On September 8, 2026, FinCEN, the Federal Deposit Insurance Corporation (FDIC), Federal Reserve, National Credit Union Administration (NCUA) and Office of the Comptroller of the Currency (OCC) jointly issued two new FAQs addressing how banks and credit unions may treat state-issued mobile driver’s licenses (mDLs) and other forms of government-issued digital credentials under the Customer Identification Program (CIP) Rule. The agencies also updated an existing FAQ to reflect current terminology. The guidance does not alter existing Bank Secrecy Act (BSA) requirements or create new supervisory expectations.
New FAQs: Defining a VDC and confirming use of an MDL under the CIP Rule
The guidance first defines a verifiable digital credential (VDC) as a data structure holding information about an individual that is digitally signed by its issuing source, cryptographically tied to a specific device, and secured by an activation factor, such as a PIN, password or biometric.
In the second FAQ, the agencies state that an mDL is one form of VDC – a state-issued digital version of a driver’s license or ID card containing the same information as its physical counterpart. It then confirms that the CIP Rule does not require or prevent institutions from relying on such government-issued VDCs to verify a customer’s identity. Notably, an unexpired, government-issued VDC (including an mDL) can satisfy the CIP Rule’s “government-issued identification” requirement, provided it also evidences the customer’s nationality or residence and carries a photograph or comparable safeguard.
The FAQ also clarifies that an institution may treat an unexpired mDL or similar government-issued VDC as one of its documentary identity verification methods, so long as doing so is permitted under its own CIP and the institution has the technology in place to extract the relevant data from the credential. As with physical government-issued IDs, institutions generally may rely on a government-issued VDC for verification, but must factor in any signs of fraud when assessing whether they can form a reasonable belief that they know the customer’s true identity.
Updated FAQ
Separately, the regulators updated an existing FAQ on nondocumentary verification methods to reflect current VDC terminology. That guidance states that a bank or credit union may use a digital certificate or VDC to verify a customer’s identity if permitted under its CIP. However, because the CIP Rule requires the bank to have a reasonable belief that it knows the true identity of the customer, when a nongovernment third party issues or maintains a VDC or electronic credential, the institution remains responsible for confirming the third party’s authentication standards match its own.
What’s next?
While the FAQs, like the explicit CIP requirements under the BSA, apply to banks and credit unions, other types of financial institutions that implement a customer identification and verification program should consider this guidance regarding the use of mDLs. Any financial institution considering mDLs or other VDCs as part of its identity verification toolkit should confirm their CIP (or equivalent policy) explicitly permits their use, validate they have the systems needed to extract and authenticate the embedded data, and build fraud-indicator checks into their onboarding workflows before rolling out acceptance of these credentials.