Feature Regulatory Compliance
FinCEN Just Said Mobile Driver's Licenses Are Valid for KYC. Your CIP Probably Doesn't Allow It Yet.
On September 8, 2026, FinCEN and the federal banking agencies issued FAQs clarifying that state-issued mobile driver's licenses and other verifiable digital credentials can satisfy CIP documentary identification requirements — with three specific conditions your program needs to meet first.
Table of Contents
TL;DR
- On September 8, 2026, FinCEN, OCC, Fed, FDIC, and NCUA jointly issued FAQs confirming that state-issued mobile driver’s licenses and other verifiable digital credentials can satisfy the CIP rule’s documentary identification requirement.
- There are three gates a VDC must clear: it evidences nationality or residence and bears a photograph; the institution has the technology to extract the data; and the institution’s CIP explicitly permits its use.
- Most institutions’ CIP policies were written before mDLs existed. They don’t permit VDC use. This guidance doesn’t automatically fix that.
- The fraud consideration still applies. A cryptographically valid mDL doesn’t override an obligation to form a reasonable belief about the customer’s true identity.
- This is an interpretive guidance — it doesn’t change the BSA or create new exam requirements. It clarifies that existing CIP definitions are broad enough to cover VDCs when the conditions are met.
A customer opens an account on their phone and holds up an Apple Wallet card instead of a plastic driver’s license. The compliance question has been the same for years: does that satisfy the Customer Identification Program rule?
On September 8, 2026, FinCEN and the federal banking agencies answered it. OCC Bulletin 2026-44 — co-issued with the Federal Reserve, FDIC, and NCUA — confirms that an unexpired, government-issued verifiable digital credential can qualify as “government-issued identification” under the CIP rule. Mobile driver’s licenses are the leading example.
The headline is clear. The operational implications are not.
What a Verifiable Digital Credential Actually Is
The FAQs define a verifiable digital credential as a data structure that holds information about an individual, is digitally signed by its issuing source (the state DMV, for example), is cryptographically tied to a specific device, and is secured by an activation factor — a PIN, password, or biometric.
This definition is technical, and intentionally so. An mDL stored in Apple Wallet or Google Wallet that meets ISO 18013-5 standards generally fits it. A photo of a driver’s license, a scanned PDF, or a screenshot does not. The cryptographic binding to a device — meaning the credential can only be presented from the device it was issued to — is a fraud-reduction feature that distinguishes a VDC from a physical copy of identifying information.
The fact that the agencies wrote a technical definition matters for compliance programs. Your CIP needs to specify not just that “mobile driver’s licenses are accepted” but what characteristics the credential must have to qualify. A policy that says “we accept digital IDs” without specifying the cryptographic signing and device-binding requirements creates an ambiguity that fraud actors will eventually exploit.
The Three-Part Test
The guidance is structured as a conditional: a VDC may qualify as government-issued identification provided three conditions are met.
Condition 1: The VDC evidences nationality or residence and bears a photograph.
This is the same basic content requirement that applies to physical ID documents. A state-issued mDL meets it — it contains the holder’s photograph, name, date of birth, and state address. The photograph requirement is significant for digital credentials because some proposed VDC formats would allow selective disclosure of specific attributes without sharing a photo. Under current CIP rules, a photo is required. A privacy-preserving credential that shares only name, date of birth, and address — without a photograph — does not qualify under this condition, even if it meets the technical definition of a VDC.
Condition 2: The institution has the technology or systems necessary to extract the appropriate information.
This is the gate most institutions haven’t cleared yet. Extracting information from an mDL is not the same as asking a customer to read their license number aloud. It requires a reader application capable of communicating with the mDL via NFC or QR code, authenticating the digital signature, and extracting the required data fields — including confirming the credential’s cryptographic validity and that it hasn’t been revoked.
Some digital onboarding platforms have added this capability. Most haven’t, and most institutions haven’t confirmed whether their existing technology stack can do it. Before you can tell your operations team that mDLs are accepted, someone needs to verify that the actual verification workflow works.
Condition 3: The institution’s CIP permits its use.
This is the easiest condition to state and the most likely to be out of compliance right now. CIP policies written in 2018, 2020, or even 2023 typically enumerate specific document types: U.S. passport, state driver’s license, state ID card, military ID. Mobile driver’s licenses didn’t exist as a regulated category when most of those policies were written.
A CIP that says “state-issued driver’s license” and doesn’t explicitly address VDCs is ambiguous. Some compliance teams will read it as covering mDLs; some examiners will not. The appropriate fix is a CIP policy update that explicitly addresses verifiable digital credentials: what qualifies, what technology is required, what fraud indicators trigger enhanced review, and what the procedure is when an mDL cannot be verified through the institution’s system.
The Fraud Problem Doesn’t Go Away
The guidance is explicit: a VDC is not automatically sufficient if there are indications of fraud. The institution must still form a reasonable belief that it knows the customer’s true identity.
This is the same standard that applies to physical documents, and it carries the same operational weight. A state-issued mDL with a valid cryptographic signature doesn’t mean the person presenting it is the legitimate holder of that credential. Account takeover fraud, stolen device access, and deepfake-assisted identity attacks are all threat vectors for digital credential presentation that don’t exist in the same form for physical documents presented in person.
After the IDScan.net breach exposed 153 million driver’s license records on the dark web, the practical risk of synthetic identity fraud using compromised identity data became more concrete. An mDL issued to a legitimate person, presented from a compromised device or replicated through a fraudulent mDL reader, is a scenario that fraud controls need to address — not just a scenario that the CIP rule’s documentary verification requirement resolves.
Institutions accepting mDLs need fraud-indicator protocols specifically designed for digital credential presentation: device risk scoring, behavioral analytics during the verification session, cross-checks against identity databases that aren’t dependent on the stolen data the mDL itself contains, and escalation procedures when the verification session looks inconsistent with legitimate use.
Why This Matters for Fintech KYC Programs
For fintechs operating fully digital onboarding workflows, the mDL guidance removes a significant conceptual uncertainty. The question “can we accept the mobile driver’s license the customer pulled up on their phone?” has had an unclear answer for years. Some onboarding vendors built mDL acceptance into their pipelines on the theory that regulators would eventually catch up; others refused to commit.
The September 8 guidance settles the conceptual question. An mDL can satisfy documentary CIP requirements. The operational question — whether your specific platform, using your specific technology, with your specific CIP policy, satisfies all three conditions for a specific mDL — still requires institution-by-institution analysis.
Fintechs that rely on third-party KYC vendors for document verification need to ask their vendors directly:
- Does your platform support ISO 18013-5 compliant mDL verification?
- How do you authenticate the digital signature and confirm device binding?
- What does your fraud scoring model look like for mDL presentations specifically?
- Do you log the cryptographic verification result separately from the extracted identity data, so we have an audit trail?
Your BSA/AML compliance program’s CIP procedures need to scale with your onboarding volume — and the CIP policy update this guidance requires is a scaling decision, not just a documentation update. If you’re accepting mDLs at volume through a third-party platform, the fraud controls need to keep pace with the verification volume.
What Non-Bank Financial Institutions Need to Know
The guidance was issued jointly by FinCEN and the federal banking agencies. The CIP rule applies to banks, savings associations, credit unions, and broker-dealers — institutions directly subject to that rule’s requirements. Non-bank financial institutions that aren’t directly subject to the CIP rule may still need to understand it: if you use a bank partner for deposit account products, your bank partner’s CIP applies to your customers, and the bank will have questions about what identity documentation your onboarding workflow captures and whether it satisfies their CIP requirements.
