Key points

  • SEC Commissioner Hester Peirce proposed shifting from broad data collection toward identity checks that disclose only required attributes.
  • She highlighted zero-knowledge proofs and reusable third-party verification as possible tools for reducing duplicated sensitive records.
  • The remarks are Peirce's personal recommendations, not an adopted SEC rule or a change to current KYC and AML obligations.

U.S. Securities and Exchange Commission member Hester Peirce has called for a privacy-focused rethink of customer identity checks, arguing that financial firms should be able to verify essential facts without collecting every underlying detail. In a September 23 speech at SIFMA's Digital Assets Conference in New York, Peirce pointed to zero-knowledge proofs and attribute-based credentials as tools that could confirm requirements such as age, citizenship, accredited-investor status or sanctions eligibility while revealing less personal information. Decrypt independently reported the remarks on September 24.

The proposal targets data duplication

Peirce's central concern is that conventional know-your-customer and anti-money-laundering systems create large stores of names, addresses, birth dates, identification numbers and transaction records across many institutions. She argued that accumulating more data does not automatically make enforcement more effective and can increase the consequences of accidental disclosure, hacking or misuse. Her preferred direction is selective verification: a cryptographic proof could tell a bank or broker that a customer satisfies a condition without disclosing the source document or unrelated attributes.

Related reporting: Senate blocks CLARITY Act in 49-50 procedural vote

Zero-knowledge proofs would change what firms receive

A zero-knowledge proof allows one party to demonstrate that a statement is true without exposing the information used to establish it. Applied to onboarding, a customer might prove that they are over a required age or are not on a sanctions list without sending a full identity document to every service provider. Peirce also urged regulators to make greater use of trustworthy third-party verification, so a customer vetted once would not necessarily have the same sensitive records copied and stored by dozens of firms.

Existing obligations remain in force

The speech did not announce a rulemaking, exemption or implementation timetable. Peirce explicitly said the views were her own and not necessarily those of the SEC or other commissioners. Current customer-due-diligence requirements therefore remain unchanged. FinCEN says its CDD rule applies to banks, mutual funds, securities brokers and dealers, futures commission merchants and introducing brokers, with the goal of improving financial transparency and preventing misuse of legal entities. Any privacy-preserving alternative would have to satisfy those anti-financial-crime objectives rather than simply remove identity checks.

Implementation would require more than cryptography

Technical proofs would still depend on reliable issuers, accurate source data and processes for correcting, expiring or revoking credentials. Regulators would also need standards for liability when an attestation is wrong, for audit access, and for interoperability among banks, brokers and digital-asset platforms. Permissionless networks add another challenge because they may not have a conventional intermediary that can collect or validate customer information. Peirce argued that public blockchains can still provide durable transaction records for analysis, but that does not by itself resolve who should verify a user's attributes.

What changes next is uncertain

Peirce delivered the speech during what she described as her penultimate week as a commissioner, limiting the time available for her to advance the idea personally. The practical signal is therefore a policy agenda rather than an immediate compliance change. Banks, crypto companies, identity providers and privacy advocates will be watching for formal requests for comment, pilot programs or agency coordination that could turn selective-disclosure credentials into an accepted part of U.S. financial regulation. Until then, firms remain responsible for existing KYC, customer-identification and AML duties.

Sources

AI-generated editorial image; not a photograph of the reported event. Prepared with AI assistance and source verification.