US banks must collect a customer’s address under CIP, but they do not always need a separate proof-of-address document. Instead, banks use risk-based checks to verify identity. Address checks can include trusted data, documents, postal confirmation, or location signals, with stronger evidence required when customer risk is higher.
A customer uploads a utility bill on a Tuesday afternoon. It carries her husband’s name, because the gas account has been in his name since 2019. The analyst reviewing her file declines the application and types five words into the notes. CIP requires proof of address.
The Customer Identification Program (CIP) rule says no such thing. A customer that the bank could have verified three other ways has just walked out the door, and the only record of why is a policy nobody actually wrote.
That decline repeats itself in US banks every day, and it almost always traces back to one misreading of 31 CFR 1020.220. The rule is narrower than its reputation, and the space it leaves you is where good address controls get built.
What the CIP Rule Actually Requires for an Address
31 CFR 1020.220 requires banks to establish risk-based CIP procedures to verify each customer’s identity. The rule separates two things that are often combined: customer information and identity verification methods. An address falls under the collection requirement, but the rule does not make it a standalone item that must always be independently proven.
The Four Items Collected Before Account Opening
Before opening an account, banks generally collect four pieces of information:
- Name
- Date of birth for individuals
- Address
- Identification number, such as a taxpayer identification number for US persons or a passport number, alien identification card number, or similar government-issued number for non-US persons
The rule defines what counts as an address. For individuals, it can be a residential or business street address. If neither exists, it allows an Army Post Office or Fleet Post Office box number, or the address of a next of kin or another contact individual. For non-individual customers such as corporations, partnerships, or trusts, it means the principal place of business, local office, or another physical location. Customers without a street address may be identified through a description of their physical location.
You Choose Documents, Data, or Both
A CIP must explain when the bank relies on documents, non-documentary methods, or a combination of both. The rule provides examples rather than requiring specific verification methods.
For individuals, documentary verification may include unexpired government-issued identification showing nationality or residence and containing a photograph or similar safeguard, such as a driver’s license or passport.
Non-documentary methods are also recognised. These may include contacting the customer, comparing information against consumer reporting agencies or public databases, checking references with other financial institutions, or obtaining financial statements. CIP procedures must also address remote account openings where customers do not appear in person.
This distinction became clearer in 2025. On 27 June, FinCEN, the OCC, FDIC, and NCUA issued an exemption allowing banks to obtain taxpayer identification number information from a third party rather than directly from the customer. The Federal Reserve issued a similar order for supervised banks on 31 July 2025. However, the exemption is optional, and banks must still obtain the full number before account opening. The change affects where one piece of information comes from, not the requirement to verify identity.
The CIP Rule Requires Reasonable Confidence, Not Proof of Every Detail
The FFIEC BSA/AML Examination Manual puts it plainly. A bank need not establish the accuracy of every element of identifying information obtained. Still, it must verify sufficient information to form a reasonable belief that it knows the customer’s true identity. The Federal Financial Institutions Examination Council (FFIEC) has said this since the 2005 interagency guidance, and it has not moved.
So the honest reading is this. CIP requires address collection and risk-based identity verification. It does not impose a standalone requirement to obtain a proof-of-address document or independently prove every address.
None of that makes addressing evidence optional. Where the address drives the risk of the customer, the account, the channel, or the product, your own risk-based CIP obligates you to go further. The obligation comes from your policy, and the rule expects your policy to have thought about it.
| CIP Area | What the Rule Requires | What it Does Not Prescribe |
| Collect customer information | Name, date of birth for an individual, address, and an identification number | A universal proof-of-address document list |
| Verify identity | Risk-based documentary, non-documentary or combined procedures | One mandatory verification method for every customer |
| Form a reasonable belief | Enough verification to know the customer’s true identity | Proof that every identifying field is independently accurate |
| Keep records | Identifying information for five years after the account closes, or for credit card accounts after closure or dormancy. The description of any identification document relied on, the description of non-documentary methods and their results, and the resolution of any discrepancy, all for five years after the record is made. See 1020.220(a)(3)(ii) | A requirement to keep a copy of every identity document. Copies are optional, and if you keep them in place of a description they fall under the general retention rule at 31 CFR 1010.430 |

Three checks get called address verification, and they answer different questions
Most arguments about address checks are really arguments about which of three unrelated services someone has in mind. Each proves something narrower than its name suggests.
