Skip to main content
Category: AML and KYC

Customer Identification Program

Also known as: CIP, CIP, Customer Identification Program requirements
Simply put

A Customer Identification Program (CIP) is a regulatory requirement that mandates financial institutions to verify the identity of individuals or entities seeking to open an account or establish a business relationship. It is a federal mandate that helps financial institutions confirm they know who their customers are. CIP is one component of broader Bank Secrecy Act (BSA) and Know Your Customer (KYC) obligations.

Formal definition

A Customer Identification Program (CIP) is a set of regulatory requirements applicable to banks and other financial institutions requiring them to establish, document, and follow procedures for verifying the identity of individuals or entities opening accounts. In the United States, CIP obligations arise under the Bank Secrecy Act framework, with requirements set out across 12 CFR Chapters I through III and VII and 31 CFR Chapter X, and banks' compliance is assessed against these BSA regulatory requirements. CIP is distinct from, though related to, wider KYC and BSA/AML programs; readers should confirm specific procedural, recordkeeping, and verification obligations against the current applicable regulations, as scope and detail vary by institution type and jurisdiction.

Why it matters

A Customer Identification Program is a foundational element of how financial institutions meet their obligations under the Bank Secrecy Act framework. By requiring banks and other covered institutions to establish and document procedures for verifying who their customers are at account opening, CIP is intended to help institutions confirm the identity of the individuals and entities they do business with. Without a documented and consistently applied CIP, an institution may struggle to demonstrate compliance when its practices are assessed against BSA regulatory requirements.

CIP sits within a broader set of Know Your Customer and BSA/AML obligations, but it is not the same as those wider programs. It addresses a specific point in the customer relationship — the verification of identity when an account is opened or a business relationship is established — rather than the full range of ongoing monitoring and risk assessment activities that KYC and AML programs cover. Treating CIP as interchangeable with the entire KYC or AML program can lead institutions to under-scope their controls or misattribute where a given obligation actually originates.

Because CIP obligations arise from specific federal regulations, the procedural, recordkeeping, and verification details that apply to a particular institution depend on its type and jurisdiction. Institutions should confirm their specific requirements against the current applicable regulations rather than relying on generalized descriptions, since scope and detail vary.

Who it's relevant to

BSA/AML Compliance Officers
Compliance officers at banks and other covered financial institutions are responsible for establishing, documenting, and maintaining the CIP as one component of the institution's broader BSA/AML obligations. They should confirm the specific procedural, recordkeeping, and verification requirements that apply to their institution against the current applicable regulations, since scope and detail vary by institution type and jurisdiction.
Financial Institution Examiners
Examiners assess an institution's compliance with the BSA regulatory requirements for the CIP, including verifying that the institution has a program in place and that it follows documented identity verification procedures. Their assessment is framed by the requirements set out in 12 CFR Chapters I through III and VII and 31 CFR Chapter X.
Account Opening and Onboarding Teams
Staff who open accounts or establish new business relationships apply the CIP procedures at the point where identity verification is required. They should follow the institution's documented CIP procedures, recognizing that CIP addresses identity verification at account opening and is distinct from the wider ongoing monitoring activities within KYC and AML programs.
Identity Verification Solution Providers
Vendors offering identity verification and validation services support institutions in completing the identity verification processes associated with a CIP. Institutions relying on such offerings remain responsible for ensuring their overall program aligns with the current applicable BSA regulatory requirements for their institution type and jurisdiction.

Inside CIP

Identity Information Collection
The minimum identifying information a covered institution must obtain before opening an account, typically including name, date of birth, address, and an identification number. CIP is a component of a broader anti-money laundering and Know Your Customer framework and is distinct from payment card data protection controls governed by PCI DSS.
Identity Verification Procedures
Documented methods used to form a reasonable belief that the institution knows the true identity of the customer, which may be documentary (reviewing an identification document) or non-documentary (comparing information against independent sources). The specific methods and their sufficiency depend on the institution's risk-based assessment.
Risk-Based Approach
CIP procedures are calibrated to the risk presented by the customer, account type, and the institution's size and activities. This means the depth of verification is intended to vary rather than following a single fixed standard for every account.
Recordkeeping
Retention of the identifying information obtained and a description of the verification methods used, kept for a defined period. Exact retention periods and format requirements depend on the governing regulation and should be confirmed against the current applicable rules.
Government List Comparison
A procedure for determining whether a customer appears on lists of known or suspected terrorists or terrorist organizations designated by relevant government authorities, as required by the applicable regulatory framework.
Customer Notice
Providing customers with adequate notice that the institution is requesting information to verify their identity, typically before an account is opened.

