FinCEN verifiable digital credentials: mDLs under the CIP Rule
FinCEN and staff of four banking agencies said on 8 September 2026 that a state mobile driver's license can be a document under the CIP Rule. What the FAQs say, who is covered and what to change in your program.

In short
On 8 September 2026 the Financial Crimes Enforcement Network (FinCEN) and staff of four federal banking agencies said a US bank or credit union may treat an unexpired, government-issued verifiable digital credential, such as a state mobile driver's license (mDL), as a document for identity verification under the Customer Identification Program (CIP) Rule.[1][2]
- It is optional, and the bank's own written program must allow it.[2]
- A credential from a non-government issuer stays a non-documentary method.[2]
- No requirement changed, and the rule text is the same as before.[2][3]
The FinCEN verifiable digital credentials answers of September 2026 settle whether a driver's license held on a phone can be the identity document a bank's onboarding rule asks for. They say yes, on conditions, and place the credential in the same paragraph of the rule as the plastic card.[2]
This analysis covers what the three answers say, the rule behind them, who is covered, what to change in a written program, and one gap most summaries skip: a mobile driver's license carries no taxpayer identification number.[9]
What happened on 8 September 2026
FinCEN, part of the US Department of the Treasury, issued answers to two new frequently asked questions (FAQs) and updated one existing answer. It did so jointly with staff of the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA) and the Office of the Comptroller of the Currency (OCC).[1]
The FDIC sent it out as Financial Institution Letter FIL-56-2026, the OCC as Bulletin 2026-44 and the Federal Reserve as supervisory letter SR 26-6.[6][7][8]
| Answer | What it says | Status |
|---|---|---|
| What a verifiable digital credential is | "a data structure that contains information about an individual, is digitally signed by the issuing source of the information, is cryptographically bound to a device, and is protected by an activation factor" | New |
| Government-issued credential | An unexpired one, such as a state mDL, would qualify as "government-issued identification", though it must also "evidence nationality or residence and bear a photograph or similar safeguard". The bank may use it as a documentary method if it can extract the data and its program allows it | New |
| Electronic credential as a non-documentary method | Allowed to the extent the program permits. For a non-government issuer, the bank must ensure the issuer uses the same level of authentication the bank would use | Updated September 2026 |
The three answers of 8 September 2026.[2]
A photograph of a license alone does not establish that those properties are met. An mDL, in the agencies' words, is "issued by a state government" and "contains all of the same information as a physical driver's license".[2]
The document states its own limit under the Bank Secrecy Act (BSA): the answers "neither alter existing BSA legal or regulatory requirements nor establish new supervisory expectations".[2] The rule itself was last amended in September 2020.[3]
The rule behind it: 31 CFR 1020.220
The CIP Rule sits in title 31 of the Code of Federal Regulations (CFR). It requires every bank to run a written program with risk-based procedures that let it "form a reasonable belief that it knows the true identity of each customer".[3] The procedures must say when the bank uses documents, non-documentary methods, or both.[3] The second new answer reads the mDL into the documents paragraph.
31 CFR 1020.220(a)(2)(ii)(A)(1)Verification through documents
"For an individual, unexpired government-issued identification evidencing nationality or residence and bearing a photograph or similar safeguard, such as a driver's license or passport"
Source: eCFR, 31 CFR 1020.220[3]
FAQ 2, answerFinCEN and the Agencies, 8 September 2026, on government-issued credentials
"The CIP Rule neither requires nor prohibits reliance on such government-issued VDCs as a means of verifying a customer's identity."
