Customer Identification Program (CIP)

A Customer Identification Program (CIP) is the set of procedures a U.S. financial institution must follow to verify the identity of anyone opening an account. It is required by Section 326 of the USA PATRIOT Act and implemented for banks at 31 CFR 1020.220. The standard it sets is not certainty but a reasonable belief that the institution knows the true identity of the customer.

Statutory basis USA PATRIOT Act Section 326
Rule (banks) 31 CFR 1020.220; parallel rules cover broker-dealers, mutual funds, futures merchants and others
Standard applied A reasonable belief that the institution knows the customer’s true identity
Minimum data collected Name, date of birth, address, and an identification number
Identification number TIN for U.S. persons; for non-U.S. persons, a passport number and country of issuance, alien identification card number, or other government-issued document number
Verification methods Documentary, non-documentary, or a combination
Four program elements Identity verification, recordkeeping, comparison with government lists, customer notice
Timing Information collected before account opening; verification within a reasonable time after

How it works

CIP has a narrow job. It is not a judgment about whether a customer is risky, or where their money comes from, or whether they should be banked at all. It answers one question: is this person who they say they are? The wider questions belong to customer due diligence, which sits on top of CIP and depends on it.

The rule requires four minimum data elements before an account is opened — name, date of birth, residential or business address, and an identification number. For U.S. persons that number is a taxpayer identification number. For non-U.S. persons the rule allows a passport number with country of issuance, an alien identification card number, or a number from another government-issued document evidencing nationality or residence and bearing a photograph or similar safeguard.

Verification then follows one of two paths, or both. Documentary verification examines an identity document — a driving permit, a passport, a residency card. Non-documentary verification compares the information given against independent sources: credit bureau data, public records, or checks against a database. Institutions commonly use both, and the rule expects risk-based procedures that specify when each applies.

The four elements of a compliant program

Element What it requires
Identity verification Risk-based procedures for verifying identity to the extent reasonable and practicable, sufficient to form a reasonable belief the institution knows the customer
Recordkeeping Retain the identifying information and a description of the documents or methods relied on, kept for five years after the account is closed
Government list comparison Determine whether the customer appears on any federal list of known or suspected terrorists or terrorist organizations
Customer notice Give customers adequate notice that information is being requested to verify identity

The recordkeeping element is the one institutions most often underestimate. It is not enough to have verified identity; the program must be able to show what was relied on and why, five years after the relationship ends.

Why CIP matters for identity verification

CIP is the point where identity verification stops being a product decision and becomes a legal obligation. Everything downstream inherits it. The customer risk rating, the expected-behavior profile that transaction monitoring compares against, the sanctions screening result — all of it assumes the name on the account belongs to the person who opened it.

That assumption is exactly what synthetic identity fraud attacks. A synthetic identity is assembled to satisfy CIP: a real identification number paired with a fabricated name and date of birth can clear non-documentary checks precisely because the number verifies. The program was satisfied and no real person was identified. This is the structural reason documentary verification with genuine document authentication has become load-bearing rather than optional.

The practical work is identity document verification that authenticates the document rather than merely reading it, paired with a biometric check binding the document to the person presenting it. For institutions building this into onboarding, KYC and AML workflows are where CIP obligations meet the customer experience, and the tension between the two is the design problem.

CIP compared with KYC and CDD

Term Scope Question answered
CIP A specific U.S. regulatory requirement Is this person who they claim to be?
CDD Broader obligation including CIP What risk does this customer present, and what is their expected activity?
EDD Applied to higher-risk customers What additional scrutiny does this relationship warrant?
KYC An umbrella term, not a single regulation Loosely, all of the above

KYC is used loosely and often interchangeably with CIP, which causes real confusion in compliance conversations. CIP is a defined rule with defined minimums. KYC is the general practice. An institution can satisfy CIP and still have a weak KYC program.

What CIP can’t do

It does not establish that a customer is legitimate. Verifying identity and assessing risk are separate exercises. A correctly identified customer may still be a poor one.

It does not require certainty. The standard is a reasonable belief formed through risk-based procedures. Regulators do not expect perfection, but they do expect the procedures to be documented and followed.

It does not cover beneficial owners on its own. Identifying the natural persons behind a legal entity customer is a separate requirement, and confusing the two leaves a gap on entity accounts.

Non-documentary verification can be satisfied by a synthetic identity. Matching a name and number against a bureau file confirms that the combination exists in a database, not that a person does.

Frequently asked questions

What information does a CIP require?

At minimum, name, date of birth, address, and an identification number. For U.S. persons the identification number is a taxpayer identification number. For non-U.S. persons, the rule permits a passport number with country of issuance, an alien identification card number, or another government-issued document number evidencing nationality or residence.

Is CIP the same as KYC?

No. CIP is a specific U.S. regulatory requirement under Section 326 of the USA PATRIOT Act covering identity verification at account opening. KYC is a broader, informal umbrella term covering identity verification, risk assessment, and ongoing monitoring. CIP is one component of it.

How long must CIP records be kept?

Identifying information must be retained for five years after the account is closed. Records describing the documents or methods relied on for verification are subject to their own retention requirement, and institutions should confirm the current periods against the rule text.

Can identity be verified without documents?

Yes. The rule permits non-documentary verification, such as comparing the information provided against credit bureau or public record data. In practice many institutions combine both approaches, and documentary verification has become more important as synthetic identities have grown better at satisfying database checks.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data