Compliance11 min read
MB
Editorial Team
·September 11, 2026

Does the GENIUS Act Make Stablecoin Issuers Banks for AML?

The GENIUS Act does not give stablecoin issuers bank charters, but the FinCEN and OFAC proposal issued 8 April 2026 would treat every permitted payment stablecoin issuer as a distinct financial institution under the Bank Secrecy Act. That moves the issuer beyond a narrow mint-and-redeem compliance model into written AML/CFT and sanctions programs, suspicious activity reporting, information sharing and transaction recordkeeping for an instrument that continues to circulate beyond its direct customers.

TL;DR — Key Takeaways

  • ✓Legal Status: A PPSI becomes a BSA financial institution, not a bank; the designation grants no charter, insurance or central-bank access.
  • ✓Program Scope: Written risk-based AML/CFT and OFAC sanctions programs, plus SAR, information-sharing, recordkeeping and Travel Rule duties.
  • ✓Risk Record: FinCEN cited about 55,000 SARs naming specific stablecoins from January 2015 through 21 November 2025.
  • ✓Core Tension: The issuer onboards mint and redemption customers, while the token can circulate through wallets the issuer never onboarded.
  • ✓Current Status: The April rule and the separate Customer Identification Program rule remained proposals as of 11 September 2026.

Ready to get started?

Join others who are already using our platform.

Does the GENIUS Act Make Stablecoin Issuers Banks for AML?

Financial Institution for One Law, Bank for None

The proposal makes a permitted payment stablecoin issuer, or PPSI, a financial institution for Bank Secrecy Act purposes without making it a bank. The result is an obligations perimeter: AML, sanctions and reporting duties attach, but banking powers do not.

FinCEN and the Office of Foreign Assets Control issued the joint proposal on 8 April 2026. It was published in the Federal Register on 10 April, and the comment period closed 9 June. The rule sits beside the separate GENIUS Act licensing proposal examined in the issued-in-the-US stablecoin perimeter.

The GENIUS Act directs Treasury to treat PPSIs as “financial institutions” for BSA purposes.

— US Treasury, 8 April 2026

A non-bank PPSI therefore cannot advertise the designation as proof that it can take deposits, hold a Fed account or act as a qualified custodian. Those permissions come from different statutes and different supervisors.

The Proposal Builds a Full Program Around the Issuer

A PPSI would need governance, risk assessment, internal controls, testing and reporting across AML/CFT and sanctions compliance. The program must describe who owns each decision and how on-chain alerts become legally required action.

ObligationOperational system
AML/CFT programRisk assessment, controls, responsible officer, training and independent testing
Suspicious activity reportingAlert investigation, case evidence, filing and confidentiality
Sanctions programScreening, blocking or rejecting, escalation and OFAC reports
Recordkeeping and Travel RuleTransfer records and required counterparty data exchange
Information sharingSearchable records and a controlled response process for lawful requests

A smart contract can enforce an address allowlist, but it cannot decide whether a pattern is suspicious, protect SAR confidentiality or document why an OFAC alert was cleared. The broader architecture belongs in the compliance layer around the contract.

The 55,000 SARs Explain the Regulatory Design

FinCEN counted about 55,000 suspicious activity reports that named at least one specific stablecoin from 1 January 2015 through 21 November 2025. The same record included about 8,400 additional SARs that referred to stablecoins generally.

OFAC received approximately 5,800 blocked-property reports and 3,000 rejected-transaction reports naming specific stablecoins over the same period. The agencies tied the rule to money-laundering chains, DPRK cyber theft, sanctions evasion, fentanyl precursor procurement and terrorist financing.

“Approximately 55,000” SARs referenced one or more specific stablecoins.

— FinCEN and OFAC proposed rule, data through 21 November 2025

These are reports, not proven crimes and not unique incidents. One case may generate more than one filing. Their value is narrower: they show that the agencies already receive stablecoin intelligence through intermediaries and now want the issuer itself inside the reporting network.

Customer Identification Stops at a Moving Boundary

A PPSI can identify the customer who mints or redeems, but stablecoins can move to secondary wallets that never form a direct issuer relationship. The compliance problem is therefore monitoring circulation without pretending every holder is an onboarded customer.

