In February 2023, New York's financial regulator told Paxos to stop minting BUSD. Paxos was a regulated trust company. BUSD was a regulated stablecoin, with about $16 billion in reported reserves behind it. The reserves were not the problem. The name was. The same "BUSD" also sat on a second token, on other chains, that Paxos never issued and the regulator never approved. To users, they looked like the same coin.
That is how stablecoin compliance usually fails. Not on a rule nobody had read, but in the gap between the rule and the system that is supposed to enforce it.
Stablecoin compliance is the set of obligations that let a stablecoin be issued, transferred and redeemed lawfully, plus the technical controls that prove they are met. Lawyers define the obligations. Your system enforces them on every mint, transfer and redemption, and produces the evidence when a supervisor asks.
The US GENIUS Act says it plainly: an issuer may issue payment stablecoins "only if the issuer has the technological capability to comply" with orders to seize, freeze, burn or block transfers. A statute, describing an engineering requirement.
We are engineers, not lawyers, so this guide won't tell you what the law requires of your firm. It shows the requirements, the roles you can take, and the seven controls we build so that regulated issuers, EMIs and banks can meet their obligations and prove it. It comes from building a stablecoin issuance platform, a confidential payment system and a cross-border payment operation that runs in production.
What are the core stablecoin compliance requirements?
The core requirements are licensing, 1:1 reserves, redemption, KYC and AML, sanctions screening, the Travel Rule, the ability to freeze or burn tokens, and records that reconcile supply with reserves. Most summaries stop at the first five. The last three live in your systems rather than in your policies.
- Licensing. Under the GENIUS Act, in force no later than January 2027, an issuer must be a subsidiary of an insured bank, a federally approved nonbank issuer or, with up to $10 billion outstanding, a state-qualified issuer. In the EU, only a credit institution or an e-money institution may issue an e-money token.
- Reserves. The GENIUS Act requires at least 1:1 backing in cash, insured deposits, Treasuries of 93 days or less, qualifying repos and government money market funds. Each month a registered public accounting firm examines the reserve report and the CEO and CFO certify it. MiCA requires segregated reserves, with at least 30% held as bank deposits.
- Redemption. Under MiCA, at par, at any time, with no fee. The GENIUS Act requires a published redemption policy.
- KYC, AML and sanctions. The GENIUS Act treats issuers as financial institutions under the Bank Secrecy Act. In the EU, issuers and CASPs fall under AML rules.
- Travel Rule. In the EU, originator and beneficiary data must accompany every crypto-asset transfer between CASPs. FATF standards apply the same principle globally.
- Freeze, burn and block. Required by the GENIUS Act to comply with lawful orders, and expected of issuers by FATF since March 2026.
- Evidence. Not a separate rule, but what every rule above relies on: records that tie each reported number back to transactions.
Which stablecoin regulations shape the build in 2026?
The GENIUS Act and MiCA drive most design decisions, with the EU Travel Rule and FATF standards underneath.
| Framework | Status on 1 October 2026 | What it means for the system |
|---|---|---|
| GENIUS Act, US | Signed 18 July 2025. In force no later than 18 January 2027. Substantive implementing rules still proposals. | Reserve-capped issuance, monthly examined reports, BSA program, freeze and burn on lawful orders |
| MiCA, EU | Stablecoin rules apply since 30 June 2024. CASP transition ended 1 July 2026. | Fee-free redemption at par, no interest, segregated reserves |
| Transfer of Funds Regulation, EU | Applies since 30 December 2024 | Travel Rule data on every transfer between CASPs, no minimum amount |
| FATF stablecoin report | Published 3 March 2026 | Freeze, burn, allow-lists and deny-lists as expected issuer controls |
The OCC, FinCEN and OFAC and the Federal Reserve have published GENIUS Act proposals. No substantive rule is final; the only one in force is Treasury's procedural interim final rule on certifying state regimes, effective 30 September 2026. Final rules will add reporting detail, not remove control families, so build now.
Who is responsible, and what changes with your role?
The licensed entity is always responsible. As we tell banks in our workshops: you can outsource the task, but not the responsibility. A vendor that promises to "deliver compliance" is selling something it cannot give you. For EU financial entities, DORA keeps you "fully responsible" when you use ICT providers.
What you are responsible for depends on your role. Decide it first, in a workshop where business, compliance, risk, IT and treasury agree what stablecoin, wallet and custody mean.
| Role | What it means | What it adds |
|---|---|---|
| 1. Own use | Settling or moving liquidity in your own name. Cross River Bank and Lead Bank settle with Visa in USDC this way. | Key security, counterparty screening |
| 2. Intermediary | Exchanging and sending stablecoins for clients, as a bank or payment company | CASP authorisation (EU banks can notify under MiCA instead); KYC, KYT and Travel Rule on every transfer |
| 3. Custodian | Holding clients' stablecoins | Segregated client assets, records per client, liability for losses (MiCA Art. 75) |
| 4. Issuer | Issuing your own stablecoin | Licence, reserves, redemption, white paper; in the US, freeze and burn |
Two lessons apply to every role. First, check which token you actually accept. The New York regulator said it "has not authorized Binance-Peg BUSD on any blockchain", and Paxos later agreed a $48.5 million settlement over due diligence failures tied to Binance. Accept tokens by contract address and chain, never by ticker. Second, start light. Our recommendation for a first pilot is role 1, with keys held by a licensed custody partner. Custody and issuance are programmes, not pilots.

