Mobile driver’s licenses are moving closer to practical use in financial services, giving institutions a new way to verify government-issued identity information digitally. But adoption has depended on more than technical capability. Financial institutions have also needed greater certainty around how mDLs would be treated under existing KYC and Customer Identification Program (CIP) requirements.
That became much clearer on September 8, when the Federal Reserve, FDIC, NCUA, OCC and FinCEN issued joint guidance on how government-issued verifiable digital credentials, including state-issued mobile driver’s licenses (mDLs), can be used under the Customer Identification Program (CIP) Rule.
While the guidance focuses on customer identification, its significance reaches further. For financial institutions, including banks and credit unions, mDLs and other digital credentials could become a trusted verification method across the customer lifecycle, rather than being confined to a single onboarding flow. As adoption develops, that creates an omnichannel opportunity spanning digital journeys, re-verification, branch visits and contact center interactions.
What the new CIP guidance changes for mDL adoption
The agencies confirm that an unexpired government-issued VDC such as a state-issued mDL can qualify as government-issued identification under the CIP Rule where it meets the existing requirements, including evidencing nationality or residence and bearing a photograph or similar safeguard.
Financial institutions still need the appropriate technology and procedures to extract the relevant information, account for indications of fraud and incorporate the method into their CIP. The guidance does not change existing BSA requirements or create new supervisory expectations.
Its importance is the clarity it provides. Rather than creating a separate framework for digital credentials, the agencies have explained how they can fit within requirements financial institutions already operate under.
Why the new mDL guidance matters for financial institutions
NIST identified regulatory uncertainty as a genuine adoption challenge in its March 2026 Initial Public Draft practice guide. One of the most common concerns raised by financial institution collaborators was whether regulators would allow mDLs to be used.
For a regulated institution, that uncertainty can make it difficult to move a technically viable approach from pilot to production.
The new FAQs address a significant part of that concern. Alongside NIST’s technical reference architecture, financial institutions now have a stronger foundation for evaluating how mDL verification could fit into their existing systems and customer journeys.
”For financial institutions, this makes digital credentials something they can use today, not just plan for tomorrow. There’s a real opportunity to make secure identity verification cheaper and easier at a time when fraud is increasingly becoming more sophisticated.”- Caleb Ion, Digital Credential Engineer, Authsignal
Mobile driver’s licenses can support verification after onboarding
NIST’s reference architecture uses an mDL during account opening, provisions a passkey for ongoing authentication, and then brings the mDL back as an additional security signal when a customer initiates a high-risk transaction. It also notes that financial institutions may consider mDLs as part of account recovery.
This points to a broader role for digital credentials. An mDL does not need to become the method customers use every day. NIST specifically cautions against routinely presenting identity credentials for day-to-day authentication and points to technologies such as passkeys instead.
A stronger model is to make digital credential verification available when greater assurance is needed, while using the most appropriate authentication method for routine access.

Omnichannel mDL verification is the bigger opportunity
Customers of banks, credit unions and other financial institutions move between websites, apps, branches and contact centers, and their verification requirements change with the interaction. A customer opening an account has different needs from someone completing a higher-risk action, updating information or needing to re-establish trust later in the relationship.
Omnichannel verification does not mean using the same method everywhere. It means making trusted verification methods available across those journeys and applying them according to context, policy and risk.
That creates a wider opportunity than simply adding mDLs to an onboarding flow. Digital credentials could support initial identity verification, return when stronger assurance is needed, and become available across more of the channels where customers and members already interact with their financial institution.
This is a model we already support: passkeys for routine access, digital credential verification when greater assurance is needed, orchestrated across web, mobile, contact center and branch from a single rules engine. It gives financial institutions a practical way to introduce mDL verification into existing journeys without creating a separate authentication and verification experience for every channel.
NIST still identifies evolving trust models, standards maturity and fragmented presentation protocols as challenges to scaled mDL adoption. The new guidance gives financial institutions greater clarity, while interoperability and orchestration remain important to making digital credentials work consistently across the customer lifecycle.
The opportunity is not simply to add mDLs to account opening. It is to make trusted digital credentials a practical part of verification across the wider customer relationship.
If you are considering what the new guidance could mean for your financial institution, talk to one of our experts about how Authsignal can help you introduce digital credential verification across web, mobile, contact center and branch.
.png)