US Regulators Confirm Banks Can Accept Mobile Driver's Licences When Opening Accounts
On 8 September 2026, FinCEN and the staffs of the Federal Reserve Board, FDIC, NCUA and OCC confirmed that an unexpired, government-issued verifiable digital credential, such as a state mobile driver's licence (mDL), can count as "government-issued identification" for documentary verification under the Customer Identification Program (CIP) Rule. Credentials issued by non-government third parties remain usable too, but only as one of a bank's verification methods, and only if the bank ensures the issuer authenticates people as strongly as the bank itself would.
The guidance takes the form of two new FAQs and one amended FAQ. It does not change the law, but it answers whether a signed credential on a phone can stand in for a plastic card at account opening.
Key takeaways
- The FAQs were issued on 8 September 2026 by FinCEN jointly with the staffs of the Federal Reserve Board, FDIC, NCUA and OCC.
- A verifiable digital credential (VDC) is signed by its issuer, bound to a device and protected by a PIN or biometric.
- An unexpired government-issued VDC such as an mDL can be a documentary verification method, if it evidences nationality or residence, bears a photograph or similar safeguard, and the bank has the technology to extract the data.
- For credentials issued by non-government third parties, the bank is responsible for ensuring the issuer uses the same level of authentication the bank would use.
- The CIP Rule neither requires nor prohibits reliance on government-issued VDCs, and the FAQs create no new supervisory expectations.
What FinCEN and the banking agencies published
The FinCEN announcement covers the use of state-issued mDLs and other government-issued VDCs to verify natural person customers under the CIP Rule at 31 C.F.R. § 1020.220. The FDIC circulated it to all FDIC-insured institutions as FIL-56-2026.
The scope is narrow: identity verification at account opening for individual customers of banks and credit unions. The FAQs state that their answers "neither alter existing BSA legal or regulatory requirements nor establish new supervisory expectations." As ABA Banking Journal reported, the effect is permission, not obligation.
What the three FAQs say
| FAQ | Question | What the agencies say |
|---|---|---|
| 1 (new) | What is a verifiable digital credential? | A data structure containing information about an individual, digitally signed by the issuing source, cryptographically bound to a device, and protected by an activation factor: something the user knows (PIN or password) or a physical biometric such as a face or fingerprint. |
| 2 (new) | Can a bank use a government-issued VDC, such as an mDL, to verify a customer opening an account in person, online or through another digital channel? | Yes. An unexpired government-issued VDC qualifies as "government-issued identification" if it evidences nationality or residence and bears a photograph or similar safeguard. The bank needs technology to extract the information, and the use must be allowed under its CIP. The CIP Rule neither requires nor prohibits this. Indications of fraud must be considered. |
| 3 (amended) | Can a bank use an electronic credential, such as a digital certificate or VDC, as a non-documentary means of verification? | Yes, as one of its methods, to the extent its CIP permits. The bank must still form a reasonable belief it knows the customer's true identity. For credentials issued and maintained by a non-government third party, the bank must ensure that party uses the same level of authentication the bank would use. |
Two routes, two different tests
The most useful thing the FAQs do is separate credentials by who issues them.
Government-issued credentials take the documentary route. The CIP Rule's documentary method for individuals has always pointed to "unexpired government-issued identification evidencing nationality or residence and bearing a photograph or similar safeguard, such as a driver's license or passport." FAQ 2 confirms that a state mDL meets that description in digital form, provided the bank can extract and read the signed data.
Third-party credentials take the non-documentary route. Any VDC issued and maintained by a non-government party sits under FAQ 3. It can be one of the methods a bank uses, alongside checks against a consumer reporting agency, a public database or "other source", but it does not become government ID.
The test for the second route is about the issuer. A cryptographic signature proves a credential has not been altered and came from the party that signed it. It says nothing, on its own, about how carefully that party checked the person before issuing it. FAQ 3 closes that gap by making the bank responsible for the issuer's authentication standard, and it points to the FFIEC's authentication guidance. The FFIEC's current guidance, issued on 11 August 2021, superseded its 2005 and 2011 documents and stresses risk assessment and multi-factor authentication or controls of equivalent strength.
Why issuer assurance is the question to answer
For compliance teams, FAQ 3 turns a technology question into a due diligence question. Before accepting a private credential, a bank needs to know who issued it, what checks that issuer ran, how it authenticated the person, and whether that standard matches the bank's own.
This is not the CIP Rule's separate reliance provision, which has its own conditions, including annual certification by a federally regulated institution. Accepting a credential as one verification method leaves the bank with the full obligation to form a reasonable belief about the customer's identity. Fraud stays in view too: even a government-issued credential that shows indications of fraud must be weighed accordingly.
A welcome step
We welcome the agencies' clarification. It shows banks and credit unions how existing rules apply to credentials their customers increasingly carry, without adding obligations or lowering the bar, and it gives the market a shared, technology-neutral definition of a VDC.
The controls around these credentials cannot be set once and left. Institutions that adopt mDLs or third-party credentials should review and recalibrate them continually, as technology and fraud risks evolve. We covered government rollouts in government digital credentials in 2026 and public-sector login mandates in our analysis of government single sign-on.
