deepidv
Back to Playbooks
The Deep Brief · Curated Playbook · Global · Oct 5, 2026 · 19 min read

The credential acceptance playbook: wallets without the wreckage

An executive playbook for accepting mDLs, wallet attestations, and reusable identity: issuer posture, binding tiers, fallbacks, and evidence, in five phases.

The Credential Acceptance Playbook cover from The Deep Brief, No. 31
Curated Playbook
19 min read · Advanced · Global

Full name + work email required. We'll email you a copy.

The credential era stopped being a roadmap item this quarter. Login.gov accepts mobile driver's licenses from Google and Samsung wallets; commercial KYC vendors ship acceptance weeks later; US regulators have confirmed credentials can serve Customer Identification Programs; Europe's wallet carries sector deadlines with dates attached; and the projections now in procurement decks, a US mDL base growing from 21.7 million toward 143 million by 2030, describe a curve, not a possibility. For every bank, platform, and verification program, the question has flipped from whether to accept reusable credentials to how to accept them without inheriting their failure modes.

Because the failure modes are real and specific. A credential proves issuance, not presence: stolen devices and coerced approvals present perfectly. Its assurance ceiling is its issuer's enrollment ceremony: a wallet provisioned against a stolen identity kit is a cryptographically flawless fraud, forever. Its privacy and conversion gains evaporate if the fallback path punishes the majority who hold no credential yet. And its regulatory welcome came with an unwritten invoice: the examiners who opened CIP to credentials will audit how acceptance actually ran, per decision. This playbook is the systematic answer: five phases over roughly twelve weeks, covering the acceptance census, intake and issuer posture, binding tiers, fallback symmetry, and the evidence and adversarial operations that keep the program honest. It is written for the compliance lead, the fraud lead, and the product lead as one audience, because credential acceptance fails in their seams: product ships the fast lane, compliance blesses the signature check, fraud discovers the provisioning hole, and the gap belonged to no one.

Deployments here reflect the deepidv platform; the architecture is stated so any vendor can be held to it, and the foundations, reusable identity's mechanics and mDL verification in detail, are covered in their own guides.

The threat model: four gaps the cryptography cannot see

Credential acceptance inherits a threat model that lives entirely outside the signature math.

The provisioning gap: enrollment is the ceiling. A stolen identity kit, genuine document images and a matching deepfake, enrolled through a weak issuer path yields a genuine credential for a fraudulent holder, and every downstream check validates the issuance. This is the fake-passkey lesson replayed at government grade, and the attack economics improve with every service that accepts the credential: one fraudulent enrollment, reused everywhere.

The possession gap: presentation proves the device, not the human. Stolen devices with shoulder-surfed PINs, delegated fallback passcodes, and coerced approvals all present validly, and the wallet's biometric gate, where it ran at all, is invisible to the relying party. For low-stakes checks this residual is priced in by design; for onboarding, money movement, and recovery it is the gap that session-level binding exists to close.

The freshness gap: revocation travels slower than fraud. A credential reported stolen, an attribute that changed, an issuer that suspended, each takes effect at the relying party only as fast as trust lists and status checks actually refresh, and the measured lag between issuer revocation and relying-party refusal is a number most programs have never computed.

The asymmetry gap: the fallback becomes the attack path or the exclusion engine. If the non-credential route is weaker, fraud simply uses it, and the credential lane's assurance is theater; if it is more punishing, the majority without credentials, which is most users in most markets for years yet, experience the program as discrimination, and regulators increasingly agree with them.

Every phase below is a tax on one of these four gaps.

Reference architecture: posture-weighted acceptance

LayerWhat it doesPasses forward
Intake layerSignature + integrity validation · trust-list / VICAL check · revocation status at presentation · freshness / channel bindValid presentation + issuer identity
Issuer posture tableProvisioning strength · remote enrollment policy · revocation infrastructure · incident history · opacity = its own gradeEvidence weight per issuer tier
Decision planeAction-class policy: what this presentation may authorize · Binding tiers: possession-only → wallet-gate trust → liveness-anchored portrait match (deepeye) · Fallback symmetry: equal-assurance non-credential routeThe acceptance decision for this action
Evidence vaultPer acceptance: issuer, trust-list version, checks run, binding method, outcome · revocation-lag telemetry · reuse analytics across the bookThe per-acceptance evidence record

Two properties carry the design. Posture-weighting: a presentation's evidence value is a function of its issuer's enrollment reality, not just its signature validity, so the posture table is live policy, not documentation. And binding as a tier, not a toggle: the present-person question gets answered in proportion to the action's risk, which is how the program keeps the credential's conversion gains for the ninety percent of checks where possession suffices while refusing to let possession authorize the moments that matter.

