2004-01-08
Added
The Agencies issue frequently asked questions regarding the application of 31 C.F.R. § 103.121, which implements section 326 of the USA PATRIOT Act and requires banks, savings associations, credit unions, and certain non-federally regulated banks to maintain a Customer Identification Program. The guidance clarifies that the rule applies to formal banking relationships such as loans and deposit accounts, defining the customer as the person opening the account, while excluding foreign subsidiaries and non-bank holding companies from the specific bank CIP rule. Banks are required to implement risk-based procedures to verify customer identity and must ensure compliance for new accounts, including those opened by minors or through assumed loans, though existing account holders are exempt upon renewal if identity is already known.
In June 2026, this document was revised to remove references to reputational risk. FAQs: Final CIP Rule The staff of the Board of Governors of the Federal Reserve System, Federal Deposit Insurance Corporation, Financial Crimes Enforcement Network, National Credit Union Administration, Office of the Comptroller of the Currency, Office of Thrift Supervision, and the United States Department of the Treasury (“Agencies”) are issuing these frequently asked questions (“FAQs”) regarding the application of 31 C.F.R. § 103.121. This joint regulation implements section 3261 of the USA PATRIOT Act and requires banks, savings associations, credit unions and certain non-federally regulated banks (“bank”) to have a Customer Identification Program (“CIP”). While the purpose of the FAQs document is to provide interpretive guidance with respect to the CIP rule, the Agencies recognize that this document does not answer every question that may arise in connection with the rule. The Agencies encourage banks to use the basic principles set forth in the CIP rule, as articulated in these answers, to address variations on these questions that may arise, and expect banks to design their own programs in accordance with the nature of their business. The Agencies wish to emphasize that a bank’s CIP must include risk-based procedures for verifying the identity of each customer to the extent reasonable and practicable. It is critical that each bank develop procedures to account for all relevant risks including those presented by the types of accounts maintained by the bank, the various methods of opening accounts provided, the type of identifying information available, and the bank’s size, location, and type of business or customer base. Thus, specific minimum requirements in the rule, such as the four basic types of information to be obtained from each customer, should be supplemented by risk-based verification procedures, where appropriate, to ensure that the bank has a reasonable belief that it knows each customer’s identity. The Agencies note that the CIP, while important, is only one part of a bank’s BSA/AML compliance program. Adequate implementation of a CIP, standing alone, will not be sufficient to meet a bank’s other obligations under the BSA, regulations promulgated by its primary Federal regulator, such as Suspicious Activity Reporting requirements, or regulations promulgated by the Office of Foreign Assets Control. Finally, these FAQs have been designed to help banks comply with the requirements of the CIP rule. They do not address the applicability of any other Federal or state laws. 31 C.F.R. § 103.121(a)(1) -- Definition of “account”
2 account is a loan, the account is opened when the bank enters into an enforceable agreement to provide a loan to the customer. (January 2004) 2. Are loan participations purchased from third parties and loans purchased from a car dealer or mortgage broker within the exclusion from the definition of “account” for loans acquired through an acquisition, merger, purchase of assets, or assumption of liabilities? Yes, this exclusion is intended to cover loan participations purchased from third parties and loans purchased from a car dealer or mortgage broker. If, however, the bank is extending credit to the borrower using a car dealer or mortgage broker as its agent, then it must ensure that the dealer or broker is performing the bank’s CIP. (January 2004) 3. Are data processing, data warehousing, and data transmission on behalf of a person an “account?” “Account” is defined to mean “a formal banking relationship established to provide or engage in services, dealings, or other financial transactions including a deposit account, a transaction or asset account, a credit account, or other extension of credit. Account also includes a relationship established to provide a safety deposit box or other safekeeping services, or cash management, custodian and trust services.” The examples provided in 31 C.F.R. § 103.121(a)(1) of formal banking relationships included within the meaning of “account” focus on bank products and services that relate to the deposit, lending or custody of funds or other assets on behalf of a customer. Data processing, warehousing, and transmission services generally do not involve a service, dealing, or financial transaction that, taken alone, constitutes a “formal banking relationship” within the meaning of 31 C.F.R. § 103.121(a)(1). If, however, any of these services are part of the establishment of a formal banking relationship, then the CIP rule in 31 C.F.R. § 103.121 would apply. (April 2005) 31 C.F.R. § 103.121(a)(2) -- Definition of “bank”
