01 / Scope
Who United States KYC rules cover
There is no single U.S. KYC rule for every business. This summary covers banks subject to 31 CFR 1020.220. Broker-dealers, mutual funds, futures firms, MSBs, and other sectors use separate BSA rules.
02 / Start the check
When United States customer due diligence starts
- Before opening a new account, collect the minimum identifying information, subject to the rule’s limited treatment for customers applying for a taxpayer identification number.
- Verify identity within a reasonable time after the account is opened using procedures appropriate to the bank’s products, customers, and risk profile.
- Resolve circumstances where identity cannot be verified and define when not to open, when to close, and when to file a suspicious activity report.
03 / Evidence
Identity data required for United States KYC
- Name.
- Date of birth for an individual.
- Residential or business street address, with limited alternatives stated in the rule.
- Identification number: generally a U.S. taxpayer identification number, or specified passport or other government-document information for a non-U.S. person.
Verification methods and evidence
- Documentary procedures may use an unexpired government-issued ID showing nationality or residence and bearing a photograph or similar safeguard for an individual.
- Non-documentary procedures may include contacting the customer, comparing information with a consumer reporting agency, public database, or other source, checking references, or obtaining a financial statement.
- The program must address non-face-to-face openings, unfamiliar or unavailable documents, and other circumstances with elevated identity risk.
04 / Entity customers
Beneficial-owner and representative checks
The separate CDD Rule at 31 CFR 1010.230 addresses covered legal-entity customers. FinCEN order FIN-2026-R001 now permits covered financial institutions to identify and verify beneficial owners at the first account, when prior information becomes doubtful, and when risk-based ongoing CDD calls for it, rather than at every additional account opening.
05 / After onboarding
Ongoing KYC monitoring in United States
The bank’s broader AML program and CDD obligations require customer-risk understanding and risk-based ongoing monitoring. CIP is the account-opening identity layer, not the full program.
Record retention
Keep core identifying information for five years after the account closes. Keep the description and results of verification, and discrepancy-resolution records, for five years after the record is made.
06 / Build notes
How to implement United States KYC requirements
- Route by regulated entity and account definition before choosing a verification flow.
- Store which documentary and non-documentary procedures were used and the discrepancy outcome.
- Keep sanctions screening, legal-entity CDD, and ongoing monitoring as connected but distinct controls.
- Define explicit outcomes for cannot verify: reject, restrict, close, escalate, and consider SAR.
07 / Related answers
Questions behind international KYC implementation
08 / Source ledger
Primary sources for United States KYC rules
We use regulator and legislation publishers here, not vendor explainers. Pinpoint citations show where to begin; the linked instrument controls.
31 CFR 1020.220 Minimum data, verification procedures, records, and customer notice.
31 CFR 1010.230 Separate requirements for covered legal-entity customers.
CDD Rule Regulator materials and FAQs for customer due diligence.
issued 13 February 2026 Current relief from repeating beneficial-owner identification and verification at every new account for an existing legal-entity customer.
31 CFR 1020.220 GovInfo source for the bank CIP provision.
Source review completed 18 July 2026. This page is a structured research summary, not a legal opinion or a substitute for sector-specific advice.