Aug
BSA Identity Verification: A CIP Guide for Compliance Officers
TL;DR:
- BSA identity verification, or the Customer Identification Program, requires financial institutions to reasonably verify each customer’s true identity before opening an account.
- A written CIP with documented verification methods, customer information collection, and escalation procedures is essential for compliance.
BSA identity verification, the formal industry term for which is the Customer Identification Program (CIP), requires every covered financial institution to form a reasonable belief in a customer’s true identity before opening an account, using risk-based documentary and/or non-documentary methods, as mandated under 31 CFR 1020.220 and Section 326 of the USA PATRIOT Act. The regulation is not aspirational. It is a binding compliance floor, and examiners test against it on every cycle.
Three actions belong at the top of your CIP task list:
- Confirm your written CIP exists and is current. The rule requires a written program embedded in your BSA/AML compliance framework, not a standalone memo.
- Verify your account-opening screens collect all required identifying fields for both individuals and legal entities before any account is activated.
- Document the specific verification method used for each customer, whether documentary or non-documentary, in a form an examiner can trace back to the decision.
The FDIC’s Financial Institution Letter on CIP makes the SAR obligation explicit: if your institution cannot form a reasonable belief about a customer’s identity after exhausting its procedures, a Suspicious Activity Report must be filed. That escalation path is where many programs go silent, and that silence is what draws examiner criticism.
Table of Contents
- What regulations actually require BSA identity checks?
- What must a compliant written CIP actually contain?
- What customer information does the CIP require you to collect?
- How does BSA identity verification work in practice?
- When does enhanced verification apply, and what does it look like?
- What records must you keep, and what notice must you give customers?
- Can you rely on another institution or a third-party vendor for CIP?
- What happens when you cannot verify a customer’s identity?
- Your practical CIP implementation checklist
- How do modern identity technologies fit into your CIP program?
- Key Takeaways
- Where CIP enforcement is actually heading
- Useful sources
- FAQ
What regulations actually require BSA identity checks?
The CIP obligation flows from three interlocking sources, each serving a distinct function in examinations and policy drafting.
31 CFR 1020.220 is the operative rule. It sets the minimum program requirements for banks, specifying the customer information to collect, the verification methods permitted, recordkeeping periods, customer notice requirements, and the conditions under which reliance on another financial institution is allowed. When an examiner cites a CIP deficiency, this is the regulation they are citing.
Section 326 of the USA PATRIOT Act is the statutory authority behind the rule. Congress directed the Treasury and the federal banking agencies to jointly prescribe regulations requiring financial institutions to implement reasonable procedures for verifying customer identity. The CIP rule is the direct regulatory output of that mandate.
FFIEC BSA/AML Examination Manual and FinCEN/Interagency Guidance translate the rule into examination expectations. The FFIEC BSA/AML Manual provides the examination procedures examiners follow, the risk factors they weigh, and the documentation they expect to find. The FinCEN Interagency Interpretive Guidance and the FDIC’s Interagency CIP FAQs answer specific implementation questions that the rule text leaves open.
For policy drafting, attach 31 CFR 1020.220 as the primary citation. For board reports, the FFIEC manual language on “reasonable belief” is the framing examiners recognize. For remediation plans, the Interagency FAQs provide the granular Q&A that supports specific procedural choices.
What must a compliant written CIP actually contain?
The FFIEC examination procedures give examiners a specific checklist. Your written CIP must address all of the following:
- Written policies and procedures embedded in the BSA/AML compliance program, approved by the board or a designated senior officer, and updated when products, channels, or risk profiles change.
- Risk-based verification procedures that describe, for each customer type and account channel, which documentary and/or non-documentary methods the institution will use and under what circumstances.
- Required identifying information collection at account opening, covering name, date of birth (individuals), address, and identification number, before the account is activated or access is granted.
- Verification procedures specifying the documents or data sources used, the timing of verification relative to account opening, and the process for resolving discrepancies.
- Recordkeeping requirements covering what to retain, in what format, and for how long (five years from account closure for most records).
- Customer notice that the institution is requesting information to verify identity, provided at or before account opening.
- Checking government lists of known or suspected terrorists or terrorist organizations, as required by Treasury order, within a reasonable period after account opening.
- Reliance provisions describing the conditions under which the institution may rely on another regulated financial institution’s CIP, including the contractual and oversight requirements.
Governance controls examiners expect to find alongside the written program:
- Board or senior management approval documented in meeting minutes.
- Annual or event-triggered policy review with a change log.
- Staff training records tied to CIP procedures, not just generic BSA training.
