When Verification Comes Back: Why You Are Asked Again
Same upload screen, same photograph of your face — except this time you did not start it. Who sent the request, and which document it comes out of, decides whether you are looking at a form or at an obligation.
Independent guide · Not affiliated with any platform · Not investment advice
You go to move money out on a weeknight, and instead of the transfer screen you get a very familiar page: front of the document, back of the document, now turn your head for the camera. You did all of this two years ago. Nothing has changed since. The account has been fine.
The first thought is usually that something has gone wrong with the account. The second is to find someone to ask, and there is nobody to ask.
What makes this disorienting is that the screen is identical to the one you filled in yourself, while the thing behind it is not. Updating your verification information and being told to verify again are two separate paths. One of them is documented on the help pages. The other is not on the help pages at all.
The seven situations the help page lists
Binance's help centre page on completing identity verification for a personal account (English version showing an update date of 2026-06-05, read 21 September 2026) sets out when you can update your verification information. Four of the seven are quoted here word for word:
- “The documents have expired”
- “The name on the document has changed”
- “The ID number on the document has changed”
- “The nationality has changed”
The remaining three cover replacing a document to meet the requirements of a particular fiat channel, switching to a document in a language the system can read, and updating a document for the platform's card product.
Read them as a set and the pattern is hard to miss: in every one of them, the thing that changed is on your side. A document ran out, a name moved, a number was reissued, a nationality changed, or you want access to something new. You are the one starting it.
What matters at least as much is what the page does not say. It sets out no review cycle, no periodic refresh, nothing along the lines of “we may ask you again”. I treat that page as an index of what I am able to initiate, and nothing more — when a firm comes to you, it has no answer to offer.
The same page is direct about the purpose of the exercise: identity verification standards “are designed to protect your account against fraud, corruption, money laundering, and terrorist financing”. That sentence is worth holding on to, because the duty discussed below grows out of exactly those words. If you are tempted to hand the whole thing to somebody who promises to clear it for you, read why guaranteed verification services are always a trap first.
On timing, the page states that submitted documents are “usually reviewed within 48 hours” and that “it may take longer in some particular cases” (read 21 September 2026). A range, not a promise; what governs is whatever your own screen shows when you submit.
Where “go back to existing customers” is actually written
If the help page does not cover it, where is it written? In the anti-money-laundering rules, and in language considerably more concrete than most people expect.
The UK Money Laundering Regulations 2017 deal with ongoing monitoring in regulation 28(11). Sub-paragraph (b) is the sentence that fits this situation exactly:
undertaking reviews of existing records and keeping the documents or information obtained for the purpose of applying customer due diligence measures up-to-date.
“Up-to-date” is the operative phrase. It means a two-year-old file is, in itself, something the firm has to deal with. You do not have to have done anything. The record simply aged.
Regulation 27(8) covers when due diligence has to be applied all over again. Sub-paragraph (a) reads:
at other appropriate times to existing customers on a risk based approach.
Sub-paragraph (b) of the same provision deals with the firm becoming aware that an existing customer's circumstances have changed. (The sentence is truncated on the page we read, so it is summarised here rather than quoted.)
The European framework says the same thing in one sentence. Article 14(5) of Directive (EU) 2015/849:
Member States shall require that obliged entities apply the customer due diligence measures not only to all new customers but also at appropriate times to existing customers on a risk-sensitive basis, including at times when the relevant circumstances of a customer change.
Two jurisdictions, one proposition: an existing customer is not someone who has been crossed off the list. Which also explains the part people find hardest to accept — the timing is not yours. Behaving impeccably is not an exemption, and doing nothing at all is not a shield, because what sets the moment is the firm's risk cycle and its statutory duties rather than your conduct.
The help page answers “what am I able to do”. The regulations answer “when does somebody else have to come and ask me”. Most of what is written online about re-verification paraphrases the first and then uses it to explain the second, which is why none of it lines up.
There is a quiet assumption buried in the question “why me” — that being asked again means somebody found something. Regulation 27(8) does not support that reading. The same provision lists, alongside the risk-based timing, a duty to contact existing customers within a given year in order to review information relating to due diligence and risk assessment and to beneficial ownership, and a separate duty to contact existing customers in order to comply with obligations under the International Tax Compliance Regulations 2015.
That second one is worth sitting with. A request can reach you purely because a tax-information obligation came due, with nothing about your account involved at all. It is not the only possible reason, and no outsider can tell you which reason applies in your case — but it does mean that “they must have flagged me” is a guess, not an inference.
What a platform-wide recall looked like in 2021
All of the above is rules. There is one publicly checkable example of what the rules look like once they are executed.
On 20 August 2021, Binance published an announcement on changes to identity verification (read 21 September 2026). It applied to “Existing users who have not yet completed [Verified] Verification” — people who had opened accounts when less was required. Accounts that did not complete were moved to “Withdraw Only”, a state limited to “withdrawal, order cancellation, position close, and redemption”. The announcement said this would be rolled out in phases, from then through 2021-10-19 00:00 (UTC).
