Periodic Review Workflow Netherlands TCSP

Periodic Review Workflow Netherlands TCSP

Risk-based CDD framework

Netherlands Trust and Company Service Providers (TCSPs) face strict periodic review requirements under the Wwft and Act on the Supervision of Trust Offices (Wtt 2018). A practical periodic review workflow that Netherlands TCSPs implement ensures compliance with AFM and DNB expectations.

This guide shows how to build a periodic review workflow that Netherlands TCSP teams can execute to meet regulatory obligations and demonstrate ongoing compliance. Learn how to structure customer reviews, assess residual risk, and maintain audit-ready documentation.

What is a periodic review workflow for Netherlands TCSPs?

A periodic review workflow Netherlands TCSP managers implement is a structured process to reassess customer due diligence findings, beneficial ownership status, and transaction patterns at defined intervals.

Periodic reviews ensure that customer risk classifications remain accurate and that new risks (PEP status changes, sanctions list additions, and unusual activity patterns) are identified and managed promptly.

Under the Wwft, TCSPs must conduct ongoing customer monitoring. A documented periodic review workflow demonstrates this is happening systematically, not ad-hoc or based on inconsistent practices. Reports of unusual transactions go to the FIU-Nederland.

Why periodic review workflow matters for Netherlands TCSPs

AFM and DNB inspect whether TCSPs implement a periodic review workflow correctly. Key inspection focus areas include:

Apply risk-based review cycles. All customers cannot be reviewed annually. Firms must allocate high-risk customers to annual cycles, medium-risk to biennial cycles, and low-risk to 3-5-year cycles.

This proportionality reduces compliance costs while focusing effort where risk is highest.

Identify emerging risks between reviews. Beneficial owners change, political figures take new office, or sanctions list additions occur. A documented periodic review workflow Netherlands TCSPs follow captures these events and triggers immediate reassessment.

Update customer files with current information. Outdated or incomplete beneficial ownership records create regulatory risk. Reviews must verify that UBO register entries remain accurate and that customer risk profiles reflect current circumstances.

Maintain audit trails. Regulators expect evidence that reviews occurred, when and who conducted them, what risk factors were considered, and what decisions were made. Spreadsheets and informal processes create gaps that inspectors identify.

Regulatory framework: Wwft and Wtt 2018 Requirements

The Wwft (Anti-Money Laundering and Counter-Terrorism Financing Act) mandates that TCSPs conduct ongoing customer due diligence and apply a risk-based approach. Articles 2b and 3 require risk assessments documenting customer, product, delivery channel, and geographical risk factors.

Implementing a periodic review workflow that Netherlands TCSPs must follow under these articles ensures documented, proportionate risk management. The periodic review workflow Netherlands TCSP teams establish becomes the mechanism for meeting this obligation.

The Trust Office Act (Wtt 2018) imposes additional governance requirements. TCSP boards must oversee integrity risks (including money laundering and terrorist financing). Compliance officers must be designated, policies documented, and independent audits allowed. TCSPs may be required to submit periodic attestations of compliance.

AFM Guidance clarifies expectations for the periodic review workflow. Reviews should assess:

  • Customer identity and beneficial ownership currency
  • Transaction patterns consistency with expected activity
  • Sanctions list and PEP database updates
  • Any events indicating higher risk (e.g., adverse media, regulatory concerns)

Risk-based cadence: High-risk customers (PEPs, beneficial owners from high-corruption jurisdictions, complex structures, and large cash flows) should be reviewed annually. Medium-risk customers: every two years. Low-risk customers: every three to five years or based on agreed-upon monitoring triggers.

Building a periodic review workflow for Netherlands TCSPs use

5 steps-

Step 1: Establish risk classification and review schedule

Conduct initial risk assessments at onboarding, assigning each customer to a risk tier: high, medium, or low. Document the rationale (jurisdiction risk, customer type, product, transaction profile, beneficial ownership complexity). Create a rolling review schedule based on risk tier: high-risk annual, medium-risk biennial, and low-risk 3-5 year.

Step 2: Define review scope and frequency triggers

Specify what information must be updated during periodic reviews: beneficial ownership verification (confirm UBO register match); customer identity validation (renew ID if >5 years old); transaction pattern assessment (compare to baseline activity); sanctions screening (screen customer and beneficial owners against OFAC, EU, UN, and national lists); and adverse media search. Define event-based triggers for out-of-cycle reviews (name on sanctions list, public announcement of political appointment, SAR filing, unusual transaction pattern).

Step 3: Schedule and execute reviews

Initiate reviews 30-60 days before the due date. Assign to the compliance officer or relationship manager. Request updated beneficial ownership information from the customer. Screen updated information against current databases. Compare transaction patterns to the customer’s risk profile. Document findings in the customer file.

Step 4: Update customer risk profile

If review findings indicate no changes, reaffirm the existing risk tier and set the next review date. If risk factors change (e.g., the beneficial owner takes public office or the customer moves to a higher-risk jurisdiction), reassess and update the risk tier. If reassessment results in higher risk, trigger enhanced due diligence and senior management review. Document all updates with date and approving authority.

Step 5: Maintain Audit Trail and Reporting

Record review completion date, reviewer name, data sources screened (sanctions databases, UBO register, KVK), findings summary, risk tier (unchanged or updated), next review date, and any escalations. File documentation in the customer record. Report results to board or audit committee periodically to demonstrate ongoing governance.