The credential itself must be unexpired and must "evidence nationality or residence and bear a photograph or similar safeguard".[2] Two conditions on the institution follow. The bank or credit union "maintains the appropriate technology or systems to extract the relevant information" from the credential, and acceptance "is allowable under the bank's or credit union's CIP".[2] The rule already says that, for a bank relying on documents, "the CIP must contain procedures that set forth the documents that the bank will use", so a credential that is not written into the program is not available to the onboarding team.[3]
Documentary
Physical ID
- Driver's license or passport named in the rule
- Bank generally may rely on it
- Record: type, number, place and dates of issue and expiry
1020.220(a)(2)(ii)(A)
Documentary, new answer
Government credential
- Unexpired state mDL or other government credential showing nationality or residence, with a photograph or similar safeguard
- Bank generally may rely on it, and must weigh indications of fraud
- Needs systems to extract the data and a program that allows it
1020.220(a)(2)(ii)(A)(1)
Non-documentary
Private credential
- Digital certificate or credential from a non-government issuer
- Bank must ensure the issuer's authentication matches its own
- Record: the methods used and their results
1020.220(a)(2)(ii)(B)
Government issuance makes a qualifying credential eligible for the documentary route. The bank's written CIP decides which methods it uses.[2][3]
The record follows the route. For a document, the bank keeps a description of "any document that was relied on", noting "the type of document, any identification number contained in the document, the place of issuance and, if any, the date of issuance and expiration date". For a non-documentary method it keeps a description of the methods and the results. Both records are kept for five years after they are made.[3] The FAQs do not say how a signed credential maps to those fields.[2] The updated answer sits in the interagency document "FAQs: Final CIP Rule", which records the September 2026 revision on its cover and still cites the rule under its old number, 31 C.F.R. § 103.121.[4]
Who it affects
The answers speak to banks and credit unions.[2] Other sectors have their own identification rules, which these FAQs do not mention.[2][14]
| Who | Position after 8 September 2026 | Source |
|---|---|---|
| Banks supervised by the OCC, the Federal Reserve or the FDIC | Covered. The OCC bulletin applies to all community banks too | Bulletin 2026-44, SR 26-6, FIL-56-2026[7][8][6] |
| Credit unions | Covered. NCUA staff co-issued the FAQs, and FAQs 2 and 3 expressly address credit unions | FAQs[2] |
| Broker-dealers, mutual funds, futures commission merchants | Not addressed. They follow 31 CFR 1023.220, 1024.220 and 1026.220 | eCFR[14][17][18] |
| Payment stablecoin issuers | Not addressed. A separate CIP rule was proposed on 22 June 2026; the comment deadline was 21 August 2026 | Federal Register[13] |
According to a note by the law firm Cooley dated 14 September 2026, "other types of financial institutions that implement a customer identification and verification program should consider this guidance regarding the use of mDLs".[16] That is a law firm's view, not an agency statement.
The Transportation Security Administration (TSA) lists mobile licenses or digital IDs from 21 states and Puerto Rico as eligible at more than 250 TSA checkpoints.[12]
Timeline: from the 2003 rule to the 2026 answers
- 9 May 2003Final ruleCIP Rule published; banks had to comply by 1 October 2003.[5]
- 27 June 2025TIN orderOptional: banks may collect the taxpayer identification number (TIN) from a third party.[11]
- 18 March 2026NIST draftNational Institute of Standards and Technology (NIST) draft guide on mDLs for financial institutions.[10]
- 8 September 2026FAQs issuedTwo new answers and one update on digital credentials.[1]
The 2003 preamble explains why the new answers matter. Commenters told the agencies that banks "do not have the means to authenticate or validate documents provided by their customers". The agencies confirmed that "once a bank has obtained and verified the identity of the customer through a document such as a driver's license or passport, the bank will not be required to take steps to determine whether the document has been validly issued".[5] The 2026 answers apply that same posture to a credential that carries its issuer's signature.[2]
What compliance teams should do now
Accepting digital credentials is optional; existing CIP obligations still apply.
- Decide whether to accept government-issued digital credentials, and record why in the risk assessment.[2]
- Add the credential to the list of documents in the written CIP, with the issuers accepted.[3]
- Test that your systems can extract the relevant information from the credential.[2]
- Check each credential is unexpired, shows residence or nationality and bears a photograph or similar safeguard.[2]
- Define what counts as an indication of fraud for a digital credential and who reviews it.[2]
- Map the credential's fields to the document record: type, number, place of issuance, issue and expiry dates.[3]
- Keep collecting the taxpayer identification number by another path.[3][9]
- Treat credentials from private issuers as non-documentary and assess the issuer's authentication.[2]
- Keep a fallback route for customers without a digital credential.[3]
1Customer presents a digital credential
In person or online, both are covered by the answer.
The issuer is a government and the program lists the credential
Documentary route
Extract the data, weigh fraud indications, keep the document record.
Non-documentary route or another document
Assess the private issuer's authentication, or ask for a card or passport.
2Collect the taxpayer identification number
From the customer or, where the bank uses the 2025 order, from a third party.
