Re-KYC. The repetition a held credential was designed for
This page defines the term and says exactly where a portable credential touches it.
What re-KYC is
Re-verification of an existing customer, on a schedule or on a trigger. A regulated business cannot verify someone once and rely on it indefinitely: documents expire, circumstances change, risk ratings move, and supervisors expect the file to be current.
So the same customer, already onboarded, gets checked again, annually, or every few years by risk tier, or when something changes. See periodic review for the scheduled version of the same duty.
Why this is the clearest fit for a held credential, said plainly
The whole reusable-credential argument rests on the same person being verified more than once. Re-KYC is the case where that is guaranteed by regulation rather than left to chance.
In every other vertical, reuse depends on the customer happening to appear elsewhere. In re-KYC the repetition is mandatory, scheduled, and paid for by the same institution that paid last time. That is why the arithmetic on the crypto-exchange vertical works at all, a multi-homed user plus a re-KYC cycle passes the reuse threshold quickly.
And a credential the customer holds is genuinely a better instrument for this than a re-run capture: the institution can request a fresh presentation, check credential status against a published status list, and see whether anything has been revoked, without asking the customer to photograph a passport again.
That is the argument, and it is a good one.
What a credential does not do here
It does not tell you the customer's risk has not changed. A valid credential says the identity was verified and has not been revoked. It says nothing about adverse media, sanctions exposure, or a change in the customer's circumstances: those are separate checks, and Solidus ships none of them.
It does not set your schedule. Re-KYC cadence is a risk-based decision your compliance function makes against a supervisor's expectations. We have no view on it and no product that manages it.
And it does not discharge your obligation. Where a regulator requires you to re-verify, accepting a credential does not transfer that duty: it changes what the customer has to do, not what you are answerable for.
What we would need to be useful here
A relying party willing to accept a presentation in place of a re-capture, and a supervisor who does not object. The second is the real gate, and it is the same gate named on the crypto-exchange vertical.
If you run re-KYC cycles and know whether your supervisor would accept a presented credential, that answer is worth more than anything else on this page.