Federal Agencies Authorize Banks to Accept Mobile Driver's Licenses for Identity Verification
The FDIC, OCC, and FinCEN have issued joint guidance clarifying that financial institutions can use state-issued digital credentials to satisfy Customer Identification Program requirements.
- Federal Regulators
- Maintain that cryptographic verification of digital IDs aligns with existing Bank Secrecy Act requirements while offering higher security than physical documents.
- Identity Infrastructure Providers
- Argue that the regulatory clarity removes the primary bottleneck for private-sector adoption, shifting the challenge to technical integration.
- Legal and Compliance Analysts
- Caution that while digital IDs are now permitted, banks must still rigorously update their risk models to detect intercepted or spoofed transmissions.
Perspectives this story doesn't cover
- Consumer privacy advocates concerned about the data trails generated by digital identity verification.
- State motor vehicle departments managing the infrastructure load of real-time cryptographic authentication requests.
Why this matters
For consumers, this eliminates the need to scan physical IDs or visit branches to open accounts, while giving financial institutions a cryptographically secure method to combat AI-driven identity fraud.
Key points
- The FDIC, OCC, and FinCEN clarified that banks can use mobile driver's licenses for Customer Identification Programs.
- Institutions must cryptographically verify the digital credential directly with the issuing state authority.
- The guidance resolves regulatory ambiguity that had stalled private-sector adoption of state-issued digital IDs.
- Banks are required to update their Anti-Money Laundering risk assessments to address digital transmission vulnerabilities.
When the Transportation Security Administration began accepting mobile driver's licenses at airport checkpoints in 2022, the verification relied entirely on physical proximity and in-person hardware. The joint regulatory guidance issued this week by 3 federal banking agencies differs in one critical respect: it explicitly authorizes these cryptographic digital credentials for remote, unmediated transactions. The Financial Crimes Enforcement Network (FinCEN), alongside the Federal Deposit Insurance Corporation (FDIC) and the Office of the Comptroller of the Currency (OCC), confirmed that banks can use state-issued digital IDs to satisfy Customer Identification Program (CIP) requirements.[1][2][5]
The clarification arrives as the financial sector grapples with surging synthetic identity fraud. According to the FBI's 2025 annual report, Americans filed more than 22,000 cases with an AI connection, reporting roughly $893 million in losses. Until now, banks operating under the Bank Secrecy Act faced regulatory ambiguity regarding whether a digital credential—transmitted over a network rather than inspected in person—met the legal threshold for a "documentary" verification method.[7]
Under the new framework, a mobile driver's license (mDL) is legally classified as a reliable documentary method, provided it is issued by a recognized state authority. The guidance specifies that banks must not merely look at a screen rendering of the ID, but must cryptographically authenticate the data payload directly against the issuing state's public key infrastructure.[3][6]
The shift places the burden of verification on the cryptographic signature rather than the visual inspection of a plastic card. "The agencies emphasize that the bank must verify the digital credential directly with the issuing authority or its authorized representative," the OCC stated in Bulletin 2026-44. This ensures that the credential has not been altered or revoked since its issuance.[1]
The shift places the burden of verification on the cryptographic signature rather than the visual inspection of a plastic card.
