A shorter application can still be a difficult journey
Removing a field from an application can reduce effort, particularly on a mobile phone. But if the missing information is retrieved inaccurately, the customer may face a more confusing problem later. The useful outcome is a correctly opened, usable account. Completion of an initial screen is only one step toward that result.
FinCEN’s 2025 exemption permits covered banks to obtain tax identification number information from a third party, subject to the remaining Customer Identification Program requirements. Use is optional, and the release states that the TIN must be obtained before account opening. The flexibility changes how information can be collected; it does not eliminate the need to form a reasonable belief about the customer’s identity. [1]
A narrow exemption, not a repeal of CIP
On June 27, 2025, FinCEN issued an order with the OCC, FDIC and NCUA permitting institutions within the order’s scope to obtain taxpayer identification number information from a third party rather than directly from the customer. On July 31, 2025, FinCEN issued a corresponding order for banks under Federal Reserve jurisdiction. The agency’s updated announcement explicitly describes the alternative as optional.
The orders change one aspect of information collection under the Customer Identification Program framework. They do not eliminate the need to obtain the required TIN information before account opening or otherwise comply with CIP. The institution must still use risk-based procedures that allow it to form a reasonable belief that it knows the customer’s true identity. A shortened customer form is therefore not evidence of a reduced identification standard.
Collection and verification are different
Collection asks where the required information comes from. Verification asks whether the institution has a reasonable basis for believing the customer is who the customer claims to be. Obtaining a number from a data provider can satisfy part of the collection workflow under the order while leaving difficult verification questions. A number associated with a similar name is not automatically the right person’s number.
The underlying rule in 31 CFR 1020.220 addresses the written program, identifying information, verification, records and procedures for situations in which identity cannot be verified. Those duties need to remain visible in the redesigned onboarding process. A vendor’s successful response should not be treated as an all-purpose certification that every CIP requirement has been fulfilled.
Price the usable result
Suppose a hypothetical provider charges $1 per lookup. Ten thousand attempts cost $10,000. If 8,000 produce usable information, the lookup cost alone is $1.25 per usable result. If only 5,000 do, it is $2.00. Neither amount includes manual review, customer support or the consequences of a false match. The example shows why the quoted price per request can be misleading.
A provider with better coverage may be valuable even at a higher price, but coverage is not the same as accuracy. A confidently returned identifier for the wrong person is worse than an explicit no-match result. Evaluate the two separately and include the cost of resolving exceptions before comparing vendors or application designs.
A hypothetical digital onboarding flow
Assume a bank asks a customer for basic identifying information and a partial TIN, then uses an approved provider to obtain the full TIN before opening the account. The provider returns a full number with a matching name but a conflicting birth date. The exemption does not tell the bank to ignore that conflict. Its risk-based procedures must determine what additional steps or restrictions are appropriate.
In this hypothetical, the benefit is less manual entry for the customer; the risk is that an incorrect or manipulated match flows silently into the account record. A sound implementation preserves the source, returned identifiers, discrepancy and resolution. If the provider cannot produce usable information, the bank needs a fallback or a decision not to open the account under its applicable procedures.
Provider dependence and data quality
Recommended due diligence examines coverage, matching logic, source freshness, correction processes and performance across relevant customer groups. A provider may work well for established domestic records while producing more uncertainty for customers with thin files, recent name changes or inconsistent historical data. Aggregate match rates can obscure those differences.
Test false matches as well as failed matches. A low failure rate is not desirable if the provider fills gaps with the wrong identity. The institution should also know whether multiple vendors rely on the same underlying source; agreement between them may not represent independent confirmation. Maintain access to sufficient evidence to investigate errors without unnecessarily exposing sensitive identifiers to every employee.
Fallbacks determine who can finish
People with recent name or address changes, limited records or inconsistent data across sources may experience the alternative route differently. Those are reasons to test actual outcomes, not assumptions that any group is inherently harder to identify. A clear way to supply and verify information can keep a failed lookup from becoming a dead end.
Evidence should follow the customer through successful identification, account opening and initial use. Compare completion, review time and corrections across relevant application paths, while respecting applicable privacy and nondiscrimination requirements. A higher top-of-funnel conversion rate is weak evidence if more customers later lose access or require repeated identity repair.
Documentation and exception handling
The bank’s written CIP should explain the alternative collection method, its scope and the controls used to evaluate and resolve discrepancies. Record when the information was obtained relative to account opening. A process that collects the full TIN only after an account is opened is not justified merely because the information eventually arrives from a third party.
Manual exceptions deserve particular attention. Staff may be tempted to bypass a failed match for a customer who appears low risk or for a high-priority business partner. The system should record the reason, authority and additional evidence for any permitted exception. The institution should be able to demonstrate that the process applies consistently across channels, including accounts originated through partners.
Costs and the customer experience
An alternative source can reduce friction and transcription errors, but it adds provider cost, integration work and dependency on data quality. It can also create support needs when a customer does not recognize information returned about them. The business case should measure completed, correctly identified accounts and resolution effort, not only the reduction in fields on the application screen.
Privacy and security controls remain important because a full TIN is sensitive information. Limit access, protect transmission and storage, and define retention and vendor use. The narrow collection exemption does not resolve every question about consent, reuse or third-party risk. Those issues should be addressed through the institution’s broader legal and control framework.
What would change the assessment
Confidence increases when the institution can show accurate matches, timely collection, effective discrepancy resolution and reliable fallback across its customer population. It weakens when the provider cannot explain errors, when match rates hide demographic or channel gaps, or when the bank cannot reconstruct the information used to open an account. Material provider or source changes should trigger review.
The June and July 2025 orders, reviewed September 29, 2026, provide operational flexibility. They do not turn customer identification into a vendor checkbox. The practical question is whether the new collection route preserves or improves the bank’s ability to know who opened the account, with enough evidence to identify and correct the cases in which the data is wrong.
Sources
- FinCEN: alternative TIN collection announcement; June 27, 2025, updated July 31, 2025Official releaseBack to text: ↑
- FinCEN/OCC/FDIC/NCUA exemption order; June 27, 2025Official source
- FinCEN/Federal Reserve exemption order; July 31, 2025Official source · PDF
- 31 CFR 1020.220: bank CIP requirements; current text reviewed September 29, 2026Official text