That is a description of one exercise in 2021, not of current policy, and nothing about how an account would be handled today follows from it. What survives is the shape: applied to a whole cohort rather than to individuals, a stated deadline, and a non-completion state that lets money leave but not much else happen.
It does not work out why you specifically were asked. Firms do not publish their trigger conditions, and guessing at them would be worthless. It also offers no way to avoid, defer or work around a check — on the provisions above, that is not a question of technique.
When it lands on you: the order to read it in
- Establish that the request really comes from the platform. Ignore the link in the email or text; open the account the way you always open it and see whether the same request is sitting inside. If it is, work through it there. If it is not, discard the message. This takes under a minute and it is the one step that cannot be skipped.
- Read what kind of document is being asked for. A document and a face answer “are you who you say”. A proof of address answers “whose rules apply to you”. A question about where the money came from is a different exercise again, covered separately in source of funds vs source of wealth. The type of document usually is the question.
- Check your documents against what is on file. If your name, number or nationality genuinely changed in the meantime, or the document expired, you are in one of the seven situations from the help page and this was yours to initiate anyway. The expiry case has its own page: what to do when your ID has expired.
- Then wait out the stated range. Usually within 48 hours, longer in some particular cases (that help page, read 21 September 2026), with your own screen governing. Resubmitting inside the range rarely helps; what is happening during those hours is unpacked in what happens in the review queue.
One last thing, and it is not comforting: there is no version of this where you do everything right and it never happens again. A check is not a gate you clear once; it is a relationship that stays open. Knowing where it is written at least spares you the half hour of assuming your account has been stolen.
The situations in which you can update your verification information, the purpose sentence and the review-time range come from Binance's English help centre page “How to Complete Identity Verification for a Personal Account?” (page showing an update date of 2026-06-05), read 21 September 2026. Only the English page was used here; the Chinese page under the same article number is a separate file with a different update date, and nothing has been carried across languages.
Ongoing monitoring and keeping records up to date are regulation 28(11)(b) of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (SI 2017/692); due diligence applied to existing customers at other appropriate times, and the beneficial-ownership and tax-compliance duties, are regulation 27(8) of the same instrument. The European provision is Article 14(5) of Directive (EU) 2015/849. All read 21 September 2026.
The 2021 exercise is Binance's announcement “Important Changes About Binance Identity Verification”, dated 20 August 2021, read 21 September 2026. It is used here only to show what a cohort-wide recall looked like in practice, and not as evidence of current policy or of how any account would be treated now.
No contractual terms are quoted in this edition. We were unable to retrieve the English terms of use in a readable form on the date of writing, and this site does not quote or number a clause it has not read in the language it is publishing in. The Chinese edition of this article, where those pages were readable, covers the contractual side.
While writing this we did not log into any account, receive any re-verification request, or observe any review in progress; everything here was checked against the public sources above. Separating self-service updates from firm-initiated re-checks, and the account of what sets the timing, are this site's reading of those provisions and should be treated as inference.
Four questions this raises
Could this be a phishing attempt?
That is the first thing to rule out, and ruling it out does not depend on anyone's judgement. Do not follow the link in the email or the text message. Open the account the way you normally open it and see whether the same request is waiting inside. If it is, work through it there. If it is not, the message can be discarded. We do not assess whether any particular message you received is genuine, and we do not confirm notices on behalf of any platform.
None of the seven situations applies to me. So why am I being asked?
Because those seven answer a different question. The help page groups them under the heading about when you can update your verification information (read 21 September 2026); they describe changes on your side. That page does not state how often a firm revisits a completed check. The duty to revisit existing customers sits in the anti-money-laundering regulations, quoted in the second and third sections above.
What happens if I simply do not respond?
There is a documented example of what non-completion looked like at scale. An announcement dated 20 August 2021 required existing users who had not yet completed verification to do so, and accounts that did not were moved to a Withdraw Only state limited to withdrawal, order cancellation, position close and redemption. That describes how that particular 2021 exercise was handled and should not be read as current policy or as a prediction about any account today.
How long does a repeat submission take to clear?
The English help page states that submitted documents are usually reviewed within 48 hours and that it may take longer in some particular cases (read 21 September 2026). That is a range rather than a commitment, and what governs is whatever the platform shows you at the time. Submitting again inside that range generally does not help; it usually sends the case to the back of the queue.
Platform side (read 21 September 2026): the updatable situations, the purpose sentence and the review-time range are on Binance's help centre page on identity verification for personal accounts; the cohort-wide requirement is in its announcement of 20 August 2021.
Legal texts (read 21 September 2026): ongoing monitoring is regulation 28 of the Money Laundering Regulations 2017; due diligence for existing customers is regulation 27 of the same instrument; the European provision is Article 14(5) of Directive (EU) 2015/849.
Splitting self-service updates from firm-initiated re-checks, and the account of what sets the timing, are this site's synthesis of the sources above and represent no institution's or platform's position. How any particular account is handled is whatever the platform's own pages and notices say at the time.