Table of contents
A Customer Identification Program (CIP) is a US anti-money-laundering rule requiring financial institutions to verify the identity of every customer who opens an account. Mandated by Section 326 of the USA PATRIOT Act, a CIP must collect four data points, name, date of birth, address and an identification number, and verify them within a reasonable time after the account is opened.
What is a Customer Identification Program (CIP)?
A CIP is a formal programme rather than a one-off check: written procedures, approved by the board, embedded in the institution’s Bank Secrecy Act (BSA) and AML compliance programme, and applied to every customer who opens an account. The rule for banks is at 31 CFR 1020.220. Its core obligation is to form a reasonable belief that the institution knows the true identity of each customer, and to be able to show an examiner how that belief was formed.
Two definitions decide how far the rule reaches:
- Account means a formal banking relationship established to provide or engage in services, dealings or other financial transactions: deposit accounts, loans, safe deposit boxes and similar. One-off transactions for non-customers, such as a wire transfer, generally fall outside it.
- Customer means the person opening a new account. For a business account the customer is the legal entity itself; its beneficial owners are covered by the separate customer due diligence rule, not by the CIP rule.
Fintechs and crypto platforms that partner with a chartered bank inherit the bank’s CIP by contract. Sponsor banks are examined on their partners’ onboarding controls, which is why programme-level rigour matters even where the rule does not name you directly.
The four CIP requirements
Before an account is opened, 31 CFR 1020.220(a)(2)(i) requires the institution to collect four pieces of identifying information. The programme must then verify enough of them to form a reasonable belief about the customer’s true identity.
Name
The customer’s full legal name. For a legal entity, the registered name as it appears on formation documents.
Date of birth
Required for individuals. Entities have no equivalent, but the formation date is commonly collected as part of the documentary record.
Address
A residential or business street address, not a post office box. An individual without a street address may give an Army or Fleet Post Office box or the address of a next of kin or other contact person. An entity gives a principal place of business, local office or other physical location.
Identification number (TIN, passport, or alien ID)
For US persons, a taxpayer identification number: a Social Security number or an Employer Identification Number. For non-US persons, one or more of a TIN, a passport number with country of issuance, an alien identification card number, or the number and issuing country of another government-issued document bearing a photograph or similar safeguard.
Two nuances trip up new programmes. A customer who has applied for but not yet received a TIN can be onboarded if the CIP says how the institution confirms the application was filed and obtains the number within a reasonable time. And since 27 June 2025, under a FinCEN exemption order issued with the concurrence of the federal banking agencies, a bank may obtain a customer’s full TIN from a reliable third-party source, such as a credit bureau, rather than from the customer directly, for example by collecting only the last four digits at account opening. Using the alternative is optional, and every other CIP obligation still applies.
Who must have a CIP?
Banks and credit unions
Banks, savings associations and credit unions, under 31 CFR 1020.220, examined by the OCC, FDIC, Federal Reserve or NCUA as part of every BSA/AML examination.
Broker-dealers and futures merchants
Broker-dealers in securities (31 CFR 1023.220), mutual funds (31 CFR 1024.220) and futures commission merchants and introducing brokers (31 CFR 1026.220) carry parallel rules with the same four data points. A fund sold through an intermediary may rely on the intermediary’s CIP under a written agreement.
Money services businesses (MSBs)
There is no CIP section for money services businesses, but 31 CFR 1022.210 requires every MSB’s AML programme to include procedures for verifying customer identity commensurate with its risk, and state money transmitter licences add identification duties of their own. US crypto exchanges are MSBs and onboard under the same expectation.
Coming into scope: payment stablecoin issuers
The GENIUS Act, signed in July 2025, treats permitted payment stablecoin issuers as financial institutions under the BSA. In April 2026 FinCEN and OFAC proposed implementing rules that would impose bank-grade AML, customer identification and sanctions obligations on those issuers. If you issue or plan to issue a payment stablecoin, build CIP-grade onboarding before the final rule lands rather than after.
CIP vs KYC vs CDD: how they differ
CIP is often used as a synonym for KYC. It is narrower: CIP is the identity-verification step at account opening, KYC is the wider practice of knowing who the customer is and how they will use the account, and customer due diligence is the rule that adds beneficial ownership, purpose of the relationship and a risk profile. All three sit inside the AML programme.