Periodic review decision matrix for Netherlands TCSPs

Risk TierReview FrequencySanctions ScreeningUBO VerificationEDD RequiredDocumentation
High-riskAnnualAt each reviewAt each reviewYes (if tier confirmed)Detailed findings, approvals, escalations
Medium-riskBiennialAt each reviewEvery second reviewIf risk factors changeSummary findings, risk tier confirmation
Low-riskEvery 3-5 yearsAt each reviewEvery third review or event-triggeredOnly if new risk factors emergeBrief findings, next review date
Event-triggeredImmediateYesYesRisk-dependentFull documentation of event, reassessment

Best practices for periodic review workflows

Use multiple data sources. Screen against OFAC, EU sanctions, UN lists, and commercial providers. No single database covers all risks; cross-referencing reduces false negatives.

Verify beneficial ownership against the KVK UBO register. Check the KVK UBO Register for discrepancies between customer-provided information and official records. Document the verification process.

Monitor for policy changes affecting customers. When a beneficial owner becomes a political figure, check public records and update the risk assessment. When customers change domicile or business focus, reassess accordingly.

Escalate material changes to senior management. If a review identifies new high-risk factors, do not merely update the file; escalate to the compliance officer or board-designated authority for a decision on relationship continuation.

Document exceptions and waivers. If a high-risk customer review results in a decision to continue the relationship despite elevated risk, document the business rationale and approving authority.

Common challenges in periodic review workflows

Inconsistent risk tier application. One team member classifies a customer as medium-risk; another classifies a similar customer as low-risk. Lack of clear, documented criteria creates inconsistency that regulators flag.

Delayed reviews due to customer non-cooperation. Customers do not provide updated beneficial ownership information on time. Establish contractual requirements that customers respond within 30 days or face account suspension.

Outdated beneficial ownership data in KVK. UBO register entries lag behind reality. Manual follow-up required to identify discrepancies between KVK and actual control structures.

High false-positive alert rates. Screening against commercial databases generates matches that are not actual PEPs or sanctions targets. Manual review consumes resources; better data quality reduces noise.

Insufficient audit trail. Reviews documented in email or unversioned spreadsheets create no clear record of who reviewed what and when. Centralized workflow platforms reduce documentation gaps.

How technology supports periodic review workflows

Automated scheduling triggers reviews on due dates. Integration with sanctions databases (OFAC, EU, LSEG World-Check) screens customers automatically and flags new matches. Workflow tools route reviews to assigned staff, track completion, and escalate delays. Centralized case management maintains version-controlled documentation of all review decisions and audit trails.

Cascade integrates with leading data providers to screen against:

Adverse media sources
UN Sanctions List (UN Sanctions)
EU Consolidated Sanctions List (EU Sanctions Map)
OFAC (U.S. Treasury) Sanctions (OFAC SDN List)
Politically Exposed Persons (PEPs) databases (FATF Guidance on PEPs)

FAQs

How do we handle periodic reviews for dormant customer accounts?

Review dormant accounts on the same cycle as active accounts; inactivity does not eliminate TCSP obligations. If the relationship ends, document closure and retain review records for five years post-closure.

What if beneficial ownership information is unavailable or unclear?

Pursue reasonable inquiries: contact the customer, review corporate filings, and consult KVK registry records. If information cannot be obtained, escalate to the compliance officer and consider enhanced due diligence or relationship review.

Can we conduct periodic reviews less frequently than required by law?

No. The WWFT-mandated cadence (annual for high-risk, biennial for medium-risk, and 3-5 years for low-risk) is a minimum. Conducting fewer reviews violates regulatory expectations.

How do we classify customers if we lack complete information at review time?

Assign a provisional risk tier based on available information, escalate for enhanced due diligence, and set a near-term follow-up review once information is obtained. Document the provisional classification rationale.

Should we conduct periodic reviews even if no transactions occur?

Yes. Ongoing due diligence applies to all customer relationships regardless of transaction activity. Inactivity does not reduce TCSP obligations.

Does Cascade’s platform integrate with the Netherlands sanctions databases and the KVK UBO register?

Cascade integrates with three leading screening data providers: Acuris Risk Intelligence, LSEG World-Check, formerly Refinitiv World-Check, and Dow Jones. These integrations support screening for sanctions, PEPs, adverse media, and other watchlist or regulatory risk data within Cascade’s AML/KYC workflows. 

Explore Cascade’s Periodic Review Workflow Capabilities

Managing periodic review workflows for dozens or hundreds of customers across varying risk tiers is complex. Many TCSPs struggle to maintain review schedules, track completion, document decisions, and respond to regulatory exams efficiently.

Explore how Cascade’s AML Software brings name screening together with broader AML/KYC workflows, or learn more about the Automated Treatment of Name Screening Alerts add-on for supporting the treatment and documentation of screening alerts.

Schedule a demo with our compliance team.

Disclaimer

This article is for general information only and not legal or compliance advice. Periodic review requirements vary based on TCSP supervision type (AFM, DNB, or both), so consult your compliance officer or external counsel to tailor this framework to your specific circumstances. The examples are illustrative; Cascade does not guarantee regulatory compliance or immunity from supervisory action. Your TCSP remains responsible for implementing effective periodic review procedures.

Ready to Get Started?

Empower your compliance with the leading end-to-end AML KYC platform Cascade