Credit unions may use an unexpired state-issued mobile driver's license or another qualifying government-issued verifiable digital credential as documentary identification under the Customer Identification Program rule, federal regulators said in guidance issued September 8. The clarification removes one legal uncertainty around digital onboarding while leaving the credit union responsible for the same core outcome: a reasonable belief that it knows the member's true identity.

The FinCEN release announced two new frequently asked questions and one update issued jointly with staff from the Federal Reserve, FDIC, NCUA and OCC. The agencies define a verifiable digital credential as a data structure containing information about an individual that is digitally signed by the issuer, cryptographically bound to a device and protected by an activation factor such as a PIN, password or physical biometric.

The answers do not change Bank Secrecy Act requirements or create new supervisory expectations. They say the CIP rule neither requires nor prohibits reliance on government-issued digital credentials. That distinction matters: a credit union can add the method when its own CIP permits it and its systems can extract the relevant information, but the FAQ does not make acceptance mandatory.

A digital credential can be documentary identification

The NCUA version of the interagency FAQs says an unexpired government-issued credential can qualify as government-issued identification when it evidences nationality or residence and bears a photograph or similar safeguard. A state-issued mobile driver's license is the clearest example.

For onboarding teams, the operating question is not whether a picture of a license appears on a phone. It is whether the credit union can receive and validate the credential, extract the required information, connect the result to the account-opening record and preserve evidence of the verification method. The credential's digital signature, device binding and activation factor are part of the structure described by the agencies; a screenshot or manually displayed image does not by itself demonstrate those properties.

Credit unions considering the method should define which issuers and credential formats are accepted, which channels can process them and what happens when a device, reader or data exchange fails. The fallback path should not quietly weaken verification. Staff also need an exception route for expired credentials, missing attributes, incompatible devices and members who cannot or do not want to use a digital credential.

Fraud signals still require judgment

The agencies say a bank or credit union may generally rely on a government-issued credential, but indications of fraud must be considered in deciding whether it can form the required reasonable belief. That keeps fraud detection and human escalation inside the workflow. A valid cryptographic response should be recorded alongside—not substituted for—device, application and behavioral signals that the credit union already uses.

Non-government credentials create a separate control point. The updated FAQ says that when an electronic or verifiable digital credential is issued and maintained by a non-government third party, the institution remains responsible for ensuring that provider uses the same level of authentication the institution itself would use. Vendor due diligence therefore needs to cover issuance, revocation, authentication strength, evidence retention, outages and incident handling before a credential becomes an accepted verification method.

The implementation can be measured without treating speed as the only goal. Digital-banking, fraud and BSA leaders can track completion rates, manual-review referrals, false rejections, suspected-fraud rates, abandoned applications and time to resolve exceptions by credential type and onboarding channel. The recent digital account-opening case study shows why elapsed time and funded-account outcomes should be separated. The accessible member-service test plan offers a structure for testing alternative paths rather than making a new digital method the only usable route.

The immediate decision is bounded: credit unions can now evaluate qualifying digital credentials as a CIP method with clearer regulatory footing. Adoption should wait until the policy, technology, fraud escalation and evidence trail all describe the same verification process.

Follow the operating evidence. Subscribe to the CreditUnionAI Weekly Briefing for practical AI, identity and technology-governance coverage.

Get the Weekly Briefing