Banks Can Use Third Parties for SSN and TIN Collection

New Flexibility for Financial Institutions

Banks and credit unions now have the option to rely on third-party providers to gather Social Security Numbers (SSNs) and Taxpayer Identification Numbers (TINs) from consumers. This change comes following a joint order issued by the Federal Deposit Insurance Corporation (FDIC), the Office of the Comptroller of the Currency (OCC), and the National Credit Union Administration (NCUA), with the approval of the Financial Crimes Enforcement Network (FinCEN).

This policy adjustment is tied to the Customer Identification Program (CIP) Rule, which is part of the broader USA PATRIOT Act. The CIP rule mandates that financial institutions collect identifying information about customers, including TINs, before opening new accounts. The new order permits institutions to fulfill this requirement through third-party sources instead of obtaining the information directly from the customer.

Understanding the CIP Rule and the New Exemption

The CIP rule plays a critical role in the fight against money laundering and terrorist financing. It requires banks and credit unions to establish procedures that enable them to form a reasonable belief that they know the identity of each customer. The new exemption, however, gives these institutions more leeway in how they collect TINs.

According to the order, the exemption is optional. This means that institutions are not required to change their current processes if they prefer to continue collecting information directly from customers. Instead, they are now permitted to use trusted third-party sources to acquire the necessary identification numbers, which could streamline account opening procedures and reduce administrative burden.

Regulatory Support and Industry Feedback

FinCEN Director Andrea Gacki emphasized that the change reflects the evolving nature of financial services. “We recognize that the way customers interact with banks and receive financial services has changed significantly since 2001, when the initial requirement was enacted into law under the USA PATRIOT Act,” Gacki stated.

She added, “This order reduces burden by providing banks with greater flexibility in determining how to fulfill their existing regulatory obligations without presenting a heightened risk of money laundering, terrorist financing, or other illicit finance activity.”

The final order takes into account feedback received from a public request for information issued in March 2024. Industry stakeholders provided input on how the proposed exemption would affect compliance efforts, customer service, and financial crime prevention.

Maintaining Risk-Based Procedures

Despite the added flexibility, the exemption does not eliminate the need for robust risk-based procedures. Financial institutions are still required to have effective CIP policies that support forming a reasonable belief in the true identity of their customers. This means that even if third-party data is used, banks and credit unions must continue to assess and verify the accuracy and reliability of that information.

The use of third parties must align with the institution’s existing risk management framework. Institutions are encouraged to conduct due diligence on third-party vendors and ensure that data collection practices meet the standards expected under federal regulations.

Optional Implementation and Strategic Considerations

Financial institutions have the discretion to adopt or decline the use of third-party sources for TIN and SSN collection. The optional nature of the exemption allows banks and credit unions to evaluate their operational needs and regulatory strategies before implementing any changes.

For some institutions, especially those that have already integrated digital onboarding tools or work closely with fintech partners, the ability to rely on external data providers may enhance efficiency and improve customer experience. For others, maintaining direct collection processes might offer greater control and reliability.

A Step Toward Modernizing Compliance

This regulatory update marks a significant step toward modernizing compliance processes in the financial services sector. As consumer behavior shifts and digital channels become more dominant, regulatory frameworks must adapt to support both innovation and security.

The interagency order provides the flexibility needed to meet these dual objectives. By permitting third-party data collection, regulators are acknowledging the changing landscape of financial interactions while maintaining a strong emphasis on preventing illicit financial activity.

As the financial industry continues to evolve, similar updates may emerge to further streamline regulatory obligations without compromising on risk management and consumer protection.


This article is inspired by content from Original Source. It has been rephrased for originality. Images are credited to the original source.

Subscribe to our Newsletter