Customer Identification Programmes: What they are, how they work, and how to use them

Radar
Radar

Fight fraud with the strength of the Stripe network.

Learn more 
  1. Introduction
  2. What is a Customer Identification Program (CIP)?
  3. Benefits of using a Customer Identification Programme
  4. Customer Identification Program requirements
  5. Differences between Customer Identification Programmes and Know Your Customer (KYC)
    1. Customer Identification Program
    2. Know Your Customer
    3. Sample CIP vs. KYC processes
  6. Who needs to follow CIP rules?
  7. How to set up a Customer Identification Programme
    1. 1. Develop a written CIP policy
    2. 2. Collect customer information
    3. 3. Verify customer identity
    4. 4. Compare against government lists
    5. 5. Maintain records
    6. 6. Manage CIPs over time
  8. Best practices for applying Customer Identification Programmes
    1. Technical best practices
    2. Operational best practices
    3. Ethical best practices
  9. How Stripe Radar can help

Customer Identification Programs (CIPs) are a component of financial institutions’ Anti-Money Laundering (AML) efforts. The United Nations estimates that between US$800 billion and US$2 trillion is laundered globally in a single year, and regulations such as the USA PATRIOT Act require the use of CIPs to prevent financial crimes including money laundering and terrorist financing.

CIPs are the first line of defence for financial systems. They ensure that financial systems can verify customer identities, which minimises the risk of illicit activities. These programmes are part of broader customer due diligence (CDD) processes that include ongoing monitoring of customer transactions to detect and report suspicious activities.

Below, we’ll discuss the benefits of using CIPs, how to set up a CIP, and best practices for applying CIPs in your business.

What's in this article?

  • What is a Customer Identification Program (CIP)?
  • Benefits of using a Customer Identification Program
  • Customer Identification Program requirements
  • Differences between Customer Identification Programs and Know Your Customer (KYC)
  • Who needs to follow CIP rules?
  • How to set up a Customer Identification Program
  • Best practices for applying Customer Identification Programs
  • How Stripe Radar can help

What is a Customer Identification Program (CIP)?

A Customer Identification Program (CIP) is a mandatory regulatory framework that requires financial institutions to verify the identity of any person or entity opening an account. Rather than an informal identity check, a CIP is a formal, written operational policy designed to ensure an institution forms a reasonable belief regarding the true identity of every customer it serves.

The CIP requirement was formally established under Section 326 of the USA PATRIOT Act, enacted in 2001 in the wake of 9/11. It was designed to prevent money laundering, terrorist financing, and other financial crimes by ensuring that financial institutions thoroughly vet potential customers before granting system access and continuously flag suspicious transactions.

To satisfy federal compliance standards, every CIP must enforce baseline data collection, identity verification, and government watchlist screening. Additionally, CIPs must retain records and other data for at least five years after an account is closed.

Benefits of using a Customer Identification Programme

CIPs benefit businesses in many different ways. These include:

  • Risk mitigation: CIPs mitigate the risk of financial crimes such as money laundering, terrorist financing, and fraud. By verifying the true identity of their customers, institutions can prevent these illegal activities and avoid potential legal and reputational damage.

  • Regulatory compliance: CIPs are a legal requirement for financial institutions in many countries, including the US. Failure to use CIPs can incur penalties and fines.

  • Stronger security: CIPs create a more secure financial environment by preventing unauthorised access to accounts and services, which protects the institution and its legitimate customers from financial losses.

  • Improved customer due diligence: CIPs enable institutions to perform more effective customer due diligence (CDD), by assessing the risk associated with each customer and tailoring services accordingly.

  • Operational efficiency: While CIPs require an initial investment in systems and processes, they can improve operational efficiency over time. Automating verification processes and simplifying onboarding procedures can save time and resources in the long run.

  • Customer fraud protection: CIPs protect customers from identity theft and fraud by ensuring that only authorised individuals can access their accounts, which safeguards financial assets and personal information.

  • Greater customer trust: Customers are more likely to trust institutions with strong security measures, such as CIPs.

  • Faster onboarding: CIP processes can lead to faster and more convenient onboarding for new customers, improving customer satisfaction and encouraging them to use the institution’s services.

  • Access to more services: CIPs enable institutions to offer customers a wider range of financial products and services. By verifying customer identities, institutions can offer services that might otherwise be restricted due to regulatory concerns.

Customer Identification Program requirements

Under the Bank Secrecy Act (BSA) and Financial Crimes Enforcement Network (FinCEN) regulations, financial institutions must design and execute a written CIP that aligns with their specific risk profile, customer base, and service offerings.

To maintain regulatory compliance, every CIP must satisfy six core legal requirements:

  • A formal written policy: The program must be documented in writing, approved by executive leadership or the board of directors, and fully integrated into the organisation's broader Anti-Money Laundering (AML) compliance framework.

  • Mandatory customer data collection: Before opening an account or granting service access, the institution must collect a customer’s full legal name, date of birth, residential or business address, and Social Security number, taxpayer identification number, or the passport number for foreign individuals.