3 Similarly, a non-bank subsidiary of a bank holding company is not subject to the CIP rule for banks solely as a result of being affiliated with a bank in a holding company structure. However, a non-bank subsidiary may be subject to one of the other CIP rules. Even if a bank holding company is not itself subject to the CIP rule under 31 C.F.R. § 103.121, it should, as a matter of safety and soundness, take appropriate measures throughout its organization to ensure that each entity is in compliance with any applicable CIP rule, to ensure that new accounts receive appropriate due diligence, and generally to protect the consolidated organization from risks associated with money laundering and financial crime. The analysis set forth above is equally applicable to savings and loan holding companies and their non-savings association subsidiaries. (April 2005) 3. Should subsidiaries of a bank implement a customer identification program? Yes. The Federal banking agencies take the position that implementation of customer identification programs by subsidiaries of banks is appropriate as a matter of safety and soundness. Subsidiaries (other than functionally regulated subsidiaries) of banks should comply with the customer identification program rule that applies to the parent bank when opening an account within the meaning of 31 C.F.R. § 103.121. In addition, a number of the Federal banking agencies have separately issued rules that require certain subsidiaries of banks to conduct their activities pursuant to the same terms and conditions that apply to the conduct of such activities by the parent bank. See, e.g., 12 C.F.R. § 5.34 (OCC); 12 C.F.R. § 559.3(h) (OTS). Some functionally regulated subsidiaries of banks are already subject to a customer identification program rule issued jointly by their functional regulator and FinCEN (i.e., 31 C.F.R. § 103.122 (broker-dealers); 31 C.F.R. § 103.131 (mutual funds); and 31 C.F.R. § 103.123 (futures commission merchants and introducing brokers)). For purposes of the requirements imposed under section 326 of the USA PATRIOT Act, functionally regulated subsidiaries are: brokerdealers, investment companies, investment advisers registered with the SEC, persons licensed to provide insurance, and any entity with respect to a financial activity that is subject to the jurisdiction of the CFTC (such as futures commission merchants, introducing brokers, commodity trading advisors, commodity pools, and commodity pool operators). See 31 U.S.C. § 5318(l)(4); 15 U.S.C. §§ 6805, 6809. Subsidiaries of banks that are functionally regulated by the SEC or the CFTC are required to comply with the applicable CIP rules issued by the SEC or CFTC, respectively, and FinCEN. The Federal banking agencies, SEC, CFTC, Department of the Treasury, and FinCEN have worked together to create uniform rules that minimize potential conflicts or differences between the agencies’ rules. In addition, Treasury and FinCEN intend to issue customer identification program rules applicable to other types of financial institutions in the future. (April 2005)
4 31 C.F.R. § 103.121(a)(3) -- Definition of “customer”
5 imposed on the plan administrator under EGTRRA, as well as the requirements in connection with plan terminations, the former employee will not be deemed to have “opened a new account” for purposes of the CIP rule until he or she contacts the bank to assert an ownership interest over the funds, at which time a bank will be required to implement its CIP with respect to the former employee. This interpretation applies only to (1) transfers of funds as required under section 657(c) of EGTRRA, and (2) transfers to banks by administrators of terminated plans in the name of participants that they have been unable to locate, or who have been notified of termination but have not responded, and should not be construed to apply to any other transfer of funds that may constitute opening an account. (January 2004) 5. A bank is an agent for a (bank) credit card issuer. The cards are co-branded, the two banks share in the revenue from the cards issued. However, the issuer approves the credit card applications and handles collections. Is a person who obtains a credit card a customer of the agent bank or the card issuer? A person who receives a credit card is receiving an extension of credit from, and therefore is establishing an account with, the issuing bank. The agent bank is compensated by the issuing bank and not by the customer. For these reasons, the issuing bank is responsible for ensuring that its CIP applies to the customer. However, the agent bank may perform parts of the CIP on behalf of the issuing bank. As with any other responsibility performed by an agent, the issuing bank ultimately is responsible for the agent’s compliance with the requirements of the CIP rule. See 68 FR 25090, 25104 (May 9, 2003). Alternatively, the issuing bank may rely upon the agent bank to perform elements of its CIP, provided that the issuing bank is able to satisfy the requirements of the reliance provision, 31 C.F.R. § 103.121(b)(6), including the requirement that the person be a customer of both the issuing and agent