Verifiable Digital Credentials Just Became CIP-Grade ID
Five US agencies issued FAQs letting banks accept mobile driver's licenses and verifiable digital credentials for CIP. What changes for onboarding now.

Verifiable digital credentials are now officially bank-grade identification. On September 8, the OCC, FinCEN, the Federal Reserve Board, the FDIC, and the NCUA jointly issued FAQs on the treatment of verifiable digital credentials under the Customer Identification Program rule, clarifying that banks may use state-issued mobile driver's licenses and other government-issued digital credentials to meet CIP obligations.
The guidance answers a question compliance teams have been asking since the first mDL launched: does a cryptographically signed credential on a phone count the way a plastic card does? The agencies' answer defines what qualifies as a VDC, explains how the CIP rule applies when a bank relies on one, and updates the terminology from earlier guidance. The bulletin reaches every national bank, federal savings association, and federal branch of a foreign bank, community institutions included.
For an industry that still photographs plastic cards at scale, this is the starting gun for digital-first onboarding.
What the FAQs actually clarify
Three things. First, definition: a verifiable digital credential is a government-issued digital identity artifact whose authenticity and integrity can be checked cryptographically, with mobile driver's licenses the leading example. Second, application: the CIP rule's documentary verification pathway can be satisfied with a VDC, provided the bank's program addresses how the credential is validated. Third, vocabulary: the agencies aligned terminology across prior guidance so examiners and institutions describe these credentials the same way.
The subtext matters as much as the text. Guidance written jointly by all five banking agencies, the same lineup behind the pending stablecoin CIP proposal, signals a coordinated position: digital credentials are not an accommodation, they are the direction of travel.
Why a signed credential beats a photographed card
The fraud math is one-sided. A photographed physical document is judged by how it looks, and AI document forgeries have industrialized exactly that attack, with generated documents now dominating AI-enabled fraud. A verifiable digital credential is judged by whether its issuer's signature checks out. There is no lighting to fake, no template to counterfeit, no hologram to imitate: either the state's cryptography validates or it does not.
Validation is not trivial, though, and that is where programs will be examined. A conforming acceptance flow has to verify the issuer's signature chain against trusted authorities, check revocation status in real time, confirm the credential is bound to the device and person presenting it, and log the whole decision trail. deepidv's Arc gateway runs that sequence natively, ingesting mDLs, eIDAS 2.0 attestations, and ZKP tokens with issuer policy, revocation checking, and binding validation before any downstream system relies on the credential.
The presentation problem the FAQ leaves open
A signed credential proves the document; it does not prove the presenter. A stolen phone with a cached mDL, or a fraud ring presenting a legitimate credential over an injected session, passes pure credential validation. The institutions that will get full value from the guidance are pairing VDC acceptance with liveness and session forensics, so the person presenting the credential is verified as thoroughly as the credential itself. The deepidv platform binds both checks into one camera session: deepeye confirms a live, present human while Arc validates the credential that human presents.
What compliance teams should do this quarter
Treat the FAQ as a program update, not a press release. Amend the CIP to name VDCs as an accepted documentary method with defined validation steps. Choose which issuers and credential formats the program trusts, and how revocation is checked. Decide the fallback when a customer's state does not yet issue an mDL. And instrument the evidence trail, because the first examiner questions will be about validation records, not adoption rates.
Institutions that move now get a conversion dividend as well: VDC onboarding removes the document photo, the retake loop, and most of the abandonment that comes with them.
Verifiable Digital Credentials FAQ
- Can banks accept mobile driver's licenses for KYC?
- Yes. As of the September 8, 2026 interagency FAQs, banks may use state-issued mobile driver's licenses and other government-issued verifiable digital credentials to satisfy the documentary verification requirements of the Customer Identification Program rule, provided their program covers how credentials are validated.
- What is a verifiable digital credential?
- A verifiable digital credential is a government-issued digital identity artifact, such as a mobile driver's license, whose authenticity and integrity can be verified cryptographically against the issuer. Unlike a photographed physical document, it is validated by signature checking rather than visual inspection.
- Which agencies issued the VDC guidance?
- All five federal banking regulators jointly: the OCC, FinCEN, the Federal Reserve Board, the FDIC, and the NCUA. The OCC published it as Bulletin 2026-44 on September 8, 2026, and it applies to national banks, federal savings associations, and federal branches of foreign banks of every size.
- Do verifiable digital credentials stop identity fraud?
- They eliminate document forgery for the credential itself, since AI cannot fake a state's cryptographic signature. They do not verify the presenter: a stolen device or an injected session can still deliver a legitimate credential. Effective programs pair VDC validation with liveness detection and session forensics.
- How should a bank update its CIP for mobile driver's licenses?
- Name VDCs as an accepted documentary method, define the validation sequence (issuer signature, revocation, device binding), select trusted issuers and formats, set the fallback path for customers without VDCs, and retain validation evidence in the CIP record. Examiners will test the validation trail, not the policy language.
Relevant Articles
Stablecoin CIP Comment Window Extended to October 23
The same five agencies, mid-rulemaking on crypto CIP.
Sep 4, 2026
EUDI Wallet Deadline: Europe's Identity Clock Hits 90 Days
The European half of the credential convergence.
Sep 11, 2026
Sub-150ms Attestation Moves Verification to the Client Edge
The device-side proofs underneath credential trust.
Sep 4, 2026
What is deepidv?
Not everyone loves compliance — but we do. deepidv is the AI-native verification engine and agentic compliance suite built from scratch. No third-party APIs, no legacy stack. We verify users across 211+ countries in under 150 milliseconds, catch deepfakes that liveness checks miss, and let honest users through while keeping bad actors out.
Learn More