I'm just commenting due to how extremely idiotic these regulations are. It won't be too long in the future when we get a major breach where millions of drivers license images and selfies are leaked, because these regulations force all of these individual financial institutions, many with dubious levels of security competence, to secure this data.
As a perfect example, when Stripe first came out with their Identity product (which takes ID and selfie images, and had a great UI and API), a lot of people were really surprised that, unlike Stripe's credit card processing APIs which never give the developer access to the customer's full credit card number (and is a major benefit to using something like Stripe - developers can delegate most of their PCI responsibilities), this was not the case with Stripe Identity: developers have full access to ID and selfie images.
In Stripe's defense, they explained they had to build it this way: KYC regs require these financial institutions to keep this raw data for compliance. These regulations really need to be updated so that institutions can instead delegate to a certified provider something like "This provider verified the customer's ID and selfie with this information..." The regs should also be updated so that nobody is forced to store these images indefinitely - it's just a recipe for disaster.