Verifiable credentials for financial compliance

Where verifiable credentials meet financial regulation

Financial institutions adopting verifiable credentials keep reaching the same question: do selective disclosure and cryptographic proofs satisfy what examiners expect? This page maps the rules that matter, AMLR, eIDAS 2.0, MiCA and the Travel Rule, the GENIUS Act, and GDPR, to how verifiable credentials meet each one. Every article number and date is cited, so your compliance and legal teams can check it against the source.

A reference, not legal advice. Citations point to the primary instruments. Last reviewed: [month year].

European Union · Anti-money laundering

AMLR: the EU’s single rulebook

Regulation (EU) 2024/1624 · applies from 10 July 2027 · EUR-Lex

The EU has replaced its patchwork of national AML transpositions with a single, directly applicable regulation, supervised by the new Anti-Money Laundering Authority (AMLA) in Frankfurt, operational since 1 July 2025 and issuing technical standards through 2026. AMLR raises the standard for how obliged entities identify and verify customers, and it is where verifiable credentials fit most directly.

Article 22(6) · Remote verification

Remote verification must rely on a government-issued identity document or on eIDAS electronic identification at the substantial or high assurance level. A credential issued from authenticated documents and biometrics at that assurance level carries a check performed to the standard the article asks for.

Risk-based due diligence · Less data, not more

AMLR moves to a risk-based model with less mandatory data collection. Selective disclosure lets an institution confirm only the attributes it needs for a given check, which is the direction the regulation favours.

Articles 48–49 · Reliance

An obliged entity may rely on customer due diligence performed by another. A reusable credential operationalises that reliance: it carries verifiable proof of the checks already done, and the records stay available to the relying institution and to supervisors. The relying institution keeps responsibility; the credential supports reliance without transferring accountability.

Ongoing monitoring · Revocation

A credential can be updated or revoked when a customer’s status changes, for example a new sanctions listing, which supports the ongoing monitoring and customer due diligence the regulation requires.

AMLA technical standards · CDD RTS

AMLA’s draft regulatory technical standards on customer due diligence support eIDAS electronic identification and forward-looking methods such as the EU Digital Identity Wallet for remote onboarding.

European Union · Digital identity

eIDAS 2.0 and the EU Digital Identity Wallet

Regulation (EU) 2024/1183 · amending Regulation (EU) No 910/2014 · EUR-Lex

eIDAS 2.0 establishes the EU Digital Identity Wallet. Every member state must offer at least one wallet, and relying parties, including financial institutions, must accept it for identity verification. Assurance is expressed as substantial or high, the same levels AMLR points to, so the two regulations line up on what a verified identity must clear.

Wallet acceptance · by December 2027

Financial institutions must accept the EU Digital Identity Wallet for identity verification by December 2027. High-assurance verification performed at the front of onboarding can feed directly into wallet-based flows rather than competing with them.

QEAA · Qualified attestations

Verified attributes can be carried as a Qualified Electronic Attestation of Attributes, a qualified trust service. Attestations can be structured to QEAA form, so a verified result can be presented in the way the framework recognises.

Assurance levels · substantial / high

Identity proofed to NIST IAL2 or IAL3 maps to the eIDAS levels of substantial and high. That mapping is what lets one verified identity satisfy both the EU framework and the assurance expectations examiners apply.

Coverage · beyond the government wallet

The solution complements the wallet rather than replacing it. It serves cases the government wallet will not itself cover: counterparty-to-counterparty verification between institutions, institutional KYC, and non-EU document coverage during the rollout, where national wallet readiness varies widely.

European Union · Crypto-assets

MiCA and the Travel Rule

Regulation (EU) 2023/1114 (MiCA) · Regulation (EU) 2023/1113 (Transfer of Funds) · both apply from 30 December 2024 · MiCA · TFR

MiCA created the EU regime for crypto-asset service providers, and the recast Transfer of Funds Regulation extended the travel rule to crypto-asset transfers. Together they set identity and traceability obligations that verifiable credentials meet without pooling raw personal data on a shared ledger.

MiCA · CASP obligations

MiCA brings crypto-asset service providers into the EU regulated perimeter, with customer due diligence obligations. Its authorisation regime has applied since 30 December 2024, and the grandfathering period for existing providers closed on 1 July 2026. A verifiable credential satisfies the customer identity checks a CASP must run, at the assurance levels AMLR and eIDAS set.

