Financial institutions and federal regulators are aligning operational frameworks as the Financial Crimes Enforcement Network (FinCEN), alongside the Federal Reserve and other banking agencies, issued compliance clarifications regarding state-issued mobile driver’s licenses and verifiable digital credentials under the Customer Identification Program Rule.
In Plain English: The Clinical Takeaway
- Digital Identity Verification: State-issued mobile driver’s licenses (mDLs) and verifiable digital credentials (VDCs) may be used by financial institutions to verify natural person customers under the Customer Identification Program (CIP) Rule.
- Regulatory Continuity: The joint guidance released by federal agencies does not alter existing legal or regulatory requirements or establish new supervisory expectations for institutions supervised by the Federal Reserve.
- Cross-Agency Alignment: The updated frequently asked questions harmonize terminology across the Financial Crimes Enforcement Network, the Federal Deposit Insurance Corporation, the National Credit Union Administration, and the Office of the Comptroller of the Currency.
Regulatory Scope and Interagency Oversight Framework
The U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN), working jointly with staff from the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA), and the Office of the Comptroller of the Currency (OCC), issued coordinated answers to two new Frequently Asked Questions and updated one existing FAQ. According to the Federal Reserve’s SR 26-6 guidance letter issued by Director Randall D. Guynn of the Division of Supervision and Regulation, these updates address the practical application of verifiable digital credentials.
Financial institutions supervised by the Federal Reserve and subject to the Bank Secrecy Act (BSA) must navigate identity verification protocols with precision. The newly released material clarifies how state-issued mobile driver’s licenses (mDLs) operate within established Customer Identification Program (CIP) rules. Crucially, according to the federal guidance, these answers do not alter current legal or regulatory obligations or impose novel supervisory expectations on regulated entities.
Updating Historical Guidance for Modern Credentialing Systems
The regulatory updates also formally amend a previously issued FAQ found in the attachment to SR letter 05-9, titled “Frequently Asked Questions Relating to Customer Identification Program Rules.” By updating this document, the agencies ensure that terminology reflects updated terminology used to describe digital credentialing.
| Regulatory Body | Guidance Document / Reference | Primary Focus Area |
|---|---|---|
| FinCEN & Federal Agencies | Joint FAQs on Verifiable Digital Credentials | State-issued mobile driver’s licenses (mDLs) under the CIP Rule |
| Federal Reserve System | SR 26-6 (Amending SR 05-9) | Supervisory compliance for BSA-subject financial institutions |
Contraindications & When to Consult a Regulatory Expert
Future Trajectory of Digital Identity Standards
Reserve Banks have been instructed to distribute the SR 26-6 letter to all supervised domestic and foreign financial institutions subject to the BSA, ensuring examination staff and banking officers share a unified understanding of digital credential standards.
References
- Financial Crimes Enforcement Network (FinCEN). “FinCEN Issues Frequently Asked Questions Regarding Treatment of Verifiable Digital Credentials.” U.S. Department of the Treasury.
- Board of Governors of the Federal Reserve System. “SR 26-6: Frequently Asked Questions Regarding Treatment of Verifiable Digital Credentials Under the Customer Identification Program Rule.” Division of Supervision and Regulation.
- Board of Governors of the Federal Reserve System. “SR letter 05-9: Frequently Asked Questions Relating to Customer Identification Program Rules.” April 28, 2005.