When to launch repeat KYC
Launching customer re-identification follows two logics: scheduled — tied to the risk category — and unscheduled, which is initiated by specific events. Both are mandatory from the regulator’s standpoint and are equally significant for risk control.
Scheduled review by risk level
The basic frequency of updating a customer’s data is determined by their risk category. In Russian legislation, the deadlines are enshrined in Federal Law 115-FZ (taking into account the amendments that came into force on July 1, 2022):
- Low risk — an update at least once every three years.
- Medium risk — at least once a year; the company sets the specific frequency in its internal control rules on its own.
- High risk — at least once a year; Rosfinmonitoring’s recommendations point to an interval of at least once every six months.
The international standards of FATF (Recommendation 10) adhere to a similar risk-based logic: the higher the customer’s risk assessment, the more often and more deeply repeat verification should be conducted.
A scheduled KYC refresh is above all a re-assessment. The company does not just update the application form: it re-checks whether the customer corresponds to the assigned category. If, over three years, a low-risk customer has gained new beneficiaries, changed their activity profile, or generated matches with sanctions lists, the category is raised — and the next scheduled cycle will launch earlier.
Automatic tracking of deadlines through a monitoring system rules out the situation where the scheduled updating of a customer’s data is missed due to the operational load — which is itself a violation of the requirements of Federal Law 115-FZ.
When the frequency of scheduled checks is tied to the customer’s risk category, and the portfolio numbers thousands of records, tracking deadlines manually means creating an operational risk of violating regulatory requirements. NeuroVision configures automatic triggers for launching repeat KYC in the “NEUROVISION” software package: the system tracks the dates for each customer on its own, determines the required depth of verification, and initiates the scenario without an employee’s involvement. The full rollout of the platform takes 3–7 days; service availability is ensured at an SLA level of 99.99%, which rules out omissions due to technical failures during periods of high load. Each decision is recorded in the audit trail with full context: during an inspection, not only the fact that re-identification was conducted is visible, but also the chosen scenario and its justification.
Unscheduled launch due to changes and risk events
The scheduled cycle does not cover situations where the risk changes between scheduled checks. Unscheduled re-KYC most often turns out to be critically important from the standpoint of fraud prevention.
The mandatory grounds for an unscheduled update under Federal Law 115-FZ:
- Doubts about the accuracy of the data — the update is carried out within seven business days of their arising: a mismatch of documents, a change of full name, a change of citizenship, or a signal from the verification system.
- Suspicion of involvement in money laundering or terrorist financing — grounds for the immediate launch of an in-depth check regardless of the date of the previous KYC.
- The unusual nature of transactions — operations without obvious economic sense, activity patterns atypical for the customer’s profile, evasion of mandatory control.
In addition to the regulatory grounds, unscheduled re-KYC is advisable in the following events:
- The customer has changed their country of residence or citizenship, especially in favor of a jurisdiction on the FATF lists.
- New beneficial owners have appeared or the structure of the legal entity has changed (for KYB customers).
- The customer has acquired the status of a politically exposed person (PEP) or turned out to be in their immediate circle.
- The validity period of the identity document has expired.
- The customer was inactive for a long time and then abruptly resumed operations with a changed profile.
Unscheduled events require a prompt reaction rather than a pre-agreed scenario. Therefore, an ongoing monitoring system — the constant monitoring of activity and changes in the customer’s data — constitutes the mandatory infrastructure foundation of effective re-KYC.
A customer’s risk can change at any moment — appearing on a sanctions list, being assigned PEP status, or a negative media publication are not tied to scheduled verification cycles. The NeuroVision AML module conducts continuous screening against 1,700+ databases and sources, including the international sanctions lists of the UN, OFAC, the EU, HMT, PEP registries, and adverse media — with daily updates of the key sources. When a status changes, the system automatically generates an alert and launches an unscheduled re-KYC according to the required scenario: the compliance team receives a notification and ready context for making a decision rather than a signal with no link to a customer. Integration of the AML loop takes 1–2 days, which makes it possible to quickly close the gap between scheduled checks and the real dynamics of risk.