Where verifiable credentials fit
AIR Identity, built by Moca Network, is a credential network with two sides. Trusted issuers, such as banks, fintechs, platforms and licensed KYC partners, issue reusable, user-held credentials from checks they have already run: passed KYC, residency, account tenure or membership tier. Verifiers request a proof of only the fact they need and receive a yes or no answer through zero-knowledge proofs, with the user's consent, and pay only upon receipt of verification.
AIR credentials are issued by non-government parties. They are not government-issued identification and do not qualify as a documentary method under the CIP Rule. A bank that chose to use them would do so only on the third-party, non-documentary route, where its CIP permits it, as an additional layer alongside a bank's documentary, biometric and database checks. Each verifier remains responsible for deciding whether a given credential satisfies its own regulatory requirements.
| CIP requirement | What stays with existing controls | What a credential layer can add |
|---|---|---|
| Collect name, date of birth, address and identification number | The bank's own application form and CIP data collection | A proof that the applicant already passed KYC with a known issuer, before the bank spends effort on a full application |
| Documentary verification | Physical ID or an unexpired government-issued VDC such as an mDL, read by the bank's own systems | Nothing replaces this step; a third-party credential is not government ID |
| Non-documentary verification | Consumer reporting agency, public database and other independent source checks | A signed issuer attestation of a specific fact, such as residency, as one additional method where the bank's CIP permits it |
| Issuer authentication equal to the bank's own | The bank's due diligence on each issuer, measured against FFIEC authentication guidance | A credential signed by an identifiable issuer, so the bank can assess that issuer's check and authentication standard |
| Consider indications of fraud | Fraud screening, device signals and manual review | A further independent signal from a prior check, cross-checked against what the applicant presents |
| Reasonable belief of true identity | The bank's overall CIP judgement | Corroboration from a prior check by an identifiable issuer, with minimal data custody for the verifier |
The acquisition value sits in the first row. A bank or fintech partner can reach applicants who already hold credentials showing they meet its criteria, such as residency in a target market or a completed KYC check with a regulated issuer, and spend onboarding budget on people likely to qualify. The bank still runs its own CIP on every one of them. See central KYC registries versus reusable credentials and why less stored identity data means less breach exposure in our analysis of verification data storage risk.
What banks can do now
- Update the CIP. State whether mDLs and other government-issued VDCs are accepted, and confirm the systems to read them.
- Separate the two routes. Treat government-issued VDCs as documentary and third-party credentials as non-documentary.
- Keep an issuer due diligence file. Record what each third-party issuer checks and how it authenticates people, against the bank's own standard.
- Recalibrate on a schedule. Review credential and fraud controls regularly and whenever fraud patterns shift.
Our read
The agencies have done something useful and restrained. They defined the credential, fitted government mobile IDs into the existing documentary rule, and made private credentials acceptable only when the bank can vouch for the issuer's checks. That puts issuer assurance at the centre of digital onboarding, where it belongs. Credential networks that make the issuer and its standard visible can support the banks' own controls but never stand in for them.
Frequently asked questions
Can banks accept a mobile driver's licence to open an account?
Yes. Under the 8 September 2026 FAQs, a bank or credit union may accept an unexpired state-issued mDL as documentary verification under the CIP Rule, if it evidences nationality or residence, bears a photograph or similar safeguard, and the bank can read it and its CIP allows it.
What is a verifiable digital credential under the CIP Rule?
The agencies define a verifiable digital credential as a data structure containing information about an individual that is digitally signed by the issuing source, cryptographically bound to a device, and protected by an activation factor such as a PIN, password or biometric.
Are banks required to accept mobile driver's licences?
No. The FAQs state that the CIP Rule neither requires nor prohibits reliance on government-issued VDCs.
Can a bank use a digital credential issued by a private company?
Yes, as a non-documentary method where the bank's CIP permits it. The bank remains responsible for ensuring the non-government issuer uses the same level of authentication the bank would use.
Do the FAQs change Bank Secrecy Act requirements?
No. The agencies state that the answers neither alter existing BSA legal or regulatory requirements nor establish new supervisory expectations.
Want to reach applicants who already hold the credentials your onboarding needs, alongside your own CIP checks? See how AIR Identity works, or partner with us to grow your business.
Sources
- FinCEN, FAQs Regarding Treatment of Verifiable Digital Credentials Under the CIP Rule (PDF)
- FinCEN news release, 8 September 2026
- FDIC FIL-56-2026
- ABA Banking Journal: FinCEN, banking agencies release FAQs on digital credentials, customer ID
- 31 C.F.R. § 1020.220, Customer identification programs for banks
- NCUA: FFIEC issues guidance on authentication and access, 11 August 2021
Partner with AIR
AIR is one integration suite for identity, money and loyalty. AIR Identity lets trusted issuers issue verifiable credentials and businesses verify them, so acquisition starts with users who already qualify, with minimal data custody. AIR Money embeds compliant global financial infrastructure, opening new markets without building new rails. AIR Loyalty gives brands a programmable, stable-value points engine that keeps users coming back.
Partner with us to grow your business.
AIR is built by Moca Network, the identity network of Animoca Brands.

.png)