How PATRIOT Act Section 326 created the Customer Identification Program, the CIP rule behind modern KYC, FinCEN's role, and who must comply with it in 2026.
Table of contents
- The USA PATRIOT Act was signed on 26 October 2001 as Public Law 107-56, and its Title III amended the Bank Secrecy Act to fight money laundering and terrorist financing.
- Section 326 is the part that matters for onboarding: it ordered Treasury to write the Customer Identification Program rule, the legal floor under all modern KYC.
- The CIP rule was published on 9 May 2003, took effect on 9 June 2003, and banks had to comply by 1 October 2003. It now sits at 31 CFR 1020.220.
- The rule requires four identity elements for an individual: name, date of birth, address, and identification number, plus verification, recordkeeping, and watchlist screening.
- Section 326 tells you to verify, record, and screen. It never tells you to pile raw identity data into one central store, and that distinction decides your breach exposure.
Section 326 of the USA PATRIOT Act is the provision that created the Customer Identification Program (CIP). It directed the Treasury and the Financial Crimes Enforcement Network to set minimum standards requiring financial institutions to verify, record, and screen the identity of every person opening an account, which became the legal backbone of modern KYC.
TL;DR
The USA PATRIOT Act is the 2001 law that turned customer identity verification from best practice into a federal mandate. Its Title III amended the Bank Secrecy Act, and Section 326 ordered Treasury and FinCEN to write the Customer Identification Program rule, which is the minimum legal floor under today's KYC. The rule, now at 31 CFR 1020.220, makes a bank collect a name, date of birth, address, and identification number, verify them, keep records, and screen customers against terrorist lists. Section 326 is still in force and actively enforced in 2026. The detail most explainers miss: the law tells you to record the information used to verify identity, not to centralise raw data into a single breach target.
What is the USA PATRIOT Act?
The USA PATRIOT Act is a United States law signed on 26 October 2001 as Public Law 107-56. The name is an acronym for the Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act of 2001. It has two broad halves. One covers counterterrorism surveillance and law-enforcement powers. The other, which this guide focuses on, rewrites how financial institutions detect and report money laundering and terrorist financing. That financial half lives in Title III, and the single provision that reshaped customer onboarding is Section 326.
If you run compliance at a bank, a broker-dealer, a money services business, or a crypto exchange, this clause explains why you collect identity documents at all. It is the statutory root of the Customer Identification Program, and everything in your KYC stack sits on top of it. The plain-English short version: it made identity verification a legal duty, not a courtesy.
Why was the PATRIOT Act passed?
The Act was passed 45 days after the 11 September 2001 attacks, with the explicit aim of cutting off the money that funds terrorism. Congress did not invent anti-money laundering controls from scratch. The Bank Secrecy Act of 1970 already required certain reporting and recordkeeping. What the PATRIOT Act did was widen that framework dramatically, pull more institution types inside it, and push verification duties down to the point of account opening. For a short definition of the underlying statute, see our Bank Secrecy Act glossary entry.
The effect was to make financial institutions front-line enforcers. Instead of treating identity checks as an internal risk preference, the law set a federal minimum that every covered firm had to meet. That shift, from optional to mandatory, is the reason this provision still anchors compliance programmes a quarter of a century later.
What is Title III of the PATRIOT Act?
Title III is the financial-crime portion of the Act, captioned the International Money Laundering Abatement and Anti-terrorist Financing Act of 2001. It is the part that amends the Bank Secrecy Act, and it is where the KYC obligations live. Its headline reforms are easier to scan as a list.
- A broader statutory definition of financial institution, sweeping in more firm types.
- Mandatory anti-money laundering programmes for those institutions (Section 352).
- Enhanced due diligence for foreign correspondent and private banking accounts (Section 312).
- Special measures against jurisdictions or institutions of primary money laundering concern (Section 311).
- New information-sharing powers between law enforcement and firms, and between firms (Section 314).
- The Customer Identification Program mandate that became modern KYC (Section 326).
The rest of this guide unpacks Section 326 first, because it is the provision with the longest operational tail, then covers the supporting sections that examiners still test against.
