GENIUS Act KYC: What Stablecoin Issuers Must Do Now
FinCEN's June 2026 proposed rule forces stablecoin issuers to build bank-grade KYC programs. Here's what the GENIUS Act means for your compliance stack.

Five US federal agencies — FinCEN, the OCC, the Federal Reserve, the FDIC, and the NCUA — released a joint notice of proposed rulemaking on June 18, 2026, rewriting the compliance obligations that apply to every stablecoin issuer operating in the United States. Docket number 2026-12460 is how the proposal entered the Federal Register on June 22. August 21, 2026 is the comment deadline.
This is no technical clarification. Classification of Permitted Payment Stablecoin Issuers (PPSIs) as financial institutions under the Bank Secrecy Act would, for the first time, force them to run Customer Identification Programs (CIP) that match commercial banks in substance.
Your onboarding stack — not a reading list for counsel — is what this proposal targets if you issue, redeem, convert, or custody a payment stablecoin in the United States.
What the GENIUS Act Set in Motion
Signed into law in 2026, the Guiding and Establishing National Innovation for US Stablecoins Act created the first federal licensing framework for payment stablecoins. Federal banking regulators and FinCEN were directed, among the Act's provisions, to treat PPSIs as financial institutions under the BSA.
That designation is not cosmetic. AML program requirements, suspicious activity reporting obligations, and — via the proposed CIP NPR — mandatory customer identification before account opening all follow from financial institution status. The CIP piece is what this proposed rulemaking implements; April 2026 saw a parallel rulemaking covering AML/CFT program and sanctions compliance requirements.
Stablecoin issuers are brought, by the two rules together, onto the same compliance baseline as the banks whose rails they sit alongside.
Four Operational Pillars of the Proposed CIP Rule
Four operational obligations form the proposed Customer Identification Program requirements for PPSIs. Mapping each of them onto the current onboarding flow is work every compliance team at a stablecoin issuer needs to do.
1. A Written CIP Policy That Is Risk-Based
A written CIP, integrated into the broader AML/CFT program, must be maintained by issuers. Risk-based is the required design: more intensive verification procedures for higher-risk customers, lighter verification for standard-risk customers — yet only inside defined limits. As risk profiles change, the written policy must be reviewed and updated.
Issuers still depending on informal onboarding processes or third-party managed flows without in-house policy documentation face a significant operational requirement here.
2. Data That Must Be Collected Before an Account Opens
Issuers must collect the following before opening an account:
| Data Element | Required |
|---|---|
| Full legal name | Yes |
| Date of birth | Yes |
| Address (residential or business) | Yes |
| Government-issued identification number | Yes |
US persons must supply a taxpayer identification number (SSN, ITIN, or EIN) as the government identification number. A passport number or equivalent foreign government-issued document number, together with the country of issuance, is what the agencies propose accepting for non-US persons.
Account opening is when this collection requirement applies. Deferring collection until after the customer has initiated transactions is not permitted under the proposed rule.
3. Verification of Identity Inside a Reasonable Time
Data collection alone does not suffice. Who the customer claims to be must be verified by issuers. Bank CIP rules supply the "reasonable time" standard the proposed rule adopts: verification has to happen before account opening or shortly after.
Documentary verification (checking identity documents), non-documentary verification (database checks, credit bureau queries, public records), or both in combination are acceptable methods. Non-documentary verification — drawing on authoritative government data sources, verifying biometrics, or running liveness detection — is the practical standard for digital-first issuers that operate without physical branches.
Stablecoin issuers operate differently from retail banks, the agencies explicitly acknowledged, and remote, automated verification methods are expected to be the norm.
4. Recordkeeping, Screening Against Government Lists, and Customer Notice
The proposed rule, beyond collection and verification, also requires:
- Recordkeeping: Five years after account closure is how long CIP records must be retained.
- Government list screening: Screening customers against lists designated for CIP purposes is mandatory, which in practice means OFAC sanctions lists at minimum.
- Customer notice: Customers must be informed by issuers that identity information will be collected and verified for CIP purposes.
- Reliance: Other federally regulated financial institutions may perform CIP functions for issuers, provided a formal reliance agreement is in place.
Issuers that distribute through regulated intermediaries or custody providers will find the reliance provision operationally important. CIP work performed by the intermediary can be relied upon by the issuer — yet the reliance agreement must be documented, and ultimate responsibility stays with the issuer if the intermediary fails.
What the Secondary Market Carve-Out Leaves Out
Secondary market activity is what the proposed rule does not cover — among its most significant scoping decisions.