Phase 0: the acceptance census (weeks 1-2)

Most organizations are already accepting credentials somewhere, informally. Phase 0 finds every path: product flows that accept wallet-presented documents as if they were document photos, vendor features switched on by default after the commercial acceptance wave, network assertions consumed in login flows, and partner integrations that quietly rely on someone else's verification. For each path, record what is actually checked, signatures, trust lists, revocation, binding, and what the acceptance currently authorizes.

The census's second half is demand mapping: which user segments and markets already hold credentials, mDL issuance by state, wallet penetration, network enrollment, and which action classes would gain most from acceptance, measured by current onboarding drop-off and verification cost. The output is the same artifact every playbook in this series starts with: a register, ranked by exposure and opportunity, with owners and dates, which doubles as the document that converts the program from a product feature into a governed risk discipline.

Phase 1: intake done properly (weeks 3-5)

Phase 1 builds the intake layer most early adopters skip past: full cryptographic validation, issuer signatures against current trust lists, VICAL-style mechanisms for mDLs, federation metadata for networks; integrity and freshness, replay and relay resistance through session binding and transcript checks; and revocation status checked at presentation, with the lag between issuer revocation and local refusal instrumented as a standing metric, because the freshness gap is invisible until it is an incident.

In parallel, the issuer posture table gets built: per accepted issuer, what is documented about provisioning, in-person versus remote enrollment, liveness requirements, document checks at enrollment, revocation infrastructure, incident history, with explicit unknowns, because opacity is itself a posture grade. The table's first draft is a research exercise; its maintenance is a policy function, re-graded quarterly and on incidents, and its output is the weight each issuer's presentations carry in the decision plane. Programs that skip the table are declaring every DMV, wallet platform, and network equally trustworthy, a position no one would sign if asked out loud.

Phase 2: binding tiers (weeks 6-8)

Phase 2 installs the program's center: the mapping from action classes to present-person proof. The working tiers: possession suffices for low-stakes, reversible actions, age gates on content, returning-user convenience; wallet-gate trust, accepting the device's own biometric gate as the bind, covers the middle where stakes are moderate and the issuer posture is strong; and the liveness-anchored portrait match, the present face matched against the credential's signed portrait on structural liveness with injection defense, gates the actions that define fraud outcomes: account opening, payout changes, credential recovery, high-value transactions, and anything that mints new authority.

Two design rules keep the tiers honest. Weak or opaque issuers earn the bind at lower thresholds, which is the posture table cashing out. And the bind must be attack-grade, because binding is where the adversary will aim next: a portrait match without liveness invites the enrolled face replayed from the breach archive, and a liveness layer without injection defense invites the virtual-camera stream, the exact composite the stolen-wallet drill in Phase 5 rehearses.

The clip shows a biometric face match running on passive liveness and deepfake detection, the attack-grade bind this section reserves for account opening, payout changes, and recovery.

Phase 3: fallback symmetry (weeks 9-10)

Phase 3 builds the route most programs treat as legacy: the non-credential path, engineered to equal assurance at comparable friction. Document-plus-liveness proofing remains the escalation tier and the route for the majority without credentials, and its quality is a fairness obligation and a security one simultaneously: a weaker fallback is where fraud routes, a crueler fallback is where regulators and journalists look first. Symmetry is measurable: completion rates, time-to-verified, and assurance levels per route, reviewed as one dashboard, with any gap between routes treated as a finding. This phase also sets the communication grammar: credential acceptance is marketed as a faster option, never a requirement, and the fallback is a first-class flow with its own conversion ownership, because the quickest way to turn a wallet program into a discrimination complaint is to let the fallback rot.

