Claude
Skills
Sign in
Back

account-opening-compliance

Included with Lifetime
$97 forever

Embed compliance controls into account opening workflows and verify regulatory readiness. Use when designing CIP/KYC identity verification gates for new accounts, implementing OFAC and sanctions screening at onboarding, collecting beneficial ownership certification for entity or trust accounts, building risk-based approval tiers that route applications by risk level, adding senior investor protections or trusted contact procedures, automating compliance screening and exception tracking, establishing CDD risk ratings and ongoing monitoring triggers, preparing account opening procedures for SEC or FINRA examination, remediating audit or exam deficiencies in onboarding compliance, or assessing the handoff from opening compliance to ongoing surveillance.

Security

What this skill does


# Account Opening Compliance

## Purpose
Guide the integration of compliance requirements into account opening operations. Covers CIP/KYC verification integration, suitability assessment, OFAC and sanctions screening, beneficial ownership certification for entities, risk-based review tiers, senior investor protections, and compliance automation. Focuses on the compliance operations perspective — how compliance checks are embedded in and executed during the account opening process.

## Layer
12 — Client Operations (Account Lifecycle & Servicing)

## Direction
prospective

## When to Use
- Designing compliance checkpoints within an account opening workflow
- Integrating CIP/KYC identity verification into new account processing
- Implementing OFAC and sanctions screening at account opening and ongoing
- Collecting and verifying beneficial ownership for legal entity accounts
- Building risk-based review tiers that route applications to the appropriate approval level
- Embedding suitability documentation requirements into the opening process
- Designing senior investor protections and trusted contact procedures at account opening
- Automating compliance screening, approval routing, and exception tracking
- Establishing CDD risk ratings and ongoing monitoring triggers at the point of account opening
- Evaluating whether a firm's account opening compliance controls satisfy regulatory expectations
- Preparing account opening procedures for SEC or FINRA examination
- Remediating deficiencies in existing account opening compliance processes identified by internal audit or regulatory examination
- Designing compliance controls for specific account types (entity accounts, trust accounts, foreign national accounts) that require enhanced procedures
- Assessing the adequacy of the handoff from account opening compliance to ongoing monitoring and surveillance

## Core Concepts

### CIP Integration in Account Opening
The Customer Identification Program is the first compliance gate in any account opening workflow. Under USA PATRIOT Act Section 326 and its implementing regulations, a firm must verify the identity of each customer before or at the time of account opening. The account opening process must be designed so that no account becomes active until CIP is satisfied.

**Verification timing.** The regulations permit two approaches: (1) verify identity before the account is opened, which is the most conservative approach and prevents any transactional activity until verification is complete; or (2) verify identity within a reasonable time after the account is opened, provided the firm has procedures to manage the risk of incomplete verification (such as restricting account activity until verification is complete). Most firms implementing digital onboarding choose the first approach — identity verification occurs in real time during the application flow, and the application cannot proceed until verification returns a pass result. The second approach — opening with restricted activity pending verification — is used primarily for paper-based or advisor-assisted workflows where verification cannot occur in real time, and requires the firm to document the risk mitigation procedures (no trading, no disbursements, no margin until verification completes).

**Database verification** is the primary method for digital account opening. The onboarding system sends applicant data (name, date of birth, address, SSN/TIN) to an identity verification vendor (LexisNexis Risk Solutions, Alloy, Equifax, TransUnion) via API. The vendor cross-references the data against credit bureau records, public records, and government databases and returns a pass, fail, or inconclusive result, typically within seconds. Database verification satisfies CIP's non-documentary verification requirement.

**Documentary verification** serves as a fallback when database verification is inconclusive or unavailable. The applicant uploads a photo of a government-issued ID (driver's license, passport, state ID). OCR extracts data fields, and the system may compare the document photo to a selfie for liveness detection. Documentary verification is slower and introduces friction but is necessary for applicants who cannot be verified through database methods — non-US persons, thin-file individuals, and cases where database results are ambiguous.

**Verification failure handling.** The account opening workflow must define clear paths for each verification outcome:
- **Pass** — proceed to the next compliance gate
- **Fail** — halt the application; notify the applicant that the account cannot be opened; document the reason; retain records per CIP recordkeeping requirements
- **Inconclusive** — route to an exception queue for manual review; request additional identifying information or documentary verification; set a time limit for resolution (e.g., 5 business days) after which the application is closed

**Exception processing for inconclusive results** is operationally critical. Common causes of inconclusive results include name mismatches (legal name vs preferred name, hyphenated names, transliteration differences for non-English names), address mismatches (recent moves, PO boxes), and thin credit files (young adults, recent immigrants). The exception processing workflow should collect additional documentation, perform manual database searches, and escalate to compliance when standard exception procedures do not resolve the issue. The firm should track exception rates by cause to identify systemic issues — for example, a high rate of transliteration-related exceptions may indicate a need to improve the verification vendor's handling of non-Latin character sets.

**Non-US persons and foreign accounts.** CIP verification for non-US persons presents additional complexity. Acceptable identification numbers include a passport number and country of issuance, an alien identification card number, or a number and country of issuance of any other unexpired government-issued document evidencing nationality or residence that bears a photograph. Database verification coverage is weaker for non-US persons, making documentary verification (passport upload with liveness check) the primary method. The account opening workflow should detect non-US applicants early and route them to the documentary verification path without requiring a failed database check first.

**Recordkeeping requirements.** CIP regulations require retention of identifying information (name, date of birth, address, identification number), a description of the documents or methods used to verify identity, and the resolution of any discrepancies. These records must be retained for 5 years after the account is closed. The account opening system should automatically generate and store a CIP verification record for each application, including the verification method, vendor response, timestamp, and outcome.

### OFAC and Sanctions Screening
OFAC screening is a mandatory compliance gate that must clear before any account is opened. Unlike CIP, which verifies that the applicant is who they claim to be, OFAC screening determines whether the applicant — or any person associated with the account — is a sanctioned individual or entity with whom the firm is prohibited from doing business.

**Scope of screening.** The firm must screen all individuals associated with the account, not just the primary applicant. This includes:
- Account holders (all owners for joint accounts)
- Beneficial owners (25% equity holders and control persons for entity accounts)
- Authorized signers and persons with trading authority
- Trustees (for trust accounts)
- Custodians under UTMA/UGMA accounts
- Any other person with authority over or beneficial interest in the account

**Lists screened.** At minimum, screening must cover the OFAC SDN (Specially Designated Nationals and Blocked Persons) list. Best practice extends screening to the Sectoral Sanctions Identifications (SSI) list, the Non-SDN Men

Related in Security