All developments
OCCKYC / CDDSeptember 8, 2026

Regulators Clarify: Mobile Driver's Licenses & Digital IDs Can Satisfy KYC Rules

Five federal regulators — OCC, FinCEN, the Federal Reserve, FDIC, and NCUA — jointly issued FAQs confirming that state-issued mobile driver's licenses and other government-issued verifiable digital credentials (VDCs) can be used to satisfy Customer Identification Program (CIP) requirements under the Bank Secrecy Act. This is significant guidance for crypto and fintech firms because it provides regulatory clarity on accepting digital identity documents during onboarding, reducing reliance on physical ID checks. Compliance officers should review the FAQs carefully to understand the conditions and limitations under which VDCs qualify as acceptable identity verification methods.

What to do

  • Review the joint FAQ guidance and assess whether your CIP policies and onboarding technology can be updated to formally accommodate state-issued mobile driver's licenses and other verifiable digital credentials as compliant identity verification methods.

Who this affects

Crypto ExchangeCrypto CustodianWallet ProviderMoney Services BusinessPayments CompanyFintech / NeobankBank / Credit UnionTrust CompanyBroker-Dealer / RIA

Does this affect your program?

Pick your institution type for an instant read on whether you're in scope — then see exactly which sections of your own policies this changes.

Source

Read the official publication

This radar entry is educational and does not constitute legal advice. Summaries are AI-assisted and grounded in the linked official source; always verify against the primary source and consult qualified legal counsel for jurisdiction-specific guidance.

Related developments

OCC

OCC Updates Cybersecurity Examination Work Program for Banks

The OCC has revised its Cybersecurity Supervision Work Program (CSW), which examiners use to assess cybersecurity risk at national banks and federal savings associations, updating its structure and references to reflect the evolving threat landscape and adoption of standardized frameworks. For compliance and risk officers at banks, neobanks, and trust companies under OCC supervision, this signals updated examiner expectations around cybersecurity controls and preparedness. Crypto custodians and fintechs with bank charters or partnerships should also take note, as vendor and third-party cybersecurity risk is often assessed through this lens.

OCC

OCC Joins Interagency Proposed Third-Party Risk Management Guidance

The OCC is co-issuing the same interagency third-party risk management proposal alongside the Fed, FDIC, and NCUA, signaling a unified supervisory approach across the federal banking agencies. National banks and federal savings associations should treat this as a near-certain indicator of forthcoming binding expectations on vendor oversight. The proposal's emphasis on risk-proportionate controls is particularly relevant for institutions using crypto or fintech service providers.

OCC

OCC/Fed/FDIC Raise Asset Threshold for 18-Month Exam Cycle to $6 Billion

An interim final rule from the OCC, Federal Reserve, and FDIC raises the total asset threshold that allows certain well-managed, well-capitalized insured depository institutions and U.S. branches of foreign banks to qualify for an extended 18-month on-site examination cycle. Smaller banks and trust companies that fall below the new threshold may see reduced examination frequency, affecting the pace of supervisory feedback on compliance programs. Fintech-partnered banks and crypto-custody trust companies under the threshold should be aware that less frequent exams do not reduce compliance obligations.

OCC

Regulators Clarify How They Will Oversee Core Tech Providers to Community Banks

The OCC, Federal Reserve, and FDIC have issued an interagency statement explaining how they will apply risk-based supervision and enforcement to core service providers — such as technology and data processors — that serve community banking organizations. This matters for fintechs and crypto firms acting as technology vendors or service providers to banks, as it signals heightened regulatory scrutiny of the bank-vendor relationship and the factors examiners will weigh when taking supervisory or enforcement action against those providers.

Stay ahead of every rule change

PliOS monitors FinCEN, OCC, OFAC, the SEC and CFTC and tells you which of your policies each new rule affects — with the edit already drafted. Start free.

Run My Free Assessment