The acceptance curve: sequencing by action class

Programs rarely fail by accepting credentials; they fail by accepting them everywhere at once. The durable rollout sequences action classes up the risk ladder, and the sequence doubles as the program's learning curve. First wave: age facts and returning-user checks, where selective disclosure shines, possession tiers suffice, and the downside of an error is bounded, the wave that generates adoption numbers and operational telemetry while nothing irreversible rides on it. Second wave: onboarding into lower-risk products, with the liveness-anchored bind mandatory from day one, because this is where provisioning fraud first becomes profitable and where the fraud-spread baseline gets established. Third wave: money movement, payout changes, and recovery, the classes that never leave the top binding tier and that join only after the posture table has survived a quarter and the drills have run clean. The sequencing rule that keeps the curve honest: no action class accepts credentials until its binding tier, fallback route, and evidence record are live, which sounds obvious and is violated by every fast-lane deployment currently in production. The curve also gives the program its negotiating position with growth teams: the conversion delta from wave one is real, measured, and quotable, which funds patience for the waves where patience is the control.

Pull quote

“Programs rarely fail by accepting credentials; they fail by accepting them everywhere at once.”

Phase 4: evidence and reporting operations (weeks 11-12)

Phase 4 assumes the examination the regulatory welcome implies. Every acceptance writes a record: credential type, issuer, trust-list version, checks run, binding method and result, decision outcome, assembled by the system so the file exists the moment the question is asked. Program-level telemetry aggregates what examiners and boards both need: acceptance volumes by issuer and action class, binding-tier distribution, revocation-lag percentiles, fallback-route symmetry numbers, and fraud outcomes by route, credential versus fallback, the spread that validates or indicts the whole design. Reuse analytics complete the evidence layer: the same credential, face, or device recurring across accounts where it should not, because reusable identity amortizes attacks exactly as efficiently as it amortizes verification, and the book-level view is where amortized fraud surfaces.

Two service levels worth committing to in writing: complete acceptance evidence for any decision within 24 hours of a lawful request, and issuer-incident response, re-weighting the posture table and re-screening recent acceptances from an implicated issuer, within one business day of credible reports.

Phase 5: adversarial assurance (ongoing)

From week twelve, Arbiter runs the credential drill calendar. The stolen-wallet drill: valid test credentials presented from devices the holder does not control, against every action class, scoring which flows accept possession as presence. The provisioning drill: test wallets enrolled against synthetic kits through the weakest accepted issuer path, presented downstream, measuring whether posture weights or binding tiers ever catch the genuine-but-fraudulent credential. The replay drill: transcript replays and relayed sessions against freshness and channel binding, scored separately from signature validation, which always passes by construction. The binding drill: presented photos and injected streams of the enrolled face against the portrait match, scoring the capture-integrity layer alone. And the arbitrage drill: the fallback route attacked with the same kit, flagging any flow whose back door is weaker than its front. Each miss converts to a dated fix; each report joins the evidence stream that tells an examiner the program tests itself.

Interoperability: one intake for many schemes

The credential era is arriving as a plural: ISO 18013 mDLs from US states, EUDI attestations under eIDAS, W3C verifiable credentials from private issuers, network assertions from identity providers, and the UK's register-verified services, each with its own trust mechanics, status infrastructure, and failure modes. The architecture mistake to refuse early is the per-scheme silo: a separate mDL lane, a separate wallet lane, a separate network lane, each with its own policy, logging, and gaps, which is three programs pretending to be one. The intake layer should normalize instead: every scheme's presentation resolves to the same internal shape, issuer identity, attribute set, assurance indicators, status result, and flows into one posture table, one binding policy, and one evidence schema, with scheme-specific validation encapsulated at the edge. The payoff compounds with every scheme the market adds: a new state's mDL, a new wallet platform, an EUDI sector attestation, each lands as a posture-table row and an intake adapter rather than a quarter of integration, and the program's policy, tiers, fallbacks, evidence, applies uniformly because it was never scheme-shaped to begin with. The test for whether the normalization is real: one query should answer, across all schemes, which acceptances in the last year relied on issuers now graded weak, because that is the question the first cross-scheme incident will ask.

