Skip to content

Peirce Calls for Less Data-Heavy KYC Using Zero-Knowledge Proofs

SEC Commissioner Hester Peirce has urged regulators and financial institutions to reconsider how much personal information they collect for customer checks. In a September 23 speech at SIFMA’s Digital Assets Conference, she argued that cryptographic credentials and zero-knowledge proofs could confirm specific facts without exposing all of the data behind them.

A commissioner’s argument, not an SEC rule

Peirce identified the remarks as her own views, not those of the Securities and Exchange Commission or her fellow commissioners. She did not announce a rule, guidance or an approved replacement for existing know-your-customer and anti-money-laundering requirements. Her speech set out a policy direction for regulators to consider.

The current framework requires financial institutions to gather and verify identifying details through customer identification programs. Firms also monitor activity and file currency transaction reports and suspicious activity reports when applicable. Peirce argued that this system spreads sensitive personal and transaction data across institutions, raising storage costs and increasing the damage that a breach or misuse could cause.

What a proof could confirm

Her proposed alternative starts with attribute-based credentials. A customer might prove that they meet an age or citizenship requirement, qualify as an accredited investor, or do not appear on a sanctions list. A zero-knowledge proof could confirm the required result without disclosing the person’s name, income, address or the other records used to establish it.

That distinction narrows the compliance question. A firm may need to know whether a customer meets a condition, but it may not need every underlying field used to verify that condition. Peirce asked regulators to review collection rules one data point at a time and determine whether a verified fact would be enough.

She also called for broader reliance on trusted third-party identity checks. Under that approach, a customer already vetted by one regulated entity would not automatically have to submit the same sensitive records to every firm they use. The speech presented this as an area for experimentation rather than a ready operating standard.

The unresolved work

Turning the idea into policy would require more than choosing a cryptographic method. Regulators would have to define which credentials are acceptable, who can issue them, how firms audit the proofs and what information must still be retained or reported. Existing suspicious-activity obligations would remain part of the legal framework unless the relevant authorities changed them.

Peirce also connected reduced data collection with public blockchain records. She said permissionless networks can provide permanent, auditable transaction histories while operating without a custodial intermediary. That transparency does not establish a customer’s identity on its own, but it gives law enforcement and compliance teams a separate record for transaction analysis.

The practical test will be whether regulators convert the speech into a proposal with defined responsibilities and technical standards. Until then, firms remain bound by current identification, monitoring and reporting rules. The speech supplies a case for collecting fewer raw records, not permission to stop required checks.

Adapted from SEC Commissioner Peirce Calls for Zero-Knowledge Proofs to Replace Data-Heavy KYC/AML Practices.