Highlights
3 years in a row named a Leader First to achieve iBeta Level 3 on iOS and Android Introducing GovFaceMatch Privacy is the architecture
01/04
01/04
Back to blog
FinCEN confirms mobile driver's licenses are valid ID for KYC

FinCEN confirms mobile driver's licenses are valid ID for KYC

On September 8, 2026, FinCEN and four federal banking agencies confirmed that a mobile driver's license (mDL) counts as government-issued ID for know-your-customer (KYC) checks when opening a bank account, in person or online.

This post breaks down what the new guidance says, the two conditions institutions must meet before accepting a digital credential, and how institutions can accept mDLs alongside the physical IDs they already verify, in one flow.

FinCEN puts mobile driver's licenses on the same footing as a physical license

FinCEN, the US Treasury's Financial Crimes Enforcement Network, issued the new guidance jointly with the Federal Reserve, FDIC, NCUA, and OCC. It confirms that a verifiable digital credential (VDC), such as a state-issued mobile driver's license, can be used to verify a customer's identity when opening an account, in person or over any digital channel.

A VDC is identity data that is digitally signed by the issuing authority, bound to the user's device, and unlocked by a PIN or a biometric. An unexpired mDL qualifies as government-issued identification under the Customer Identification Program (CIP) Rule, which governs how US financial institutions verify new customers, provided it evidences nationality or residence and bears a photograph or similar safeguard. It sits on the same footing as a passport or a physical license.

Two conditions apply. First, the institution must maintain the appropriate technology or systems to extract the relevant information from the credential (visually reading the fields a wallet shows on screen is not extraction). Second, the credential must be an allowable method under the institution's written CIP.

Government mDLs and third-party credentials follow different paths

The guidance covers both halves of the digital wallet market. A state-issued mDL enters as a documentary method: it counts as government-issued identification, in the same category as a passport or a plastic license, so an institution adds it to its written CIP as an approved method with no new risk framework to build.

Credentials issued by non-government third parties, such as a reusable ID from a private provider, enter through the non-documentary path. There, the institution is responsible for confirming that the issuer applies the same level of authentication the institution itself would use, measured against authentication guidance from the FFIEC, the federal interagency council that sets examination standards for banks. Most institutions will start with government-issued credentials, where the trust model is simpler: a credential signed by a state DMV reflects an identity-proofing event the state already performed.

More than 20 states already issue mobile driver's licenses

The credential supply is ready. More than 20 US states and territories run active mDL programs, issuing credentials to ISO/IEC 18013-5, the international standard for mobile driver's licenses. Customers can present from Apple Wallet, Google Wallet, Samsung Wallet, or a state-run app, and a companion standard (ISO/IEC 18013-7) defines how the same credential is presented remotely, over the web or in an app.

Until now, the missing piece was regulatory certainty. Institutions and their counsel had to interpret the CIP Rule on their own, and many treated the ambiguity as a reason to wait. Joint guidance from FinCEN and the four agencies that supervise most US banks and credit unions removes that ambiguity, and examiners across regulators can now point to the same document.

Higher assurance, less friction

"Frictionless KYC" is often read as a lighter check. This is the opposite: a higher-assurance check that removes the steps most likely to fail. This is valuable for both people and the businesses serving them:

  1. For the person: onboarding in seconds. No need to hunt for a physical ID. The user presents a credential from the mobile device already in their hand, in seconds, and shares only what is needed, so flows that people abandon mid-capture get finished.
  2. For compliance teams: cleaner evidence and less manual review. Attributes arrive signed by the issuing authority instead of parsed from a photo. Institutions get clean, structured fields and a cryptographic proof of origin: a stronger audit trail than a document image, with fewer cases routed to manual review.

Verifying an mDL in the same flow as a physical ID

Incode accepts mobile driver's licenses in the same verification flow institutions already run for physical documents. A customer with an mDL presents it from their device wallet, or a state app; a customer without one captures a physical ID. Both paths run on one platform, so accepting digital IDs is a configuration change rather than a second integration.

Incode reads mDLs to the ISO/IEC 18013-5/-7 international standards for mobile driver's licenses. That coverage grows every quarter as more states issue credentials. National eID schemes extend the same flow for institutions operating beyond the US. One integration keeps pace with new programs, rather than a separate build per wallet or jurisdiction.

Acceptance is only the first step. On the Incode platform, the credential runs through the checks the institution already applies to physical IDs. Verification is cryptographic: issuer signature, data integrity, device binding, and freshness, all checked server-side.

Put FinCEN’s guidance to work

Ready to accept mobile driver's licenses and verify the person behind each one, or curious how Incode's digital ID verification keeps digital and physical IDs in one flow? Request a demo.

Ready to see it in action?

Request a demo