← Industry Insights

Customer Identification Program (CIP): A Compliance Guide for Financial Institutions

Updated Jun 2026 · 6 min read
SHAREinXf
What is a Customer Identification Program (CIP)?

A customer identification program (CIP) is the set of documented procedures a financial institution uses to collect and verify the identity of every customer who opens an account. It is mandatory. Under the Bank Secrecy Act and Section 326 of the USA PATRIOT Act, every institution's anti-money laundering program has to include one. At a minimum, a CIP captures a customer's name, date of birth, address, and a government-issued identification number, then verifies that information through documentary or non-documentary methods.

Below, we cover what the CIP rule requires, who has to follow it, the four data elements every program collects, how identity verification works in practice, and where CIP sits inside a wider customer due diligence framework. The audience here is compliance teams at banks, fintechs, and other regulated firms, not consumers looking for a how-to.

What Is a Customer Identification Program?

A customer identification program is one part of a financial institution's anti-money laundering policy, and it is not the part you can skip. At its core it is a set of procedures for confirming who sits on the other side of an account, person or organization alike. Run it well and the institution gets a clear picture of its customers, which makes the firm a much harder target for money laundering, terrorist financing, or fraud.

The program is not a single check at onboarding. It defines what information the institution collects, how that information is verified, how records are retained, and how customer names are screened against government watchlists. Every later control depends on knowing the true identity behind an account, so a well-run CIP becomes the foundation the rest of the AML program sits on.

CIP Regulatory Framework

Plenty of jurisdictions require firms to adopt customer identification programs. In the United States, Section 326 of the USA PATRIOT Act, enacted in 2001, requires financial institutions to establish written policies and procedures that verify the identity of any person seeking to open an account. Firms must also retain records of the information used to verify identity, and they must compare customers against government lists of known or suspected terrorists.

These obligations sit inside the wider Bank Secrecy Act framework and connect directly to a firm's AML compliance program. The CIP is the entry point. It works alongside ongoing monitoring, suspicious activity reporting, and recordkeeping requirements.

Key Regulatory Bodies

Several regulatory bodies oversee the enforcement of customer identification requirements.

The Financial Crimes Enforcement Network (FinCEN), a bureau of the U.S. Treasury, administers and enforces the Bank Secrecy Act and related anti-money laundering rules. The Office of Foreign Assets Control (OFAC), also part of the Treasury, runs economic and trade sanctions tied to U.S. foreign policy, which is exactly why sanctions screening belongs in any CIP. Internationally, the Financial Action Task Force (FATF) sets the global standards that many national regimes are modeled on.

Who Is Subject to the Customer Identification Program Rule?

The CIP rule reaches a wide range of entities defined as "financial institutions" under the Bank Secrecy Act and related regulations. Banks and credit unions are covered. So are broker-dealers in securities, mutual funds, money services businesses, and certain trust companies. Other regulated sectors, including casinos and iGaming platforms, insurance companies, cryptocurrency businesses, and finance or lending companies, either fall within scope or operate under closely parallel identity rules.

Plenty of businesses that are not strictly required to follow the CIP rule build a comparable program anyway. A documented identity process cuts fraud exposure, supports fraud prevention controls, and gives the firm a defensible audit trail when a regulator or partner asks how an onboarding decision was made. For institutions operating across borders, a consistent program is also what lets them hold customers in different markets to the same standard.

The Four Elements of Customer Identification Verification

Before opening an account for an individual, every customer identification program must collect four pieces of identifying information. These are the regulatory minimum. Most firms gather more, based on their own risk assessment.

  • Name. The customer's full legal name as it appears on official records.
  • Date of birth confirms that the applicant is a real, identifiable account holder rather than a fabricated one.
  • Address. A residential or business street address, and depending on the institution's policy, not a P.O. box on its own.
  • Identification number, meaning a government-issued identifier such as a taxpayer identification number or passport number.

Collecting these elements is only half the obligation. The program also has to verify them, which is where documentary and non-documentary methods come in.

Customer Identification Verification Methods

A CIP can verify the four data elements through documentary methods, non-documentary methods, or a mix of both. The right approach hinges on three things: the institution's risk profile, the channel the customer onboards through, and the type of account being opened.

Documentary verification means reviewing government-issued documents such as a passport, driver's license, or national ID. Non-documentary verification confirms identity by comparing what the customer provided against independent sources, including credit bureaus, public databases, and government registries. For remote and digital onboarding, many institutions pair identity verification with biometric checks like liveness detection, so they can confirm a document genuinely belongs to the person presenting it.

