Language

Customer Identification Program (CIP)

What Is a Customer Identification Program (CIP)?

A Customer Identification Program (CIP) is a written set of procedures that covered U.S. financial institutions use to collect customer information and verify identity when a new account is opened. Its purpose is to give the institution reasonable confidence that it knows the customer’s true identity.
CIP focuses on initial customer identification and verification, while Customer Due Diligence (CDD) has a broader scope that includes understanding the business relationship, assessing risk, and conducting ongoing monitoring. The term CIP comes from requirements introduced under the USA PATRIOT Act and implemented through the U.S. Bank Secrecy Act framework. Other countries have similar identification requirements within their KYC or CDD rules.

How Does a Customer Identification Program (CIP) Work?

A CIP usually includes the following steps:
  • Collect a customer’s identity information (for individuals, that commonly includes name, date of birth, address, and a government identification number)
  • Verify the customer’s identity using documentary methods, non-documentary methods, or both
  • Keep records of the information and verification results
  • Screen against government lists where required
Documentary verification uses government-issued identity documents, such as passports or driver’s licenses. Non-documentary methods may include comparing customer information with reliable third-party sources, contacting the customer, or checking references with other financial institutions.

Who Must Maintain a Customer Identification Program (CIP)?

In the United States, banks and certain other regulated financial institutions must maintain a written CIP as part of their AML compliance program. Covered institutions include banks, mutual funds, securities brokers and dealers, futures commission merchants, and introducing brokers. Governance and approval requirements depend on the type of institution.
Specific U.S. CIP rules generally do not apply directly to the foreign branches of U.S. banks. However, those branches are expected to maintain appropriate AML procedures that follow local law and are consistent with the bank’s broader policies.
Outside the United States, organizations may follow comparable identification and verification requirements under local KYC or CDD rules without using the term CIP. For fintechs, neobanks, and payment providers, the exact responsibilities depend on their regulated activities, licensing arrangements, and relationships with partner financial institutions.

How Can Regula Help with a Customer Identification Program (CIP)?

Since identity verification is at the core of CIP, Regula provides document and biometric checks that help confirm the applicant is a real person presenting a genuine identity document.
Regula Document Reader SDK checks identity documents and extracts the personal fields CIP records need. It reads the visual zone with OCR, parses the MRZ, and reads NFC/RFID chips when the document supports it. It supports more than 16,500 document templates from 254 countries and territories.
Regula Face SDK runs a 1:1 comparison between a live capture and the portrait on the document. Active or passive liveness can run in the same session. Active liveness asks for a prompted gesture. Passive liveness checks the capture without asking the user to do more. Face matching and liveness detection help confirm that the applicant is present and matches the document portrait. Those results may be kept with the CIP verification record.

FAQ

What is CIP in banking?

In U.S. banking, a Customer Identification Program (CIP) is a written, risk-based set of procedures for collecting customer information and verifying identity when an account is opened. The CIP must be appropriate for the bank’s size and business activities and form part of its broader BSA/AML compliance program. The bank’s board of directors must approve the overall BSA/AML program, which includes the CIP. 

Is a CIP the same as Know Your Customer (KYC)?

No. CIP is a specific U.S. regulatory requirement for collecting identifying information and verifying a customer’s identity when an account is opened. KYC is a broader industry term that may include customer identification, due diligence, risk assessment, and other AML controls. CIP can therefore form part of a wider KYC and CDD process. 

What information does CIP typically collect?

For individuals, a CIP generally collects the customer’s name, date of birth, address, and identification number. The institution uses this information to verify the customer’s identity through documentary methods, non-documentary methods, or both. Documentary methods may use a passport or driver’s license, while digital systems can extract data using OCR, MRZ reading, or NFC chip reading. Requirements differ for legal entities and certain account types.

How do biometrics support CIP?

Biometrics can help confirm that the person opening the account matches the portrait on the identity document. Face matching performs a 1:1 comparison, while liveness detection helps identify attempts involving photos, masks, or replayed videos. These checks can strengthen remote customer verification but are not explicitly required by the CIP rule. They also do not replace the collection of required identifying information. 

Where does CIP end and CDD begin?

CIP and CDD overlap rather than forming two completely separate stages. CIP focuses on collecting identifying information, verifying the customer’s identity, and recording the results at account opening. CDD has a broader scope that includes understanding the relationship, assessing risk, identifying beneficial owners where required, and conducting ongoing monitoring. Higher-risk relationships may also require enhanced due diligence.

On our website, we use cookies to collect technical information. In particular, we process the IP address of your location to personalize the content of the site

Cookie Policy rules