31 CFR 1020.220 sets the Customer Identification Program requirements every covered bank must follow when opening new accounts. The rule requires a written program, built into the bank’s broader anti-money laundering compliance program, that spells out how the bank will collect identifying information, verify it, keep records of what it did, screen customers against government lists, and tell customers what to expect. The program has to be risk-based and tailored to the bank’s size, location, customer base, and the accounts it offers.1eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks
Which Banks and Accounts Are Covered
The rule reaches any bank required to maintain an anti-money laundering compliance program under federal law. That covers national banks, state-chartered banks, savings associations, credit unions, and U.S. branches of foreign banks.1eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks The CIP cannot be a standalone document; it must be part of the AML program.
An “account” is a formal banking relationship used to provide financial services or conduct transactions. The CIP is triggered whenever a customer opens a new account, whether in a branch or online. The verification procedures inside the CIP must be reasonable and practical for the bank’s circumstances rather than a one-size template.2FinCEN. FAQs: Final CIP Rule
The Four Required Data Points
Before an account can be opened, the bank must collect at minimum:
- Name (full legal name of the individual or entity)
- Date of birth (individuals only)
- Address (residential or business street address for an individual; principal place of business or a local office for a business entity)
- Identification number: for a U.S. person, a taxpayer identification number; for a non-U.S. person, at least one of a taxpayer identification number, passport number with country of issuance, alien identification card number, or the number of another government-issued document showing nationality or residence and bearing a photograph
The regulation says “taxpayer identification number” rather than “Social Security number.” Both SSNs and ITINs satisfy the requirement, which matters for resident aliens who file taxes with an ITIN.1eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks
For business entities, the bank must also collect documentation showing the entity exists, such as certified articles of incorporation, a government-issued business license, or a partnership agreement.1eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks
Two narrow exceptions loosen these requirements. A customer without a residential or business street address may provide an APO or FPO box, or the street address of a next of kin or another contact person. And if the customer has applied for a taxpayer identification number but not yet received it, the bank’s CIP may allow the account to open, so long as the bank confirms the application was filed and obtains the actual number within a reasonable time.1eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks
Verifying Customer Identity
Collecting information is only half the job. The bank must verify enough of it, through risk-based procedures, to form a reasonable belief that it knows the customer’s true identity. It doesn’t need to confirm every data point, but it does need to hit that standard.2FinCEN. FAQs: Final CIP Rule
Documentary Verification
The CIP has to list which documents the bank will accept. For individuals, the norm is an unexpired, government-issued document showing nationality or residence with a photograph, such as a driver’s license or passport. For business entities, acceptable documents include certified articles of incorporation, government-issued business licenses, partnership agreements, and trust instruments.1eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks The bank checks these for tampering or forgery.
Non-Documentary Verification
When physical documents are unavailable or the risk profile calls for more, non-documentary methods fill in. These include contacting the customer directly, cross-referencing information against consumer reporting agency data, checking public databases, verifying references with other financial institutions, or obtaining a financial statement. Banks often layer several methods, especially for accounts opened remotely.1eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks
When Verification Fails
The CIP must include procedures for cases where the bank cannot form a reasonable belief. The rule does not force immediate closure. Instead, the procedures must address when to refuse to open an account at all, when to allow limited account use while verification continues, when to close an account after verification attempts have failed, and when to file a Suspicious Activity Report. The bank has discretion because innocent delays are common.3eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks
Screening Against Government Lists
Separate from verifying identity, the CIP must include procedures to check the customer against any federal government list of known or suspected terrorists or terrorist organizations designated by Treasury in consultation with federal regulators. The check has to happen within a reasonable time after the account is opened, or sooner if another federal law or directive requires it. If a match hits, the bank must follow all federal directives tied to that list.1eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks
Recordkeeping Timelines
Two different retention clocks apply:
- Identifying information (name, date of birth, address, identification number): five years after the account is closed. For credit card accounts, five years after the account is closed or becomes dormant.
- Verification records (descriptions of documents reviewed, non-documentary methods used, and how any discrepancies were resolved): five years after the record is made.
The second clock catches people off guard. Verification records only need to survive five years from the date they were created, even if the account itself lasts twenty. The identifying data, by contrast, has to be kept five years past account closure.1eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks
Verification records must be detailed enough to reconstruct what the bank did. For documents, that means the type of document, its identification number, place of issuance, and any issuance or expiration date. For non-documentary methods, the file must describe the methods used and the results. If a discrepancy came up, the record must explain how it was resolved.1eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks
Customer Notice
The CIP must give customers adequate notice that the bank is collecting information to verify their identity. The rule does not prescribe a specific delivery method, so banks post notices in lobbies, on websites and mobile apps, and directly on account applications. The customer needs to encounter the notice before completing the application.
