Free guide: How to use AI in compliance
Back

CIP (Customer Identification Program)

Updated September 18, 2026

Table of contents

A Customer Identification Program (CIP) is a US anti-money-laundering rule requiring financial institutions to verify the identity of every customer who opens an account. Mandated by Section 326 of the USA PATRIOT Act, a CIP must collect four data points, name, date of birth, address and an identification number, and verify them within a reasonable time after the account is opened.

What is a Customer Identification Program (CIP)?

A CIP is a formal programme rather than a one-off check: written procedures, approved by the board, embedded in the institution’s Bank Secrecy Act (BSA) and AML compliance programme, and applied to every customer who opens an account. The rule for banks is at 31 CFR 1020.220. Its core obligation is to form a reasonable belief that the institution knows the true identity of each customer, and to be able to show an examiner how that belief was formed.

Two definitions decide how far the rule reaches:

  • Account means a formal banking relationship established to provide or engage in services, dealings or other financial transactions: deposit accounts, loans, safe deposit boxes and similar. One-off transactions for non-customers, such as a wire transfer, generally fall outside it.
  • Customer means the person opening a new account. For a business account the customer is the legal entity itself; its beneficial owners are covered by the separate customer due diligence rule, not by the CIP rule.

Fintechs and crypto platforms that partner with a chartered bank inherit the bank’s CIP by contract. Sponsor banks are examined on their partners’ onboarding controls, which is why programme-level rigour matters even where the rule does not name you directly.

The four CIP requirements

Before an account is opened, 31 CFR 1020.220(a)(2)(i) requires the institution to collect four pieces of identifying information. The programme must then verify enough of them to form a reasonable belief about the customer’s true identity.

Name

The customer’s full legal name. For a legal entity, the registered name as it appears on formation documents.

Date of birth

Required for individuals. Entities have no equivalent, but the formation date is commonly collected as part of the documentary record.

Address

A residential or business street address, not a post office box. An individual without a street address may give an Army or Fleet Post Office box or the address of a next of kin or other contact person. An entity gives a principal place of business, local office or other physical location.

Identification number (TIN, passport, or alien ID)

For US persons, a taxpayer identification number: a Social Security number or an Employer Identification Number. For non-US persons, one or more of a TIN, a passport number with country of issuance, an alien identification card number, or the number and issuing country of another government-issued document bearing a photograph or similar safeguard.

Two nuances trip up new programmes. A customer who has applied for but not yet received a TIN can be onboarded if the CIP says how the institution confirms the application was filed and obtains the number within a reasonable time. And since 27 June 2025, under a FinCEN exemption order issued with the concurrence of the federal banking agencies, a bank may obtain a customer’s full TIN from a reliable third-party source, such as a credit bureau, rather than from the customer directly, for example by collecting only the last four digits at account opening. Using the alternative is optional, and every other CIP obligation still applies.

Who must have a CIP?

Banks and credit unions

Banks, savings associations and credit unions, under 31 CFR 1020.220, examined by the OCC, FDIC, Federal Reserve or NCUA as part of every BSA/AML examination.

Broker-dealers and futures merchants

Broker-dealers in securities (31 CFR 1023.220), mutual funds (31 CFR 1024.220) and futures commission merchants and introducing brokers (31 CFR 1026.220) carry parallel rules with the same four data points. A fund sold through an intermediary may rely on the intermediary’s CIP under a written agreement.

Money services businesses (MSBs)

There is no CIP section for money services businesses, but 31 CFR 1022.210 requires every MSB’s AML programme to include procedures for verifying customer identity commensurate with its risk, and state money transmitter licences add identification duties of their own. US crypto exchanges are MSBs and onboard under the same expectation.

Coming into scope: payment stablecoin issuers

The GENIUS Act, signed in July 2025, treats permitted payment stablecoin issuers as financial institutions under the BSA. In April 2026 FinCEN and OFAC proposed implementing rules that would impose bank-grade AML, customer identification and sanctions obligations on those issuers. If you issue or plan to issue a payment stablecoin, build CIP-grade onboarding before the final rule lands rather than after.

CIP vs KYC vs CDD: how they differ

CIP is often used as a synonym for KYC. It is narrower: CIP is the identity-verification step at account opening, KYC is the wider practice of knowing who the customer is and how they will use the account, and customer due diligence is the rule that adds beneficial ownership, purpose of the relationship and a risk profile. All three sit inside the AML programme.

LayerWhat it isWhen it happensLegal basis (US)
CIPCollecting and verifying the four identity data points; recordkeeping, list checks, customer noticeAt account opening31 CFR 1020.220 (Section 326, USA PATRIOT Act)
KYCThe umbrella practice of knowing who your customer is and how they will use the account; includes CIP plus risk ratingOnboarding and ongoingIndustry term, implemented through the CIP and CDD rules
CDDUnderstanding the nature and purpose of the relationship, identifying beneficial owners of legal entities, building a customer risk profileOnboarding, then ongoing monitoringFinCEN CDD Rule (31 CFR 1010.230 and the programme rules)
EDDDeeper scrutiny for higher-risk customers such as PEPs: source of funds and wealth, adverse media, senior-management approvalTriggered by risk rating or red flagsRisk-based expectation under the BSA/AML programme rules

Put differently: CIP answers “is this person who they claim to be?”, CDD answers “what should we expect from this relationship?”, and enhanced due diligence answers “this customer is higher risk, do we understand why and can we manage it?”. For business customers the equivalent of CIP is KYB, and the two are compared in KYC vs KYB.