bank. (January 2004) 6. Does the CIP rule prohibit a minor from opening an account? No, the CIP rule does not bar a minor from opening an account. It merely states that the bank’s “customer” is the individual who opens the account for an individual who lacks legal capacity, such as a minor. In other words, if a parent opens an account for a minor, the bank’s customer is the parent. If, however, a minor opens the account, then the minor is the bank’s customer. For example, where a bank sends its employees to elementary schools so that students may open savings accounts as part of a program to promote financial literacy, a student opening an account is the bank’s customer. In this situation, as for all customers, the bank should get the name, address, date of birth, and taxpayer identification number of the student. Since verification procedures are risk-based, banks can use any reasonable documentary or non-documentary method to verify a student’s identity. In this case, the bank might verify a student’s identity using a student identification card or by having the student’s teacher confirm the student’s identity. (April 2005) 7. The definition of “account” excludes accounts opened for the purpose of participating in an employee benefit plan established under the Employee Retirement Income Security Act of 1974 (ERISA). In the case of a trust, custodial, or other administrative account
6 established by an employer at a bank to maintain and administer assets under a nonERISA employee retirement, benefit, or deferred compensation plan, who is the bank's "customer?" Is a participant in or beneficiary of such an account the “customer?” In the case of these accounts (including, for example, accounts established by governmental entities to administer retirement or benefit plans or by employers to administer stock option or restricted stock plans) that are established as trusts, the bank’s “customer” will be the trust established by the employer to maintain the assets. If the account is not a trust, the bank’s “customer” will be the employer that contracts with the bank to establish the account.* Based on the bank's risk assessment of any new account opened by a customer that is not an individual, the bank may need "to obtain information about" individuals with authority or control over such an account, including signatories, in order to verify the customer's identity. See 31 C.F.R. § 103.121(b)(2)(ii)(C). For purposes of the CIP rule, a participant in or beneficiary of such an account will not be deemed to be the bank’s “customer,” as such a person will not have initiated the relationship with the bank. The account will not be considered opened by the employee even if a subaccount is maintained in the employee’s name, or the employee is able to make deposits into the account, so long as such ability to make deposits is limited to rolling over assets from another plan, purchasing securities or exercising options to purchase securities issued by the employer, or repaying a loan, in accordance with the terms of the plan. By contrast, where an individual opens an individual retirement account in a bank, the individual who opens the account is the bank's "customer." (April 2005)
7 verify the identities of beneficiaries and instead will only be required to verify the identity of the named accountholder.” See 68 FR 25090, 25094 (May 9, 2003). However, the CIP rule also provides that, based on the bank’s risk assessment of a new account opened by a customer that is not an individual, the bank may need “to obtain information about” individuals with authority or control over such an account, including signatories, in order to verify the customer’s identity. See 31 C.F.R. § 103.121(b)(2)(ii)(C). For example, in certain circumstances involving revocable trusts, the bank may need to gather information about the settlor, grantor, trustee, or other persons with the authority to direct the trustee, and who thus have authority or control over the account, in order to establish the true identity of the customer. (April 2005) 10. Who is the “customer” for purposes of escrow accounts? An escrow account is an account generally established for the deposit of funds that are to be paid to a specified party on the fulfillment of escrow conditions or returned. If a bank establishes an account in the name of a third party, such as a real estate agent, who is acting as escrow agent, then the bank’s customer will be the escrow agent. If the bank is the escrow agent, then the person who establishes the account is the bank’s “customer.” For example, if the purchaser of real estate directly opens an escrow account and deposits funds to be paid to the seller upon satisfaction of specified conditions, the bank’s customer will be the purchaser. Further, if a company in formation establishes an escrow account for investors to deposit their subscriptions pending receipt of a required minimum amount, the bank’s customer will be the company in formation (or if not yet a legal entity, the person opening the account on its behalf). “A bank will not be required to look through trust, escrow, or similar accounts to verify the identities of beneficiaries and instead will only be required to verify the identity of the named accountholder.” See 68 FR 25090, 25094 (May 9, 2003). However, the CIP rule also provides that, based on the bank’s risk assessment of a new account opened by a customer that is not an individual, the bank may need “to obtain information about” individuals with authority or control over such an account, including signatories, in order to verify the customer’s identity. See 31 C.F.R. § 103.121(b)(2)(ii)(C). (April 2005) 31 C.F.R. § 103.121(a)(3)(ii)(C) – Person with an existing account
