Today, FinCEN — jointly with the staffs of the Federal Reserve Board, the FDIC, the NCUA, and the OCC — released on how verifiable digital credentials fit under the Customer Identification Program Rule (the CIP Rule).
Solutions
The benchmark for digital credentials is the institution's own standard, according to guidance published by FinCEN in September 2026.

Today, FinCEN — jointly with the staffs of the Federal Reserve Board, the FDIC, the NCUA, and the OCC — released on how verifiable digital credentials fit under the Customer Identification Program Rule (the CIP Rule).
Learn more about SOLO's bank reliance network.
The primary takeaway is that digital identity credentials are squarely inside the CIP perimeter. The more consequential detail is how the agencies drew the line for credentials that don't come from a government issuer. Rather than enforce a uniform standard around what is or is not acceptable, the agency defined the standard as the bank's own: a bank or credit union relying on a credential from a non-government third party is responsible for ensuring that the third party "uses the same level of authentication as the bank or credit union itself would use."
This definition is exactly aligned with the standard of reasonableness that SOLO has applied to the CIP Reliance framework, another section of the CIP Rule that addresses an institution’s ability to rely on process work done by another institution.
FinCEN addressed three questions in their guidance:
The definition of VDC, in this context. The agencies define a verifiable digital credential (VDC) as a data structure containing information about an individual that is digitally signed by the issuing source, cryptographically bound to a device, and protected by an activation factor — something the user knows, like a PIN, or a unique attribute they possess, like a face or fingerprint.
Government-issued credentials get documentary treatment. A state-issued mobile driver's license (mDL) contains the same information as the physical license, and the agencies confirmed that an unexpired, government-issued VDC qualifies as a "government-issued identification" for purposes of the CIP Rule's documentary methods — provided it evidences nationality or residence and bears a photograph or similar safeguard, and provided the institution has the technology to extract the relevant information. The Rule neither requires nor prohibits accepting them. And as with a physical license, if the credential shows indications of fraud, the institution has to weigh that in deciding whether it can form a reasonable belief that it knows the customer's true identity.
Third-party credentials are an acceptable non-documentary method, with a condition. The agencies also updated a longstanding FAQ on electronic credentials. A bank or credit union may obtain an electronic credential or a VDC as one of the methods it uses to verify identity, to the extent its own CIP permits. But because the Rule still requires a reasonable belief as to true identity, where the credential is issued and maintained by a non-government third party, the institution is responsible for ensuring that the third party authenticates at the same level the institution itself would.
The agencies were explicit that none of this alters existing BSA legal or regulatory requirements or establishes new supervisory expectations. These FAQs clarify. They don't rewrite. But in this corner of the market, clarity is the binding constraint — the reason digital identity has moved slowly through bank compliance functions is not prohibition, it's ambiguity about what "reasonable" means when the credential is digital and the issuer isn't a DMV.
Today the agencies answered that question, and they answered it by pointing at the institution's own standard.
SOLO operates in a different section of the CIP Rule: reliance, which addresses an institution's ability to rely on identity process work performed by another institution. Today's identity verification within an institution's own CIP, however, they answer the same underlying question we had to answer — reasonable compared to what? — and they answer it the same way.
If Bank A, a member of the SOLO Network, wants to rely on a digital identity artifact produced by another member of the SOLO Network, SOLO will only return a match if we hold an artifact that meets or exceeds the standards Bank A has laid out in its own pre-existing CIP policies. Not an industry average. Not SOLO's opinion of what good looks like. Bank A's policies, as written. Learn about how SOLO enables this in our network with bank-defined querying policies.
The rationale here is simple. Banks and credit unions have already had their CIP policies reviewed by their prudential regulator's examiners. That review is the closest thing this industry has to a settled, institution-specific definition of adequate identity assurance — and it already exists, in writing, for every regulated institution in the country. The job of any new method for verifying digital identity is to meet or exceed that bar, not to substitute a new one for it.
We are pleased to see FinCEN and the Agencies land on the same benchmark as SOLO.
A standard-matching test is not a format test. The agencies did not ask whether identity arrived as physical document, as a scan, or as a cryptographic assertion. They asked whether the authentication behind it holds up to the institution's own requirements. That is what makes the framing durable: it will survive the next several generations of credential technology, because it isn't about the credential. It's about the assurance behind it and the institution's ability to evaluate that assurance.
Which, in turn, is why transparency within digital identity is a design requirement rather than a feature. An institution can only confirm that another party authenticates at its own level if it can see what that party actually did — the evidence collected, the policy applied, and the provenance of both.
In the words of Eric Woodward, former President of Early Warning Services and a SOLO Board Member:
“SOLO has operationalized something the industry has discussed for years: the ability to trust work completed by another institution without requiring every institution to operate under identical standards. By making the underlying evidence, policies, and provenance transparent, SOLO allows each bank to maintain its own risk appetite and regulatory responsibilities while eliminating unnecessary duplication. This fundamentally changes financial services from a series of disconnected applications into a continuous, accountable relationship.”
Today, a customer who has been fully verified by one institution starts over at the next one. The second institution isn't getting better assurance for that effort. It's redoing work it would have accepted, and paying for it in application time, cost, and abandoned applications.
Reliance is how that stops, and today's FAQs point in the same direction. The agencies told institutions they can accept a digital credential when the authentication behind it meets their own standard. The SOLO Network applies that same test to identity work performed by another institution: verified once, to your standard, with the evidence producible on audit, and available to you the next time.
That's the system we've built towards.
Read the full guidance release: FinCEN FAQs on Verifiable Digital Credentials Under the CIP Rule