- Independent testing results and management responses.
- Vendor oversight documentation for any third party performing CIP functions.
A policy that names the right elements but lacks the governance trail around it will still draw a finding. Examiners look for evidence that the program is operational, not just written.
What customer information does the CIP require you to collect?
The minimum fields are fixed by regulation. What varies is how you handle edge cases, and that is where most account-opening systems fall short.
| Field | Individual customers | Legal entity customers |
|---|---|---|
| Name | Full legal name | Full legal name of the entity |
| Date of birth | Required | Not required for entities |
| Address | Residential or business street address | Principal place of business or local office |
| Identification number | U.S. persons: SSN or TIN; non-U.S. persons: passport number and country, alien ID, or other government-issued document number | Taxpayer Identification Number (EIN); for foreign entities, a government-issued document evidencing legal existence |
A few edge cases compliance officers encounter regularly:
Agents opening accounts on behalf of customers. The regulation requires you to verify the identity of the person opening the account, but your CIP should also address whether you verify the underlying customer on whose behalf the account is opened.
Non-legal persons (trusts, estates). The rule does not explicitly require CIP for these, but your risk-based procedures should address them, and examiners will ask.
Non-U.S. persons without a SSN. The Interagency CIP FAQs confirm that passport number and country of issuance, alien identification card number, or another government-issued document number with country of issuance are acceptable alternatives.
Pro Tip: If a customer cannot immediately provide an identification number, your CIP may allow account opening under a written agreement that the customer will provide the information within a reasonable period. Document the agreement, set a hard deadline in your system, and restrict account functionality until the number is received. Never leave the field open-ended.
How does BSA identity verification work in practice?
The regulation permits two verification approaches, and most institutions use both depending on the customer and the channel.

| Dimension | Documentary methods | Non-documentary methods |
|---|---|---|
| What it involves | Reviewing an unexpired, government-issued photo ID (driver’s license, passport, military ID) | Comparing customer-supplied PII against consumer reporting agencies, public records, or independent data sources |
| Common data sources | State DMV-issued IDs, U.S. passports, federal agency credentials | Credit bureaus, LexisNexis, Equifax, public records databases, digital credential providers |
| Strengths | Tangible, examiner-visible evidence; high assurance for in-person onboarding | Effective for remote/online onboarding; catches synthetic identity patterns documentary review misses |
| Typical use cases | Branch account opening, in-person business onboarding | Online account opening, mail-in applications, customers who cannot present physical documents |

For in-person onboarding, a government-issued photo ID is the baseline. When fraud risk is elevated, whether because of the customer’s profile, the account type, or prior suspicious patterns, the Interagency FAQs explicitly encourage obtaining more than one document. A passport plus a utility bill, or a driver’s license plus a secondary government-issued credential, raises the assurance level without requiring a full enhanced due diligence process.
Non-documentary methods, as the FFIEC manual describes, can include contacting the customer directly, checking consumer reporting agencies, cross-referencing public databases, or using third-party identity verification services. Electronic identity verification workflows typically collect customer-supplied PII and verify it against credit reference agencies and premium data providers, a process that supports Customer Due Diligence and reduces regulatory risk when applied in a risk-based manner.
Banks may also accept electronic credentials, such as digital certificates, for internet account openings, provided the institution ensures the third party’s authentication level meets the bank’s own standards.
- Documentary: retain a description of the document type, issuing authority, identification number, place of issuance, and expiration date. A photocopy is not required by regulation, but many institutions retain one.
- Non-documentary: document the specific source consulted, the data elements compared, the result, and the date of the check.
Pro Tip: Never describe a non-documentary check as simply “database verified.” Name the specific source (e.g., Equifax Identity Verification, LexisNexis Instant Authenticate), the data elements compared, and the outcome. Opaque descriptions are the single most common non-documentary documentation deficiency examiners cite.
When does enhanced verification apply, and what does it look like?
Risk triggers that require step-up verification are not exhaustive in the regulation, but examination practice has made several patterns predictable.
Common triggers include: non-face-to-face account opening (online, mobile, mail); politically exposed persons or their immediate family members; accounts with anticipated high-dollar or high-volume activity inconsistent with the customer’s profile; customers who are unable or unwilling to provide standard identifying information; and new digital channels where the institution has limited fraud history.
When a trigger is present, enhanced steps typically include requesting additional documents beyond the primary government-issued ID, applying multi-layer document verification (optical character recognition, metadata extraction, issuer cross-reference), requiring a liveness check to confirm the person presenting the document is physically present, cross-referencing the customer against sanctions lists and adverse media databases, and routing the application to manual review before account activation.
