A quiet change in U.S. banking guidance could become important infrastructure for agentic finance. On 8 September, FinCEN and staff from the Federal Reserve, FDIC, NCUA and OCC published new FAQs explaining how verifiable digital credentials can be used under Customer Identification Program rules.
The guidance covers government-issued credentials such as mobile driver’s licences and also allows electronic credentials to be used as non-documentary verification methods where a bank’s CIP supports them. Responsibility does not disappear: the financial institution still has to establish a reasonable belief that it knows the customer’s true identity and, where a third party issues the credential, satisfy itself about the authentication assurance involved.
Proof has moved quickly into that opening. Its new reusable Verifiable Digital Credential is issued after identity proofing through a Kantara-certified IAL2 service and chains to Proof’s WebTrust-audited certificate authority. It is designed to let a person reuse cryptographic evidence of identity without repeatedly distributing copies of passports or licences.
Separately, Proof is positioning its x401 protocol around agent authority: a service can request evidence of who is behind an agent and what that person authorised. That is Proof’s product and protocol direction, not a requirement or endorsement contained in the FinCEN guidance.
The distinction could become fundamental in financial services. A bank may increasingly need to verify three things independently: the human, the software agent and the mandate joining them.