Address Verification Service (AVS) is a payment-fraud control. It compares the numeric portion of the street address, the house or street number, and the postal code supplied for a card transaction against the billing address the card issuer has on file. It never reads the street name, and issuer support is concentrated in the US, Canada, and the UK.
Postal address validation standardizes an address and checks whether it appears in a postal delivery file. A clean result tells you mail can arrive there. It tells you nothing about who lives there.
KYC address verification asks the only question that matters for onboarding. Is this address linked to this customer well enough for your identity, fraud, and AML compliance?
An AVS match and a deliverable postal address are both useful. Neither one is proof of residence, and treating either as proof is how a file gets approved on evidence that was never about the customer.
Where CIP ends, and customer due diligence begins
CIP is a question about the moment of opening. Can you identify this person? Customer due diligence (CDD) is a question about the relationship. Do you understand its nature and purpose? Can you build a risk profile from it, and can you monitor what happens next?
An address does work in both. At onboarding, it identifies information inside CIP. Afterward, it feeds geographic risk, product eligibility, contactability, fraud analysis, and your sense of what normal customer activity looks like.
The FFIEC is direct about the update question. Updating customer information is event-driven and occurs as part of normal monitoring. There is no categorical requirement to continuously update all customer information, or to do so on a fixed cycle, though you may run risk-based periodic reviews when your risk assessment supports them.
Which means you do not owe anyone an annual address refresh for every customer just because twelve months elapsed. What you owe is a set of triggers that fire on material change, and a process that can act when one does. Go back to the customer whose gas bill was in her husband’s name. If she moves in eighteen months and tells you, that is the event. The calendar is not.
| Question | Customer Identification Program | Customer due diligence |
| Main legal anchor | 31 CFR 1020.220 | 31 CFR 1020.210(a)(2)(v) for banks with a Federal functional regulator, and 1020.210(b)(2)(v) for banks without one |
| Main purpose | Form a reasonable belief about the customer’s true identity | Understand the relationship, assess risk, and monitor activity |
| Timing | Information is generally collected before opening. Identity is verified within a reasonable time after opening | Continues throughout the relationship on a risk basis |
| Role of address | A required identifying element used within risk-based verification | Customer information that may shape the risk profile and monitoring |
| Update approach | No address-refresh schedule is stated | Material changes are updated through event-driven monitoring. Risk-based periodic reviews may also be used |
Why Does Address Quality Carry Weight in AML
An address provides a customer’s location and activity in geographic context. When it is wrong, stale or deliberately misleading, the error travels. It reaches risk scoring, customer contact, product access and the way a transaction six months from now gets read. What an address should not do is decide a customer’s jurisdiction, sanctions exposure or tax status on its own. Those calls require several attributes.
For scale, FinCEN’s most recent identity-focused Financial Trend Analysis, published in January 2024 on 2021 filings, found that roughly 1.6 million BSA reports, 42% of the 3.8 million filed that year, related to identity and represented $212 billion in suspicious activity. FinCEN excluded individual amounts above $100 million, so that total is a floor rather than a ceiling.
Those numbers do not address fraud numbers, and FinCEN is careful to say the analysis sets no new customer identification requirements. They do make a smaller point worth holding onto. Identity attributes are not data-entry fields. The bank that can say where an address came from, what the check proved, what it did not prove and how a change will be caught is in a different position from the bank holding a scan of a utility bill.
