SERIES 7 • FUNCTION 2: OPENS ACCOUNTS

Apply Customer Identification Rules — Apply customer identification, screening, and privacy requirements (CIP, KYC, Regulation S-P).

Understanding the regulatory framework that ensures every brokerage account opening protects both the firm and the customer.

Historical Context & Motivation

Before the modern era of financial regulation, opening a brokerage account was largely an informal process that relied on handshakes and personal reputation. Firms had limited obligations to verify who their customers actually were, creating vulnerabilities that allowed money laundering, terrorist financing, identity theft, and privacy violations to flourish in the financial system. The evolution of customer identification rules reflects a decades-long effort by legislators and regulators to close these gaps while simultaneously protecting consumers' sensitive personal information.

The regulatory landscape we navigate today is primarily shaped by three interconnected frameworks: the Customer Identification Program (CIP) mandated under the USA PATRIOT Act, the broader Know Your Customer (KYC) obligations established through FINRA and SEC rules, and Regulation S-P, the SEC's primary privacy regulation derived from the Gramm-Leach-Bliley Act. Each arose from distinct historical pressures, yet together they form a cohesive regulatory architecture for account opening.

1970
Bank Secrecy Act (BSA)
The BSA establishes the first federal framework for anti-money laundering (AML) by requiring financial institutions to maintain records and file reports that could be useful in detecting and preventing financial crimes.
1999
Gramm-Leach-Bliley Act (GLBA)
Title V of GLBA mandates that financial institutions protect customer nonpublic personal information (NPI). This act becomes the statutory foundation for Regulation S-P, adopted by the SEC in 2000.
2001
USA PATRIOT Act — Section 326
Enacted after the September 11 attacks, the PATRIOT Act requires all financial institutions to implement Customer Identification Programs (CIPs), mandating identity verification at account opening and screening against government watch lists.
2003
CIP Final Rule (31 CFR 103.122)
The Treasury Department and SEC jointly issue the final CIP rule, specifying the minimum identification requirements for broker-dealers—including the four required data elements and verification procedures.
2016
FinCEN CDD Rule
The Financial Crimes Enforcement Network (FinCEN) issues the Customer Due Diligence (CDD) rule, requiring firms to identify and verify beneficial owners of legal entity customers, significantly expanding KYC obligations.

The central question these regulations address is deceptively simple: How can a broker-dealer ensure it knows who its customers are, prevent the financial system from being exploited by bad actors, and simultaneously safeguard the very personal data it collects? For Series 7 candidates, mastering this triad—CIP, KYC, and Regulation S-P—is essential because these rules govern literally the first step in the customer relationship: opening the account.

Core Principles & Definitions

The regulatory requirements for customer identification, screening, and privacy rest on several foundational principles that a registered representative must internalize. These principles do not exist in isolation—they interlock to create a system where a firm simultaneously verifies identity, assesses risk, and protects information. Understanding these core ideas clarifies why specific procedures are mandated and helps you apply them to novel fact patterns on the Series 7 examination.

1

Customer Identification Program (CIP)

A written program required by Section 326 of the USA PATRIOT Act that sets minimum procedures for verifying the identity of any person seeking to open an account. At minimum, a firm must collect four data elements: name, date of birth, address, and identification number (e.g., SSN for U.S. persons or passport/tax ID number for non-U.S. persons).
2

Know Your Customer (KYC)

A broader obligation under FINRA Rule 2090 requiring firms to use reasonable diligence to know the essential facts about every customer. KYC encompasses CIP but extends to understanding the customer's financial profile, investment objectives, risk tolerance, and the authority of persons acting on behalf of the account.
3

OFAC Screening

Broker-dealers must screen customers against the Specially Designated Nationals and Blocked Persons (SDN) list maintained by the Office of Foreign Assets Control. If a match is found, the account must be blocked and the firm must report to OFAC within 10 business days.
4

Regulation S-P (Privacy)

SEC rule implementing Title V of the Gramm-Leach-Bliley Act. It requires firms to deliver an initial privacy notice, annual privacy notices, and an opt-out notice before sharing nonpublic personal information (NPI) with nonaffiliated third parties. It also mandates safeguard policies to protect customer data.
5

