Learn more about the latest security and privacy threats
Back

Customer Identification Program (CIP): The Complete 2026 Guide to Requirements and Verification

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published July 30, 2026 Updated July 30, 2026
Identity card with four checked fields representing the four required CIP elements

A customer identification program is the CIP banks run under 31 CFR 1020.220. The 4 elements, required data, documentary vs non-documentary verification, 2026.

Table of contents
  • A CIP is the written, risk-based procedure a financial institution uses to form a reasonable belief that it knows the true identity of each customer at account opening.
  • It is required by Section 326 of the USA PATRIOT Act and codified for banks at 31 CFR 1020.220, with parallel rules for broker-dealers, mutual funds and futures commission merchants.
  • A compliant programme has four elements: identity verification, recordkeeping, comparison with government lists, and adequate customer notice.
  • The minimum data set is name, date of birth, a street address, and an identification number, collected before the account opens, then verified through documentary or non-documentary methods.
  • Records must be kept for five years, which is why the central question is no longer whether you can verify identity, but whether you must warehouse the raw data to prove it.
  • In March 2022, FinCEN and the OCC assessed USAA Federal Savings Bank a combined 140 million dollar penalty, and the OCC cease-and-desist order required the board to adopt an appropriate written CIP.

A customer identification program is the federally mandated set of procedures a bank uses to verify the identity of every customer opening an account. Required by Section 326 of the USA PATRIOT Act and codified at 31 CFR 1020.220, it has four elements: identity verification, recordkeeping, comparison with government lists, and customer notice.

TL;DR

A customer identification program is the entry point of know your customer, defined narrowly by regulation: the procedures a bank uses to form a reasonable belief that it knows the true identity of each customer at onboarding. Section 326 of the USA PATRIOT Act ordered it, and the CIP Rule at 31 CFR 1020.220 sets the four elements: verify identity, keep records, screen against government lists, and notify customers. You must collect name, date of birth, address and an identification number, then verify by documentary or non-documentary means. The detail most guides skip is what the rule never says. It demands a reasonable belief and a five-year record, not permanent custody of the underlying personal data.

What is a customer identification program?

A customer identification program is a federally mandated set of procedures, required by Section 326 of the USA PATRIOT Act and codified at 31 CFR 1020.220, that requires banks and financial institutions to verify the identity of every customer opening an account. Put in the regulator's own words, it is the written, risk-based programme a bank uses to form a reasonable belief that it knows the true identity of each customer. That phrase, a reasonable belief, is the legal heart of the rule and it matters later, so hold onto it.

It helps to place the term precisely. A CIP is the entry point of know your customer (KYC), not a synonym for it. KYC is the wider programme that covers ongoing monitoring and risk scoring across the customer lifecycle; the CIP is the narrow, regulatorily defined first step that happens at account opening. The short companion definition lives in our CIP glossary entry, and the broader concept in the KYC glossary entry. This guide is the deep version: the obligations, the data, and the architecture decision they force.

Why does a customer identification program exist?

The CIP is a direct product of the response to the 11 September 2001 attacks. Section 326 of the USA PATRIOT Act of 2001 directed the Treasury, acting through the Financial Crimes Enforcement Network (FinCEN), to write a rule setting minimum identity-verification standards for financial institutions. The final CIP Rule was published on 9 May 2003, took effect on 9 June 2003, and required full bank implementation by 1 October 2003. It did not invent identity checks; it made a baseline of them statutory and uniform.

The rule does not sit alone. It is one component of the broader Bank Secrecy Act and anti-money laundering framework, the same regime that governs Suspicious Activity Reports and currency reporting. The bank version is codified at 31 CFR 1020.220, but parallel CIP rules apply across the sector: 31 CFR 1023.220 for brokers or dealers in securities, 31 CFR 1024.220 for mutual funds, and 31 CFR 1026.220 for futures commission merchants and introducing brokers. For the wider statutory context, see the Bank Secrecy Act glossary entry and our guide to AML compliance software.

What are the four elements of a customer identification program?

Every compliant CIP rests on four required elements. Element one is identity verification: the bank must use risk-based procedures, documentary or non-documentary, to verify enough of the customer's identity to form a reasonable belief it knows who they are. Element two is recordkeeping: the bank retains the identifying information and a record of how it verified the customer. Element three is comparison with government lists: the bank checks each customer against any list of known or suspected terrorists issued by a federal agency. Element four is adequate customer notice: the bank tells customers it is collecting information to verify their identity.