What does Section 326 require?
Section 326 did not write the detailed rules itself. It directed the Treasury, acting through FinCEN and the federal banking agencies, to prescribe minimum standards. Those standards arrived as the Customer Identification Program final rule, a joint rule from Treasury and FinCEN with the Office of the Comptroller of the Currency, the Federal Reserve, the Federal Deposit Insurance Corporation, the Office of Thrift Supervision, and the National Credit Union Administration. The rule was published in the Federal Register on 9 May 2003 (68 FR 25090), took effect on 9 June 2003, and banks had to be compliant by 1 October 2003. It was first codified at 31 CFR 103.121, then recodified to 31 CFR 1020.220 in 2011 when the Bank Secrecy Act rules moved to Chapter X.
The statute sets three core duties. A financial institution must verify the identity of any person opening an account to the extent reasonable and practicable, maintain records of the information used to verify that identity, and determine whether the person appears on any government list of known or suspected terrorists. The implementing rule then fixes the detail. For an individual customer, a bank's CIP must collect, at a minimum, four identifying elements: name, date of birth, address, and identification number. The institution must verify those elements within a reasonable time using documentary or non-documentary methods, retain the information used, and give customers adequate notice that it is collecting identity data. The standard notice begins, "To help the government fight the funding of terrorism and money laundering activities, Federal law requires all financial institutions to obtain, verify, and record information that identifies each person who opens an account." Our Customer Identification Program glossary entry gives the quick reference version.
How did Section 326 create modern KYC?
KYC, know your customer, is the operational practice. CIP is the legal floor underneath it. Section 326 set the minimum identity-verification step that every covered institution must perform, and the rest of a modern programme stacks on top. Customer due diligence and enhanced due diligence add risk-based scrutiny. FinCEN's 2018 CDD rule layered on a beneficial-ownership requirement, often called the fifth pillar, that pushed firms to identify the natural persons behind legal-entity customers. Ongoing monitoring watches behaviour over time. The clean way to hold the relationship in your head: KYC contains CIP, and CIP is the part Section 326 made mandatory.
One detail is easy to misread, and it changes your architecture. The statute tells you to maintain records of the information used to verify identity. It does not tell you to centralise raw identity documents in a single database. Recordkeeping is a duty about retention and retrievability, not about warehousing every passport scan in one honeypot. That distinction is the difference between a clean audit and a breach headline, and it is the thread we pick up at the end of this guide.
What is FinCEN and what does it do?
The Financial Crimes Enforcement Network (FinCEN) is a bureau of the United States Department of the Treasury and the country's financial intelligence unit. It administers the Bank Secrecy Act, writes the implementing regulations including the CIP rule, and collects the reports that institutions file. Two filing thresholds come up constantly. A Currency Transaction Report (CTR) must be filed for each cash transaction of more than 10,000 dollars, measured on a daily aggregate basis. A Suspicious Activity Report (SAR) must be filed no later than 30 calendar days from the initial detection of the suspicious activity, extended to 60 days if no suspect has been identified.
FinCEN also administers Beneficial Ownership Information reporting under the Corporate Transparency Act, though that programme changed sharply in 2025. On 21 March 2025, FinCEN issued an interim final rule, published on 26 March 2025, that exempts all United States-formed entities and United States persons from BOI reporting. As of 2025, only entities formed under foreign law and registered to do business in the United States remain reporting companies. So while BOI reporting is still a FinCEN programme, the blanket "every company files" framing is out of date. Note that FinCEN is distinct from the Office of Foreign Assets Control, which administers sanctions; CIP terrorist-list screening overlaps with sanctions screening but the two regimes are run by different bodies.
Which other AML sections matter?