Customer Due Diligence (CDD)

Under FinCEN's 2016 rule, firms must identify beneficial owners (individuals owning 25% or more of a legal entity) and a single individual with significant managerial control. CDD also requires ongoing monitoring to maintain and update customer information and detect suspicious activity.
KEY TAKEAWAY
Think of the account-opening process like passing through airport security. CIP is checking your ID at the counter—verifying you are who you claim to be. KYC is the broader boarding process—knowing where you're going, what luggage you carry, and whether you have the right ticket. OFAC screening is checking the no-fly list—ensuring you're not a prohibited person. And Regulation S-P ensures the airline doesn't share your passport details with an unauthorized party. Each step serves a distinct purpose, but skip any one and the system fails.

Visual Explanation — The Account-Opening Compliance Flow

The following diagram illustrates the compliance workflow that a broker-dealer follows when a prospective customer seeks to open an account. Each stage represents a regulatory checkpoint, and the process cannot advance until the prior stage is satisfactorily completed. This sequential structure ensures that no account is opened without proper identification, screening, and privacy disclosure.

This flowchart traces the six sequential steps a broker-dealer must complete before an account is approved—from initial CIP data collection through CDD for entity accounts—followed by ongoing compliance obligations that persist for the life of the relationship.

Notice the deliberate ordering in the diagram. A firm must collect and verify the customer's identity (Steps 1–2) and screen against the OFAC SDN list (Step 3) before the account can even be provisionally opened. The privacy notice under Regulation S-P must be delivered at or before the time the customer relationship is established—not after transactions have already occurred. Only then does the firm proceed to collect the broader KYC and suitability information needed under FINRA Rules 2090 and 2111. For legal entity customers, the additional CDD requirement to identify beneficial owners adds a sixth step. Once the account is opened, the firm's obligations do not end: ongoing monitoring, annual privacy notices, and SAR filing duties persist throughout the relationship and for five years after account closure.

How CIP, KYC, and Regulation S-P Work in Practice

CIP: The Four Required Data Elements

Under Section 326 of the USA PATRIOT Act and the implementing rule (31 CFR 1023.220 for broker-dealers), every firm must adopt a written CIP that is appropriate for its size and type of business. At the point of account opening, the firm must collect—at a minimum—four identifying data elements from each customer: the customer's legal name, date of birth (for individuals), residential or business address, and an identification number (Social Security number for U.S. persons; passport number, alien registration number, or government-issued ID number for non-U.S. persons). The CIP must also include procedures for verifying this information within a reasonable time after the account is opened.

Verification Methods: Documentary vs. Non-Documentary

Identity verification can be accomplished through documentary methods—examining an unexpired government-issued photo ID such as a driver's license or passport—or through non-documentary methods such as checking the customer's information against consumer reporting agency databases, public databases, or other reliable sources. The regulation explicitly recognizes that non-documentary methods may be the primary means of verification in situations where the account is opened remotely (e.g., online or by telephone), the customer presents documents that the firm is unfamiliar with, or the customer cannot present documents at the time of account opening. Importantly, a firm's CIP must describe both documentary and non-documentary procedures, and the firm should utilize both when elevated risk factors are present.

KYC Under FINRA Rule 2090

FINRA Rule 2090 codifies the long-standing "Know Your Customer" principle by requiring that every member firm use reasonable diligence to know the essential facts concerning every customer and the authority of each person acting on behalf of the customer. "Essential facts" are those required to effectively service the account, act in accordance with special instructions, understand the authority of each person acting on behalf of the customer, and comply with applicable laws and regulations. This goes well beyond CIP—it includes understanding the customer's financial situation, investment experience, tax status, time horizon, liquidity needs, and risk tolerance, all of which feed into the suitability analysis under FINRA Rule 2111 (now largely subsumed by Regulation Best Interest for retail customers).