The regulatory and liability map

RegimeInstrumentAcceptance obligationEnforcement posture
USFinCEN and agencies, CIP credential FAQs (2026)Credentials may serve CIP within a program still forming reasonable belief in true identityExamination of how acceptance ran, per decision
US statesmDL issuance statutes and ISO 18013 adoptionIssuer-side provisioning and trust-list participation vary by statePosture differences are the relying party's risk input
EUeIDAS 2 / EUDI frameworkAcceptance duties for regulated and very large services at assurance levels; sector ladders (health: high assurance 2030-2032)Supervisors grading acceptance and binding per sector
UKDVS trust framework, machine-readable registerCertified providers verified at transaction time; VICAL/RICAL rails for credentialsOfDIA register testing from October 2026
GlobalAML/KYC record-keepingAcceptance evidence retained like any verification recordDecision records satisfy; raw minimization applies
PrivacyGDPR, state biometric and minimization statutesSelective disclosure favored; binding biometrics governed as biometric processingDeletion and proportionality enforced on the bind layer

The map's through-line: every regime welcomes credentials and none of them transfers the relying party's obligation. The bank still must know its customer; the platform still must prove its process; the binding biometric still answers to privacy law. Acceptance is an input the rules permit, not a liability the rules absorb, and the programs that internalize that sentence early are the ones whose examinations stay boring.

The migration question: what happens to the old stack

Acceptance does not retire the document-and-liveness stack; it repositions it, and programs should say so explicitly to avoid two opposite mistakes. The first mistake is premature decommissioning: treating credential adoption as license to let document proofing, liveness quality, and forensic coverage decay, which guts the fallback route and the escalation tier simultaneously, the two places the old stack now matters most. The second is parallel neglect: running the legacy flow unchanged beside the credential lane without re-tuning it, so its thresholds, friction, and staffing still assume it carries all traffic when it now concentrates the contested, thin-file, and escalated cases, a harder population than it was tuned for. The right migration re-scopes the old stack deliberately: document-plus-liveness proofing becomes the escalation and inclusion tier, staffed and measured for the tougher mix it now receives, with its forensic and injection defenses maintained at full strength because the adversaries it meets are now the ones the credential lane filtered out. Budget-wise this means the legacy stack's cost per verification rises as its volume falls, which is expected and correct, and finance should hear that framing before the first quarterly review makes it look like a problem.

Measurement: the program scoreboard

Ten numbers run the program. Adoption: share of eligible verifications arriving by credential, and conversion delta versus the fallback route, the numbers product owns. Assurance: binding-tier distribution by action class, and fraud rate by route, credential versus fallback, the spread that proves the tiers are real. Freshness: revocation-to-refusal lag percentiles, and trust-list staleness, the gap metrics. Fairness: fallback completion rate and time-to-verified versus the credential path, the symmetry pair. Operations: acceptance-evidence SLA hit rate, and drill catch rates by attack class. Publish monthly to compliance, fraud, and product together; the seams between them are where the four gaps live.

Failure modes: how acceptance programs actually fail

The recurring failures are already visible in early deployments. The fast-lane fallacy: acceptance built as a conversion feature with signature checks only, which works flawlessly until the first provisioning fraud arrives cryptographically perfect; the posture table and binding tiers exist precisely for the day signatures stop being the question. The uniform-issuer assumption: every DMV and wallet treated identically because the standard is shared, when enrollment ceremonies differ by an order of magnitude; opacity deserves a grade, not a pass. The withering fallback: the non-credential route starved of product attention until it is slower, crueler, and the fraud team's main intake simultaneously. The revocation afterthought: trust lists refreshed on deployment cycles rather than policy cycles, with the lag discovered during the incident it enabled. The binding theater: a portrait match without liveness or injection defense, which replays the breach archive's faces straight through. And the evidence gap: acceptances that decide but do not record, leaving the first examination to be answered from logs that were never designed to answer it. Each failure shares the signature this series keeps finding: the dashboard stays green while an assumption compounds, which is why the scoreboard pairs every adoption number with an assurance spread.

Segment notes

Banks and fintechs carry the CIP examination directly: their sequence weights the evidence layer and the binding tiers on money-moving actions, and their posture table should start conservative, strong-provisioning issuers only, widening as the table matures. Marketplaces and platforms gain most from the conversion delta and should resist the fast-lane fallacy hardest, because their seller-side payout events are exactly where possession-as-presence fails expensively. Age-regulated services get the cleanest early win: credential-presented age facts with selective disclosure satisfy the strictest privacy-minimization statutes, with estimation as the majority route and the credential as the escalation tier. Government services inherit the equity mandate: fallback symmetry is a legal requirement, not a design preference, and the Login.gov pattern, credential acceptance beside document routes, is the reference. And EU-exposed firms should read the EUDI sector ladders as scheduled demand: acceptance capability becomes an obligation with dates, health data first.

