Bank Customer Identification Program: The Compliance Officer’s Exam-Ready Guide

Hands verifying identity documents on desk
11

Aug

Bank Customer Identification Program: The Compliance Officer’s Exam-Ready Guide

A bank customer identification program (CIP) is a written, board-approved, risk-based set of procedures that requires a bank to collect minimum identifying information, verify customer identity through documentary or non-documentary means, retain records for five years after account closure, and screen against government lists, as mandated by Section 326 of the USA PATRIOT Act and implemented through 31 C.F.R. §1020.220.

The minimum elements examiners expect to find documented in every CIP:

  • Written, board-approved policy integrated into the bank’s BSA/AML compliance program
  • Required customer identifying information collected at account opening (name, date of birth for individuals, address, and taxpayer identification number)
  • Verification procedures covering both documentary and non-documentary methods
  • Recordkeeping and retention rules specifying what to keep and for how long (five years)
  • Government list screening procedures and timing requirements
  • Customer notice language and delivery method
  • Reliance provisions if the bank delegates CIP performance to another financial institution

Key Takeaways

A bank’s CIP must be written, board-approved, risk-based, and integrated into the BSA/AML program, with five-year retention of identifying information after account closure and five-year retention of verification records from the date they are made.

Point Details
Board approval is non-negotiable Document CIP approval in board minutes with the policy text attached, naming the compliance officer.
Five-year retention has two clocks Identifying information: five years after account closure. Verification records: five years from the date the record is made.
Non-documentary verification requires documented rationale Record the specific reason codes and evidence that produced a “reasonable belief” of identity for every non-documentary decision.
Reliance arrangements require written agreements Annual certification from the performing institution and a due diligence file on its CIP performance are examiner requirements.
Vendor technology must be independently validated Bias testing, false match rates, and audit log retention must be documented before deploying eKYC or biometric tools in a CIP workflow.

Table of Contents

What is the regulatory basis for a bank’s CIP requirement?

Section 326 of the USA PATRIOT Act directed the Secretary of the Treasury, jointly with federal banking regulators, to prescribe minimum standards for financial institutions to verify customer identity. The implementing regulation is 31 C.F.R. §1020.220, which replaced the earlier codification at 31 C.F.R. §103.121. Both citations appear in examiner workpapers, so your board materials and audit responses should reference §1020.220 as the operative text while acknowledging §103.121 as the predecessor.

The principal federal regulators and guidance documents examiners draw on:

  • FinCEN (Financial Crimes Enforcement Network, U.S. Department of the Treasury): issues the implementing rules and interpretive FAQs on the Final CIP Rule
  • FDIC: publishes the Risk Management Manual of Examination Policies, Section 8.1, which is the primary examiner reference for state non-member banks
  • Federal Reserve: issues supervisory letters, including SR 08-8, governing compliance risk management at large, complex organizations
  • OCC: applies CIP rules to national banks through its BSA/AML examination procedures
  • NCUA: applies equivalent standards to federally insured credit unions
  • FFIEC BSA/AML Examination Manual: the cross-agency reference that all examiners use when assessing CIP compliance

When you reference these sources in board materials or audit responses, cite the specific section and date of the guidance, not just the agency name. Examiners respond well to precision; a citation that reads “31 C.F.R. §1020.220(a)(1)” carries more weight than “applicable FinCEN regulations.”


What must your written CIP policy actually contain?

The regulation is specific about what must appear in writing. Compliance officers who treat the CIP as a summary paragraph in the BSA/AML policy manual routinely fail exams because examiners cannot find the required elements documented at the granular level the rule demands.

Program governance

The CIP must be part of the bank’s BSA/AML compliance program, which itself must be approved by the board of directors. That approval must be documented in board minutes. The program must designate a BSA/AML compliance officer, provide for ongoing employee training, and include independent testing of CIP controls. The FDIC’s examination guidance treats the absence of any one of these four elements as a program deficiency, not a minor gap.