What to update during customer re-identification
The scope of the check is determined by two parameters: what has changed in the customer’s profile and what risk level has been assigned to them. Requesting the same set of data from all customers is operationally inefficient and destructive for conversion. The risk-based approach, enshrined in FATF Recommendation 10 and implemented in the requirements of Federal Law 115-FZ, makes it possible to commensurate the depth of re-identification with the real level of risk.
All repeat KYC scenarios fall into three types depending on what exactly needs to be updated.
When it is enough to confirm that the data is current
For customers with a low and stable risk profile who have shown no changes in behavior, transactional activity, or statuses, full re-identification is redundant. It is enough to confirm that the previously collected data is still current.
Technically, this is implemented through digital self-declaration: the customer confirms in the mobile app or personal account that their personal data has not changed. In parallel, the system automatically conducts repeat screening against sanctions lists, PEP databases, and adverse media — these checks are performed independently of changes on the customer’s side, because changes may occur on the side of the regulatory databases. Documents and biometrics do not need to be requested again in this case.
The scenario is applicable when several conditions are met simultaneously: the customer has not moved to a higher risk category, their transactional activity corresponds to the declared profile, the monitoring system has not recorded any alerts, and the valid documents have not expired.
When a new document and a face check are needed
This scenario is activated when the integrity of the initial identification has been broken: the document’s validity period has expired, the customer has changed their name or citizenship, and also when enough time has passed since the initial KYC that the biometric reference has lost sufficient comparability with the person’s current appearance.
In this case, the customer provides a current document, and the system again performs AI-OCR: it extracts the data, verifies the security features and the MRZ, and classifies the document type. Then biometric comparison is carried out: a new selfie is matched with the photo from the document rather than with the archived reference — updating the reference reduces the accumulated identification error. A liveness check is mandatory: it protects against substitution, when a photograph or a deepfake is presented instead of a live person.
The combination “current document + fresh selfie + liveness” makes it possible to reliably establish that the same person still controls the account rather than having handed it over to a third party.
An expired document or a change of personal data requires not just an update of the application form but full-fledged identity confirmation — with an accuracy at which an identification error is unacceptable. NeuroVision performs a repeat AI-OCR in less than 1 second with an accuracy of 99.85%: it extracts the fields, verifies the security features and the MRZ, and classifies the document from a base of 10,000+ templates — including foreign documents from more than 200 countries.
Biometric comparison via Enface reaches an accuracy of 99.74%, and the liveness check cuts off attacks using a photograph, video, and deepfakes with an accuracy of 99.9% — passively, without additional actions on the customer’s part. The full repeat KYC cycle with document, face, and liveness is available from 35–50 rubles per check depending on the set of modules and the volume.
When additional risk-based checks are needed
The third scenario is launched when the customer’s profile has changed so much that standard re-identification is insufficient for a correct risk assessment. Typical triggers: the customer has acquired PEP status or turned out to be connected with one, their transactional activity has gone beyond the boundaries of the declared profile, they have moved to a jurisdiction with an elevated risk according to the FATF assessment, or the monitoring system has recorded anomalies unexplainable within the current profile.
EDD (Enhanced Due Diligence) is added to the standard set of checks: verification of the source of funds and the source of wealth, an in-depth analysis of the transactional history, a check of counterparties, and for legal entities — the updating of data on the ownership chain and the ultimate beneficial owners (UBO). Additionally, checks against industry databases, court and enforcement proceedings, and bankruptcy registers are connected.
The result of such a repeat KYC is a revised customer risk rating with a documented justification of the decision. During an inspection, the supervisory authority must see not only the fact that re-identification was conducted, but also what data was obtained, how it affected the risk assessment, and what decision was made.
How to build a repeat KYC scenario without losing customers
Repeat KYC creates friction by its very nature: the customer has already passed identification and perceives an additional request as a burden. Most often, churn is provoked not by the procedure itself but by its implementation: an unexpected request without explanation, an excessive application form, a dead end after an error. A well-built scenario makes it possible to pass repeat verification with minimal losses — provided that each step is designed deliberately.
