TL;DR: A Customer Identification Program (CIP) is the written process U.S. banks use to collect identifying information and verify identity when a customer opens an account. Under 31 CFR 1020.220, the bank must form a reasonable belief that it knows the customer's true identity. CIP is the identity step at account opening — not ongoing CDD, beneficial ownership, or EDD.
What CIP Actually Requires

A Customer Identification Program is the identity-collection and verification program a bank must run at account opening. Section 326 of the USA PATRIOT Act directed Treasury to set minimum standards; FinCEN implemented them for banks in 31 CFR 1020.220. The FFIEC BSA/AML Examination Manual tells examiners how to test them. The CIP must sit inside the bank's BSA/AML program — one of the five pillars of an AML program — and the board must approve that program.
The legal test is specific. Procedures must be risk-based and must enable the bank to form a reasonable belief that it knows the true identity of each customer, to the extent reasonable and practicable. A branch-only community bank and a digital bank are not expected to run identical stacks. Both must document why their stack produces that belief, given products, opening channels, available identifying information, size, location, and customer base.
A customer, for CIP, is a person who opens a new account — or an individual who opens one for someone who lacks legal capacity or for an entity that is not a legal person. An account means a formal banking relationship (deposit, credit, safekeeping, cash management, custody, or trust). Check-cashing, a one-off wire, merger-acquired accounts, ERISA plan accounts, and denied loan applications sit outside the rule.
Before opening, the bank must collect four elements: name; date of birth for an individual; address (street address for an individual, or a physical location for an entity); and an identification number — a TIN for a U.S. person, or for a non-U.S. person a TIN, passport, alien ID, or other qualifying government-issued document. Collection and verification are not the same step. The four elements come in before opening. Verification, using that information, may occur within a reasonable time after opening. The written CIP must say when the bank uses documents, non-documentary methods, or both.
Documentary verification for individuals typically means an unexpired government-issued ID with a photograph or similar safeguard. For entities, documents showing existence — articles of incorporation, a business license, a partnership agreement, or a trust instrument. Identity document verification at onboarding is how most banks operationalize that path, including remote capture. Non-documentary methods include contacting the customer, matching data to a consumer reporting agency or public database, checking references with other financial institutions, and obtaining a financial statement. Those procedures must cover remote opening, missing photo ID, and unfamiliar documents.
When the customer is not an individual and both methods still fail, the CIP must address additional verification of individuals with authority or control over the account, including signatories. That check is a CIP identity tool, not a substitute for UBO identification under the CDD rule. The CIP must also state what happens when a reasonable belief never forms: when not to open, limited use while verification continues, when to close after failure, and when to file a SAR. Identifying information is retained for five years after the account closes (credit cards: five years after close or dormancy). Method descriptions and discrepancy resolutions are retained for five years after the record is made. The program must compare the customer against designated federal terrorist lists within a reasonable period after opening, and give customers notice that identity information is being requested.
Why CIP Still Breaks at Scale
CIP looks simple on a checklist: four fields, a document or a database match, a notice, a five-year file. The operational failure is treating that checklist as the whole of "know your customer" while risk rating, beneficial ownership, and purpose of the relationship live in a different system with a different owner.
Remote opening made that split expensive. Non-documentary CIP often leans on credit-header matching. The CFPB's Office of Research has reported that over 10% of U.S. consumers are not reported at a credit bureau, so thin-file and new-to-country applicants fail a bureau-only path even with a genuine government ID. Document-only remote CIP has the opposite problem: a captured image is not a reasonable belief. Deepfake selfies and synthetic IDs sit at the CIP–fraud seam. The rule already requires the bank to consider indications of fraud when deciding whether it knows the customer's true identity.
Cost pressure makes the seam worse. A LexisNexis Risk Solutions study conducted by Forrester Consulting put financial crime compliance costs in the United States and Canada at $61 billion, with 99% of surveyed institutions reporting increases and 79% reporting higher KYC software costs. CIP is a small slice on paper. In practice it is the gate every other onboarding control waits on, so delays compound into CDD backlogs.