Common questions

Answers to the questions practitioners most commonly ask about CIP.

Is a Customer Identification Program (CIP) a PCI DSS requirement?
No. CIP is a component of anti-money-laundering (AML) and Know Your Customer (KYC) obligations under financial regulatory frameworks, not a PCI DSS control. PCI DSS governs the protection of cardholder data and the security of the cardholder data environment, while CIP concerns verifying the identity of customers when accounts are opened. The two address different objectives, and satisfying one does not satisfy the other. Organizations should confirm applicable CIP obligations against the relevant financial regulations and their supervisory authority rather than assuming coverage under payment security standards.
Does completing a CIP identity check prevent fraud such as account takeover or synthetic identity fraud?
No. CIP is intended to verify identity information at account opening and support AML programs; it is not a comprehensive fraud-prevention control. It may help reduce certain risks, but it does not by itself stop account takeover, which typically occurs after an account is established, and it can be challenged by synthetic identity fraud, where fabricated or blended identity elements are used. Effective fraud mitigation generally combines CIP with ongoing monitoring, authentication controls, and other detection measures, each with its own false-positive and false-negative trade-offs.
What identifying information is typically collected under a CIP?
A CIP generally establishes the identifying information a covered institution collects to form a reasonable belief that it knows the true identity of a customer. The specific data elements and acceptable verification methods depend on the applicable regulatory framework and the institution's risk-based procedures. Organizations should define the required elements and verification approaches in their documented CIP and confirm them against current regulatory guidance and their supervisory authority rather than relying on a fixed list.
How should CIP procedures be documented and maintained?
CIP procedures are typically documented as part of an institution's broader AML compliance program, describing the information collected, the methods used to verify identity, recordkeeping practices, and how the program is applied on a risk basis. The precise documentation, retention, and review expectations depend on the governing regulation, so organizations should align their documented procedures with current requirements from the applicable authority and update them as those requirements change.
How does CIP relate to other identity and authentication controls in a payment environment?
CIP addresses identity verification at the point of establishing a customer relationship, which is distinct from transaction-level authentication controls such as EMV chip authentication, 3-D Secure, strong customer authentication, and multi-factor authentication. Those controls operate at different points in a transaction and address different risks. CIP does not replace them, and none of them satisfy CIP obligations. Institutions generally layer these controls, recognizing that each mitigates specific risks and none eliminates fraud on its own.
How does CIP interact with data protection obligations when identity data is retained?
Information collected and retained for CIP purposes may include personal data that is subject to privacy and data protection requirements, and, where it involves payment card details, may also fall within the scope of cardholder data protections. The applicable retention periods, safeguards, and access controls depend on the governing regulations and the type of data involved. Organizations should coordinate CIP recordkeeping with their data protection and, where relevant, PCI DSS scoping analyses, confirming requirements against the current published standards and regulations.

Common misconceptions

CIP is a PCI DSS requirement or part of payment card security compliance.
CIP is an identity and anti-money laundering control governed by financial regulatory frameworks, not by PCI DSS. PCI DSS addresses the protection of cardholder data and sensitive authentication data; the two operate under different governance and serve different objectives, and satisfying one does not satisfy the other.
Completing CIP verifies a customer's identity with certainty and eliminates fraud such as account takeover or synthetic identity fraud.
CIP is intended to help an institution form a reasonable belief about a customer's identity, not to guarantee it. It may reduce certain risks but has known limitations and does not by itself eliminate synthetic identity fraud, account takeover, or other fraud types, which require additional detection and monitoring controls.
There is one uniform set of CIP documents and verification steps every institution must apply identically.
CIP is risk-based, so the required identifying information and verification methods are intended to vary based on the customer, account, and institution profile. Practitioners should confirm the precise obligations against the current applicable regulation rather than assuming a fixed checklist.

Best practices

Document the institution's CIP as a written, board-approved procedure that specifies the identifying information collected, the documentary and non-documentary verification methods used, and the risk factors that determine which methods apply.
Adopt a risk-based framework that scales verification depth to the customer, account type, and institution profile, and periodically review whether the risk tiers remain appropriate.
Keep CIP recordkeeping separate from and independent of payment card data controls, and retain identifying information and verification descriptions for the period required by the current applicable regulation.
Establish a repeatable process for comparing customers against relevant government-designated lists and for handling matches, and confirm the process against the current applicable requirements.
Treat CIP as one layer within a broader identity and fraud program, complementing it with monitoring controls that address account takeover, synthetic identity fraud, and other fraud types CIP alone does not eliminate.
Provide clear customer notice about identity verification before account opening, and train staff on both documentary and non-documentary procedures and their limitations.