SardineCon SF/2026

Learn More

O que é Customer Identification Program (CIP)?

SUBSCRIBE

CIP is the minimum US requirement to collect and verify core identifying details, such as name, date of birth, address, and an ID number, at onboarding. It is the identity floor beneath fuller due diligence: necessary, but on its own it says nothing about whether a customer is actually who you want.

What is CIP, in plain English?

A Customer Identification Program is the baseline identity check that US financial institutions must perform when opening an account. Under the framework tied to the USA PATRIOT Act, the firm has to collect certain core details, typically name, date of birth, address, and an identification number, and then verify enough of them to form a reasonable belief that it knows the customer's true identity.

CIP is deliberately a floor, not a ceiling. It establishes the minimum identity information every customer must provide, and it sits beneath the broader customer due diligence that assesses risk, purpose, and ownership. Think of it as the first, mandatory rung: confirming that the customer is who they claim to be, in a documented and consistent way.

The critical limit is that CIP confirms identity but does not assess risk or beneficial ownership. A customer can clear CIP with entirely real-looking data and still be a synthetic identity or a mule. Passing CIP tells you the details match; it tells you nothing about whether the person behind them is someone you actually want as a customer. Verification of details is not the same as trust.

CIP versus full CDD

What it does

CIP alone

Full CDD

Confirms identity

Yes, core details collected and verified.

Yes, and builds on it.

Assesses risk

No.

Yes, drives the customer risk rating.

Understands purpose

No.

Yes, captures expected activity.

Checks ownership

No.

Yes, identifies beneficial owners.

What it looks like in practice

In practice

An applicant opens an account with a name, date of birth, address, and Social Security number that all check out against the data sources. CIP passes cleanly, and to a checklist-driven process the customer looks fully verified.

What CIP cannot see is that the identity is synthetic: a real number belonging to someone else, stitched to a fabricated name and a rented address. Only the risk-based layers on top, expected-activity analysis, device signals, and later monitoring, catch the mismatch. The lesson operators internalize is that a clean CIP result is a starting point, not a verdict on whether the customer is genuine.

Why it matters to operators

CIP is the legal identity baseline in the US, and getting it right is non-negotiable: the required elements have to be collected, verified, and documented for every customer. It gives the firm a consistent, defensible record that it confirmed identity at onboarding, which is the first thing an examiner will check.

But the operational trap is treating a CIP pass as sufficient. CIP answers whether the details are real and consistent; it does not answer whether the identity is synthetic, whether the account is a mule, or how risky the relationship is. Someone can clear CIP with convincing data and still be exactly the person the program was built to keep out. Treat CIP as necessary but not sufficient, and layer risk assessment and monitoring on top.

What to watch

  • CIP as the whole answer. Treating a passing identity check as proof the customer is safe skips the risk assessment CIP does not do.
  • Synthetic identities. Real-looking data assembled from mismatched elements can clear CIP while hiding a fabricated person.
  • No ownership check. CIP does not identify beneficial owners, so business accounts still need separate ownership diligence.
  • Weak verification method. Collecting details but verifying them thinly undermines the reasonable-belief standard CIP requires.
  • Documentation gaps. Failing to record what was collected and how it was verified is a common and avoidable exam finding.

Quick questions

What does CIP require?

Collecting core identifying details, typically name, date of birth, address, and an identification number, and verifying enough of them to form a reasonable belief that you know the customer's true identity, all documented.

How is CIP different from CDD?

CIP is the identity floor: confirm who the customer claims to be. CDD is broader: assess risk, understand purpose, and identify ownership. CIP is one required component within the wider due diligence process.

Can a synthetic identity pass CIP?

Yes. Synthetic identities are built from real-looking, internally consistent data specifically to clear identity checks. CIP confirms the details are valid, not that the person behind them exists, which is why it is necessary but not sufficient.

Does CIP cover beneficial ownership?

No. CIP verifies the identity of the customer opening the account. Identifying the beneficial owners of a business is a separate requirement handled under the wider CDD rules.

Is CIP a US-only concept?

The term and its specific requirements come from the US framework. Other countries have equivalent identity-verification obligations at onboarding, but CIP as a named program is the US formulation.

What should sit on top of CIP?

Risk assessment, expected-activity capture, beneficial ownership checks, screening, and ongoing monitoring. CIP confirms identity; the risk-based layers on top decide whether the verified customer is one you should keep.

Go deeper

  • FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

O que saber junto com Customer Identification Program (CIP)