Skip to main content
Category: Customer Due Diligence

Non-Documentary Verification

Also known as: Non-Documentary Methods, Non-Documentary CIP, Document-Free Verification
Simply put

Non-documentary verification is a way of confirming a customer's identity without relying on physical or digital identity documents such as a passport or driver's license. Instead, it typically involves cross-checking the information a customer provides against independent, reliable sources. It is one of the accepted approaches financial institutions may use to verify who their customers are, alongside document-based (documentary) methods.

Formal definition

Non-documentary verification refers to procedures for confirming a customer's identity through means other than reviewing an identity document, generally by comparing customer-provided information against independent and reliable sources or by contacting the customer directly. In the US, it is one of the two verification approaches contemplated under the Customer Identification Program (CIP) rules implementing the Bank Secrecy Act, codified for banks at 31 CFR § 1020.220, alongside documentary verification. Under those rules, a bank's CIP must include procedures that address situations where non-documentary methods are used, including where an individual is unable to present an unexpired government-issued identification. This term is defined in a regulatory and operational context rather than as a criminal-law concept; successful verification supports identity confidence but does not by itself establish the legitimacy of a customer or any transaction. Terminology, acceptable source data, and specific procedural requirements vary by jurisdiction and by the applicable obliged-entity regime, and exact requirements should be confirmed against the relevant regulation.

Why it matters

Verifying who a customer is sits at the foundation of an effective anti-money laundering program, and non-documentary verification gives institutions a legitimate path to establish identity confidence when a physical or digital identity document is not the practical or available option. In the US, the Customer Identification Program (CIP) rules implementing the Bank Secrecy Act recognize both documentary and non-documentary approaches as acceptable ways to verify identity, and CIP procedures must specifically address situations where an individual is unable to present an unexpired government-issued identification. Without a workable non-documentary pathway, institutions could either exclude customers who lack conventional documents or default to weaker checks, either of which creates operational and compliance risk.

Non-documentary methods also matter because they support customer onboarding in remote and digital channels, where reviewing a physical document is not always feasible or reliable. By comparing customer-provided information against independent and reliable sources, or by contacting the customer directly, institutions can build identity confidence in environments where in-person document inspection is not part of the process. This helps reconcile the need to reach customers efficiently with the underlying regulatory expectation that the institution form a reasonable belief that it knows the true identity of each customer.

It is important to keep the boundaries of the concept clear. Successful non-documentary verification supports identity confidence but does not by itself establish the legitimacy of a customer or of any transaction, and it is not a criminal-law determination. It is one control among several within a broader risk-based program and should not be treated as a guarantee against misuse. Terminology, acceptable source data, and specific procedural requirements vary by jurisdiction and by the applicable obliged-entity regime, so institutions should confirm exact requirements against the relevant regulation rather than assuming a single global standard.

Who it's relevant to

BSA/AML Compliance Officers
Those responsible for a US institution's Customer Identification Program need to ensure their CIP procedures cover both documentary and non-documentary verification, and specifically address cases where a customer cannot present an unexpired government-issued identification. They should confirm that the methods chosen are consistent with the institution's risk assessment and with 31 CFR § 1020.220 and related guidance.
Onboarding and Digital Identity Teams
Teams operating remote or digital onboarding flows often rely on non-documentary methods where inspecting a physical document is impractical. They benefit from understanding which independent and reliable sources are acceptable and how automated verification can reduce manual review, while recognizing that verification supports identity confidence rather than confirming legitimacy.
Financial Intelligence and Investigations Analysts
Analysts reviewing accounts should understand how a customer's identity was verified, including whether non-documentary methods were used, so they can accurately assess the strength of identity information underlying an account. It is important to note that successful verification does not by itself establish wrongdoing or the absence of it.
Compliance Technology and RegTech Vendors
Providers offering document-free or non-documentary verification products should align their offerings with the regulatory expectations of the institutions they serve, including the requirement to handle situations where customers cannot present standard identification. Vendors should be clear that acceptable source data and procedural requirements vary by jurisdiction and regime.

Inside Non-Documentary Verification

Non-Documentary Verification Methods
Techniques used to verify a customer's identity without relying on physical or original identity documents, typically by comparing the information provided by the customer against data obtained from independent and reliable sources. Under the US Customer Identification Program (CIP) rules implementing the Bank Secrecy Act, covered financial institutions are generally permitted to use non-documentary methods, alone or in combination with documentary methods, as part of their risk-based CIP.
Independent Data Source Comparison
The practice of checking customer-supplied identifying information against data from sources such as credit bureaus, public databases, or other third-party reference data. This is a core mechanism of non-documentary verification, used to corroborate identity where documents are not obtained or are supplemented by additional checks.
Risk-Based Application
Non-documentary verification is typically applied within a risk-based framework, meaning the depth and combination of methods may vary according to the assessed risk of the customer, product, or channel. It is a measure to help manage and mitigate identity-related risk rather than a guarantee that identity is genuine.
Relationship to CIP and CDD
Non-documentary verification is one route to satisfying the identity verification element of a Customer Identification Program under FinCEN rules, and it supports broader Customer Due Diligence (CDD) obligations. It addresses identity verification specifically and does not by itself discharge wider CDD requirements such as understanding the nature and purpose of a relationship or ongoing monitoring.
Use in Non-Face-to-Face Onboarding
These methods are commonly relevant to remote or non-face-to-face account opening, where original documents cannot be physically inspected. Terminology and permissibility differ across jurisdictions; the specific approaches available should be confirmed against the applicable regulatory regime.

