Free guide: How to use AI in compliance
Editorial illustration for the article "SEC's Peirce backs zero-knowledge KYC: what the CIP rule still requires".

SEC Commissioner Peirce urged zero-knowledge KYC and easier CIP reliance on 23 September 2026. No rule changed. What stays binding and what to prepare.

Table of contents

SEC Commissioner Hester Peirce called on 23 September 2026 for attribute-based verification, the approach known as zero-knowledge KYC, and for easier reliance on other firms' identity checks. She spoke in her penultimate week in office, in a personal capacity. No rule changed: broker-dealers must still collect, verify and keep the Customer Identification Program data.

  • Peirce proposed attribute-based credentials and zero-knowledge proofs that confirm facts such as age, citizenship or absence from sanctions lists without revealing the underlying data.
  • She asked for easier reliance on third-party identity verification, with reliance on a regulated firm's earlier check as the norm.
  • The broker-dealer CIP rule at 31 CFR 1023.220 still requires name, date of birth, address and an identification number before an account opens.
  • The statute behind the rule, 31 U.S.C. 5318(l), requires records of the information used to verify identity, "including name, address".
  • The 2003 adopting release says a broker-dealer is not responsible for a relied-on institution's failure if its reliance was reasonable and documented.

What did Commissioner Peirce propose?

Peirce argued that KYC and anti-money laundering rules build ever larger stores of personal data, and that cryptography now lets firms confirm a fact without holding the data behind it. She proposed attribute-based credentials, zero-knowledge proofs and wider reliance on other institutions' checks, and said the missing piece is regulation.

The speech, "Looking for Change in Haystacks", was delivered at SIFMA's Digital Assets Conference in New York. Peirce gave her standard disclaimer that the views were her own and not necessarily those of the SEC or her fellow Commissioners, and noted it was her penultimate week as a Commissioner.

Tools already exist, she said, to limit what customers disclose and to how many firms. In her words: "What is missing is the regulatory framework that would allow and encourage their adoption." She framed this as a route to catching more criminals with less data, and not simply an excuse to deregulate.

She set out four questions for every collection rule: whether a specific data point is needed, whether only a fact it proves is needed, whether thresholds are too low, and whether more than one firm needs to collect it. She also warned against lowering thresholds simply because new technology makes collection cheap.

The most concrete proposal concerned reliance. Peirce said that "with limited exceptions" the CIP rules require each regulated entity to collect and verify customer information independently, even for a customer another registered firm has vetted. She called the area ripe for experimentation and asked why reliance on earlier work should not become the norm.

ItemDetail
SpeakerHester M. Peirce, SEC Commissioner
Date and venue23 September 2026, SIFMA Digital Assets Conference, New York
StatusPersonal views, not necessarily those of the SEC or other Commissioners
ProposalsAttribute-based credentials, zero-knowledge proofs, wider CIP reliance, review of collection thresholds
Legal effectNone: no rule, proposal, exemption or guidance was issued
ContextSame speech discussed the Innovation Exemption for tokenized securities announced on 17 September 2026

What does the CIP rule require today?

The broker-dealer CIP rule requires named identifying data, verification, four kinds of record and a list check, and it allows reliance under three conditions. Zero-knowledge KYC could be logged as a verification method today, but it cannot replace the identifying data the rule names.

Under 31 CFR 1023.220(a)(2)(i)(A), a broker-dealer must obtain name, date of birth, address and an identification number before opening an account. Paragraph (a)(3)(i) then requires four records: (A) that identifying information, (B) a description of any document relied on, (C) the methods and results of verification measures, and (D) how each substantive discrepancy was resolved.

Retention splits in two. Item (A) is kept five years after the account closes; items (B) to (D) are kept five years after the record is made. That split matters here. A proof result could sit in the (C) record of methods and results, while (A) still requires the data itself.

Reliance already exists at paragraph (a)(6), and it is narrow. Reliance must be reasonable; the other institution must be subject to an anti-money laundering program rule under 31 U.S.C. 5318(h) and a federal functional regulator; and it must certify annually by contract that it runs that program and performs the specified CIP steps.

The limited exceptions Peirce mentioned are real. Since 2004, SEC staff have let broker-dealers treat a registered investment adviser as if it were subject to such a program rule, with the other reliance conditions still applying. The latest staff letter, dated 3 December 2025, extends that position to 1 January 2028 and also covers beneficial ownership reliance.

