What Compliance Officers Need to Learn Now That Stablecoins Are BSA-Regulated
A stablecoin issuer used to be, from a regulatory standpoint, mostly a money transmitter with a state license and a handful of federal obligations layered on top. That description no longer holds. Under the GENIUS Act, permitted payment stablecoin issuers are now treated as financial institutions for purposes of the Bank Secrecy Act. FinCEN and OFAC have proposed the rules that will define exactly what that means in practice, and a second proposal covering customer identification followed close behind. Neither is final yet, but the direction is set, and it is set firmly. If you are a compliance officer at a stablecoin issuer, or you are advising one, this is the point where reading the proposals closely matters more than waiting for the final text. Programs built now, even against proposed rules, will be miles ahead of programs that wait.

Why Stablecoins Moved Into BSA Territory Under the GENIUS Act
The GENIUS Act, signed into law in July 2025, created the first comprehensive federal framework for payment stablecoins in the United States. One of its central provisions is a simple instruction with enormous consequences: a permitted payment stablecoin issuer, or PPSI, is to be treated as a financial institution for BSA purposes and made subject to the same federal laws that apply to any other financial institution operating in the country, covering sanctions, money laundering prevention, customer identification, and due diligence.
FinCEN and OFAC responded on April 8, 2026 with a joint proposed rule laying out what that treatment actually requires, published in the Federal Register on April 10. A related proposal on customer identification followed from FinCEN and the federal banking agencies on June 18, 2026. Together, these two proposals are the clearest picture available of how a stablecoin issuer's compliance program will need to function once the rules are finalized.
Neither is law yet. Comments on the first proposal closed in June 2026, and comments on the CIP proposal are due roughly two months after its Federal Register publication in late June. But few people inside the regulatory community expect the core structure to change much between proposal and final rule, and issuers who are still treating this as a future problem are already behind.
AMLI Analysis: The proposed text is detailed enough to build against now. Waiting for the final rule just makes this harder later.
The Change Compliance Officers Actually Need to Understand
Most stablecoin issuers already have some AML program in place, usually built around their existing status as money transmitters under FinCEN's money services business rules. What changes under the new framework is not the general idea of AML compliance. It is the specificity, the scope, and the direct line of accountability back to a named individual.
A few structural changes stand out.

PPSI Compliance Officer Requirements Under the New Rule
The proposal requires a United States-based AML/ATF officer who resides in the country, and it explicitly bars anyone with a felony conviction related to financial crime from holding the role. That is not a suggestion for best practice. It is a regulatory floor.
GENIUS Act Sanctions Compliance Requirements Are Now Standalone
Previously, stablecoin issuers operated under general U.S. person sanctions obligations without an explicit standalone requirement. The new proposal requires a dedicated OFAC sanctions compliance program built on the same five pillars OFAC applies elsewhere:
-
Management commitment
-
A documented risk assessment
-
Internal controls
-
Testing and auditing
-
Training
Violations carry a penalty of up to $100,000 per day, which is a meaningfully different number than what most issuers have budgeted risk around.
Stablecoin SAR Reporting Thresholds Under the Proposed Rule
The proposal sets a $5,000 threshold for filing Suspicious Activity Reports tied to primary market activity, which is lower than many compliance teams are used to working with elsewhere in traditional banking.
Technical Enforcement Capability Is Now a BSA Compliance Requirement
Issuers must be able to block, freeze, and reject transactions that violate federal or state law or a lawful order, and that includes the ability to burn tokens, meaning permanently destroy them, or reissue tokens when required. This obligation applies across both primary and secondary market activity, which means compliance officers now need a working understanding of what their own smart contracts can and cannot do on command. The full list of these obligations is laid out in FinCEN's fact sheet on the proposed rule.
AMLI Analysis: The blocking and burning requirement is the one compliance officers are least prepared for. It needs an early conversation with engineering.
Primary Market vs. Secondary Market: The Core of the PPSI Customer Identification Program
If there is one concept every compliance officer at a stablecoin issuer needs to internalize before anything else, it is the difference between primary market activity and secondary market activity, because the entire scope of the CIP proposal is built around it.
Primary market activity is anything where the issuer has a direct relationship with a customer: issuing, converting, redeeming, repurchasing, burning, reissuing, or providing custodial services. This is where an account relationship exists, and where full customer identification obligations apply.
