Historical Context & Motivation
Before the modern era of financial regulation, opening a brokerage account was largely an informal process that relied on handshakes and personal reputation. Firms had limited obligations to verify who their customers actually were, creating vulnerabilities that allowed money laundering, terrorist financing, identity theft, and privacy violations to flourish in the financial system. The evolution of customer identification rules reflects a decades-long effort by legislators and regulators to close these gaps while simultaneously protecting consumers' sensitive personal information.
The regulatory landscape we navigate today is primarily shaped by three interconnected frameworks: the Customer Identification Program (CIP) mandated under the USA PATRIOT Act, the broader Know Your Customer (KYC) obligations established through FINRA and SEC rules, and Regulation S-P, the SEC's primary privacy regulation derived from the Gramm-Leach-Bliley Act. Each arose from distinct historical pressures, yet together they form a cohesive regulatory architecture for account opening.
The central question these regulations address is deceptively simple: How can a broker-dealer ensure it knows who its customers are, prevent the financial system from being exploited by bad actors, and simultaneously safeguard the very personal data it collects? For Series 7 candidates, mastering this triad—CIP, KYC, and Regulation S-P—is essential because these rules govern literally the first step in the customer relationship: opening the account.
Core Principles & Definitions
The regulatory requirements for customer identification, screening, and privacy rest on several foundational principles that a registered representative must internalize. These principles do not exist in isolation—they interlock to create a system where a firm simultaneously verifies identity, assesses risk, and protects information. Understanding these core ideas clarifies why specific procedures are mandated and helps you apply them to novel fact patterns on the Series 7 examination.
Customer Identification Program (CIP)
Know Your Customer (KYC)
OFAC Screening
Regulation S-P (Privacy)
Customer Due Diligence (CDD)
Visual Explanation — The Account-Opening Compliance Flow
The following diagram illustrates the compliance workflow that a broker-dealer follows when a prospective customer seeks to open an account. Each stage represents a regulatory checkpoint, and the process cannot advance until the prior stage is satisfactorily completed. This sequential structure ensures that no account is opened without proper identification, screening, and privacy disclosure.
Notice the deliberate ordering in the diagram. A firm must collect and verify the customer's identity (Steps 1–2) and screen against the OFAC SDN list (Step 3) before the account can even be provisionally opened. The privacy notice under Regulation S-P must be delivered at or before the time the customer relationship is established—not after transactions have already occurred. Only then does the firm proceed to collect the broader KYC and suitability information needed under FINRA Rules 2090 and 2111. For legal entity customers, the additional CDD requirement to identify beneficial owners adds a sixth step. Once the account is opened, the firm's obligations do not end: ongoing monitoring, annual privacy notices, and SAR filing duties persist throughout the relationship and for five years after account closure.
How CIP, KYC, and Regulation S-P Work in Practice
CIP: The Four Required Data Elements
Under Section 326 of the USA PATRIOT Act and the implementing rule (31 CFR 1023.220 for broker-dealers), every firm must adopt a written CIP that is appropriate for its size and type of business. At the point of account opening, the firm must collect—at a minimum—four identifying data elements from each customer: the customer's legal name, date of birth (for individuals), residential or business address, and an identification number (Social Security number for U.S. persons; passport number, alien registration number, or government-issued ID number for non-U.S. persons). The CIP must also include procedures for verifying this information within a reasonable time after the account is opened.
Verification Methods: Documentary vs. Non-Documentary
Identity verification can be accomplished through documentary methods—examining an unexpired government-issued photo ID such as a driver's license or passport—or through non-documentary methods such as checking the customer's information against consumer reporting agency databases, public databases, or other reliable sources. The regulation explicitly recognizes that non-documentary methods may be the primary means of verification in situations where the account is opened remotely (e.g., online or by telephone), the customer presents documents that the firm is unfamiliar with, or the customer cannot present documents at the time of account opening. Importantly, a firm's CIP must describe both documentary and non-documentary procedures, and the firm should utilize both when elevated risk factors are present.