  • Risk-based identity verification: The program must detail specific procedures for verifying the customer's identity within a reasonable time frame. This includes verification of documents like driver’s licences, and comparing collected data against credit bureaus and public registries.

  • Government watchlist comparison: The institution must check customer identities against federal lists of known or suspected terrorists and sanctions targets, primarily maintained by the Office of Foreign Assets Control (OFAC).

  • Adequate customer notice: Institutions must provide customers with clear, advance notice informing them that the business is required by federal law to request and verify identifying information prior to opening an account.

  • Recordkeeping and data retention: Institutions must maintain a complete audit trail, including all collected customer data, descriptions of documents used for verification, and resolutions of any data discrepancies. These records must be retained for at least five years after the account is closed.

Differences between Customer Identification Programmes and Know Your Customer (KYC)

Customer Identification Programmes (CIPs) and Know Your Customer (KYC) are processes used to identify and verify customers, but they have distinct focuses and scopes. The use of CIPs is a specific regulatory requirement focused on verifying customer identity, while KYC is a broader process encompassing identity verification, risk assessment, and ongoing monitoring. CIP is the initial step in the broader KYC process: while CIP establishes the customer’s identity, KYC goes further by uncovering their financial behaviour and assessing their risk profile.

Customer Identification Program

CIPs focus on verifying the identity of a customer during the onboarding process. The CIP process involves collecting and verifying specific identifying information such as name, date of birth, address, and government-issued identification number. The purpose of CIPs is to establish a reasonable belief that the institution knows the identity of the customer, thereby preventing identity theft and fraud.

Know Your Customer

The KYC process is broader in scope than the CIP process. It encompasses not only identity verification but also an understanding of the customer’s financial activities and risk profile. The primary purpose of KYC is to assess the overall risk associated with a customer and verify that their activities align with the institution’s risk appetite and regulatory requirements. The KYC process involves collecting and analysing a wider range of information than CIPs assess. Typically, the information includes the customer’s occupation, source of funds, transaction history, and risk tolerance.

Sample CIP vs. KYC processes

When opening a bank account, a customer must provide their identification documents (e.g., passport, driver’s licence) to fulfil the CIP requirement. The bank’s KYC process, however, might involve asking about their occupation, income source, and intended use of the account to assess their risk level.

Dimension
Customer Identification Program (CIP)
Know Your Customer (KYC)
Scope Narrow, specific regulatory requirement (Section 326 of USA PATRIOT Act) Broad, end-to-end compliance framework that encompasses CIP, due diligence, and monitoring
Primary objective Establish reasonable proof of a customer's true identity to prevent fraud and identity theft Assess overall customer risk, understand financial behaviour, and detect ongoing money laundering
Timing and cadence One-time execution up-front during the initial onboarding process Continuous process maintained throughout the entire customer lifecycle
Data Required Four baseline identifiers: Legal name, date of birth, physical address, and government ID number Extended profile: Occupation, source of funds or wealth, expected transaction volume, and risk rating
Practical example Submitting a passport or driving licence to verify who you are when opening an account Declaring your income source and having your ongoing account activity monitored for suspicious patterns

Who needs to follow CIP rules?

In many countries, AML guidelines require financial institutions and certain companies to implement CIPs. In the US, for example, a variety of regulatory agencies enforce CIP requirements, including the Financial Crimes Enforcement Network (FinCEN), the Federal Reserve Board, the Federal Deposit Insurance Corp. (FDIC), and the Office of the Comptroller of the Currency (OCC). In addition to the types of companies listed below, other businesses might need to implement a CIP if they engage in financial risk-based activities that are susceptible to money laundering or terrorist financing.

  • Banks: Commercial banks, savings banks, and investment banks

  • Credit unions: Cooperative financial institutions owned and operated by their members

  • Securities brokers and dealers: Firms that buy and sell securities on behalf of clients or for their own accounts

  • Mutual funds: Investment companies that pool money from investors to purchase a diversified portfolio of securities

  • Futures commission merchants: Individuals or firms that solicit or accept orders for the purchase or sale of futures contracts and options on futures contracts

  • Introducing brokers: Individuals or firms that solicit or accept orders for the purchase or sale of futures contracts and options on futures contracts but do not accept money or securities from customers

  • Commodity trading advisors: Individuals or firms that advise others on buying or selling futures contracts and options on futures contracts

  • Commodity pool operators: Individuals or firms that operate commodity pools, which are investment vehicles that pool funds from investors to trade in commodities

  • Money services businesses: Businesses that provide services such as money transmission, cheque cashing, currency exchange, or the sale of money orders or traveller’s cheques

How to set up a Customer Identification Programme

Designing and implementing a CIP involves a series of steps that you will need to customise to your business’s size, scope, and layout. Consider working with legal counsel or compliance experts, who can provide you with guidance on how to establish a CIP. Train your staff on CIP requirements and procedures so they can implement them consistently, and communicate to customers the importance of the CIP.