Minimum customer identifying information

At account opening, the bank must collect:

  • Full legal name
  • Date of birth (for individuals)
  • Address (residential street address for individuals; principal place of business or local office for entities; for U.S. military personnel, an APO/FPO address is acceptable)
  • Taxpayer identification number (TIN): Social Security Number for U.S. persons; EIN, ITIN, or a foreign equivalent for non-U.S. persons

The FinCEN FAQs clarify several application questions compliance teams frequently get wrong. An existing customer opening a new account type does not automatically require re-collection of all fields if the bank has a reasonable belief it already has current, verified information. Credit card accounts issued through a third-party retailer arrangement may be treated differently under the rule, but the bank remains responsible for ensuring CIP is performed.

Policy text elements and timing

Policy Element What the Written Policy Must Address
Account opening timing When information is collected (at or before account opening) and any permissible exceptions
TIN exception Procedures for customers who have applied for but not yet received a TIN
Legal entity accounts Additional fields required for entities (formation documents, beneficial ownership linkage)
Existing customers Criteria for when re-verification is required vs. when prior records suffice
Exceptions log Process for documenting and escalating any deviation from standard collection procedures

A sample board-approval clause: “This Customer Identification Program, adopted pursuant to 31 C.F.R. §1020.220 and Section 326 of the USA PATRIOT Act, is hereby approved by the Board of Directors of [Bank Name] and incorporated into the Bank’s BSA/AML Compliance Program, effective [date].” That language, in the board minutes, satisfies the approval requirement examiners look for on day one of a BSA exam.


How should you verify customer identity: documentary vs. non-documentary methods?

Verification is where most CIP deficiencies originate. The rule permits banks to use documentary methods, non-documentary methods, or a combination, but it requires the bank to document why the chosen approach produced a “reasonable belief” that it knows the true identity of the customer. That documentation requirement is where weak programs fail.

Documentary verification

Documentary verification relies on an unexpired government-issued photo ID or, for entities, formation documents. Acceptable documents for individuals typically include:

  • U.S. driver’s license or state ID card
  • U.S. passport or passport card
  • Military ID
  • Permanent resident card (Green Card)

For legal entities: articles of incorporation or organization, partnership agreements, or trust instruments. The bank must record the type of document, the issuing authority, the identification number, and the expiration date.

Non-documentary verification

Non-documentary methods are required or appropriate when a customer cannot produce documents, when documents appear altered, or when the account is opened remotely. Acceptable non-documentary methods include:

  1. Contacting the customer directly by phone or email to confirm information
  2. Checking consumer reporting agency files (e.g., credit header data)
  3. Comparing information against public databases or government records
  4. Obtaining a financial reference from another institution
  5. Analyzing account activity for consistency with the stated customer profile

Risk factors that push a bank toward requiring stronger verification include: non-resident alien status, complex or multi-layered legal entity structures, remote or digital-only onboarding channels, and indicators of synthetic identity such as recently issued SSNs with thin credit files. For a deeper look at how false identity bank accounts exploit verification gaps, the patterns are instructive for calibrating your exception thresholds.

Pro Tip: Document the rationale for every non-documentary verification decision in a structured field within your onboarding system, not just a free-text note. Examiners want to see that the bank applied a consistent standard, not that individual underwriters made ad hoc calls. A structured reason code tied to a policy category is far more defensible than “customer could not produce ID.”

For online account opening, the workflow should log device telemetry, IP geolocation, email and phone verification steps, and any manual-review triggers before a decision is recorded. That log is your evidence trail if an examiner asks how the bank formed a reasonable belief of identity for a customer it never met in person. The FinCEN guidance on risk-based CIP tailoring explicitly supports combining methods when no single approach is sufficient.


What are the recordkeeping and retention requirements?

The five-year retention rule has two distinct clocks, and conflating them is a common compliance error.

