# KYC Refresh: Upcoming periodic confirmation requirements

*Last Updated: October 2026*
Stripe is introducing **Know Your Customer (KYC) Refresh**, a recurring regulatory effort that asks connected accounts to confirm that the information they previously provided is still accurate. The first rollout applies to connected accounts in Europe.
If you are a platform that is responsible for collecting requirement information from your connected accounts, you will need to update your integration to handle these changes. This will ensure your connected accounts meet the new requirements, allowing them to continue accepting card payments and receiving payouts without interruption.
> **2026 Private Preview release**: The KYC Refresh API is currently available in private preview. During the preview, impacted KYC refresh requirements have no due dates and do not affect capabilities.
> **2027 Public Preview release**: The KYC Refresh API will be available for public preview in Q1 2027, along with an in-depth API Integration guide. Additional information will be provided closer to the release date.
## What is changing
Stripe will periodically add attestation requirements to connected accounts. Unlike most requirements, these don't ask for new information. They ask the connected account to review information it has already provided and confirm that it's still correct, or update it if it has changed.
Attestation requirements appear in the account's `requirements` hash, and they trigger the same `account.updated` webhook events. Each attestation requirement references an inquiry, an object that lists the specific fields   for the account to review.
Stripe may ask connected accounts to confirm:
* The account representative of the Stripe account
* The business associated with the Stripe account
* Any individuals who ultimately own or control that business
How often an account is asked to refresh depends on its risk profile, local regulatory requirements, and when account information was last updated. Refresh windows are specific to each connected account and are applied on a rolling basis.
## What you need to do
Your required work depends on how your connected accounts complete onboarding and requirement updates.
**Standard/Express/UA1&UA2 platforms do not require any integration changes.** Stripe will reach out to connected accounts directly to collect updated business information.
**If you use an API-based flow to onboard your connected accounts**, you must update your integration to handle all requirement changes. Platforms have three options to choose from when deciding how to adjust their onboarding flow to ensure connected accounts meet these requirements.
* **Stripe Hosted**: Send users to our hosted onboarding experience. This flow also updates automatically to reflect new requirements, but provides less customization. When your new connected accounts provide business information we’re unable to verify, we’ll surface detailed verification responses via the Accounts API. You’ll need to adjust your integration to handle new verification responses.
* **Embedded Onboarding**: Add customizable embedded onboarding components to your site. These dynamically update to reflect new requirements.
* **API Onboarding**: Modify your existing onboarding flow using detailed verification responses from the Accounts API. This allows the most control, but requires the most effort to maintain.
> If you currently use API onboarding, consider [migrating your onboarding and remediation flows to Stripe-hosted or embedded onboarding](https://docs.stripe.com/connect/migrate-from-api-onboarding) so that subsequent requirement changes are handled by Stripe.
### If you use Stripe-hosted onboarding
Send accounts to an onboarding experience built and hosted by Stripe. [Stripe-hosted onboarding](https://docs.stripe.com/connect/custom/onboarding#stripe-hosted-onboarding) adapts to handle verification requirements updates automatically.
### If you use embedded onboarding components
No integration changes are required if your embedded component is configured to collect all applicable outstanding requirements. When a connected account has KYC Refresh requirements, the component presents the review and confirmation experience automatically.
If you use `collectionOptions.requirements.only` or `collectionOptions.requirements.exclude`, review those restrictions before KYC Refresh begins.
Narrowly scoped component configurations can omit KYC Refresh from that component instance. This doesn't remove or satisfy the connected account's requirements, so ensure the account has another path to complete them, such as an unrestricted embedded or Stripe-hosted experience. Stripe doesn't currently support configuring requirement restrictions specifically for KYC Refresh.
### How do embedded-component requirement restrictions interact with KYC Refresh?
Requirement restrictions continue to control what a particular embedded-component instance presents. A narrowly scoped component might not present KYC Refresh, but the underlying requirements remain outstanding on the Account and can still be completed through another available remediation surface.
Stripe does not recommend relying on internal requirement identifiers to configure KYC Refresh behavior. These identifiers aren’t part of the public API and are subject to change.
### If you use API onboarding
Stripe plans to release the KYC Refresh API in public preview in Q1 2027, along with an integration guide, API reference, and test-mode tooling. Once released, you'll need to update your integration so your connected accounts can see refresh requests, review the information Stripe has on file, and confirm or update their information.
---
## Frequently asked questions
### Why is Stripe introducing KYC Refresh?
Financial regulations require Stripe to keep the identity and business information of the accounts it serves accurate and up to date over time, not only at onboarding. People move, ownership changes, and
As part of meeting our regulatory obligations, Stripe must periodically review and refresh account information to ensure it remains accurate and up to date. KYC Refresh will provide a predictable way to do this, help reduce the scope of future remediation, and ensure evolving regulatory commitments focus primarily on newly introduced requirements. Keeping account information current also helps accounts remain in good standing and minimizes potential disruptions.
### Is this a new regulatory requirements update similar to the Europe updates?
No. KYC Refresh does not introduce new data fields or verification steps. Connected accounts are asked to confirm information they have already given. New information is only needed if something has changed, or if Stripe is unable to verify the updated information.
Accounts that recently completed a requirements update (for example, the [Europe verification update](https://support.stripe.com/questions/europe-updated-verification-requirements-for-connected-accounts-of-platforms)) are considered refreshed as of that date and will enter their next refresh window based on their risk profile.
### Which connected accounts are affected?
The initial rollout applies to connected accounts based in Europe. Stripe plans to expand KYC Refresh to additional regions and account types over time and will communicate those changes in advance.
Not every connected account will receive a refresh request at the same time. Accounts enter refresh windows on a rolling basis as they become due.
### What should I tell my connected accounts?
Tell them this is a routine confirmation. Explain that they only need to provide new information if something has changed. For more information, you can direct them to [this support page](https://support.stripe.com/questions/why-did-stripe-ask-me-to-review-my-account-information).
### Can a platform confirm information on behalf of a connected account?
For Custom platforms that collect requirements on behalf of their connected accounts, the platform must submit the attestation through the API after the user has reviewed their information in your interface. The attestation records that the user reviewed the data; it should reflect a real user action and not an automated data sync.