A narrow exemption, not a repeal of CIP
On June 27, 2025, FinCEN issued an order with the OCC, FDIC and NCUA permitting institutions within the order’s scope to obtain taxpayer identification number information from a third party rather than directly from the customer. On July 31, 2025, FinCEN issued a corresponding order for banks under Federal Reserve jurisdiction. The agency’s updated announcement explicitly describes the alternative as optional.
The orders change one aspect of information collection under the Customer Identification Program framework. They do not eliminate the need to obtain the required TIN information before account opening or otherwise comply with CIP. The institution must still use risk-based procedures that allow it to form a reasonable belief that it knows the customer’s true identity. A shortened customer form is therefore not evidence of a reduced identification standard.
Collection and verification are different
Collection asks where the required information comes from. Verification asks whether the institution has a reasonable basis for believing the customer is who the customer claims to be. Obtaining a number from a data provider can satisfy part of the collection workflow under the order while leaving difficult verification questions. A number associated with a similar name is not automatically the right person’s number.
The underlying rule in 31 CFR 1020.220 addresses the written program, identifying information, verification, records and procedures for situations in which identity cannot be verified. Those duties need to remain visible in the redesigned onboarding process. A vendor’s successful response should not be treated as an all-purpose certification that every CIP requirement has been fulfilled.
A hypothetical digital onboarding flow
Assume a bank asks a customer for basic identifying information and a partial TIN, then uses an approved provider to obtain the full TIN before opening the account. The provider returns a full number with a matching name but a conflicting birth date. The exemption does not tell the bank to ignore that conflict. Its risk-based procedures must determine what additional steps or restrictions are appropriate.
In this hypothetical, the benefit is less manual entry for the customer; the risk is that an incorrect or manipulated match flows silently into the account record. A sound implementation preserves the source, returned identifiers, discrepancy and resolution. If the provider cannot produce usable information, the bank needs a fallback or a decision not to open the account under its applicable procedures.
Provider dependence and data quality
Recommended due diligence examines coverage, matching logic, source freshness, correction processes and performance across relevant customer groups. A provider may work well for established domestic records while producing more uncertainty for customers with thin files, recent name changes or inconsistent historical data. Aggregate match rates can obscure those differences.
Test false matches as well as failed matches. A low failure rate is not desirable if the provider fills gaps with the wrong identity. The institution should also know whether multiple vendors rely on the same underlying source; agreement between them may not represent independent confirmation. Maintain access to sufficient evidence to investigate errors without unnecessarily exposing sensitive identifiers to every employee.
Documentation and exception handling
The bank’s written CIP should explain the alternative collection method, its scope and the controls used to evaluate and resolve discrepancies. Record when the information was obtained relative to account opening. A process that collects the full TIN only after an account is opened is not justified merely because the information eventually arrives from a third party.
Manual exceptions deserve particular attention. Staff may be tempted to bypass a failed match for a customer who appears low risk or for a high-priority business partner. The system should record the reason, authority and additional evidence for any permitted exception. The institution should be able to demonstrate that the process applies consistently across channels, including accounts originated through partners.
Costs and the customer experience
An alternative source can reduce friction and transcription errors, but it adds provider cost, integration work and dependency on data quality. It can also create support needs when a customer does not recognize information returned about them. The business case should measure completed, correctly identified accounts and resolution effort, not only the reduction in fields on the application screen.
Privacy and security controls remain important because a full TIN is sensitive information. Limit access, protect transmission and storage, and define retention and vendor use. The narrow collection exemption does not resolve every question about consent, reuse or third-party risk. Those issues should be addressed through the institution’s broader legal and control framework.
What would change the assessment
Confidence increases when the institution can show accurate matches, timely collection, effective discrepancy resolution and reliable fallback across its customer population. It weakens when the provider cannot explain errors, when match rates hide demographic or channel gaps, or when the bank cannot reconstruct the information used to open an account. Material provider or source changes should trigger review.
The June and July 2025 orders, reviewed September 29, 2026, provide operational flexibility. They do not turn customer identification into a vendor checkbox. The practical question is whether the new collection route preserves or improves the bank’s ability to know who opened the account, with enough evidence to identify and correct the cases in which the data is wrong.
Sources
- FinCEN: alternative TIN collection announcement; June 27, 2025, updated July 31, 2025Official release
- FinCEN/OCC/FDIC/NCUA exemption order; June 27, 2025Official source
- FinCEN/Federal Reserve exemption order; July 31, 2025Official source · PDF
- 31 CFR 1020.220: bank CIP requirements; current text reviewed September 29, 2026Official text