A KYC form, short for Know Your Customer, is the identity-verification document a bank, credit union, brokerage, or other financial business has you complete before it will open an account or move money for you. At a minimum, the form collects four pieces of information about you: your legal name, your date of birth, a physical address, and a taxpayer identification number such as a Social Security Number.1Financial Crimes Enforcement Network. FAQs: Final CIP Rule Federal law requires the institution to collect it. Refusing to fill one out means the institution will decline to do business with you.
What the Form Asks You For
Federal rules set a floor of four data points every institution must capture for an individual customer:1Financial Crimes Enforcement Network. FAQs: Final CIP Rule
- Your full legal name, exactly as it appears on your government-issued ID. Nicknames or abbreviations will cause a mismatch.
- Your date of birth.
- A residential or business street address. A P.O. box on its own doesn’t satisfy the requirement, because it doesn’t describe where you can physically be located.1Financial Crimes Enforcement Network. FAQs: Final CIP Rule
- A taxpayer identification number. For most U.S. individuals, that’s a Social Security Number. Businesses provide an Employer Identification Number instead.2Internal Revenue Service. U.S. Taxpayer Identification Number Requirement
Those four fields are the minimum. Most institutions also want to see a government-issued photo ID, like a driver’s license or passport, so they can visually confirm you’re the person on the form. Many request a secondary proof of address, often a recent utility bill or bank statement.
Accuracy matters more than people realize. A transposed digit in your Social Security Number or a stale address will trigger a manual review, delay your account opening, and sometimes result in an outright rejection. The institution is legally required to form a “reasonable belief” that it knows your true identity, and mismatched data makes that impossible.3Financial Crimes Enforcement Network. Interagency Interpretive Guidance on Customer Identification Program Requirements Under Section 326 of the USA PATRIOT Act
Why You Have To Fill One Out
The requirement traces to the Bank Secrecy Act, codified at 31 U.S.C. ยง 5311, which directs financial institutions to maintain records and file reports that help the government detect money laundering and terrorism financing. The Financial Crimes Enforcement Network, or FinCEN, is the Treasury Department bureau that writes the rules.4Office of the Law Revision Counsel. 31 USC 5311 – Declaration of Purpose
Section 326 of the USA PATRIOT Act expanded the framework by requiring every financial institution to adopt a written Customer Identification Program, commonly called a CIP, spelling out exactly how it verifies the identity of each new account holder.3Financial Crimes Enforcement Network. Interagency Interpretive Guidance on Customer Identification Program Requirements Under Section 326 of the USA PATRIOT Act The KYC form you fill out is that CIP in action. The CIP must use risk-based procedures, so higher-risk accounts get more scrutiny, not less.
Which Businesses Ask for One
The Bank Secrecy Act’s definition of “financial institution” is broader than most people expect. It reaches commercial banks and credit unions, obviously, but the statutory list also includes securities brokers, insurance companies, casinos, precious-metals dealers, pawnbrokers, and vehicle sellers.5GovInfo. 31 USC 5312 – Definitions and Application The CIP rule itself applies to banks, savings associations, credit unions, and certain non-federally regulated banks, with parallel requirements covering broker-dealers and other entities regulated by the SEC and CFTC.3Financial Crimes Enforcement Network. Interagency Interpretive Guidance on Customer Identification Program Requirements Under Section 326 of the USA PATRIOT Act
Cryptocurrency exchanges have been pulled into this framework as well. FinCEN treats them as money services businesses, which means they face the same identity-verification obligations as traditional wire-transfer companies.
How You Submit It and What Happens Next
Most institutions now handle KYC through encrypted online portals. You upload photographs or scans of your ID and supporting documents directly to the institution’s secure system. Many platforms add a biometric step where you take a live selfie or perform prompted facial movements so the system can confirm you’re the same person pictured on the ID.
If you’re opening an account in person at a branch, the process is simpler: you hand over the physical documents, a representative reviews them and enters the data, and you sign the form. Some institutions require notarized copies for accounts opened remotely or by mail.
Once your documents are in, the institution checks your information against internal databases and external verification services. Straightforward applications usually clear within a day or two. Applications involving foreign documentation or incomplete address histories can take longer. If something doesn’t match, you’ll get a specific explanation of what failed and a chance to resubmit. Common rejection reasons are blurry document images, expired IDs, and mismatched names between your form and your documents.