Identity verification providers have anticipated this regulatory green light. SpruceID, a digital credential infrastructure firm, noted that the ruling shifts the industry's focus from acceptance to implementation. Banks now need to integrate the ISO 18013-5 standard, the technical protocol that governs how mDLs transmit data securely between a user's mobile device and a relying party's reader.[6]
The federal endorsement is expected to accelerate state-level rollouts of digital IDs. As of September 2026, more than 15 states offer some form of mobile driver's license, typically housed in Apple Wallet, Google Wallet, or dedicated state applications. However, adoption by private-sector relying parties had stalled due to compliance uncertainties at the federal level.[3]
Legal analysts view the joint statement as a necessary modernization of the 2001 USA PATRIOT Act provisions that originally mandated the CIP rules. InfoBytes, a legal publication by Orrick, highlighted that banks must still incorporate these digital methods into their broader Anti-Money Laundering (AML) compliance programs. Institutions are required to update their risk assessments to account for the specific vulnerabilities of digital transmission, such as man-in-the-middle attacks.[4]
For retail banking, the immediate consequence is a streamlined onboarding funnel. Customers will increasingly be able to open accounts by tapping their smartphone to transmit an encrypted identity payload, bypassing the friction of photographing physical cards and waiting for optical character recognition to parse the text. The timeline for widespread consumer availability now depends on how quickly core banking software providers can deploy the necessary cryptographic verification modules to their institutional clients.[5][6]
Viewpoints in depth
Federal Regulators
The FDIC, OCC, and FinCEN emphasize that digital credentials offer a higher degree of security than physical cards.
Regulators maintain that this modernization aligns with existing Bank Secrecy Act requirements while addressing the vulnerabilities of optical document scanning. By requiring banks to cryptographically verify the data directly with the issuing state, the agencies aim to establish a verification standard that cannot be easily spoofed by generative AI or sophisticated physical forgeries.
Identity Infrastructure Providers
Firms building the technical plumbing for digital IDs argue that this guidance removes the primary bottleneck for private-sector adoption.
Infrastructure developers stress that the challenge now shifts from regulatory compliance to technical integration. Banks are being urged to adopt the ISO 18013-5 standard to securely request and parse encrypted identity payloads. Providers view the federal clarification as the catalyst needed to move mobile driver's licenses out of limited pilot programs and into mainstream financial services.
Legal and Compliance Analysts
Banking attorneys caution that the guidance does not absolve institutions of their broader Anti-Money Laundering responsibilities.
While the guidance clarifies the "documentary" status of mDLs, legal experts highlight that banks must update their risk models to account for new digital attack vectors. Compliance teams are being advised to ensure their systems can detect intercepted cryptographic transmissions and to maintain robust secondary verification protocols for high-risk transactions.
Sources
[1]OCCFederal RegulatorsBank Secrecy Act/Anti-Money Laundering: Frequently Asked Questions Regarding Treatment of Verifiable Digital Credentials Under the Customer Identification Program Rule
Read on OCC →
[2]FDICFederal RegulatorsFrequently Asked Questions Regarding Treatment of Verifiable Digital Credentials Under the Customer Identification Program Rule
Read on FDIC →
[3]Biometric UpdateIdentity Infrastructure ProvidersFederal regulators say mDLs can be used for bank identity checks
Read on Biometric Update →
[4]InfoBytesLegal and Compliance AnalystsAgencies clarify banks may accept mobile driver's licenses and digital credentials for CIP identity verification
Read on InfoBytes →
[5]ZypheFederal RegulatorsFinCEN opens the CIP rule to verifiable digital credentials
Read on Zyphe →
[6]SpruceIDIdentity Infrastructure ProvidersFinCEN Confirms Banks Can Accept Digital Credentials. Now They Need to Verify Them.
Read on SpruceID →
[7]The Hindu BusinessLineAI is supercharging money scams – here’s what you can do to protect yourself
Read on The Hindu BusinessLine →
Comments
More in Finance
See all →Mortgage Underwriting
The 28/36 Rule: How the Debt-to-Income Ratio Sets the Maximum Monthly Mortgage Payment
7 sources
Inflation Metrics
The Weighting and Substitution Differences That Make the PCE the Federal Reserve's Preferred Inflation Gauge
7 sources
Retirement Planning
The Hidden Medicare Surcharge: How a Single 401(k) Withdrawal Can Spike Your Premiums
3 sources
Asset Tokenization
Tokenized Treasury Market Surpasses $10 Billion as Blockchain Offers Global Inflation Shield
6 sources
Every angle. Every day.
Get Finance stories with full source coverage and perspective breakdowns delivered to your inbox.