Secondary market activity is everything else: a self-hosted wallet sending stablecoins to a vendor, one holder exchanging stablecoins for another asset on an exchange, a peer-to-peer transfer between two users who never touched the issuer directly. FinCEN and the banking agencies have been explicit that mere ownership or control of a stablecoin, without more, does not create an account relationship with the issuer.
This distinction matters enormously in practice. Without it, an issuer could be pushed toward identifying every person who ever holds or moves its stablecoin, something the regulators themselves describe as close to impossible to implement and potentially damaging to the industry. With it, compliance officers get a workable boundary: know your direct customers thoroughly, and build a defensible, risk-based rationale for why secondary market activity sits outside that obligation.
Legal requirement: A written, risk-based Customer Identification Program is required as part of the broader AML/ATF program, covering collection of identifying information, verification within a reasonable time, recordkeeping, screening against designated government lists, customer notice, and clearly limited reliance on other regulated institutions.
Operational expectation: Compliance officers need to map every product, wallet flow, redemption channel, and third-party relationship against this primary and secondary market line, and be ready to explain, in writing, why each falls where it falls.
AMLI Analysis: Regulators want scoping decisions justified in writing.
Digital Identity Tools in the Stablecoin CIP Are Allowed
The CIP proposal acknowledges something that traditional bank rules never had to address directly: identity verification has moved well past driver's licenses and passport scans. Mobile IDs, verifiable credentials, and other digital identity tools are recognized as legitimate methods for meeting CIP obligations.
What the proposal does not do is hand compliance officers a specific technical standard to follow. There is no approved list, no required protocol, no minimum technical specification written into the rule. That flexibility is useful for issuers building innovative onboarding flows, but it also means the burden of proof sits entirely with the issuer.
If a stablecoin issuer relies on a digital identity tool to verify a customer, the compliance officer needs a documented, defensible answer to a handful of questions:
-
Why is this tool reliable for this type of customer?
-
What residual risk remains after using it?
-
What controls exist over the vendor providing it?
-
How are exceptions handled?
-
Can all of this be reconstructed later for an auditor or examiner?
AMLI Analysis: No hard technical standard means more documentation is expected of the issuer.
Reliance on Other Institutions Is Available, But It Does Not Transfer Liability
Many stablecoin issuers work through exchanges, wallet providers, or other regulated partners who already perform some level of customer verification. The CIP proposal allows an issuer to rely on another federally regulated financial institution to carry out specified CIP procedures, but only under specific conditions:
-
The reliance has to be reasonable
-
The other institution has to be subject to its own AML/ATF and CIP requirements and regulatory oversight
-
The arrangement has to be backed by a contract that includes annual certification
Even when all of that is in place, the issuer keeps its own compliance obligation. Reliance is an operational convenience. If the partner's verification process turns out to be inadequate, the issuer is still the one accountable to FinCEN.
Legal requirement: Reliance arrangements require a documented contract with annual certification confirming the relied-upon institution's AML/ATF program and CIP performance.
Operational expectation: Compliance officers should treat every reliance arrangement as a vendor relationship requiring ongoing oversight, not a one-time legal agreement signed and filed away.
AMLI Analysis: A signed agreement is not the same as proof the partner is actually doing what it says.
The GENIUS Act Travel Rule Requirements for Stablecoin Transfers
Stablecoin issuers are also being brought formally into the Travel Rule framework that has applied to traditional wire transfers for decades. PPSIs will need to transmit required originator and beneficiary information to other financial institutions on qualifying transfers, the same basic obligation that has governed correspondent banking relationships for years, now applied to a payment rail that moves at a completely different speed and scale.
For a compliance officer, this means building or confirming a technical pathway for transmitting that information alongside the transaction itself. It also means understanding which transfers qualify and which fall on the secondary market side of the line described earlier, because the Travel Rule obligation follows the same primary and secondary market logic running through the rest of the framework.
AMLI Analysis: The concept is familiar. The infrastructure behind it is not, and that gap is where the real build happens.

What a Compliance Officer's Learning Priorities Should Look Like Right Now
Given where the proposed rules stand, here is where a compliance officer's attention is best spent over the coming months, in rough order of urgency.
-
Understand the primary versus secondary market distinction well enough to explain it to a non-lawyer, because it is the foundation for almost every other scoping decision in the CIP proposal.
