Financial Crimes and the GENIUS Act

What Financial Institutions Need to Know

 

Stablecoins are moving quickly from emerging payment innovation to mainstream financial infrastructure. As the GENIUS Act advances federal oversight of payment stablecoins, financial services organizations face a practical readiness question: are their BSA/AML, sanctions, and third-party controls prepared for tokenized payments? Treasury’s recent report to Congress underscores why the answer matters. Digital assets can move quickly across borders, creating new challenges for detecting fraud, sanctions evasion, and other illicit finance risks.

The proposed framework would formalize compliance expectations for permitted payment stablecoin issuers, or PPSIs, with greater focus on customer identification, suspicious activity reporting, sanctions screening, recordkeeping, and risk-based AML/CFT program effectiveness.

What’s Changing Now

The GENIUS Act, signed into law in July 2025, established the first federal framework for payment stablecoins. The latest implementation step is part of a broader interagency effort: FinCEN, together with the OCC, Federal Reserve, FDIC, and NCUA, has issued a joint proposed rule focused on implementing the Act’s customer identification program requirements for permitted payment stablecoin issuers. That proposal complements FinCEN’s separate rulemaking on broader AML obligations, signaling that stablecoin oversight is moving toward a more formal supervisory model. For compliance teams, the practical takeaway is clear: expectations are becoming clearer around CIP, AML/CFT program design, sanctions screening, recordkeeping, third-party oversight, and governance aligned to each issuer’s business model and risk profile.

The implications, however, extend beyond issuers. Banks, fintechs, payment providers, and other financial services organizations that support reserve accounts, custody, settlement, liquidity, correspondent services, technology partnerships, blockchain analytics, digital identity, or fiat on/off-ramps may need to reassess how stablecoin activity touches their customers, products, transaction flows, vendor relationships, and board-level reporting.

Core Compliance Requirements to Watch

  • BSA financial institution status: PPSIs would be brought into a familiar financial-crime compliance framework, including AML/CFT program, reporting, due diligence, recordkeeping, and information-sharing expectations.
  • Risk-based AML/CFT programs: PPSIs would need written programs tailored to their size, complexity, customers, geographies, products, services, and transaction activity.
  • Customer identification procedures: PPSIs would need to obtain and verify core customer information, address failed verification, retain records, provide customer notice, check government lists, and define when reliance on another regulated institution is appropriate.
  • Sanctions compliance: Sanctions controls would need to address customer and wallet screening, alert escalation, blocked or rejected transactions, and exposure to stablecoin activity that moves through mixers, bridges, decentralized exchanges, or other indirect transaction paths beyond direct customer relationships.
  • Supervisory coordination: The proposal highlights increased coordination between prudential regulators and FinCEN, signaling that stablecoin compliance will be reviewed through both prudential and financial-crime risk lenses.

What This Means for Financial Institutions

Organizations do not need to issue stablecoins to feel the impact. The proposed framework may influence onboarding, enhanced due diligence, third-party oversight, sanctions screening, payment operations, transaction monitoring, technology controls, and board reporting.

Treasury’s report also points to responsible innovation, including AI, digital identity, blockchain monitoring, and APIs, as a way to improve illicit finance detection when supported by sound governance and validation. The opportunity now is to move from awareness to action: identify exposure, test whether existing controls are fit for purpose, and document a clear path to readiness before supervisory expectations become more defined.

Your Stablecoin Readiness Check Starts Here

For most firms, readiness should start with a focused review that connects regulatory expectations to practical controls. Priority actions include:

  • Map exposure now: Identify stablecoin-related customers, products, services, vendors, payment flows, reserve relationships, and partnerships before activity expands.
  • Refresh the risk assessment: Incorporate stablecoin-specific customer, product, transaction, geography, sanctions, technology, and third-party risks, including potential exposure to mixers, bridges, digital asset kiosks, ransomware proceeds, fraud schemes, and sanctions evasion typologies.
  • Test control readiness: Review CIP, CDD, EDD, sanctions screening, blockchain analytics, transaction monitoring, SAR escalation, and recordkeeping processes to confirm they can address digital asset activity.
  • Challenge partner oversight: Strengthen due diligence and ongoing monitoring for PPSIs, fintech platforms, exchanges, custodians, wallet providers, and blockchain analytics vendors.
  • Prepare for supervisory scrutiny: Maintain clear evidence of governance, risk decisions, control design, issue management, board reporting, and remediation progress.

From Regulatory Change to Confident Execution

As stablecoin oversight matures, financial services organizations should not wait for final rules to define their response. The organizations best positioned for this shift will be those that can answer three questions with confidence: Where are we exposed? Are our controls fit for purpose? Can we prove it?

Eliassen Group can help translate emerging regulatory expectations into practical, risk-based actions that strengthen governance, enhance control effectiveness, and position your organization for confident execution in a rapidly evolving digital asset environment.

 

Author

Miguel Garcia circle-1

 

Miguel Garcia

Senior Manager, Risk & Compliance Solutions

MGarcia@eliassen.com

Miguel Garcia | LinkedIn