SEC Commissioner Peirce urged zero-knowledge KYC and easier CIP reliance on 23 September 2026. No rule changed. What stays binding and what to prepare.
Table of contents
SEC Commissioner Hester Peirce called on 23 September 2026 for attribute-based verification, the approach known as zero-knowledge KYC, and for easier reliance on other firms' identity checks. She spoke in her penultimate week in office, in a personal capacity. No rule changed: broker-dealers must still collect, verify and keep the Customer Identification Program data.
- Peirce proposed attribute-based credentials and zero-knowledge proofs that confirm facts such as age, citizenship or absence from sanctions lists without revealing the underlying data.
- She asked for easier reliance on third-party identity verification, with reliance on a regulated firm's earlier check as the norm.
- The broker-dealer CIP rule at 31 CFR 1023.220 still requires name, date of birth, address and an identification number before an account opens.
- The statute behind the rule, 31 U.S.C. 5318(l), requires records of the information used to verify identity, "including name, address".
- The 2003 adopting release says a broker-dealer is not responsible for a relied-on institution's failure if its reliance was reasonable and documented.
What did Commissioner Peirce propose?
Peirce argued that KYC and anti-money laundering rules build ever larger stores of personal data, and that cryptography now lets firms confirm a fact without holding the data behind it. She proposed attribute-based credentials, zero-knowledge proofs and wider reliance on other institutions' checks, and said the missing piece is regulation.
The speech, "Looking for Change in Haystacks", was delivered at SIFMA's Digital Assets Conference in New York. Peirce gave her standard disclaimer that the views were her own and not necessarily those of the SEC or her fellow Commissioners, and noted it was her penultimate week as a Commissioner.
Tools already exist, she said, to limit what customers disclose and to how many firms. In her words: "What is missing is the regulatory framework that would allow and encourage their adoption." She framed this as a route to catching more criminals with less data, and not simply an excuse to deregulate.
She set out four questions for every collection rule: whether a specific data point is needed, whether only a fact it proves is needed, whether thresholds are too low, and whether more than one firm needs to collect it. She also warned against lowering thresholds simply because new technology makes collection cheap.
The most concrete proposal concerned reliance. Peirce said that "with limited exceptions" the CIP rules require each regulated entity to collect and verify customer information independently, even for a customer another registered firm has vetted. She called the area ripe for experimentation and asked why reliance on earlier work should not become the norm.
| Item | Detail |
|---|---|
| Speaker | Hester M. Peirce, SEC Commissioner |
| Date and venue | 23 September 2026, SIFMA Digital Assets Conference, New York |
| Status | Personal views, not necessarily those of the SEC or other Commissioners |
| Proposals | Attribute-based credentials, zero-knowledge proofs, wider CIP reliance, review of collection thresholds |
| Legal effect | None: no rule, proposal, exemption or guidance was issued |
| Context | Same speech discussed the Innovation Exemption for tokenized securities announced on 17 September 2026 |
What does the CIP rule require today?
The broker-dealer CIP rule requires named identifying data, verification, four kinds of record and a list check, and it allows reliance under three conditions. Zero-knowledge KYC could be logged as a verification method today, but it cannot replace the identifying data the rule names.
Under 31 CFR 1023.220(a)(2)(i)(A), a broker-dealer must obtain name, date of birth, address and an identification number before opening an account. Paragraph (a)(3)(i) then requires four records: (A) that identifying information, (B) a description of any document relied on, (C) the methods and results of verification measures, and (D) how each substantive discrepancy was resolved.
Retention splits in two. Item (A) is kept five years after the account closes; items (B) to (D) are kept five years after the record is made. That split matters here. A proof result could sit in the (C) record of methods and results, while (A) still requires the data itself.
Reliance already exists at paragraph (a)(6), and it is narrow. Reliance must be reasonable; the other institution must be subject to an anti-money laundering program rule under 31 U.S.C. 5318(h) and a federal functional regulator; and it must certify annually by contract that it runs that program and performs the specified CIP steps.
