We’ve launched NetiRails: infrastructure for stablecoin-based cross-border paymentsExplore NetiRails

Stablecoin Compliance by Design: 7 Controls Built Into Your Stack

Stablecoin compliance by design: seven controls that build GENIUS Act, MiCA and Travel Rule obligations into your stack, with evidence a supervisor can check.

Adrianna Szymańska-Krowiak
Adrianna Szymańska-Krowiak
• October 2026
Ask AI

Opens in a new tab with this page in the prompt

ChatGPTChatGPTGeminiGeminiPerplexityPerplexityCopilotCopilotClaudeClaudeGrokGrok

In February 2023, New York's financial regulator told Paxos to stop minting BUSD. Paxos was a regulated trust company. BUSD was a regulated stablecoin, with about $16 billion in reported reserves behind it. The reserves were not the problem. The name was. The same "BUSD" also sat on a second token, on other chains, that Paxos never issued and the regulator never approved. To users, they looked like the same coin.

That is how stablecoin compliance usually fails. Not on a rule nobody had read, but in the gap between the rule and the system that is supposed to enforce it.

Stablecoin compliance is the set of obligations that let a stablecoin be issued, transferred and redeemed lawfully, plus the technical controls that prove they are met. Lawyers define the obligations. Your system enforces them on every mint, transfer and redemption, and produces the evidence when a supervisor asks.

The US GENIUS Act says it plainly: an issuer may issue payment stablecoins "only if the issuer has the technological capability to comply" with orders to seize, freeze, burn or block transfers. A statute, describing an engineering requirement.

We are engineers, not lawyers, so this guide won't tell you what the law requires of your firm. It shows the requirements, the roles you can take, and the seven controls we build so that regulated issuers, EMIs and banks can meet their obligations and prove it. It comes from building a stablecoin issuance platform, a confidential payment system and a cross-border payment operation that runs in production.

What are the core stablecoin compliance requirements?

The core requirements are licensing, 1:1 reserves, redemption, KYC and AML, sanctions screening, the Travel Rule, the ability to freeze or burn tokens, and records that reconcile supply with reserves. Most summaries stop at the first five. The last three live in your systems rather than in your policies.

  • Licensing. Under the GENIUS Act, in force no later than January 2027, an issuer must be a subsidiary of an insured bank, a federally approved nonbank issuer or, with up to $10 billion outstanding, a state-qualified issuer. In the EU, only a credit institution or an e-money institution may issue an e-money token.
  • Reserves. The GENIUS Act requires at least 1:1 backing in cash, insured deposits, Treasuries of 93 days or less, qualifying repos and government money market funds. Each month a registered public accounting firm examines the reserve report and the CEO and CFO certify it. MiCA requires segregated reserves, with at least 30% held as bank deposits.
  • Redemption. Under MiCA, at par, at any time, with no fee. The GENIUS Act requires a published redemption policy.
  • KYC, AML and sanctions. The GENIUS Act treats issuers as financial institutions under the Bank Secrecy Act. In the EU, issuers and CASPs fall under AML rules.
  • Travel Rule. In the EU, originator and beneficiary data must accompany every crypto-asset transfer between CASPs. FATF standards apply the same principle globally.
  • Freeze, burn and block. Required by the GENIUS Act to comply with lawful orders, and expected of issuers by FATF since March 2026.
  • Evidence. Not a separate rule, but what every rule above relies on: records that tie each reported number back to transactions.

Which stablecoin regulations shape the build in 2026?

The GENIUS Act and MiCA drive most design decisions, with the EU Travel Rule and FATF standards underneath.