3Form the reasonable belief and keep the record
The decision stays with the bank.
A digital credential in a CIP flow.[2][3][11]
Watch out
An mDL does not finish the CIP on its own. The rule requires an identification number, which for a US person is a taxpayer identification number, and NIST notes: "A TIN attribute is not included in US State issued mDLs."[3][9]
The NIST mapping lines up each paragraph of 31 CFR 1020.220 with a test build that stored the license number, expiry date, issuing state and issue date. NIST's demonstration "uses both documentary and non-documentary processes", the second to validate the taxpayer number, and NIST adds that the mapping "does not guarantee regulatory acceptance or compliance".[9]
What is still open, and the latest developments
As of 6 October 2026 there is no follow-up from FinCEN on the topic, and the rule text is unchanged in the eCFR edition dated 2 October 2026.[1][3] The NIST practice guide is still a draft whose comment period has closed.[10] America's Credit Unions wrote in its compliance blog on 22 September 2026 that the FAQs do not "prescribe a specific implementation approach".[15]
| Open point | What the texts say |
|---|---|
| Checking the issuer's signature | The stated condition is extracting the information. The FAQs do not say the bank must validate the signature[2] |
| Fraud standard | The 2003 preamble says "obvious indications of fraud". The 2026 answer says "indications of fraud", and also says it sets no new supervisory expectations[5][2] |
| Record fields | The rule lists them for documents. The FAQs do not address recordkeeping[3][2] |
| Nationality | NIST observes that a driver's license, mobile or not, shows residence, not nationality[9] |
My reading: the agencies put a new kind of evidence in an old category and left the judgement with the institution that opens the account.
How Didit helps with identity verification next to the CIP Rule
Reading a US mobile driver's license is not a Didit product today. What works today is the document route in Didit's ID verification, which is also the fallback a bank needs for people without a digital credential.
It captures the identity document, reads the near-field communication (NFC) chip of e-passports and electronic ID cards, runs passive or active liveness, matches the face to the document photo and analyses the device and internet protocol (IP) address. It covers 14,000+ document types in 220+ countries and territories. A full know your customer (KYC) check costs $0.33, as listed on the pricing page. If your program also screens customers, anti-money laundering (AML) screening checks 1,300+ sanctions, politically exposed person and watchlists for $0.20 per check.
Didit provides
- Document capture, chip reading, liveness and face match in a hosted flow or by application programming interface (API)
- Device and IP address analysis in the same check
- Data retention you set from 1 month to 10 years, with delete on demand
- A no-code workflow builder with manual review
Stays with you
- The written CIP and the list of documents and credentials in it
- The decision to accept a government-issued digital credential
- Collecting the taxpayer identification number
- The reasonable-belief decision, the five-year record and any report
Run the document route while credentials mature
Set up document, liveness and face match checks in one workflow.
Key takeaways
- On 8 September 2026 FinCEN and staff of four banking agencies issued two new CIP answers and updated one.[1]
- An unexpired government-issued digital credential, such as a state mDL, can be a document under 31 CFR 1020.220(a)(2)(ii)(A)(1).[2]
- Acceptance is optional and needs two things: systems that extract the data, and a written program that allows it.[2]
- A credential from a private issuer is a non-documentary method, and the bank answers for the issuer's authentication.[2]
- The mDL carries no taxpayer identification number, and the reasonable-belief decision stays with the bank.[9][3]
Frequently asked questions
Can a US bank accept a mobile driver's license to open an account?
Yes, if its written Customer Identification Program allows it and it has the systems to extract the information. The FAQs of 8 September 2026 say an unexpired, government-issued credential such as an mDL would qualify as government-issued identification under 31 CFR 1020.220(a)(2)(ii)(A)(1), though it must also evidence nationality or residence and bear a photograph or similar safeguard.[2]
Do the FinCEN FAQs require banks to accept mobile driver's licenses?
No. The answer says the CIP Rule "neither requires nor prohibits" reliance on government-issued verifiable digital credentials. A bank or credit union "may consider accepting" one.[2]
What is a verifiable digital credential according to FinCEN?
It is a data structure that contains information about an individual, is digitally signed by the issuing source, is cryptographically bound to a device and is protected by an activation factor. An activation factor is something the user knows, such as a PIN or password, or a physical biometric such as a face or fingerprint.[2]
Did the CIP Rule change in September 2026?