  • Identifying information collected (name, DOB, address, TIN): retained for five years after the date the account is closed
  • Verification records (description of documents reviewed, results of non-documentary methods, resolution of discrepancies): retained for five years after the record is made

That second clock means a verification record created at account opening must be kept for five years from that creation date, regardless of when the account closes. If the account remains open for ten years, the verification record from year one may have already aged out of its retention window while the account is still active. Your records management policy must address this explicitly.

The record itself must contain:

  • All identifying information collected (the four minimum fields)
  • A description of any document relied on, including type, issuing authority, ID number, and expiration date
  • A description of the non-documentary methods used and the results
  • A description of how any discrepancy in the information was resolved

Retention anchor: The FFIEC BSA/AML Examination Manual references these retention timelines when examiners test CIP compliance. Having an indexed, searchable record system that can produce a complete CIP file for any account within 24 hours is the operational standard examiners expect at larger institutions.

For practical file organization, tag each CIP record with the account number, customer TIN, account open date, account close date (when applicable), and the verification method used. An index that allows retrieval by any of those fields cuts exam response time significantly and signals to examiners that the program is operationally mature.


What happens when you cannot verify a customer’s identity?

The CIP rule does not require banks to verify identity with certainty. It requires a “reasonable belief.” But when that standard cannot be met, the bank must have written procedures for what happens next.

  1. Refuse to open the account. If the bank cannot form a reasonable belief of identity before account opening, the default position is to decline. This is the cleanest outcome from a compliance standpoint.
  2. Open with restrictions. The rule permits a bank to open an account while verification is pending, provided the bank has procedures that restrict the account’s activity until verification is complete. This is appropriate for customers who have applied for a TIN but not yet received one.
  3. Close the account. If verification attempts fail after account opening, the bank must close the account and document the reason.
  4. File a Suspicious Activity Report (SAR). Failed verification alone does not automatically trigger a SAR obligation, but it is a material factor. If the failure is accompanied by indicators of fraud, such as inconsistent information, altered documents, or behavior consistent with synthetic identity fraud, the bank must evaluate whether a SAR is warranted under 31 C.F.R. §1020.320.

The decision flow should be documented in the CIP policy itself, not left to individual judgment. A written escalation matrix that maps verification outcomes to operational actions and SAR evaluation triggers is what examiners want to see. Key triggers that should prompt SAR evaluation:

  • Customer provides multiple conflicting identification documents
  • TIN does not match IRS records and customer cannot explain the discrepancy
  • Address provided is a known mail drop or commercial receiving agent with no other corroborating information
  • Device or behavioral signals during digital onboarding are inconsistent with stated identity

Understanding the full scope of financial identity theft helps compliance teams calibrate which verification failures represent genuine fraud risk versus administrative error.


Who is exempt from CIP, and when can you rely on another institution?

Exemptions

The regulation grants the federal banking agencies authority to exempt certain accounts or customers from CIP requirements when the risk of money laundering or terrorist financing is low. Exemptions are narrow and must be formally granted; a bank cannot self-exempt. Common categories that receive different treatment include:

  • Accounts opened for certain government entities
  • Accounts for publicly traded companies listed on U.S. exchanges (where identity is verifiable through SEC filings)
  • Accounts opened through intermediaries subject to their own CIP obligations

Even where an exemption applies, the bank should document the basis for the exemption in the account record.

Reliance on another financial institution

A bank may rely on another federally regulated financial institution, including an affiliate, to perform CIP functions, provided:

  • The other institution is subject to an anti-money laundering program under the Bank Secrecy Act
  • The other institution has agreed in writing to certify annually that it has implemented an AML program and will perform the specified CIP procedures
  • The relying bank retains responsibility for CIP compliance and cannot outsource that accountability

The regulatory text at 31 C.F.R. §1020.220 is explicit: reliance does not transfer legal responsibility. An examiner will expect to see the written agreement, evidence that the relying bank reviewed the other institution’s CIP performance, and documentation that the customer was also a customer of the other institution at the time of reliance.