Section 326 gets the attention, but examiners test a wider set of Title III provisions. The table below summarises the ones a compliance team is most likely to meet.
| Section | What it covers |
|---|---|
| 311 | Special measures against jurisdictions or institutions of primary money laundering concern, codified at 31 USC 5318A. |
| 312 | Enhanced due diligence on foreign correspondent and private banking accounts. |
| 314(a) | Law-enforcement information requests routed to financial institutions. |
| 314(b) | Voluntary, protected information sharing between financial institutions. |
| 319 | Forfeiture from, and summons of, correspondent accounts. |
| 326 | The Customer Identification Program mandate behind modern KYC. |
| 352 | Mandatory anti-money laundering programmes with four minimum components. |
Section 352 deserves a closer look because it defines the shape of an AML programme. It requires four minimum components, often called the four pillars: written internal policies, procedures, and controls; a designated compliance officer; an ongoing training programme; and an independent audit function. The CIP duty plugs into that programme as the identity layer.
Who must comply with the PATRIOT Act?
The duties fall on financial institutions under the expanded Bank Secrecy Act definition. In practice that means banks, credit unions, broker-dealers, futures commission merchants, mutual funds, casinos and card clubs, and money services businesses. The category of money services businesses sweeps in money transmitters, currency dealers, and several fintech models; our money services businesses glossary entry breaks down the definition. Through later FinCEN action and proposed rules, many crypto and digital-asset firms also fall inside the perimeter.
The practical message for a modern fintech, neobank, or crypto exchange is to assume scope. If you onboard customers, hold value, or move money, the CIP duties almost certainly apply to you, whether or not you think of yourself as a bank. Our guide to KYC for crypto exchanges walks through the controls a digital-asset onboarding flow needs.
What are the penalties for non-compliance?
Bank Secrecy Act and anti-money laundering failures carry serious consequences. Regulators including FinCEN, the Office of the Comptroller of the Currency, the Federal Deposit Insurance Corporation, and the Federal Reserve pursue civil money penalties and consent orders, and the Department of Justice pursues criminal liability for willful violations. CIP and KYC weaknesses are among the most common findings in BSA examinations.
The scale is not hypothetical. In October 2024, TD Bank agreed to pay roughly 3.1 billion dollars to resolve Bank Secrecy Act program failures spanning January 2014 to October 2023. FinCEN assessed a record 1.3 billion dollar penalty. The Department of Justice imposed a 1.43 billion dollar criminal penalty plus a 452.4 million dollar forfeiture, the Office of the Comptroller of the Currency added 450 million dollars, and the Federal Reserve added 123.5 million dollars. TD Bank became the largest bank in United States history to plead guilty to Bank Secrecy Act program failures, and the first United States bank to plead guilty to conspiracy to commit money laundering. The lesson for a smaller firm is not the headline number but the pattern: sustained programme gaps, including identity and monitoring weaknesses, compound into existential liability.
The Section 326 CIP compliance map
Most explainers stop at "Section 326 requires you to collect and store identity." That conflates two different things. The table below maps each statutory duty to what the law literally requires, to the common centralise-everything vendor approach and the liability it creates, and to a privacy-first way to satisfy the identical duty. It reframes compliance as an architecture decision rather than a simple checklist of boxes to tick. Read the rows side by side, because the duty in the second column never dictates the centralised design in the third. It is a starting point for your own analysis, not legal advice.
| CIP duty (31 CFR 1020.220) | What the law literally requires | Centralise-everything approach and its liability | Privacy-first way to meet the same duty |
|---|---|---|---|
| Collect | Name, date of birth, address, and identification number for each individual customer. | Store raw documents and identifiers in one database, creating a single high-value target. | Capture and shard data so no single store holds a complete record. |
| Verify | Confirm identity within a reasonable time using documentary or non-documentary methods. | Upload and retain image scans on central servers indefinitely. | Read identity from an NFC chip with liveness checks, no image upload. |
| Record | Maintain records of the information used to verify identity. | Keep the full plaintext record in one place, conflating retention with centralisation. | Retain a retrievable, audit-ready trail without a central plaintext honeypot. |
| Screen | Check the customer against government terrorist lists, with adequate notice. | Couple screening to the same central PII store, widening blast radius. | Screen against lists while keeping identity data sharded and access-controlled. |

Download: the Section 326 CIP compliance map (PDF) is a one-page, print-ready version you can keep beside your onboarding rules and share with compliance and risk teams.
