Skip to main content
Category: Customer Due Diligence

Customer Identification Program

Also known as: CIP, Customer Information Program
Simply put

A Customer Identification Program (CIP) is a set of procedures that a bank or other covered financial institution must follow to verify the identity of each customer when an account is opened. It typically requires collecting basic identifying information, such as a customer's name, date of birth, and address, before the account is established. The term is most closely associated with US Bank Secrecy Act requirements, and note that the phrasing 'Customer Information Program' is a common variant referring to the same concept.

Formal definition

Under the US Bank Secrecy Act framework as implemented through FinCEN and the federal banking agencies, a CIP is a documented, risk-based program that a covered institution must maintain as part of its account-opening controls. The CIP must include procedures specifying the identifying information to obtain from each customer before opening an account, generally including, for an individual, name, date of birth, and address, as well as procedures to verify that identity and to retain the identifying information obtained (per the CIP rule, retention is required for a specified period after account opening, which practitioners should confirm against the applicable regulation). CIP is a component of, but distinct from, broader Customer Due Diligence (CDD) obligations: it addresses identification and verification at onboarding rather than the ongoing due diligence, risk profiling, and beneficial ownership requirements that fall under CDD. It should not be treated as a guarantee against financial crime, but as a measure to establish and reasonably verify customer identity. Scope, thresholds, and precise requirements are jurisdiction-specific; the term as defined here derives from the US regime and analogous obligations elsewhere may differ in terminology and detail.

Why it matters

A Customer Identification Program sits at the front door of a financial institution's anti-money laundering controls. Because it governs how identity is established and verified at account opening, it is the foundation on which later due diligence, monitoring, and risk assessment depend. Weak or inconsistently applied identification procedures can undermine every downstream control: an institution cannot meaningfully profile customer risk, screen against sanctions or PEP lists, or investigate suspicious activity if it cannot reasonably establish who the customer is in the first place. Under the US Bank Secrecy Act framework, maintaining an adequate CIP is a supervisory expectation, and deficiencies in identification and verification procedures are a recurring theme in examination findings by the federal banking agencies.

Who it's relevant to

Compliance and BSA/AML officers
Those responsible for designing and maintaining AML programs must ensure their CIP procedures specify the identifying information to collect before account opening, set out documentary and non-documentary verification methods on a risk basis, and address retention of the information obtained. Because CIP is one component of a wider CDD framework, compliance teams should be clear on where CIP obligations end and broader ongoing due diligence and beneficial ownership requirements begin.
Onboarding and account-opening staff
Front-line personnel apply the CIP in practice, collecting name, date of birth, and address (for individuals) and performing verification before the account is established. Their consistent execution of documented procedures is what makes the program effective; gaps at this stage propagate into every subsequent control.
Examiners and internal auditors
Supervisory examiners and internal audit functions assess whether an institution's CIP meets applicable requirements, covering the information obtained, the verification approach, and record retention. The FFIEC BSA/AML Examination Manual frames the expectations that examiners test against for US-regulated institutions.
Legal and risk professionals
Legal and risk teams advising covered institutions need to understand that CIP requirements derive from the US Bank Secrecy Act framework as implemented by FinCEN and the federal banking agencies, and that scope, thresholds, and terminology may differ in other jurisdictions. They should treat the term 'Customer Information Program' as a common variant of the same concept and confirm precise retention periods and requirements against the applicable regulation.

Inside CIP

Customer Identification (Identity Data)
The core identifying information typically collected for a customer. For natural persons this generally includes name, date of birth, address, and an identification number (such as a government-issued identifier); for legal entities it commonly includes the entity name, principal place of business, and a registration or identification number. Exact required data elements vary by jurisdiction and by the applicable rules governing the obliged entity, and should be confirmed against the relevant regulation.
Identity Verification
The process of confirming that the customer is who they claim to be, using documentary methods (such as reviewing identification documents), non-documentary methods (such as consulting reference data), or a combination. This is distinct from merely collecting identity data; verification tests the reliability of that data. In the US context this is closely associated with the Customer Identification Program (CIP) requirement under Bank Secrecy Act implementing rules.
Relationship to CDD and the Broader KYC Framework
Customer identification and verification are foundational components of Customer Due Diligence (CDD) and the wider Know Your Customer (KYC) framework. Identification/verification establishes who the customer is; CDD generally extends further to understanding the nature and purpose of the relationship and conducting ongoing monitoring. These are related but not interchangeable concepts.
Beneficial Ownership Component
Where the customer is a legal entity or arrangement, programs typically require identifying and taking steps to verify beneficial owners, the natural persons who ultimately own or control the customer. Beneficial ownership is conceptually distinct from legal ownership. Specific thresholds and obligations differ across regimes (for example, FATF standards, EU AML instruments, and US rules) and should be confirmed against the applicable framework.
Recordkeeping and Retention
Programs generally require retaining records of the identity information obtained and the verification methods used, for a period specified by the applicable regulation. Retention periods and record content requirements vary by jurisdiction.
Risk-Based Application
The depth and methods of identification and verification are typically applied on a risk-sensitive basis, with enhanced measures for higher-risk customers and situations. These measures are intended to detect, deter, and manage financial crime risk rather than to guarantee its prevention.