KYC Under FINRA Rule 2090
FINRA Rule 2090 codifies the long-standing "Know Your Customer" principle by requiring that every member firm use reasonable diligence to know the essential facts concerning every customer and the authority of each person acting on behalf of the customer. "Essential facts" are those required to effectively service the account, act in accordance with special instructions, understand the authority of each person acting on behalf of the customer, and comply with applicable laws and regulations. This goes well beyond CIP—it includes understanding the customer's financial situation, investment experience, tax status, time horizon, liquidity needs, and risk tolerance, all of which feed into the suitability analysis under FINRA Rule 2111 (now largely subsumed by Regulation Best Interest for retail customers).
Regulation S-P: Privacy Notices and the Opt-Out Right
Regulation S-P (17 CFR Part 248, Subpart A) imposes three key obligations. First, the initial privacy notice must be provided at or before the time the customer relationship is established, clearly describing the firm's privacy policies and practices for collecting, sharing, and safeguarding nonpublic personal information (NPI). Second, the firm must deliver an annual privacy notice for as long as the customer relationship persists—unless the firm qualifies for the annual notice exception (i.e., the firm only shares NPI in ways that do not require an opt-out right). Third, if the firm intends to share NPI with nonaffiliated third parties, it must provide an opt-out notice and a reasonable opportunity for the customer to opt out before such sharing occurs. There is a critical exception: sharing NPI with nonaffiliated third parties is permissible without opt-out when it is necessary to process a transaction, maintain an account, or as otherwise authorized by law.
OFAC Screening, Recordkeeping, and Regulatory Exceptions
Beyond collecting and verifying customer identity, broker-dealers must screen customers against government-maintained watch lists and maintain meticulous records. The screening and recordkeeping obligations are not just regulatory formalities—they are the enforcement mechanism that gives teeth to the entire CIP/KYC framework. A firm that perfectly collects all four CIP elements but fails to screen against the OFAC list, or fails to retain records for the required period, is in violation of federal law.
Recordkeeping Requirements
| Record Type | Retention Period | Governing Rule |
|---|---|---|
| CIP identifying information | 5 years after account closure | 31 CFR 1023.220(a)(3) |
| Description of verification documents | 5 years after record made | 31 CFR 1023.220(a)(3) |
| Methods and results of verification discrepancies | 5 years after record made | 31 CFR 1023.220(a)(3) |
| Suspicious Activity Reports (SARs) | 5 years from filing date | 31 CFR 1023.320 |
| Privacy notices and opt-out records | Duration of customer relationship | Regulation S-P / Firm Policy |
Exceptions and Special Situations
- Existing customers: CIP applies only when a new account is opened. If an existing customer opens an additional account and the firm already has the required CIP information on file, the firm need not re-collect it—provided it has a reasonable belief the identity has been previously verified.
- Persons authorized to act on behalf of a customer: A firm must verify the identity of the person opening the account but does not need to separately verify every authorized signer or agent—though KYC obligations under FINRA Rule 2090 still require the firm to understand the authority of each person acting on the account.
- Regulation S-P exceptions to opt-out: No opt-out is required when sharing NPI to process or service a transaction requested by the customer, to maintain or service the account, or with consent of the customer.
- Annual privacy notice exception: Under the FAST Act (2015), a firm is exempt from delivering the annual privacy notice if it has not changed its policies since the last notice and shares NPI only in ways that do not trigger the opt-out right.
Worked Example — Opening a New Individual Account
Consider the following scenario: Sarah Chen, a U.S. citizen, walks into the branch office of ABC Securities to open an individual brokerage account. She wants to invest a portion of her savings in stocks and bonds. Walk through the compliance steps the registered representative must complete.