The operational note that matters most: enhanced verification does not mean verification of every data element. The FFIEC manual is clear that institutions need not verify every piece of identifying information, only enough to reach reasonable belief. What scales with risk is the intensity and the number of independent sources consulted, not a requirement to achieve certainty.
For non-face-to-face onboarding specifically, the NCUA Examiner’s Guide on CIP reinforces that institutions should have specific written procedures addressing the elevated risk of remote channels, not just a general statement that risk-based procedures apply.
What records must you keep, and what notice must you give customers?
Records to retain (minimum five years from the date the account is closed, or five years from the date the record is made for verification records):
- All identifying information collected at account opening (name, DOB, address, identification number).
- A description of any document relied on for verification, including document type, issuing authority, identification number, place of issuance, and expiration date.
- A description of the non-documentary methods used, the results of each check, and the resolution of any discrepancies.
- A description of the resolution of any substantive discrepancy discovered when verifying the identifying information.
Customer notice must be provided at or before account opening. The notice must state that the institution is requesting information to verify identity in accordance with federal law. It does not need to be lengthy. A brief disclosure on the account-opening form, the institution’s website, or a posted notice in the branch satisfies the requirement, provided it is visible and legible before the customer completes the application.
For audit preparation, structure your records so that a single account number pulls up the complete verification chain: fields collected, method used, source consulted, result, and any follow-up action. Examiners sampling new accounts expect to trace that chain in under five minutes. If your system requires navigating three separate screens to reconstruct a single verification decision, that friction will show up as an operational finding even when the underlying verification was sound.
Can you rely on another institution or a third-party vendor for CIP?
Yes, under specific conditions. The regulation permits a bank to rely on another federally regulated financial institution’s CIP, but the relying bank remains legally responsible for the adequacy of that program.
The conditions for permissible reliance are: the other institution is subject to an anti-money laundering program rule and is regulated by a federal functional regulator; the reliance is reasonable under the circumstances; and the other institution enters into a contract agreeing to certify annually that it has implemented an AML program and will perform the specified CIP procedures.
For third-party vendors performing CIP functions (identity verification platforms, document authentication services, database providers), the regulatory framework is different. The bank cannot formally “rely” on a vendor the way it can on another regulated institution. Instead, the bank remains fully responsible, and the vendor relationship must be governed by a robust vendor oversight program.
Vendor oversight controls that examiners expect to find:
Due diligence before onboarding. Review the vendor’s SOC 2 Type II report, data security practices, regulatory compliance history, and the specific methodology behind their verification decisions. Understand exactly which data sources they query and how they weight discrepancies.
SLA and performance metrics. Define acceptable match rates, false positive and false negative thresholds, and response times in the contract. Require the vendor to report against these metrics quarterly.
Audit rights and testing access. The contract should give the institution the right to audit the vendor’s processes and access test environments so internal audit can validate that the vendor’s outputs align with the institution’s CIP procedures.
Change management. Require advance notice of any material changes to the vendor’s methodology, data sources, or technology stack. A vendor that silently changes its matching algorithm can invalidate your documented verification procedures overnight.
Periodic validation. At least annually, run a sample of accounts through the vendor’s process and compare results against your internal standards. Document the validation and any corrective actions.
What happens when you cannot verify a customer’s identity?
This is the section of most CIP programs that is under-documented, and it is the first place an examiner looks when a SAR filing gap surfaces.
Numbered response steps when verification fails:
- Document all verification attempts. Record every method used, every source consulted, every discrepancy identified, and the date and outcome of each step.
- Restrict account functionality. Pending resolution, limit the account to low-risk activities or suspend access entirely, depending on the risk level and your written procedures.
- Set a resolution deadline. Give the customer a defined period to provide additional information. Document the deadline and the customer’s response or non-response.
- Escalate to compliance or risk management. If the deadline passes without resolution, escalate per your written escalation matrix. Do not leave the decision at the front-line level.
- Close the account if identity cannot be established. Your written CIP must specify the conditions under which the institution will decline to open or will close an existing account.
- Evaluate for SAR filing. If the circumstances suggest the customer was attempting to evade identification, or if the pattern is otherwise suspicious, evaluate whether a SAR is required. The FDIC guidance is explicit: a SAR must be filed when the institution cannot form a reasonable belief about a customer’s identity and the circumstances are suspicious.
Common examiner findings in this area:
- Written procedures that describe verification steps but are silent on what happens when those steps fail.
- No documented escalation path between front-line staff and compliance.
- SAR decisions made informally, with no written analysis in the file.
