News

US Regulators Confirm Banks Can Accept Mobile Driver's Licences When Opening Accounts

Moca Network
September 17, 2026

On 8 September 2026, FinCEN and the staffs of the Federal Reserve Board, FDIC, NCUA and OCC confirmed that an unexpired, government-issued verifiable digital credential, such as a state mobile driver's licence (mDL), can count as "government-issued identification" for documentary verification under the Customer Identification Program (CIP) Rule. Credentials issued by non-government third parties remain usable too, but only as one of a bank's verification methods, and only if the bank ensures the issuer authenticates people as strongly as the bank itself would.

The guidance takes the form of two new FAQs and one amended FAQ. It does not change the law, but it answers whether a signed credential on a phone can stand in for a plastic card at account opening.

Key takeaways

  • The FAQs were issued on 8 September 2026 by FinCEN jointly with the staffs of the Federal Reserve Board, FDIC, NCUA and OCC.
  • A verifiable digital credential (VDC) is signed by its issuer, bound to a device and protected by a PIN or biometric.
  • An unexpired government-issued VDC such as an mDL can be a documentary verification method, if it evidences nationality or residence, bears a photograph or similar safeguard, and the bank has the technology to extract the data.
  • For credentials issued by non-government third parties, the bank is responsible for ensuring the issuer uses the same level of authentication the bank would use.
  • The CIP Rule neither requires nor prohibits reliance on government-issued VDCs, and the FAQs create no new supervisory expectations.

What FinCEN and the banking agencies published

The FinCEN announcement covers the use of state-issued mDLs and other government-issued VDCs to verify natural person customers under the CIP Rule at 31 C.F.R. § 1020.220. The FDIC circulated it to all FDIC-insured institutions as FIL-56-2026.

The scope is narrow: identity verification at account opening for individual customers of banks and credit unions. The FAQs state that their answers "neither alter existing BSA legal or regulatory requirements nor establish new supervisory expectations." As ABA Banking Journal reported, the effect is permission, not obligation.

What the three FAQs say

FAQQuestionWhat the agencies say
1 (new)What is a verifiable digital credential?A data structure containing information about an individual, digitally signed by the issuing source, cryptographically bound to a device, and protected by an activation factor: something the user knows (PIN or password) or a physical biometric such as a face or fingerprint.
2 (new)Can a bank use a government-issued VDC, such as an mDL, to verify a customer opening an account in person, online or through another digital channel?Yes. An unexpired government-issued VDC qualifies as "government-issued identification" if it evidences nationality or residence and bears a photograph or similar safeguard. The bank needs technology to extract the information, and the use must be allowed under its CIP. The CIP Rule neither requires nor prohibits this. Indications of fraud must be considered.
3 (amended)Can a bank use an electronic credential, such as a digital certificate or VDC, as a non-documentary means of verification?Yes, as one of its methods, to the extent its CIP permits. The bank must still form a reasonable belief it knows the customer's true identity. For credentials issued and maintained by a non-government third party, the bank must ensure that party uses the same level of authentication the bank would use.

Two routes, two different tests

The most useful thing the FAQs do is separate credentials by who issues them.

Government-issued credentials take the documentary route. The CIP Rule's documentary method for individuals has always pointed to "unexpired government-issued identification evidencing nationality or residence and bearing a photograph or similar safeguard, such as a driver's license or passport." FAQ 2 confirms that a state mDL meets that description in digital form, provided the bank can extract and read the signed data.

Third-party credentials take the non-documentary route. Any VDC issued and maintained by a non-government party sits under FAQ 3. It can be one of the methods a bank uses, alongside checks against a consumer reporting agency, a public database or "other source", but it does not become government ID.

The test for the second route is about the issuer. A cryptographic signature proves a credential has not been altered and came from the party that signed it. It says nothing, on its own, about how carefully that party checked the person before issuing it. FAQ 3 closes that gap by making the bank responsible for the issuer's authentication standard, and it points to the FFIEC's authentication guidance. The FFIEC's current guidance, issued on 11 August 2021, superseded its 2005 and 2011 documents and stresses risk assessment and multi-factor authentication or controls of equivalent strength.

Why issuer assurance is the question to answer

For compliance teams, FAQ 3 turns a technology question into a due diligence question. Before accepting a private credential, a bank needs to know who issued it, what checks that issuer ran, how it authenticated the person, and whether that standard matches the bank's own.

This is not the CIP Rule's separate reliance provision, which has its own conditions, including annual certification by a federally regulated institution. Accepting a credential as one verification method leaves the bank with the full obligation to form a reasonable belief about the customer's identity. Fraud stays in view too: even a government-issued credential that shows indications of fraud must be weighed accordingly.

A welcome step

We welcome the agencies' clarification. It shows banks and credit unions how existing rules apply to credentials their customers increasingly carry, without adding obligations or lowering the bar, and it gives the market a shared, technology-neutral definition of a VDC.

The controls around these credentials cannot be set once and left. Institutions that adopt mDLs or third-party credentials should review and recalibrate them continually, as technology and fraud risks evolve. We covered government rollouts in government digital credentials in 2026 and public-sector login mandates in our analysis of government single sign-on.

Where verifiable credentials fit

AIR Identity, built by Moca Network, is a credential network with two sides. Trusted issuers, such as banks, fintechs, platforms and licensed KYC partners, issue reusable, user-held credentials from checks they have already run: passed KYC, residency, account tenure or membership tier. Verifiers request a proof of only the fact they need and receive a yes or no answer through zero-knowledge proofs, with the user's consent, and pay only upon receipt of verification.