Comparing CIP, KYC, and Regulation S-P
One of the most common sources of confusion on the Series 7 exam is the overlap between CIP, KYC, and privacy obligations. While they share the common goal of protecting the integrity of the financial system, each framework has a distinct purpose, scope, and regulatory source. The following table clarifies these distinctions and helps you identify which rule applies in a given scenario.
| Dimension | CIP (PATRIOT Act § 326) | KYC (FINRA Rule 2090) | Regulation S-P (GLBA) |
|---|---|---|---|
| Primary Purpose | Verify identity to prevent money laundering and terrorist financing | Understand customer to service account and ensure suitability | Protect customer's nonpublic personal information |
| Trigger | Account opening | Account opening and ongoing | Establishment of customer relationship |
| Required Data | Name, DOB, address, ID number | Essential facts: financial status, objectives, risk tolerance, authority | Description of firm's NPI collection/sharing practices |
| Key Obligation | Verify identity via documentary or non-documentary means | Use reasonable diligence; know facts about customer and authorized persons | Deliver privacy notices; provide opt-out; implement safeguards |
| Enforcement Authority | FinCEN / SEC | FINRA | SEC |
| Record Retention | 5 years after account closure | Duration of relationship + firm policy | Duration of relationship |
Connection to Advanced Regulatory Concepts
The CIP/KYC/Regulation S-P framework covered in this lesson is foundational, but it connects to several more advanced regulatory concepts that registered representatives encounter as they progress in their careers. Understanding these connections demonstrates how account-opening compliance is not an isolated procedure but part of a broader regulatory ecosystem designed to ensure market integrity and investor protection.
| Foundation Concept | Advanced Extension | Key Difference |
|---|---|---|
| CIP — identity verification | Enhanced Due Diligence (EDD) | EDD applies to high-risk customers (PEPs, correspondent accounts, private banking). Requires deeper investigation into source of funds and ongoing enhanced monitoring. |
| KYC — essential facts | Regulation Best Interest (Reg BI) | Reg BI elevates the standard from suitability to acting in the retail customer's best interest. KYC data feeds directly into the Care Obligation under Reg BI. |
| Regulation S-P — privacy | Regulation S-ID (Red Flags Rule) | Reg S-ID requires firms to implement identity theft prevention programs. While S-P protects data from unauthorized sharing, S-ID protects customers from identity theft. |
| OFAC screening | Comprehensive AML Program (FINRA Rule 3310) | The full AML program includes SAR filing, independent testing, designated compliance officer, and ongoing training—OFAC screening is just one component. |
| CDD — beneficial ownership | Corporate Transparency Act (CTA, 2024) | The CTA creates a national beneficial ownership registry maintained by FinCEN, potentially streamlining CDD by providing firms a centralized data source. |
As you advance beyond the Series 7, particularly if you pursue the Series 24 (General Securities Principal) or engage in compliance roles, you will encounter each of these advanced concepts in depth. The critical insight for now is that the CIP, KYC, and Regulation S-P requirements you learn for account opening are not merely procedural checkboxes—they form the foundation upon which the entire anti-money laundering, investor protection, and data privacy architecture of the U.S. securities industry is built.
Practice Problems
Lesson Summary
Opening a brokerage account requires navigating three interconnected regulatory frameworks. The Customer Identification Program (CIP), mandated by Section 326 of the USA PATRIOT Act, requires firms to collect four minimum data elements—name, date of birth, address, and identification number—and verify identity through documentary or non-documentary methods. The broader Know Your Customer (KYC) obligation under FINRA Rule 2090 requires firms to use reasonable diligence to know the essential facts about every customer—including financial status, investment objectives, risk tolerance, and the authority of persons acting on the account. OFAC screening against the SDN list must occur at account opening, with matches resulting in immediate blocking and reporting within 10 business days. For legal entity customers, the CDD rule adds the requirement to identify beneficial owners holding 25% or more equity and one individual with significant managerial control.
Regulation S-P governs the privacy side: firms must deliver an initial privacy notice at or before establishing the customer relationship, provide annual privacy notices (unless the FAST Act exception applies), and furnish an opt-out notice before sharing nonpublic personal information (NPI) with nonaffiliated third parties. CIP records must be retained for five years after account closure. Together, these frameworks ensure that broker-dealers can identify their customers, prevent financial crime, and protect sensitive personal data throughout the entire customer lifecycle.