Skip to content
Innopulse Consulting
Family office

What is a periodic review in compliance?

Short definition

A periodic review is the recurring check of an existing business relationship: are the details still current, has the structure changed, is the risk rating still appropriate. The rhythm follows the risk.

A periodic review is the recurring check of an ongoing business relationship. It examines whether the details gathered at onboarding still hold, whether the structure or the beneficial owners have changed, and whether the original risk rating remains appropriate. It is the counterpart of the onboarding check and in practice the more demanding part.

Why onboarding is not enough

A check describes a state at a point in time. Ownership changes through transfers, succession and restructurings. Identity documents expire. A person can become politically exposed through an election. The wealth structure can develop in directions not foreseeable at onboarding. Without recurring checks the file, after a few years, describes a relationship that no longer exists in that form.

What is checked concretely

A review typically covers the currency of identification documents, confirmation or correction of the beneficial owners, a fresh check for politically exposed persons among those involved, reconciliation of actual against expected business activity, and a reassessment of the risk rating. Where a change emerges, additional enquiries or an adjustment to the review rhythm may follow.

The rhythm follows the risk

There is no uniform cycle for all relationships. The risk-based approach requires that relationships with elevated risk be reviewed more often than low-risk ones. Your own organisation must set which rhythms apply to which risk classes and justify that setting. A cycle identical for all relationships does not formally satisfy the risk-based approach — it is either too costly for the low-risk ones or too lax for the high-risk ones.

Out-of-cycle triggers

Alongside the fixed rhythm, certain events should trigger a review regardless of cycle: a recognisable change in ownership, a change in management or governing bodies, unusual transactions, adverse press coverage, or an external indication. An organisation that only works the calendar and has not defined these triggers is effectively monitoring only half.

The real problem is visibility

In practice, periodic review rarely fails because somebody refuses it but because the due date is not visible. Where deadlines live in a separate list maintained by one person, the compliance of an entire practice depends on that person’s discipline and presence. Due reviews therefore belong where the mandate is run, so they surface in the daily workflow rather than in a side file.

What belongs documented

For evidence, what counts is not only that a review took place but what was checked, with what result and on what basis. A review producing no change also belongs recorded — an empty period in the file is, under review, indistinguishable from an omitted control. A continuous audit trail solves this, because it produces the evidence as a by-product of the workflow. Assessment in the individual case remains the task of the responsible person.

Family office is our specialty

Innopulse doesn't just explain terms — we put them into practice for DACH companies.