Lifestyle

FinCEN and OFAC's Joint AML and Sanctions Compliance Proposal for Stablecoin Issuers, Not Yet in Effect

On April 10, 2026 a joint FinCEN and OFAC proposed rule, from two U.S. Treasury agencies, was published in the Federal Register (91 FR 18582). From the full text, FinCEN's fact sheet, the Treasury release and the Federal Register's docket lookup, this article sets out how the proposal would bring permitted payment stablecoin issuers under the Bank Secrecy Act, the four AML program requirements, the $5,000 suspicious activity reporting threshold, and OFAC's proposed sanctions compliance program.

About 16 min read

Original illustration: coins run left to right along a track, with a padlocked shield checkpoint in the middle; a dotted line below it leads down to one stopped coin, beside a warning triangle
Image: Mokaair (© Mokaair)

On April 10, 2026 the U.S. Federal Register published a proposed rule. The Financial Crimes Enforcement Network (FinCEN) and the Office of Foreign Assets Control (OFAC), both within the Department of the Treasury, jointly propose bringing permitted payment stablecoin issuers (PPSIs) under the anti-money laundering and sanctions compliance requirements of the Bank Secrecy Act (BSA). The document is cited as 91 FR 18582, with Docket No. FINCEN-2026-0100 and RIN 1506-AB73. It was signed and announced on April 8, filed for public inspection on April 9, and published on April 10, which is also the day the comment period began.

This article was checked on September 17, 2026, working from the official Federal Register full-text PDF on govinfo, FinCEN's fact sheet, the Treasury press release of April 8, and the Federal Register's official document lookup that lists the documents filed under this docket number. We have not tested anything ourselves, and this is not investment or legal advice. Every requirement set out below is what the proposal would impose, and none of it is in effect; where the document says nothing, this article says the proposal says nothing.

What this proposal is: two agencies, one proposal, three parts of the regulations

Both proposing agencies sit within the Treasury, and this is one joint proposal. It would touch three places in the regulations: OFAC would add a new 31 CFR part 502, and FinCEN would amend part 1010 and add a new part 1033. FinCEN proposes exercising its 31 U.S.C. 5312(a)(2)(Y) authority to define PPSIs expressly as financial institutions under the BSA, while carving them out of the definition of money services business (MSB); stablecoin issuers today are regulated as money transmitters. According to FinCEN's fact sheet, the proposal would also amend four existing definitions and add nine new definitions.

The legal basis is the GENIUS Act, which the proposal states was enacted on July 18, 2025. The status is proposed: the comment deadline printed in the DATES section is June 9, 2026, the proposal does not say when it will be finalized, and it only proposes that the final rules become effective 12 months after issuance. A search of the Federal Register's official document lookup by this docket number returned only this one proposal as of September 17, 2026, with no final rule found. Under footnote 111, the customer identification program is left to a separate rulemaking.

Who supervises and who examines: FinCEN, OFAC and the four prudential regulators

On the division of labor, FinCEN handles the BSA programs, reports and records, and OFAC handles the sanctions compliance program. Examination authority would be delegated to the federal agency that examines the same entity for safety and soundness. The proposal notes that under the GENIUS Act the primary Federal payment stablecoin regulators are the Office of the Comptroller of the Currency (OCC), the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation (FDIC) and the National Credit Union Administration (NCUA); for issuers that no such agency examines, the proposal would have the Internal Revenue Service (IRS) examine them under the existing 1010.810(b)(8).

Those are mostly state-qualified issuers: on the proposal's account of the GENIUS Act, an issuer with a consolidated total outstanding issuance of not more than $10 billion may generally opt to stay under a state-level regime substantially similar to the federal framework, while one above that threshold has to move into the federal framework or obtain a waiver. The proposal also sets out an enforcement policy: except for a significant or systemic failure to implement the program, an issuer that has established a program under the proposed 1033.210(b) would not face FinCEN enforcement under the proposed 1033.210 — but the proposal says these enforcement requirements do not affect criminal enforcement liability under the BSA.

