Most compliance programmes carry out third-party due diligence at onboarding. The entity is assessed, given a risk rating and put on a review schedule. The file is complete.
That file rests on an assumption: the company will stay broadly the same until the next review. Our early research suggests it often does not.
The Traditional Due Diligence Model
Third-party due diligence became standard practice for good reasons. Structured onboarding reviews, risk tiering and scheduled reassessment give compliance teams a workable way to manage large third-party populations. The model is auditable and defensible, and most organisations use it.
The model works. The gap is what happens between reviews.
An onboarding assessment is a snapshot. It records the owners, the directors and the legal status on one particular day, and the risk rating reflects that day.
Companies keep changing after that day.
What Changes After Verification?
The details compliance teams check at onboarding can change quickly. Counterparties are rarely told when they do.
Shares can be transferred. Directors can be appointed or removed. A company can move its registered jurisdiction, change its legal status or come under regulatory action. In some jurisdictions these changes are filed with the registry and become public. In others they are much harder to see.
There is no predictable timing. A company that passes onboarding cleanly this quarter can look materially different in six months, and different again by the next scheduled review.
The Compliance Blind Spot
Annual reviews are common in third-party programmes. Lower-risk relationships are often reviewed every two years, or less often. This is a practical choice. A team responsible for hundreds or thousands of third parties cannot run frequent deep reviews across all of them.
The result is a structural gap. Between one review and the next, directors can be replaced and beneficial ownership can shift. A company in good standing at onboarding can enter a striking-off process or pick up new sanctions exposure, and nobody in the relationship is alerted.
Compliance teams are doing the reviews. The issue is that reviews follow the calendar, and corporate events do not.
“The calendar determines the review. The company determines when it changes.”
– Ficoal Dong, Founder & CPTO, AsiaVerify
Why It Matters
The impact of a missed change depends on the relationship and the type of change. The underlying exposure is the same across third-party risk categories: a decision is still standing on facts that are no longer true.
A transfer of ownership can bring in beneficial owners who would not have passed the original assessment. A new director can be someone whose background would have triggered extra scrutiny.
A change in legal status can do more than affect the validity of existing agreements. When a company is struck off, deregistered or placed into liquidation, the due diligence file on record describes an entity that may no longer legally exist. Yet the access granted on the strength of that file often remains in place. A merchant account can keep accepting payments. A supplier record can keep receiving invoices and payment instructions.
That residual access is where a compliance gap becomes a financial crime exposure. An entity that passed verification once but no longer operates as a legitimate business can be used to move funds, process payments for undisclosed parties, or receive diverted supplier payments. Transaction monitoring may not flag it, because nothing about the transactions has changed. Only the entity’s legal existence has. Funds paid to a company that no longer exists can be difficult to recover. And when the issue surfaces, the question is not only regulatory: it is why the organisation was still doing business with a company that had ceased to exist.
For organisations with anti-money laundering obligations, many frameworks encourage a risk-based approach to ongoing oversight rather than relying on fixed review dates alone. A material change that goes unnoticed between reviews is a gap in that oversight.
Procurement and supply chain teams face the same issue. If a supplier’s ownership moves to a new structure, it can bring concentration risk, geopolitical exposure or conflicts of interest that did not exist when the supplier was approved.
Evidence from the Field
Early findings from AsiaVerify’s 2026 APAC company monitoring research suggest corporate change is more frequent than many compliance programmes assume. The research covers 620 companies across Australia, China, Hong Kong, Japan, New Zealand, Taiwan and Thailand.
Within roughly two months, 92 of the 620 companies (14.8%, or nearly one in seven) recorded at least one corporate change. Changes were found in all seven jurisdictions. The first appeared within two days in New Zealand, Thailand and Hong Kong. The average time to first detected change was about six days.
In a 400-company subset, 276 individual change events were categorised. More than 60% related to shares, shareholders or key individuals: share changes accounted for 30.1%, major person changes for 17.4% and shareholder changes for 13.4%.
The Perpetual KYB Study: June Baseline and October Expansion
The study began on 10 June 2026 and set its baseline by tracking changes across the first 620 companies. A second phase is planned for October 2026. It will extend the observation window and test whether the early patterns hold over a longer period.
The combined findings are intended to support The Cost of Standing Still: 2027 APAC Company Monitoring Report, planned for publication in December 2026, subject to final methodology.
Moving Towards Perpetual KYB Monitoring
Perpetual KYB monitoring does not mean running full due diligence on every third party, over and over. For most organisations that would be neither practical nor proportionate. It means keeping sight of relevant corporate changes between scheduled reviews.
A risk-based approach puts attention where it is needed. When something changes at a specific entity, the team sees it, judges how significant it is and decides how quickly to review it.
That needs a way to pick up corporate changes when they are filed, not only on a schedule. It also needs a clear rule for which changes are material enough to review now and which can wait for the next cycle.
A change of registered address may be low risk. A change in ultimate beneficial ownership usually is not. How a team tells the two apart decides how fast it needs to act.
Questions Compliance Leaders Should Ask
- How quickly would we know if a critical supplier or counterparty changed its beneficial ownership?
- How many of our third parties could have changed materially since their last review?
- Which third parties carry the most monitoring risk, and do our review intervals reflect that?
- Is our annual review cycle a considered risk decision, or a default?
- If a regulator asked us to show ongoing third-party oversight, what evidence could we provide?
The right answers will differ by organisation, risk appetite, regulatory environment and type of relationship. We would still suggest asking them before a change at a key third party turns into a compliance event.
Effective Due Diligence Doesn’t End at Onboarding
Onboarding due diligence is an important control. A thorough assessment at the start of a relationship gives a documented baseline and catches risk indicators early.
That baseline is where oversight starts.
Owners, directors, legal status and regulatory exposure can all change after onboarding. Effective third-party risk management needs a way to see those changes when they happen, and a proportionate process for responding to them.
“The question for compliance leaders is not whether their third parties will change. The question is whether they will know when they do.”
– Ficoal Dong, Founder & CPTO, AsiaVerify
Third-party populations are getting larger and more international. Monitoring between review cycles now matters as much as the onboarding review. A sound compliance programme identifies risk at the start of a relationship, and notices when that risk changes.
If you want to know when a third party changes between reviews, read how Perpetual KYB monitoring tracks registry changes to company status, directors, shareholders and ownership.