- Accounts left in a “pending verification” status indefinitely, with no system controls to force resolution.
The regulatory consequences of CIP failures range from examination criticisms and Matters Requiring Attention (MRAs) to formal enforcement actions, civil money penalties, and, in egregious cases, cease-and-desist orders. Documented attempts, a clear escalation trail, and timely SAR filings are the primary factors that distinguish a manageable examination finding from a formal enforcement action.
Your practical CIP implementation checklist
Map each item to an owner and a deadline before your next examination cycle.
- Policy update: Assign the BSA officer to review and update the written CIP against current 31 CFR 1020.220 requirements. Target: within 30 days of any product launch, channel change, or regulatory update.
- Account-opening system audit: Have operations confirm that all required fields (name, DOB, address, ID number) are mandatory and cannot be bypassed at account opening. Target: quarterly system check.
- Staff training: Deliver CIP-specific training (not just general BSA) to all staff who open accounts or handle customer identification. Document completion. Target: annually and upon onboarding new staff.
- Vendor contracts: Review all third-party CIP vendor contracts for audit rights, change notification clauses, and performance metrics. Target: annual contract review cycle.
- Testing schedule: Conduct transaction testing across a cross-section of new accounts, covering consumer, business, online, and branch channels. Examiners select samples across these dimensions, and your internal testing should mirror that approach.
- Examination prep: Maintain a CIP evidence binder (or digital equivalent) that includes the written program, training records, testing results, vendor oversight documentation, and a sample of verified accounts with their complete verification chains.
Sample test cases for internal testing:
- Individual consumer account opened online: confirm non-documentary method is documented with source and result.
- Business account opened in branch: confirm entity documents and controlling individual identification are both on file.
- Account where verification was delayed: confirm the delay was documented, a deadline was set, and resolution is recorded.
- Account where identity could not be verified: confirm escalation, account restriction, and SAR evaluation are all documented.
Pro Tip: Build a verification method field directly into your core banking system or CRM that logs the specific method, source, and result for every account. When an examiner asks to see the verification decision for account number 12345, you should be able to produce a complete audit artifact in under two minutes. If that retrieval takes longer, the system design is the problem, not the policy.
How do modern identity technologies fit into your CIP program?
Document verification alone is increasingly insufficient. AI-generated document fraud rose sharply in late 2025, and multi-layer verification combining OCR, metadata analysis, issuer cross-reference, and AI artifact detection is now the recommended standard for catching sophisticated forgeries.
The technologies compliance officers are integrating into CIP workflows:
Biometric verification and liveness detection confirm that the person presenting a document is physically present and matches the photo on the credential. These controls are particularly effective for non-face-to-face onboarding, where the risk of synthetic identity fraud and document substitution is highest. Fraud Signals News covers liveness detection and eKYC developments as they affect regulatory compliance.
Metadata analysis and issuer cross-reference examine the digital properties of a submitted document image, checking for editing artifacts, font inconsistencies, and template mismatches against known issuer formats. This layer catches forgeries that pass visual inspection.
AI artifact detection identifies patterns in document images that indicate synthetic generation or manipulation, including pixel-level anomalies that human reviewers cannot detect at scale.
The compliance caveat that applies to all of these: every technology-based decision must be auditable. If your vendor’s system returns a “pass” or “fail” without logging the specific checks performed and the data elements compared, you have a black-box compliance problem. The FFIEC’s non-documentary documentation standard applies equally to automated and manual checks.
DAON (DAON.com) is one vendor option that offers biometric and liveness-based identity verification capabilities designed for regulated financial institutions. As with any vendor, the institution must validate that DAON’s methodology aligns with its written CIP procedures, review the vendor’s audit documentation, and confirm that decision logs are accessible for examination purposes. Vendor selection in this space also benefits from reviewing identity verification alternatives to understand the range of capabilities and oversight requirements across the market.
For institutions operating in higher-risk onboarding environments, such as fully digital account opening or cross-border customer acquisition, the deepfake and synthetic media risks that Fraud Signals News tracks directly inform which verification layers are worth the operational investment.
Key Takeaways
BSA identity verification under the CIP requires a written, risk-based program that collects required customer fields, documents every verification method used, and maintains a complete audit trail an examiner can trace from account number to decision.
| Point | Details |
|---|---|
| Written CIP is mandatory | The program must be embedded in your BSA/AML framework, board-approved, and updated when products or channels change. |
| Four required fields at account opening | Name, date of birth, address, and identification number are the regulatory minimum for individual customers. |
| Document every verification method | Name the specific source, data elements compared, and outcome for both documentary and non-documentary checks. |
| Escalation path must be written | When identity cannot be verified, your procedures must specify account restriction, closure conditions, and SAR evaluation. |
| Examiners sample across channels | Internal testing should mirror examiner sampling: consumer, business, online, and branch accounts in every test cycle. |
Where CIP enforcement is actually heading
The conventional framing of CIP compliance treats it as a documentation exercise: collect the fields, check the box, file the record. That framing is obsolete, and enforcement patterns confirm it.