CIP obligations are explicitly limited by the proposal to primary market relationships: situations in which the PPSI has a direct relationship with a customer through issuing, redeeming, converting, repurchasing, burning, reissuing, or providing custodial services. An account relationship that triggers CIP requirements is not created, by itself, merely by owning or controlling a stablecoin in a secondary market transaction.
Interactions with smart contracts on secondary markets do not trigger CIP obligations either, the agencies also proposed — even when the issuer's stablecoin is the underlying asset. That point is critical.
Decentralized exchange activity gets meaningful relief from this. Every wallet that holds or trades an issuer's stablecoin on a secondary platform does not need to be KYC'd. Only a direct, intentional customer relationship carries the obligation.
Read this carefully, though, if you sit on a compliance team. Custodial services, mint/redeem portals, or direct-to-consumer distribution operated by an issuer — even through a third party — remain primary market activity and sit within scope.
Why Deadlines Shape the Work
June 22, 2026 is when the proposal published. August 21, 2026 is when comments close. Twelve months after publication is when any final rule would become effective, under the agencies' proposal — so the realistic compliance deadline sits in early-to-mid 2027.
Appearances overstate how generous that twelve-month runway is. Six to nine months minimum is what building a compliant CIP from scratch — documented policy, integrated verification systems, OFAC screening, recordkeeping infrastructure — takes for a mid-sized issuer. Scrambling is what awaits organizations that start only after the final rule publishes.
Nor is the comment period a delay. Months of inter-agency coordination after the GENIUS Act's passage are reflected in the proposed rule. Technical parameters are what the comment period exists to refine; the fundamental requirement is not up for reconsideration. Treating the NPR stage as "just a proposal" and waiting for finality is a material compliance risk for issuers.
How the Crypto KYC Landscape Shifts
Broader crypto compliance has already tightened significantly by the moment the GENIUS Act CIP rule arrives. Verified identity data on every crypto transfer, with no minimum threshold, became mandatory when the MiCA Travel Rule took full effect for EU-registered CASPs earlier this year. Correspondent relationship rules for crypto firms were extended by the UK's MLR amendments, effective June 30. Our State of KYC in Crypto 2026 report maps how these obligations stack.
A domestic KYC mandate at the issuer level now exists, for the first time, in the world's largest stablecoin market — that is the new dimension the US rule adds. A patchwork of state money transmitter licenses with inconsistent identity verification requirements is what US stablecoin issuers previously operated under. That patchwork is replaced with a uniform standard by the federal floor the GENIUS Act and the proposed CIP rule create.
Dual-jurisdiction CIP compliance is now necessary for issuers operating in both the EU and the US. Core data elements, fortunately, look similar. Name, date of birth, address, and government identification number are required by both the EU's AMLR framework and the proposed US CIP rule. One flow can satisfy both requirements if verification infrastructure is well-designed — but only when the right data fields are collected and retained from the start.
A retroactive compliance gap now sits with issuers that built lightweight onboarding in earlier years — minimal data collection, no formal verification policy. Re-verification of existing account holders who do not meet the new standard is typically mandated by a CIP requirement, unlike a new regulatory requirement that applies only to future customers. Remediating an existing customer base that was never properly KYC'd costs far more operationally than building it correctly the first time.
Fraud Risk as the Driver of the Rule
Pure bureaucracy is not the regulatory logic behind the CIP rule. AI-enabled fraud losses in the United States will reach $40 billion annually by 2027, Deloitte's Center for Financial Services projects, up from $12.3 billion in 2023. Approximately 1 in 20 verification attempts are now being flagged by banks as potentially fraudulent. AI-generated synthetic identities — including AI-generated documents, voice clones, and deepfake video — now figure in more than 50% of fraud attempts.
Weaker identity controls than banks have historically left stablecoin issuers a predictable target. A fraudster, without mandatory CIP, can acquire stablecoins from a primary issuer using a synthetic identity, convert them to other assets, and leave the regulated perimeter before detection. That gap is what the proposed rule closes.
FATF's July 2026 typologies report documented the scale of the underlying risk: stablecoins now account for 84% of all illicit virtual asset transaction volume globally — $154 billion laundered in 2025 alone. That finding cannot be separated from the regulatory logic behind the GENIUS Act CIP rule. Full analysis: FATF's stablecoin money laundering findings and what CASPs must do.
Detection efficacy, not merely regulatory form, is also what the fraud environment demands of CIP compliance. Collecting a name and government ID without verifying document authenticity, checking biometric liveness, or screening against adverse media yields legal cover but minimal fraud protection. Our article on synthetic identity fraud and the KYC response walks through the mechanics of what happens when verification systems fail.
