A customer identification program is the written part of KYC that most firms have and few firms reread. It says what information you collect from a customer, how you verify it, what you record, and how long you keep it. Because it is a written policy rather than a screen, it is the thing that quietly drifts away from what the firm actually does, and the gap between the two is what an examiner finds.
What the programme has to say
At minimum it names the information collected from a customer, which typically includes name, date of birth for an individual, address and an identifying number. It says how that information is verified, whether through documents, through non-documentary methods, or both. It says what happens when verification fails. And it says what is recorded and for how long. The point of writing it down is that it makes the standard the same on a busy Friday as it is on a quiet Tuesday.
Verification and identification are two steps, not one
Collecting a customer's details is identification. Satisfying yourself that the details belong to a real person who is the person in front of you is verification, and it is where the actual work lives. Firms that treat the two as one step tend to have complete records that verify nothing, which is worse than an incomplete record because it looks finished. Whatever method you use, the file should say which method was used for that customer, not only that the box was ticked.
The retention rule is longer than most people assume
Identifying information obtained about a customer has to be retained for five years after the date the account is closed, and records of the verification methods used are kept on their own clock. That is a long time for evidence to live in a mailbox or on the laptop of somebody who has since left. It is the practical reason a customer identification program needs a system of record rather than a shared folder, well before anyone thinks about examinations.
Questions people ask about customer identification program
Does a customer identification program apply to us?
That depends on what kind of firm you are, and it is a question for your policy and your counsel rather than for a software page. What is generally true is that firms with a CIP obligation are expected to have it in writing and to follow what it says, and that following it is easier to demonstrate when the evidence lives on a record with dates.
What is the difference between a CIP and CDD?
CIP is the identification piece: who the customer is and how you verified it. CDD is the wider judgement built on top, including the risk rating, the beneficial owners behind a company customer and the ongoing review. CIP is a step inside CDD rather than an alternative to it.
What should customer identification program software actually do?
Hold the collected information against the customer, record which verification method was used and when, keep the result for as long as the retention rule requires, and make the whole thing producible in one action. If it does those four things it is doing its job; the rest is convenience.