Transfer of Funds Regulation · the Travel Rule

Every crypto-asset transfer must be accompanied by verified information on the originator and the beneficiary, with no minimum-value threshold for CASPs. A credential carrying verified identity provides that information as cryptographic proof, so the required data can accompany a transfer without exposing the full personal record.

Selective disclosure · Verified data, not raw PII

Selective disclosure lets a provider present only the attributes a transfer requires. Compliance is proven while the underlying personal data stays under the institution’s own controls, off any shared ledger.

Self-hosted wallets · Proof of control

The regulation adds specific measures for transfers involving self-hosted addresses. A credential is cryptographically bound to its holder, and a wallet can inherit that binding through signed proof of control, which links a verified person to the address in question.

United States · Digital assets

The GENIUS Act and the Treasury position

GENIUS Act (2025) · Treasury Report to Congress, March 2026 · Read the report

The GENIUS Act is the first federal framework for payment stablecoins. It treats stablecoin issuers as financial institutions under the Bank Secrecy Act, which pulls them into customer identification and AML obligations. The Treasury report that followed named the technology by which those obligations can be met.

“Verifiable credentials offer a potential pathway to mitigate identity fraud and other sources of identity-related illicit finance risk.”

U.S. Department of the Treasury, Report to Congress, March 2026

Bank Secrecy Act · Stablecoin issuers

By treating stablecoin issuers as financial institutions, the Act extends full customer identification program and AML duties to them. A verifiable credential carries identity verified to the assurance a CIP requires, reusable across the venues an issuer touches.

Treasury · A named priority technology

Treasury’s March 2026 report describes verifiable credentials as a pathway for financial institutions to conduct customer identification and verification while minimizing the sensitive data collected. It signals guidance to follow on using them within existing customer identification programs.

Standards · NIST and interoperability

The report points to work with NIST on international standards and to enabling third-party providers to issue credentials accepted for customer identification. The direction is verified, portable identity built on common standards, which is exactly what this technology delivers.

European Union · Data protection

GDPR and the privacy architecture

Regulation (EU) 2016/679 · with European Data Protection Board guidance on blockchain · EUR-Lex

The other regulations require identity to be verified and traceable. GDPR governs what happens to the personal data behind that verification, and recent European Data Protection Board guidance on blockchain points to the exact architecture verifiable credentials already use: keep personal data off the ledger, and put only cryptographic proof on it.

Data minimisation · Selective disclosure

GDPR requires collecting only the data a purpose needs. Selective disclosure lets a verifier confirm a single attribute, that a person is over 18, resident in a country, or cleared to transact, without receiving the full identity record, which is data minimisation enforced by design rather than by policy.

EDPB blockchain guidance · Data off-ledger

The European Data Protection Board’s blockchain guidance recommends that personal data not be stored on-chain. Verifiable credentials keep personal data off the ledger and place only a cryptographic proof on it, so a public or shared chain never holds identity data.

No central store · Reduced breach surface

Because the customer holds their own credential, there is no central database of identity data acting as a honeypot. That removes a single point of failure and shrinks the breach surface the other regulations expect institutions to manage.

Consent and control · Rights by design

The customer presents their own credential and consents to each disclosure, which supports the access, consent, and control rights GDPR grants data subjects. Storage of the underlying data by the verifier is not required to complete a check.

Standards

Built on the standards these rules reference

The regulations above point to a common set of technical standards. Credentials are issued and verified to them, which is what lets one verified identity satisfy rules across both the EU and the US.

NIST SP 800-63

US identity assurance levels IAL2 and IAL3, the root-of-trust bar for KYC and CIP.

FATF

The global AML standard behind the travel rule now written into EU and US law.

Kantara Initiative

Independent certification of identity assurance, referenced by regulators.

W3C Verifiable Credentials

The open credential model: tamper-evident, held by the customer, revocable.

ISO 18013-7 · mdoc

The mdoc format carrying authenticated documents and biometrics, in production for financial KYC.


Where this maps in practice

Working through how these rules apply to your obligations? Talk to our team.

A reference, not legal advice. Citations point to the primary instruments. Last reviewed: August 15, 2026.