Skip to content
RiskTemplates · The Daily Brief Saturday, September 19, 2026
Wire SEC's $64 Million Croft & Frost Offering Fraud Case: The Warning Email Compliance Teams Cannot Ignore SEP 14

Feature Regulatory Compliance

FinCEN Just Said Mobile Driver's Licenses Are Valid for KYC. Your CIP Probably Doesn't Allow It Yet.

On September 8, 2026, FinCEN and the federal banking agencies issued FAQs clarifying that state-issued mobile driver's licenses and other verifiable digital credentials can satisfy CIP documentary identification requirements — with three specific conditions your program needs to meet first.

By Rebecca Leung · September 18, 2026 ·
Table of Contents

TL;DR

  • On September 8, 2026, FinCEN, OCC, Fed, FDIC, and NCUA jointly issued FAQs confirming that state-issued mobile driver’s licenses and other verifiable digital credentials can satisfy the CIP rule’s documentary identification requirement.
  • There are three gates a VDC must clear: it evidences nationality or residence and bears a photograph; the institution has the technology to extract the data; and the institution’s CIP explicitly permits its use.
  • Most institutions’ CIP policies were written before mDLs existed. They don’t permit VDC use. This guidance doesn’t automatically fix that.
  • The fraud consideration still applies. A cryptographically valid mDL doesn’t override an obligation to form a reasonable belief about the customer’s true identity.
  • This is an interpretive guidance — it doesn’t change the BSA or create new exam requirements. It clarifies that existing CIP definitions are broad enough to cover VDCs when the conditions are met.

A customer opens an account on their phone and holds up an Apple Wallet card instead of a plastic driver’s license. The compliance question has been the same for years: does that satisfy the Customer Identification Program rule?

On September 8, 2026, FinCEN and the federal banking agencies answered it. OCC Bulletin 2026-44 — co-issued with the Federal Reserve, FDIC, and NCUA — confirms that an unexpired, government-issued verifiable digital credential can qualify as “government-issued identification” under the CIP rule. Mobile driver’s licenses are the leading example.

The headline is clear. The operational implications are not.

What a Verifiable Digital Credential Actually Is

The FAQs define a verifiable digital credential as a data structure that holds information about an individual, is digitally signed by its issuing source (the state DMV, for example), is cryptographically tied to a specific device, and is secured by an activation factor — a PIN, password, or biometric.

This definition is technical, and intentionally so. An mDL stored in Apple Wallet or Google Wallet that meets ISO 18013-5 standards generally fits it. A photo of a driver’s license, a scanned PDF, or a screenshot does not. The cryptographic binding to a device — meaning the credential can only be presented from the device it was issued to — is a fraud-reduction feature that distinguishes a VDC from a physical copy of identifying information.

The fact that the agencies wrote a technical definition matters for compliance programs. Your CIP needs to specify not just that “mobile driver’s licenses are accepted” but what characteristics the credential must have to qualify. A policy that says “we accept digital IDs” without specifying the cryptographic signing and device-binding requirements creates an ambiguity that fraud actors will eventually exploit.

The Three-Part Test

The guidance is structured as a conditional: a VDC may qualify as government-issued identification provided three conditions are met.

Condition 1: The VDC evidences nationality or residence and bears a photograph.

This is the same basic content requirement that applies to physical ID documents. A state-issued mDL meets it — it contains the holder’s photograph, name, date of birth, and state address. The photograph requirement is significant for digital credentials because some proposed VDC formats would allow selective disclosure of specific attributes without sharing a photo. Under current CIP rules, a photo is required. A privacy-preserving credential that shares only name, date of birth, and address — without a photograph — does not qualify under this condition, even if it meets the technical definition of a VDC.

Condition 2: The institution has the technology or systems necessary to extract the appropriate information.

This is the gate most institutions haven’t cleared yet. Extracting information from an mDL is not the same as asking a customer to read their license number aloud. It requires a reader application capable of communicating with the mDL via NFC or QR code, authenticating the digital signature, and extracting the required data fields — including confirming the credential’s cryptographic validity and that it hasn’t been revoked.

Some digital onboarding platforms have added this capability. Most haven’t, and most institutions haven’t confirmed whether their existing technology stack can do it. Before you can tell your operations team that mDLs are accepted, someone needs to verify that the actual verification workflow works.

