FinTech & RegTechNorth AmericaRegulation & Policy

U.S. Proposes New Illicit-Finance Rules for Payment Stablecoin Issuers

The U.S. Department of the Treasury has proposed a new anti-illicit-finance framework for regulated payment stablecoin issuers under the GENIUS Act.

Issued jointly by the Financial Crimes Enforcement Network and the Office of Foreign Assets Control, the proposal would treat permitted payment stablecoin issuers as financial institutions for Bank Secrecy Act purposes and require them to maintain formal AML/CFT and sanctions compliance programs.

The proposed framework recognises that stablecoin issuers occupy a different position from banks, custodians and trading platforms. An issuer may have direct relationships with only a limited number of institutional customers, while its stablecoin circulates through exchanges, custodial wallets and peer-to-peer transactions around the world.

The rules therefore combine traditional financial institution obligations with technical requirements specific to blockchain-based assets.

Who Would Be Covered?

The proposal applies to permitted payment stablecoin issuers, or PPSIs, authorised under the GENIUS Act.

It does not automatically apply to every company that uses, trades or provides custody for a payment stablecoin.

A cryptocurrency exchange, wallet provider or custodian may already be regulated as a money services business, bank or another type of financial institution. Those businesses remain responsible for their own AML, customer due diligence and reporting obligations.

The issuer would have a separate set of responsibilities arising from its role in:

  • Issuing and redeeming the stablecoin;
  • Maintaining relationships with account holders;
  • Operating or controlling the stablecoin’s smart contract;
  • Responding to lawful government orders; and
  • Managing risks connected with the stablecoin in both primary and secondary markets.

This creates overlapping responsibilities rather than transferring all compliance duties to one participant.

Core AML/CFT Program Requirements

The proposal would require each PPSI to establish and maintain a risk-based AML/CFT program.

The program would need to include:

  • Risk-based internal policies, procedures and controls;
  • Documented money laundering and terrorist financing risk assessment processes;
  • Ongoing customer due diligence;
  • Independent testing;
  • An ongoing employee training program; and
  • A designated AML/CFT officer located in the United States.

The institution would also be expected to update its risk assessment when material changes affect its risk profile.

Relevant changes could include:

  • Launching the stablecoin on a new blockchain;
  • Adding new smart contract functions;
  • Introducing new products or customer types;
  • Entering new jurisdictions;
  • Changing distribution arrangements;
  • Acquiring another business; or
  • Adopting new risk-management technology.

The proposal is therefore not limited to creating an AML policy before launching a stablecoin. The compliance framework would need to change with the product and its use.

Customer Identification Is Required, but the Detailed Rules Were Deferred

The GENIUS Act requires permitted payment stablecoin issuers to maintain an effective customer identification program, including the identification and verification of account holders.

However, the April proposal does not itself establish the detailed customer identification program requirements. FinCEN indicated that those procedures would be addressed through separate rulemaking.

This distinction matters.

The statutory obligation already establishes the direction of travel: issuers will need formal procedures for identifying and verifying customers rather than relying only on wallet addresses or blockchain data.

But the April proposal should not be read as providing the complete operational standard for:

  • What constitutes an account;
  • Which parties must be treated as customers;
  • What information must be collected;
  • How identity must be verified;
  • When non-documentary verification may be used; or
  • How customer information must be maintained.

Issuers should prepare for a formal customer identification framework while avoiding assumptions about requirements that were not yet included in this proposal.

Ongoing Due Diligence Goes Beyond Initial Verification

Customer identification establishes who the customer is. Ongoing customer due diligence addresses how the relationship is expected to operate and whether actual activity remains consistent with that expectation.

A PPSI may need to understand:

  • The type of institution seeking issuance or redemption services;
  • Its jurisdiction and regulatory status;
  • The markets and customers it serves;
  • Its operating history;
  • The intermediaries it uses;
  • Expected issuance and redemption volumes; and
  • Its exposure to higher-risk wallets, services or jurisdictions.

This is particularly important where the issuer’s direct customers include exchanges, custodians, payment companies or other institutions that distribute the stablecoin to a wider user base.

An exchange may initially appear to be a regulated institutional customer. Its risk profile may change if on-chain activity later shows significant stablecoin flows involving sanctioned addresses, illicit marketplaces or other high-risk services.

Blockchain information may therefore become relevant to the issuer’s ongoing assessment of a direct customer, even where the issuer is not required to identify every person using the stablecoin in the secondary market.

Suspicious Activity Reporting

The proposal would require PPSIs to monitor customer relationships and report qualifying suspicious transactions.

FinCEN proposed a $5,000 reporting threshold, rather than the $2,000 threshold currently applicable to stablecoin issuers operating as money services businesses.

A suspicious activity report would generally need to be filed within 30 calendar days after the initial detection of facts that may support a filing. Where no suspect has been identified, filing could be delayed for an additional 30 days, but not beyond 60 days from initial detection.