The seven stablecoin compliance controls
Most of the obligations above land on one of seven controls. We use this checklist to scope regulated stablecoin systems.
| # | Control | Evidence it produces |
|---|---|---|
| 1 | Reserve-capped minting | Every mint refused if supply would exceed reserve |
| 2 | Multi-party mint and burn approval | Signed approval trail per supply change |
| 3 | Verified counterparties only | Register of who may mint, buy and burn |
| 4 | KYT and sanctions screening before settlement | Screening result stored with each transfer |
| 5 | Travel Rule data linked to transfers | Originator and beneficiary data per transfer |
| 6 | Freeze, burn and block with role separation | Logged order, approver and on-chain action |
| 7 | Reconciliation and audit trail | Supply vs reserve at any moment |
1. Reserve-capped minting
The platform refuses any mint that would push supply above the reserve. Proof of reserves does not have to be an oracle feed: if the platform records the reserve and controls the mint, it can enforce the cap itself.
2. Multi-party mint and burn approval
No single person or key can create or destroy money. Mints and burns need N independent signatures.
3. Verified counterparties only
Only entities that passed KYC, and hold the right licence, mint or redeem directly. New supply lands on a technical wallet first, where a distribution can still be stopped.
4. KYT and sanctions screening before settlement
Banks often ask us: if a transfer settles in 40 seconds and cannot be reversed, when do we validate it? Before settlement, in the payment path, with risk thresholds that decide whether it goes, waits or stops. A check after settlement only documents the problem. For flows that should not be public, see how ZK proofs keep payments confidential yet compliant.
5. Travel Rule data linked to transfers
The blockchain carries the value. Your system carries the identity data, matched to the transfer hash. Missing data means the transfer waits, as an explicit state, not an email. Plan time for it. With one bank, agreeing the goal, settlement in 15 minutes, took a minute. Agreeing which data moves, in what form and when, took months. Banks have done this before: ISO 20022 became mandatory on Swift on 22 November 2025 after years of agreeing one data dictionary.
6. Freeze, burn and block with role separation
FATF, citing Chainalysis, reports that stablecoins accounted for 84% of illicit virtual asset volume in 2025, and Tether has frozen about $4.2 billion. The question is who can trigger these powers. Use separate roles and keys, a logged approval, and design them up front: deployed contracts are hard to change. ERC-3643 builds freezing and on-chain whitelisting into the token, and we cover role design in our smart contract development work.
Signing is where losses happen. Attackers stole over $1.5 billion from Bybit in 2025 by compromising a wallet vendor's developer machine and altering what signers saw. The multisig worked as designed. The weak point was a third-party tool.
7. Reconciliation and audit trail
A double-entry ledger reconciles supply against reserves and partner reports daily, and evidences every correction. That turns monthly reporting into a query. This is compliance as code: the rule runs before the transaction, not in a report after it.

What we learned building these controls
A payments company: "One compromised key, and the reserve ratio is fiction"
A company running its own payment systems wanted its own stablecoin. "Minting a token is four lines of Solidity. That part is not the project." The risk was governance. We built issuance that "cannot issue more tokens than the fiat held in the backing account, and no oracle was needed to enforce it," with multisig on every mint and burn and KYC-verified CASPs as the only counterparties. A core team of four delivered around 80% of the business scope in about three months. Read the stablecoin infrastructure case study.
The same client: private to the market, open to the regulator
On a public chain, every payment shows the amount and the sender's balance. Mixers were off the table: "A regulated business cannot go near them." The requirement "was confidentiality, not anonymity," so we built transfers a regulator can decrypt with a view key. "The audit trail is not lost, it is encrypted." Read the confidential stablecoin payments case study or see our confidential transactions work.
Damisa: "Whose is it right now?"
Damisa, a regulated British cross-border payment company, needed to know who owns the money when a payment stops halfway. We designed KYT and Travel Rule data into the flow, separated ledgers, wallets and keys per legal entity, and made sure "every correction is evidenced, not just every transaction." The MVP went into production in December 2025. Read the Damisa case study.
None of these projects made a client compliant. Each made the client's obligations evidenceable.
Build the controls before the examiner asks
Neti designs and builds stablecoin issuance, payment orchestration and settlement systems for EMIs, banks and payment companies, and our engineers contribute to the core of the XRP Ledger. We do not give legal advice and we do not make anyone compliant. We build the controls and the evidence your compliance team needs. If you are still choosing a partner, our list of the best stablecoin development companies shows what to compare.
Working on a stablecoin project and want to check your controls? Contact us.


