The Financial Crimes Enforcement Network (FinCEN) and the federal banking agencies have issued new guidance confirming that banks and credit unions may use government-issued verifiable digital credentials—including state-issued mobile driver’s licenses—to verify customers under the Customer Identification Program Rule.
This is an important modernization of federal financial-crime compliance and a direct response to a regulatory clarification The Digital Chamber has repeatedly requested.
Why This Guidance Was Needed
Financial institutions increasingly serve customers through mobile applications and other digital channels, but identity-verification practices often remain rooted in physical documents. Customers may be asked to photograph and upload a driver’s license, transmit sensitive personal information, or rely on authentication methods that are vulnerable to forgery and identity theft.
Mobile driver’s licenses and other verifiable digital credentials offer a more secure alternative. They use cryptographic signatures, device binding, authentication factors, and other safeguards to help institutions determine whether a credential is authentic and belongs to the person presenting it.
Until now, however, regulatory uncertainty limited adoption. Financial institutions needed clear confirmation that these credentials could be used consistently with existing Bank Secrecy Act and Customer Identification Program obligations.
From an Ask to a Win
TDC made that clarification a specific policy priority.
In our comments on Bank Secrecy Act modernization, permitted payment stablecoin issuer requirements, and NIST’s mobile driver’s license implementation guidance, TDC urged regulators to recognize privacy-preserving digital identity and verifiable credentials as legitimate compliance tools.
In May, we publicly called on FinCEN to issue clear guidance explaining how financial institutions could use mobile driver’s licenses and other digital credentials to satisfy BSA and Customer Identification Program requirements. FinCEN has now answered that request.
The new FAQs confirm that an unexpired government-issued verifiable digital credential can qualify as “government-issued identification” under the documentary verification provisions of the Customer Identification Program Rule, provided it contains the required information and the institution has the technology, policies, and procedures necessary to use it.
The guidance also confirms that these credentials may be used when customers open accounts in person, remotely over the internet, or through another digital or virtual channel. In addition, electronic credentials issued by nongovernmental entities may also be used as a non-documentary verification method when the institution ensures an appropriate level of authentication.
Why It Matters
This guidance gives regulated institutions greater confidence to adopt stronger identity technology without waiting for Congress or regulators to rewrite the underlying rule.
Properly implemented, verifiable digital credentials can:
- Make forged or altered identity documents easier to detect
- Strengthen remote customer onboarding
- Reduce dependence on easily copied physical documents
- Prevent new fraud tactics made widely available by AI
- Limit unnecessary collection and storage of sensitive information
- Improve the customer experience while supporting effective compliance
The FAQs do not require institutions to accept digital credentials or create new supervisory expectations. Institutions must still form a reasonable belief that they know a customer’s true identity, address signs of fraud, and incorporate any credential into a compliant risk-based program.
That flexibility is a strength. It allows financial institutions to adopt better tools while preserving responsibility for effective identity verification.
This is how sustained policy engagement produces results: identify a barrier, develop a workable recommendation, place it consistently before the right agencies, and secure clear federal guidance.
TDC thanks FinCEN and the federal banking agencies for recognizing that modern technology can advance compliance, cybersecurity, innovation, and consumer privacy at the same time.
Read the new FinCEN FAQs