From the joint FinCEN and OFAC proposal (91 FR 18582), checked on September 17, 2026. Every row but the IRS one, which cites an existing provision, is proposed and not in effect.
ItemWho the proposal would make responsibleBasis
AML program, suspicious activity reportsFinCENProposed 31 CFR 1033
Sanctions compliance programOFACProposed 31 CFR 502
Examination of federally regulated issuersOCC, the Federal Reserve Board, FDIC, NCUAProposed 1010.810(b)
Examination of all other issuersInternal Revenue ServiceThe existing 1010.810(b)(8)
Customer identification programA separate rulemakingFootnote 111 of this document

The AML program: the four requirements the proposed provision numbers

The proposed 1033.210 splits "effective" into two halves: establishing a program under (b), and maintaining it by implementing it in all material respects under (c). The first requirement is risk-based internal policies, procedures and controls. The risk assessment would have to evaluate the risks of the issuer's business activities, review and, as appropriate, incorporate the AML/CFT Priorities, and be updated promptly upon any change the issuer knows or has reason to know significantly changes its risks. Next comes mitigating those risks, and the approach the proposal offers as an example is devoting more attention and resources to higher-risk customers and activities than to lower-risk ones. Third is ongoing customer due diligence.

The second requirement is independent testing. The provision reads as establishing independent AML/CFT program testing to be conducted by the issuer's own personnel or by an outside party, rather than as a requirement to set up an audit function; the preamble adds that an issuer that employs no outside auditors or consultants and has no internal audit department may comply by using internal staff who are not involved in the function being tested. The third is designating an officer: located in the United States, accessible to and subject to oversight by FinCEN, responsible for establishing and implementing the program and for coordinating the monitoring of day-to-day compliance, and not convicted of a felony offense involving insider trading, embezzlement, cybercrime, money laundering, financing of terrorism or financial fraud. The fourth is an ongoing employee training program.

The program would have to be written and approved by the issuer's board of directors, an equivalent governing body within the issuer, or appropriate senior management, with a copy provided at FinCEN's request; the issuer would also have to provide, on request, any and all certifications it has submitted to its regulator stating that it has implemented an AML/CFT program.

A four-panel diagram: named a financial institution, AML program, reports and records, sanctions compliance
Four layers of requirements: named a financial institution, AML program, reports and records, sanctions compliance. Source: the joint FinCEN and OFAC proposal (91 FR 18582), check date September 17, 2026. · Image: Mokaair (© Mokaair)

Blocking, freezing and lawful orders: two obligations that reach the secondary market

The first half of the proposed 1033.240 would require issuers to have the technical capabilities, policies and procedures to block, freeze and reject specific or impermissible transactions that violate federal or state laws, rules or regulations, and those capabilities, policies and procedures would have to account for transactions occurring by, at or through the issuer, as well as transactions by third parties, including where a transaction results in an interaction with the issuer's smart contract. The second half would require issuers both to have the technical capabilities to comply with the terms of any lawful order and to comply with those terms. The proposed definition confines a lawful order to a final and valid writ, process, order, rule, decree, command or other requirement issued or promulgated under federal law by a court of competent jurisdiction or by an authorized federal agency pursuant to its statutory authority, and it has to meet three requirements at once: it requires the issuer to seize, freeze, burn or prevent the transfer of payment stablecoins it issued; it specifies the payment stablecoins or accounts subject to blocking with reasonable particularity; and it is subject to judicial or administrative review or appeal as provided by law. The proposal says both obligations would apply to the secondary market, and that both are imposed on issuers directly by the GENIUS Act.

The proposal does not prescribe how that capability is to be built, and it would not require an issuer to make an independent determination that a given transaction is unlawful: when the capability is used is decided by other federal or state laws, rules and regulations and by court orders. The line between the primary and secondary markets is one the proposal draws for this rulemaking: an issuer interacting directly with a user or holder is the primary market (the examples the proposal gives include issuing, redeeming and burning), and activity that does not directly involve the issuer as a party to the transaction other than via a smart contract is the secondary market.

