ARTICLE
15 September 2026

FinCEN Clarifies Use Of Digital Credentials Under CIP

BS
Ballard Spahr LLP

Contributor

Ballard Spahr LLP—an Am Law 100 law firm with more than 750 lawyers in 18 U.S. offices—serves clients across industries in litigation, transactions, and regulatory compliance. A strategic legal partner to clients, Ballard goes beyond to deliver actionable, forward-thinking counsel and advocacy powered by deep industry experience and an understanding of each client’s specific business goals. Our culture is defined by an entrepreneurial spirit, collaborative environment, and top-down focus on service, efficiency, and results.
FinCEN and federal banking regulators have issued new guidance clarifying that financial institutions may use verifiable digital credentials, including state-issued mobile driver's licenses, to verify customer identities under the Customer Identification Program Rule. The guidance confirms that existing CIP frameworks are technologically neutral and can accommodate digital forms of identification while maintaining the same authentication standards.
United States Finance and Banking
Ballard Spahr LLP are most popular:
  • within Insolvency/Bankruptcy/Re-Structuring, Strategy and Environment topic(s)

FinCEN and the staffs of the Fed, FDIC, OCC, and NCUA, have jointly issued two FAQs addressing the use of verifiable digital credentials (VDCs), including state-issued mobile driver’s licenses (mDLs), to verify customer identities under the Customer Identification Program (CIP) Rule.

The principal clarification is that an unexpired, government-issued VDC, such as an mDL, may qualify as “government-issued identification” for purposes of the CIP Rule, provided that the VDC evidences nationality or residence and bears a photograph, the institution has the technology or systems necessary to extract the appropriate information, and the institution’s CIP permits its use. As with physical identification cards, however, a VDC is not automatically sufficient if there are indications of fraud. The institution must still be able to form a reasonable belief that it knows the customer’s true identity.

The agencies also updated an existing FAQ to clarify that VDCs issued or maintained by private third parties may be used as a non-documentary means of verification, but the financial institution remains responsible for ensuring that the third party uses the same level of authentication that the institution itself would use. Before relying on a third-party credential, the institution should therefore understand how the provider authenticates an individual and satisfy itself that the process is consistent with the institution’s CIP requirements.

The agencies emphasize that the FAQs “neither alter existing BSA [Bank Secrecy Act] legal or regulatory requirements nor establish new supervisory expectations” and that institutions are not required to accept digital credentials. The FAQs merely confirm that the existing CIP framework is technologically neutral and can accommodate digital forms of identification.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More