Condition 3: The institution’s CIP permits its use.

This is the easiest condition to state and the most likely to be out of compliance right now. CIP policies written in 2018, 2020, or even 2023 typically enumerate specific document types: U.S. passport, state driver’s license, state ID card, military ID. Mobile driver’s licenses didn’t exist as a regulated category when most of those policies were written.

A CIP that says “state-issued driver’s license” and doesn’t explicitly address VDCs is ambiguous. Some compliance teams will read it as covering mDLs; some examiners will not. The appropriate fix is a CIP policy update that explicitly addresses verifiable digital credentials: what qualifies, what technology is required, what fraud indicators trigger enhanced review, and what the procedure is when an mDL cannot be verified through the institution’s system.

The Fraud Problem Doesn’t Go Away

The guidance is explicit: a VDC is not automatically sufficient if there are indications of fraud. The institution must still form a reasonable belief that it knows the customer’s true identity.

This is the same standard that applies to physical documents, and it carries the same operational weight. A state-issued mDL with a valid cryptographic signature doesn’t mean the person presenting it is the legitimate holder of that credential. Account takeover fraud, stolen device access, and deepfake-assisted identity attacks are all threat vectors for digital credential presentation that don’t exist in the same form for physical documents presented in person.

After the IDScan.net breach exposed 153 million driver’s license records on the dark web, the practical risk of synthetic identity fraud using compromised identity data became more concrete. An mDL issued to a legitimate person, presented from a compromised device or replicated through a fraudulent mDL reader, is a scenario that fraud controls need to address — not just a scenario that the CIP rule’s documentary verification requirement resolves.

Institutions accepting mDLs need fraud-indicator protocols specifically designed for digital credential presentation: device risk scoring, behavioral analytics during the verification session, cross-checks against identity databases that aren’t dependent on the stolen data the mDL itself contains, and escalation procedures when the verification session looks inconsistent with legitimate use.

Why This Matters for Fintech KYC Programs

For fintechs operating fully digital onboarding workflows, the mDL guidance removes a significant conceptual uncertainty. The question “can we accept the mobile driver’s license the customer pulled up on their phone?” has had an unclear answer for years. Some onboarding vendors built mDL acceptance into their pipelines on the theory that regulators would eventually catch up; others refused to commit.

The September 8 guidance settles the conceptual question. An mDL can satisfy documentary CIP requirements. The operational question — whether your specific platform, using your specific technology, with your specific CIP policy, satisfies all three conditions for a specific mDL — still requires institution-by-institution analysis.

Fintechs that rely on third-party KYC vendors for document verification need to ask their vendors directly:

  • Does your platform support ISO 18013-5 compliant mDL verification?
  • How do you authenticate the digital signature and confirm device binding?
  • What does your fraud scoring model look like for mDL presentations specifically?
  • Do you log the cryptographic verification result separately from the extracted identity data, so we have an audit trail?

Your BSA/AML compliance program’s CIP procedures need to scale with your onboarding volume — and the CIP policy update this guidance requires is a scaling decision, not just a documentation update. If you’re accepting mDLs at volume through a third-party platform, the fraud controls need to keep pace with the verification volume.

What Non-Bank Financial Institutions Need to Know

The guidance was issued jointly by FinCEN and the federal banking agencies. The CIP rule applies to banks, savings associations, credit unions, and broker-dealers — institutions directly subject to that rule’s requirements. Non-bank financial institutions that aren’t directly subject to the CIP rule may still need to understand it: if you use a bank partner for deposit account products, your bank partner’s CIP applies to your customers, and the bank will have questions about what identity documentation your onboarding workflow captures and whether it satisfies their CIP requirements.

The FTC Safeguards Rule’s customer identification requirements for non-bank financial institutions also interact here. Non-bank financial institutions have been under the FTC Safeguards Rule’s full requirements for three years, and the rule’s customer data protection and access-management requirements apply to identity documentation — digital or physical — that you collect and store.