The limited exceptions Peirce mentioned are real. Since 2004, SEC staff have let broker-dealers treat a registered investment adviser as if it were subject to such a program rule, with the other reliance conditions still applying. The latest staff letter, dated 3 December 2025, extends that position to 1 January 2028 and also covers beneficial ownership reliance.
| CIP element | Current requirement | What Peirce proposed |
|---|---|---|
| Customer information | Name, date of birth, address, ID number, (a)(2)(i)(A) | Collect only the fact needed, where feasible |
| Verification | Documents, non-documentary methods or both, (a)(2)(ii) | Attribute-based credentials and zero-knowledge proofs |
| Records | Four records, (a)(3)(i)(A) to (D), two retention periods | Not addressed directly; implied reduction |
| Government lists | Check designated lists after account opening, (a)(4) | Credential attesting absence from sanctions lists |
| Reliance | Three conditions, (a)(6)(i) to (iii) | Reliance on a prior regulated check as the norm |
What does this mean for your obligations?
Nothing changes today. Every duty in the CIP rule and the customer due diligence rule remains binding, and a firm that stopped collecting CIP data because of this speech would be in breach. The speech is a planning signal, and it maps onto five specific duties.
Customer information and verification. A zero-knowledge proof that a customer is over 18 does not supply a date of birth, and (a)(2)(i)(A) names the date of birth. Zero-knowledge KYC can supplement a CIP today, for example to confirm an attribute again at a later step, but it cannot replace the four listed data points without a rule change or exemption.
Recordkeeping. This is the hardest constraint, because it sits in the statute. 31 U.S.C. 5318(l)(2)(B) requires procedures for "maintaining records of the information used to verify a person's identity, including name, address". Any zero-knowledge KYC model has to answer what record the firm keeps. The statute does let Treasury, and the SEC for broker-dealers, exempt institutions or account types under 5318(l)(5), so the route runs through regulators rather than Congress.
Government list comparison and sanctions screening. The (a)(4) check is made within a reasonable period after account opening, and the 2003 adopting release noted that no list had yet been designated for it. OFAC's prohibitions apply for the life of the account, which is why screening is ongoing. Zero-knowledge KYC for sanctions status only helps if the proof is refreshed against the current list each time it is used.
Reliance. Firms already using (a)(6) should check that each relied-on party still meets all three conditions, and that the annual certification is on file. The staff position ends on 1 January 2028, the date Treasury's August 2025 order set for the investment adviser AML Program Rule. If that rule takes effect, covered advisers meet the program rule condition directly; if it slips, watch for another staff extension.
Beneficial ownership. The customer due diligence rule carries a matching reliance clause at 31 CFR 1010.230(j). Section 6403(d)(2)(A) of the Corporate Transparency Act requires Treasury to rescind paragraphs (b) through (j) once a revised rule takes effect. That revision is overdue, so the (j) reliance clause still applies until it arrives, and any replacement depends on the new rule.
What is still uncertain?
Almost everything that would turn the speech into law is uncertain. Peirce leaves the Commission on 2 October 2026, the rule's exemption paragraph needs Treasury's agreement, and the statute requires records that attribute-only verification does not produce. Four open questions will decide whether zero-knowledge KYC moves beyond pilots.
Who can change the rule. Under 5318(l)(4), CIP rules for broker-dealers are prescribed jointly by Treasury and the relevant federal functional regulator. The statute would let the SEC grant exemptions itself, but paragraph (b) of the joint rule allows the Commission to exempt a broker-dealer only "with the concurrence of the Secretary". Any change needs FinCEN at the table.
Who takes the agenda forward. The speech was delivered in Peirce's penultimate week, and she gave the standard personal-views disclaimer. Her departure leaves a two-member Commission, Chairman Paul Atkins and Commissioner Mark Uyeda. No one yet: the speech announced no rulemaking, no request for comment on CIP and no exemptive order.
How far the reliance safe harbour stretches. The 2003 adopting release says a broker-dealer "will not be held responsible" for another institution's failure if its reliance was reasonable and the contracts and certifications are in place. That protection covers regulated institutions only. Credential issuers outside the (a)(6)(ii) definition are not reached, which is the gap a zero-knowledge KYC model would need filled.
Who trusts the issuer. Zero-knowledge KYC is only as good as the credential behind it. For banks, FinCEN's 8 September 2026 FAQs already put issuer risk on the institution: with a non-government credential, it must ensure the issuer uses "the same level of authentication" it would use itself. We found no equivalent statement for broker-dealers.
