Platform
Platform
Drop-In Authentication
Passkeys
Phishing-resistant, FIDO2/WebAuthn
Biometric authentication
Face and device-native biometrics
WhatsApp OTP
Global reach, lower cost than SMS
Email OTP
Universal second factor
App push authentication
Native device push notifications
Palm biometrics
Contactless identity verification
KEY FEATURES
No-code rules engine
Step-up auth, risk policies, alerts
User observability
Audit trails, dynamic linking
Risk-based authentication
Adaptive MFA by context
Session management
Persistent sessions across channels
Digital Credential Verification
Accept and verify digital IDs
Pre-built UI
Fastest deployment path
Digital Credentials Verification
Accept and verify digital IDs
Solutions
Solutions
USE CASE
Account takeover prevention
Stop ATO without adding friction
Go passwordless
Replace passwords with passkeys
Call center authentication
Verify callers without KBA
SMS cost optimization
Cut OTP costs up to 90%
Existing apps
Add auth without re-architecting
Palm biometric payments
Contactless in-store payments
INDUSTRY
Financial services & banking
Secure high-value transactions
Healthcare
Authentication for ePHI access
Marketplaces & loyalty programs
Protect points and member accounts
Telecommunications
Secure subscriber accounts and channels
Government & public sector
Citizen identity and digital credentials
ROLE
Engineering
Fast integration, flexible SDKs
PricingCustomers
Resources
Resources
LEARN
Blog
Guides
Docs
COMPANY
About us
Why Authsignal
Partners
Careers
Security
Contact
INTEGRATIONS
Amazon Cognito
Auth0
Azure AD B2C
Duende IdentityServer
Keycloak
Salesforce
ServiceNow
WSO2 Identity Platform
View all integrations
Docs
Start free trial
Book a demoLogin
AUS Flag

Authsignal secures millions of passkey transactions out of our hosted Sydney region.

AUS Flag

Authsignal secures millions of passkey transactions out of our hosted Sydney region.

Join us today!
Right icon
Blog
/
Current article
Digital IDs
Identity Verification
Financial services

Mobile driver’s licenses for KYC: what new US guidance means for financial institutions

Paul Bickley
⬤
September 14, 2026
Share
Financial Services

Mobile driver’s licenses are moving closer to practical use in financial services, giving institutions a new way to verify government-issued identity information digitally. But adoption has depended on more than technical capability. Financial institutions have also needed greater certainty around how mDLs would be treated under existing KYC and Customer Identification Program (CIP) requirements.

That became much clearer on September 8, when the Federal Reserve, FDIC, NCUA, OCC and FinCEN issued joint guidance on how government-issued verifiable digital credentials, including state-issued mobile driver’s licenses (mDLs), can be used under the Customer Identification Program (CIP) Rule.

While the guidance focuses on customer identification, its significance reaches further. For financial institutions, including banks and credit unions, mDLs and other digital credentials could become a trusted verification method across the customer lifecycle, rather than being confined to a single onboarding flow. As adoption develops, that creates an omnichannel opportunity spanning digital journeys, re-verification, branch visits and contact center interactions.

What the new CIP guidance changes for mDL adoption

The agencies confirm that an unexpired government-issued VDC such as a state-issued mDL can qualify as government-issued identification under the CIP Rule where it meets the existing requirements, including evidencing nationality or residence and bearing a photograph or similar safeguard.

Financial institutions still need the appropriate technology and procedures to extract the relevant information, account for indications of fraud and incorporate the method into their CIP. The guidance does not change existing BSA requirements or create new supervisory expectations.

Its importance is the clarity it provides. Rather than creating a separate framework for digital credentials, the agencies have explained how they can fit within requirements financial institutions already operate under.

Why the new mDL guidance matters for financial institutions

NIST identified regulatory uncertainty as a genuine adoption challenge in its March 2026 Initial Public Draft practice guide. One of the most common concerns raised by financial institution collaborators was whether regulators would allow mDLs to be used.

For a regulated institution, that uncertainty can make it difficult to move a technically viable approach from pilot to production.

The new FAQs address a significant part of that concern. Alongside NIST’s technical reference architecture, financial institutions now have a stronger foundation for evaluating how mDL verification could fit into their existing systems and customer journeys.

