signzy

API Marketplace

downArrow
Logo
Responsive

Can Banks Accept Mobile Driver's Licenses for CIP? What the 2026 FinCEN FAQ Means

By Saurin Parikh
By Saurin Parikh
October 1, 2026
8 Minutes
Open in ChatGPTOpen in ChatGPT

Key Highlights

  • On September 8, 2026, FinCEN and the staffs of the Federal Reserve, FDIC, NCUA, and OCC issued FAQs on state-issued mobile driver's licenses (mDLs). The FAQs confirm that banks and credit unions may use mDLs to verify customer identity under the Customer Identification Program (CIP) Rule.
  • This covers accounts opened in person, remotely, and through other digital channels.
  • An unexpired, government-issued verifiable digital credential (VDC) counts as "government-issued identification" for documentary verification. It must also show nationality or residence and carry a photograph or similar safeguard.
  • Two conditions apply. The institution needs technology that can pull the relevant information from the credential, and its CIP must allow the credential.
  • The FAQ creates no new requirement. Banks do not have to accept mDLs, and the fraud and "reasonable belief" standards are unchanged.
  • Login.gov's live rollout of mDL verification shows remote acceptance works today, though coverage is still limited by state, wallet, and device.

What did FinCEN and the banking agencies say?

The September 8 release adds two new FAQs and updates one earlier FAQ under the CIP Rule (31 C.F.R. § 1020.220).

The central question is whether a bank or credit union can use a government-issued VDC, such as a state mDL, to verify a customer who opens an account "in-person, remotely over the Internet, or through some other digital or virtual channel." The answer is "Yes."

The reasoning is simple. An mDL is a digital version of a state driver's license or ID card. It holds the same information as the physical card. So an unexpired, government-issued VDC qualifies as "government-issued identification" under the documentary verification provision, as long as it also "evidence[s] nationality or residence and bear[s] a photograph or similar safeguard."

Two conditions apply:

  1. The institution must maintain "the appropriate technology or systems to extract the relevant information" from the credential.
  2. Accepting the credential must be allowed under the institution's own CIP.

Institutions that meet both conditions can treat mDLs as one of their documentary verification methods.

The agencies also state that the answers "neither alter existing BSA legal or regulatory requirements nor establish new supervisory expectations." In other words, this clarifies existing rules rather than creating a new one, and there is no compliance deadline.

What counts as a verifiable digital credential?

The FAQ defines a VDC as a data structure that:

  • contains information about an individual,
  • is digitally signed by the issuing source of that information,
  • is cryptographically bound to a device, and
  • is protected by an activation factor, such as a PIN, a password, or a biometric like a face or fingerprint.
mobile-drivers-license-cip-fincen-faq-image-11

This definition has a practical consequence. An mDL is trustworthy because of the issuer's digital signature and its binding to the device. A screenshot of a wallet screen, or a photo of a phone showing a license, has neither. It is just an image. If your flow accepts one, treat it like any other document image and run document verification on it. Do not treat it as credential verification.

Documentary or non-documentary: which applies?

Both verification paths now mention digital credentials, but they work differently.

Documentary verification : A government-issued VDC, such as an mDL, can be used the same way as a physical driver's license: as government-issued photo identification.

mobile-drivers-license-cip-fincen-faq-image-16

Electronic credentials as a non-documentary method : The agencies updated an earlier FAQ on using electronic credentials, such as digital certificates, as a non-documentary means of verification, so that it now includes VDCs. A bank may use these credentials as one of its verification methods to the extent its CIP allows. If a private company, rather than a government, issues and maintains the credential, the bank must make sure that company authenticates people as rigorously as the bank itself would.

The practical difference is this. A state-issued mDL can support documentary verification directly. A privately issued credential requires the bank to stand behind the issuer's authentication standards.

What remains unchanged under the CIP Rule?

The FAQ allows institutions to use mDL as an additional verification method. It does not change or remove their existing CIP obligations.

  • Acceptance is optional. The CIP Rule "neither requires nor prohibits" relying on government-issued VDCs.
  • Fraud indicators still count. If a VDC shows signs of fraud, the institution must weigh that when deciding whether it can form a reasonable belief that it knows the customer's true identity.
  • No technology is prescribed. The FAQ requires systems that can extract the relevant information, but it does not name standards, vendors, or validation steps. Each institution decides how much validation its risk profile calls for.
  • The rest of CIP still applies. Collecting the required identifying information, verifying it, keeping records of the verification methods used, and list screening all continue as before.
  • Your written CIP must allow it. Staff and systems should not rely on VDCs until the policy lists them as an accepted documentary method.

Is remote mDL verification ready for production?

Until recently, the honest answer was that the standards existed but implementation was uneven. Signzy's August 2026 analysis of mobile driver's license verification described that gap.

Login.gov now shows it can work. On September 22, 2026, the General Services Administration (GSA) said the federal sign-in service had begun widely accepting mDLs for identity proofing the month before. Login.gov currently supports mDLs stored in Google Wallet and Samsung Wallet. It says availability depends on the user's state, device, and wallet.

GSA describes the mDL option as additional rather than mandatory, and says users share only the details needed for verification. According to GSA, 20 states and one territory offered mDLs as of March 2026. That made them available to about 71.5 million people, with roughly 8 million people using them.

There are two takeaways for banks:

  • Remote, cryptographic mDL presentation already works at government scale.
  • Coverage is still partial. Any bank flow needs a fallback for customers whose state, phone, or wallet is not supported yet.

How should banks implement mDLs in CIP?

  1. Update the written CIP. List unexpired, government-issued VDCs as an accepted documentary method, and describe when they are used.
  2. Receive the credential itself, not a picture of it. Use a verifier flow that requests the credential from the wallet with the customer's consent, so the signed data arrives intact.
  3. Validate the issuer's signature. Check the credential's signature against trusted certificates from the state issuers, and confirm the data has not been altered.
  4. Check expiry and required elements. The FAQ covers unexpired credentials that show nationality or residence and include a photograph or similar safeguard.
  5. Keep risk signals running. Device, velocity, and data-consistency checks still apply. Add selfie match and liveness where the risk calls for it.
  6. Record what you relied on. Log the credential type, issuing state, validation result, and timestamp, so examiners can see which method was used.
  7. Keep a fallback. Route customers with unsupported wallets or states to physical license verification or non-documentary methods, so no one hits a dead end.
  8. Ask vendors specific questions. Which wallets and states do they support? Do they validate issuer signatures, or only read the displayed data? How do they log results?

Where Signzy fits

Signzy's Driver's License Verification API automatically extracts and verifies data from physical and mobile licenses across all 50 U.S. states. It checks the details against DMV and AAMVA-aligned databases.

Combined with face match and liveness, it lets banks run mDLs and plastic licenses through one CIP flow, with the same audit trail for both.

Related reading: What is a Customer Identification Program (CIP)?, Driver's license verification methods compared, and AAMVA DLDV state coverage.

Sources

end
LinkedInX

FAQ

Saurin Parikh

Saurin Parikh

Saurin is a Sales & Growth Leader at Signzy with deep expertise in digital onboarding, KYC/KYB, crypto compliance, and RegTech. With over a decade of professional experience across sales, strategy, and operations, he’s known for driving global expansions, building strategic partnerships, and leading cross-functional teams to scale secure, AI-powered fintech infrastructure.

Related Blogs

The global API marketplace for KYC, KYB, & AML

Explore the end-to-end verification stack trusted by 1,000 businesses.

Get in touch