FrameworkStatus on 1 October 2026What it means for the system
GENIUS Act, USSigned 18 July 2025. In force no later than 18 January 2027. Substantive implementing rules still proposals.Reserve-capped issuance, monthly examined reports, BSA program, freeze and burn on lawful orders
MiCA, EUStablecoin rules apply since 30 June 2024. CASP transition ended 1 July 2026.Fee-free redemption at par, no interest, segregated reserves
Transfer of Funds Regulation, EUApplies since 30 December 2024Travel Rule data on every transfer between CASPs, no minimum amount
FATF stablecoin reportPublished 3 March 2026Freeze, burn, allow-lists and deny-lists as expected issuer controls


The OCC, FinCEN and OFAC and the Federal Reserve have published GENIUS Act proposals. No substantive rule is final; the only one in force is Treasury's procedural interim final rule on certifying state regimes, effective 30 September 2026. Final rules will add reporting detail, not remove control families, so build now.

Who is responsible, and what changes with your role?

The licensed entity is always responsible. As we tell banks in our workshops: you can outsource the task, but not the responsibility. A vendor that promises to "deliver compliance" is selling something it cannot give you. For EU financial entities, DORA keeps you "fully responsible" when you use ICT providers.

What you are responsible for depends on your role. Decide it first, in a workshop where business, compliance, risk, IT and treasury agree what stablecoin, wallet and custody mean.

RoleWhat it meansWhat it adds
1. Own useSettling or moving liquidity in your own name. Cross River Bank and Lead Bank settle with Visa in USDC this way.Key security, counterparty screening
2. IntermediaryExchanging and sending stablecoins for clients, as a bank or payment companyCASP authorisation (EU banks can notify under MiCA instead); KYC, KYT and Travel Rule on every transfer
3. CustodianHolding clients' stablecoinsSegregated client assets, records per client, liability for losses (MiCA Art. 75)
4. IssuerIssuing your own stablecoinLicence, reserves, redemption, white paper; in the US, freeze and burn


Two lessons apply to every role. First, check which token you actually accept. The New York regulator said it "has not authorized Binance-Peg BUSD on any blockchain", and Paxos later agreed a $48.5 million settlement over due diligence failures tied to Binance. Accept tokens by contract address and chain, never by ticker. Second, start light. Our recommendation for a first pilot is role 1, with keys held by a licensed custody partner. Custody and issuance are programmes, not pilots.

Four stablecoin roles for banks and payment companies, from own use to issuer, and the compliance obligations each adds


The seven stablecoin compliance controls

Most of the obligations above land on one of seven controls. We use this checklist to scope regulated stablecoin systems.

#ControlEvidence it produces
1Reserve-capped mintingEvery mint refused if supply would exceed reserve
2Multi-party mint and burn approvalSigned approval trail per supply change
3Verified counterparties onlyRegister of who may mint, buy and burn
4KYT and sanctions screening before settlementScreening result stored with each transfer
5Travel Rule data linked to transfersOriginator and beneficiary data per transfer
6Freeze, burn and block with role separationLogged order, approver and on-chain action
7Reconciliation and audit trailSupply vs reserve at any moment


1. Reserve-capped minting

The platform refuses any mint that would push supply above the reserve. Proof of reserves does not have to be an oracle feed: if the platform records the reserve and controls the mint, it can enforce the cap itself.

2. Multi-party mint and burn approval

No single person or key can create or destroy money. Mints and burns need N independent signatures.

3. Verified counterparties only

Only entities that passed KYC, and hold the right licence, mint or redeem directly. New supply lands on a technical wallet first, where a distribution can still be stopped.

4. KYT and sanctions screening before settlement

Banks often ask us: if a transfer settles in 40 seconds and cannot be reversed, when do we validate it? Before settlement, in the payment path, with risk thresholds that decide whether it goes, waits or stops. A check after settlement only documents the problem. For flows that should not be public, see how ZK proofs keep payments confidential yet compliant.

5. Travel Rule data linked to transfers

The blockchain carries the value. Your system carries the identity data, matched to the transfer hash. Missing data means the transfer waits, as an explicit state, not an email. Plan time for it. With one bank, agreeing the goal, settlement in 15 minutes, took a minute. Agreeing which data moves, in what form and when, took months. Banks have done this before: ISO 20022 became mandatory on Swift on 22 November 2025 after years of agreeing one data dictionary.

