In a Friday (Aug. 21) comment letter, the digital-asset trade group broadly endorsed proposed rules requiring permitted payment stablecoin issuers to maintain customer identification programs, or CIPs, comparable to those used by banks and other financial institutions under the Bank Secrecy Act.
But the association said the final rules must clearly limit those requirements to primary-market relationships in which an issuer deals directly with a customer, warning that extending customer-identification requirements to downstream wallet transfers could “cripple the industry.” The rules should not cover secondary-market transfers between third-party wallets that an issuer does not intermediate, facilitate or approve, the group said.
The joint proposal was issued by the Financial Crimes Enforcement Network (FinCEN), Office of the Comptroller of the Currency (OCC), Federal Reserve, Federal Deposit Insurance Corporation (FDIC) and National Credit Union Administration. It implements a provision of the GENIUS Act requiring permitted issuers to verify the identities of their account holders.
The association supports the agencies’ decision to define an “account” around the existence of a formal relationship between an issuer and a customer. That approach applies identity checks at centralized points where an issuer exercises operational control, including issuance, fiat conversion, reserve management and some redemptions.
Downstream transfers work differently, the group argued. Once stablecoins have entered circulation, users can transfer them directly from one wallet to another without the issuer’s involvement. A sender signs and broadcasts a transaction, distributed validators confirm it and a smart contract executes predetermined code.
We’d love to be your preferred source for news.
Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!
In that process, an issuer may have no contractual relationship with either party, no custody over the stablecoins and no ability to identify or perform real-time KYC checks on the wallet holders. The issuer generally cannot approve or block a transaction before settlement merely because its smart contract is involved.
The GENIUS Act itself requires issuers to verify “account holders with the permitted payment stablecoin issuer,” the association noted. It does not, in the group’s view, authorize regulators to make an issuer responsible for identifying every person who subsequently holds or transfers its tokens.
The regulators acknowledged in the proposal that applying CIP requirements to every transfer could create “nearly impossible” and “global” obligations that could indeed “cripple the industry.” Although the proposal excludes secondary-market activity, the agencies asked whether the final rule should go further, making preservation of that exclusion a central issue in the rulemaking.
The association also wants sharper definitions around other interactions that should not create an account relationship. It said CIP rules should exclude one-time redemption requests, redemptions processed through another regulated financial institution, data-processing and transmission services, vendor relationships and other commercial partnerships.
Companies that issue stablecoins while also operating as digital-asset service providers should not have their unrelated exchange, transfer or custody activities pulled into the issuer-specific rule, it added. Those businesses may already be subject to separate Bank Secrecy Act requirements, creating a risk of duplicative compliance.
The letter also seeks a liability safeguard for issuers that reasonably rely on customer identification conducted by federally regulated financial institutions. An issuer should not automatically be responsible if the institution performing the check fails to satisfy its own obligations, the association said.
Finally, the association urged regulators to align the rule’s effective date with forthcoming FinCEN and Office of Foreign Assets Control requirements covering anti-money laundering, terrorist-financing and sanctions compliance. Staggered deadlines, it warned, could force issuers to rebuild the same compliance systems repeatedly.
The association’s underlying message is that stablecoin regulation should follow control. KYC obligations are workable when attached to direct customer relationships, but extending them across decentralized wallet activity could turn issuers into compliance gatekeepers for transactions they neither see nor control.