Skip to main content
Category: Virtual Assets and Technology

Payment Stablecoin Issuers

Also known as: PPSIs, Permitted Payment Stablecoin Issuers, PPSI
Simply put

A Payment Stablecoin Issuer (PPSI) is an entity authorized under the US GENIUS Act to mint payment stablecoins, digital tokens designed to hold a stable value for use in payments. Under proposed rules, these issuers would be treated as financial institutions for anti-money laundering purposes, meaning they would have to follow customer identification and other compliance obligations similar to banks and money services businesses.

Formal definition

In the US regulatory context, a Permitted Payment Stablecoin Issuer (PPSI) is an entity authorized under the GENIUS Act to issue (mint) payment stablecoins. Proposed rulemaking would designate PPSIs as "financial institutions" for purposes of the Bank Secrecy Act (BSA), thereby subjecting them to anti-money laundering obligations, including the maintenance of an effective customer identification program (CIP) requiring identification and verification of relevant persons. The GENIUS Act framework also restricts PPSIs (and foreign payment stablecoin issuers) from paying holders any form of interest or yield solely for holding the stablecoin. This is a US-specific statutory and regulatory classification distinct from that of a money services business (MSB) or money transmitter, and the treatment described reflects proposed rules whose scope, effective dates, and precise requirements should be confirmed against the final applicable rulemaking. As of the evidence available, related proposals include comment and compliance deadlines in 2026; exact obligations remain subject to the rulemaking process.

Why it matters

Payment stablecoins have grown into a significant mechanism for moving value across the digital asset ecosystem, and the entities that mint them sit at a critical control point. By designating Permitted Payment Stablecoin Issuers (PPSIs) as "financial institutions" for purposes of the Bank Secrecy Act (BSA), proposed US rulemaking would bring these issuers within the same broad AML framework that applies to banks and money services businesses. This matters because it extends customer identification, verification, and other compliance expectations to a class of actors that until recently occupied an ambiguous regulatory position. For compliance officers and financial intelligence analysts, the classification changes who bears direct BSA obligations at the point of issuance, rather than leaving those responsibilities solely to downstream exchanges, custodians, or transmitters.

The distinction between a PPSI and a money services business (MSB) or money transmitter is not merely academic. A PPSI is a US-specific statutory category created under the GENIUS Act and authorized to mint payment stablecoins, whereas an MSB is a money transmitter subject to a separate long-standing regulatory regime. Treating these categories as interchangeable can lead to misapplied controls or gaps in coverage, so professionals should be precise about which framework governs a given entity's activities. The GENIUS Act framework also restricts PPSIs and foreign payment stablecoin issuers from paying holders any form of interest or yield solely for holding the stablecoin, a design constraint that shapes the product itself and distinguishes payment stablecoins from yield-bearing instruments.

It is important to emphasize that much of the detailed treatment described here reflects proposed rules rather than finalized obligations. Related proposals reference comment and compliance deadlines in 2026, but the exact scope, effective dates, and precise requirements remain subject to the rulemaking process. Practitioners building or updating programs should treat these obligations as developing and confirm final requirements against the applicable rulemaking before relying on them operationally.

Who it's relevant to

Stablecoin Issuers and Their Compliance Teams
Entities authorized or seeking authorization to mint payment stablecoins are the direct subjects of the proposed PPSI framework. Their compliance functions would need to stand up or adapt customer identification programs and other BSA-aligned controls, and to track the rulemaking timeline, including comment and compliance deadlines referenced in 2026, to ensure readiness against final requirements.
AML and BSA Compliance Officers at Financial Institutions
Compliance professionals at banks and other BSA-regulated institutions that interact with stablecoin issuers benefit from understanding how PPSIs are classified and what obligations may attach to them. This informs counterparty risk assessments, correspondent-style relationships, and expectations about the controls a PPSI counterparty should maintain.
Legal and Regulatory Advisors
Attorneys and regulatory advisors guiding clients through the GENIUS Act framework must distinguish the PPSI category from MSB and money transmitter classifications, advise on the interest and yield prohibition, and interpret proposed CIP obligations. Because the treatment described reflects proposed rules, advisors play a key role in confirming scope and effective dates against final rulemaking.
Financial Intelligence Analysts and Investigators
Analysts and investigators tracing value through payment stablecoins gain relevant context from understanding which entities bear direct BSA obligations at the point of issuance. Knowing that PPSIs may be subject to customer identification and verification requirements can inform where identifying information is expected to exist along a transaction chain, though such controls do not themselves establish wrongdoing.