| Layer | What it is | When it happens | Legal basis (US) |
|---|---|---|---|
| CIP | Collecting and verifying the four identity data points; recordkeeping, list checks, customer notice | At account opening | 31 CFR 1020.220 (Section 326, USA PATRIOT Act) |
| KYC | The umbrella practice of knowing who your customer is and how they will use the account; includes CIP plus risk rating | Onboarding and ongoing | Industry term, implemented through the CIP and CDD rules |
| CDD | Understanding the nature and purpose of the relationship, identifying beneficial owners of legal entities, building a customer risk profile | Onboarding, then ongoing monitoring | FinCEN CDD Rule (31 CFR 1010.230 and the programme rules) |
| EDD | Deeper scrutiny for higher-risk customers such as PEPs: source of funds and wealth, adverse media, senior-management approval | Triggered by risk rating or red flags | Risk-based expectation under the BSA/AML programme rules |
Put differently: CIP answers “is this person who they claim to be?”, CDD answers “what should we expect from this relationship?”, and enhanced due diligence answers “this customer is higher risk, do we understand why and can we manage it?”. For business customers the equivalent of CIP is KYB, and the two are compared in KYC vs KYB.
Documentary vs non-documentary verification
The rule does not mandate a verification technology. It requires risk-based procedures that say when the institution uses documents, when it uses non-documentary methods, when it uses both, and what happens when verification fails.
| Method | What it involves | Typical examples | When it is used |
|---|---|---|---|
| Documentary | Examining an unexpired government-issued document with a photograph or similar safeguard | Driving licence, passport, national ID card; for entities, articles of incorporation, business licences, partnership agreements | In-person and digital onboarding where the customer can present ID |
| Non-documentary | Corroborating identity against independent sources without inspecting a document | Credit bureau checks, public database lookups, contacting the customer, references from other institutions, comparison with prior statements | Remote onboarding, thin-file customers, or as a second factor when documents alone leave doubt |
| Combined (typical modern practice) | Automated document authentication plus biometric and database checks in one flow | ID capture with forgery detection, selfie-to-document face match with liveness, database corroboration of name, date of birth, address and ID number | Digital-first banks, fintechs and any institution onboarding customers it never meets in person |
The written programme must also cover four edge cases: customers who cannot present unexpired government ID, documents that look altered or unfamiliar, accounts opened without face-to-face contact, and what the institution does when it cannot form a reasonable belief about identity, including when it closes the account and when it files a suspicious activity report.
Government list screening under CIP
Under 31 CFR 1020.220(a)(4) the programme must include procedures to determine, within a reasonable time after the account is opened, whether the customer appears on any list of known or suspected terrorists or terrorist organisations issued by a federal agency. This is distinct from OFAC sanctions screening, which is a separate obligation, but in practice both run in the same screening step, alongside PEP and adverse media screening for higher-risk customers. See the sanctions screening guide for how the lists differ.
CIP recordkeeping: what to retain and for how long
- Identifying information: the name, date of birth, address and identification number collected, retained for five years after the account is closed.
- Verification records: a description of any document relied on (type, number, issuer, expiry), the non-documentary methods used and their results, and how any discrepancy was resolved, retained for five years after the record is made. A description is sufficient; the rule does not require keeping a copy of the document.
- Customer notice: adequate notice, before the account is opened, that the institution is requesting information to verify identity. A posted or on-screen notice satisfies it.
- Reliance: an institution may rely on another regulated US financial institution to perform CIP elements for a shared customer, if reliance is reasonable, the other institution has an AML programme rule, and it certifies annually that it will perform the steps. The relying institution stays responsible for the outcome.
What happens when a CIP fails: enforcement and penalties
CIP is examined at every BSA/AML examination, and failures rarely appear alone. In March 2022 FinCEN assessed a $140 million civil money penalty against USAA Federal Savings Bank for wilful BSA violations, including failing to implement and maintain an adequate AML programme, with a concurrent $60 million penalty from the OCC. Civil penalties under 31 U.S.C. 5321 accrue per violation, and regulators can add cease-and-desist orders, consent orders with independent monitors and, for non-banks, the loss of state licences.
Examiners work from the FFIEC BSA/AML Examination Manual. The findings they write up most often: a programme that is a template rather than a description of the institution’s real channels and customers, files that show information collected but not resolved, no documented failure procedure, and records that cannot be retrieved five years on.
Automating CIP with Zyphe
Zyphe’s KYC software runs the documentary leg of a CIP against over 4,000 identity document versions from 213 countries and territories, with active liveness and a face match to the document portrait, and screens the verified person against sanctions, PEP, watchlist and adverse media data in the same flow. The CIP record is the verification result, the audit log and the cryptographic proof of what was checked; the document itself is processed transiently and stored in the customer’s own encrypted vault rather than in a central database. That satisfies the five-year description requirement without building a store of ID images that a breach could expose.
Where the customer is a company, the same workflow runs KYC and KYB together: the entity is verified against the official register, ownership is traced to natural persons, and each owner and director completes a linked identity check before the business can be approved.
Written by Michelangelo Frigo (Co-Founder at Zyphe) Reviewed September 18, 2026 Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.