Federal regulators publish model language that satisfies the requirement:
“Important Information About Procedures for Opening a New Account — To help the government fight the funding of terrorism and money laundering activities, Federal law requires all financial institutions to obtain, verify, and record information that identifies each person who opens an account. What this means for you: When you open an account, we will ask for your name, address, date of birth, and other information that will allow us to identify you. We may also ask to see your driver’s license or other identifying documents.”1eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks
Banks may reword the notice, but the model language is standard because it explains both the legal basis and what the customer should expect.
Beneficial Owners for Business Accounts
When a legal entity opens an account, 31 CFR 1010.230 requires the bank to identify the entity’s beneficial owners in addition to satisfying 1020.220. A beneficial owner is defined two ways:
- Ownership prong: any individual who directly or indirectly owns 25 percent or more of the entity’s equity interests.
- Control prong: a single individual with significant responsibility to control, manage, or direct the entity, typically a CEO, CFO, COO, president, or equivalent.
The bank must identify every individual meeting the ownership threshold and at least one individual meeting the control test. If a trust owns 25 percent or more, the trustee is treated as the beneficial owner for the ownership prong.4eCFR. 31 CFR 1010.230 – Beneficial Ownership Requirements for Legal Entity Customers A range of entity types are exempt, including publicly traded companies and majority-owned subsidiaries, banks and bank holding companies, SEC-registered investment companies, state-regulated insurers, and government agencies. Most trusts other than statutory trusts formed by filing with a state are also exempt.5FFIEC BSA/AML Examination Manual. Appendix 1 – Beneficial Ownership
This bank-level collection under 1010.230 is separate from the Corporate Transparency Act reporting to FinCEN. As of March 2025, FinCEN exempted all U.S.-formed entities from CTA reporting through an interim final rule, leaving reporting to foreign entities registered to do business in the United States. The bank-level obligation under 1010.230 is unaffected.6FinCEN. Beneficial Ownership Information Reporting
Relying on Another Institution’s Verification
A CIP may allow the bank to rely on another financial institution’s identity verification instead of duplicating it. Three conditions must be met: the reliance is reasonable under the circumstances; the other institution is subject to an AML program rule and regulated by a federal functional regulator (the Federal Reserve, FDIC, NCUA, OCC, SEC, or CFTC); and the other institution enters into a contract requiring it to certify annually that it has implemented its AML program and will perform the relevant CIP steps. Reliance does not shift liability. The bank opening the account remains responsible for CIP compliance.7FFIEC BSA/AML InfoBase. Assessing Compliance with BSA Regulatory Requirements: Customer Identification Program
Penalties for Noncompliance
CIP failures are enforced under the Bank Secrecy Act penalty framework, on both civil and criminal tracks.
On the civil side, willful violations carry a statutory penalty of up to the greater of $25,000 or the amount involved in the transaction, capped at $100,000 per violation.8Office of the Law Revision Counsel. 31 USC 5321 – Civil Penalties Those figures are adjusted for inflation. As of January 2024, the inflation-adjusted range for willful violations was $69,733 to $278,937 per violation.9Federal Register. Financial Crimes Enforcement Network; Inflation Adjustment of Civil Monetary Penalties FinCEN published a further adjustment in January 2025, and the 2026 annual adjustment was cancelled by the White House, so the 2025 figures are the current ceiling. Negligent violations carry a statutory penalty of up to $500 per violation before inflation adjustment.
On the criminal side, an individual who willfully violates BSA regulations faces up to $250,000 in fines and five years in prison. If the violation occurs alongside another federal crime or as part of a pattern of illegal activity involving more than $100,000 in a twelve-month period, the maximum rises to $500,000 in fines and ten years in prison.10Office of the Law Revision Counsel. 31 USC 5322 – Criminal Penalties Under Anti-Money Laundering Act of 2020 amendments, a convicted individual must forfeit profits gained from the violation and repay any bonus received during the year of the violation or the following year if they were a bank officer or employee at the time.
Most enforcement lands on the civil side. Criminal prosecution is reserved for egregious or intentional failures, not paperwork oversights, but the civil ceiling alone is high enough to make the CIP a real financial priority for banks of any size.