5 min read

What Is a Customer Identification Program (CIP), and How Do Digital Credentials Change It?

The Customer Identification Program rule requires banks to verify customer identity at account opening. The FinCEN ruling changes what counts as acceptable evidence.

What Is a Customer Identification Program (CIP), and How Do Digital Credentials Change It?

A Customer Identification Program (CIP) is the set of procedures a bank uses to verify the identity of every person who opens an account. It is required by federal law, and it applies to every bank and credit union in the United States.

The CIP rule is codified at 31 CFR 1020.220, implementing Section 326 of the USA PATRIOT Act. It was enacted in 2003 and has not been substantially amended since. Until recently, the rule operated in a world of physical documents. On September 8, 2026, FinCEN and four federal banking regulators issued joint FAQs confirming that verifiable digital credentials now qualify as acceptable identification evidence under the same rule.

This article explains what the CIP rule requires, what counts as acceptable identity evidence, and what changes now that digital credentials are part of the picture.

What the CIP rule requires

The CIP rule requires banks to establish written procedures for verifying customer identity at account opening. The procedures must enable the bank to "form a reasonable belief that it knows the true identity of each customer."

At minimum, the bank must collect four identifying data elements from each individual customer:

  • Name
  • Date of birth
  • Address (residential or business street address for U.S. persons; for non-U.S. persons, an address plus one of: taxpayer identification number, passport number and country of issuance, or alien identification card number)
  • Identification number (for U.S. persons, this is a taxpayer identification number, typically a Social Security number)

Collecting these data elements is the first step. The bank must then verify the customer's identity using the information collected. The rule allows two categories of verification methods: documentary and non-documentary.

Documentary vs. non-documentary verification

This distinction matters for understanding how digital credentials fit into the CIP framework.

Documentary verification means verifying identity through documents. The rule permits banks to rely on "a document...that evidences nationality or residence and bearing a photograph or similar safeguard, such as a driver's license or passport." For non-individuals, acceptable documents include certified articles of incorporation, government-issued business licenses, and similar instruments.

The key characteristics of acceptable documentary evidence for individuals: the document must be unexpired, it must be government-issued, it must evidence nationality or residence, and it must include a photograph or comparable safeguard. Physical driver's licenses and passports have been the standard examples for two decades.

Non-documentary verification means confirming identity through methods other than documents. The rule permits banks to use approaches such as contacting the customer directly, comparing the customer's information against consumer reporting agency databases or public records, checking references with other financial institutions, or obtaining financial statements. Non-documentary methods are required when the bank cannot obtain documents, when the bank is not satisfied with the documents provided, or when the account is opened remotely and the bank has not been able to verify documents.

Banks are not required to use both methods, but their CIP must describe when they will use each approach and must include procedures for situations where documentary verification is not possible.

What the FinCEN FAQ changes

The September 2026 FAQ does not amend the CIP rule. It clarifies how the existing rule applies to a new category of evidence: verifiable digital credentials.

The FAQ defines a VDC as "a data structure containing information about an individual that is digitally signed by the issuing source, cryptographically bound to a device, and protected by an activation factor." An activation factor is something the holder knows (such as a PIN) or a biometric (such as a fingerprint or facial recognition).

Two key clarifications follow from this definition.

Government-issued VDCs qualify as documentary evidence. An unexpired, government-issued VDC, such as a state mobile driver's license, satisfies the CIP rule's documentary verification standard. It evidences nationality or residence, includes a photograph, and is issued by a government authority. This places government VDCs in the same category as physical driver's licenses and passports. Banks can accept them in person, online, or through any digital channel.

Non-government VDCs are limited to non-documentary verification. VDCs issued by private-sector entities, such as employers or financial institutions, do not qualify as documentary evidence under the CIP rule. However, they may be used as a non-documentary verification method, similar to how banks use consumer reporting agency data or other third-party information to corroborate identity. When using non-government VDCs this way, the bank must ensure the issuer's authentication standards meet the bank's own risk-based requirements.

This distinction between government and non-government credentials is important. It preserves the CIP rule's existing framework while extending it to digital formats. Government authority still matters for documentary evidence. Private-sector credentials can supplement but not replace government-issued identification for that purpose.

What actually changes for banks in practice

The rule change is permissive. The joint FAQ explicitly states that the CIP rule "neither requires nor prohibits" relying on VDCs. Banks now have the option to accept digital credentials; they are not obligated to.

For banks that choose to accept VDCs, the practical implications span operations, technology, and compliance.

The bank's written CIP must be updated to describe when and how it will accept VDCs, which types it will accept, and what verification steps it will perform. Examiners will evaluate whether these procedures are reasonable and consistent with the bank's risk profile. On the technology side, as FinCEN's confirmation that banks can accept verifiable digital credentials makes clear, accepting a VDC is not the same as verifying one. Proper verification requires cryptographic signature validation, revocation checking, device binding confirmation, and activation factor assurance. Banks need infrastructure to perform these checks, either built internally or obtained from verification service providers.

The FAQ also confirms VDC acceptance across in-person, remote, and digital account opening, and each channel presents different technical requirements. In-person verification may use NFC or QR code presentation, while online verification requires browser-based or app-based credential presentation protocols. Banks will need to integrate VDC verification into each channel separately. Finally, bank staff, compliance teams, and auditors will need training on what a VDC is, how verification works, and how to document VDC-based identity checks for regulatory examination.

The bigger picture: from scanning documents to verifying credentials

The CIP rule has operated for over two decades on the assumption that identity verification means inspecting a document. That model has well-known weaknesses: physical documents can be forged, photocopies lose security features, and remote document verification often relies on image analysis rather than cryptographic proof.

VDCs offer a structurally stronger verification model. A credential that is digitally signed by a state DMV, bound to the holder's device, and unlocked by a biometric provides mathematical certainty about its origin and integrity. No visual inspection of a physical document provides equivalent assurance.

The FinCEN FAQ does not mandate this transition. But by recognizing VDCs as valid documentary evidence, it establishes the regulatory foundation for banks to move from document-based to credential-based identity verification. Over time, as more states issue mDLs and more banks build verification infrastructure, this shift will likely become the standard rather than the exception.

For compliance teams, technology leaders, and CISOs evaluating their institution's CIP roadmap, the September 2026 FAQ is the starting point. The regulatory permission exists. The question now is implementation.

Building digital services that scale take the right foundation.
Talk to our team

About SpruceID: SpruceID builds digital trust infrastructure for government. We help states and cities modernize identity, security, and service delivery — from digital wallets and SSO to fraud prevention and workflow optimization. Our standards-based technology and public-sector expertise ensure every project advances a more secure, interoperable, and citizen-centric digital future.