Relevant activity might include:

  • Issuance or redemption inconsistent with the customer’s profile;
  • Stablecoins funded with unexplained or suspicious assets;
  • Attempts to evade transaction or due diligence controls;
  • Use of intermediaries without a clear business purpose;
  • Transactions linked to fraud, ransomware or sanctions evasion;
  • Activity lacking an apparent lawful purpose; or
  • Transactions involving suspected criminal proceeds.

However, the proposal draws an important boundary around secondary-market activity.

A PPSI would not automatically be required to file a SAR on every suspicious secondary-market transfer merely because the transaction interacts with the stablecoin’s smart contract.

FinCEN recognised that the issuer may see a wallet-to-wallet transfer on the blockchain without knowing the identity of the parties or the purpose of the transaction. In many cases, a regulated exchange or custodian handling the customer relationship may be better positioned to investigate and report the activity.

The proposal therefore does not impose a blanket secondary-market SAR monitoring obligation.

An issuer may still have a reporting obligation where information available through its customers, compliance systems, public sources or other investigations gives it sufficient grounds to suspect activity conducted by, at or through the issuer.

Sanctions Controls Would Extend to the Secondary Market

The proposed sanctions requirements are broader in an important respect.

OFAC would require a PPSI to maintain an effective sanctions compliance program covering all payment stablecoin-related activity, including both primary and secondary markets.

The program would need five core elements:

  1. Senior management commitment;
  2. Risk assessment;
  3. Internal controls;
  4. Independent testing or audit; and
  5. Risk-based training.

The issuer would need technical capabilities and written procedures capable of identifying, blocking or rejecting transactions that may violate U.S. sanctions.

At a minimum, sanctions screening tools should be capable of identifying digital currency addresses included on OFAC sanctions lists.

Depending on the issuer’s risk profile, controls may also consider:

  • Direct and indirect exposure to sanctioned wallets;
  • Transactions associated with sanctioned jurisdictions;
  • Wallets linked to sanctions evasion networks;
  • Use of mixers or obfuscation services;
  • Cross-chain movement intended to conceal origin;
  • Newly designated addresses; and
  • Geographic and device information available from direct customers.

The controls would need to be updated as OFAC designations and sanctions risks change.

Issuers Must Be Able to Block, Freeze and Reject Transactions

One of the most significant features of the proposal is the requirement for issuers to maintain technical capabilities to:

  • Block;
  • Freeze; and
  • Reject

specific or impermissible transactions that violate applicable federal or state requirements.

These capabilities would need to extend beyond direct issuance and redemption activity to secondary-market transactions involving the stablecoin.

The proposal also requires issuers to be able to comply with lawful orders. This may include orders requiring the issuer to:

  • Freeze stablecoins held at identified addresses;
  • Prevent further transfers;
  • Seize or redirect assets;
  • Burn existing stablecoins; or
  • Reissue equivalent stablecoins to a government-controlled wallet.

Maintaining the capability does not mean that the issuer must independently decide that every suspicious transaction violates the law.

Action would generally be required where a legal obligation, sanctions requirement or lawful order applies.

The practical implication is that a payment stablecoin issued under the GENIUS Act cannot be designed in a way that makes lawful intervention technically impossible.

Responsibility Boundaries Across the Stablecoin Ecosystem

The proposed framework does not make the issuer solely responsible for all illicit activity involving its stablecoin.

Responsibilities depend on each participant’s role and the information it controls.

Stablecoin Issuer

The issuer would generally be responsible for:

  • AML/CFT controls over its direct customer relationships;
  • Customer due diligence for account holders;
  • Monitoring issuance and redemption activity;
  • Filing SARs where required;
  • Maintaining required records;
  • Complying with the Travel Rule where applicable;
  • Operating an effective sanctions compliance program;
  • Screening relevant blockchain activity; and
  • Maintaining technical capabilities to act on prohibited transactions and lawful orders.

Custodian or Wallet Provider

A custodial provider would remain responsible for:

  • Identifying its own customers;
  • Understanding beneficial ownership where applicable;
  • Monitoring deposits, withdrawals and wallet activity;
  • Screening customer transactions;
  • Investigating suspicious activity;
  • Filing SARs where required; and
  • Transmitting required Travel Rule information.

The custodian cannot assume that the issuer’s controls replace its own obligations.

Trading Platform

A trading platform would generally be responsible for risks arising from:

  • Customer onboarding;
  • Fiat and virtual asset funding;
  • Trading activity;
  • Transfers to and from external wallets;
  • Customer-controlled or self-hosted wallets;
  • Market manipulation;
  • Suspicious transactions; and
  • Sanctions exposure.

The platform may have customer identity and transaction-purpose information unavailable to the issuer.

Shared Responsibility

Some cases will require coordinated action.

For example, the issuer may identify a sanctioned wallet through blockchain monitoring, while an exchange holds the customer identity and transaction records associated with that wallet.