To make those four elements citable rather than abstract, the matrix below maps each one to its place in the regulation, the minimum action it demands, the retention clock that attaches, and the privacy failure mode it can create. The final column is where the architecture question first appears.

The CIP four-elements compliance matrix

Element31 CFR 1020.220 citationWhat the rule requiresMinimum actionRetention clockPrivacy-first failure mode
1. Identity verification(a)(2)(ii)Risk-based procedures to form a reasonable belief of true identityVerify via documentary or non-documentary methodsVerification record kept five years after the record is madeStoring the raw documents used to verify builds a standing breach target
2. Recordkeeping(a)(3)Retain the identifying information and verification description and resultsLog data, document type, methods, results, discrepancy resolutionIdentifying information kept five years after the account is closedA growing archive of raw personal data outlives the relationship that justified it
3. Comparison with government lists(a)(4)Check customers against federal lists of known or suspected terroristsScreen at onboarding against required listsScreening evidence kept under the same five-year ruleCentralising screened identity files concentrates value for an attacker
4. Adequate customer notice(a)(5)Give customers notice that identity information is being collectedPublish or present a clear CIP noticeNotice procedures documented and retainedNone directly, though notice should state how long data is held

This matrix is the educational core of the page; the next sections expand the parts examiners probe hardest, starting with the exact data the rule names.

What information must a customer identification program collect?

Before opening an account, a CIP must collect four pieces of information for each customer. For an individual these are: the full legal name; the date of birth; a residential or business street address; and an identification number. A post office box alone does not satisfy the address requirement for an individual, though an Army Post Office or Fleet Post Office box, or the street address of a next of kin or contact, is allowed where the customer has no street address. For an entity, the address is the principal place of business, local office or other physical location.

The identification number rule differs by status, and this is where teams slip. For a United States person, the identification number is a taxpayer identification number, such as a Social Security number or an employer identification number for an entity. For a non-United States person, it can be a taxpayer identification number, a passport number and country of issuance, an alien identification card number, or the number and country of any other government-issued document that evidences nationality or residence and bears a photograph or similar safeguard. Collecting these is distinct from verifying them: collection is gathering the data, verification is forming the reasonable belief that it is true. Our KYC software page shows how that capture and verification step runs in practice.

Documentary or non-documentary: which verification does the rule permit?

The CIP Rule permits two verification methods and is deliberately technology-neutral about both. Documentary verification means reviewing an identity document, typically a government-issued photo identification such as a driver's licence or passport. Non-documentary verification means confirming identity without a document in hand: comparing the customer's information against a consumer reporting agency or public database, checking references with another financial institution, or matching the data to other independently verified sources. The rule expects you to address situations where documentary review is not practical, such as remote onboarding.

Crucially, the rule requires a result, not a tool. It demands a reasonable belief that you know the customer, and leaves the choice of method to your risk-based procedures. That is the legal opening this guide returns to: nothing in 31 CFR 1020.220 requires that you, or a vendor acting for you, keep the raw document image forever to prove the belief was reasonable. The table below maps each method to when the rule contemplates it.

Verification methodWhat it involvesWhen the rule permits or favours it
DocumentaryReviewing a government-issued photo IDIn-person or remote onboarding where a reliable document can be examined
Non-documentaryMatching data to reporting agencies, public databases or other institutionsWhen a document cannot be reviewed, or to add assurance to a documentary check
Combined, risk-basedLayering both methods against the customer's risk profileHigher-risk customers, discrepancies, or where a single method gives weak assurance

For the document and liveness mechanics behind a modern check, our proof of address verification guide covers one common evidence type in depth.

How does a customer identification program differ from KYC and CDD?

This is the most common source of confusion in onboarding teams, so it is worth being exact. A CIP, know your customer, and customer due diligence (CDD) are three nested layers, not three names for the same thing. The CIP is the narrow regulatory step that verifies identity at the door. KYC is the umbrella programme that the CIP sits inside. CDD, governed by FinCEN's CDD Rule at 31 CFR 1010.230, adds the ongoing risk-assessment layer, including beneficial-ownership identification for legal-entity customers.

LayerScopeWhen it happensWhat it requires
CIPVerifying customer identityAt account openingCollect four identifiers, verify, screen lists, give notice, keep records
KYCThe whole identity programmeOnboarding plus the relationshipIdentity verification plus risk scoring and periodic review
CDDOngoing risk and ownershipOnboarding and continuouslyUnderstand the customer, identify beneficial owners, monitor activity

In short, the CIP is the first step of KYC, and CDD is the continuous layer that surrounds it. For how identity verification relates to the wider anti-money laundering perimeter, see our decentralised KYC explainer and the KYB software guide for the business-entity equivalent.