The privacy dividend, claimed deliberately

Credential acceptance carries a privacy story strong enough to be a regulatory asset, but only if the program claims it architecturally. Selective disclosure means an age gate can learn over-18 and nothing else; a residency check can learn the fact without the address; and the relying party's data footprint shrinks with every flow that stops photographing documents. The claim becomes real through three commitments. Minimize at the decision plane: request the narrowest attribute set each action needs, and let the evidence record prove the narrowness, because examiners and privacy regulators now read request patterns. Govern the bind biometrics hardest: the liveness-anchored portrait match processes biometric data under the strictest statutes in the stack, so it runs with explicit purpose, short retention, and deletion evidence, the same custody discipline any biometric layer owes. And resist enrichment temptation: the credential's verified attributes are evidence for the decision, not a feed for marketing profiles, and programs that blur that line convert their privacy dividend into their next consent scandal. Claimed properly, the dividend compounds: data-minimization statutes that punish document-photography stacks reward credential flows, and the program's privacy posture becomes a sentence in the board narrative rather than a caveat.

The human layer: acceptance culture

Three installations keep the architecture honest. First, the posture table needs an owner with standing: someone whose job includes telling product that a popular issuer's enrollment is weak, with the table's quarterly re-grade on a calendar nobody can quietly skip. Second, the binding tiers need defense in depth against convenience creep: every request to move an action class down a tier is a priced decision with a named signer, because tier erosion is how fast-lane fallacies rebuild themselves one exception at a time. Third, the fallback needs advocacy: a named owner for the non-credential route's conversion and fairness numbers, reviewed beside the credential path's, so the majority route never becomes the neglected one. The cultural tell worth watching: when product managers start asking "what tier is this action" unprompted, the program has taken root; when credential acceptance ships in a sprint without the posture table hearing about it, the census needs re-running.

The economics: pricing the program

Price acceptance against both of its counterfactuals. Against document-only verification: credential checks cost less per verification, convert better, and collect less data, the gains that fund the program, multiplied by an adoption curve heading toward 143 million US credentials. Against naive acceptance: the program's marginal cost, posture table, binding tiers, fallback parity, evidence, is the premium that prevents inheriting the four gaps, and its price is a quarter of disciplined work, while the uninsured alternative's price is the first provisioning scandal arriving as your fraud loss, your CIP finding, and your headline simultaneously. The honest board framing: acceptance is coming either way, by product demand and by regulation; this program decides whether it arrives as compounding advantage or deferred liability.

143 million
projected US mDL base by 2030, up from 21.7 million

Choosing the stack: the buyer's evaluation grid

Six questions expose any vendor's acceptance readiness. Does intake validate against live trust lists with revocation checked at presentation, and what is the measured refresh lag? Can acceptance weight by issuer posture, and who maintains the table? Are binding tiers native, possession, wallet-gate, liveness-anchored portrait match, with injection defense under the bind? Is the fallback route equal-assurance and instrumented for symmetry? What does the per-acceptance evidence record contain, exportable, on what SLA? And can the stolen-wallet, provisioning, and replay drills run on a schedule with results in writing? Insist on the provisioning scenario in every proof of concept: a genuine credential enrolled against a synthetic kit. Signature-grade stacks pass it forever; acceptance-grade stacks catch it at the bind or the book.

Day-two operations: running the program

Steady state is three rhythms. Daily: revocation feeds consumed, issuer incident monitoring, binding-failure queue worked within SLA. Weekly: route-symmetry and fraud-spread numbers reviewed across the three leads, new acceptance requests adjudicated against the posture table before they ship. Quarterly: the drill calendar, the posture re-grade, trust-list and threshold recalibration, and the board line refreshed: adoption up, spread held, lags bounded. The program's health reads in two numbers moving together: credential adoption rising and the credential-versus-fallback fraud spread staying flat or favorable, because adoption with a widening spread is the fast-lane fallacy measured in real time.