Common questions

Answers to the questions practitioners most commonly ask about Non-Documentary Verification.

Is non-documentary verification a lesser or fallback method compared to documentary verification?
It is generally better understood as a complementary method rather than an inherently inferior one. In many jurisdictions, obliged entities may use non-documentary methods either alongside or instead of documentary verification depending on the assessed risk and the reliability of the sources involved. Neither approach is universally treated as the default; the appropriate mix typically depends on the applicable regime, the customer risk profile, and the quality of the data or documents available. Exact expectations should be confirmed against the applicable rules, such as FinCEN's Customer Identification Program requirements under the US Bank Secrecy Act framework or the relevant national transposition of AML obligations.
Does non-documentary verification satisfy an entity's full customer due diligence obligation on its own?
No. Non-documentary verification is a technique used to verify identity information, and verifying identity is only one component of customer due diligence (CDD). CDD in many frameworks also encompasses understanding the nature and purpose of the relationship, identifying beneficial ownership where applicable, and conducting ongoing monitoring. Verifying identity through non-documentary means, however robust, does not by itself discharge these broader obligations, and it should not be conflated with the full CDD process.
What kinds of sources are typically used for non-documentary verification?
Non-documentary verification generally relies on comparing customer-provided information against independent and reliable sources rather than physical or digital documents. Depending on the jurisdiction and the entity's risk-based approach, this may include cross-referencing information against consumer reporting or credit reference data, public databases, or other independent third-party sources. The reliability and independence of the source is typically the key consideration, and what qualifies as acceptable may vary by regime and should be confirmed against the applicable regulation.
When might an entity choose non-documentary methods over documentary verification?
The choice is typically driven by a risk-based assessment. Non-documentary methods may be selected where documents are unavailable, where the customer is not physically present, where the assessed risk supports it, or where independent data sources provide sufficient assurance of identity. Conversely, higher-risk situations may call for documentary verification, a combination of methods, or enhanced due diligence measures. Entities generally document the rationale for the method chosen, and the specific triggers and expectations depend on the applicable framework.
How should discrepancies identified during non-documentary verification be handled?
Discrepancies between customer-provided information and independent sources are generally treated as a prompt for further inquiry rather than as conclusive findings. Entities typically resolve inconsistencies before completing the customer relationship, which may involve requesting additional information, applying documentary verification, or escalating for enhanced scrutiny. A discrepancy or an unresolved data point does not by itself establish wrongdoing; it is an operational trigger for risk assessment and, where warranted, further action under the entity's procedures.
What documentation should an entity retain when relying on non-documentary verification?
As a general matter, entities are expected to be able to demonstrate how identity was verified, including the sources used and the basis for concluding that verification was satisfactory. Record-keeping expectations vary by jurisdiction and by the applicable instrument, so the specific retention periods and content requirements should be confirmed against the relevant regulation. Maintaining an auditable record of the method, the sources relied upon, and the resolution of any discrepancies generally supports both supervisory review and the entity's own ongoing monitoring.

Common misconceptions

Non-documentary verification is a lesser or non-compliant substitute for checking identity documents.
Under the US CIP rules implementing the Bank Secrecy Act, non-documentary methods are a permitted means of verifying identity and may be used alone or alongside documentary methods within a risk-based program. Whether they are sufficient in a given case depends on the assessed risk and the applicable regulation, which varies by jurisdiction.
Successfully verifying identity through non-documentary means confirms the customer is legitimate and lowers financial crime risk to zero.
Identity verification is a measure to help detect and mitigate identity-related risk; it does not establish that a customer is free of wrongdoing, nor does it eliminate money laundering or other financial crime risk. It also does not by itself satisfy the broader CDD obligations that continue to apply.
There is a single global standard specifying exactly which non-documentary methods are acceptable.
Requirements and terminology differ across regimes. The permissibility and expectations described here relate primarily to the US CIP framework under the Bank Secrecy Act and FinCEN rules; other jurisdictions may treat non-documentary verification differently, and the applicable rules should be confirmed against local regulation.

Best practices

Use non-documentary methods within a documented, risk-based framework that specifies when they are applied alone and when they are combined with documentary methods.
Corroborate customer-supplied information against independent and reliable data sources, and consider using multiple sources for higher-risk situations.
Confirm which non-documentary methods are permissible under the specific regime you operate in, rather than assuming a single global standard applies.
Treat identity verification as one component of a wider CDD process, ensuring that ongoing monitoring and understanding of the relationship are addressed separately.
Pay particular attention to non-face-to-face and remote onboarding scenarios, where documents cannot be physically inspected, and calibrate verification depth to the assessed risk.
Maintain records of the methods used and the sources relied upon so that verification decisions can be evidenced and reviewed against the applicable regulation.