TL;DR: A June 2025 FinCEN-backed exemption lets financial institutions collect taxpayer identification numbers from trusted third parties instead of directly from customers, while still requiring full CIP identity verification and risk-based procedures, according to Prove Identity. The real change is not reduced assurance but a shift in onboarding governance, vendor reliance, and fraud controls.
NHIMG editorial — based on content published by Prove Identity: A New Way to Know Your Customer: Inside the FinCEN TIN Collection Exemption
By the numbers:
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
Questions worth separating out
Q: How should financial institutions use trusted third-party TIN data without weakening CIP controls?
A: They should treat third-party TIN data as one verified input inside a risk-based CIP workflow, not as a replacement for identity proofing.
Q: When does third-party identity data create more risk than it reduces?
A: It creates more risk when source trust is weak, freshness is unclear, or the institution cannot explain how the data was validated and monitored.
Q: What do teams get wrong about frictionless digital onboarding?
A: They often assume that fewer manual steps automatically means lower risk.
Practitioner guidance
- Update CIP procedures for third-party TIN sourcing Define exactly which third-party sources are acceptable, how source validity is proven, and what evidence is stored for examiner review.
- Separate identifier capture from identity proofing Design onboarding so a sourced TIN feeds the verification flow, but the customer still has to be matched against other assurance signals before account creation.
- Strengthen third-party due diligence for identity data providers Add accuracy testing, dispute handling, and monitoring for stale or inconsistent records into vendor oversight for onboarding sources.
What's in the full article
Prove Identity's full blog covers the operational detail this post intentionally leaves for the source:
- How the TIN exemption fits into existing CIP procedures and account-opening workflows
- Where third-party data sourcing can reduce friction without weakening identity assurance
- Why vendor due diligence and monitoring matter when identity data comes from outside the institution
- What risk-based segmentation can look like across account types and customer profiles
👉 Read Prove Identity's analysis of the FinCEN TIN collection exemption and digital onboarding →
TIN collection from trusted sources: what it means for IAM teams?
Explore further
Third-party identity sourcing is now an identity governance problem, not just a compliance shortcut. The exemption changes who supplies a core identifier, which means the institution must govern source trust, data freshness, and verification evidence as first-class controls. That shifts the programme from direct collection to controlled dependency management. Practitioners should treat the third-party source as part of the identity perimeter.
A few things that frame the scale:
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to Ultimate Guide to NHIs.
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures.
A question worth separating out:
Q: Who is accountable when a trusted third-party TIN source is wrong?
A: The financial institution remains accountable for its CIP decision, even if the bad data came from an external provider. Third-party reliance changes the operating model, but it does not transfer regulatory responsibility, so governance, contracts, and monitoring have to reflect that reality.
👉 Read our full editorial: FinCEN TIN collection exemption changes digital onboarding governance