Language

08 Oct 2026 in News

What Should You Actually Verify When a Customer Presents a Mobile Driver’s License?

Evgeny Kvilinkov

Head of Compliance and RegTech Solutions

Andrey Terekhin

Head of Product

Henry Patishman

Executive VP, Identity Verification Solutions

A mobile driver’s license (mDL) can now help a customer open a bank account in the US. Until recently, it was unclear whether a digital credential could serve the same documentary role as a physical ID. 

In September 2026, the Financial Crimes Enforcement Network (FinCEN), together with federal banking regulators, clarified that state-issued mDLs and other government-issued verifiable digital credentials can be used to verify a customer’s identity under Customer Identification Program (CIP) rules. The clarification removes an important source of regulatory uncertainty around the use of digital credentials for documentary identity verification. 

Accepting an mDL, however, involves more than replacing a plastic card with a digital one.

Physical documents have security features that can be inspected visually or with special equipment, from holograms to ghost images. Digital credentials work differently. Trust comes from digital signatures, trusted issuers, cryptographic protections, devices, activation factors and, increasingly, biometrics.

So what exactly does an organization need to verify before it can trust the identity presented through an mDL?

How an mDL fits into risk-based identity verification

For US banks, the underlying standard has not changed.

A Customer Identification Program uses risk-based checks to give an institution reasonable confidence that it knows who the customer really is. There is no universal federal formula that makes one document, one database match, a selfie, or any other individual check sufficient on its own.

In many US onboarding flows, banks do not start with a physical document at all. They may first collect the customer’s name, date of birth, Social Security number, address, phone number, and email, then compare that information with independent sources.

If those checks provide enough assurance, onboarding can proceed without an identity document. If something does not match or the risk is higher, the bank can step up verification and request an identity document and biometrics.

An mDL is another strong source of identity evidence within this risk-based model. How much weight it carries depends on the customer, the onboarding channel, and the risk involved.

When a bank accepts an mDL as documentary verification, it needs to establish that the credential is government-issued and unexpired, contains the required identity information and a photograph or similar biometric safeguard, and can be read and verified by its systems.

quote

Think of it this way: given this customer’s risk and onboarding channel, have we collected and independently verified enough reliable information to reasonably believe that we know who is opening the account? An mDL can provide strong evidence, but it does not create a single possible verification workflow. The bank still has to decide whether that evidence is sufficient for this customer and this particular risk scenario.

Evgeny Kvilinkov Head of Compliance and RegTech Solutions

A digital credential changes how authenticity is established

Moving identity documents onto phones solves some familiar problems.

Physical IDs need to be captured and converted into digital data before they can be used online. Many of their security features were designed for in-person inspection rather than remote verification.

An mDL starts as digital data. It can be exchanged and verified digitally, without first converting information from a physical document.

But the basic questions behind verification remain the same.

quote

Whether the document is physical or digital, you still have to answer two things: why should I trust this credential, and why should I believe it belongs to the person presenting it? Digital credentials do not remove that trust chain; they change the evidence used to establish it. Instead of inspecting physical security features, you need to establish who issued the credential, whether that issuer is trusted, and whether the credential has retained its integrity.

Andrey Terekhin Head of Product

With a physical identity document, trust ultimately leads back to the issuing authority. Security features help show that the document came from that authority and has not been altered.

An mDL relies on digital evidence for the same purpose. A verifiable digital credential is digitally signed by its issuer, cryptographically bound to a device, and protected by an activation factor such as a PIN, password, face, or fingerprint. The verifier checks this digital and cryptographic evidence instead of holograms, printing techniques, and other physical security features.

The issuer is an important part of that check. Open standards make it possible to create digital credentials. A valid cryptographic signature can show that a credential has not changed since it was signed. The verifier still needs to know whether the organization that signed it is a trusted issuer.

Verification therefore covers both the source and the credential itself: who issued it, whether that issuer is trusted, whether the credential is valid, and whether its integrity has been preserved.

A genuine credential does not automatically prove a genuine holder

There is another problem that digitization does not remove: possession of a credential is not proof of identity. Activation factors help protect an mDL from unauthorized use. PINs and passwords, however, can be shared, stolen, or obtained through social engineering. 

Remote verification therefore needs a reliable way to establish that the person presenting the mDL is its legitimate holder. Biometrics can provide that link by comparing the person presenting the credential with trusted biometric data associated with the identity.

But this introduces another verification weak point. The biometric data captured during the interaction must itself be trustworthy. In remote onboarding, that means protecting the capture process against presentation attacks, injections, deepfakes, and other attempts to substitute or manipulate biometric input.

Digital credentials will not make the rest of identity verification disappear

It is tempting to see mDLs as the eventual replacement for physical document verification. But organizations are likely to operate in a mixed environment for some time.

Some customers will present physical documents. Others will use government-issued digital credentials. Different jurisdictions, wallets, issuers, and credential formats will coexist. And higher-risk situations may still require additional evidence even when the credential itself is valid.

quote

Government-issued does not mean risk-free. An mDL can provide strong evidence that a digital credential is authentic, but that is only one part of an identity decision. Organizations still need to establish who is actually in control of the identity and assess the risk of the interaction. This is why the future of identity verification is hybrid: digital credentials, physical documents, biometrics, and contextual risk signals need to work together to provide sufficient assurance for each identity decision.

Henry Patishman Executive Vice President of Identity Verification Solutions

The bottom line

When a customer presents an mDL, there are several things to verify:

  • The issuer: Is the credential from an authority the organization trusts?

  • The credential: Is it valid, unexpired, authentic, and unchanged?

  • The holder: Is the person presenting the credential the person it belongs to?

  • The level of assurance: Is the available evidence sufficient for this customer, channel, and level of risk?

That is the real shift behind FinCEN’s clarification. Digital credentials can make document authenticity easier to prove, but they do not remove the need for holder verification, contextual risk assessment, or step-up checks when something does not add up. In the end, a trustworthy identity decision requires the full picture.

 

On our website, we use cookies to collect technical information. In particular, we process the IP address of your location to personalize the content of the site

Cookie Policy rules