Explain the reason for the request and use one official channel
A sudden demand to provide documents is a classic phishing pattern. A customer who does not understand why and from whom the request came will most likely ignore it or regard it as a threat. This is the first and most frequent reason why re-identification breaks down before it even starts.
The notification must arrive before the request rather than simultaneously with it: explain that the scheduled updating of data is being carried out in accordance with the requirements of Federal Law 115-FZ, the FATF standards, or the organization’s internal policy; indicate the deadline; describe what exactly will be required. Such a notification removes the barrier of distrust and gives time to prepare.
In parallel, it is necessary to establish a single official request channel and inform the customer in advance through which channel exactly the link or form will arrive. Duplication across several channels in the absence of a single entry point creates confusion and reduces conversion. One channel — one link — one action.
Pre-fill the application form and request only the changed information
Asking the customer to re-enter data that is already in the system is a direct loss of conversion. Every excess field reduces the probability of completing the form; in the context of re-KYC, where the customer perceives the process as an obligation, an overloaded application form becomes a critical barrier.
The working model is a pre-filled form with data from the profile, where the customer confirms currency or makes changes: the so-called “delta update”. The address has not changed — one click is enough. The document is expired — only the upload of a new one. The data diverges from external sources — only the clarification of the discrepancy. This approach reduces the average time to complete repeat KYC and lowers the cognitive load, which is directly reflected in the share of completed sessions.
Automate simple cases and route disputed ones to manual review
If the customer’s profile has remained in the previous risk segment, the documents are valid, the data has not changed, and screening against sanctions lists has yielded no matches — the decision is made automatically. Based on implementation practice, automatic processing covers from 70 to 90% of repeat verification cases depending on the structure of the customer base and the industry.
Manual review is reserved for non-standard situations: a change of personal data, a mismatch between the declared and the detected information, an expired document with signs of replacement, matches in AML screening, a change of risk category. In these cases, the automation routes the case to the verification queue with full context — without data loss and without restarting the process for the customer.
Such a division preserves speed for the majority of customers and concentrates analysts’ resources where they are needed. The move to manual review must not mean a “black box”: the customer receives a notification about the status and the expected timeframes.
With well-configured repeat KYC, up to 90% of cases are closed without operator involvement — this reduces the manual review queue and shortens the waiting time for the customer. NeuroVision configures the logic of automatic decisions in the “NEUROVISION” software package: the system checks the document, performs biometric comparison, conducts AML screening, and makes a decision in a single pipeline. Non-standard cases — a change of personal data, discrepancies, compliance alerts — are routed to the operator back office with full context, without restarting the process for the customer. The rollout takes 3–7 days; the share of automatic decisions, the reasons for routing to manual review, and the conversion by funnel stage are displayed in the platform dashboard in real time.
Give the customer a quick retry after an error
An error at any step — a low-quality document, a failed liveness check, a data mismatch — must not mean the end of the session. It is precisely here that most scenarios lose the customer for good: instead of a clear next step — a refusal screen and a feedback form.
An effective scenario provides for a built-in retry path: a specific explanation of the cause of the error (insufficient lighting, a cropped corner of the document, the face is obscured), instructions for correction, and a “try again” button right on the same screen. The optimal window for a retry is 24-48 hours from the first: enough for the customer to return at a time convenient for them, but not so long that the task “gets lost” in their plans.
Additionally, one should record the point of failure and, on re-entry, return the customer to exactly that point rather than to the beginning of the process. This eliminates one of the most irritating patterns: the need to re-do already successfully completed steps.
How to control churn during repeat KYC
Managing churn during re-identification requires a separate system of metrics — not general retention analytics but a detailed breakdown of each step of the process. During repeat KYC, the customer is already verified, and any excess friction is perceived more sharply than during initial onboarding.
Conversion by stage
The repeat KYC funnel must be broken down into minimal measurable steps, with conversion recorded at each transition.
Notification received → the customer opened the request. Shows the effectiveness of the delivery channel and the wording of the message. Low conversion at this step points not to the complexity of the process itself but to problems in communication: an unsuitable channel, an unclear email subject, an incomprehensible reason for the request.