The completed form functions as a legal declaration that everything you submitted is truthful. The institution is required to retain your identifying information for at least five years after the account is closed, along with descriptions of the documents you presented and the verification steps it performed.6eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks
When You’ll Be Asked Again
KYC isn’t a one-time event. Institutions re-verify customer information on a risk-based schedule. Higher-risk accounts are typically reviewed annually, medium-risk accounts every two to three years, and lower-risk accounts every three to five years. If your address, name, or citizenship status changes in between, the institution may ask you to update your records outside that cycle.
Don’t ignore those requests. When an institution can’t confirm its records are still accurate, it may restrict or freeze your account until you provide the requested documentation. Freezes tied to missing KYC paperwork can last anywhere from a few days to several weeks, and the institution isn’t required to process transactions during that period. The fastest fix is to contact the institution directly, ask exactly which documents they need, and provide them promptly.
If You Don’t Have a Social Security Number
You can use an Individual Taxpayer Identification Number, or ITIN, in place of a Social Security Number. To get an ITIN, you apply through IRS Form W-7. A foreign passport is the only single document that proves both your identity and foreign status on its own; without a passport, you’ll need at least two alternative documents, one of which must include a photograph. A passport without a U.S. entry date stamp is no longer accepted for ITIN purposes.7Internal Revenue Service. Obtaining an ITIN From Abroad
Under the CIP rule, an institution can also accept foreign government-issued identification for a non-U.S. person who doesn’t yet have a taxpayer ID number, as long as the document bears a photograph and is unexpired. The institution may give you a reasonable period to apply for a TIN after the account is opened.
Extra Questions for Higher-Risk and Business Accounts
Standard KYC is a starting point. When an account or customer profile raises red flags, federal rules require the institution to perform Enhanced Due Diligence, or EDD. Triggers include a complicated or opaque ownership structure, a customer based in a country with weak anti-money-laundering controls, account activity that doesn’t match the stated purpose, or a connection to a politically exposed person.
A politically exposed person, or PEP, is anyone who holds or recently held a prominent government role, whether domestic or foreign. Immediate family members and close business associates also qualify. For these accounts, the institution must get senior management approval before opening the relationship, investigate the source of the customer’s wealth, and apply closer ongoing monitoring. If a bank has ever asked unusually detailed questions about where your money came from, this is usually why.
When a business entity opens an account, the institution must also identify the real people behind it. Federal rules require identifying every individual who owns 25 percent or more of the entity, plus at least one person with significant day-to-day control, such as a CEO or managing member.8eCFR. 31 CFR 1010.230 – Beneficial Ownership Requirements for Legal Entity Customers Depending on how ownership is spread, that can mean identifying up to five individuals: four owners and one controller.
Penalties for Providing False Information
Lying on a KYC form isn’t just grounds for losing your account. Under federal law, knowingly making a false statement to influence the action of a federally insured financial institution is a crime punishable by up to $1,000,000 in fines, up to 30 years in prison, or both.9Office of the Law Revision Counsel. 18 USC 1014 – Loan and Credit Applications Generally; Renewals and Discounts; Crop Insurance That statute covers a wide range of financial documents, but it applies to the identity information you provide when opening an account.
Prosecutions under this statute tend to involve people who fabricate identities to launder money or commit bank fraud, not someone who accidentally uses an old address. But the law makes no distinction based on the size of the lie. If you notice an error after submission, correct it with the institution immediately.
How Your KYC Data Is Protected
Handing over your Social Security Number, a passport scan, and your home address understandably raises privacy concerns. Federal law addresses this through the Gramm-Leach-Bliley Act, which requires every financial institution to develop and maintain a written information-security program with administrative, technical, and physical safeguards appropriate to the sensitivity of the data it holds.10Federal Trade Commission. Gramm-Leach-Bliley Act
The FTC’s Safeguards Rule, which implements the GLBA’s security requirements, gets specific. Covered institutions must conduct written risk assessments, implement access controls that limit employee access to only the customer data they need, encrypt customer information both in transit and at rest, and periodically test their security systems for vulnerabilities.11eCFR. 16 CFR Part 314 – Standards for Safeguarding Customer Information Institutions must also explain their information-sharing practices and give you the right to opt out of having your data shared with certain third parties.10Federal Trade Commission. Gramm-Leach-Bliley Act
If a breach does occur, federal guidance directs the institution to notify you, describe what happened, explain what information was exposed, tell you what it’s doing to prevent further harm, provide a phone number you can call, and remind you to watch your accounts closely for the next 12 to 24 months.12FDIC.gov. Final Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice Many states have their own breach-notification laws with shorter timelines and additional requirements, so the protections you actually receive may be stronger than the federal floor.