Regulation S-P: Privacy Notices and the Opt-Out Right

Regulation S-P (17 CFR Part 248, Subpart A) imposes three key obligations. First, the initial privacy notice must be provided at or before the time the customer relationship is established, clearly describing the firm's privacy policies and practices for collecting, sharing, and safeguarding nonpublic personal information (NPI). Second, the firm must deliver an annual privacy notice for as long as the customer relationship persists—unless the firm qualifies for the annual notice exception (i.e., the firm only shares NPI in ways that do not require an opt-out right). Third, if the firm intends to share NPI with nonaffiliated third parties, it must provide an opt-out notice and a reasonable opportunity for the customer to opt out before such sharing occurs. There is a critical exception: sharing NPI with nonaffiliated third parties is permissible without opt-out when it is necessary to process a transaction, maintain an account, or as otherwise authorized by law.

⚖️ Key Distinction: Affiliate vs. Nonaffiliated Third Party
Regulation S-P's opt-out requirement applies only when NPI is shared with nonaffiliated third parties. An affiliate is any company that controls, is controlled by, or is under common control with the broker-dealer. A nonaffiliated third party is any entity that does not meet this standard. Sharing NPI among affiliates does not trigger the opt-out requirement under Regulation S-P, though it may trigger obligations under the Fair Credit Reporting Act.

OFAC Screening, Recordkeeping, and Regulatory Exceptions

Beyond collecting and verifying customer identity, broker-dealers must screen customers against government-maintained watch lists and maintain meticulous records. The screening and recordkeeping obligations are not just regulatory formalities—they are the enforcement mechanism that gives teeth to the entire CIP/KYC framework. A firm that perfectly collects all four CIP elements but fails to screen against the OFAC list, or fails to retain records for the required period, is in violation of federal law.

This diagram organizes the five major regulatory domains into a reference grid. The top row shows the three primary frameworks (CIP, KYC, and Regulation S-P) with their required data elements, while the bottom row details OFAC screening procedures and beneficial ownership requirements under the CDD rule.

Recordkeeping Requirements

Key recordkeeping obligations for CIP, KYC, and privacy compliance
Record TypeRetention PeriodGoverning Rule
CIP identifying information5 years after account closure31 CFR 1023.220(a)(3)
Description of verification documents5 years after record made31 CFR 1023.220(a)(3)
Methods and results of verification discrepancies5 years after record made31 CFR 1023.220(a)(3)
Suspicious Activity Reports (SARs)5 years from filing date31 CFR 1023.320
Privacy notices and opt-out recordsDuration of customer relationshipRegulation S-P / Firm Policy

Exceptions and Special Situations

  • Existing customers: CIP applies only when a new account is opened. If an existing customer opens an additional account and the firm already has the required CIP information on file, the firm need not re-collect it—provided it has a reasonable belief the identity has been previously verified.
  • Persons authorized to act on behalf of a customer: A firm must verify the identity of the person opening the account but does not need to separately verify every authorized signer or agent—though KYC obligations under FINRA Rule 2090 still require the firm to understand the authority of each person acting on the account.
  • Regulation S-P exceptions to opt-out: No opt-out is required when sharing NPI to process or service a transaction requested by the customer, to maintain or service the account, or with consent of the customer.
  • Annual privacy notice exception: Under the FAST Act (2015), a firm is exempt from delivering the annual privacy notice if it has not changed its policies since the last notice and shares NPI only in ways that do not trigger the opt-out right.

Worked Example — Opening a New Individual Account

Consider the following scenario: Sarah Chen, a U.S. citizen, walks into the branch office of ABC Securities to open an individual brokerage account. She wants to invest a portion of her savings in stocks and bonds. Walk through the compliance steps the registered representative must complete.