8 reasonable belief that it knows the person’s true identity, the bank need not perform its CIP when a loan is renewed or certificate of deposit is rolled over. However, if a new customer is added to the loan or deposit account, the bank would need to satisfy the CIP rule with respect to that new account relationship. (January 2004) 2. Does the exclusion from the definition of “customer” in 31 C.F.R. § 103.121(a)(3)(ii)(C) for a person with an existing account extend to a person who has had an account with the bank in the last twelve months but who no longer has an account? No, this provision only excludes from the definition of “customer” a person that at the time a new account is opened currently “has an existing account with the bank,” and only if the bank has a reasonable belief that it knows the true identity of the person. Therefore, for example, when a person has a deposit account and subsequently obtains a loan, the person has an existing account with the bank. Conversely, a person would not be deemed to have an existing account at the bank if the person had a loan, paid it off, and twelve months later obtains a new loan. (January 2004) 3. How can a bank demonstrate that it has “a reasonable belief that it knows the true identity of a person with an existing account” with respect to persons that had accounts with the bank as of October 1, 2003? Among the ways a bank can demonstrate that it has “a reasonable belief” is by showing that prior to the issuance of the final CIP rule, it had comparable procedures in place to verify the identity of persons that had accounts with the bank as of October 1, 2003, though the bank may not have gathered the very same information about such persons as required by the final CIP rule. Alternative means include showing that the bank has had an active and longstanding relationship with a particular person, evidenced by such things as a history of account statements sent to the person, information sent to the IRS about the person’s accounts without issue, loans made and repaid, or other services performed for the person over a period of time. This alternative, however, may not suffice for persons that the bank has deemed to be high risk. (January 2004) 4. Can a bank exclude from the definition of “customer” a person that has an existing account with its affiliate? No, a person that has an existing account with a bank affiliate does not qualify as “a person who has an existing account with the bank” within the meaning of 31 C.F.R. § 103.121(a)(3)(ii)(C). However, the bank may be able to rely on its affiliate to perform elements of its CIP, as provided in 31 C.F.R. § 103.121(b)(6). (January 2004) 31 C.F.R. § 103.121(b)(2)(i) -- Information required
9 Yes, the number on the roadside mailbox on a rural route is acceptable as an address. A rural route number, unlike a post office box number, is a description of the approximate area where the customer can be located. In the absence of such a number, and in the absence of a residential or business address for next of kin or another contact individual, a description of the customer’s physical location will suffice. (January 2004) 2. Can a bank open an account for a U.S. person that does not have a taxpayer identification number? No, the bank cannot unless the customer has applied for a taxpayer identification number, the bank confirms that the application was filed before the customer opened the account, and the bank obtains the taxpayer identification number within a reasonable period of time after the account is opened. Note, however, that a bank does not need to obtain a taxpayer identification number when opening a new account for a customer that has an existing account, as long as the bank has a reasonable belief that it knows the true identity of the customer. A bank may also open an account for a person who lacks legal capacity with the identifying information, including taxpayer identification number, of an individual who opens an account for that person. (January 2004) 3. The CIP rule requires a bank to obtain a taxpayer identification number from the customer prior to opening an account from a customer that is a U.S. person. When the bank’s customer is a trust, what taxpayer identification number should the bank obtain? The taxpayer identification number for a trust is the trust’s employer identification number (EIN). If the trust is not required to have an EIN under the tax laws, then the bank may obtain the grantor’s taxpayer identification number, consistent with section 6109 of the Internal Revenue Code and the regulations thereunder. (April 2005) 31 C.F.R. § 103.121(b)(2)(ii) -- Customer verification
