Customer Identification Program
A Customer Identification Program (CIP) is a regulatory requirement that mandates financial institutions to verify the identity of individuals or entities seeking to open an account or establish a business relationship. It is a federal mandate that helps financial institutions confirm they know who their customers are. CIP is one component of broader Bank Secrecy Act (BSA) and Know Your Customer (KYC) obligations.
A Customer Identification Program (CIP) is a set of regulatory requirements applicable to banks and other financial institutions requiring them to establish, document, and follow procedures for verifying the identity of individuals or entities opening accounts. In the United States, CIP obligations arise under the Bank Secrecy Act framework, with requirements set out across 12 CFR Chapters I through III and VII and 31 CFR Chapter X, and banks' compliance is assessed against these BSA regulatory requirements. CIP is distinct from, though related to, wider KYC and BSA/AML programs; readers should confirm specific procedural, recordkeeping, and verification obligations against the current applicable regulations, as scope and detail vary by institution type and jurisdiction.
Why it matters
A Customer Identification Program is a foundational element of how financial institutions meet their obligations under the Bank Secrecy Act framework. By requiring banks and other covered institutions to establish and document procedures for verifying who their customers are at account opening, CIP is intended to help institutions confirm the identity of the individuals and entities they do business with. Without a documented and consistently applied CIP, an institution may struggle to demonstrate compliance when its practices are assessed against BSA regulatory requirements.
CIP sits within a broader set of Know Your Customer and BSA/AML obligations, but it is not the same as those wider programs. It addresses a specific point in the customer relationship — the verification of identity when an account is opened or a business relationship is established — rather than the full range of ongoing monitoring and risk assessment activities that KYC and AML programs cover. Treating CIP as interchangeable with the entire KYC or AML program can lead institutions to under-scope their controls or misattribute where a given obligation actually originates.
Because CIP obligations arise from specific federal regulations, the procedural, recordkeeping, and verification details that apply to a particular institution depend on its type and jurisdiction. Institutions should confirm their specific requirements against the current applicable regulations rather than relying on generalized descriptions, since scope and detail vary.
Who it's relevant to
Inside CIP
Common questions
Answers to the questions practitioners most commonly ask about CIP.