Customer Identification Program (CIP)
A Customer Identification Program (CIP) is the set of procedures a U.S. financial institution must follow to verify the identity of anyone opening an account. It is required by Section 326 of the USA PATRIOT Act and implemented for banks at 31 CFR 1020.220. The standard it sets is not certainty but a reasonable belief that the institution knows the true identity of the customer.
| Statutory basis | USA PATRIOT Act Section 326 |
| Rule (banks) | 31 CFR 1020.220; parallel rules cover broker-dealers, mutual funds, futures merchants and others |
| Standard applied | A reasonable belief that the institution knows the customer’s true identity |
| Minimum data collected | Name, date of birth, address, and an identification number |
| Identification number | TIN for U.S. persons; for non-U.S. persons, a passport number and country of issuance, alien identification card number, or other government-issued document number |
| Verification methods | Documentary, non-documentary, or a combination |
| Four program elements | Identity verification, recordkeeping, comparison with government lists, customer notice |
| Timing | Information collected before account opening; verification within a reasonable time after |
How it works
CIP has a narrow job. It is not a judgment about whether a customer is risky, or where their money comes from, or whether they should be banked at all. It answers one question: is this person who they say they are? The wider questions belong to customer due diligence, which sits on top of CIP and depends on it.
The rule requires four minimum data elements before an account is opened — name, date of birth, residential or business address, and an identification number. For U.S. persons that number is a taxpayer identification number. For non-U.S. persons the rule allows a passport number with country of issuance, an alien identification card number, or a number from another government-issued document evidencing nationality or residence and bearing a photograph or similar safeguard.
Verification then follows one of two paths, or both. Documentary verification examines an identity document — a driving permit, a passport, a residency card. Non-documentary verification compares the information given against independent sources: credit bureau data, public records, or checks against a database. Institutions commonly use both, and the rule expects risk-based procedures that specify when each applies.
The four elements of a compliant program
| Element | What it requires |
|---|---|
| Identity verification | Risk-based procedures for verifying identity to the extent reasonable and practicable, sufficient to form a reasonable belief the institution knows the customer |
| Recordkeeping | Retain the identifying information and a description of the documents or methods relied on, kept for five years after the account is closed |
| Government list comparison | Determine whether the customer appears on any federal list of known or suspected terrorists or terrorist organizations |
| Customer notice | Give customers adequate notice that information is being requested to verify identity |
The recordkeeping element is the one institutions most often underestimate. It is not enough to have verified identity; the program must be able to show what was relied on and why, five years after the relationship ends.
Why CIP matters for identity verification
CIP is the point where identity verification stops being a product decision and becomes a legal obligation. Everything downstream inherits it. The customer risk rating, the expected-behavior profile that transaction monitoring compares against, the sanctions screening result — all of it assumes the name on the account belongs to the person who opened it.
That assumption is exactly what synthetic identity fraud attacks. A synthetic identity is assembled to satisfy CIP: a real identification number paired with a fabricated name and date of birth can clear non-documentary checks precisely because the number verifies. The program was satisfied and no real person was identified. This is the structural reason documentary verification with genuine document authentication has become load-bearing rather than optional.
The practical work is identity document verification that authenticates the document rather than merely reading it, paired with a biometric check binding the document to the person presenting it. For institutions building this into onboarding, KYC and AML workflows are where CIP obligations meet the customer experience, and the tension between the two is the design problem.
CIP compared with KYC and CDD
| Term | Scope | Question answered |
|---|---|---|
| CIP | A specific U.S. regulatory requirement | Is this person who they claim to be? |
| CDD | Broader obligation including CIP | What risk does this customer present, and what is their expected activity? |
| EDD | Applied to higher-risk customers | What additional scrutiny does this relationship warrant? |
| KYC | An umbrella term, not a single regulation | Loosely, all of the above |
KYC is used loosely and often interchangeably with CIP, which causes real confusion in compliance conversations. CIP is a defined rule with defined minimums. KYC is the general practice. An institution can satisfy CIP and still have a weak KYC program.
What CIP can’t do
It does not establish that a customer is legitimate. Verifying identity and assessing risk are separate exercises. A correctly identified customer may still be a poor one.
It does not require certainty. The standard is a reasonable belief formed through risk-based procedures. Regulators do not expect perfection, but they do expect the procedures to be documented and followed.
It does not cover beneficial owners on its own. Identifying the natural persons behind a legal entity customer is a separate requirement, and confusing the two leaves a gap on entity accounts.
Non-documentary verification can be satisfied by a synthetic identity. Matching a name and number against a bureau file confirms that the combination exists in a database, not that a person does.
Frequently asked questions
What information does a CIP require?
At minimum, name, date of birth, address, and an identification number. For U.S. persons the identification number is a taxpayer identification number. For non-U.S. persons, the rule permits a passport number with country of issuance, an alien identification card number, or another government-issued document number evidencing nationality or residence.
Is CIP the same as KYC?
No. CIP is a specific U.S. regulatory requirement under Section 326 of the USA PATRIOT Act covering identity verification at account opening. KYC is a broader, informal umbrella term covering identity verification, risk assessment, and ongoing monitoring. CIP is one component of it.
How long must CIP records be kept?
Identifying information must be retained for five years after the account is closed. Records describing the documents or methods relied on for verification are subject to their own retention requirement, and institutions should confirm the current periods against the rule text.
Can identity be verified without documents?
Yes. The rule permits non-documentary verification, such as comparing the information provided against credit bureau or public record data. In practice many institutions combine both approaches, and documentary verification has become more important as synthetic identities have grown better at satisfying database checks.
Related reading
- Customer due diligence — the broader obligation CIP sits inside, and where risk assessment begins
- Know Your Customer — the umbrella term, and why it is not interchangeable with CIP
- Bank Secrecy Act — the statute the whole U.S. AML framework is built on
- KYC checklist for banks — how these obligations translate into an operational onboarding process