ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

ABA Compliance Center Inbox, November/December 2017

October 9, 2017
Reading Time: 3 mins read

Q: Can I keep a copy of a customer’s ID on file? I am working for a new bank and am being told that Section 326 of the Patriot Act (the Customer Identification Program rule) requires that banks keep a copy of the ID that the customer provided. I have heard that many small banks such as ours keep the copy in the loan file and cite the Patriot Act. According to my peers, the examiners have not questioned this practice. Is this acceptable?

A: The CIP rule requires the bank to collect certain pieces of information about a customer and then verify the customer’s identity. The rule then requires that the bank keep the information, name, physical address, date of birth and ID number such as a social security number or taxpayer identification number. It must also retain information about how it verified the identity. All of this will be set forth in the written CIP policy approved by the bank’s board of directors.
See the CIP overview section in the FFIEC Bank Secrecy Act Examination Manual:

A bank’s CIP must include recordkeeping procedures. At a minimum, the bank must retain the identifying information (name, address, date of birth for an individual, TIN, and any other information required by the CIP) obtained at account opening for a period of five years after the account is closed. For credit cards, the retention period is five years after the account closes or becomes dormant. The bank must also keep a description of the following for five years after the record was made:

  • Any document that was relied on to verify identity, noting the type of document, the identification number, the place of issuance, and, if any, the date of issuance and expiration date.
  • The method and the results of any measures undertaken to verify identity.
  • The results of any substantive discrepancy discovered when verifying identity.

For many banks, the easiest way to demonstrate compliance is to retain a copy of the customer’s driver’s license. And, there are certain teller software packages that use the driver’s license to identify the customer. However, while that complies with CIP, the question is what about Regulation B and the Equal Credit Opportunity Act.

This is a situation where there is a conflict between two regulations. Reg B generally prohibits collection of information about a customer’s race, ethnicity and gender for non-mortgage loans. The problem is that if you have a copy of driver’s license in the file, you have a picture which will indicate race and gender and the surname may indicate ethnicity. Also—it is illegal in some states to make a copy of driver’s license and it is illegal under federal law to make a copy of any government or military ID.

One solution that some banks have used in states where it’s permissible to keep a copy of a driver’s licenses is to create a firewall or barrier so that the bank’s lenders and underwriters do not have access to the files where the copy of a customer’s driver’s license is maintained. This is important if the bank does keep copies of a driver’s license in customer files.

Importantly, nowhere in Section 326 does it state that you must keep a copy of the identification provided. In fact, during the comment period for the final rule, the agencies discussed whether to require financial institutions to make a copy of the consumer’s identification but decided against it. The final regulation states that banks must keep the information and a description—not the documents themselves. The information on a driver’s license, for example, would be the name of the document (driver’s license), issuing party (state of X), issue date and expiration date. For a passport, a bank would retain the information relating to the country, issue date and expiration date. (Response provided July 2017.)

Answers are provided by Leslie Callaway, CRCM, CAFP, director of compliance outreach and development; Mark Kruhm, CRCM, CAFP, senior compliance analyst; and Rhonda Castaneda, CRCM, compliance analyst, ABA Center for Regulatory Compliance. Answers do not provide, nor are they intended to substitute for, professional legal advice. Answers were current as of the response date shown at the end of each item.

Tags: Bank Secrecy ActECOAKnow your customer
ShareTweetPin

Related Posts

Banking agencies seek public input on capital standards for large banks

Banking agencies release revised compliance guide for Community Bank Leverage Ratio

Community Banking
July 30, 2026

The Federal Reserve, FDIC and OCC issued a revised compliance guide for the Community Bank Leverage Ratio framework, reflecting changes that took effect in July.

Proposed bill would block large ransomware payments by financial institutions

BIS: Bad actors have financial edge in using AI for cyberattacks

Compliance and Risk
July 30, 2026

While frontier artificial intelligence models strengthen both cyberattacks and cyber defense, the financial costs for both are “asymmetric” and may favor attackers, according to a new bulletin published by the Bank for International Settlements.

ABA’s Benda shares policy recommendations for fighting AI-enabled scams

ABA’s Benda shares policy recommendations for fighting AI-enabled scams

Compliance and Risk
July 29, 2026

Generative AI has made scams more convincing, personalized and scalable while enabling criminals to exploit trusted identities and communications channels, ABA's Paul Benda told senators.

Treasury Department seeks feedback on stablecoins, illicit activities

ABA, associations: Stablecoin review committee must establish formal procedures

Compliance and Risk
July 29, 2026

A new committee to review state-level regulatory frameworks for stablecoins must adopt strong, transparent rules before it starts making decisions “that will shape the payment stablecoin market for years to come,” ABA and three bankers associations said.

ABA survey: Americans strongly support prohibiting crypto companies from offering yield-like rewards for holding stablecoin

ABA, associations ask agencies to commit to reproposing conflicting Genius Act rules

Compliance and Risk
July 28, 2026

As the various federal banking agencies race to establish separate regulations for stablecoin issuers, they should be open to reproposing any rule that conflicts with a regulation put forward by another agency, ABA and three banking associations said.

ABA highlights banker comments seeking stronger ‘know your customer’ rules for originating providers

ABA highlights banker comments seeking stronger ‘know your customer’ rules for originating providers

Compliance and Risk
July 28, 2026

In a new comment letter, ABA highlighted the dozens of bankers who wrote to the Federal Communications Commission in support of stronger “know your customer” requirements for voice service providers that originate calls.

NEWSBYTES

Banking agencies release revised compliance guide for Community Bank Leverage Ratio

July 30, 2026

BIS: Bad actors have financial edge in using AI for cyberattacks

July 30, 2026

ABA DataBank: Real GDP growth slowed in 2026 Q2

July 30, 2026

SPONSORED CONTENT

Why Your Systems Keep Slowing Down — and What to Do About It

Examiners Are Now Looking at Your Non-Core Systems

June 11, 2026
Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

June 1, 2026
A Modern Blueprint for Serving High-Net-Worth Families

A Modern Blueprint for Serving High-Net-Worth Families

May 28, 2026
Why Your Systems Keep Slowing Down — and What to Do About It

AI Is in Your Bank. Is Your Cloud Contract Governing It?

May 20, 2026

PODCASTS

Podcast: Tactics for meaningful strategic planning

July 28, 2026

Podcast: Why it might be time to revisit a key FDIC ratio

July 23, 2026

Is Your Bank’s Wealth Business Built to Last?

July 23, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.