After go-live: the first quarter

Expect three waves. Weeks one to four: adoption concentrates among strong-issuer holders and the conversion delta shows immediately, which is when the pressure to loosen tiers arrives; hold the line until the fraud spread has a baseline. Weeks five to eight: the first issuer surprises land, an incident report, an opacity that resolves badly, and the posture table earns its keep as a weight change instead of a crisis. Weeks nine to twelve: the first drill cycle converts assumptions into fixes, revocation lags get measured against policy for the first time, and the scoreboard stabilizes into trends. The quarter's deliverable is the second census against the first: acceptance paths governed, tiers holding, evidence flowing, and the comparison is what an examiner reads as a program rather than a feature.

The board narrative

Four sentences carry the program upstairs. Reusable credentials are becoming how customers prove identity, with regulators' blessing and a nine-figure adoption curve, and we now accept them as governed evidence rather than as a bypass. Every acceptance is weighted by the issuing authority's real enrollment strength, and the actions that matter still require proof of the present human. Our non-credential route holds equal assurance, so acceptance is an option, never a wall. And we attack our own acceptance quarterly, stolen wallets, fraudulent enrollments, replays, so the credential era's first scandal finds us with drill results instead of exposure. A board that can repeat those sentences can answer investors, examiners, and the press with the same four lines.

The hardest week

Every acceptance deployment has one: the week a strong-posture issuer has its provisioning incident, and the program discovers how many of its accepted credentials trace to the implicated enrollment window. The playbook's answer is prepared in Phase 4: the posture table re-weights the issuer the same day, recent acceptances from the window re-screen through the binding tier they skipped, affected customers re-verify through the fallback route with honest communication, and the evidence vault produces the exposure list as a query instead of a forensic project. Programs survive this week when re-screening is machinery; they fold when it is a war room, because the window's size is never known on day one, and improvised re-verification at scale is indistinguishable from an outage.

The ninety-day variant

Compressed timelines run the sequence with narrowed scope: census over everything, acceptance live for one action class, age or returning-user checks, where possession tiers suffice; the posture table drafted for the top five issuers by expected volume; the liveness-anchored bind wired for onboarding before onboarding accepts credentials at all; fallback symmetry measured from day one; and one drill, stolen-wallet, before day ninety. The variant's discipline is sequencing: binding before volume, posture before breadth, evidence before marketing, with the funded plan for full coverage as the deliverable and the census as the contract.

Credential Acceptance Playbook FAQ

What is a credential acceptance program?
The governed discipline of consuming reusable identity credentials, mDLs, wallet attestations, network assertions, as verification evidence: cryptographic intake with live trust and revocation checks, issuer posture weighting, risk-tiered present-person binding, equal-assurance fallbacks, and per-acceptance evidence.
Do mobile driver's licenses replace identity verification?
No: they replace the document-photography step with cryptographic validation. The present-person question, who is holding the device, and the enrollment question, who was proofed at provisioning, remain the relying party's to answer, tiered by action risk.
What is an issuer posture table?
A maintained grading of each accepted issuer's real enrollment and lifecycle strength: provisioning ceremony, remote enrollment policy, liveness at enrollment, revocation infrastructure, and incident history, with opacity graded explicitly, feeding acceptance weights and binding thresholds.
When should a credential presentation require a liveness check?
When the action mints authority or moves value: account opening, payout and credential changes, recovery, high-value transactions, and whenever the issuer's posture is weak or unknown. Low-stakes, reversible checks can ride possession.
Can banks accept wallet credentials for CIP compliance?
Yes, per the 2026 federal FAQs, within a program still forming reasonable belief in the customer's true identity, which keeps risk tiering, binding, and evidence in scope: acceptance is permitted input, not transferred liability.
How do fraudsters attack credential acceptance?
Around the cryptography: fraudulent enrollment at weak issuers, stolen devices and coerced approvals, replayed and relayed presentations, attacks on the binding step with photos and injected streams, and arbitrage against weaker fallback routes.
How long does a credential acceptance program take to deploy?
Roughly twelve weeks in five phases, census, intake and posture, binding tiers, fallback symmetry, evidence operations, with drills ongoing, and a ninety-day variant that opens one action class with binding and posture in place first.
TagsIdentity VerificationCryptographyKYCBankingGlobalAdvancedPlaybook

Relevant Articles

deepidv

Credential acceptance as a risk discipline

deepidv's engineers run this playbook with your team: posture-weighted intake, tiered binding, symmetric fallbacks, and evidence from day one.