What examiners are increasingly focused on is not whether the fields were collected, but whether the verification decision was defensible at the moment it was made. That shift has real consequences. An institution that collected a driver’s license number but cannot show which database it cross-referenced, or what the result was, or who reviewed a discrepancy, is exposed even if no fraud occurred. The audit trail is the compliance product, not the ID itself.
The next 12 months will put particular pressure on three areas. Remote onboarding controls are the most urgent: as digital account opening becomes the default channel, non-documentary verification procedures that were written for occasional use are now handling the majority of volume, and most of them were not designed for that load. Vendor validation is the second pressure point. Institutions that deployed identity verification platforms quickly during the pandemic-era digital shift often did so without the contractual audit rights or performance benchmarks that examination guidance requires. Those gaps are surfacing in examinations now. The third is end-to-end audit trail integrity: the ability to reconstruct a complete verification decision, from the fields collected to the method used to the result logged, for any account, on demand.
Institutions that treat CIP as a banking and fintech compliance discipline rather than a one-time setup task will be better positioned when the next examination cycle arrives. The difference between a finding and a clean report is almost always documentation, not intent.
Useful sources
The following primary sources belong in your policy citations, board packets, and remediation plans.
-
31 CFR 1020.220 (eCFR): The operative CIP rule. Attach this to your written program as the primary regulatory authority. Every CIP policy should cite this section by number.
-
FFIEC BSA/AML Examination Manual — Customer Identification Program: The examination procedures examiners follow. Use this to structure your internal testing and to draft the “reasonable belief” language in your policy. This is the document your examiner has open during a CIP review.
-
FDIC Financial Institution Letter on CIP: Practical FDIC guidance on documentary and non-documentary methods, SAR obligations, and integration with AML programs. Best used in staff training materials and as a supplemental citation in remediation plans.
-
Interagency CIP FAQs (FDIC): Answers specific implementation questions: acceptable ID types, non-U.S. person alternatives, agent-opened accounts, and electronic credentials. Cite specific FAQ numbers when justifying procedural choices to examiners.
-
FinCEN Interagency Interpretive Guidance on CIP: The joint agency guidance that accompanied the final rule. Useful for understanding regulatory intent and for board-level explanations of why CIP requirements exist.
-
NCUA Examiner’s Guide — Customer/Member Identification Program: Credit union-specific examination procedures that mirror bank CIP requirements. Useful for credit union compliance officers and for understanding how examiners approach non-face-to-face account opening.
This article provides general regulatory information for educational purposes. Compliance officers should confirm current requirements directly against the primary regulatory sources cited above and consult qualified legal counsel for institution-specific guidance.
FAQ
What is BSA identity verification, and who must comply?
BSA identity verification refers to the Customer Identification Program required under 31 CFR 1020.220, which mandates that banks and other covered financial institutions collect and verify identifying information for every customer before opening an account. Banks, savings associations, credit unions, and certain broker-dealers are among the covered institutions.
Why does a bank need to verify your identity?
Federal law requires banks to form a reasonable belief in a customer’s true identity to prevent money laundering, terrorist financing, and other financial crimes. The CIP rule under the USA PATRIOT Act Section 326 is the direct legal basis for that requirement.
Who needs to file a BSA report?
Financial institutions covered by the Bank Secrecy Act, including banks, credit unions, and money services businesses, must file Suspicious Activity Reports (SARs) and Currency Transaction Reports (CTRs) as required. A SAR is specifically required when an institution cannot form a reasonable belief about a customer’s identity and the circumstances are suspicious.
What is the $3,000 rule for banks?
The rule requires banks to collect and retain records on funds transfers and transmittals above a specified threshold, including the name and address of the originator and beneficiary. This is a separate BSA recordkeeping requirement from CIP, though both fall under the broader BSA/AML compliance framework.
What is the purpose of identity verification under the CIP?
The purpose is to ensure that financial institutions know who their customers are, reducing the risk that accounts are used for money laundering, fraud, or terrorist financing. Effective CIP also protects the institution from regulatory penalties and reputational harm associated with facilitating financial crime.


