Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Mobile driver's licenses in KYC: what changes for bank onboarding?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20605
Topic starter  

TL;DR: FinCEN and four federal banking agencies now treat unexpired mobile driver’s licences as government-issued ID for KYC, provided institutions can extract credential data and have the method written into CIP, according to Incode. The shift reduces onboarding friction, but the real governance question is how banks operationalise cryptographic verification without weakening existing identity controls.

NHIMG editorial — based on content published by Incode: FinCEN confirms mobile driver's licenses are valid ID for KYC

Questions worth separating out

Q: How should banks govern mobile driver's licence acceptance in KYC flows?

A: Banks should treat mDL acceptance as a governed identity-verification method, not a product feature.

Q: Why do digital identity credentials change KYC assurance requirements?

A: Digital credentials change assurance because they can be validated cryptographically rather than inferred from a document image.

Q: What breaks when mobile IDs are added without policy and extraction controls?

A: Without policy and extraction controls, institutions end up with a wallet flow that looks compliant but cannot prove what was accepted, how it was verified, or whether the credential type was allowed.

Practitioner guidance

  • Update CIP policy for digital credentials Add explicit approval language for government-issued mDLs, define which credential types are acceptable, and record any conditions for online and in-person account opening.
  • Verify cryptographic field extraction end to end Test that your onboarding stack can extract signed credential data server-side, validate issuer signatures, and preserve freshness and device-binding evidence.
  • Separate government and third-party trust paths Create distinct control logic for state-issued mDLs and reusable IDs from private issuers so examination evidence maps cleanly to the right assurance model.

What's in the full article

Incode's full blog covers the operational detail this post intentionally leaves for the source:

  • How the platform verifies issuer signature, device binding, and credential freshness in the same onboarding flow.
  • The specific configuration path for accepting mDLs alongside physical IDs without building a second integration.
  • Practical notes on how wallet presentation maps to ISO/IEC 18013-5 and 18013-7 credential handling.
  • Why institutions can treat acceptance as a configuration change rather than a separate verification programme.

👉 Read Incode's analysis of FinCEN's mobile driver's licence guidance for KYC →

Mobile driver's licenses in KYC: what changes for bank onboarding?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 20196
 

Digital identity verification is becoming a governance control, not just a UX feature. FinCEN’s guidance shows that mobile driver’s licences are now part of regulated onboarding decisions, which shifts the conversation from convenience to assurance. Institutions that treat mDL support as a front-end enhancement will miss the policy, evidence, and issuer-trust requirements that make the channel defensible. The practitioner conclusion is clear: digital identity acceptance now belongs in identity governance.

A question worth separating out:

Q: What is the difference between government-issued mDLs and third-party reusable IDs?

A: Government-issued mDLs enter as documentary identification and rely on the state’s prior identity-proofing event. Third-party reusable IDs follow a non-documentary path, so the institution must assess the issuer’s authentication assurance and decide whether that method fits its written CIP and risk appetite.

👉 Read our full editorial: FinCEN mDL guidance raises the bar for digital KYC verification



   
ReplyQuote
Share: