FinCEN says verifiable digital credentials can verify identity under the CIP rule. What the 8 September 2026 FAQs change, what they do not, and what stays open.
Table of contents
FinCEN and staff of four federal regulators confirmed on 8 September 2026 that banks and credit unions may verify a customer's identity with a state-issued mobile driver's license or another government-issued digital credential under the Customer Identification Program rule, where their written program allows it. The FAQs create no new duties. They rewrite an older answer on electronic credentials.
- FinCEN issued two new FAQs and amended one existing FAQ on 8 September 2026, jointly with staff of the Federal Reserve Board, the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA) and the Office of the Comptroller of the Currency (OCC).
- An unexpired government-issued digital credential can qualify as documentary evidence under 31 CFR 1020.220(a)(2)(ii)(A)(1), provided it evidences nationality or residence and bears a photograph or similar safeguard.
- The agencies were explicit that the answers "neither alter existing BSA legal or regulatory requirements nor establish new supervisory expectations".
- The amended FAQ carries the 2004 third-party authentication duty forward and now scopes it expressly to credentials issued and maintained by a non-government third party.
- The FAQs address banks and credit unions only. The parallel programs at 31 CFR 1023.220, 1024.220 and 1026.220 were untouched.
What did FinCEN actually say about verifiable digital credentials?
FinCEN published two new answers and one amendment on 8 September 2026, developed jointly with staff of the four federal regulators above. The first defines what verifiable digital credentials, abbreviated VDCs in the agencies' text, actually are. The second says a bank or credit union may accept a state-issued mobile driver's license (mDL) when opening an account, in person or remotely.
The definition is narrow. The agencies describe verifiable digital credentials as a data structure containing information about an individual, digitally signed by the issuing source, cryptographically bound to a device, and protected by an activation factor such as a PIN or a biometric. That last element matters: a photograph of a license or a screenshot of an app does not meet the definition, because nothing binds it to a device or to a person.
On whether banks must accept them, the agencies were deliberately neutral. The FAQ states that "The CIP Rule neither requires nor prohibits reliance on such government-issued VDCs" as a means of verifying identity. Acceptance is a choice each institution makes in its own written program, not a mandate.
| Element | What the 8 September 2026 FAQs say |
|---|---|
| Issuing bodies | FinCEN with staff of the Federal Reserve Board, FDIC, NCUA and OCC |
| Instruments | Two new FAQs, one existing FAQ amended |
| Rule affected | 31 CFR 1020.220, banks and credit unions |
| Legal status | Interpretive guidance, not rulemaking, effective on publication |
| New obligations | None stated by the agencies |
| Channels covered | In person, remotely over the internet, or other digital channels |
Is a mobile driver's license documentary or non-documentary evidence?
Documentary, if the institution chooses that path and the issuer is a government. The rule text at 31 CFR 1020.220(a)(2)(ii)(A)(1) covers unexpired government-issued identification, and the agencies read an unexpired state-issued mobile driver's license into that subparagraph alongside a physical license or passport. It is the rule, not the FAQ, that draws the line at the issuer.
That split is the most consequential part of the release: the two paths carry different recordkeeping duties and different failure modes. The issuer decides whether the documentary path is open at all. A bank taking the documentary route must hold "the appropriate technology or systems to extract the relevant information" from the credential, and its written program must allow it. A bank obtaining a credential from a private provider is treated under the non-documentary answer, and inherits responsibility for that provider's authentication quality.
The amendment to the older answer is easy to miss. The 2004 text covered only a digital certificate presented over the internet or another purely electronic channel, and used "bank" as a defined term that already included credit unions. The September 2026 version adds verifiable digital credentials and any digital or virtual channel.
| Question 3, then and now | January 2004 | September 2026 |
|---|---|---|
| Institutions named | Bank (defined to include credit unions) | Bank or credit union |
| Credential types named | Digital certificate | Digital certificate or verifiable digital credential |
| Channels named | Over the internet or purely electronic channel | In person, remotely, or other digital or virtual channel |
| Third-party duty | Bank ensures the third party uses the same level of authentication | Same duty, now scoped expressly to credentials issued and maintained by a non-government third party |
| Cross-reference | FFIEC "Authentication in an Electronic Banking Environment" (July 2001) | Same title, no date given |
What changes for your CIP, recordkeeping and CDD obligations?