Inside PPSIs

Permitted Payment Stablecoin Issuer (PPSI)
A category of entity authorized to issue payment stablecoins under a dedicated statutory or regulatory framework. The precise definition, the authorizing body, and the conditions for permission vary by jurisdiction, and practitioners should confirm the specific criteria against the applicable regime rather than assuming a single global standard.
Payment stablecoin
A digital asset typically designed to maintain a stable value relative to a reference (often a fiat currency) and intended for use as a means of payment or settlement. The exact scope of what qualifies as a 'payment stablecoin' depends on the governing regime, and certain digital assets may fall outside the definition.
Obliged-entity / AML status
Where an issuer is brought within the perimeter of AML/CFT requirements, it may be treated as an obliged entity subject to obligations such as customer due diligence, transaction monitoring, and suspicious activity or suspicious transaction reporting. Whether and how these obligations apply depends on how the relevant jurisdiction classifies the issuer and its activities.
Reserve and redemption arrangements
Frameworks governing PPSIs commonly address the backing reserves supporting the stablecoin and the terms on which holders may redeem. These are prudential and consumer-protection features; the specific reserve composition, custody, and redemption requirements differ across regimes and should be verified against the applicable rules.
Distinction between issuance and downstream use
The regulatory treatment of the issuer differs conceptually from AML/CFT risks arising in the secondary transfer, custody, or exchange of the stablecoin by other participants. Obligations attaching to a PPSI do not necessarily extend to every party in the transaction chain.

Common questions

Answers to the questions practitioners most commonly ask about PPSIs.

Does issuing a payment stablecoin mean the issuer is automatically exempt from AML obligations because the token is fully reserved?
No. Full reserve backing addresses the redemption and stability profile of a payment stablecoin, but it does not remove financial crime obligations. In many jurisdictions, an entity issuing or redeeming a payment stablecoin may fall within the definition of an obliged entity, money services business, or virtual asset service provider, depending on how the applicable regime characterizes the activity. Where that is the case, the issuer would generally be expected to maintain AML/CFT controls such as customer due diligence, transaction monitoring, and suspicious activity or suspicious transaction reporting. Whether and how these obligations apply depends on the specific instrument and jurisdiction, and the classification should be confirmed against the applicable law rather than assumed from the reserve model alone.
Is a payment stablecoin issuer the same thing as a virtual asset service provider (VASP)?
Not necessarily, and the two should not be treated as interchangeable. "Payment stablecoin issuer" typically describes the specific role of creating and redeeming a stablecoin, while "VASP" is a broader category defined by the FATF Recommendations (which are standards, not binding law) and adopted with variations across jurisdictions to capture a range of virtual asset activities. An issuer may be regulated as a VASP, as a bank or money transmitter, under a dedicated stablecoin regime, or under some combination, depending on the jurisdiction and the functions it performs. The regulatory label and the source instrument that imposes obligations should be identified for the specific case rather than assumed to be uniform.
How should a payment stablecoin issuer approach customer due diligence when tokens can circulate between parties the issuer never onboarded?
This is a recognized operational challenge. An issuer generally applies customer due diligence to the parties with whom it has a direct relationship, such as those it onboards for minting and redemption, but it may have limited visibility into secondary-market holders who acquire tokens peer-to-peer or through intermediaries. A risk-based approach typically involves distinguishing the direct customer relationship from downstream circulation, applying due diligence and monitoring at the points where the issuer has a relationship or transaction, and considering how transfers to and from unhosted or third-party wallets are handled. These measures are intended to help detect and manage risk, not to guarantee visibility over every holder. The precise expectations depend on the applicable regime and should be confirmed against it.
What role does transaction monitoring play for an issuer, and what are its limits?
Transaction monitoring is generally used to detect and flag activity that may warrant further review, such as unusual minting and redemption patterns, structuring behavior, or transfers involving addresses associated with elevated risk. For a stablecoin issuer, monitoring may draw on both onboarding data and on-chain activity where visible. It is a measure to detect and deter potential misuse rather than a guarantee of prevention, and an alert or match does not by itself establish wrongdoing; alerts require review and, where appropriate, escalation. The scope of monitoring is bounded by the data available to the issuer, which may be limited for tokens circulating outside its direct relationships.
How do sanctions screening and travel rule obligations typically apply to stablecoin minting and redemption?
Sanctions screening and, where applicable, travel-rule-type obligations are generally applied at points where the issuer has a relationship or processes a transfer, subject to the requirements of the relevant regime. Sanctions screening is distinct from PEP screening and from broader due diligence, and it focuses on identifying parties or addresses subject to applicable sanctions restrictions. Travel rule obligations, where adopted, typically require originator and beneficiary information to accompany qualifying transfers, but the thresholds, covered entities, and technical implementation vary by jurisdiction. Applying these controls to on-chain transfers, particularly those involving unhosted wallets, can raise practical implementation questions, and the specific requirements should be confirmed against the applicable rules.
How should an issuer approach suspicious activity or suspicious transaction reporting?
Where an issuer is an obliged entity under the applicable regime, it may be required to report suspicious activity to the relevant authority. The terminology differs by jurisdiction: a Suspicious Activity Report (SAR) is used in some regimes, such as under the US Bank Secrecy Act and FinCEN rules, while a Suspicious Transaction Report (STR) is the term used in many others. A report reflects a suspicion or reasonable grounds for suspicion as defined by the relevant standard; it is a compliance filing and does not establish that a crime has occurred. Issuers generally need internal processes to identify, escalate, and, where required, report such activity, and to observe any applicable tipping-off restrictions. The precise triggers, timeframes, and recipient authority should be confirmed against the governing regulation.