Who needs a customer identification program?

The covered institutions are defined by the Bank Secrecy Act and the parallel rules. They are banks, savings associations and credit unions under 31 CFR 1020.220; brokers and dealers in securities under 1023.220; mutual funds under 1024.220; and futures commission merchants and introducing brokers under 1026.220. If you are one of these and you open accounts, you must maintain a CIP. There is no minimum size that exempts you.

The harder cases are the modern ones that the original 2003 rule did not picture. A fintech or neobank that operates through a banking-as-a-service partner does not escape the obligation; the CIP duty flows to the programme that onboards the customer, and the sponsor bank remains accountable for it. Crypto exchanges and money services businesses are inside the wider Bank Secrecy Act perimeter and run equivalent identity controls; our KYC for crypto exchanges guide and the money services businesses glossary entry cover those edges. As a rule, state regulators and sponsor banks set expectations that meet or exceed the federal floor, so plan to the higher bar.

How do you build a compliant customer identification program?

Building a compliant programme is well-trodden ground, and it follows a predictable order. First, draft a written CIP and have the board or a designated committee approve it. Second, define your risk-based collection and verification procedures, specifying when you use documentary and when you use non-documentary methods. Third, implement screening against the required government lists and against Office of Foreign Assets Control (OFAC) sanctions. Fourth, deliver adequate customer notice. Fifth, set a five-year recordkeeping schedule. Sixth, integrate the programme with CDD and ongoing monitoring. Seventh, audit and update it as risk and regulation move.

The step most teams underestimate is not in that list as a procedure; it is a design choice that runs underneath all of them. Once you decide how you verify, you must decide where the verified data lives and who is liable when it leaks. That decision is independent of whether your checks pass an exam, and it is the part with the longest tail. Our guide to KYC API integration covers how the verification step wires into an onboarding flow, and the next two sections take up the data-architecture question the rule leaves open.

What is the hidden risk in a traditional customer identification program?

Here is the contrarian point, and it is a legal one before it is a product one. The CIP Rule requires a reasonable belief that you know the customer, and a five-year record proving how you formed it. It never requires that you, or a verification vendor acting for you, permanently warehouse the raw personal data and document images used to form that belief. Yet the incumbent model, run by vendors such as Sumsub, Onfido, Veriff, Jumio, Trulioo and Persona, typically satisfies the rule by collecting and centrally storing that raw data, and the five-year retention clock only makes the resulting archive larger and longer-lived.

That archive is a high-value target, and the breaches are not hypothetical. On 3 October 2025 Discord disclosed an intrusion at a third-party customer service vendor, naming the vendor as 5CA on 9 October 2025, that exposed government-ID photos of roughly 70,000 users held to review age-related appeals. Sumsub, separately, has confirmed an intrusion that began in July 2024 through a malicious attachment on a third-party support platform and went undetected for around 18 months until a January 2026 audit; Sumsub states it was confined to a support environment and did not reach live verification workflows or document images, which makes the dwell time, not document loss, the lesson there. And in November 2025, Cybernews researchers found an unprotected database linked to identity vendor IDMerit holding more than a billion records across 26 countries, disclosed in February 2026; IDMerit disputed that customer data was compromised. Different facts, one pattern: centralised identity data is a standing liability. We analyse a fourth case in our piece on why your KYC vendor is your biggest data breach risk.

How do you satisfy CIP without holding a PII honeypot?

The alternative starts from the rule's own wording: form the reasonable belief, keep the audit-ready record, but do not let your systems become the place raw identity data accumulates. Verification can read an identity document's chip to International Civil Aviation Organization (ICAO) 9303 and eIDAS standards with two-step liveness and no image upload, which produces strong assurance without a photo sitting in a database for five years. The verified result can then be sharded across a decentralised network so no single store holds a complete record, and a reusable credential lets a customer verify once and re-present elsewhere instead of resubmitting documents to every new provider.

Zyphe is built on exactly that frame: compliance is the floor, architecture is the differentiator. Verified data is split across a network of more than 60,000 nodes under a 29-of-100 threshold scheme, the customer holds the key, and there is no master key or central honeypot to breach. The examiner's first question is usually whether you can still produce a complete record on demand, and you can, because authorised parties reconstruct the record through the threshold scheme and export a per-region, audit-ready trail. That meets the same five-year, complete-record standard the rule already expects, without keeping the single archive that turned a bribed insider or a misconfigured database into someone else's breach headline. See how it works for the architecture in detail.

