• News

Banks can now accept a mobile driver's license. Here's what actually changed.

ㅣ

Kelly Soudan

The rule changed on September 8

On September 8, 2026, five federal agencies confirmed that banks and credit unions can use a mobile driver's license, or mDL, to verify a new customer, settling a question compliance teams have been sitting on for years.

Five agencies, one document, no new law

FinCEN wrote the guidance. Staff from the Federal Reserve, the FDIC, the NCUA, and the OCC signed on with it. When five bank regulators land on the same page, that's about as close to consensus as this industry gets.

It didn't arrive as a new rule. It arrived as two new FAQs, plus one existing CIP FAQ updated alongside them. Quiet, but it counts.

What it actually says

This guidance doesn't create a new legal category, lower any bar, or require a single bank to accept a digital ID. FinCEN was explicit that the FAQs don't change Bank Secrecy Act requirements or set new supervisory expectations.

What it does is remove the ambiguity. Banks had been treating mobile IDs as a gray area, something you could maybe accept if you read the rules generously. That gray area is gone. A state-issued mDL now reads as "government-issued identification" under the same rule that already covers a physical license.

The rule doing the work is the Customer Identification Program, CIP for short. It comes from the Bank Secrecy Act, and it tells a bank how to check a new customer's identity: a government photo ID, matched against the name, address, and date of birth the customer provided. Until now, that checklist assumed a laminated card. Now it explicitly covers a digital credential too, government issued or third party, as long as it carries a photo (or comparable safeguard) and proof of nationality or residence. One condition applies: if a third party issues it, the bank still owns the responsibility for verifying it to the same standard.

How this actually works, mechanically

An mDL isn't a photo of a card. FinCEN describes it as a verifiable digital credential, and to count, it has to be three things: digitally signed by the issuer, cryptographically bound to a specific device, and protected by an activation factor like a PIN or fingerprint. In practice, that means it can't simply be copied from one phone to another.

Most US mDLs are built to ISO/IEC 18013-5, the standard for phone-to-reader verification at short range. It's the same standard TSA already reads at the airport when a traveler taps a phone instead of handing over a card. That standard was built for in-person use. Bank onboarding is often remote, which is where a newer companion standard, ISO/IEC 18013-7, comes in. Published in 2024, it extends the same credential over the internet for account opening that happens entirely online. FinCEN's guidance covers both, and a compliant flow needs to handle the customer at the branch counter as well as the customer opening an app from their couch.

Done well, a bank isn't asking someone to photograph a license and hope it's legible. It's requesting a cryptographic response, checking the signature against the issuing state's public key, and confirming the credential hasn't been revoked, all in one exchange. A photocopy can be forged. A valid cryptographic signature can't.

The gap this creates

Twenty US states and territories now operate a live mDL program built to that standard, according to mDL Connection's implementation tracker, maintained by the Secure Technology Alliance. That number keeps climbing.

Which creates a real integration gap. Most banks' identity verification stacks were built around scanning a physical card. Reading a cryptographically signed credential off a phone is a different technical task, and most legacy document-scanning tools were never built to do it. That gap tends to surface at the exact moment a customer is trying to open an account, not later in a support queue.

Where Hopae fits

This is the gap Hopae Connect is built to close.

  • Coverage today: ISO/IEC 18013-5 mobile driver's licenses issued by a dozen states and territories, including California, Arizona, Colorado, and Georgia.

  • Wallets supported: Samsung Wallet, Google Wallet, and Apple Wallet implementations.

  • Also included: Google's ID Pass.

A bank that integrates Hopae Connect for CIP verification isn't standing up a separate mDL project. It's turning on one more credential type inside the identity verification API it already has.

What this means for you

The FinCEN guidance removes the excuse for waiting. The customer's phone has held a verifiable equivalent for years, that part was never really in question. What's left is the technical question, and Hopae Connect already has an answer, live today across a dozen states and growing.

Ready to get started?

Talk to an identity expert. Accept global eIDs or build your own digital wallet with Hopae.

Talk to an identity expert.
Accept global eIDs or build your own
digital wallet with Hopae.

Ready to
get started?

Talk to an identity expert.
Accept global eIDs or build your own
digital wallet with Hopae.