Skip to main content
Category: Customer Due Diligence

Customer Identification and Verification (ID&V)

Also known as: ID&V, Identification and Verification, Identity Verification, Customer Identity Verification
Simply put

Customer Identification and Verification (ID&V) is the process a business uses to confirm that a customer is who they claim to be. It typically involves first collecting identifying details about an individual or entity (identification) and then checking those details against reliable evidence such as documents or data (verification). ID&V is commonly used in the financial and telecommunications sectors and forms a foundational part of a firm's customer onboarding and compliance controls.

Formal definition

ID&V refers to the paired operational steps of identifying a customer, by obtaining identifying information about an individual or legal entity, and verifying that identity against reliable and independent evidence to establish that the customer is legitimate and accurately represented. In an AML context, ID&V generally sits within the broader Customer Due Diligence (CDD) process and supports Know Your Customer (KYC) obligations; it is a distinct but related concept, as CDD and KYC extend beyond identity confirmation to matters such as understanding the purpose of the relationship, beneficial ownership, and ongoing monitoring. In the United States, the identity-confirmation function is operationalized through a Customer Identification Program (CIP) under the USA PATRIOT Act, though the specific documents, data sources, and thresholds applied to ID&V vary by jurisdiction, obliged-entity type, and applicable regulation and should be confirmed against the relevant regime. ID&V is a risk-mitigation control intended to help firms deter and detect impersonation and identity-related risk; it does not by itself guarantee that a customer is not involved in financial crime.

Why it matters

Customer Identification and Verification is the entry point to nearly every regulated financial relationship, which makes it a foundational control within a firm's broader Customer Due Diligence framework. If a firm cannot reliably confirm that a customer is who they claim to be, subsequent controls, including sanctions and PEP screening, transaction monitoring, and beneficial ownership analysis, rest on an unstable footing. ID&V is therefore commonly treated as a prerequisite to onboarding across the financial and telecommunications sectors, and in many jurisdictions it is embedded in specific legal obligations rather than left to firm discretion.

Because ID&V is designed primarily to deter and detect impersonation and identity-related risk, it plays a distinct role from other elements of KYC and CDD that focus on the purpose of a relationship or the source of funds. Firms that treat ID&V as a mere formality risk admitting customers whose stated identity does not correspond to reliable evidence, which can expose the firm to fraud, regulatory criticism, and reputational harm. In the United States, the identity-confirmation function is operationalized through a Customer Identification Program (CIP) under the USA PATRIOT Act, illustrating how a conceptual control can be given concrete legal form; the specific requirements, however, vary by jurisdiction and obliged-entity type.

It is important to keep the limits of ID&V in view. Successfully confirming that a customer is who they claim to be does not establish that the customer is free of financial crime risk, nor does it substitute for ongoing monitoring or wider due diligence. ID&V is one risk-mitigation measure among several, and its value depends on how well it integrates with the rest of a firm's compliance controls rather than on identity confirmation alone.

Who it's relevant to

Compliance and onboarding teams
Teams responsible for customer onboarding rely on ID&V as a foundational step before a relationship is established. They design and operate the identification and verification workflow, ensuring that identifying information is collected and checked against reliable evidence in line with the applicable regime, and that ID&V is integrated with the wider CDD and KYC process rather than treated in isolation.
Financial institutions and other obliged entities
Banks and other firms subject to AML obligations use ID&V as a core control, which in the United States is operationalized through a Customer Identification Program under the USA PATRIOT Act. Because specific documents, data sources, and thresholds vary by jurisdiction and obliged-entity type, these firms must map their ID&V procedures to the regime that applies to them.
Telecommunications providers
ID&V is used primarily in the financial and telecommunications sectors, and telecom providers apply identification and verification to confirm a customer's identity at onboarding as part of their compliance and security controls. The specific requirements depend on the applicable regulation in the relevant jurisdiction.
Fraud and identity risk analysts
Analysts focused on impersonation and identity-related risk use ID&V outputs to help detect and deter customers who are not who they claim to be. They should treat successful verification as a risk-mitigation measure rather than a guarantee, since confirming identity does not by itself establish that a customer is free of financial crime risk.

Inside ID&V

Identification
The process of obtaining identifying information about a customer, such as name, date of birth, residential address, and, for legal entities, registration details and legal form. Identification is the collection of the customer's claimed identity, distinct from the subsequent step of verifying it.
Verification
The process of confirming that the identifying information obtained is accurate and that the customer is who they claim to be, typically using reliable, independent source documents, data, or information. Verification tests the identity that identification captured.
Reliable and independent source data
The evidentiary basis for verification, which may include government-issued documents (such as passports or national ID cards), registry data, or electronic verification against trusted databases. What qualifies as reliable and independent typically depends on the applicable regime and the entity's risk-based approach.
Relationship to CDD
ID&V is generally a foundational component of Customer Due Diligence (CDD) rather than a synonym for it. CDD is broader and typically also encompasses understanding the purpose and intended nature of the relationship and ongoing monitoring, whereas ID&V focuses specifically on identifying and verifying the customer (and, where relevant, beneficial owners).
Beneficial ownership considerations
For legal persons and arrangements, ID&V obligations commonly extend to identifying beneficial owners and taking reasonable measures to verify their identity. Beneficial ownership (natural persons who ultimately own or control) is distinct from legal ownership, and the verification standard applied to beneficial owners may differ from that applied to the direct customer.
Timing and risk-based application
Verification is generally required before or during the establishment of a business relationship or before conducting certain transactions, though some regimes permit verification to be completed shortly afterward where necessary and where money laundering and terrorist financing risks are effectively managed. The extent and depth of measures typically vary with assessed risk.
Regulatory versus operational nature
ID&V is both a regulatory obligation imposed on obliged entities under instruments such as the FATF Recommendations (as standards), the EU AML framework, the US Bank Secrecy Act and FinCEN rules, and the UK Money Laundering Regulations, and an operational process implemented through onboarding workflows, document checks, and electronic verification tools. Exact requirements diverge by jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about ID&V.

