What a well-run KYC campaign actually looks like

A review cycle comes due, and suddenly you need updates documents from a few thousand existing customers who have little reason to reply quickly. Run that on a mail merge and a shared inbox and it drags on for weeks, with the evidence scattered across inboxes by the time anyone asks for it. Here is what a well-run KYC campaign looks like instead.

When you run a periodic review or a remediation campaign, the rulebook is the part you already have handled. You know what to collect and by when. The work that consumes the team is operational: getting thousands of existing customers to respond, then checking and evidencing everything that comes back. Getting through that volume, and standing up to an audit afterwards, is the real work. Done by hand or by mail merge, it is slow and draining, and it tends to hang over the team for weeks.

The response problem is the one that is easy to underestimate. The Financial Brand reports that banks lose around 60 percent of would-be customers to onboarding that feels too complex or slow, and those were motivated new customers. In a review campaign you are contacting existing customers who gain nothing obvious by replying, so the same friction hits harder. Everything that follows is about handling that reality at scale.

The typical version

A review cycle comes due, or a regulator points out a gap in the book. Someone pulls a list of the customers who need updating, and the outreach starts.

Often it is a mail merge. A templated email goes out asking for an updated ID, a recent proof of address, and in some cases beneficial ownership details. Replies land in a shared inbox. Some customers send the right files. Many send a blurry photo, an expired passport, or a document in the wrong format. A few reply asking why you need this at all. Most do not reply on the first try.

We heard a clear version of this from a broker who runs client updates entirely by hand, across a book of more than ten thousand clients with a team of about ten people. Forms go out, and the team waits for signed copies to come back. In their own words, the whole thing is slow and far from the most efficient way to work.

The whole thing is slow and far from the most efficient way to work.

— A broker running client updates by hand across a book of 10,000+ clients

From there it is manual. Someone opens each reply, checks whether the documents are valid, and keys the details into the system. And it is rarely one system. As one compliance lead put it on a call, after the data is collected they still have to update the AML fields in the CRM and store the evidence in a separate document management system. Independent research puts real money on this. A Forrester study of financial crime compliance costs found the annual total across the United States and Canada reaching about 61 billion dollars, with labour the largest and fastest-rising part of the bill. A good deal of that labour is exactly this: staff gathering and re-entering the same data across different systems.

The part that hurts most comes at the end. The regulator asks you to show your work: who you contacted, when, what came back, and how you checked it. If that history is spread across inboxes and spreadsheets, assembling the evidence becomes its own project. And the stakes are not small. Global AML penalties ran to roughly 3.8 billion dollars in 2025, before counting the remediation programs and lost business that tend to follow.

The well-run version covers the same ground. What changes is how each step runs.

Stage

The typical version

The well-run version

Before outreach

A raw list pulled from the CRM

Clean segmentation: who is due, at what risk level, what exactly is missing

Outreach

Mail merge into a shared inbox

Tailored, mobile-friendly request per customer, with automatic reminders

Document checks

Opened, read and keyed in by hand

Read and validated on arrival; problems fixed while the customer is still in the flow

Progress

Nobody knows the real completion rate

Live dashboard with exact numbers, any morning

Audit trail

Assembled from inboxes and spreadsheets after the fact

Logged as it happens, timestamped and exportable

Step one: know who needs what before you reach out

A well-run campaign begins with a clean segmentation of the book, before any outreach goes out. Which customers are due for review, at what risk level, and what exactly is missing or out of date for each one.

That last part matters more than it looks. A customer whose address you already hold should not be asked for it again. When the request is tailored to the gap, response rates go up and complaints go down. You are only asking for what you genuinely need from that specific person.

Step two: reach the whole book at once, with a request people can actually complete

Once you know who needs what, the outreach goes out as a structured request instead of a plain email. Each customer receives a link to a short form built for their situation, accessible from their phone, in their language. It shows them exactly which documents to upload and nothing else.

This is where the friction research becomes practical. Studies of abandoned verifications keep pointing to two simple causes: the customer did not have the right document to hand, or the process asked too much and took too long. A short request that can be completed on a phone in a few minutes, saved and resumed later, removes a good deal of that.

Reminders are set once and run on their own. A customer who has not responded after a few days gets a nudge without anyone remembering to send it. The same sequence applies across the entire campaign, so a book of four thousand customers is handled with the same effort as forty.

Step three: read and check documents as they arrive

Documents come back in every shape: scans, phone photos, PDFs, the occasional handwritten page. In the manual process a person opens each one, reads it, decides if it is valid, and types the details in. In a well-run campaign, the document is read on arrival and the key fields are extracted automatically.

The check happens up front too. An expired ID or an unreadable file is caught the moment it arrives, and the customer is asked to fix it straight away. This matters more than it sounds, because research on verification flows finds that customers asked to re-upload a document are far more likely to give up. Catching the problem while they are still in the flow keeps them from dropping out. By the time a compliance analyst opens the file, the obvious problems have already been handled and the data is in place.

Step four: watch the campaign in real time

This is what many teams say they wish they had. A live view of where the campaign stands, showing how many customers have finished and how many are stuck partway or have not opened the request yet.

That visibility changes how you manage the work. You can see the two hundred customers who started and stalled, and send them a targeted reminder. You can tell your Head of Compliance the exact completion rate on any given morning. When the deadline approaches, you know precisely which accounts still need attention.

Step five: keep the audit trail as you go

Every message sent, every document received, and every check performed is logged as it happens. The evidence the regulator will ask for is assembled by the process itself, in order, with timestamps.

When the review or the audit comes, there is no scramble. The record of who was contacted, what they provided, and how it was verified is already there and exportable.

What good looks like in practice

A bank needs to refresh KYC on roughly four thousand higher-risk customers before a regulatory deadline three months out. Rather than a mail merge into a shared inbox, each customer gets a link to a short form asking only for what is missing from their file.

In the first two weeks, a live dashboard shows completion climbing past sixty percent. The customers who have not opened the request are sent an automatic second reminder. Documents are read and validated as they land, so expired passports are caught and re-requested without an analyst lifting a finger. The compliance lead can answer the question “where are we?” at any moment, with a real number at hand.

Nobody spent their evenings copying data between systems. The campaign moved on its own, and the audit trail built itself along the way.

When to start

There is another reason to get this right now. Supervisors across Europe are moving away from the calendar-driven periodic review toward continuous, event-based due diligence, which raises the bar for how current and how well-evidenced your customer records need to be. The manual campaign was already stretched. The direction of travel stretches it further.

The good news is that the payoff is large. PwC estimates that automating periodic reviews can cut the effort by 60 to 80 percent for a mid-sized bank. The tools to read documents, send structured requests, and track a campaign in real time already exist. The manual version was shaped around the workload a team could physically keep up with. A well-run version is shaped around what the review and the customer both need.

Automating periodic reviews can cut the effort by 60 to 80 percent for a mid-sized bank.

— PwC, on the payoff of automated review campaigns

Redesigning that takes some upfront effort, usually during a period when the team is already busy. That is the honest trade. A little time now against a lot of time, and a lot of audit risk, later.

Most compliance teams know which side of that trade they are on. The question is when to start.

Penbox runs compliance and KYC campaigns on top of the systems you already use, so the work above happens in one place with a full audit trail. If you want the wider picture first, here is what case management means.