Skip to content

Periodic reviews

Clients must be re-assessed periodically. The review date follows from the client’s risk classification, and the review itself is created automatically, well before it is due.

When compliance completes a review, it sets the next review date. The dashboard suggests a date based on the final risk classification:

Final risk classificationSuggested next review
Low3 years later
Medium2 years later
High / Unacceptable1 year later

The compliance officer can always override the suggestion with a custom date. The chosen date is stored on the client.

Every day the system checks which clients reach their next review date in exactly 90 days. For each of those clients — unless a review is already open — it automatically:

  1. Creates a new review with reason Periodic review, copying the document states, partial conclusions and comments from the previous review, so the work starts pre-filled.
  2. Creates a verification check for every active party.
  3. Emails the account managers that the periodic review is ready, including the review date it anticipates.

This email is also the reminder: from the moment it arrives, there are three months left to complete the review before the due date.

A periodic review runs like any other: the account manager verifies the checks — focusing on what changed since last time, since everything is pre-filled — and hands over to compliance. Periodic reviews do not require management approval; compliance completes them directly and sets a new next review date.