US Stablecoin Issuers Now Face BSA AML Compliance Rules Under GENIUS Act
AML Network•June 3, 2026

Bringing Issuers Inside the Bank Secrecy Act
The headline states that US stablecoin issuers now fall within Bank Secrecy Act anti-money-laundering requirements under the GENIUS Act. The mechanism behind that sentence matters more than the label. The Bank Secrecy Act does not apply generally; it applies to entities that fall within the statutory and regulatory definition of a financial institution. Once a category of business is brought inside that definition, a standard set of duties attaches, and the business becomes examinable and enforceable against on them.
What a BSA Programme Requires
The core obligation is a written, risk-based anti-money-laundering and counter-terrorist-financing programme. In outline, that means:
- Internal policies, procedures and controls proportionate to the risks the business actually faces.
- A designated compliance officer with the seniority, authority and resource to run the programme.
- Training for staff whose roles touch onboarding, payments or monitoring.
- Independent testing of the programme by someone other than the people who operate it.
- A customer identification programme with verification, risk-based ongoing due diligence, and beneficial ownership collection for legal entity customers.
- Suspicious activity reporting to FinCEN, subject to the confidentiality restrictions that attach to a filed report.
- Recordkeeping for funds transfers, including passing originator and beneficiary information with qualifying transfers under the travel rule.
Sanctions compliance is administered separately by the Office of Foreign Assets Control and is strict liability rather than risk-based, but firms almost always run the two disciplines as a single control environment.
Why Stablecoins Are Structurally Awkward
An issuer's direct relationships are usually with the counterparties that mint and redeem tokens. After issue, tokens circulate on public ledgers between wallets with which the issuer has no relationship at all, including self-hosted wallets and non-custodial protocols. The result is strong visibility over the primary market and much weaker visibility over secondary circulation.
Compliance therefore leans on tools that traditional payment firms use less: blockchain analytics and address screening, clustering and attribution work, exposure scoring against known illicit services, and contract-level capability to block or freeze balances. Where a freeze capability exists, supervisors and counterparties will expect a documented governance process setting out who may invoke it, on what evidence, and how a decision is recorded and reviewed.
Supervision and Consequences
FinCEN administers the Bank Secrecy Act, while day-to-day examination is generally carried out by the relevant federal functional regulator for the institution in question. Outcomes range from supervisory findings and remediation undertakings to consent orders, civil money penalties and, where failures are wilful, criminal exposure. Programme deficiencies are frequently identified through a lookback review of historic activity, which is expensive and disruptive precisely because it is retrospective.
The Typical Build-Out
Firms newly brought into scope usually begin with a scope determination and a gap analysis against the programme elements above, then appoint the compliance officer, document the programme, and tune monitoring to on-chain typologies rather than to card or wire patterns. Governance follows: management information, board reporting, an audit plan, and a record of decisions taken. The evidence trail is what supervisors examine, so building it from the start is cheaper than reconstructing it later.
