Financial institutions may use a mobile driver’s license or other government-issued virtual ID as a form of documentary verification for purposes of customer identification program compliance, so long as they maintain the appropriate technology or systems to extract the relevant information from the IDs, according to FAQs published today by the Financial Crimes Enforcement Network and banking agencies.
The new FAQs explain how the Customer Identification Program, or CIP, rule may apply to such verifiable digital credentials, according to a joint statement. The FAQs warn that if government-issued electronic credentials show indications of fraud, that must be considered a factor in determining whether the institution can form a reasonable belief it knows the customer’s true identity. In addition, FinCEN updated an existing CIP FAQ which permits the use of electronic credentials for verification purposes under certain circumstances, including those issued and maintained by non-government third parties, to include the new defined term “verifiable digital credential.”
The FAQs state that banks and credit unions may consider using virtual government-issued credentials for CIP documentary verification, in accordance with their CIP programs, provided that the institutions meet the requirements of the CIP rule. However, for virtual credentials issued and maintained by non-government third parties, institutions are required to ensure those parties use the same level of authentication that they would use.
In related news, the Financial Services Sector Coordinating Council’s AI and Identity and Authentication Workstream, which was co-chaired by the American Bankers Association and Better Identity Coalition, released a report in March highlighting the role that policymakers can play in helping financial institutions defend against current and emerging attacks powered by the malicious use of gen AI that target identity and authentication systems.










