Five agencies say banks may accept mobile driver’s licenses

  • Expert quote: A signed credential “is bound to a device and protected by an activation factor, so it can’t be screenshotted and resold the way a license image can,” said David Maimon of SentiLink.
  • Supporting data: Depository institutions filed about 1.3 million reports of suspicious activity tied to identity in 2021, or 54% of all such filings, flagging $201 billion.
  • Forward look: Banks weighing a purchase should ask a supplier how it proves the issuer, the device interaction and the freshness of each transaction, rather than whether the product reads mobile IDs at all.

Overview bullets generated by AI with editorial review.

Processing Content

Federal regulators cleared banks and credit unions to accept a driver’s license that lives on a customer’s phone, as long as the institution can prove it is reading a real one.

The Financial Crimes Enforcement Network, or FinCEN, published two new frequently asked questions last week, jointly with the Federal Reserve, the Federal Deposit Insurance Corp., the National Credit Union Administration and the Office of the Comptroller of the Currency.

An unexpired mobile driver’s license, or mDL, issued by a state would count as a government-issued identification for confirming a customer’s identity when they open an account, the agencies wrote. That confirmation is the know-your-customer requirement at the center of the rule.

A bank may accept an mDL if it “maintains the appropriate technology or systems to extract the relevant information” and its own customer identification program allows it, according to the FAQ document.

The new FAQs do not contain a mandate or deadline. The customer identification rule, known in the industry as the CIP rule, “neither requires nor prohibits” accepting mDLs, the agencies wrote.

FinCEN and the NCUA did not respond to requests for comment.

Reading an mDL is less like examining a plastic card than like “tapping a card from a mobile wallet, although the bank is verifying state-issued identity data rather than authorizing a payment,” Tim Rawlins, director of security at NCC Group, a cybersecurity consultancy, told American Banker.

Every U.S. financial institution opens accounts under the CIP rule, and identity trouble accounts for a large share of what banks report to the government.

Depository institutions filed about 1.3 million reports of suspicious activity tied to identity in 2021, or 54% of all such filings, flagging $201 billion, according to a FinCEN analysis.

‘No, I can’t accept a screenshot’

A verifiable digital credential is a data structure “digitally signed by the issuing source of the information,” “cryptographically bound to a device” and “protected by an activation factor,” according to the FAQ document.

That last factor is a PIN, a password or a biometric such as a face or fingerprint, according to the document.

For example, on an iPhone, that means pulling up the mDL in the Wallet app, holding the phone near the reader, and releasing the data by double-tapping the side button and using Face ID, according to Apple’s instructions.

A signed credential “is bound to a device and protected by an activation factor, so it can’t be screenshotted and resold the way a license image can,” David Maimon, head of fraud insights at the fraud-prevention vendor SentiLink, told American Banker.

Still, a bank has to check the credential properly for everything to work as expected.

“If they just look at a screenshot and it passes, then anyone can use it,” Rawlins said. “There has to be a check that it isn’t just a photo.”

That means checking the mDL against the issuing state’s public key, a published value that lets anyone confirm the state really signed the credential. But, there is no single, standard way to do that for all mDLs.

One credential, many wallets, no standard

Where a customer keeps a mobile license depends on the state that issued it. Some states put it in Apple Wallet or Google Wallet, and the two services cover different lists of states. Others hand out an app of their own.

Not every state even calls the thing a mobile driver’s license. New York calls its version a mobile ID, and it lives in a state-run app that shows a QR code for someone to scan rather than tapping the phone to a reader.

California runs its own wallet app as well as supporting Apple and Google phone wallets.

A bank also needs the state’s public keys to check any of those credentials, and these keys are scattered the same way.

The American Association of Motor Vehicle Administrators, or AAMVA, hands out states’ public keys on its website, free of charge. The file is available publicly for anyone to download.

Mobile licenses come from 22 states and Puerto Rico, but the AAMVA’s list does not cover all of them. It holds keys for 14 states, including New York, Maryland, Georgia, Arizona and Utah, according to the association’s implementation map.

An institution that wants to accept mDLs needs a patchwork solution — a way of accepting a QR code or tap-to-ID, a way of checking the ID against the state’s public key, and marketing and communications that walk customers through whatever process their state requires.

The federal government is aware of the patchwork mDLs create and is looking to solve it.

In March, the National Institute of Standards and Technology, or NIST, wrote a draft publication on mobile licenses for financial institutions. Settling the standards is “particularly urgent” for the protocols that govern how a credential gets presented, the agency said at the time.

NIST’s ongoing standardization project has participation from a number of companies and state governments, including seven banks: Capital One, JPMorganChase, PNC Bank, Raymond James, Synchrony, U.S. Bank and Wells Fargo.

Navy Federal Credit Union is the only credit union taking part.

What’s actually for sale, and to whom

One company that sells license scanning to banks and credit unions, IDScan.net, was traced this month to a dark web license sale in which a service claimed to offer more than 153 million U.S. and Canadian driver’s licenses before it went offline.

While that breach affected traditional licenses, the New Orleans company also sells verification of mobile driver’s licenses (which were not breached) through an iPhone app or a paired reader.

However, it only supports in-person verification of mDLs — nothing over the internet.

“While businesses may not yet be able to verify mDLs and e-passports digitally for online transactions, these tools can help with in-person checks until the standards for digital verification are finalized and adopted,” the company wrote in a March post on its website.

The agencies’ guidance last week covers account opening “in-person, remotely over the Internet, or through some other digital or virtual channel.” The remote channel it reaches is the one IDScan says it cannot yet verify.

Remote acceptance does exist in a narrow form. Persona, an identity verification company, verifies California mobile licenses presented remotely through that state’s wallet app and lists onboarding at financial institutions among the uses, according to a May post on the company’s website.

The closest thing to a working example in American banking predates the guidance by four years and runs in branches. America First Credit Union began accepting Utah mobile licenses at its 100 Utah and Arizona branches in August 2022.

A spokesperson for the credit union did not respond to a request for comment about the mDL guidance issued last week.

American Banker also asked core providers (the companies that build the core systems on which banks and credit unions run their accounts) whether they are building the capability.

Jack Henry and Fiserv did not respond to requests for comment. A spokesperson for FIS did not answer American Banker’s questions.

For any community or regional bank looking to buy (rather than build) support for mDLs, Rawlins said the key questions to ask a vendor are:

  1. How does the vendor know an mDL actually came from the state that issued it?
  2. How does the vendor check that the credential is the one bound to the customer’s own phone, rather than a copy?
  3. How does the vendor know the exchange is happening in real time, rather than a replay of an earlier one?

“Smaller institutions can buy the capability, but they cannot outsource judgement or accountability,” Rawlins said.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *