Stablecoins are moving quickly from emerging payment innovation to mainstream financial infrastructure. As the GENIUS Act advances federal oversight of payment stablecoins, financial services organizations face a practical readiness question: are their BSA/AML, sanctions, and third-party controls prepared for tokenized payments? Treasury’s recent report to Congress underscores why the answer matters. Digital assets can move quickly across borders, creating new challenges for detecting fraud, sanctions evasion, and other illicit finance risks.
The proposed framework would formalize compliance expectations for permitted payment stablecoin issuers, or PPSIs, with greater focus on customer identification, suspicious activity reporting, sanctions screening, recordkeeping, and risk-based AML/CFT program effectiveness.
The GENIUS Act, signed into law in July 2025, established the first federal framework for payment stablecoins. The latest implementation step is part of a broader interagency effort: FinCEN, together with the OCC, Federal Reserve, FDIC, and NCUA, has issued a joint proposed rule focused on implementing the Act’s customer identification program requirements for permitted payment stablecoin issuers. That proposal complements FinCEN’s separate rulemaking on broader AML obligations, signaling that stablecoin oversight is moving toward a more formal supervisory model. For compliance teams, the practical takeaway is clear: expectations are becoming clearer around CIP, AML/CFT program design, sanctions screening, recordkeeping, third-party oversight, and governance aligned to each issuer’s business model and risk profile.
The implications, however, extend beyond issuers. Banks, fintechs, payment providers, and other financial services organizations that support reserve accounts, custody, settlement, liquidity, correspondent services, technology partnerships, blockchain analytics, digital identity, or fiat on/off-ramps may need to reassess how stablecoin activity touches their customers, products, transaction flows, vendor relationships, and board-level reporting.
Organizations do not need to issue stablecoins to feel the impact. The proposed framework may influence onboarding, enhanced due diligence, third-party oversight, sanctions screening, payment operations, transaction monitoring, technology controls, and board reporting.
Treasury’s report also points to responsible innovation, including AI, digital identity, blockchain monitoring, and APIs, as a way to improve illicit finance detection when supported by sound governance and validation. The opportunity now is to move from awareness to action: identify exposure, test whether existing controls are fit for purpose, and document a clear path to readiness before supervisory expectations become more defined.
For most firms, readiness should start with a focused review that connects regulatory expectations to practical controls. Priority actions include:
As stablecoin oversight matures, financial services organizations should not wait for final rules to define their response. The organizations best positioned for this shift will be those that can answer three questions with confidence: Where are we exposed? Are our controls fit for purpose? Can we prove it?
Eliassen Group can help translate emerging regulatory expectations into practical, risk-based actions that strengthen governance, enhance control effectiveness, and position your organization for confident execution in a rapidly evolving digital asset environment.
Miguel Garcia
Senior Manager, Risk & Compliance Solutions