U.S. Securities and Exchange Commission seal mounted on a stone building exterior
REGULATION

SEC’s Peirce Backs Zero-Knowledge Proofs for KYC

Image Credit: Shutterstock

SEC Commissioner Hester Peirce has called on U.S. regulators to explore zero-knowledge proofs and digital credentials as alternatives to collecting large amounts of personal information for customer verification.

Speaking at SIFMA’s Digital Assets Conference on Sept. 23, Peirce said financial firms could verify attributes such as age, citizenship, accredited investor status or absence from sanctions lists without seeing the personal data used to establish them. Her remarks represent her own policy views and do not change existing KYC or anti-money laundering requirements.

Zero-Knowledge Proofs Could Verify Attributes Without Exposing Personal Data

Peirce pointed to attribute-based credentials as one way to reduce how much customer information financial institutions collect and retain. A zero-knowledge proof can confirm that a person meets a particular requirement without revealing underlying details such as their name, income or address. 

Peirce said regulators should reconsider whether institutions need the original data when a compliance obligation depends only on verifying a specific fact. She called for the federal government and regulated institutions to move away from prescriptive collection requirements toward attribute-based verification where technologically feasible.

Peirce Targets Repeated Collection Of Customer Information 

Current Customer Identification Programs require financial institutions to collect and verify information including names, dates of birth, addresses and identification numbers.

Peirce argued that customers using multiple financial institutions can therefore have the same sensitive information collected and stored repeatedly, increasing the number of places where that data could be mishandled or compromised.

She also proposed making it easier for registered firms to rely on identity verification already completed by trusted third parties rather than requiring each institution to independently collect and verify the same information.

July 17 Aztec Meeting Tested Privacy-Preserving KYC Model

The SEC Crypto Task Force has already discussed similar technology with privacy developers. Representatives of Aztec Laboratorium Limited met with the task force on July 17 to demonstrate ZKPassport. 

Meeting materials described proofs that could establish attributes including age, permitted jurisdiction, sanctions status and possession of a valid government identity document without revealing the underlying personal data.

Peirce said the missing piece is a regulatory framework that allows and encourages firms to use such technologies.

Her Sept. 23 remarks do not establish new KYC or AML rules. Peirce described the speech as occurring during her penultimate week as an SEC commissioner, leaving any formal regulatory changes to future Commission and government action.

More For You

Explore More News