Opening an Individual Account for Sarah Chen
1
Step 1 — Collect CIP InformationThe representative asks Sarah for the four required CIP data elements. She provides: Legal name (Sarah J. Chen), date of birth (April 15, 1990), residential address (456 Oak Lane, Denver, CO 80202), and her Social Security number (XXX-XX-1234). The representative records each element in the firm's account-opening system.
All four CIP elements collected ✓
2
Step 2 — Verify Identity (Documentary Method)Sarah presents her unexpired U.S. passport. The representative examines it, confirms the name and date of birth match the information provided, and records the document type (U.S. Passport), document number, expiration date, and issuing authority. Because the firm is also meeting Sarah in person and comparing the photo to the individual present, documentary verification is completed. The representative notes in the system that identity was verified via documentary method.
Identity verified via documentary method ✓
3
Step 3 — OFAC ScreeningThe firm's compliance system automatically screens Sarah's name and identifying information against the OFAC Specially Designated Nationals (SDN) list and other government watch lists. No matches are returned. If there had been a potential match, the representative would escalate to the compliance department immediately, which would investigate the match and, if confirmed, block the account and report to OFAC within 10 business days.
OFAC screening clear — no SDN match ✓
4
Step 4 — Deliver Initial Privacy NoticeBefore the customer relationship is established, the representative provides Sarah with ABC Securities' initial privacy notice. This notice describes: the categories of NPI the firm collects (account information, transaction history, SSN), the categories of affiliates and nonaffiliated third parties with whom NPI may be shared, and the firm's policies for safeguarding NPI. Because ABC Securities shares certain NPI with a nonaffiliated marketing partner, the notice also includes an opt-out provision with a toll-free number and an online form Sarah can use to opt out.
Initial privacy notice + opt-out notice delivered ✓
5
Step 5 — Collect KYC / Suitability InformationThe representative gathers Sarah's essential facts under FINRA Rule 2090 and suitability/Reg BI information: annual income ($95,000), liquid net worth ($150,000), total net worth ($320,000), investment objectives (growth), risk tolerance (moderate), time horizon (10+ years), tax bracket (24%), employment (software engineer at a publicly traded tech company—which also triggers a check for insider status under Rule 3210). This information is documented in the new account form and signed by the customer and the branch manager.
KYC profile complete — account approved and opened ✓
📝 Exam Tip
Series 7 questions frequently test whether you know the exact CIP data elements. Remember the mnemonic "N-D-A-I": Name, Date of birth, Address, Identification number. Also know that CIP verification must be completed within a reasonable time after account opening—the rule does not specify an exact number of days, but the account may be provisionally opened while verification is pending.

Comparing CIP, KYC, and Regulation S-P

One of the most common sources of confusion on the Series 7 exam is the overlap between CIP, KYC, and privacy obligations. While they share the common goal of protecting the integrity of the financial system, each framework has a distinct purpose, scope, and regulatory source. The following table clarifies these distinctions and helps you identify which rule applies in a given scenario.

Comparative analysis of the three primary regulatory frameworks governing account opening
DimensionCIP (PATRIOT Act § 326)KYC (FINRA Rule 2090)Regulation S-P (GLBA)
Primary PurposeVerify identity to prevent money laundering and terrorist financingUnderstand customer to service account and ensure suitabilityProtect customer's nonpublic personal information
TriggerAccount openingAccount opening and ongoingEstablishment of customer relationship
Required DataName, DOB, address, ID numberEssential facts: financial status, objectives, risk tolerance, authorityDescription of firm's NPI collection/sharing practices
Key ObligationVerify identity via documentary or non-documentary meansUse reasonable diligence; know facts about customer and authorized personsDeliver privacy notices; provide opt-out; implement safeguards
Enforcement AuthorityFinCEN / SECFINRASEC
Record Retention5 years after account closureDuration of relationship + firm policyDuration of relationship
KEY TAKEAWAY
CIP, KYC, and Regulation S-P are concentric circles of obligation. CIP sits at the center—it is the most specific and narrowly focused, addressing only identity verification. KYC is the middle ring—it encompasses CIP but also requires understanding the customer's full financial profile. Regulation S-P is the outer ring—it addresses what you do with all the information you've gathered, ensuring it is protected and not improperly shared. On the exam, always ask yourself: "Is this question about who the customer is, what the customer needs, or what we do with the customer's data?"

Connection to Advanced Regulatory Concepts

The CIP/KYC/Regulation S-P framework covered in this lesson is foundational, but it connects to several more advanced regulatory concepts that registered representatives encounter as they progress in their careers. Understanding these connections demonstrates how account-opening compliance is not an isolated procedure but part of a broader regulatory ecosystem designed to ensure market integrity and investor protection.