AIR credentials are issued by non-government parties. They are not government-issued identification and do not qualify as a documentary method under the CIP Rule. A bank that chose to use them would do so only on the third-party, non-documentary route, where its CIP permits it, as an additional layer alongside a bank's documentary, biometric and database checks. Each verifier remains responsible for deciding whether a given credential satisfies its own regulatory requirements.

CIP requirementWhat stays with existing controlsWhat a credential layer can add
Collect name, date of birth, address and identification numberThe bank's own application form and CIP data collectionA proof that the applicant already passed KYC with a known issuer, before the bank spends effort on a full application
Documentary verificationPhysical ID or an unexpired government-issued VDC such as an mDL, read by the bank's own systemsNothing replaces this step; a third-party credential is not government ID
Non-documentary verificationConsumer reporting agency, public database and other independent source checksA signed issuer attestation of a specific fact, such as residency, as one additional method where the bank's CIP permits it
Issuer authentication equal to the bank's ownThe bank's due diligence on each issuer, measured against FFIEC authentication guidanceA credential signed by an identifiable issuer, so the bank can assess that issuer's check and authentication standard
Consider indications of fraudFraud screening, device signals and manual reviewA further independent signal from a prior check, cross-checked against what the applicant presents
Reasonable belief of true identityThe bank's overall CIP judgementCorroboration from a prior check by an identifiable issuer, with minimal data custody for the verifier

The acquisition value sits in the first row. A bank or fintech partner can reach applicants who already hold credentials showing they meet its criteria, such as residency in a target market or a completed KYC check with a regulated issuer, and spend onboarding budget on people likely to qualify. The bank still runs its own CIP on every one of them. See central KYC registries versus reusable credentials and why less stored identity data means less breach exposure in our analysis of verification data storage risk.

What banks can do now

  1. Update the CIP. State whether mDLs and other government-issued VDCs are accepted, and confirm the systems to read them.
  2. Separate the two routes. Treat government-issued VDCs as documentary and third-party credentials as non-documentary.
  3. Keep an issuer due diligence file. Record what each third-party issuer checks and how it authenticates people, against the bank's own standard.
  4. Recalibrate on a schedule. Review credential and fraud controls regularly and whenever fraud patterns shift.

Our read

The agencies have done something useful and restrained. They defined the credential, fitted government mobile IDs into the existing documentary rule, and made private credentials acceptable only when the bank can vouch for the issuer's checks. That puts issuer assurance at the centre of digital onboarding, where it belongs. Credential networks that make the issuer and its standard visible can support the banks' own controls but never stand in for them.

Frequently asked questions

Can banks accept a mobile driver's licence to open an account?

Yes. Under the 8 September 2026 FAQs, a bank or credit union may accept an unexpired state-issued mDL as documentary verification under the CIP Rule, if it evidences nationality or residence, bears a photograph or similar safeguard, and the bank can read it and its CIP allows it.

What is a verifiable digital credential under the CIP Rule?

The agencies define a verifiable digital credential as a data structure containing information about an individual that is digitally signed by the issuing source, cryptographically bound to a device, and protected by an activation factor such as a PIN, password or biometric.

Are banks required to accept mobile driver's licences?

No. The FAQs state that the CIP Rule neither requires nor prohibits reliance on government-issued VDCs.

Can a bank use a digital credential issued by a private company?

Yes, as a non-documentary method where the bank's CIP permits it. The bank remains responsible for ensuring the non-government issuer uses the same level of authentication the bank would use.

Do the FAQs change Bank Secrecy Act requirements?

No. The agencies state that the answers neither alter existing BSA legal or regulatory requirements nor establish new supervisory expectations.

Want to reach applicants who already hold the credentials your onboarding needs, alongside your own CIP checks? See how AIR Identity works, or partner with us to grow your business.

Sources

Partner with AIR

AIR is one integration suite for identity, money and loyalty. AIR Identity lets trusted issuers issue verifiable credentials and businesses verify them, so acquisition starts with users who already qualify, with minimal data custody. AIR Money embeds compliant global financial infrastructure, opening new markets without building new rails. AIR Loyalty gives brands a programmable, stable-value points engine that keeps users coming back.

Partner with us to grow your business.

AIR is built by Moca Network, the identity network of Animoca Brands.

Stay updated on AIR launches
Product updates, partner launches, and research across digital identity, fintech, and loyalty. Unsubscribe anytime.
By subscribing, you agree to our Privacy Policy and consent to receive updates.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
In this article
Blog

Read more articles

Lorem ipsum dolor sit amet, consectetur adipiscing elit.
View all
News
Three Turkish Regulators Now Put the NFC Chip at the Centre of Remote Onboarding
MASAK, the CMB and the CBRT now anchor remote onboarding in Türkiye to NFC chip reading, and open it to foreign nationals holding ICAO 9303 passports.
News
The EU KIDS Act Proposes 15 as the Minimum Age for Independent Social Media Accounts
The EU KIDS Act proposal sets 15 as the minimum age for independent social media accounts, adds supervised accounts from 13 and requires certified age checks.
News
South Korea's Amended Privacy Law Lets the Regulator Fine Serious Breaches up to 10% of Total Revenue
South Korea's amended privacy law took effect on 11 September 2026: fines up to 10% of total revenue, CEO accountability and 72-hour notice of possible leaks.