No. The FAQs say they neither alter existing BSA legal or regulatory requirements nor establish new supervisory expectations. The text of 31 CFR 1020.220 was last amended in September 2020.[2][3]
How is a credential from a private company treated?
As a non-documentary method. For a credential issued and maintained by a non-government third party, the bank or credit union is responsible for ensuring that the third party uses the same level of authentication it would use itself.[2]
Does a mobile driver's license cover every CIP data element?
No. The rule also requires an identification number, which for a US person is a taxpayer identification number, and NIST notes that state mDLs do not include one. The bank still collects it from the customer or, under FinCEN's June 2025 order, from a third party.[3][9][11]
Do the FAQs apply to broker-dealers, fintechs or crypto firms?
They address banks and credit unions only. Broker-dealers, mutual funds and futures commission merchants have their own CIP sections, and a CIP rule for payment stablecoin issuers was proposed on 22 June 2026.[2][14][17][18][13]
Must a bank check the digital signature on the credential?
The FAQs do not say so. The stated condition is that the bank maintains the technology or systems to extract the relevant information.[2]
Does Didit verify mobile driver's licenses?
No, that is not a Didit product today. Didit verifies physical identity documents with document capture, NFC chip reading for e-passports and electronic IDs, liveness and face match. The bank keeps the decision.
Sources
- FinCEN Issues Frequently Asked Questions Regarding Treatment of Verifiable Digital Credentials Under the Customer Identification Program Rule, FinCEN news release, 8 September 2026.
- Frequently Asked Questions Regarding Treatment of Verifiable Digital Credentials Under the Customer Identification Program Rule, FinCEN and the Agencies, September 2026.
- 31 CFR 1020.220, Customer identification program requirements for banks, eCFR, up to date as of 2 October 2026.
- FAQs: Final CIP Rule, interagency document, revised September 2026.
- Customer Identification Programs for Banks, Savings Associations, Credit Unions and Certain Non-Federally Regulated Banks, 68 FR 25090, Federal Register, 9 May 2003.
- Financial Institution Letter FIL-56-2026, FDIC, 8 September 2026.
- OCC Bulletin 2026-44, Bank Secrecy Act/Anti-Money Laundering: FAQs on verifiable digital credentials, OCC, 8 September 2026.
- SR 26-6: Frequently Asked Questions Regarding Treatment of Verifiable Digital Credentials Under the Customer Identification Program Rule, Federal Reserve Board, 8 September 2026.
- mDL to CIP Regulatory Mapping, NIST National Cybersecurity Center of Excellence, from the draft SP 1800-42A.
- Draft NIST Guidelines on Implementing Mobile Driver's Licenses for Financial Institutions, NIST, 18 March 2026.
- FinCEN Permits Banks to Use Alternative Collection Method for Obtaining TIN Information, FinCEN news release, 27 June 2025.
- Participating States and Eligible Digital IDs, Transportation Security Administration, read on 6 October 2026.
- Permitted Payment Stablecoin Issuer Customer Identification Program, proposed rule, Federal Register, 22 June 2026.
- 31 CFR 1023.220, Customer identification programs for broker-dealers, eCFR.
- CIP and Digital Credentials, America's Credit Unions compliance blog, 22 September 2026.
- FinCEN, Other Regulators Clarify Use of Mobile Driver's Licenses Under CIP Rule, Cooley Finsights, 14 September 2026 (the page also shows 15 September 2026).
- 31 CFR 1024.220, Customer identification programs for mutual funds, eCFR.
- 31 CFR 1026.220, Customer identification programs for futures commission merchants and introducing brokers, eCFR.
The September 2026 answers clarify how digital credentials fit the evidence a bank may accept, and leave its existing duties unchanged. The document route still has to be right first: see how Didit's ID verification handles it.
Verify identity documents today
Add new credential types to your program when you are ready.
Related articles
- Revolut data breach: the reported fake government request
- CIMA AML Rule: Cayman's audit filing duty explained
- e-Devlet for businesses: identity verification in Turkey
- Singpass Myinfo integration: a guide for businesses in Singapore
- Cl@ve integration in Spain: who can connect and what to use instead
- PhilSys verification: how businesses check the National ID