NewsCryptoSEC Commissioner Hester Peirce Proposes Crypto KYC With Less Customer Data

SEC Commissioner Hester Peirce Proposes Crypto KYC With Less Customer Data

Author: Coindoo·

Key Takeaways

  • •SEC Commissioner Hester Peirce proposed at SIFMA's Digital Assets Conference that crypto platforms could use verifiable credentials and zero-knowledge proofs to conduct identity, compliance, and eligibility checks without collecting customers' underlying documents.
  • •Under the proposed model, a trusted issuer such as a government agency or regulated institution would verify original documents and issue cryptographically signed credentials that customers store in compatible digital wallets.
  • •Peirce's comments reflect her personal and carry no regulatory force, as the SEC cannot on its own rewrite the customer-identification framework established under the Bank Secrecy Act and administered by FinCEN.
  • •FinCEN's September 8 guidance already allows banks and credit unions to use certain government-issued verifiable digital credentials, including mobile driver's licences, to verify natural-person customers, though existing obligations to collect and retain identifying information remain.
  • •Data-minimized KYC would leave unresolved challenges, including credential expiration and revocation checks, fraud risks from stolen wallets, and the continued need for source-of-funds verification, transaction monitoring, and suspicious-activity reporting.
SEC Commissioner Hester Peirce Proposes Crypto KYC With Less Customer Data

SEC Commissioner Hester Peirce has described a version of crypto customer due diligence in which an investment platform could verify who a customer is without ever seeing their passport, home address or financial records.

Speaking at SIFMA's Digital Assets Conference, Peirce proposed using verifiable credentials and zero-knowledge proofs for identity, compliance and product-eligibility checks. Under her scenario, a platform that needs to establish three facts before accepting a customer would receive those answers without necessarily obtaining the underlying documents. The framing speaks to a familiar pattern in crypto onboarding: each platform runs its own checks today, and customers who use several services typically resubmit the same documents to every new provider.

Her comments represent her personal position. They are not an SEC rule, proposal or exemption, and the SEC cannot on its own rewrite the broader customer-identification framework established under the Bank Secrecy Act and administered by FinCEN and other regulators.

Where the identity check would happen

A trusted issuer, such as a government agency, a regulated institution or an approved verification provider, would first examine the customer's original documents. The issuer could then issue a cryptographically signed credential that the customer stores in a compatible digital wallet.

A verifiable credential carries attestations from that issuer. A zero-knowledge proof can use those attestations to confirm that a particular condition has been met without revealing the information used to reach the answer.

The model changes where personal data is held rather than making identity verification disappear. The original issuer still needs reliable evidence, while the crypto platform may receive only the facts relevant to the service being requested.

Peirce raised a related data-minimization question when discussing whether tokenized-security records always need conventional fields such as names and physical addresses. Coindoo examined that debate in its report on the SEC's proposed tokenized-stock ownership rules.

Can financial firms use this approach today?

FinCEN has already accepted a narrower use of the technology. Its September 8 guidance says banks and credit unions may use certain government-issued verifiable digital credentials, including mobile driver's licences, as a method of verifying natural-person customers.

The guidance did not remove existing legal obligations. Covered institutions must still obtain required identifying information and retain the prescribed records. A crypto company's duties likewise depend on its activities and on whether it operates as a money-services business, securities intermediary, bank or another regulated entity. For crypto firms, in other words, the guidance is a reference point rather than a transferable template.

What private KYC would fail to solve

Sanctions status and customer eligibility can change, so credentials would require expiration, status and revocation checks. Platforms would also need to know whether the issuer performed a reliable original verification, and a stolen wallet or compromised credential would create another route for identity fraud.

Receiving less personal information would reduce a platform's breach exposure only if it stopped retaining the underlying documents. The risk would not vanish; more of it would sit with the organization that issued or maintained the credential. Selective proofs also cannot establish the source of a customer's funds or replace transaction monitoring and suspicious-activity reporting.

The technology is of the rulebook

Financial institutions can already verify signed digital credentials. The unfinished policy question is when they may retain proof that a check occurred instead of collecting the personal data behind it.

Peirce's proposal would make KYC less repetitive, not optional. Turning it into standard practice would require regulators beyond the SEC to decide that a verified answer can sometimes satisfy the law without another complete identity file. Until then, data-minimized KYC remains a set of conference remarks rather than a compliance option, and day-to-day obligations continue to run through the existing rulebook.