010.620), and the higher-risk customers the bank's own risk-rating process identifies as requiring EDD.

The EDD content extends beyond the basic CDD collection. Source-of-wealth documentation for the individual customers or the beneficial owners of entity customers is a specific EDD requirement, and the documentation includes tax returns, financial statements, professional-services letters, or specific documentation from other financial institutions. Principal-owner background verification includes public-records searches, professional-history verification, and specific due diligence on the owner's business history. Transaction-pattern review at a more granular level and at a higher frequency is part of EDD monitoring.

The agent's EDD contribution is the structuring of the additional information collection, the running of the additional screening at the elevated frequency, and the assembly of the file the reviewer's judgment is applied to. The EDD reviewer is typically more senior than the standard CDD reviewer, and the reviewer's time is the specific bottleneck the agent's contribution addresses.

The EDD's output feeds the customer's risk rating and the ongoing monitoring intensity. A customer whose EDD identifies specific higher-risk features has ongoing monitoring at an appropriately elevated level, and the ongoing monitoring feeds the next refresh's inputs. The refresh cycle for EDD customers is annual or more frequent, and the cycle is one where the ongoing monitoring and the refresh interact continuously.

## The Politically Exposed Persons Screening and the Family-and-Associates Question

Politically exposed persons screening is a specific EDD component the [FATF Guidance on PEPs](https://www.fatf-gafi.org/publications/fatfrecommendations/documents/peps-r12-22.html) and the FinCEN commentary treat as one of the specific risk factors. A PEP is a current or former senior political figure, a member of the PEP's immediate family, or a close associate of the PEP. The screening looks for PEPs among the customer's principals, beneficial owners, and account signers.

The screening's operational challenge is the family-and-associates definition. Immediate family (spouse, children, parents, siblings) is straightforward; close associates is not. The FATF Guidance and the FinCEN commentary describe close associates as persons known to have a close business relationship with the PEP, and the identification of the associates requires specific research on the PEP's known business relationships.

The agent's PEP screening uses commercial PEP lists as a starting point and extends the screening with entity-resolution and relationship-graph analysis. The screening's outputs are ranked by the confidence of the PEP identification, and the reviewer's judgment on the specific PEPs identified is the analytical output.

A customer whose principal is identified as a PEP requires additional EDD, ongoing monitoring at a specific intensity, and specific senior-management approval under the FFIEC Manual's PEP-specific expectations. The refresh's identification of a new PEP in the customer's structure (either a principal who has become politically exposed or a newly identified PEP relationship) is a specific trigger for the enhanced review.

## The Sanctions Watchlist Refresh and the Ongoing Screening Overlap

Sanctions screening is a distinct process from KYC refresh, but the two intersect at specific points. The refresh's identification of new beneficial owners, new counterparties, or new geographies feeds the sanctions screening, and any positive match triggers the [OFAC compliance workflow](/blog/ofac-sanctions-screening-ai-agents-50-percent-rule). The screening's outputs, in turn, may inform the refresh's risk rating.

The sanctions screening is ongoing; every transaction and every relationship-change event is screened in real time. The refresh's contribution is to update the customer's information so the ongoing screening runs against current data, and to structure the ongoing screening at the intensity appropriate for the customer's risk rating.

The agent's coordination of the two workflows produces a specific data-flow discipline. The refresh's outputs update the customer profile that the ongoing screening runs against, and the ongoing screening's alerts feed back into the refresh's risk-rating analysis. The two workflows are not the same, but they are operationally coupled, and the AI program that runs both with coordinated data is a program whose sanctions compliance and CDD compliance are stronger for the coordination.

## The Audit File the Refresh Produces

The audit file per customer per refresh cycle that the examiner will ask for includes the refresh's initiation timestamp, the specific information reviewed and the specific sources for each piece, the customer's responses to the refresh questionnaire, the specific adverse-media, beneficial-ownership, and transaction-pattern findings, the reviewer's specific judgment on the customer's risk rating, and the specific documentation of any EDD activity for higher-risk customers.