-
Sit down with engineering and get a real answer on what the block, freeze, and burn capabilities actually look like today, not what the roadmap says they will look like eventually.
-
Build the sanctions compliance program as its own standalone structure, with its own risk assessment and its own testing cycle, rather than folding it into the general AML program and hoping the five pillars overlap enough.
-
Confirm the compliance officer role itself meets the residency and background requirements written into the proposal, and document that confirmation formally.
-
Review every onboarding flow, including any digital identity or verifiable credential tools in use, and build the documentation trail explaining why each one is reliable for its intended use case.
-
Audit existing reliance arrangements with exchanges, wallet providers, or other partners, and confirm the contractual and certification elements match what the CIP proposal will require.
-
Map transaction flows against the $5,000 SAR threshold for primary market activity and the Travel Rule obligations for qualifying transfers, and confirm the monitoring system can actually catch activity at that level.
AMLI Analysis: None of this needs a final rule to start. Building against the proposal now beats rebuilding under pressure later.
What Happens to Issuers Who Wait
The GENIUS Act's own language leaves little room to argue that BSA treatment is optional or distant. Stablecoin issuers are already money transmitters subject to FinCEN's existing money services business rules, which means many of the underlying AML obligations already apply in some form. What the new proposals add is specificity, a named and personally accountable compliance officer, a standalone sanctions program with real financial penalties attached, and a customer identification framework built specifically for how stablecoins actually move.
Firms that treat the proposal stage as optional reading are setting themselves up to build an entire compliance architecture in the gap between a final rule's publication and its effective date, which is rarely enough time to do the job well. Firms that start now are simply building once.
A Quick Readiness Check: Eight Questions Every Compliance Officer Should Be Able to Answer
-
Does the AML/ATF officer meet the residency requirement and the background check bar described in the proposed rule?
-
Is there a standalone OFAC sanctions compliance program, built on its own risk assessment, separate from the general AML/ATF program?
-
Can engineering confirm, in writing, the current state of transaction blocking, freezing, and token burning capability?
-
Has every product and wallet flow been mapped against the primary and secondary market distinction, with a documented rationale for each?
-
Are digital identity or verifiable credential tools backed by a defensible reliability assessment for the customer types they serve?
-
Do existing reliance arrangements with partners include the contractual and annual certification elements the CIP proposal requires?
-
Can the transaction monitoring system reliably flag activity at the $5,000 SAR threshold for primary market transactions?
-
Is there a working Travel Rule transmission process for qualifying stablecoin transfers?
If any answer is uncertain, that uncertainty is exactly where the exposure sits once the rules are finalized.
Frequently Asked Questions
Are stablecoin issuers required to comply with the Bank Secrecy Act now?
Yes, by statute. The GENIUS Act directs that permitted payment stablecoin issuers be treated as financial institutions for purposes of the Bank Secrecy Act. FinCEN and OFAC have proposed the specific rules that define what that treatment requires, and those rules are expected to be finalized in 2026, but the underlying obligation is already set in law.
What is a Permitted Payment Stablecoin Issuer (PPSI)?
A PPSI is an entity authorized under the GENIUS Act to issue payment stablecoins in the United States, operating under federal or state supervision depending on its structure. Not every stablecoin issuer qualifies as a PPSI, and not every stablecoin counts as a payment stablecoin under the Act's definitions, so the first step for any issuer is confirming whether it actually falls into this category.
What is the SAR threshold for stablecoin issuers under the new rule?
The proposed rule sets a $5,000 threshold for filing Suspicious Activity Reports tied to primary market activity, meaning transactions where the issuer has a direct relationship with the customer, such as issuance, redemption, or conversion. This is lower than thresholds compliance teams may be used to from traditional banking.
Does the Travel Rule apply to stablecoin transfers?
Yes. PPSIs will be required to transmit originator and beneficiary information on qualifying transfers, the same basic obligation that has applied to traditional wire transfers for years. Whether a specific stablecoin transfer qualifies depends on the same primary and secondary market distinction that runs through the rest of the proposed framework.
How AML Incubator Supports Stablecoin Issuers
AML Incubator works with stablecoin issuers, crypto platforms, and fintechs to build compliance programs that hold up under regulatory scrutiny.
If your stablecoin compliance program is still built around the assumptions that applied before the GENIUS Act, this is the moment to change that, before an examiner changes it for you.




