Customer Identification and Verification (ID&V)
Customer Identification and Verification (ID&V) is the process a business uses to confirm that a customer is who they claim to be. It typically involves first collecting identifying details about an individual or entity (identification) and then checking those details against reliable evidence such as documents or data (verification). ID&V is commonly used in the financial and telecommunications sectors and forms a foundational part of a firm's customer onboarding and compliance controls.
ID&V refers to the paired operational steps of identifying a customer, by obtaining identifying information about an individual or legal entity, and verifying that identity against reliable and independent evidence to establish that the customer is legitimate and accurately represented. In an AML context, ID&V generally sits within the broader Customer Due Diligence (CDD) process and supports Know Your Customer (KYC) obligations; it is a distinct but related concept, as CDD and KYC extend beyond identity confirmation to matters such as understanding the purpose of the relationship, beneficial ownership, and ongoing monitoring. In the United States, the identity-confirmation function is operationalized through a Customer Identification Program (CIP) under the USA PATRIOT Act, though the specific documents, data sources, and thresholds applied to ID&V vary by jurisdiction, obliged-entity type, and applicable regulation and should be confirmed against the relevant regime. ID&V is a risk-mitigation control intended to help firms deter and detect impersonation and identity-related risk; it does not by itself guarantee that a customer is not involved in financial crime.
Why it matters
Customer Identification and Verification is the entry point to nearly every regulated financial relationship, which makes it a foundational control within a firm's broader Customer Due Diligence framework. If a firm cannot reliably confirm that a customer is who they claim to be, subsequent controls, including sanctions and PEP screening, transaction monitoring, and beneficial ownership analysis, rest on an unstable footing. ID&V is therefore commonly treated as a prerequisite to onboarding across the financial and telecommunications sectors, and in many jurisdictions it is embedded in specific legal obligations rather than left to firm discretion.
Because ID&V is designed primarily to deter and detect impersonation and identity-related risk, it plays a distinct role from other elements of KYC and CDD that focus on the purpose of a relationship or the source of funds. Firms that treat ID&V as a mere formality risk admitting customers whose stated identity does not correspond to reliable evidence, which can expose the firm to fraud, regulatory criticism, and reputational harm. In the United States, the identity-confirmation function is operationalized through a Customer Identification Program (CIP) under the USA PATRIOT Act, illustrating how a conceptual control can be given concrete legal form; the specific requirements, however, vary by jurisdiction and obliged-entity type.
It is important to keep the limits of ID&V in view. Successfully confirming that a customer is who they claim to be does not establish that the customer is free of financial crime risk, nor does it substitute for ongoing monitoring or wider due diligence. ID&V is one risk-mitigation measure among several, and its value depends on how well it integrates with the rest of a firm's compliance controls rather than on identity confirmation alone.
Who it's relevant to
Inside ID&V
Common questions
Answers to the questions practitioners most commonly ask about ID&V.