A separate interagency proposal would implement a formal Customer Identification Program for PPSIs. That program anchors identity at the primary-market boundary. Beyond it, the issuer needs wallet-risk signals, exposure rules and escalation thresholds that distinguish a direct customer, an indirect holder and a sanctioned counterparty.

The same boundary appears in tokenized securities, where onboarding and transfer eligibility are related but not identical. Our KYC and AML Layer-0 guide explains how a reusable compliance state can connect identity evidence to transfer rules without publishing personal data.

One Risk Score Cannot Run Both AML and Sanctions

AML and sanctions programs may share blockchain analytics, but they answer different legal questions. AML asks whether activity is suspicious; sanctions asks whether a prohibited party or property interest requires blocking or rejection.

An address risk score is evidence, not a decision. The system must preserve the source and timestamp of the signal, the path of funds, the customer relationship, the analyst's disposition and the rule version applied. It also needs distinct actions: monitor, investigate, file, reject, block or freeze where the token design and law permit.

This is where issuer-level governance becomes more valuable than a wallet blacklist. The same event can enter two case queues with different deadlines and confidentiality rules, and the audit trail must keep them linked without collapsing them into one result.

What a PPSI Should Build Before the Rule Is Final

A PPSI should build the evidence model now while keeping thresholds configurable for the final rule. The expensive work is linking customer, wallet, transaction, reserve and case records; a change in a filing threshold is cheaper than adding those links later.

  • Define direct customers at mint and redemption and preserve their identity evidence.
  • Map every issuer-controlled address, contract, chain, bridge and freeze authority.
  • Separate AML investigation logic from sanctions blocking and rejection logic.
  • Store analytics inputs, rule versions, analyst decisions and transaction lineage.
  • Test how a legal hold propagates across every chain without corrupting total supply.
  • Assign board and officer accountability before a vendor generates the first alert.

The proposal's lasting change is not the label “financial institution.” It is that the issuer becomes the accountable junction between a regulated customer relationship and a bearer-style token that continues moving after issuance.

Frequently Asked Questions

Does the GENIUS Act legally make a stablecoin issuer a bank?

No. A permitted payment stablecoin issuer, or PPSI, can be a bank subsidiary, credit union issuer or approved non-bank issuer. The April 2026 proposal would classify every PPSI as a financial institution for Bank Secrecy Act purposes. That classification assigns AML and reporting duties; it does not grant a bank charter, deposit insurance or Federal Reserve account access.

What would a PPSI have to build under the proposed rule?

Each PPSI would need a written, risk-based AML/CFT program and a sanctions compliance program. The proposal also applies suspicious activity reporting, information sharing, recordkeeping and Travel Rule duties. Separate agencies proposed a Customer Identification Program rule, so direct mint and redemption customers would sit inside a formal identity process.

How much stablecoin-related suspicious activity did FinCEN report?

From 1 January 2015 through 21 November 2025, FinCEN received about 55,000 suspicious activity reports naming one or more specific stablecoins, plus about 8,400 with a general stablecoin reference. OFAC received about 5,800 blocked-property reports and 3,000 rejected-transaction reports naming specific stablecoins in the same period.

Must a stablecoin issuer identify every secondary-market holder?

The proposal does not turn every wallet into the issuer's direct customer. The issuer can identify customers at issuance and redemption, yet it remains accountable for a risk-based program covering how its tokens circulate. That requires transaction monitoring, sanctions controls and documented escalation for addresses with which the issuer has no direct onboarding relationship.

What is the difference between AML and sanctions screening for a PPSI?

AML controls assess patterns, customer risk and suspicious activity, then support SAR filing and information sharing. Sanctions controls prevent or block prohibited dealings and report them to OFAC. The same on-chain event can engage both systems, but the decision rules, reporting channels and legal consequences differ, so one vendor score cannot replace both programs.

Is the April 2026 FinCEN and OFAC rule final?

No. FinCEN and OFAC issued a notice of proposed rulemaking on 8 April 2026, published in the Federal Register on 10 April, with comments due 9 June. As of 11 September 2026, the cited agency pages still identify it as a proposal. Issuers should design against the proposed perimeter while tracking the final text.

Ready to get started?

Join others who are already using our platform.