The key insight is in the third column versus the fourth. The duty to record the information used to verify identity is a duty about retention and retrievability. It is not a statutory instruction to build a centralised PII honeypot. Vendors who centralise turned a recordkeeping obligation into a breach liability. Retention is about keeping a record you can retrieve when an examiner asks for it, and retrievability does not require warehousing every raw passport scan in one place. The two ideas are routinely conflated, and that quiet conflation is what builds the honeypot in the first place. Hold them apart and the architecture choice becomes visible again.
Can you meet Section 326 without a honeypot?
You can be fully Section 326 compliant and audit-ready without holding a central honeypot, and a named case shows why the distinction matters. In June 2024, 404 Media reported that the identity-verification provider AU10TIX had left administrative credentials exposed for roughly 18 months. The credentials were collected by malware in December 2022, posted to Telegram in March 2023, and were still active when discovered in June 2024. They granted access to a logging platform that linked to customer ID documents, including names, dates of birth, nationalities, ID numbers, and document images. AU10TIX serves clients including TikTok, Uber, X, and Coinbase. The exposure was not caused by the record-keeping duty itself. It was caused by the architecture choice of centralising identity data behind a single set of credentials. For more on why the central store is the real liability, see why your KYC vendor is your biggest data breach risk.
The honest counter-argument is that plenty of well-run institutions hold a central KYC store in a hardened environment and pass their examinations year after year. That is true. Centralisation is not automatically non-compliant. The point is narrower: the law does not require it, and every central store is a standing target whose blast radius you carry for as long as retention rules force you to keep the data. The question is whether the convenience is worth the risk you cannot fully insure away.
Zyphe's answer is to verify identity without becoming the place it accumulates. Identity data is sharded across a decentralised network of more than 60,000 nodes under a 29-of-100 threshold scheme, so no single node holds a complete record and there is no central honeypot to breach. Verification reads an NFC chip to ICAO 9303 and eIDAS standards with two-step liveness and no image upload, and the customer keeps a reusable credential they can re-present elsewhere. When an examiner asks for a complete record, authorised parties reconstruct it through the threshold scheme and export the audit trail, so sharding never means losing access. The same statutory duties, met without the single store that turned a credential leak into a breach. Zyphe frames this as an efficiency point too, with materially lower compliance cost at a fraction of the cost of a conventional stack in its own modelling, though we treat that as a Zyphe estimate rather than a cited fact. If that architecture fits your build, our KYC software page and how it works walk through the detail.
The bottom line
The chain is straightforward: the USA PATRIOT Act amended the Bank Secrecy Act through Title III, Section 326 ordered the Customer Identification Program rule, and that rule became the legal backbone of modern KYC, enforced by FinCEN. Compliance is mandatory and ongoing. But the architecture you use to meet it is a choice. Section 326 tells you to verify, record, and screen identity. It never tells you to build a central PII honeypot that becomes your single largest breach liability. The teams that come out ahead will satisfy the verification duty without inheriting the central data risk that has cost others dearly.
Related resources
- Bank Secrecy Act glossary definition
- Customer Identification Program glossary definition
- KYC for crypto exchanges: compliant onboarding
- Why your KYC vendor is your biggest data breach risk
- Zyphe KYC software
- How Zyphe verifies identity without storing PII
Cited sources
- USA PATRIOT Act of 2001, Public Law 107-56, full text (Congress.gov)
- FinCEN, Interagency Interpretive Guidance on Customer Identification Program Requirements under Section 326
- 31 CFR 1020.220, Customer Identification Program requirements for banks (eCFR)
- OCC Bulletin 2003-22, Customer Identification Program final rule (occ.gov)
- FinCEN, USA PATRIOT Act statutes and regulations
- FinCEN assesses record 1.3 billion dollar penalty against TD Bank (fincen.gov)
- FinCEN removes beneficial ownership reporting for U.S. companies and U.S. persons (fincen.gov)
- 404 Media, ID verification provider AU10TIX exposed driver's licenses
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.