The FTC Safeguards Rule’s customer identification requirements for non-bank financial institutions also interact here. Non-bank financial institutions have been under the FTC Safeguards Rule’s full requirements for three years, and the rule’s customer data protection and access-management requirements apply to identity documentation — digital or physical — that you collect and store.
The Practical Checklist
If you’re evaluating whether and how to accept mDLs or other VDCs in your onboarding workflow, work through this in order:
| Step | What to Assess | Who Owns It |
|---|---|---|
| Technology confirmation | Does your onboarding platform support ISO 18013-5 mDL verification? Can it authenticate digital signatures and confirm device binding? | Technology / Vendor Management |
| CIP policy update | Does your existing CIP explicitly address VDCs? Update to specify acceptable credential types, minimum characteristics, and the fraud-indicator review process | Compliance |
| Fraud controls | Do your existing identity fraud controls address digital credential presentation specifically? Are device risk scoring and behavioral analytics in place? | Fraud / InfoSec |
| Vendor questionnaire | For third-party KYC vendors: what mDL capabilities do they offer, what fraud signals do they check, and what audit trail do they produce? | TPRM / Compliance |
| Exam readiness | Can you produce documentation showing: (a) your CIP permits VDC use, (b) your technology can extract and authenticate the required data, and (c) your fraud controls address digital credential-specific risks? | Compliance / Risk |
So What?
FinCEN’s September 8 guidance is permissive, not mandatory. No one is required to accept mobile driver’s licenses. But for institutions running digital-first onboarding workflows, the guidance removes the regulatory uncertainty that has been a friction point for mDL adoption.
The three conditions — photograph and nationality evidence, technology capability, and CIP policy permission — aren’t burdensome on their own. The challenge is that most institutions don’t have all three in place. The technology may exist in the vendor stack but hasn’t been turned on. The CIP policy probably predates mDLs as a category. The fraud controls probably weren’t designed with digital credential-specific attacks in mind.
The guidance creates a clear implementation checklist. Working through it is a reasonable compliance project, not a major program overhaul. Start with the CIP policy update — that one is entirely within your control and doesn’t require a technology decision. Then assess your onboarding platform’s capabilities and your fraud controls. Most institutions will find the path to mDL acceptance shorter than they expected once the three-part test is on paper.
Managing BSA/AML and CIP documentation? The AML/BSA Risk Assessment Template includes a CIP program assessment module, high-risk customer due diligence workflows, and a FinCEN exam preparation checklist for regulated institutions and their fintech partners.
◆ Related template
AML/BSA Risk Assessment Template (Fintech Edition)
32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did FinCEN clarify on September 8, 2026 about mobile driver's licenses?
What is a verifiable digital credential (VDC)?
Does the September 8 guidance change the BSA requirements for customer identification?
What do banks need to do before accepting mobile driver's licenses for KYC?
What states have issued mobile driver's licenses that could qualify under the CIP guidance?
What happens if there are fraud indicators on a verifiable digital credential?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AML/BSA Risk Assessment Template (Fintech Edition)
32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.
◆ Keep reading
Related posts.
Regulatory Compliance
Federal Reserve Stress Test Overhaul: What Risk and Capital Teams Need to Change Now
The Federal Reserve stress test overhaul adds model transparency, two-year averaging, and new supervisory uses. Here is the control impact.
Sep 19, 2026
Regulatory Compliance
The SEC's Securities Lending Reporting Deadline Is Nine Days Away. Here's What Your Firm Still Needs to Build.
SEC Rule 10c-1a requires broker-dealers, agent lenders, and custodian banks to report securities lending transactions to FINRA SLATE by September 28, 2026. Here is what covered persons must have in place before the deadline.
Sep 19, 2026
Regulatory Compliance
FINRA Rule 3290 Approved: Rebuild Your Outside Activities Program Before the Effective Date
FINRA Rule 3290 is approved. See what changes for outside activities, private securities transactions, supervision, records, and implementation.
Sep 17, 2026