10 expectation that banks will obtain government-issued identification from most customers. However, other forms of identification may be used if they enable the bank to form a reasonable belief that it knows the true identity of the customer. Nonetheless, given the availability of counterfeit and fraudulently obtained documents, a bank is encouraged to obtain more than a single document to ensure that it has a reasonable belief that it knows the customer’s true identity. (January 2004) 3. Can a bank use an electronic credential, such as a digital certificate, as a nondocumentary means to verify the identity of a customer that opens an account over the Internet or through some other purely electronic channel? A bank may obtain an electronic credential, such as a digital certificate, as one of the methods it uses to verify a customer’s identity. However, the CIP rule requires the bank to have a reasonable belief that it knows the true identity of the customer. Therefore, for example, the bank is responsible for ensuring that the third party uses the same level of authentication as the bank itself would use. See also FFIEC guidance titled “Authentication in an Electronic Banking Environment” (July 30, 2001). (January 2004) 4. How should a bank verify the identity of a partnership that opens a new account when there are no documents or non-documentary methods that will establish the identity of the partnership? A bank opening an account for such a partnership must undertake additional verification by obtaining information about the identity of any individual with authority or control over the partnership account, in order to verify the partnership’s identity, as described in 31 C.F.R. § 103.121(b)(2)(ii)(C). (January 2004) 5. How should a bank verify the identity of a sole proprietorship that opens a new account, (such as an account titled in the name of an individual “doing business as” a sole proprietorship) when there are no documents or non-documentary methods that will establish the identity of the sole proprietorship? In some states, sole proprietorships are required to file “fictitious” or “assumed name certificates.” Banks may choose to use these certificates as a means to verify the identity of a sole proprietorship, if appropriate. However, when there are no documents or non-documentary methods that will establish the identity of the sole proprietorship, the bank must undertake additional verification by obtaining information about the sole proprietor or any other individual with authority or control over the sole proprietorship account -- such as the name, address, date of birth, and taxpayer identification number of the sole proprietor, or any other individual with authority or control over the account -- in order to verify the sole proprietorship’s identity, as described in 31 C.F.R. § 103.121(b)(2)(ii)(C). (January 2004) 31 C.F.R. § 103.121(b)(3)(i) – Required records
11 detection system) in a general policy or procedure instead of recording the fact that a particular method was used on each individual customer's record? Yes, provided that the record cross-references the specific provision(s) of the risk-based procedures contained in the bank’s CIP used to verify the customer’s identity. (January 2004) 2. Can a bank keep copies of documents provided to verify a customer’s identity, in addition to the description required under 31 C.F.R. § 103.121(b)(3)(i)(B), even if it is not required to do so? Yes, a bank may keep copies of identifying documents that it uses to verify a customer’s identity. A bank’s verification procedures should be risk-based and, in certain situations, keeping copies of identifying documents may be warranted. In addition, a bank may have procedures to keep copies of documents for other purposes, for example, to facilitate investigating potential fraud. (These documents should be retained in accordance with the general recordkeeping requirements in 31 C.F.R. § 103.38.) Nonetheless, a bank should be mindful that it must not improperly use any document containing a picture of an individual, such as a driver’s license, in connection with any aspect of a credit transaction. (January 2004) 31 C.F.R. § 103.121(b)(3)(ii) – Retention of records
12 If several accounts are opened for a customer simultaneously, all identifying information about a customer obtained under 31 C.F.R. § 103.121(b)(2)(i) must be retained for five years after the last account is closed or, in the case of credit card accounts, five years after the last account is closed or becomes dormant. All remaining records must be kept for five years after the records are made. (January 2004) 4. How does the record retention period apply to a situation where a bank sells a loan but retains the servicing rights to the loan? When a bank sells a loan, the account is “closed” under the record retention provision (31 C.F.R. § 103.121(b)(3)(ii)), regardless of whether the bank retains the servicing rights to the loan. Thus, a bank should keep the records of identifying information about a customer for five years after the date that the loan is sold, as required by 31 C.F.R. § 103.121(b)(3)(i)(A). Any other record required by 31 C.F.R. § 103.121(b)(3)(i) must be kept for five years after the record is made. (April 2005) 31 C.F.R. § 103.121(b)(4) -- Section 326 List
13 notice on the loan application given to the customer, orally providing the notice, or by providing the notice in any manner that is reasonably designed to ensure that the customer is given notice before opening an account. (January 2004) 31 C.F.R. § 103.121(b)(6) -- Reliance