6. Freeze, burn and block with role separation

FATF, citing Chainalysis, reports that stablecoins accounted for 84% of illicit virtual asset volume in 2025, and Tether has frozen about $4.2 billion. The question is who can trigger these powers. Use separate roles and keys, a logged approval, and design them up front: deployed contracts are hard to change. ERC-3643 builds freezing and on-chain whitelisting into the token, and we cover role design in our smart contract development work.

Signing is where losses happen. Attackers stole over $1.5 billion from Bybit in 2025 by compromising a wallet vendor's developer machine and altering what signers saw. The multisig worked as designed. The weak point was a third-party tool.

7. Reconciliation and audit trail

A double-entry ledger reconciles supply against reserves and partner reports daily, and evidences every correction. That turns monthly reporting into a query. This is compliance as code: the rule runs before the transaction, not in a report after it.

Seven stablecoin compliance controls grouped into issuance, transfers and evidence, with the evidence each produces


What we learned building these controls

A payments company: "One compromised key, and the reserve ratio is fiction"

A company running its own payment systems wanted its own stablecoin. "Minting a token is four lines of Solidity. That part is not the project." The risk was governance. We built issuance that "cannot issue more tokens than the fiat held in the backing account, and no oracle was needed to enforce it," with multisig on every mint and burn and KYC-verified CASPs as the only counterparties. A core team of four delivered around 80% of the business scope in about three months. Read the stablecoin infrastructure case study.

The same client: private to the market, open to the regulator

On a public chain, every payment shows the amount and the sender's balance. Mixers were off the table: "A regulated business cannot go near them." The requirement "was confidentiality, not anonymity," so we built transfers a regulator can decrypt with a view key. "The audit trail is not lost, it is encrypted." Read the confidential stablecoin payments case study or see our confidential transactions work.

Damisa: "Whose is it right now?"

Damisa, a regulated British cross-border payment company, needed to know who owns the money when a payment stops halfway. We designed KYT and Travel Rule data into the flow, separated ledgers, wallets and keys per legal entity, and made sure "every correction is evidenced, not just every transaction." The MVP went into production in December 2025. Read the Damisa case study.

None of these projects made a client compliant. Each made the client's obligations evidenceable.

Build the controls before the examiner asks

Neti designs and builds stablecoin issuance, payment orchestration and settlement systems for EMIs, banks and payment companies, and our engineers contribute to the core of the XRP Ledger. We do not give legal advice and we do not make anyone compliant. We build the controls and the evidence your compliance team needs. If you are still choosing a partner, our list of the best stablecoin development companies shows what to compare.

Working on a stablecoin project and want to check your controls? Contact us.

FAQs

Stablecoin compliance is the set of obligations that let a stablecoin be issued, transferred and redeemed lawfully, plus the technical controls that prove they are met. The licensed issuer or provider owns the obligations; its systems enforce them and produce the evidence.

Licensing, 1:1 reserves in cash and short-term government assets, redemption at par, KYC and AML programs, transaction and sanctions screening, the Travel Rule, the ability to freeze or burn tokens, and records that reconcile supply with reserves.

Yes. Issuers carry reserve, redemption and freeze obligations. Payment companies carry KYC, KYT, sanctions and Travel Rule obligations on every transfer, and must check that the token they accept is permitted. In the US, from 18 July 2028, providers may only offer stablecoins from permitted issuers.

Under the GENIUS Act, yes: issuers must be able to comply with lawful orders to seize, freeze, burn or block transfers. FATF also expects freeze and burn powers and allow-lists and deny-lists. The design challenge is limiting who can trigger them and logging every use.

Yes. In the EU, it has applied to every crypto-asset transfer between CASPs, with no minimum amount, since 30 December 2024. Identity data must travel with each transfer and stay matched to it.

They first choose their role: own use, intermediary, custodian or issuer. Each adds obligations. Then they screen with KYC, KYT and sanctions checks before settlement, keep Travel Rule data with each transfer, and supervise every provider under DORA.