Common misconceptions

There is a single, globally uniform definition of a Payment Stablecoin Issuer and a single set of rules that applies everywhere.
Frameworks for stablecoin issuers diverge across jurisdictions in their definitions, authorizing bodies, and obligations. FATF Recommendations operate as standards rather than binding law, and specific requirements stem from national or regional instruments. Practitioners should confirm which regime applies and consult the relevant text rather than assuming a common global rule.
Because a stablecoin is designed to hold a stable value and is backed by reserves, it carries little or no money laundering or terrorist financing risk.
Price stability and reserve backing are prudential and consumer-protection features and do not, on their own, mitigate ML or TF risk. The transferability, speed, and potential for pseudonymity associated with digital assets can present risks that AML/CFT measures are intended to detect and manage; no such feature guarantees prevention.
Being authorized as a PPSI means the issuer is responsible for AML monitoring across the entire lifecycle of the stablecoin, including all downstream transfers.
An issuer's obligations depend on how it is classified and on the activities it actually performs. Downstream custody, exchange, or peer-to-peer transfer may involve other participants who carry their own, separate obligations. The scope of an issuer's duties should be assessed against the specific regime and its role, not assumed to be all-encompassing.

Best practices

Identify and confirm the specific regime under which the entity is authorized or seeks authorization, and map obligations to the correct source instrument and supervisory body rather than assuming a uniform global standard.
Verify jurisdiction-specific requirements, including any reserve, redemption, and AML/CFT obligations, against the applicable regulatory text, and treat any numeric thresholds or figures as items to be confirmed against that text.
Determine whether and how the issuer is classified as an obliged entity for AML/CFT purposes, and design customer due diligence, monitoring, and suspicious activity/transaction reporting processes accordingly, noting where SAR versus STR terminology differs by jurisdiction.
Clearly delineate the issuer's own obligations from those of downstream participants (custodians, exchanges, transferors) to avoid over- or under-scoping controls across the transaction chain.
Apply a risk-based approach in which controls are documented as measures to detect, deter, and manage ML/TF risk, recognizing that no single control eliminates financial crime risk.
Maintain up-to-date monitoring of regulatory developments across relevant jurisdictions, since frameworks for stablecoin issuers continue to evolve and diverge.