Your organization just added stablecoin support. You've read the regulatory guidance, attended the webinars, and reviewed the vendor proposals. Now you need an actual compliance program that addresses how stablecoins move through your infrastructure.
This playbook walks you through building controls that account for the complete lifecycle of stablecoin activity, from customer onboarding through ongoing monitoring and sanctions response.
The Problem: Partial Visibility Creates Compliance Gaps
Traditional AML/CFT frameworks weren't designed for assets that move across blockchains, interact with decentralized protocols, and pass through multiple intermediaries in seconds. Your existing customer identification program captures who opened the account. Your transaction monitoring system flags unusual dollar amounts. But neither tells you what happens when a customer transfers stablecoins to an external wallet, where those tokens move next, or whether they've touched a sanctioned service.
The GENIUS Act, passed in July 2025, established a federal framework for payment stablecoin issuers. In June 2026, FinCEN and federal banking agencies proposed customer identification program requirements for permitted payment stablecoin issuers under the Bank Secrecy Act. These developments signal that stablecoin businesses will be held to financial institution standards, not software company standards.
You can't wait for final regulations to close the gaps in your program. Build the foundation now.
What You Need Before Starting
Organizational clarity:
- Document your specific role in the stablecoin lifecycle (issuer, exchange, payment processor, custodian, or wallet provider).
- Identify which stablecoins you support and who issues them.
- Map which blockchains and wallet types you allow.
- Define who performs customer due diligence at each stage.
- Establish who has authority to freeze or block tokens.
Technical infrastructure:
- Access to blockchain analytics tools that can trace wallet exposure and transaction pathways.
- Integration points between your customer database and transaction monitoring system.
- Ability to screen wallet addresses, not just customer names.
- Method for correlating on-chain addresses with off-chain customer records.
Compliance resources:
- Investigators trained to interpret blockchain data in the context of customer profiles.
- Legal guidance on sanctions authority and token freezing procedures.
- Documentation templates for escalation decisions and regulatory reporting.
Step-by-Step Implementation
1. Expand Your Customer Identification Program
Your customer identification program must connect to downstream monitoring and investigation processes.
During onboarding, collect:
- Standard identifying information (name, date of birth, address, taxpayer identification number).
- Beneficial ownership information for legal entities.
- Expected stablecoin use case and transaction volumes.
- Source of funds for initial purchases.
- Destination wallet types (custodial, self-hosted, multi-signature).
Configure your system to:
- Store this information in a format accessible to investigators reviewing alerts.
- Link customer profiles to all associated wallet addresses.
- Update records when customers provide new wallet addresses.
- Flag accounts when expected activity changes significantly.
2. Build Risk Ratings That Reflect Stablecoin Activity
Generic cryptocurrency risk ratings won't capture the specific risks in your customer base.
Develop risk factors based on:
- Customer type (individual, business, financial institution, exchange).
- Jurisdiction of customer and beneficial owners.
- Stablecoin use case (payments, trading, treasury management, remittances).
- Wallet types used (custodial wallets carry different risks than self-hosted wallets).
- Transaction patterns (frequent small transfers vs. infrequent large redemptions).
- Blockchain exposure (some chains have higher illicit activity rates).
Assign initial risk ratings during onboarding. Update ratings when:
- Customer activity diverges from stated purpose.
- New wallet addresses are added.
- Transaction volumes increase materially.
- Customer moves funds to high-risk jurisdictions.
- Blockchain analytics identify exposure to illicit services.
Document the factors that drove each rating change.
3. Integrate On-Chain and Off-Chain Monitoring
Your transaction monitoring rules need visibility into both customer behavior and blockchain activity.
Configure monitoring to:
- Screen wallet addresses against sanctions lists and known illicit services.
- Identify transactions involving mixers, darknet marketplaces, or ransomware-linked wallets.
- Detect rapid movement through newly created wallets.
- Flag unusual minting or redemption patterns relative to customer history.