How foundational account-opening concepts connect to advanced regulatory frameworks
Foundation ConceptAdvanced ExtensionKey Difference
CIP — identity verificationEnhanced Due Diligence (EDD)EDD applies to high-risk customers (PEPs, correspondent accounts, private banking). Requires deeper investigation into source of funds and ongoing enhanced monitoring.
KYC — essential factsRegulation Best Interest (Reg BI)Reg BI elevates the standard from suitability to acting in the retail customer's best interest. KYC data feeds directly into the Care Obligation under Reg BI.
Regulation S-P — privacyRegulation S-ID (Red Flags Rule)Reg S-ID requires firms to implement identity theft prevention programs. While S-P protects data from unauthorized sharing, S-ID protects customers from identity theft.
OFAC screeningComprehensive AML Program (FINRA Rule 3310)The full AML program includes SAR filing, independent testing, designated compliance officer, and ongoing training—OFAC screening is just one component.
CDD — beneficial ownershipCorporate Transparency Act (CTA, 2024)The CTA creates a national beneficial ownership registry maintained by FinCEN, potentially streamlining CDD by providing firms a centralized data source.

As you advance beyond the Series 7, particularly if you pursue the Series 24 (General Securities Principal) or engage in compliance roles, you will encounter each of these advanced concepts in depth. The critical insight for now is that the CIP, KYC, and Regulation S-P requirements you learn for account opening are not merely procedural checkboxes—they form the foundation upon which the entire anti-money laundering, investor protection, and data privacy architecture of the U.S. securities industry is built.

Practice Problems

PROBLEM 1CONCEPTUAL
A new customer walks into a brokerage office to open an individual account. Under the CIP rule, what are the four minimum data elements the broker-dealer must collect, and what is the statutory basis for this requirement?
PROBLEM 2BASIC CALCULATION
A customer closes their brokerage account on March 1, 2025. The firm collected CIP information when the account was opened on June 15, 2018. What is the earliest date the firm may destroy the CIP records, and under which regulatory provision?
PROBLEM 3INTERMEDIATE
ABC Securities plans to share its customers' account balance information and transaction history with a nonaffiliated marketing company to offer targeted financial product advertisements. Under Regulation S-P, what specific obligations must ABC Securities fulfill before sharing this information, and are there any circumstances under which this sharing could occur without customer consent?
PROBLEM 4APPLIED
A registered representative is opening an account for GreenTech Ventures LLC, a privately held company. The LLC has three members: Partner A owns 40%, Partner B owns 35%, and Partner C owns 25%. The LLC's operations are managed by a CEO who holds no ownership stake. Under the CDD rule, how many individuals must be identified as beneficial owners, and what CIP information must be collected for each?
PROBLEM 5CRITICAL THINKING
A broker-dealer's OFAC screening system returns a potential match for a new customer against the SDN list. Upon investigation, the compliance department determines that the match is a false positive—the customer shares the same name as a designated person but is clearly a different individual (different date of birth, different country of residence, different SSN). However, during the KYC interview, the customer reveals income patterns and account funding sources that are inconsistent with the customer's stated occupation. Analyze the firm's obligations under CIP, OFAC, and AML rules. Should the account be opened?

Lesson Summary

Opening a brokerage account requires navigating three interconnected regulatory frameworks. The Customer Identification Program (CIP), mandated by Section 326 of the USA PATRIOT Act, requires firms to collect four minimum data elements—name, date of birth, address, and identification number—and verify identity through documentary or non-documentary methods. The broader Know Your Customer (KYC) obligation under FINRA Rule 2090 requires firms to use reasonable diligence to know the essential facts about every customer—including financial status, investment objectives, risk tolerance, and the authority of persons acting on the account. OFAC screening against the SDN list must occur at account opening, with matches resulting in immediate blocking and reporting within 10 business days. For legal entity customers, the CDD rule adds the requirement to identify beneficial owners holding 25% or more equity and one individual with significant managerial control.

Regulation S-P governs the privacy side: firms must deliver an initial privacy notice at or before establishing the customer relationship, provide annual privacy notices (unless the FAST Act exception applies), and furnish an opt-out notice before sharing nonpublic personal information (NPI) with nonaffiliated third parties. CIP records must be retained for five years after account closure. Together, these frameworks ensure that broker-dealers can identify their customers, prevent financial crime, and protect sensitive personal data throughout the entire customer lifecycle.

Varsity Tutors • Series 7 • Apply Customer Identification Rules — Apply customer identification, screening, and privacy requirements (CIP, KYC, Regulation S-P).