Effective compliance may therefore depend on:

  • Clear contractual responsibilities;
  • Rapid escalation channels;
  • Information-sharing arrangements;
  • Consistent wallet-risk classifications;
  • Procedures for freezes and redemptions; and
  • Defined responses to lawful government requests.

Overlapping visibility should strengthen controls rather than create uncertainty over which party is expected to act.

The Travel Rule and Stablecoin Transfers

The proposal would expressly apply the existing Recordkeeping Rule and Travel Rule to payment stablecoin transfers where their conditions are met.

For qualifying transfers of $3,000 or more, financial institutions may be required to collect, retain and transmit specified information through the payment chain.

For stablecoin businesses, implementation can be more complicated than for conventional wire transfers.

The parties may need to determine:

  • Whether the counterparty is another regulated financial institution;
  • Whether the destination is a self-hosted wallet;
  • Which institution is responsible for transmitting information;
  • How information is linked to the blockchain transaction;
  • Whether the receiving provider can accept the required data; and
  • How incomplete or inconsistent information should be handled.

Travel Rule compliance should not operate separately from transaction monitoring.

Information about the originator, beneficiary, sending institution and receiving institution can help identify whether a transfer is consistent with the customer’s profile and whether enhanced review is required.

What On-Chain Monitoring Should Achieve

The proposal does not require issuers to conduct unlimited global surveillance of every transfer involving their stablecoin.

It does require monitoring proportionate to the issuer’s AML and sanctions responsibilities.

A practical framework may combine:

  • Wallet-address screening;
  • Blockchain analytics;
  • Customer and counterparty information;
  • Issuance and redemption records;
  • Exposure to sanctioned or illicit addresses;
  • Transaction velocity and flow analysis;
  • Information from exchanges and custodians; and
  • Open-source or law-enforcement intelligence.

On-chain monitoring should support different decisions depending on the context.

It may help the issuer:

  • Reassess a direct institutional customer;
  • Investigate suspicious issuance or redemption activity;
  • Identify sanctions exposure;
  • Respond to a lawful order;
  • Determine whether a transaction must be blocked; or
  • Provide useful information to law enforcement.

A blockchain risk score alone should not determine the outcome.

The issuer should understand the nature of the exposure, the reliability of the attribution, the distance from the identified risk and what additional customer information is available.

What Firms Should Prepare For

Stablecoin businesses should begin mapping their responsibilities before the rules are finalised.

Priority areas include:

  1. Identifying which entity would qualify as the permitted payment stablecoin issuer;
  2. Defining who holds the direct customer and account-holder relationships;
  3. Separating issuer, custodian and platform responsibilities;
  4. Designing risk-based AML/CFT and sanctions programs;
  5. Preparing for formal customer identification requirements;
  6. Connecting customer data with blockchain analytics;
  7. Establishing Travel Rule processes;
  8. Testing the technical ability to block, freeze, reject, burn or redirect stablecoins;
  9. Creating escalation procedures with exchanges and custodians;
  10. Appointing a qualified U.S.-based AML/CFT officer; and
  11. Planning independent testing of both compliance controls and technical systems.

The compliance model should be reflected in the stablecoin’s technical architecture.

Where an issuer is legally required to control prohibited transactions but lacks the technical ability to intervene, a written policy alone will not resolve the deficiency.

The Compliance Takeaway

The GENIUS Act framework does not treat a payment stablecoin issuer only as a technology company responsible for maintaining reserves and operating smart contracts.

It treats the issuer as a regulated financial institution with direct responsibility for AML/CFT, customer due diligence, suspicious activity reporting and sanctions compliance.

At the same time, the proposal recognises that issuers do not hold all relevant customer information and should not automatically be responsible for investigating every secondary-market transfer.

The emerging model is based on divided but overlapping responsibility:

  • Issuers control issuance, redemption and the stablecoin’s technical architecture;
  • Custodians control customer wallets and account relationships;
  • Trading platforms control customer trading and transfer activity; and
  • Each regulated participant remains responsible for the risks it can identify and manage.

For payment stablecoins, effective compliance will depend on connecting off-chain customer information with on-chain transaction activity—while clearly defining which institution must investigate, report or intervene.

Main Sources

FinCEN — Treasury Proposes Rule to Implement the GENIUS Act’s Requirements to Counter Illicit Finance

https://www.fincen.gov/news/news-releases/treasury-proposes-rule-implement-genius-acts-requirements-counter-illicit

Federal Register — Permitted Payment Stablecoin Issuer AML/CFT Program and Sanctions Compliance Program Requirements

https://www.federalregister.gov/documents/2026/04/10/2026-06963/permitted-payment-stablecoin-issuer-anti-money-launderingcountering-the-financing-of-terrorism

Adminrichie

AML Observatory Webmaster, responsible for the website's operations.

Related Articles

Leave a Reply

Back to top button