How does this fit the wider shift toward credential-based verification?
The speech is the second US signal in September 2026 that regulators will consider verification without a full document copy, and the more ambitious because it points to zero-knowledge KYC. FinCEN changed practice at the margin; Peirce proposed changing what the rules collect in the first place.
On 8 September, FinCEN and the staffs of four federal regulators said banks and credit unions may treat a state-issued mobile driver's license as documentary evidence under their CIP rule. Our analysis of those FAQs found they left the broker-dealer rule untouched and kept the full recordkeeping field set.
| Development | Date | Who it binds | What it changes |
|---|---|---|---|
| FinCEN FAQs on verifiable digital credentials | 8 September 2026 | Banks and credit unions (interpretive) | Government-issued digital credentials may count as documents |
| SEC Innovation Exemption for tokenized stock | 17 September 2026 | Qualifying venues and liquidity providers | Five-year exemptions from exchange and dealer definitions for permissioned pools |
| Peirce SIFMA speech | 23 September 2026 | Nobody | Proposes attribute-based CIP and wider reliance |
| SEC staff reliance letter | 3 December 2025 | Staff enforcement position | Reliance on investment advisers to 1 January 2028 |
The direction is consistent even though the legal weight varies. Regulators are moving from which document was shown toward whether a trustworthy source confirmed the fact. The zero-knowledge KYC model sits at the far end of that line, and the statutory record duty is its hardest constraint.
How should compliance teams respond?
Five steps pay off whether or not zero-knowledge KYC reaches the CIP rule: map each collected field to the paragraph that requires it, audit (a)(6) certifications, diarise 1 January 2028, log proof results under (a)(3)(i)(C), and keep sanctions screening separate from one-off attributes.
| Action | Rule hook | Timing |
|---|---|---|
| Map every CIP field to its legal basis; flag fields collected by habit | (a)(2)(i)(A), (a)(3)(i) | Now |
| Confirm each relied-on party meets all three conditions and has certified | (a)(6)(i) to (iii) | Annual certification cycle |
| Check whether the adviser rule or the staff position covers each adviser | SEC staff letter, 3 December 2025 | Before 1 January 2028 |
| Record how any attribute or proof result was obtained | (a)(3)(i)(C) | Whenever used |
| Keep sanctions screening ongoing, not reliant on a one-off credential | OFAC prohibitions (31 CFR chapter V) | Life of the account |
If you plan a comment on the Innovation Exemption, consider whether identity and reliance belong in it.
Zyphe addresses the reuse half of Peirce's case: a customer verified once does not hand the same documents to every firm. That customer holds a reusable KYC passport, with personal data sharded across thousands of nodes under a 29-of-100 threshold and a customer-held key. Each institution keeps an exportable audit trail of every verification. Book a demo to see how it fits your CIP.
The bottom line
Peirce has made one of the most direct cases from inside a US financial regulator for verifying facts instead of stockpiling documents. It comes as a speech from a departing Commissioner, and it meets a statute that requires records of the data used to verify identity. The useful response is preparation: know why you collect each field, keep reliance arrangements clean, and separate one-off attributes from ongoing screening. If the rules move, firms that do this will be ready to use zero-knowledge KYC; if they do not, the same work still leaves a tighter CIP.
Cited sources
- SEC, Commissioner Hester M. Peirce, "Looking for Change in Haystacks", 23 September 2026
- 31 CFR 1023.220, Customer identification programs for broker-dealers
- SEC Division of Trading and Markets, no-action letter to SIFMA on CIP and beneficial ownership reliance, 3 December 2025
- 31 U.S.C. 5318(l), identification and verification of accountholders
- Treasury and SEC, Customer Identification Programs for Broker-Dealers, final rule, 68 FR 25113, 9 May 2003
- 31 CFR 1010.230, Beneficial ownership requirements for legal entity customers
- Public Law 116-283, including Corporate Transparency Act section 6403(d)
- FinCEN, Frequently Asked Questions Regarding Treatment of Verifiable Digital Credentials Under the CIP Rule, 8 September 2026
- CoinDesk, "U.S. SEC's steadiest crypto advocate Hester Peirce to depart next week", 25 September 2026
- SEC press release 2026-90, Innovation Exemption for tokenized NMS stock, 17 September 2026
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.