A sample reliance clause for vendor or affiliate contracts: “[Institution Name] certifies that it has implemented an anti-money laundering program consistent with 31 U.S.C. §5318(h) and agrees to perform the following CIP procedures on behalf of [Relying Bank]: [list specific procedures]. [Institution Name] will provide annual certification of compliance upon request.”

Examiners will also want to see the relying bank’s due diligence file on the other institution, including any periodic reviews of that institution’s CIP performance.


How do you tailor a CIP to your institution and satisfy examiners?

A CIP written for a $500 million community bank with a single branch and a predominantly local customer base should look materially different from one written for a $200 billion institution with digital-only account opening, international wire capabilities, and a complex legal-entity customer base. The Federal Reserve’s SR 08-8 makes clear that larger, more complex organizations need firmwide compliance oversight and a documented compliance risk management program tied to board oversight and resource allocation. Smaller institutions may adopt simpler governance structures, but the reasonableness of every choice must still be documented.

Risk-based tailoring framework

Tailor your CIP across five dimensions:

  • Product risk: higher-risk products (private banking, correspondent accounts, digital wallets) require more rigorous verification
  • Delivery channel risk: remote/digital onboarding carries higher synthetic identity and fraud risk than in-person account opening
  • Geographic risk: customers from higher-risk jurisdictions or states with elevated fraud rates warrant enhanced procedures
  • Customer base: a predominantly retail consumer base differs from a commercial or institutional customer base in verification complexity
  • Legal entity complexity: shell companies, trusts, and multi-layered ownership structures require additional documentation beyond the four minimum fields

Examiner governance checklist

Governance Element Examiner Expectation
Board approval Documented in board minutes with policy attached
Compliance officer Named individual with defined CIP oversight responsibilities
Training Annual at minimum; documented completion records by employee
Independent testing Conducted by internal audit or qualified third party; findings reported to board
Verification rate metrics Percentage of accounts verified by method (documentary vs. non-documentary)
Exception rate Percentage of accounts opened with pending or failed verification; trend over time
Time-to-verify Average days from account opening to verification completion for exceptions

Common examiner findings include: CIP policy not updated to reflect new products or delivery channels, verification records missing the required description of documents reviewed, no documented escalation path for failed verifications, and reliance arrangements lacking annual certifications. Each of these is remediable, but remediating them after an exam finding is far more costly than building them into the program proactively. The FDIC examination guidance treats program governance gaps as indicators of systemic BSA/AML weakness, not isolated procedural errors.


How do you evaluate eKYC, biometrics, and advanced identity vendors within your CIP?

Modern identity verification vendors offer document authentication, facial biometrics, liveness detection, and ML-based identity resolution. These tools can materially strengthen a risk-based CIP, but they introduce their own compliance obligations: model validation, bias testing, explainability, and audit log requirements that examiners increasingly expect to see documented.

The evaluation matrix below reflects the dimensions a compliance team must assess before deploying any eKYC or biometric vendor:

Evaluation Dimension What to Assess Documentation Required
Data coverage Geographic and document-type coverage relevant to your customer base Vendor coverage report; gap analysis
False match / false non-match rates Error rates by demographic group Vendor test results; independent validation
Bias testing Differential performance across race, age, and gender Third-party bias audit or vendor attestation
Explainability Reason codes for adverse decisions; manual review triggers Decision log samples; reason code taxonomy
Privacy and data retention How long biometric data is stored; deletion rights Vendor DPA; data flow diagram
Audit logs Immutable record of each verification decision and its inputs Sample log export; retention period confirmation
Vendor SLA Uptime, accuracy guarantees, and remediation timelines Executed SLA with performance benchmarks

DAON (daon.com) is one vendor worth evaluating in this space, with capabilities spanning biometric authentication, liveness detection, and identity proofing that align with the documentation and audit-log requirements examiners expect.