The Practical Checklist

If you’re evaluating whether and how to accept mDLs or other VDCs in your onboarding workflow, work through this in order:

StepWhat to AssessWho Owns It
Technology confirmationDoes your onboarding platform support ISO 18013-5 mDL verification? Can it authenticate digital signatures and confirm device binding?Technology / Vendor Management
CIP policy updateDoes your existing CIP explicitly address VDCs? Update to specify acceptable credential types, minimum characteristics, and the fraud-indicator review processCompliance
Fraud controlsDo your existing identity fraud controls address digital credential presentation specifically? Are device risk scoring and behavioral analytics in place?Fraud / InfoSec
Vendor questionnaireFor third-party KYC vendors: what mDL capabilities do they offer, what fraud signals do they check, and what audit trail do they produce?TPRM / Compliance
Exam readinessCan you produce documentation showing: (a) your CIP permits VDC use, (b) your technology can extract and authenticate the required data, and (c) your fraud controls address digital credential-specific risks?Compliance / Risk

So What?

FinCEN’s September 8 guidance is permissive, not mandatory. No one is required to accept mobile driver’s licenses. But for institutions running digital-first onboarding workflows, the guidance removes the regulatory uncertainty that has been a friction point for mDL adoption.

The three conditions — photograph and nationality evidence, technology capability, and CIP policy permission — aren’t burdensome on their own. The challenge is that most institutions don’t have all three in place. The technology may exist in the vendor stack but hasn’t been turned on. The CIP policy probably predates mDLs as a category. The fraud controls probably weren’t designed with digital credential-specific attacks in mind.

The guidance creates a clear implementation checklist. Working through it is a reasonable compliance project, not a major program overhaul. Start with the CIP policy update — that one is entirely within your control and doesn’t require a technology decision. Then assess your onboarding platform’s capabilities and your fraud controls. Most institutions will find the path to mDL acceptance shorter than they expected once the three-part test is on paper.


Managing BSA/AML and CIP documentation? The AML/BSA Risk Assessment Template includes a CIP program assessment module, high-risk customer due diligence workflows, and a FinCEN exam preparation checklist for regulated institutions and their fintech partners.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did FinCEN clarify on September 8, 2026 about mobile driver's licenses?
FinCEN and the OCC, Federal Reserve, FDIC, and NCUA jointly issued FAQs (OCC Bulletin 2026-44) clarifying that an unexpired, government-issued verifiable digital credential (VDC) — including a state-issued mobile driver's license (mDL) — may qualify as 'government-issued identification' under the CIP rule, provided three conditions are met: the VDC evidences nationality or residence and bears a photograph, the institution has the technology to extract the required information, and the institution's CIP explicitly permits its use.
What is a verifiable digital credential (VDC)?
A VDC is a data structure holding information about an individual that is digitally signed by its issuing source, cryptographically tied to a specific device, and secured by an activation factor such as a PIN, password, or biometric. A state-issued mobile driver's license stored in Apple Wallet or Google Wallet is one example of a VDC.
Does the September 8 guidance change the BSA requirements for customer identification?
No. The guidance does not alter existing Bank Secrecy Act requirements or establish new supervisory expectations. It clarifies that existing CIP rule definitions are broad enough to accommodate VDCs — the guidance is interpretive, not a new rule.
What do banks need to do before accepting mobile driver's licenses for KYC?
Three things: (1) update the institution's CIP to explicitly permit VDC or mDL use; (2) confirm or acquire the technology and systems needed to extract and authenticate the embedded data (cryptographic verification, not just a screenshot); and (3) build fraud-indicator checks into the onboarding workflow to ensure the institution can still form a reasonable belief about the customer's true identity.
What states have issued mobile driver's licenses that could qualify under the CIP guidance?
As of 2026, multiple U.S. states have issued ISO 18013-5 compliant mobile driver's licenses, including California, Colorado, Arizona, Georgia, Maryland, and others. Apple Wallet and Google Wallet both support accepted state mDLs. Not all state mDL implementations are identical, and institutions should confirm that any mDL they accept meets the VDC definition in the FAQs.
What happens if there are fraud indicators on a verifiable digital credential?
A VDC is not automatically sufficient if there are indications of fraud. Even a government-issued, cryptographically valid mDL does not clear the CIP hurdle if the institution cannot form a reasonable belief that it knows the customer's true identity. The fraud consideration doesn't go away with digital credentials — it moves earlier in the verification workflow.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AML/BSA Risk Assessment Template (Fintech Edition)

32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.