Below are the basic steps to develop a strong CIP. For more detailed information and specific requirements, refer to the CIP rules and regulations published by the relevant regulatory agencies (e.g., FinCEN, FDIC).

1. Develop a written CIP policy

Outline the specific procedures your institution will follow to collect and verify customer identification information. Specify the types of accounts the CIP will cover (e.g., current accounts, credit accounts) and explain how you will handle exceptions or alternative procedures for certain customers (e.g., those without a National Insurance number).

2. Collect customer information

Obtain the following four pieces of information from each customer:

  • Full legal name

  • Date of birth

  • Residential or business street address

  • Identification number (e.g., Social Security number, passport number)

Collect this information when the customer opens their account, or before the customer can conduct transactions.

3. Verify customer identity

Verify the information the customer provides using independent, reliable sources. Acceptable methods include:

  • Checking government-issued identification documents (e.g., driving licence, passport)

  • Using third-party identity verification services

  • Obtaining information from a consumer reporting agency or public database

Document the verification methods you used and the results of the verification process.

4. Compare against government lists

Check the customer’s name against lists of known or suspected terrorists or other criminals provided by the government (e.g., OFAC’s SDN list). If you find a match, take appropriate action, such as freezing the account and reporting the information to the authorities.

5. Maintain records

Maintain records of all customer identification information and verification results for at least five years after the account is closed. Make these records available to regulators upon request.

6. Manage CIPs over time

Designate a compliance officer or team that will be responsible for overseeing the CIP for your business. This person or team should be in charge of reviewing and updating the CIP policy regularly so it remains effective and complies with any regulatory changes. They should also conduct periodic risk assessments to identify and address any vulnerabilities in the programme.

Best practices for applying Customer Identification Programmes

Follow these best practices – technical, operational, and ethical – to help your business apply CIPs effectively.

Technical best practices

  • Unique and consistent IDs: Assign each customer a unique identifier that remains consistent across all interactions and platforms. This identifier could be a randomly generated number, a hashed email address, or a combination of relevant information.

  • Secure storage: Protect customer IDs using encryption and secure storage methods. Limit access to authorized personnel only.

  • Data integration: Integrate customer IDs across all systems and databases within your company to create a holistic view of the customer that facilitates personalised experiences.

  • Data quality: Maintain accurate and current customer ID information. Implement data validation and cleansing processes for consistency and reliability.

  • Scalability: Choose a customer ID system that can scale with your business and handle large volumes of data.

Operational best practices

  • Consent: Obtain explicit consent from customers before collecting and using their IDs.

  • Privacy protection: Implement privacy-enhancing technologies to anonymise customer IDs or use pseudonyms.

  • Data minimisation: Collect only the minimum customer information you need for legitimate business purposes. Avoid collecting sensitive data unless absolutely necessary.

  • Access control: Establish strict access controls and audit trails for customer ID data. Limit access to authorized personnel only and monitor usage.

  • Incident response plan: Develop a comprehensive incident response plan to address any data breaches or security incidents involving customer IDs.

Ethical best practices

  • Customer autonomy: Empower customers by giving them control over their data. Allow customers to access, update, or delete their information at any time.

  • Nondiscrimination: Never use customer IDs to discriminate against or unfairly profile individuals based on their personal attributes or behaviour.

  • Transparency: Use customer IDs in a fair and transparent manner. Communicate to customers how you will use these IDs and avoid any deceptive or misleading practices.

  • Accountability: Take responsibility for the ethical use of customer IDs. Implement regular audits and reviews for compliance with best practices and ethical standards.

How Stripe Radar can help

Stripe Radar uses AI models to detect and prevent fraud, trained on data from Stripe's global network. It continuously updates these models based on the latest fraud trends, protecting your business as fraud evolves.

Stripe also offers Radar for Fraud Teams, which allows users to add custom rules addressing fraud scenarios specific to their businesses and access advanced fraud insights.

Radar can help your business:

  • Prevent fraud losses: Stripe processes over US$1.9 trillion in payments annually. This scale uniquely enables Radar to help detect and prevent fraud, saving you money.

  • Increase revenue: Radar's AI models are trained on actual dispute data, customer information, browsing data and more. This enables Radar to identify risky transactions and reduce false positives, boosting your revenue.

  • Save time: Radar is built into Stripe and requires zero lines of code to set up. You can also monitor your fraud performance, write rules and more in a single platform, increasing efficiency.

Learn more about Stripe Radar or get started today.

The content in this article is for general information and education purposes only and should not be construed as legal or tax advice. Stripe does not warrant or guarantee the accuracy, completeness, adequacy, or currency of the information in the article. You should seek the advice of a competent lawyer or accountant licensed to practise in your jurisdiction for advice on your particular situation.

More articles

  • Something went wrong. Please try again or contact support.

Ready to get started?

Create an account and start accepting payments – no contracts or banking details required. Or, contact us to design a custom package for your business.
Radar

Radar

Fight fraud with the strength of the Stripe network.

Radar docs

Use Stripe Radar to protect your business against fraud.