The New Mandate
The UK Government has tasked the Bank of England with a new responsibility: supporting innovation in payment systems, specifically focusing on stablecoins. This isn't a consultation or pilot program; it's a formal expansion of the central bank's role. This shift in regulatory focus presents a challenge for your compliance team. The central bank is now tasked with fostering innovation in assets that most AML/CFT frameworks weren't designed to handle. Your role is to ensure these new payment methods don't become channels for illicit finance.
Immediate Challenges
The announcement came without a phased implementation or transitional guidance. The Bank of England's new responsibilities are already in effect. However, you're missing:
- Specific regulatory standards for stablecoin AML/CFT controls
- Guidance on applying existing Payment Services Regulations to stablecoin transactions
- Clarification on whether stablecoin issuers fall under current electronic money institution requirements
- Updated transaction monitoring rules for blockchain-based settlements
You're now dealing with a central bank incentivized to approve payment innovations that your compliance framework may not be ready to assess.
Structural Control Gaps
This isn't about missing a deadline or ignoring a red flag. The gap is structural. Most UK payment institutions built compliance programs around:
- Fiat currency transactions with identifiable counterparties
- Traditional correspondent banking relationships
- Payment rails with traceable funds through regulated intermediaries
- Customer Due Diligence processes assuming stable identity verification at onboarding
Stablecoins disrupt these assumptions. When a customer initiates a stablecoin transfer, you're dealing with:
- Transactions in digital assets that may be issued offshore
- Settlements on a blockchain without traditional correspondent relationships
- Counterparties identified only by wallet addresses, not verified entities
- Customers holding stablecoins across multiple platforms, complicating exposure calculations
The missing piece is a risk assessment framework that accounts for these differences. If your transaction monitoring flags structuring based on fiat patterns, it won't catch a customer moving £50,000 in stablecoin across ten wallets in two hours. If your Customer Risk Profile relies on GBP transaction volumes, it's ineffective when the customer switches to USDC.
Regulatory Standards
FATF Recommendation 15 requires countries to ensure virtual asset service providers (VASPs) implement AML/CFT measures equivalent to traditional financial institutions. This includes:
- Customer Due Diligence at onboarding and ongoing monitoring
- Transaction monitoring to detect suspicious patterns
- Filing Suspicious Activity Reports for red flags
- Record retention for customer identification and transaction data
The Travel Rule (FATF Recommendation 16) extends this further. For stablecoin transfers above the threshold, you must obtain and transmit originator and beneficiary information. The challenge: many stablecoin transactions settle peer-to-peer or through decentralized exchanges without a "next institution" to receive that data.
The UK's Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 apply to cryptoasset exchange providers and custodian wallet providers. However, these regulations were written before stablecoins became payment instruments. You're expected to apply Customer Due Diligence, but the regulations don't specify how to verify beneficial ownership when the stablecoin issuer is a Cayman Islands foundation with no disclosed shareholders.
Action Items for Your Team
Map your stablecoin exposure now. Identify which customers hold or transact in stablecoins. Determine whether your institution acts as an on-ramp (fiat to stablecoin), off-ramp (stablecoin to fiat), or both. Each role carries different risks and requires different controls.
Expand your transaction monitoring rules. Include stablecoin-specific typologies. You need rules that flag:
- Rapid conversion between fiat and stablecoins just below your CDD refresh threshold
- Customers receiving stablecoins from multiple external wallets, then converting to fiat
- Stablecoin deposits that don't match the customer's business model or transaction history
Revise your Customer Risk Rating methodology. Add stablecoin activity as a discrete risk factor. A customer using stablecoins for daily business payments needs enhanced due diligence due to potential sanctions evasion or trade-based money laundering.
Document your Travel Rule compliance approach. If you facilitate stablecoin transfers, outline how you'll obtain originator and beneficiary information when the counterparty is a non-custodial wallet or decentralized exchange. If you can't obtain that information, document why the transaction was rejected. Regulators will ask.
Assess stablecoin issuer risk. Not all stablecoins carry the same risk. Evaluate issuer transparency, reserve composition, and regulatory status. Use this framework to determine which stablecoins you'll accept.
Prepare for divergence between innovation mandates and compliance expectations. The Bank of England's new responsibility creates tension you'll need to manage. The regulator wants to enable stablecoin adoption. You need to ensure that adoption doesn't compromise your AML/CFT obligations. When considering a stablecoin payment product, your compliance sign-off should include a written risk assessment addressing each FATF recommendation and explaining how your controls will function in a blockchain environment.
The UK Government's directive doesn't create new compliance obligations. It accelerates the timeline for payment innovations your current controls may not cover. Start closing that gap now.