Common questions

Answers to the questions practitioners most commonly ask about CIP.

Is a Customer Identification Program the same thing as Customer Due Diligence?
No. A Customer Identification Program (CIP) is a narrower component focused on identifying and verifying the identity of a customer at account opening, whereas Customer Due Diligence (CDD) is a broader, ongoing process that also includes understanding the nature and purpose of the customer relationship, conducting ongoing monitoring, and, where applicable, identifying beneficial owners. In the US framework, CIP obligations derive from the Bank Secrecy Act and implementing FinCEN and federal banking agency rules, while CDD obligations are addressed under related but distinct requirements. Treating CIP as if it satisfies all CDD expectations would understate an institution's obligations. Exact scope should be confirmed against the applicable regulation.
Does completing a CIP confirm that a customer is not involved in financial crime?
No. A CIP is a measure to verify identity and to form a reasonable belief that an institution knows the true identity of its customer; it is not a determination of the customer's legitimacy or guilt. Successful identity verification does not establish that a customer is free of financial crime risk, nor does it substitute for sanctions screening, PEP screening, ongoing monitoring, or broader CDD. CIP should be understood as one control that helps detect and deter certain risks at onboarding, not as a guarantee against wrongdoing.
What identifying information is typically collected under a CIP at account opening?
Programs generally collect, at minimum, identifying information such as name, date of birth (for individuals), address, and an identification number, with the specific data elements set by the applicable regulation and the institution's risk-based procedures. The precise required fields and any distinctions between individual and entity customers should be confirmed against the governing rules, as scope and terminology can vary. Institutions typically document these requirements within their written CIP procedures.
How can identity verification be performed under a CIP?
Verification is generally accomplished through documentary methods, non-documentary methods, or a combination of both, as provided for under the applicable rules and the institution's risk-based procedures. Documentary methods may rely on identification documents, while non-documentary methods may involve comparing information against reliable independent sources. The methods an institution chooses, and how they are applied to higher-risk situations, should be defined in its written CIP procedures and calibrated to the assessed risk.
Must a CIP be documented in writing?
In many frameworks, a CIP is expected to be a written program that is appropriate to the institution's size and risk profile and is typically incorporated into the broader AML compliance program. Written procedures generally address the information collected, verification methods, recordkeeping, and handling of situations where identity cannot be verified. Specific documentation and approval expectations should be confirmed against the applicable regulation and supervisory guidance.
What are the recordkeeping expectations associated with a CIP?
Institutions are generally expected to retain records of the identifying information obtained and of the methods and results used to verify identity, with retention periods and content set by the applicable rules. These records support examinations and demonstrate that the institution followed its written procedures. Because retention periods and required record contents can vary by regime, exact requirements should be confirmed against the governing regulation.

Common misconceptions

Customer identification and CDD are the same thing.
Identification and verification establish who the customer is and are a foundational element of CDD, but CDD generally extends further, to understanding the purpose and intended nature of the relationship and to ongoing monitoring. Treating them as identical understates the broader due diligence obligation.
Collecting a customer's identity information satisfies the requirement.
Collecting identity data and verifying it are distinct steps. Programs typically require the obliged entity to verify identity using documentary and/or non-documentary methods, not simply to record what the customer provides.
There is a single global standard defining exactly what must be collected and verified.
Requirements diverge across regimes. FATF Recommendations set standards that are not themselves binding law, while specific obligations, data elements, thresholds, and retention periods are set by national or regional instruments (such as US Bank Secrecy Act rules, EU AML instruments, or the UK Money Laundering Regulations). Exact requirements should be confirmed against the applicable jurisdiction.

Best practices

Distinguish clearly in policies and procedures between collecting identity data and verifying it, and document the verification method used for each customer.
Apply identification and verification measures on a risk-sensitive basis, reserving enhanced measures for higher-risk customers and situations while ensuring baseline requirements are met for all.
For legal entities and arrangements, build in steps to identify and verify beneficial owners, treating beneficial ownership as distinct from legal ownership.
Confirm required data elements, verification standards, and record retention periods against the specific regulation applicable to your entity and jurisdiction rather than assuming a uniform global rule.
Maintain retrievable records of identity information obtained and verification methods used for the retention period required by the applicable regime.
Integrate identification and verification within the broader CDD and KYC framework, including provisions for ongoing monitoring, rather than treating onboarding checks as a one-time exercise.