”For financial institutions, this makes digital credentials something they can use today, not just plan for tomorrow. There’s a real opportunity to make secure identity verification cheaper and easier at a time when fraud is increasingly becoming more sophisticated.”- Caleb Ion, Digital Credential Engineer, Authsignal

Mobile driver’s licenses can support verification after onboarding

NIST’s reference architecture uses an mDL during account opening, provisions a passkey for ongoing authentication, and then brings the mDL back as an additional security signal when a customer initiates a high-risk transaction. It also notes that financial institutions may consider mDLs as part of account recovery.

This points to a broader role for digital credentials. An mDL does not need to become the method customers use every day. NIST specifically cautions against routinely presenting identity credentials for day-to-day authentication and points to technologies such as passkeys instead.

A stronger model is to make digital credential verification available when greater assurance is needed, while using the most appropriate authentication method for routine access.
‍


Omnichannel mDL verification is the bigger opportunity

Customers of banks, credit unions and other financial institutions move between websites, apps, branches and contact centers, and their verification requirements change with the interaction. A customer opening an account has different needs from someone completing a higher-risk action, updating information or needing to re-establish trust later in the relationship.

Omnichannel verification does not mean using the same method everywhere. It means making trusted verification methods available across those journeys and applying them according to context, policy and risk.

That creates a wider opportunity than simply adding mDLs to an onboarding flow. Digital credentials could support initial identity verification, return when stronger assurance is needed, and become available across more of the channels where customers and members already interact with their financial institution.

This is a model we already support: passkeys for routine access, digital credential verification when greater assurance is needed, orchestrated across web, mobile, contact center and branch from a single rules engine. It gives financial institutions a practical way to introduce mDL verification into existing journeys without creating a separate authentication and verification experience for every channel.

NIST still identifies evolving trust models, standards maturity and fragmented presentation protocols as challenges to scaled mDL adoption. The new guidance gives financial institutions greater clarity, while interoperability and orchestration remain important to making digital credentials work consistently across the customer lifecycle.

The opportunity is not simply to add mDLs to account opening. It is to make trusted digital credentials a practical part of verification across the wider customer relationship.

If you are considering what the new guidance could mean for your financial institution, talk to one of our experts about how Authsignal can help you introduce digital credential verification across web, mobile, contact center and branch.

Question icon
Have a question?
Book a demo
NewsletterDemo PasskeysView docs
Digital IDs
Identity Verification
Financial services

You might also like

Digital payment credentials: how verifiable trust could reshape payments
Digital Credentials
AI agents

Digital payment credentials: how verifiable trust could reshape payments

September 9, 2026
Digital identity credentials and passkeys: what businesses need to prepare for next
Digital IDs
Passkeys

Digital identity credentials and passkeys: what businesses need to prepare for next

August 28, 2026
Digital identity credentials are going global. Authsignal makes them drop-in.
Digital IDs

Digital identity credentials are going global. Authsignal makes them drop-in.

August 8, 2026

Secure your customers’ accounts today with Authsignal

Passkey demoCreate free account
Authsignal Purple Logo

Authsignal is a drop-in authentication and orchestration layer for consumer-facing businesses. Passkeys, adaptive MFA, and omnichannel verification on top of your existing identity stack. Deployed in weeks, not quarters.

AICPA SOCFido Certified
LinkedInTwitter
Platform
Drop-In Authentication
PasskeysBiometric authenticationWhatsApp OTPEmail OTPApp push authenticationPalm biometricsSMS OTPEmail OTPMagic LinksAuthenticator apps (TOTP)
View all auth methods
KEY FEATURES
No-code rules engineUser observabilityRisk-based authenticationSession managementDigital Credential VerificationPre-built UI
Pricing
Customers
Solutions
USE CASE
Account takeovers (ATO)
Go passwordless
Call center
SMS cost optimization
Existing apps
Palm biometric payments
industry
Financial services
Government & Public Sector
Healthcare
Loyalty Programs & Marketplaces
Telecommunications
ROLE
Engineering
Docs
Compare
Twilio Verify vs AuthsignalAuth0 vs AuthsignalAWS Cognito vs Authsignal + AWS Cognito
Resources
LEARN
BlogGuidesDocs
COMPANY
About usWhy AuthsignalPartnersCareersSecurityContact
Integrations
Amazon Cognito
Auth0
Azure AD B2C
Duende IdentityServer
Keycloak
Salesforce
ServiceNow
WSO2 Identity Platform
View all integrations
United States
+1 214 974-4877
Australia
+61 387 715 810
New Zealand
+64 275 491 983
© 2026 Authsignal - All Rights Reserved
Terms of servicePrivacy policySecuritySystem statusCookies