The file's completeness supports the bank's exam posture on ongoing CDD compliance, the bank's SAR-filing posture on the specific customer, and the bank's ongoing-monitoring posture on the customer's activity. The file is the specific artifact that connects the refresh's operational activity to the bank's overall BSA/AML program compliance.

The [FFIEC Manual's expectation on documentation](https://bsaaml.ffiec.gov/manual/AssessingComplianceWithBSARegulatoryRequirements/03) is that the bank's file demonstrates the analysis performed rather than a summary conclusion. A refresh whose file records "reviewed, no changes" without the specific evidence of the review is a refresh whose exam posture is weak. A refresh whose file records the specific analysis, the specific sources, and the specific judgment is a refresh whose exam posture is strong.

## The Failure Mode We Engineer Against

The pattern that produces the worst KYC-refresh outcomes is the bank whose refresh program is chronically behind the risk-rated cadence, whose EDD reviews are conducted on rushed timelines to catch up, whose adverse-media screening is done through a vendor product that produces high false-positive rates the reviewers do not fully evaluate, and whose customer-facing refresh interaction is a source of relationship friction rather than a routine touch. The exam finding on the refresh backlog and the EDD-completion rate is a specific finding that produces the specific consent order.

The architecture we run against this is that the refresh program's cadence is met, that the customer-facing interaction is a routine and short touch, that the reviewer's time is applied to judgment rather than to information gathering, and that the specific higher-risk customer reviews get the specific senior-reviewer attention the FFIEC Manual expects. The program's completion rate against the cadence is a specific metric the bank's compliance leadership tracks, and the metric is meaningfully improved by the AI operation.

The commercial-customer experience in this model is that the refresh is a routine touch that does not disrupt the relationship, the compliance team's experience is that the workload shifts from information gathering to judgment, and the exam experience is that the refresh program's file is complete and defensible. The bank's overall BSA/AML program is stronger for the operational improvement, and the specific higher-risk exposures the program is designed to identify are identified at the specific intensity the risk-rated program expects.

## The Honest Read

Periodic KYC refresh at commercial banks is the least glamorous and most consequential part of the ongoing BSA/AML program. The refresh's completion rate against the risk-rated cadence, the EDD's coverage of higher-risk customers, and the specific quality of the reviewer's judgment on each refresh are the specific operational metrics the exam will look at. The bank whose refresh program meets the cadence, whose EDD is thorough, and whose customer-facing interaction is short and respectful is a bank whose exam posture and whose commercial-banking retention are both stronger.

The AI operation's contribution is real and it is specific: it closes the gap between the risk-rated cadence and the actual completion rate, it redirects the compliance team's time toward judgment, and it produces the specific audit file the exam requires. The judgment is the reviewer's; the operational discipline that supports the judgment is the agent's.

We have written separately on the [FinCEN BOI reporting and CDD Rule intake framework](/blog/fincen-boi-cdd-corporate-transparency-act-ai-commercial-banking), on the [OFAC sanctions screening architecture](/blog/ofac-sanctions-screening-ai-agents-50-percent-rule), on the [BSA/AML SAR narrative production process](/blog/ai-agents-bsa-aml-sar-narratives-transaction-monitoring), and on the [third-party risk management framework for AI vendors](/blog/third-party-risk-management-ai-vendors-banking-tprm-playbook). The KYC refresh sits at the center of the ongoing BSA/AML program, and the agent that runs across the workflows with the same architecture is the agent whose contribution to the bank's BSA/AML program compounds across the customer relationship's lifecycle.

---

_Source: [https://www.seiright.com/blog/kyc-periodic-review-edd-refresh-ai-agents-commercial-banking](https://www.seiright.com/blog/kyc-periodic-review-edd-refresh-ai-agents-commercial-banking) · Sei AI_
