Customer Identification Program (CIP): A Compliance Guide for Financial Institutions
A customer identification program (CIP) is the set of documented procedures a financial institution uses to collect and verify the identity of every customer who opens an account. It is mandatory. Under the Bank Secrecy Act and Section 326 of the USA PATRIOT Act, every institution's anti-money laundering program has to include one. At a minimum, a CIP captures a customer's name, date of birth, address, and a government-issued identification number, then verifies that information through documentary or non-documentary methods.
Below, we cover what the CIP rule requires, who has to follow it, the four data elements every program collects, how identity verification works in practice, and where CIP sits inside a wider customer due diligence framework. The audience here is compliance teams at banks, fintechs, and other regulated firms, not consumers looking for a how-to.
What Is a Customer Identification Program?
A customer identification program is one part of a financial institution's anti-money laundering policy, and it is not the part you can skip. At its core it is a set of procedures for confirming who sits on the other side of an account, person or organization alike. Run it well and the institution gets a clear picture of its customers, which makes the firm a much harder target for money laundering, terrorist financing, or fraud.
The program is not a single check at onboarding. It defines what information the institution collects, how that information is verified, how records are retained, and how customer names are screened against government watchlists. Every later control depends on knowing the true identity behind an account, so a well-run CIP becomes the foundation the rest of the AML program sits on.
CIP Regulatory Framework
Legal Requirements
Plenty of jurisdictions require firms to adopt customer identification programs. In the United States, Section 326 of the USA PATRIOT Act, enacted in 2001, requires financial institutions to establish written policies and procedures that verify the identity of any person seeking to open an account. Firms must also retain records of the information used to verify identity, and they must compare customers against government lists of known or suspected terrorists.
These obligations sit inside the wider Bank Secrecy Act framework and connect directly to a firm's AML compliance program. The CIP is the entry point. It works alongside ongoing monitoring, suspicious activity reporting, and recordkeeping requirements.
Key Regulatory Bodies
Several regulatory bodies oversee the enforcement of customer identification requirements.
The Financial Crimes Enforcement Network (FinCEN), a bureau of the U.S. Treasury, administers and enforces the Bank Secrecy Act and related anti-money laundering rules. The Office of Foreign Assets Control (OFAC), also part of the Treasury, runs economic and trade sanctions tied to U.S. foreign policy, which is exactly why sanctions screening belongs in any CIP. Internationally, the Financial Action Task Force (FATF) sets the global standards that many national regimes are modeled on.
Who Is Subject to the Customer Identification Program Rule?
The CIP rule reaches a wide range of entities defined as "financial institutions" under the Bank Secrecy Act and related regulations. Banks and credit unions are covered. So are broker-dealers in securities, mutual funds, money services businesses, and certain trust companies. Other regulated sectors, including casinos and iGaming platforms, insurance companies, cryptocurrency businesses, and finance or lending companies, either fall within scope or operate under closely parallel identity rules.
Plenty of businesses that are not strictly required to follow the CIP rule build a comparable program anyway. A documented identity process cuts fraud exposure, supports fraud prevention controls, and gives the firm a defensible audit trail when a regulator or partner asks how an onboarding decision was made. For institutions operating across borders, a consistent program is also what lets them hold customers in different markets to the same standard.
The Four Elements of Customer Identification Verification
Before opening an account for an individual, every customer identification program must collect four pieces of identifying information. These are the regulatory minimum. Most firms gather more, based on their own risk assessment.
- Name. The customer's full legal name as it appears on official records.
- Date of birth confirms that the applicant is a real, identifiable account holder rather than a fabricated one.
- Address. A residential or business street address, and depending on the institution's policy, not a P.O. box on its own.
- Identification number, meaning a government-issued identifier such as a taxpayer identification number or passport number.
Collecting these elements is only half the obligation. The program also has to verify them, which is where documentary and non-documentary methods come in.
Customer Identification Verification Methods
A CIP can verify the four data elements through documentary methods, non-documentary methods, or a mix of both. The right approach hinges on three things: the institution's risk profile, the channel the customer onboards through, and the type of account being opened.
Documentary verification means reviewing government-issued documents such as a passport, driver's license, or national ID. Non-documentary verification confirms identity by comparing what the customer provided against independent sources, including credit bureaus, public databases, and government registries. For remote and digital onboarding, many institutions pair identity verification with biometric checks like liveness detection, so they can confirm a document genuinely belongs to the person presenting it.
A strong verification step does more than satisfy a regulator. This is the control that catches synthetic identities, stolen documents, and fabricated applications before any of them reach an account. And the tighter that step is, the less investigation and remediation a compliance team is left to clean up later.
When Customer Identification Should Be Triggered
Account opening is the most common trigger for customer identification, but treating it as the only one is a mistake. A CIP should re-run identity checks whenever a customer's risk profile shifts, whenever an existing record proves incomplete or out of date, or whenever activity hints that the original verification no longer holds up.
Video KYC and other remote methods come into play whenever a customer cannot present documents in person and the institution still needs a high-assurance check. That covers digital account opening, the onboarding of higher-risk customers, and any case where earlier documentary evidence has expired. Treat identification as something that can recur rather than a one-time gate, and customer records stay accurate, which is exactly what a perpetual approach to KYC depends on.
Customer Identification and Customer Due Diligence
A customer identification program answers one question: who is the customer? Customer due diligence answers a different one: how risky is that customer, and how much ongoing attention do they need? The two are distinct but tightly linked, and a CIP is effectively the first step of the broader customer due diligence process.
A customer due diligence program layers several activities on top of basic identification. It risk-rates the customer, establishes the nature and purpose of the relationship, screens against sanctions and watchlists, identifies beneficial owners for legal-entity customers, and monitors activity over the life of the relationship. Higher-risk customers move into enhanced due diligence, which means deeper investigation and more frequent review. Once you map how your CIP feeds these later stages, a loose collection of identity checks turns into a coherent compliance program.
How KYC Hub Supports Customer Identification
KYC Hub's global KYC solution pulls the identification and verification steps of a CIP into a single workflow built for banks and fintechs. The platform covers video KYC, identity verification, document-based ID verification, liveness checks, phone verification, and digital signature. A compliance team can collect and verify all four data elements through one configurable process instead of stitching together separate tools.
Because identification underpins everything downstream, the same platform links verified identities through to screening, risk rating, and ongoing monitoring. Institutions get to apply one consistent standard across markets, cut onboarding time, and keep a clean audit trail for regulators. To see how it maps to your CIP and customer due diligence requirements, get a free demo.