How Banks Actually Verify an Address
Banks combine methods because each one produces a different kind of evidence. What the right combination looks like depends on the customer’s risk, the product, the onboarding channel and how good the available data is for that population.
| Method | What it can establish | Main limitation | Useful role |
| Postal validation | The address is complete, standardized and probably deliverable | It does not link the customer to the location | Clean the data before matching and cut avoidable failures |
| Independent data matching | The customer and the address appear together in a trusted source | Records can be stale, incomplete or missing for thin-file customers who have little credit or public-record history | Fast, low-friction first check where coverage is strong |
| Documentary proof of address | A document shows the customer’s name and declared address together | Documents can be old, altered, synthetic or issued to somebody else | Step-up evidence when data matching is unavailable or risk is higher |
| Postal confirmation | The customer can receive a code or letter at the address | It proves access to mail, not long-term residence | Higher-friction escalation for selected cases |
| Device and location signals | The session location is or is not consistent with the claim | VPNs, travel and mobile networks generate false signals | Corroboration and risk scoring, never sole proof of residence |
So the bank address verification process should not require every customer to upload the same document. A low-risk customer with a strong independent match may never need one. A high-risk or mismatched case may require a document and independent corroboration in addition to it.
What Counts as Proof of Address, and Who Decides
No US federal rule publishes one list of accepted proof-of-address documents, and the reason is structural. The CIP rule requires each bank to specify in its own written procedures which documents it will use. The list is institution-specific by design, which is exactly why yours has to be written down and defensible.
Common examples across US banks include the following.
- Utility bills for electricity, gas, water, or fixed-line services.
- Bank, credit card, or mortgage statements.
- A current lease, mortgage document, property deed, property tax bill or property insurance statement.
- Government or tax correspondence.
- Pay statements, vehicle registration, or current school-enrollment records, where policy allows.
Recency rules vary just as much. Chase accepts a bank statement or a utility bill showing name and address at branch account opening, each less than 60 days old. It publishes them as secondary identification options rather than as a separate address list. Wells Fargo asks for separate proof of a physical US address when neither ID carries one. Its list runs to utility bills, pay stubs and bank, credit card, or mortgage statements issued within the last 60 days, alongside a current lease, a current vehicle registration, and a prior-year tax return. So “issued within three months” is a policy choice somebody made, not a federal rule or a banking standard.
Whatever list you land on, your policy needs to answer five questions.
- Which document types and issuers do you accept?
- How recent does each one have to be?
- Whether the customer’s full name and declared address must appear together on the page.
- How joint, family, student, temporary, and recently moved customers are handled, which is where the gas-bill decline came from in the first place.
- When an independent data match can replace or support a document.
Sugegsted Read: Address Verification: What It Is, How It Works, and Why It Matters for Compliance
How Shufti handles proof-of-address verification for banks
Shufti is a Glocal platform managing the full compliance lifecycle, from sign-up and onboarding through authentication, monitoring and remediation, across 240+ countries and territories, 10,000+ actively processed document types and 150+ languages.
For address work, four layers run in one flow. Document-based proof of address, docless verification that matches a customer and address against trusted data with no upload at all, address validation, and geolocation risk signals. You start with the cheapest check and ask for more only when coverage or risk requires it.
On uploaded evidence, forensic analysis runs 500+ in-house machine-learning detectors per document, including EXIF metadata analysis, PDF modification tracing and detection of AI-generated documents. Context-aware extraction separates the customer’s address from the issuer, branch and institutional addresses on the same page.
None of this replaces your policy. You still own the document list, the thresholds, the escalation logic and the answer you give an examiner.
Frequently Asked Questions
Q: Does a bank have to verify the address itself under CIP?
Not as a separate, universal proof-of-address requirement. You collect an address and use it in risk-based identity verification. You do not have to prove every identifying element independently, though a higher risk in the customer, account, channel or product can make address corroboration necessary.
Q: How often should a bank re-verify a customer's address?
The FFIEC treats customer information updates as event-driven and tied to normal monitoring, not a fixed cycle for everyone. Update an address when you learn a relevant material change has happened. Risk-based periodic reviews are still available for higher-risk relationships.
Q: Can a bank verify a customer's address without a document?
Yes. CIP permits non-documentary methods, including comparisons against consumer reporting agencies, public databases, and other sources. A docless address match works where coverage is reliable. Judge the result inside the full identity-verification process, because an address match alone does not satisfy CIP.
