Get a free demo

A strong verification step does more than satisfy a regulator. This is the control that catches synthetic identities, stolen documents, and fabricated applications before any of them reach an account. And the tighter that step is, the less investigation and remediation a compliance team is left to clean up later.

When Customer Identification Should Be Triggered

Account opening is the most common trigger for customer identification, but treating it as the only one is a mistake. A CIP should re-run identity checks whenever a customer's risk profile shifts, whenever an existing record proves incomplete or out of date, or whenever activity hints that the original verification no longer holds up.

Video KYC and other remote methods come into play whenever a customer cannot present documents in person and the institution still needs a high-assurance check. That covers digital account opening, the onboarding of higher-risk customers, and any case where earlier documentary evidence has expired. Treat identification as something that can recur rather than a one-time gate, and customer records stay accurate, which is exactly what a perpetual approach to KYC depends on.

Customer Identification and Customer Due Diligence

A customer identification program answers one question: who is the customer? Customer due diligence answers a different one: how risky is that customer, and how much ongoing attention do they need? The two are distinct but tightly linked, and a CIP is effectively the first step of the broader customer due diligence process.

A customer due diligence program layers several activities on top of basic identification. It risk-rates the customer, establishes the nature and purpose of the relationship, screens against sanctions and watchlists, identifies beneficial owners for legal-entity customers, and monitors activity over the life of the relationship. Higher-risk customers move into enhanced due diligence, which means deeper investigation and more frequent review. Once you map how your CIP feeds these later stages, a loose collection of identity checks turns into a coherent compliance program.

How KYC Hub Supports Customer Identification

KYC Hub's global KYC solution pulls the identification and verification steps of a CIP into a single workflow built for banks and fintechs. The platform covers video KYC, identity verification, document-based ID verification, liveness checks, phone verification, and digital signature. A compliance team can collect and verify all four data elements through one configurable process instead of stitching together separate tools.

Because identification underpins everything downstream, the same platform links verified identities through to screening, risk rating, and ongoing monitoring. Institutions get to apply one consistent standard across markets, cut onboarding time, and keep a clean audit trail for regulators. To see how it maps to your CIP and customer due diligence requirements, get a free demo.

[ FREQUENTLY ASKED QUESTIONS ]

Any questions? We got you.

What are the four required elements of a customer identification program?

A CIP must collect a customer's name, date of birth, address, and a government-issued identification number before opening an account for an individual. These four elements are the regulatory minimum under the CIP rule. Most institutions also collect additional data based on their own risk assessment.

Is a customer identification program legally required?

Yes. For U.S. financial institutions, a written CIP is required under Section 326 of the USA PATRIOT Act and the Bank Secrecy Act. The program must be part of the institution's broader anti-money laundering program and approved by its board or a designated committee. Many firms outside the strict legal scope adopt equivalent programs to manage fraud and operational risk.

What is the difference between CIP and customer due diligence?

A customer identification program verifies who the customer is by collecting and confirming identifying information at onboarding. Customer due diligence goes further by assessing the customer's risk, screening against watchlists, identifying beneficial owners, and monitoring activity over time. The CIP is best understood as the first step within a wider customer due diligence framework.

What verification methods can a CIP use?

A CIP can use documentary methods, such as reviewing a passport or driver's license, and non-documentary methods, such as checking the customer's details against credit bureaus and government databases. Most institutions combine both, and many add biometric or liveness checks for remote and digital onboarding. The chosen mix should reflect the institution's risk profile and onboarding channel.

When should customer identification be triggered?

Identification is required at account opening, but it should also be re-triggered when a customer's risk profile changes, when an existing record is incomplete or outdated, or when activity suggests the original verification is no longer reliable. Remote methods such as video KYC are typically triggered when a customer cannot verify in person but still needs a high-assurance check.

Who is subject to the CIP rule?

The rule applies to entities defined as financial institutions under the Bank Secrecy Act, including banks, credit unions, broker-dealers, mutual funds, and money services businesses. Other regulated sectors such as casinos, insurers, and cryptocurrency businesses fall within scope or operate under closely related identity requirements. Many non-regulated firms adopt similar programs voluntarily.

[ KYC HUB ]

Automate your compliance operations

Replace manual checks and spreadsheets with automated screening, workflows and audit-ready records.

Explore the compliance automationBook a demo