Technical Capabilities Required for Compliance
Identity infrastructure with several specific capabilities — capabilities many stablecoin issuers currently lack — is needed to meet the proposed CIP rule.
Document verification: Government-issued identity documents must be authenticable by the issuer. Document databases, forensic image analysis, and the ability to detect AI-generated or manipulated documents are required — a growing problem, given that AI-generated fake IDs are now commercially available.
Biometric liveness detection: Linking a document to the customer presenting it, for remote verification, practically means biometric matching against a selfie or video plus liveness detection that rules out a replay attack or deepfake. Injection attacks that bypass the camera layer entirely must be something liveness detection can withstand.
OFAC screening: Screening against OFAC's Specially Designated Nationals list, plus other government lists as designated, is required in real time or near-real-time, both at onboarding and on an ongoing basis.
Automated case management: Human review of every case is not operationally viable given the onboarding volume of a stablecoin issuer with mass adoption. Scale without proportionally scaling headcount is increasingly handled by compliant issuers through Agentic KYC — AI systems that automate verification, risk scoring, and case routing.
Audit trails: Structured data management is required by five-year record retention. Data collected, the method and result of verification, and the date must sit in each CIP record.
Open Questions During the Comment Period
August 21, 2026 is when the comment period closes. Significant comment is likely on several open questions in the proposed rule:
- Timing of verification: Ambiguity around the "reasonable time" standard for post-opening verification has persisted in bank CIP rules for decades. Clearer timelines for stablecoin-specific flows are likely to be a push from commenters.
- Non-US persons: A passport number or equivalent for non-US natural persons is required by the proposed rule. Practical application remains unclear for institutional customers from jurisdictions with different documentation norms.
- Beneficial ownership: Beyond what existing regulations already require, the proposed rule does not impose beneficial ownership requirements for legal entity customers. Whether this gap will eventually be closed by GENIUS Act regulations remains an open question.
- Interoperability with state regimes: Explicit clarity on when federal CIP compliance satisfies state requirements and vice versa has been requested by issuers already subject to state money transmitter CIP requirements.
The comment period is also an opportunity for compliance teams building their response. Substantive technical comments are taken seriously by agencies, and what the industry submits will shape how verification requirements are operationalized in the final rule.
FAQ
Does the GENIUS Act CIP rule apply to all stablecoin issuers?
No. Permitted Payment Stablecoin Issuers — entities holding a federal license or approval under the GENIUS Act framework to issue payment stablecoins — are the ones it covers. This specific proposed rule does not directly cover issuers operating under state regimes, or entities that have not sought GENIUS Act authorization, though similar requirements may still apply under other regulatory frameworks.
When will the rule become final and effective?
August 21, 2026 is when comments close. A final rule will be published by agencies after comments are reviewed. A twelve-month implementation period after the final rule is published is provided for in the proposal, so mid-to-late 2027 at the earliest is the likely effective date — though how quickly the agencies move to finalize will determine that.
Does the rule cover decentralized stablecoin protocols?
Entities that act as PPSIs under the GENIUS Act are the scope of the rule. Coverage is not straightforward for purely decentralized protocols with no identifiable issuer entity. Any entity performing issuing, redeeming, or custodying functions, however — even through a DAO wrapper — may find regulators treating them as a functional PPSI.
What happens to secondary market activity?
Buying and selling stablecoins on exchanges or through smart contracts — secondary market trading — is explicitly excluded from the proposed CIP scope. Direct relationship between the issuer and the account holder is where the rule applies, not a secondary transaction in which the issuer's token changes hands.
Can an issuer rely on a third-party KYC provider for CIP compliance?
Yes. A reliance provision sits in the proposed rule: other federally regulated financial institutions may perform CIP functions for issuers, provided a written agreement is in place. Ultimate responsibility for CIP compliance remains with the issuer, even when a third party is relied upon.
What data does the rule require issuers to collect?
Natural person customers: full legal name, date of birth, residential address, and government-issued identification number. Legal entity customers: entity name, principal place of business address, and taxpayer identification number or equivalent.
Related Articles

EU AI Act August 2026: What It Means for Your KYC Stack
The EU AI Act's August 2 deadline activates high-risk AI rules. Here is what the biometric verification exemption really means for your KYC compliance stack.

EU Digital Omnibus: What the AI Act Delay Means for KYC
The EU Digital Omnibus entered into force July 27, extending high-risk AI deadlines to December 2027. Here is what it means for your KYC compliance stack.

EU AI Act Article 50: Deepfake Rules Live—KYC Impact
EU AI Act Article 50 entered force on 2 August 2026. Here's what the deepfake disclosure mandate means for KYC compliance and fraud defence.