Is ID&V the same thing as Customer Due Diligence (CDD)?
No. ID&V and CDD are related but not interchangeable. ID&V refers specifically to identifying a customer (obtaining identity information) and verifying that identity against reliable, independent sources. CDD is the broader set of measures that, in many jurisdictions, encompasses ID&V alongside understanding the nature and purpose of the relationship, identifying beneficial owners where applicable, and conducting ongoing monitoring. ID&V is generally a component of CDD rather than a synonym for it, though exact terminology and scope vary by regime and should be confirmed against the applicable regulation.
Does completing ID&V confirm that a customer is legitimate or not involved in financial crime?
No. ID&V is a control designed to establish and verify who a customer purports to be; it does not establish the legitimacy of that person's conduct or guarantee that they are not involved in financial crime. A successfully verified identity is an operational compliance outcome, not a finding of good character. ID&V works alongside other measures such as risk assessment, screening, and ongoing monitoring to detect, deter, and mitigate risk, and no single control eliminates financial crime risk.
What types of sources are generally considered acceptable for verifying a customer's identity?
Verification typically relies on reliable, independent source documents, data, or information. In practice these may include government-issued identity documents, data from independent electronic sources or registries, and other documentary or non-documentary methods, depending on the regime and the assessed risk. What qualifies as sufficiently reliable and independent varies by jurisdiction and by obliged entity type, so acceptable sources should be confirmed against the applicable rules and the entity's own risk-based policies.
When must ID&V be completed relative to establishing the business relationship?
In many jurisdictions ID&V is generally expected before or at the point of establishing a business relationship or carrying out certain transactions. Some regimes permit verification to be completed during the establishment of the relationship where this is necessary not to interrupt normal business and the risk is managed, subject to conditions. The precise timing rules, permitted exceptions, and any thresholds vary by regime and should be confirmed against the applicable regulation.
How does a risk-based approach affect the depth of ID&V required?
Under a risk-based approach, the extent and robustness of ID&V measures can generally be calibrated to the assessed risk of the customer, product, channel, and jurisdiction. Higher-risk situations may warrant more rigorous or additional verification as part of enhanced due diligence, while lower-risk situations may permit simplified measures where the applicable regime allows. Baseline identification and verification obligations still generally apply; the risk-based approach adjusts intensity rather than removing the core requirement.
Does ID&V apply equally to individuals and to legal entities?
The core principle of identifying and verifying the customer applies to both, but the practical steps differ. For a natural person, ID&V focuses on verifying that individual's identity. For a legal entity or arrangement, ID&V typically involves verifying the entity's existence and identity and, in many jurisdictions, identifying and taking measures to verify the beneficial owners, which is a distinct concept from legal ownership. The specific requirements, documents, and scope vary by entity type, obliged entity, and jurisdiction, and should be confirmed against the applicable rules.

Common misconceptions

ID&V and CDD are the same thing.
ID&V is typically one component of CDD, not the whole of it. CDD generally also includes understanding the purpose and nature of the relationship and conducting ongoing monitoring. Treating them as interchangeable understates the wider due diligence obligations that apply.
Collecting a customer's identity details satisfies the verification requirement.
Identification (obtaining the claimed information) and verification (confirming it against reliable, independent sources) are separate steps. Recording a name and address without independently confirming it generally does not meet verification obligations.
Completing ID&V confirms a customer is legitimate and eliminates financial crime risk.
ID&V is a measure to detect, deter, and mitigate risk, not a guarantee of a customer's integrity or a proof of absence of wrongdoing. It establishes and confirms identity but does not by itself validate the legitimacy of a customer's conduct, and it must operate alongside ongoing monitoring and other controls.

Best practices

Clearly separate the identification step (collecting claimed identity information) from the verification step (confirming it against reliable, independent sources), and document how each was satisfied.
Calibrate the depth and type of verification measures to assessed risk, applying more robust or additional measures for higher-risk customers and situations, consistent with a risk-based approach.
For legal persons and arrangements, extend ID&V to beneficial owners by identifying the natural persons who ultimately own or control the customer and taking reasonable measures to verify them, keeping this distinct from legal ownership.
Verify identity before or during establishment of the relationship where required, and where a regime permits later completion, apply appropriate risk controls in the interim and confirm the timing rules against the applicable regulation.
Confirm what qualifies as a reliable and independent source under the applicable jurisdiction and regime rather than assuming a single global standard, and periodically review the adequacy of documents and electronic verification tools relied upon.
Maintain records of the information obtained and the evidence used to verify it in line with applicable retention requirements, and treat ID&V as part of a wider CDD and ongoing monitoring framework rather than a one-time onboarding task.