deepidv
All AI Prompts
FinTechTask Prompt

Task Prompt to Draft a Verifiable Digital Credential CIP Acceptance Policy

This **Arc** task prompt takes your onboarding flow and the **September 8, 2026 interagency CIP FAQs (OCC Bulletin 2026-44)**, then drafts the verifiable digital credential acceptance policy the guidance now expects. Arc, the deepidv credential gateway, writes the **issuer trust policy** for which credential formats and authorities you accept (state mDLs, eIDAS 2.0 attestations, ZKP tokens) with trust-list sources and update cadence, the **validation sequence** per credential type binding issuer signature, revocation, device binding, and presenter liveness into one session, the **failure routing** with a step-down to NFC or forensic verification at equal assurance, the five-year **evidence schema** an examiner can read without manual assembly, and the **CIP program language** naming VDCs as an accepted documentary method in the FAQ's own terminology. Built for bank and fintech compliance teams turning the FAQ into an examinable program rather than a press release.

Task Prompt to Draft a Verifiable Digital Credential CIP Acceptance Policy

How to use this prompt

  1. 1

    Open Arc in the deepidv dashboard and paste the full prompt, or run it in Claude, ChatGPT, or Gemini if you are drafting the policy outside the platform.

  2. 2

    Replace the INPUT section with the credential formats your customers present, your current onboarding flow, and your record-retention setup.

  3. 3

    Run the prompt and read the validation sequence first: it binds issuer signature, revocation, device binding, and presenter liveness into one session per credential type.

  4. 4

    Route the CIP program language to your compliance committee and the evidence schema to engineering, and assign each flagged gap an owner and date.

  5. 5

    Re-run the prompt as issuers and credential schemes expand so the policy stays current with the FAQ and the arriving EUDI wallets.

The prompt

Arc, draft our verifiable digital credential acceptance policy under the September 8, 2026 interagency CIP FAQs (OCC Bulletin 2026-44).

Context: the OCC, FinCEN, Federal Reserve, FDIC, and NCUA have clarified that state-issued mobile driver's licenses and other government-issued verifiable digital credentials may satisfy CIP documentary verification, provided the program defines validation.

Produce:
1. Issuer trust policy: which credential formats and issuing authorities we accept (state mDLs, eIDAS 2.0 attestations, ZKP age/attribute tokens), with the trust-list source and update cadence for each.
2. Validation sequence per credential type: issuer signature chain, revocation status, device binding, and presenter verification (deepeye liveness + portrait match) as one session.
3. Failure routing: expired or revoked credential, unbound device, liveness failure, and unsupported issuer, with the step-down path to NFC or forensic document verification at equal assurance.
4. Evidence schema: the per-decision record we retain for five years, validation results, timestamps, issuer references, sufficient for a CIP examination without manual assembly.
5. CIP program language: the amendment text naming VDCs as an accepted documentary method, using the FAQ's terminology, ready for compliance committee review.

Flag any gap between this policy and our current onboarding flow as a work item with an owner and a target date.

Test it in Claude or another LLM

This prompt is built for the Arc agent inside deepidv, where Arc validates real credentials and reconciles the policy to your onboarding flow. You can dry-run the policy structure in any general LLM first with synthetic issuers before wiring it live.

  1. 1

    Paste the full prompt into Claude, ChatGPT, or Gemini, but replace the opening 'Arc,' with a role instruction such as 'Act as a bank CIP policy author for verifiable digital credential acceptance.' Keep the OUTPUT sections exactly as written.

  2. 2

    Under the INPUT section, paste the synthetic sample block below so the model has credential formats, a flow, and a retention setup to draft against.

  3. 3

    Add one framing line: 'This is synthetic test data. Where a validation step cannot be defined from the input, flag it as an open question instead of assuming it.'

  4. 4

    Check the output shape: an issuer trust policy, a per-credential validation sequence, failure routing at equal assurance, a five-year evidence schema, CIP program language, and a gap list. If the validation sequence omits presenter verification, tighten the role line and re-run.

  5. 5

    Once the output shape is right, run it live in the deepidv dashboard where Arc validates the real credentials your customers present.

Synthetic sample data to paste alongside the prompt

Fake test data, safe to share with any LLM. Swap in your own once the output looks right.

CREDENTIAL FORMATS (synthetic, fake): Arizona and Colorado mDLs, eIDAS 2.0 attestation (pilot), ZKP age token (rare)
CURRENT FLOW (fake): document photo capture plus selfie match, no cryptographic credential path
RETENTION (fake): case records kept 5 years but not structured for per-decision validation evidence
FALLBACK (fake): NFC chip read available on ~60% of documents; forensic analysis otherwise
OPEN ITEM (fake): whether to accept a state mDL whose issuer trust list has not published a revocation endpoint

FAQ

What did the September 2026 CIP FAQ allow?

The OCC, FinCEN, Federal Reserve, FDIC, and NCUA jointly clarified that state-issued mobile driver's licenses and other government-issued verifiable digital credentials can satisfy the CIP rule's documentary verification requirement, provided the bank's program defines how each credential is validated.

What does this prompt produce?

An issuer trust policy, a per-credential validation sequence covering signature, revocation, device binding, and presenter liveness, failure routing to a fallback at equal assurance, a five-year evidence schema an examiner can read, and CIP program language naming VDCs as an accepted documentary method, with a gap list against your current flow.

Can I run this outside the deepidv dashboard?

Yes. The structure works in Claude, ChatGPT, or Gemini as a policy-drafting framework and returns the trust policy, validation sequence, and program language. Live credential validation, issuer-chain, revocation, binding, and presenter liveness, only runs when it executes inside the deepidv dashboard through Arc.

Run it with live verification data

These prompts work in any LLM. Inside the deepidv dashboard, Luna, Arbiter, and Arc run them against your real sessions, screening lists, and audit trails.

Book a Demo