The request is opened → the customer started the process. Characterizes the clarity of the interface and the comprehensibility of the instructions. A sharp drop-off here most often means that the user did not understand what exactly was required of them, or the scope of the task seemed excessive.
Start of the process → data submission. Reflects operational barriers: difficulties uploading the document, poor shooting quality, an inconvenient selfie step. This is the most manageable part of the funnel — most problems are eliminated through real-time prompts and a preliminary image quality check before submission.
Submission → final decision. This step no longer depends on the customer. Here it is important to distinguish technical failures, false positives, and justified risk-based refusals — three different categories with different response actions.
For customers with a low and medium risk level, with a properly built process, the total funnel conversion is 80-90%. If the figure is consistently lower, there is a bottleneck at one of the first two steps. For high-risk customers, the target conversion is lower and is determined individually: some of them will leave deliberately, and this is a natural outcome in the logic of the risk-based approach.
Conversion data must be segmented: by channel (mobile / web), by document type, by the customer’s risk category. Without segmentation, aggregated figures do not make it possible to understand where exactly and with which audience churn occurs.
Time to decision and the share of automatic decisions
Two indicators are directly connected with the customer experience and the operational load: the median time from the start of the session to receiving a decision and the share of cases closed automatically without operator involvement.
With fully automated processing, the median time to a decision must not exceed 2-3 minutes. If the document goes to manual review, the wait grows to several hours, which multiplies the risk that the customer will not return for the result. The waiting time during manual review must be accompanied by a clear notification about the status and the timeframes.
The share of automatic decisions is a key operational KPI. For well-configured repeat KYC with an established customer base, this figure should be 70-85% and higher. A low share indicates one of two things: either the trigger thresholds are excessively conservative, or the quality of the incoming data is unsatisfactory — blurry photos, unreadable documents, a discrepancy of the data with the customer’s profile.
Additionally, it is worth tracking the share of sessions interrupted before data submission. This is a separate category of losses requiring a separate response measure: retargeting, simplifying the interface, or an additional instruction on the problem step — depending on exactly which transition the drop-off occurs at.
Reasons for refusals and customer departure
The analysis of causes is conducted at two levels: technical system refusals and behavioral customer departure.
Among the technical causes, the most common are: low image quality of the document or selfie (blur, overexposure, incomplete capture in the frame), an expired document, a mismatch of the data in the profile with what is indicated in the new document (for example, a change of surname after the initial registration), as well as false positives from anti-fraud rules. Each of these categories is manageable. Image quality is improved through prompts in the capture interface. Data discrepancies are reduced through pre-filling the application form and an explicit request to confirm changes. False-positive decisions — through threshold calibration and the introduction of exception logic for customers with a long history without incidents.
Behavioral departure is the cases where the system is technically ready to accept the customer, but they themselves stop the interaction. The key patterns: the customer did not respond to any notification; opened the request but did not start the process; started but left at a specific step. Each pattern requires its own response measure — from changing the tone and channel of notifications to redesigning the problem step in the interface.
The analysis of causes must be regular: norms change, documents become outdated, the customer base evolves. The optimal rhythm is a quarterly review of aggregated data and a situational analysis after each significant wave of repeat KYC. This makes it possible not only to reduce current churn but also to accumulate analytics for improving the next iterations of the process.
The scope of repeat verification is determined by the customer’s real risk level: for some, digital self-declaration and background screening are enough; for others — a new document with a biometric check; for still others — full EDD with a revision of the risk rating. A precise match of the depth of the check to the customer’s profile reduces the operational load and keeps the funnel conversion at an acceptable level for low- and medium-risk segments — without excessive friction where it is not needed.
A sustainable result is achieved when re-KYC is built into the infrastructure: automated launch triggers, pre-filled application forms, clear paths after an error, and the regular analysis of the reasons for refusals and customer departure. Companies that build this process systematically gain not only compliance with the requirements of Federal Law 115-FZ and the FATF standards but also data for the continuous improvement of the identification loop — reducing losses where they previously seemed inevitable.