Vendor marketing claims about AI accuracy require independent validation before you rely on them in a CIP context. A vendor asserting high match accuracy across all demographics is making a claim your compliance team must verify through documented testing against your own customer population, not just the vendor’s benchmark dataset. The identity proofing techniques that hold up under exam scrutiny are those with documented performance metrics, not those with the most compelling sales presentation.

Pro Tip: Demand that every eKYC or biometric vendor contract include: (1) a right to audit the vendor’s model performance data, (2) a requirement to notify the bank within 30 days of any material change to the underlying model, and (3) a minimum retention period for decision logs that matches your CIP retention obligations. Vendors who resist these clauses are telling you something important about their auditability posture.

For compliance teams tracking how biometrics reduce bank fraud in practice, the performance gap between well-validated biometric tools and legacy knowledge-based authentication is substantial. But the compliance value of biometrics depends entirely on how well the bank documents the validation, not just on the technology itself.


CIP is active risk management, not a one-time policy exercise

The compliance community has spent years treating the CIP as a document to be approved once and revisited only when regulators force the issue. That posture is no longer defensible. Synthetic identity fraud, which combines real and fabricated information to create identities that pass standard verification checks, has exposed the limits of static, document-centric CIP designs. Digital onboarding channels have accelerated the problem: a fraudster operating at scale can probe a bank’s verification logic repeatedly, identify the thresholds that trigger manual review, and calibrate submissions to stay below them.

A CIP that was adequate in 2020 may be structurally inadequate today, not because the regulation changed, but because the threat environment did. Compliance officers who treat the annual policy review as a formatting exercise rather than a substantive risk assessment are leaving their institutions exposed. The outdated fraud prevention failures documented across the industry share a common thread: programs that were technically compliant on paper but operationally blind to how fraud actually enters through the front door.

The practical response is a quarterly cross-functional review that brings together BSA/AML compliance, fraud operations, technology, and product teams to assess verification gap data, exception rates, and emerging threat patterns. That forum should have a standing agenda item for CIP policy updates and a documented output that goes to the compliance officer and, annually, to the board. Fraud Signals News covers the evolving identity verification threat environment specifically to support that kind of ongoing, evidence-based program review.


Sources

The sources below are the primary references examiners cite when testing CIP compliance. Keeping them bookmarked and referenced by section in your board materials signals program maturity.

When referencing these sources in board materials, cite the specific section and the date of the version you relied on. A citation that reads “FFIEC BSA/AML Manual, CIP Core Overview, accessed [date]” is more useful to an examiner than a generic reference to “FFIEC guidance.”


This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

FAQ

Who is required to have a CIP?

Banks, savings associations, credit unions, and other financial institutions subject to the Bank Secrecy Act must maintain a CIP under 31 C.F.R. §1020.220, implementing Section 326 of the USA PATRIOT Act.

Who is exempt from CIP requirements?

Exemptions are narrow and must be granted by the applicable federal banking agency; banks cannot self-exempt. Certain government entity accounts and accounts for publicly traded U.S. companies may receive different treatment, but the bank must document the basis for any exemption.

What is the difference between CDD and CIP?

CIP covers the minimum identity verification steps required at account opening. Customer due diligence (CDD) is a broader, ongoing obligation that includes understanding the nature and purpose of the customer relationship and monitoring for suspicious activity, governed separately under federal AML regulations.

How long do banks keep CIP information?

Identifying information collected at account opening must be retained for five years after the account closes. Verification records (documents reviewed, non-documentary methods used, discrepancy resolutions) must be retained for five years from the date the record is made, per 31 C.F.R. §1020.220.

Can a bank open an account before verifying a customer’s identity?

A bank may open an account before verification is complete if its CIP includes procedures for doing so, but it must restrict account activity and complete verification within a reasonable time. If verification ultimately fails, the bank must close the account and evaluate whether a SAR filing is warranted.

Share this post

RELATED

Posts