- Monitor cross-chain transfers that may obscure transaction origin.
- Track exposure to high-risk jurisdictions or sanctioned entities.
When an alert fires, investigators should have access to:
- Customer identification and due diligence records.
- Expected activity profile from onboarding.
- Complete wallet transaction history.
- Blockchain analytics showing indirect exposure.
- Previous alerts and investigation outcomes for this customer.
Don't rely solely on automated scoring. Require documented human judgment for every alert disposition.
4. Establish Sanctions Response Procedures
Define your sanctions response before you need it.
Document:
- Who screens for sanctioned wallet addresses (not just customer names).
- How often sanctions lists are updated in your systems.
- Who has authority to freeze or block stablecoin transactions.
- Whether you have technical capability to freeze tokens post-transfer.
- How you handle false positives that could affect innocent downstream holders.
- What reports or notifications are required for blocked transactions.
- How you document each sanctions decision.
Test these procedures with realistic scenarios:
- Customer attempts to transfer stablecoins to a sanctioned wallet address.
- Blockchain analytics identify indirect exposure to a blocked jurisdiction.
- Sanctioned entity appears in a customer's transaction history after onboarding.
- Partner exchange requests you block a wallet based on their investigation.
If you don't have technical authority to freeze tokens after transfer, document that limitation and explain how you mitigate the risk through pre-transaction screening.
5. Manage Third-Party Dependencies
If you rely on partners for reserves, custody, analytics, or distribution, document their role in your compliance program.
For each critical vendor, verify:
- Their regulatory status and examination history.
- Which controls they perform on your behalf.
- What data they provide and how quickly you can access it.
- How they escalate potential issues to you.
- Whether they impose geographic or customer restrictions.
- Their incident response procedures.
Establish processes for:
- Monitoring partner performance against service-level agreements.
- Escalating concerns when partners fail to deliver expected data.
- Responding when a partner identifies suspicious activity.
- Obtaining transaction details needed for investigations and SARs.
Don't assume a contract assigns responsibility effectively. Test whether you can actually get the information you need within investigation timelines.
Validation: How to Verify It Works
Run these tests quarterly:
Customer identification integration:
- Select five recent alerts and verify investigators had access to complete customer profiles.
- Confirm wallet addresses are linked to customer records in your system.
- Test whether risk rating changes trigger monitoring rule updates.
Monitoring coverage:
- Review alerts from the past 30 days and identify any that lacked blockchain context.
- Verify sanctions screening includes wallet addresses, not just customer names.
- Check whether cross-chain transfers generated appropriate alerts.
Sanctions response:
- Simulate a sanctioned wallet address appearing in a pending transaction.
- Measure time from detection to escalation decision.
- Confirm documentation meets regulatory reporting requirements.
Partner oversight:
- Request transaction details from your blockchain analytics provider for a sample investigation.
- Verify your custodian can provide reserve attestation within required timelines.
- Test escalation procedures with your exchange partner.
Maintenance and Ongoing Tasks
Monthly:
- Review alert disposition rates and investigate any sudden changes.
- Update sanctions screening lists and verify system integration.
- Audit new wallet addresses added by customers.
Quarterly:
- Reassess customer risk ratings based on actual transaction patterns.
- Review blockchain analytics coverage for newly supported stablecoins or chains.
- Test sanctions response procedures with updated scenarios.
- Evaluate partner performance against service-level agreements.
Annually:
- Update risk assessment to reflect new stablecoin use cases.
- Revise monitoring rules based on typology changes.
- Validate that documentation standards meet current regulatory expectations.
- Conduct independent testing of key controls.
When regulations change or new guidance emerges, map the requirements to your existing program. Identify gaps. Document remediation steps. Don't rebuild from scratch every time FinCEN issues a proposal.
Your stablecoin compliance program should evolve as your business model and regulatory expectations change. Build it to be updated, not replaced.



