FinCEN Leads Govt Agencies in Customer ID Rules for Stablecoin Issuers

AML stablecoins

Federal financial regulators are looking to add some know your customer (KYC) flesh to the bones of the GENIUS Act.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    yesSubscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    The Financial Crimes Enforcement Network (FinCEN), along with the Office of the Comptroller of the Currency, Federal Reserve, Federal Deposit Insurance Corp. and National Credit Union Administration, last month issued a joint Notice of Proposed Rulemaking on extending the Bank Secrecy Act’s customer identification obligations to stablecoin issuers, as called for in the landmark digital currency law.

    The joint notice would require permitted payment stablecoin issuers (PPSIs) to establish written customer identification programs modeled on those long required of banks and broker-dealers, according to a June 30 analysis by international law firm Mayer Brown. Comments on the proposal are due Aug. 21, with regulators proposing a 12-month implementation period after a final rule is issued.

    The proposal focuses specifically on the GENIUS Act’s requirement that stablecoin issuers maintain an effective customer identification program that includes identifying and verifying account holders. While companion rulemakings address broader anti-money laundering, countering the financing of terrorism and sanctions obligations, this proposal centers on how issuers must verify customer identities before establishing business relationships.

    The proposal would have its greatest impact on nonbank stablecoin issuers currently regulated primarily as money transmitters, the analysis said. Unlike banks, money transmitters generally are not subject to comprehensive customer identification program requirements, instead verifying customer identities only for certain higher-value transactions. The proposed rule would therefore impose formal customer identification obligations on many stablecoin issuers for the first time.

    The proposed framework largely mirrors existing bank customer identification rules while directing each issuer to tailor its program to its size, business model and risk profile, according to the analysis. PPSIs would be required to collect standard identifying information, including a customer’s name, physical address, date of birth or formation, and taxpayer ID or other identifying number before opening an account. They also would need risk-based procedures for documentary or non-documentary identity verification, customer notification, government watch-list screening and record retention.

    A notable feature of the proposal, per the analysis, is its narrow definition of when customer identification obligations apply. Consistent with a companion AML proposal, regulators would limit the rules to direct, primary-market relationships between an issuer and its customers, such as stablecoin issuance, redemption, conversion and custodial services. The proposal explicitly excludes purely secondary-market transactions where users interact only through smart contracts, with regulators concluding that imposing customer identification requirements on every secondary-market transfer would create an impractical global compliance obligation.

    The proposal also introduces stablecoin-specific definitions of “account” and “customer” that differ from traditional bank rules, the analysis said. Merely holding or controlling a stablecoin would not, by itself, establish a customer relationship with the issuer under the rule. Instead, a formal relationship must exist before customer identification requirements are triggered.

    One of the proposal’s most significant unresolved issues, however, involves direct redemptions, according to the analysis. Regulators acknowledge that a person could purchase a stablecoin on a secondary-market exchange and later seek to redeem it directly with the issuer despite having no previous relationship. The agencies suggest such a redemption could create a customer relationship requiring identity verification, but they have not reached a final conclusion. The analysis described this as a consequential question because it could affect onboarding obligations for issuers whose business models emphasize redemptions.

    Among the broader policy questions in the proposal is whether the “formal relationship” standard should remain the basis for determining when a customer identification obligation exists or whether another standard, such as a contractual or business relationship, would provide greater clarity, the analysis said.

    Other questions focus on whether customer identification requirements should ever extend to secondary-market activity, how digital identity technologies and verifiable credentials should be incorporated into customer verification, whether redemption-only relationships warrant special treatment, and how frequently stablecoin issuers are likely to rely on another financial institution’s customer identification program rather than conducting verification themselves, according to the analysis.

    Together with the companion AML and sanctions proposal, the customer identification rule provides prospective stablecoin issuers with a clearer picture of the Bank Secrecy Act obligations accompanying GENIUS Act compliance, the analysis said.