Expertise

Blog

ING, Standard Chartered, and HSBC Are Making Perpetual KYC Work, Thanks to Better Data

AI

AI Agents

AML

Compliance

Regulatory

In a previous post we framed pKYC as more a question of operational execution over model soundness. In essence this relies upon an institution’s data, decisioning, and governance being mature enough to run continuous monitoring without drowning in the events it generates. A growing number of banks have started to answer that question in production.

The pattern in those answers is clear. Institutions like ING, Standard Chartered, and HSBC, which are making pKYC real, are the ones that fixed the customer record first. Continuous, event-driven monitoring is only ever as good as the record it monitors, and a review triggered against stale or incorrect data manufactures false confidence.

How did ING build a connected customer record?

ING made its customer data connected: it links customers and counterparties into a networked view instead of storing them as isolated records. This is the first requirement of a pKYC-ready record, and the one most legacy systems fail.

Since 2017, through its global KYC Enhancement Programme, ING has rebuilt customer due diligence around data and analytics. The bank combines internal transaction data with external sources and uses anomaly detection to connect customers and counterparties and surface hidden relationships across 38 million customers in more than 40 countries.

ING has rolled out continuous name screening and continuous adverse-media screening across many of its markets, and works with other banks and public-private partners to pool transaction data and sharpen alert detection. As Ivar Lammers, ING’s Global Head of Financial Crime for Wholesale Banking, has put it, an institution must understand not only its customer but its customer’s customer too.

The relevance to pKYC is direct. An event such as ‘a new beneficial owner’ carries no meaning until it is connected to and contextualised by the network it is a part of; until the bank can see whether that owner links the customer to a sanctioned entity, a high-risk jurisdiction, or an existing investigation. Without context, event-driven monitoring only generates alerts faster. With it, the institution triggers the right review for the right reason. 

How did Standard Chartered wire in real-time, authoritative data?

Standard Chartered feeds its customer record from authoritative sources in real time, via API, rather than through periodic re-collection. A connected record decays the moment its inputs go out of date, which makes a live feed from source registries the second requirement.

In 2025 Standard Chartered’s Hong Kong business automated company-data retrieval through the Hong Kong Monetary Authority’s Commercial Data Interchange (CDI). The system pulls verified corporate information, including ultimate beneficial ownership structures, directly via API.

CDI is HKMA-operated infrastructure that lets banks retrieve company data from authoritative providers with the client’s consent. For Standard Chartered, registry and ownership data arrive already verified and structured, without having to be keyed in from customer documents and periodically re-checked.

Operationally, this significantly reduced onboarding time: SME clients can now open accounts and apply for financing in hours rather than weeks, with compliant, straight-through onboarding.

Architecturally, perpetual KYC promises a profile that is current by design, and that promise rests on the pipes feeding it. When the record is wired to a live source, a change at the registry can flow through as an event rather than waiting for the next scheduled review to catch it.

How did HSBC make continuous KYC refreshes affordable?

HSBC lowered the cost of pKYC by standardising and reusing customer data instead of re-collecting it. This standardisation and reuse is the third requirement, so refreshes don’t have to just involve re-collecting data. If every refresh re-gathers information that has not changed, continuous monitoring collapses under its own cost. A single client review can exceed several thousand dollars.

HSBC has used Swift's KYC Registry since 2015 and now consumes thousands of counterparty KYC profiles each year through an API into the platform. Where it can consume a profile, it leverages up to 95% of the information automatically and, in the words of its Global Head of Corporates Onboarding, completes due diligence “significantly faster and often without any kind of outreach at all”, redirecting analyst time to complex queries.

The registry works because it is mutualised. Once a bank publishes a standardised KYC profile, every other member can use it. HSBC applies this primarily to correspondent banking, where the same institutions are onboarded and refreshed repeatedly across the industry. This allows data to be gathered once and reused, rather than re-collected by each bank.

HSBC has also developed reusable KYC credentials for its own customers. Known as its Trusted ID work, the system is built on a privacy-preserving infrastructure, so verified individuals are not asked to submit the same identity data repeatedly across HSBC services.

This is the real-world answer to the cost objection raised against pKYC. When data is standardised and shared, a refresh becomes a low-cost lookup instead of a full re-investigation, and a continuous cadence becomes survivable at scale.

Key takeaways

  • ING shows the record must be connected, linking customers and counterparties to surface hidden risk.

  • Standard Chartered shows it must be authoritative and real-time, with live API feeds from registries keeping it current.

  • HSBC shows it must be standardised and reusable, so mutualised data makes a refresh a low-cost lookup.

The road ahead: is your data ready for perpetual KYC?

The strategic question for compliance leaders is no longer whether to adopt perpetual KYC, but whether their data can carry it. The institutions mentioned here treated data readiness as the starting point and their pilots reached production because of it. These examples show that pKYC is a goal that can only be reasonably attained, and maintained, through watertight customer records.

Decisioning earns its place once the foundation is sound. An agentic system can then resolve an event rather than just flagging it, enriching the profile against those sources, screening for sanctions, PEP, and adverse-media exposure, and producing a single, auditable investigation narrative for a human to evaluate. This is the role Silent Eight’s Iris 7 is built for: its Risk Data Manager and Expert CDD Agent turn an authoritative record into resolved, explainable refreshes in seconds, augmenting analysts’ workflows.

The lesson is the same across all three. Invest in the connected, authoritative, and reusable record first, and continuous due diligence becomes more defensible than the periodic model. Build in the reverse order, and no amount of monitoring frequency will close the gap. The sequence matters: the data comes first.

Share article

Latest news

Latest news

Discover how AI is Revolutionising Compliance and Risk Adjudication

Download our latest collateral to stay ahead.


Discover how AI is Revolutionising Compliance and Risk Adjudication

Download our latest collateral to stay ahead.


Discover how AI is Revolutionising Compliance and Risk Adjudication

Download our latest collateral to stay ahead.