CIP elementCurrent requirementWhat Peirce proposed
Customer informationName, date of birth, address, ID number, (a)(2)(i)(A)Collect only the fact needed, where feasible
VerificationDocuments, non-documentary methods or both, (a)(2)(ii)Attribute-based credentials and zero-knowledge proofs
RecordsFour records, (a)(3)(i)(A) to (D), two retention periodsNot addressed directly; implied reduction
Government listsCheck designated lists after account opening, (a)(4)Credential attesting absence from sanctions lists
RelianceThree conditions, (a)(6)(i) to (iii)Reliance on a prior regulated check as the norm

What does this mean for your obligations?

Nothing changes today. Every duty in the CIP rule and the customer due diligence rule remains binding, and a firm that stopped collecting CIP data because of this speech would be in breach. The speech is a planning signal, and it maps onto five specific duties.

Customer information and verification. A zero-knowledge proof that a customer is over 18 does not supply a date of birth, and (a)(2)(i)(A) names the date of birth. Zero-knowledge KYC can supplement a CIP today, for example to confirm an attribute again at a later step, but it cannot replace the four listed data points without a rule change or exemption.

Recordkeeping. This is the hardest constraint, because it sits in the statute. 31 U.S.C. 5318(l)(2)(B) requires procedures for "maintaining records of the information used to verify a person's identity, including name, address". Any zero-knowledge KYC model has to answer what record the firm keeps. The statute does let Treasury, and the SEC for broker-dealers, exempt institutions or account types under 5318(l)(5), so the route runs through regulators rather than Congress.

Government list comparison and sanctions screening. The (a)(4) check is made within a reasonable period after account opening, and the 2003 adopting release noted that no list had yet been designated for it. OFAC's prohibitions apply for the life of the account, which is why screening is ongoing. Zero-knowledge KYC for sanctions status only helps if the proof is refreshed against the current list each time it is used.

Reliance. Firms already using (a)(6) should check that each relied-on party still meets all three conditions, and that the annual certification is on file. The staff position ends on 1 January 2028, the date Treasury's August 2025 order set for the investment adviser AML Program Rule. If that rule takes effect, covered advisers meet the program rule condition directly; if it slips, watch for another staff extension.

Beneficial ownership. The customer due diligence rule carries a matching reliance clause at 31 CFR 1010.230(j). Section 6403(d)(2)(A) of the Corporate Transparency Act requires Treasury to rescind paragraphs (b) through (j) once a revised rule takes effect. That revision is overdue, so the (j) reliance clause still applies until it arrives, and any replacement depends on the new rule.

What is still uncertain?

Almost everything that would turn the speech into law is uncertain. Peirce leaves the Commission on 2 October 2026, the rule's exemption paragraph needs Treasury's agreement, and the statute requires records that attribute-only verification does not produce. Four open questions will decide whether zero-knowledge KYC moves beyond pilots.

Who can change the rule. Under 5318(l)(4), CIP rules for broker-dealers are prescribed jointly by Treasury and the relevant federal functional regulator. The statute would let the SEC grant exemptions itself, but paragraph (b) of the joint rule allows the Commission to exempt a broker-dealer only "with the concurrence of the Secretary". Any change needs FinCEN at the table.

Who takes the agenda forward. The speech was delivered in Peirce's penultimate week, and she gave the standard personal-views disclaimer. Her departure leaves a two-member Commission, Chairman Paul Atkins and Commissioner Mark Uyeda. No one yet: the speech announced no rulemaking, no request for comment on CIP and no exemptive order.

How far the reliance safe harbour stretches. The 2003 adopting release says a broker-dealer "will not be held responsible" for another institution's failure if its reliance was reasonable and the contracts and certifications are in place. That protection covers regulated institutions only. Credential issuers outside the (a)(6)(ii) definition are not reached, which is the gap a zero-knowledge KYC model would need filled.

Who trusts the issuer. Zero-knowledge KYC is only as good as the credential behind it. For banks, FinCEN's 8 September 2026 FAQs already put issuer risk on the institution: with a non-government credential, it must ensure the issuer uses "the same level of authentication" it would use itself. We found no equivalent statement for broker-dealers.