Nothing in the rule text changed, so your obligations are identical and your evidence is not. Five duties deserve a fresh look before an institution accepts verifiable digital credentials at account opening.
Written CIP procedures
Section 1020.220(a)(2)(ii) requires the program to describe when the institution uses documents, non-documentary methods, or both. A program that lists "unexpired government-issued photo identification" without naming digital formats does not obviously authorise a mobile driver's license. The agencies made acceptance conditional on it being "allowable under the bank's or credit union's CIP", which is a drafting task, not a technology one.
Recordkeeping and data minimisation
Digital credentials collide with the recordkeeping rule here. Section 1020.220(a)(3)(i)(B) requires a description of any document relied on, noting the type, any identification number it contains, the place of issuance and, where present, the issue and expiry dates. The American Association of Motor Vehicle Administrators (AAMVA) promotes mobile driver's licenses for their "selective information release", yet the documentary path obliges an institution to capture and retain that full field set for five years after the record is made. Verifiable digital credentials can disclose less; this rule asks you to keep more.
Remote openings and the non-documentary paragraph
A bank accepting a credential remotely does not escape section 1020.220(a)(2)(ii)(B)(2), which requires non-documentary procedures to address accounts opened where the customer does not appear in person. Treating an mDL as documentary evidence does not switch that paragraph off, so programs need to say how the two paths reconcile on a remote opening rather than assume the format resolves it.
Beneficial ownership under the CDD Rule
The interpretation flows through to legal entity customers. Section 1010.230(b)(2) requires that procedures for verifying a beneficial owner contain the elements required for verifying individuals under 1020.220(a)(2), so a policy on verifiable digital credentials should extend to beneficial owners, not just to the person opening the account. There is a wrinkle the agencies did not address. For documentary verification of a beneficial owner, the CDD Rule permits "photocopies or other reproductions" of those documents. A reproduction is exactly what strips a credential of its signature and device binding, so the allowance written for paper does not carry over cleanly.
Lack of verification and SAR filing
The agencies kept the fraud caveat intact: where a credential shows indications of fraud, the institution must weigh that in deciding whether it can form a reasonable belief about the customer. With a signed credential, "indications of fraud" stops meaning a scuffed hologram and starts meaning a failed signature check, an untrusted issuer certificate, or a revoked credential. Procedures under 1020.220(a)(2)(iii) should say who decides, and when that escalates to suspicious activity reporting.
What is still uncertain about verifiable digital credentials?
Five questions remain open, and each can cost an institution money or an examination finding. None were resolved on 8 September 2026.
Issuer trust infrastructure
Accepting verifiable digital credentials means validating the issuer's certificate and checking revocation, which in practice means consuming AAMVA's Digital Trust Service or an equivalent. The presentation itself is governed by ISO/IEC 18013-5 in person and by the technical specification ISO/IEC TS 18013-7 online. The FAQs name none of this, and say nothing about what diligence on that plumbing looks like, or what an examiner expects when a state rotates a signing key.
A standard that keeps moving
The remote channel the agencies just opened rests on the least settled part of the stack. The 2024 edition of TS 18013-7 has been withdrawn and replaced by a 2025 edition, and ISO lists 18013-5 itself as due for replacement. Acceptance criteria written today are written against a moving specification, with no supervisory statement on what version drift means for an approved program.
State coverage
As of 10 September 2026, TSA's participating-states page lists 21 states plus Puerto Rico with an eligible digital ID, so a national institution cannot use verifiable digital credentials as its only documentary method. Dual-path onboarding is unavoidable for years, and the operational cost sits with the institution.
A stale cross-reference
The amended FAQ still points readers to guidance from the Federal Financial Institutions Examination Council (FFIEC) titled "Authentication in an Electronic Banking Environment". That 2001 document was replaced in 2005 by "Authentication in an Internet Banking Environment", which the FFIEC in turn replaced on 11 August 2021 with "Authentication and Access to Financial Institution Services and Systems". The benchmark an institution is told to meet is two revisions out of date on its face.
Terminology, or scope
The agencies describe the amendment as reflecting "updated terminology being used to describe VDCs". The then-and-now comparison above suggests otherwise: the revision added a credential type, opened in-person and other digital channels, and narrowed the third-party duty to non-government issuers. Presented as a vocabulary change, it reads in part as a scope change, and firms relying on the older answer should re-read it.
How does this compare with the EU approach?
The EU wrote its answer on verifiable digital credentials into binding law, and the United States has written its answer into staff guidance. Article 22(6)(b) of Regulation (EU) 2024/1624 names electronic identification means meeting eIDAS assurance level substantial or high as a way to verify identity. FinCEN, by contrast, added an interpretation to a rule that predates the technology.
The practical difference is defensibility. An EU obliged entity can point at the operative text of a regulation that applies from 10 July 2027. A US institution points at an FAQ that says it changes nothing. Recital 66 goes further, saying electronic identification should be accepted, though recitals do not bind.
| Dimension | United States | European Union |
|---|---|---|
| Instrument | Staff FAQs under 31 CFR 1020.220 | Article 22(6)(b), Regulation (EU) 2024/1624 |
| Legal status | Interpretive guidance, in effect now | Adopted and in force, applies from 10 July 2027 |
| Acceptance | Neither required nor prohibited | Named as a permitted verification method |
| Quality benchmark | Institution's own authentication standard | eIDAS assurance level substantial or high |
| Scope | Banks and credit unions | All obliged entities |
The UK sits between the two. Its Digital Verification Services trust framework version 1.0 reached its earliest possible start date on 1 September 2026, and is designed to certify providers rather than credential formats once an assessment body is accredited, which puts the assurance question on the supplier instead of on the relying firm.
How should compliance teams respond?
Start with the paperwork, not the vendor demo. Read your written CIP against the documentary and non-documentary paragraphs and decide which digital formats you accept. Then check that your account-opening record captures the type, number, place of issuance and validity dates the recordkeeping rule demands, and that you can retain them for five years.
Next, treat issuer trust as a control. Write down how you validate the signature, which trust list you consume, how you handle revocation, and what happens when validation fails. Map the failure states to your procedures for lack of verification and, where the pattern warrants it, to a Suspicious Activity Report. Where a credential comes from a private provider, document how you satisfied yourself that its authentication matches your own.
Then decide what you are willing to store. The lesson of the IDScan breach and the nine class actions that followed is that retained identity data is a liability with a long tail.
Zyphe's own position, stated as such. We read chip credentials to ICAO 9303 and eIDAS standards, which covers passports and eID cards rather than the mDL formats these FAQs address. Verification uses a two-step liveness check and no image upload. The result is sharded across a decentralised network, so no single node holds a complete record, and the key stays with the customer. That removes the vendor-side copy and the document image, not your CIP record, which still has to exist and be retained. See how it works, our KYC software and decentralised storage pages, or book a demo.
The bottom line
The agencies did the smallest useful thing: they told banks and credit unions that a digital government credential is not a lesser form of identification, and then declined to make anyone use one. That leaves the interesting work with compliance teams. Rewriting a program, proving issuer trust, and deciding how much identity data to keep are board-level choices rather than technical ones. Institutions that treat verifiable digital credentials as permission to collect the same data through a shinier channel will still be holding the honeypot when the next breach lands.
Cited sources
- FinCEN, FAQs Regarding Treatment of Verifiable Digital Credentials Under the CIP Rule, 8 September 2026
- FinCEN news release announcing the FAQs, 8 September 2026
- 31 CFR 1020.220, Customer identification program requirements for banks
- 31 CFR 1010.230, beneficial ownership requirements for legal entity customers
- FinCEN and the agencies, FAQs: Final CIP Rule (original text of question 3)
- OCC Bulletin 2021-36, FFIEC statement on authentication and access
- OCC Bulletin 2005-35, replacing the 2001 FFIEC authentication guidance
- Regulation (EU) 2024/1624, Article 22, Recital 66 and Article 90
- TSA, participating states and eligible digital IDs
- AAMVA, Mobile Driver's License program and Digital Trust Service
- ISO/IEC 18013-5:2021, mobile driving licence application
- ISO/IEC TS 18013-7:2025, mDL add-on functions including presentation over the internet
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.