Comparison showing a centralised KYC store as a single breach target versus a decentralised network where verified identity data is sharded so no single node holds a complete record.
A central CIP store is one record per customer and one breach away; a sharded network holds no complete record on any node.

Download: the CIP architecture one-pager (PDF) is a print-ready version of this comparison you can keep beside your onboarding rules and share with compliance and security teams.

What are the penalties for a weak customer identification program?

Customer identification program failures rarely produce a standalone fine; they show up inside broader Bank Secrecy Act and anti-money laundering enforcement, and the figures are large. The clearest named example is USAA Federal Savings Bank. In March 2022, FinCEN and the OCC assessed a combined 140 million dollar civil money penalty for willful Bank Secrecy Act violations between January 2016 and April 2021 (the OCC's 60 million dollar penalty was credited against FinCEN's 140 million dollar penalty, so USAA paid a single 140 million dollars, not 200 million), and the OCC cease-and-desist order specifically required USAA's board to revise, adopt and promptly implement an appropriate written CIP. Separately, Pacific National Bank in Miami was assessed 7 million dollars each by the OCC and FinCEN for Bank Secrecy Act and USA PATRIOT Act violations. These are concrete proof that the cost of getting it wrong runs well above a million dollars.

The common mistakes are predictable, and most are organisational rather than technical. The top failure modes are: no board-approved written programme; weak or undocumented non-documentary procedures; missing or inadequate customer notice; gaps in government-list and OFAC screening; and, increasingly, over-retention of raw personal data beyond what the programme actually needs. That last one is the through-line of this guide. The rule asks you to retain a record of verification, not to hoard the underlying documents in a way that compounds your breach exposure year after year. Designing the data layer well is how you satisfy the first four mistakes and avoid the fifth at the same time.

The bottom line

A CIP is the regulated front door of every covered financial institution: verify identity, keep the record, screen the lists, notify the customer. The four elements are settled, the data set is short, and the methods are flexible by design. What the rule asks for is a reasonable belief and a five-year record, not a permanent vault of raw personal data, and that distinction is where compliance and security stop pulling against each other. The teams that come out ahead will satisfy every element of the CIP while refusing to inherit a honeypot that the rule never required them to build.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

A CIP is a federally required programme under Section 326 of the USA PATRIOT Act and 31 CFR 1020.220 that a financial institution uses to verify each customer's identity at account opening and form a reasonable belief that it knows the customer's true identity. It is the first identity step inside a wider KYC programme.

A compliant CIP has four elements: identity verification using risk-based documentary or non-documentary procedures; recordkeeping of the identifying information and verification results; comparison of customers against government lists of known or suspected terrorists; and adequate customer notice that identity information is being collected. All four are mandatory under the CIP Rule.

The requirements are a written, board-approved programme that collects four identifiers, name, date of birth, a street address and an identification number, before account opening; verifies identity through documentary or non-documentary methods; screens customers against required government and sanctions lists; gives customers notice; and retains the records for five years. Procedures must be risk-based.

A CIP must collect four minimum identifiers before opening an account: the customer's full legal name, date of birth for individuals, a residential or business street address, and an identification number. For United States persons the number is a taxpayer identification number; for non-United States persons it can be a passport number, alien identification number or similar government document number.

A CIP is the narrow, regulatorily defined identity-verification step at onboarding. KYC is the broader programme the CIP sits inside. Customer due diligence, governed by FinCEN's CDD Rule, adds ongoing risk assessment and beneficial-ownership checks. In short, CIP is the first step of KYC, and CDD is the continuous layer around it.

Covered institutions under the Bank Secrecy Act must maintain a CIP: banks, savings associations, credit unions, brokers and dealers in securities, mutual funds, and futures commission merchants. Fintechs and neobanks operating through partner banks, plus crypto exchanges and money services businesses, effectively inherit the obligation through the programmes that onboard their customers.

Section 326 of the USA PATRIOT Act of 2001 requires a CIP. It directed the Treasury and FinCEN to issue the CIP Rule, which was finalised in 2003 and codified at 31 CFR 1020.220 for banks, with parallel rules for broker-dealers, mutual funds and futures commission merchants. The rule sits within the broader Bank Secrecy Act and anti-money laundering framework.

Five years. The identifying information collected at account opening must be retained for five years after the account is closed. The description of any document relied on, the methods and results of any non-documentary verification, and the resolution of any substantive discrepancy must be retained for five years after the record is made. The rule never requires permanent retention of raw personal data.

Run identity verification without the honeypot

Zyphe verifies customers at onboarding and reuses that proof across platforms — without storing a central pile of PII.

Book a demo