How does this fit the wider shift toward credential-based verification?

The speech is the second US signal in September 2026 that regulators will consider verification without a full document copy, and the more ambitious because it points to zero-knowledge KYC. FinCEN changed practice at the margin; Peirce proposed changing what the rules collect in the first place.

On 8 September, FinCEN and the staffs of four federal regulators said banks and credit unions may treat a state-issued mobile driver's license as documentary evidence under their CIP rule. Our analysis of those FAQs found they left the broker-dealer rule untouched and kept the full recordkeeping field set.

DevelopmentDateWho it bindsWhat it changes
FinCEN FAQs on verifiable digital credentials8 September 2026Banks and credit unions (interpretive)Government-issued digital credentials may count as documents
SEC Innovation Exemption for tokenized stock17 September 2026Qualifying venues and liquidity providersFive-year exemptions from exchange and dealer definitions for permissioned pools
Peirce SIFMA speech23 September 2026NobodyProposes attribute-based CIP and wider reliance
SEC staff reliance letter3 December 2025Staff enforcement positionReliance on investment advisers to 1 January 2028

The direction is consistent even though the legal weight varies. Regulators are moving from which document was shown toward whether a trustworthy source confirmed the fact. The zero-knowledge KYC model sits at the far end of that line, and the statutory record duty is its hardest constraint.

How should compliance teams respond?

Five steps pay off whether or not zero-knowledge KYC reaches the CIP rule: map each collected field to the paragraph that requires it, audit (a)(6) certifications, diarise 1 January 2028, log proof results under (a)(3)(i)(C), and keep sanctions screening separate from one-off attributes.

ActionRule hookTiming
Map every CIP field to its legal basis; flag fields collected by habit(a)(2)(i)(A), (a)(3)(i)Now
Confirm each relied-on party meets all three conditions and has certified(a)(6)(i) to (iii)Annual certification cycle
Check whether the adviser rule or the staff position covers each adviserSEC staff letter, 3 December 2025Before 1 January 2028
Record how any attribute or proof result was obtained(a)(3)(i)(C)Whenever used
Keep sanctions screening ongoing, not reliant on a one-off credentialOFAC prohibitions (31 CFR chapter V)Life of the account

If you plan a comment on the Innovation Exemption, consider whether identity and reliance belong in it.

Zyphe addresses the reuse half of Peirce's case: a customer verified once does not hand the same documents to every firm. That customer holds a reusable KYC passport, with personal data sharded across thousands of nodes under a 29-of-100 threshold and a customer-held key. Each institution keeps an exportable audit trail of every verification. Book a demo to see how it fits your CIP.

The bottom line

Peirce has made one of the most direct cases from inside a US financial regulator for verifying facts instead of stockpiling documents. It comes as a speech from a departing Commissioner, and it meets a statute that requires records of the data used to verify identity. The useful response is preparation: know why you collect each field, keep reliance arrangements clean, and separate one-off attributes from ongoing screening. If the rules move, firms that do this will be ready to use zero-knowledge KYC; if they do not, the same work still leaves a tighter CIP.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

No. Commissioner Peirce gave a speech expressing her own views, not necessarily those of the Commission or other Commissioners. No rule, proposal, exemption or guidance was issued. The broker-dealer Customer Identification Program rule at 31 CFR 1023.220 applies exactly as before, including the collection of name, date of birth, address and identification number.

Zero-knowledge KYC uses cryptographic proofs to confirm a fact about a customer, such as being over 18 or not appearing on a sanctions list, without revealing the underlying data. Peirce described attribute-based credentials that answer yes or no to a requirement while the counterparty never sees the customer's name, income or address.

Yes, under paragraph (a)(6) of the rule, if reliance is reasonable, the other institution is subject to an anti-money laundering program rule and a federal functional regulator, and it certifies annually by contract. SEC staff also let broker-dealers treat registered investment advisers as meeting the program rule condition until 1 January 2028.

The statute, 31 U.S.C. 5318(l), requires CIP rules for broker-dealers to be prescribed jointly by Treasury and the relevant federal functional regulator. The statute would allow the SEC to grant exemptions, but the joint rule's exemption paragraph requires the Secretary's concurrence. The statute also requires records of the information used to verify identity.

See privacy-first KYC in action

Verify identity without a central store of documents. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo