What a well-run KYC campaign actually looks like
KYC compliance software splits into two jobs: screening who a customer is, and running the campaign that gets their data updated in the first place. This is about the second one. A well-run periodic review reaches thousands of customers at once, checks what comes back as it arrives, and builds its own audit trail, so the deadline stops being a scramble.

Written by
Rolf Tjalsma
Published
Category
Compliance
When you run a periodic review or a remediation campaign, the rulebook is the part you already have handled. You know what to collect and by when. The work that consumes the team is operational: getting thousands of existing customers to respond, then checking and evidencing everything that comes back. Getting through that volume, and standing up to an audit afterwards, is the real work. Done by hand or by mail merge, it is slow and draining, and it tends to hang over the team for weeks.
The response problem is the one that is easy to underestimate. The Financial Brand reports that banks lose around 60 percent of would-be customers to onboarding that feels too complex or slow, and those were motivated new customers. In a review campaign you are contacting existing customers who gain nothing obvious by replying, so the same friction hits harder. Everything that follows is about handling that reality at scale.
Most of what gets called KYC compliance software falls into two different jobs. One kind screens who a customer is: sanctions lists, PEP checks, identity documents run against a database. The other kind runs the campaign itself: reaching thousands of existing customers, collecting what is missing, checking it, and proving you did all of it. Screening tools assume the data has already arrived. The harder problem, most of the time, is getting it to arrive at all. That is the part this article is about.
The typical version
A review cycle comes due, or a regulator points out a gap in the book. Someone pulls a list of the customers who need updating, and the outreach starts.
Often it is a mail merge. A templated email goes out asking for an updated ID, a recent proof of address, and in some cases beneficial ownership details. Replies land in a shared inbox. Some customers send the right files. Many send a blurry photo, an expired passport, or a document in the wrong format. A few reply asking why you need this at all. Most do not reply on the first try.
We heard a clear version of this from a broker who runs client updates entirely by hand, across a book of more than ten thousand clients with a team of about ten people. Forms go out, and the team waits for signed copies to come back. In their own words, the whole thing is slow and far from the most efficient way to work.
From there it is manual. Someone opens each reply, checks whether the documents are valid, and keys the details into the system. And it is rarely one system. As one compliance lead put it on a call, after the data is collected they still have to update the AML fields in the CRM and store the evidence in a separate document management system. Independent research puts real money on this. A Forrester study of financial crime compliance costs found the annual total across the United States and Canada reaching about 61 billion dollars, with labour the largest and fastest-rising part of the bill. A good deal of that labour is exactly this: staff gathering and re-entering the same data across different systems.
The part that hurts most comes at the end. The regulator asks you to show your work: who you contacted, when, what came back, and how you checked it. If that history is spread across inboxes and spreadsheets, assembling the evidence becomes its own project. And the stakes are not small. Global AML penalties are reported at roughly 3.8 billion dollars in 2025, before counting the remediation programs and lost business that tend to follow.
The well-run version covers the same ground. What changes is how each step runs.
Step one: know who needs what before you reach out
A well-run campaign begins with a clean segmentation of the book, before any outreach goes out. Which customers are due for review, at what risk level, and what exactly is missing or out of date for each one.
That last part matters more than it looks. A customer whose address you already hold should not be asked for it again. When the request is tailored to the gap, response rates go up and complaints go down. You are only asking for what you genuinely need from that specific person.
Step two: reach the whole book at once, with a request people can actually complete
Once you know who needs what, the outreach goes out as a structured request instead of a plain email. Each customer receives a link to a short form built for their situation, accessible from their phone, in their language. It shows them exactly which documents to upload and nothing else.
This is where the friction research becomes practical. Studies of abandoned verifications keep pointing to two simple causes: the customer did not have the right document to hand, or the process asked too much and took too long. A short request that can be completed on a phone in a few minutes, saved and resumed later, removes a good deal of that.
Reminders are set once and run on their own. A customer who has not responded after a few days gets a nudge without anyone remembering to send it. The same sequence applies across the entire campaign, so a book of four thousand customers is handled with the same effort as forty.
Step three: read and check documents as they arrive
Documents come back in every shape: scans, phone photos, PDFs, the occasional handwritten page. In the manual process a person opens each one, reads it, decides if it is valid, and types the details in. In a well-run campaign, the document is read on arrival and the key fields are extracted automatically.
The check happens up front too. An expired ID or an unreadable file is caught the moment it arrives, and the customer is asked to fix it straight away. This matters more than it sounds, because research on verification flows finds that customers asked to re-upload a document are far more likely to give up. Catching the problem while they are still in the flow keeps them from dropping out. By the time a compliance analyst opens the file, the obvious problems have already been handled and the data is in place.
Step four: watch the campaign in real time
This is what many teams say they wish they had. A live view of where the campaign stands, showing how many customers have finished and how many are stuck partway or have not opened the request yet.
That visibility changes how you manage the work. You can see the two hundred customers who started and stalled, and send them a targeted reminder. You can tell your head of compliance the exact completion rate on any given morning. When the deadline approaches, you know precisely which accounts still need attention.
Step five: keep the audit trail as you go
Every message sent, every document received, and every check performed is logged as it happens. The evidence the regulator will ask for is assembled by the process itself, in order, with timestamps.
When the review or the audit comes, there is no scramble. The record of who was contacted, what they provided, and how it was verified is already there and exportable.
What good looks like in practice
A bank needs to refresh KYC on roughly four thousand higher-risk customers before a regulatory deadline three months out. Rather than a mail merge into a shared inbox, each customer gets a link to a short form asking only for what is missing from their file.
In the first two weeks, a live dashboard shows completion climbing past sixty percent. The customers who have not opened the request are sent an automatic second reminder. Documents are read and validated as they land, so expired passports are caught and re-requested without an analyst lifting a finger. The compliance lead can answer the question "where are we?" at any moment, with a real number at hand.
Nobody spent their evenings copying data between systems. The campaign moved on its own, and the audit trail built itself along the way.
When to start
There is another reason to get this right now. Supervisors across Europe are moving away from the calendar-driven periodic review toward continuous, event-based due diligence, which raises the bar for how current and how well-evidenced your customer records need to be. The manual campaign was already stretched. The direction of travel stretches it further.
The good news is that the payoff is large. PwC estimates that automating periodic reviews can cut the effort by 60 to 80 percent for a mid-sized bank. The tools to read documents, send structured requests, and track a campaign in real time already exist. The manual version was shaped around the workload a team could physically keep up with. A well-run version is shaped around what the review and the customer both need.
Redesigning that takes some upfront effort, usually during a period when the team is already busy. That is the honest trade. A little time now against a lot of time, and a lot of audit risk, later.
Most compliance teams know which side of that trade they are on. The question is when to start.
Penbox runs compliance and KYC campaigns on top of the systems you already use, so the work above happens in one place with a full audit trail. If you want the wider picture first, here is what case management means.
Similar articles
All articles

Case management
The case that understands itself
When a case writes its own summary and key fields, the next handler knows what it is before reading a page. Meet the case that understands itself.

Rolf Tjalsma
FNOL
FNOL software: why the first notice of loss decides how long a claim takes
FNOL software and why the first notice of loss decides most of a claim's timeline before anyone has even started deciding it.

Rolf Tjalsma
Compliance
Best KYC software for compliance campaigns, not just checking one ID at a time
The best KYC software depends on the job. Here's how identity screening tools and compliance-campaign tools actually differ, and which one solves which problem.

Rolf Tjalsma

