4 min read

What the FinCEN VDC Ruling Means for State mDL Programs

Federal regulators have confirmed banks can accept mobile driver's licenses for customer identification. For the 22 states with mDL programs, this ruling creates a new adoption driver beyond TSA checkpoints.

What the FinCEN VDC Ruling Means for State mDL Programs

On September 8, 2026, FinCEN and four federal banking regulators jointly confirmed that government-issued verifiable digital credentials (VDCs), including mobile driver's licenses, qualify as documentary identification under the Customer Identification Program (CIP) rule. For the 22 states and territories that have launched mDL programs conforming to ISO/IEC 18013-5, this ruling creates something they have been waiting for: a concrete, regulated use case beyond TSA checkpoints.

State CIOs should pay attention. The financial services channel changes the adoption math for mobile driver's licenses, and it raises practical questions that states will need to answer.

A new use case with real institutional demand

Until now, the primary acceptance venue for mDLs has been airport security. TSA acceptance matters for visibility, but it serves a narrow population of frequent travelers and does not generate the kind of recurring, high-volume usage that drives broad adoption.

Banking is different. 31 CFR 1020.220 requires every bank to verify customer identity at account opening. That applies to every new checking account, savings account, and lending relationship, whether opened in a branch, online, or through a mobile app. The FinCEN FAQ confirms that banks may accept an mDL across all of these channels: in-person, remote, and digital.

For states, this means that every resident who holds an mDL now carries a credential that a bank can use for one of the most regulated identity transactions in American commerce. The volume of potential verifications dwarfs TSA checkpoint usage. And unlike TSA, which operates its own acceptance infrastructure, banks represent thousands of independent institutions that will each need to build or procure verification capabilities.

What the ruling does and does not do for states

The FAQ is permissive, not prescriptive. The joint agency guidance clarifies that the CIP rule "neither requires nor prohibits" relying on government-issued VDCs. Banks can accept mDLs; they are not required to. The ruling does not create a mandate for states to issue mDLs, nor does it impose new technical requirements on state programs.

What it does is remove regulatory ambiguity. Before this FAQ, a bank's compliance team could reasonably question whether a digital credential met the CIP rule's documentary evidence standard. That question is now answered. An unexpired, government-issued VDC that evidences nationality or residence and includes a photograph qualifies under the same provision that has long covered physical driver's licenses and passports.

For state CIOs, the practical effect is this: your mDL program now has a federally recognized use case in a heavily regulated industry. That changes conversations with governors, legislators, and budget offices about the return on investment for digital credential infrastructure.

The verification gap states need to understand

Regulatory permission does not equal operational readiness. As SpruceID's analysis of the ruling explains, most banks today cannot cryptographically verify a digital credential. They can scan a physical ID, but verifying an mDL requires different infrastructure: the ability to obtain the issuing DMV's public keys, validate the digital signature, confirm device binding, and check revocation status.

This matters for states because banks will need issuer public key infrastructure to verify credentials. States that make their public keys accessible through well-defined trust infrastructure will see faster bank adoption of their mDLs. States that treat key distribution as an afterthought will find that banks either refuse to accept their credentials or accept them without meaningful verification, which undermines the security value of the entire system.

The AAMVA Digital Trust Service provides one distribution mechanism for mDL issuer certificates, and states participating in that infrastructure are better positioned for financial services acceptance. But the broader point holds: issuing a credential is only half the job. States also need to support the verification ecosystem.

What states without mDL programs should consider

Roughly 41% of Americans live in a state with an active mDL program. That leaves a majority of states where residents cannot present a digital credential at account opening, even though the regulatory barrier has been removed.

For states evaluating whether to launch an mDL program, the FinCEN ruling changes the calculus. The business case no longer rests solely on traveler convenience or DMV modernization. It now includes participation in financial services identity verification, a use case with clear institutional demand, regulatory backing, and potential for high-volume adoption.

States considering new programs should also note the technical baseline. The FAQ references VDCs that are "digitally signed by the issuing source, cryptographically bound to a device, and protected by an activation factor." Meeting this definition requires ISO/IEC 18013-5 conformance, which is the standard that existing state mDL programs already follow. Starting with this standard is not optional if a state wants its credential recognized under the ruling.

Three things state CIOs should do now

First, assess your public key distribution infrastructure. If banks cannot reliably obtain your DMV's issuer certificates, they cannot verify your mDLs. Work with your mDL vendor and trust service providers to confirm that your verification infrastructure is accessible to financial institutions.

Second, engage your state's banking regulators and financial services industry. The federal ruling is permissive, but bank adoption will depend on practical guidance about how to integrate mDL verification into existing compliance workflows. State-level coordination between DMV programs and banking regulators can accelerate this.

Third, measure program health without creating surveillance infrastructure. The number of mDLs issued has always been an incomplete measure of program success. But tracking verification volume by channel would create exactly the kind of transaction monitoring that privacy-preserving credential architectures are designed to prevent. Better measures include bank readiness (how many institutions in the state can cryptographically verify an mDL), resident awareness surveys, and the breadth of acceptance points, none of which require the state to observe individual credential presentations.

The FinCEN ruling does not change what an mDL is. It changes what an mDL is for. States that recognize this shift and invest in the verification infrastructure to support it will see their digital credential programs move from convenience features to regulated-industry identity infrastructure.

Building digital services that scale take the right foundation.
Talk to our team

About SpruceID: SpruceID builds digital trust infrastructure for government. We help states and cities modernize identity, security, and service delivery — from digital wallets and SSO to fraud prevention and workflow optimization. Our standards-based technology and public-sector expertise ensure every project advances a more secure, interoperable, and citizen-centric digital future.