The suspicious activity reporting threshold in the proposed 1033.320 is a transaction that involves or aggregates at least $5,000. A suspicious activity report (SAR) would be due within 30 calendar days after initial detection; where no suspect is identified on the day of detection, the issuer could take an additional 30 calendar days to identify one, but in no case could reporting be delayed more than 60 calendar days after that initial detection. The currency transaction report threshold is transactions in currency of more than $10,000 during a single business day, but the proposal explains that the definition of currency there does not include a payment stablecoin; the Recordkeeping Rule for funds transfers of $3,000 or more and the Travel Rule would apply as well. FinCEN, for its part, is not proposing to require secondary market monitoring as part of the AML program, nor to require suspicious activity reporting for secondary market transactions.

The sanctions compliance program, and what the proposal has not yet sorted out

OFAC's new part 502 would set five minimum elements for a sanctions compliance program: senior management and organizational commitment, risk assessment, internal controls, testing and auditing, and training. The internal controls would have to be risk-based and applicable to all payment stablecoin-related activity, whether on the primary or the secondary market, and would have to identify any payment stablecoin-related activity that is or may be prohibited by U.S. sanctions, block or reject, as applicable, any such activity that violates or would violate U.S. sanctions, provide reports to OFAC as required, and retain records. The proposal says that sanctions screening should, at a minimum, include tools sufficient to identify and block transactions associated with digital currency addresses included on OFAC's Specially Designated Nationals and Blocked Persons List (SDN List), but it does not specify any tool or software.

The penalties sit in the proposed 502.401: an issuer that materially violates the requirement to maintain an effective sanctions compliance program would be liable for a civil penalty of not more than $100,000 for each day during which the violation continues, and one that knowingly violates it — knowingly being defined in the proposal to mean that a person has actual knowledge, or should have known — would be liable for an additional civil penalty of not more than $100,000 for each such day. The proposal says this is consistent with the GENIUS Act's penalties, and says that the GENIUS Act's sanctions compliance program requirement represents the first time federal law has explicitly mandated that a particular U.S. person have an effective sanctions compliance program — which is an agency's own account of the novelty of its own statute.

The proposal is internally inconsistent in several places, and this article prints two of them side by side as the source has them. The first is a citation: the preamble reads 31 CFR 1022.220(a)(2), while the proposed provision 1010.230(b)(2) reads 1020.220(a)(2). The second is that the preamble says FinCEN is not proposing to apply to these issuers 1010.630, which prohibits correspondent accounts for foreign shell banks, or 1010.670, which relates to summons and subpoenas on foreign banks, yet the proposed text still carries a 1033.630 that points to 1010.630, so this article does not assert that the shell bank prohibition applies. What this proposal covers is issuers established and permitted in the United States, not holders, and the document does not mention Taiwan.

Frequently asked questions

Is this proposal in effect now?

No. The ACTION section reads Joint proposed rule, and the comment deadline printed in the DATES section was June 9, 2026. The proposal does not say when it will be finalized; it only proposes that each agency's own final rule become effective 12 months after the final rules are issued, and it asks for comment on that timing. A search of the Federal Register's official document lookup by Docket No. FINCEN-2026-0100 returned, as of this article's check date of September 17, 2026, only this one proposal of April 10, 2026, categorized as a proposed rule, with no final rule.

Does this reach the stablecoins I hold?

The proposal's obligations all fall on issuers rather than on holders, and the document says nothing about what an ordinary user has to do. The proposal also says that because the GENIUS Act framework is not yet in place, it is not yet determined which specific stablecoins will be payment stablecoins and which specific issuers will be permitted payment stablecoin issuers, so it does not identify any company as such an issuer. Company names and ticker symbols do appear in its footnotes, but as parties to the Department of Justice forfeiture cases it cites, not as issuers it has identified. This article likewise names no one and compares no one.

Can an issuer really freeze or burn stablecoins?