Identity failure also feeds reporting. CIP tells the bank when unsuccessful verification should produce a SAR. According to FinCEN figures compiled by Forvis Mazars, banks, savings associations, and credit unions filed more than 2.193 million SARs in 2025, up 7.66% from 2024. CIP is not the source of that volume. It is one of the first places a bank either documents a defensible identity decision or creates a file that cannot explain who opened the account.
Two recent changes show the rule catching up to how accounts actually open. In June 2025, FinCEN, with the OCC, FDIC, and NCUA, issued an optional exemption that lets banks obtain TIN information from a third party rather than collecting the full TIN from the customer — provided written CIP procedures still get the TIN before opening and still produce a reasonable belief of true identity. The Federal Reserve joined that order on July 31, 2025. In 2026, the agencies confirmed that an unexpired government-issued verifiable digital credential, such as a state mobile driver's license, can qualify as documentary identification if the bank can extract the data and the credential meets the photograph-or-similar-safeguard test. Non-government electronic credentials remain a non-documentary method.
CIP vs CDD vs EDD
CIP answers who is opening this account. CDD answers what the relationship is, who owns the legal entity, and how the bank will keep that picture current. EDD answers what extra evidence is required because the relationship is higher risk. Mixing the three is how programs fail exams even when the four CIP fields are complete.
Customer due diligence requirements for banks pick up after identity is established. Completing CIP on the person who signed the signature card does not identify the 25% owners behind a holding company. KYB still needs entity existence, control persons, and ownership — covered in a complete guide to KYB — on top of CIP as the rule defines the customer.
Enhanced due diligence is the high-risk layer, not a heavier CIP. A PEP may still sail through name, date of birth, address, and TIN verification. EDD then demands source of wealth, ownership tracing, and senior approval. Using EDD as a catch-all for failed CIP hides an identity-control failure inside a high-risk label.
Reliance on another financial institution is allowed only inside CIP, and only if the reliance is reasonable, the other institution is subject to a 31 U.S.C. 5318(h) program and a federal functional regulator, and a contract requires annual certification that it will perform the specified CIP procedures. Bank-fintech partnerships that treat the partner's onboarding screen as "CIP done" without that contract are not relying. They are outsourcing without the rule's safe harbor.
What a Defensible CIP Looks Like
A program that survives an exam is written at the level of account type and channel, not as a restatement of the regulation.
Minor, isolated CIP misses are not automatically an inadequate program. Patterned misses — digital channels with no non-documentary procedures, TIN exemptions used without a procedure update, unresolved identity discrepancies — are.
Where Sphinx Fits
Sphinx automates investigation and documentation around CIP exceptions and the CDD handoff — assembling evidence for the reasonable-belief decision and the audit trail examiners sample. Straightforward matches can clear with a complete file. Failures, source conflicts, and CIP–fraud cases route to a human with the record already built.
Frequently Asked Questions
What information must a bank collect under CIP?
Name, date of birth for an individual, address, and identification number, collected before the account opens. For a U.S. person the number is a TIN; for a non-U.S. person, a TIN, passport, alien ID, or another qualifying government-issued document. Verification then occurs within a reasonable time after opening, using documents, non-documentary methods, or both.
How is CIP different from CDD?
CIP is the identity program at account opening under 31 CFR 1020.220. CDD covers the nature and purpose of the relationship, beneficial owners of legal entity customers, risk rating, and ongoing monitoring. Completing CIP does not complete CDD, and later monitoring does not retroactively satisfy CIP if identity was never verified at opening.
Can a bank open the account before identity is verified?
Yes. The four identifying elements must be obtained before opening. Verification may occur within a reasonable time after opening. The CIP must define limited-use terms during that window, and must say when to close the account and when to file a SAR if a reasonable belief of true identity never forms.
How long must CIP records be kept?
Identifying information must be retained for five years after the account is closed, or five years after a credit card account is closed or becomes dormant. Descriptions of documents, non-documentary methods and results, and discrepancy resolutions must be retained for five years after the record is made.
Can a bank collect a TIN from a third party instead of the customer?
Optionally, for banks under OCC, FDIC, NCUA, and Federal Reserve jurisdiction, per the June–July 2025 FinCEN and agency orders. The bank must still obtain TIN information before opening through written risk-based CIP procedures, and must still form a reasonable belief of true identity. The exemption does not automatically cover non-bank financial institutions.

.png)