Documentary vs non-documentary verification

The rule does not mandate a verification technology. It requires risk-based procedures that say when the institution uses documents, when it uses non-documentary methods, when it uses both, and what happens when verification fails.

MethodWhat it involvesTypical examplesWhen it is used
DocumentaryExamining an unexpired government-issued document with a photograph or similar safeguardDriving licence, passport, national ID card; for entities, articles of incorporation, business licences, partnership agreementsIn-person and digital onboarding where the customer can present ID
Non-documentaryCorroborating identity against independent sources without inspecting a documentCredit bureau checks, public database lookups, contacting the customer, references from other institutions, comparison with prior statementsRemote onboarding, thin-file customers, or as a second factor when documents alone leave doubt
Combined (typical modern practice)Automated document authentication plus biometric and database checks in one flowID capture with forgery detection, selfie-to-document face match with liveness, database corroboration of name, date of birth, address and ID numberDigital-first banks, fintechs and any institution onboarding customers it never meets in person

The written programme must also cover four edge cases: customers who cannot present unexpired government ID, documents that look altered or unfamiliar, accounts opened without face-to-face contact, and what the institution does when it cannot form a reasonable belief about identity, including when it closes the account and when it files a suspicious activity report.

Government list screening under CIP

Under 31 CFR 1020.220(a)(4) the programme must include procedures to determine, within a reasonable time after the account is opened, whether the customer appears on any list of known or suspected terrorists or terrorist organisations issued by a federal agency. This is distinct from OFAC sanctions screening, which is a separate obligation, but in practice both run in the same screening step, alongside PEP and adverse media screening for higher-risk customers. See the sanctions screening guide for how the lists differ.

CIP recordkeeping: what to retain and for how long

  • Identifying information: the name, date of birth, address and identification number collected, retained for five years after the account is closed.
  • Verification records: a description of any document relied on (type, number, issuer, expiry), the non-documentary methods used and their results, and how any discrepancy was resolved, retained for five years after the record is made. A description is sufficient; the rule does not require keeping a copy of the document.
  • Customer notice: adequate notice, before the account is opened, that the institution is requesting information to verify identity. A posted or on-screen notice satisfies it.
  • Reliance: an institution may rely on another regulated US financial institution to perform CIP elements for a shared customer, if reliance is reasonable, the other institution has an AML programme rule, and it certifies annually that it will perform the steps. The relying institution stays responsible for the outcome.

What happens when a CIP fails: enforcement and penalties

CIP is examined at every BSA/AML examination, and failures rarely appear alone. In March 2022 FinCEN assessed a $140 million civil money penalty against USAA Federal Savings Bank for wilful BSA violations, including failing to implement and maintain an adequate AML programme, with a concurrent $60 million penalty from the OCC. Civil penalties under 31 U.S.C. 5321 accrue per violation, and regulators can add cease-and-desist orders, consent orders with independent monitors and, for non-banks, the loss of state licences.

Examiners work from the FFIEC BSA/AML Examination Manual. The findings they write up most often: a programme that is a template rather than a description of the institution’s real channels and customers, files that show information collected but not resolved, no documented failure procedure, and records that cannot be retrieved five years on.

Automating CIP with Zyphe

Zyphe’s KYC software runs the documentary leg of a CIP against over 4,000 identity document versions from 213 countries and territories, with active liveness and a face match to the document portrait, and screens the verified person against sanctions, PEP, watchlist and adverse media data in the same flow. The CIP record is the verification result, the audit log and the cryptographic proof of what was checked; the document itself is processed transiently and stored in the customer’s own encrypted vault rather than in a central database. That satisfies the five-year description requirement without building a store of ID images that a breach could expose.

Where the customer is a company, the same workflow runs KYC and KYB together: the entity is verified against the official register, ownership is traced to natural persons, and each owner and director completes a linked identity check before the business can be approved.

Michelangelo Frigo Written by Michelangelo Frigo (Co-Founder at Zyphe) Reviewed September 18, 2026 Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

CIP stands for Customer Identification Program. It is the set of procedures a financial institution uses to verify that customers are who they claim to be, required under Section 326 of the USA PATRIOT Act and codified for banks at 31 CFR 1020.220.

Every CIP must collect a customer’s name, date of birth, residential or business street address, and an identification number: a taxpayer identification number for US persons, or a passport number, alien identification card number or similar government-issued document number for non-US persons. The programme must then verify enough of that information to form a reasonable belief about the customer’s true identity.

No. CIP is one component of KYC. KYC is the broader programme covering customer identification, customer due diligence, risk rating and ongoing monitoring. CIP covers only the identity-verification step performed at account opening.

Banks, savings associations, credit unions, broker-dealers, mutual funds and futures commission merchants operating in the United States must maintain a written CIP. Money services businesses carry an equivalent customer-verification duty inside their AML programme rule, and fintechs that partner with a bank inherit the bank’s CIP by contract.

Identifying information must be retained for five years after the account is closed. Records of the verification methods used, including a description of any document relied on and how discrepancies were resolved, must be kept for five years after the record is made.

Yes. Non-documentary verification, comparing customer data against credit bureau records, public databases or other reliable independent sources, is permitted and is common in digital onboarding, either on its own or alongside document checks. The written programme must say when each method is used.

Run identity verification without the honeypot

Zyphe verifies customers at onboarding and reuses that proof across platforms, without storing a central pile of PII.

Book a demo