The proposal would require issuers to have the technical capabilities to block, freeze and reject specific or impermissible transactions that violate federal or state law, and both to have the technical capabilities to comply with lawful orders and to comply with them. The proposed definition of a lawful order has to satisfy three requirements at once: it requires the issuer to seize, freeze, burn or prevent the transfer of payment stablecoins it issued; it specifies the payment stablecoins or accounts subject to blocking with reasonable particularity; and it is subject to judicial or administrative review or appeal as provided by law. When the capability is used is not for the issuer to decide: the proposal would not require an issuer to determine on its own whether a transaction is unlawful, and says other federal or state laws and court orders decide that. FinCEN also says some issuers are currently able to do these things by programming their stablecoin's smart contracts.

What is the $5,000 threshold?

It is the proposed suspicious activity reporting threshold, meaning a transaction that involves or aggregates at least $5,000. The proposal explains that this is higher than the $2,000 threshold that applies to stablecoin issuers today as money services businesses, and the reasons it gives include that this is the threshold it uses for the types of institutions that must maintain a customer identification program, that primary market transactions below $5,000 are uncommon, and that this ecosystem has no transmitter-and-agent relationship. Separately, the $10,000 currency transaction report threshold does not cover transactions in the stablecoin itself.

Is the citation 1022.220 or 1020.220?

The preamble reads 31 CFR 1022.220(a)(2) and calls it the customer identification program rule for banks, while the proposed provision 1010.230(b)(2) reads 1020.220(a)(2). Comparing the full text we obtained on our check date, 1022.220 appears once and 1020.220 appears four times; those two counts are ours, not figures the document prints. This article prints both readings, picks neither one for the source, and does not correct it on the source's behalf; if you cite the document, it is worth writing the discrepancy out alongside.

How do I check the current status of this docket myself?

Search the Federal Register site by Docket No. FINCEN-2026-0100 or RIN 1506-AB73 and see how many documents are listed under it and whether their category is a proposed or a final rule; what this article used is the Federal Register's official document lookup by docket number, which returns a count and the category of each document. For the full text, the Federal Register PDF is on the U.S. Government Publishing Office's govinfo site, and page 18582 is its first page. FinCEN's fact sheet is the official summary of the same proposal and is easier to read than the full text, but for the detail the full text governs.

  • Lifestyle

    The OCC's Proposed Stablecoin Rules: One-to-One Reserves, Redemption in Two Business Days and Periodic Reporting

    On March 2, 2026 the U.S. Office of the Comptroller of the Currency published a proposed rule on payment stablecoins implementing the GENIUS Act in the Federal Register, cited as 91 FR 10202 and running to 102 pages, with comments due by May 1, 2026. Working from the Federal Register full text and the public law text of the GENIUS Act, this article sets out whom the new 12 CFR part 15 would reach, what it would require on reserves and redemption, and why it is not yet a rule in force.

  • Lifestyle

    FDIC Stablecoin Proposal: Reserve Deposits Insured to the Issuer, Not Passed Through to Holders

    On April 7, 2026 the board of the U.S. Federal Deposit Insurance Corporation (FDIC) approved a proposal implementing the GENIUS Act, published in the Federal Register on April 10 at 91 FR 18534. Working from that full text and the FDIC's own press release, this article sets out whom the proposal would reach, the proposed reserve asset and redemption requirements, and why it would count the deposit insurance on reserve deposits as the issuer's rather than each stablecoin holder's.

  • Lifestyle

    NCUA's Proposed Stablecoin Standards: Credit Unions Could Issue Only Through a Subsidiary; Stablecoins Get No Share Insurance

    On May 18, 2026 the U.S. National Credit Union Administration's supplemental proposed rule implementing the GENIUS Act was published in the Federal Register (91 FR 28956). From that full text, the NCUA press release, the enacted GENIUS Act and the agency's February licensing proposal: why a credit union could issue payment stablecoins only through a subsidiary, how tokenized shares and the coin differ on share insurance, and why every line here reads as a proposal.

  • Lifestyle

    Brazil's Petrobras tests Cardano blockchain to track claims about cleaner jet fuel and diesel

    According to CoinDesk, Brazil's state-owned energy company Petrobras is testing the Cardano blockchain in two research projects: one to stop the same emissions cut from sustainable aviation fuel being counted twice, the other to record the history of its partly renewable Diesel R. Both are still research work, with no timeline for wider use.

Latest travel guides

Sources

Lifestyle