Feature Regulatory Compliance
GENIUS Act Stablecoin Compliance: The July 18 Deadline and What Every Issuer Still Needs to Build
Federal agencies must finalize GENIUS Act implementing regulations by July 18, 2026 — 39 days from today. FinCEN's AML comment period closes today. Here's the compliance checklist stablecoin issuers and their bank partners need to build before the deadline hits.
Table of Contents
TL;DR
- Federal agencies must finalize GENIUS Act implementing regulations by July 18, 2026 — 39 days from today
- FinCEN and OFAC’s AML/sanctions proposed rules (April 10, 2026) had their comment period close today — June 9
- Four compliance pillars: licensing (federal PPSI or certified state), reserves (1:1 perpetually with monthly disclosure), AML/BSA (treated as a financial institution), and consumer protection
- Issuers below $10 billion in outstanding stablecoin can use state regimes — only if the state earns Treasury certification as “substantially similar” to the federal framework
- Reserve failure is automatically actionable: miss 1:1 for 15 consecutive business days and you’re in mandatory wind-down
The comment period on FinCEN and OFAC’s proposed AML and sanctions rules for stablecoin issuers closes today. If your institution is a stablecoin issuer or a bank partner to one and hasn’t submitted comments, that window is closed. What isn’t closed — yet — is the time to build the compliance infrastructure the GENIUS Act requires before July 18.
Thirty-nine days. That’s how long you have before the deadline for implementing regulations to land. And unlike many regulatory deadlines where early non-compliance is managed through MRAs and corrective action plans, the GENIUS Act’s prohibition is structural: after July 18, issuing a payment stablecoin without being a “permitted payment stablecoin issuer” isn’t a gap in your compliance program — it’s a prohibited activity.
The Act was signed in July 2025. The 12-month implementation window was supposed to be preparation time. Here’s what that preparation needs to cover across each of the four compliance pillars.
Who’s Covered: The PPSI Framework
The GENIUS Act creates a new category: the permitted payment stablecoin issuer (PPSI). To issue a payment stablecoin in the United States, you must qualify as a PPSI. The prohibition covers any entity — bank, fintech, crypto native, or foreign — that issues tokens functioning as payment stablecoins to US persons.
The federal PPSI framework covers:
- Subsidiaries of national banks or federal savings associations issuing stablecoins
- Entities receiving new OCC Federal qualified payment stablecoin issuer charters
- State-licensed issuers receiving federal approval under the state-track pathway
- Any other entity the OCC or Federal Reserve determines should be treated as a PPSI
The OCC issued its proposed implementing rules in March 2026 and is taking the lead on federal licensing. The FDIC followed with its proposed rules for FDIC-supervised entities in April 2026.
The dual-track provision: Issuers with less than $10 billion in outstanding stablecoin issuance can operate under a state regulatory framework — but only if Treasury certifies the state’s regime as “substantially similar” to the federal framework. As of June 2026, that certification process is active but not complete for most states. States with established money transmitter licensing frameworks are likely to pursue certification, but timing is uncertain. Issuers counting on state-track eligibility should not assume their state will be certified before July 18. Build to federal standards as a baseline.
Reserve Requirements: The 1:1 Rule and Its Enforcement Trigger
The reserve requirement sounds simple: maintain 1:1 reserves at all times. The operational complexity is in what “1:1” means and what happens when you miss it.
Eligible reserve assets:
- US dollar cash
- Insured bank deposits at FDIC-insured institutions
- Short-term US Treasury securities (generally T-bills and recent maturities)
Prohibited:
- Paying interest or yield to stablecoin holders (converts a payment instrument to a security under the GENIUS Act framework)
- Using reserve assets for purposes other than backing outstanding issuance
- Holding long-dated, illiquid, or non-qualifying assets as reserve
Monthly disclosure: Issuers must publish reserve composition and coverage ratios monthly. This creates a public accountability mechanism that didn’t exist for most stablecoins before the GENIUS Act. The monthly disclosure is the market’s early warning signal — and regulators will watch it.
The 15-business-day enforcement trigger is the operational requirement that issuers need to operationalize now:
If a PPSI fails to maintain 1:1 reserves, it must immediately notify its primary regulator and cease new issuance. If the shortfall persists for 15 consecutive business days, the issuer must begin liquidating reserve assets and redeeming outstanding stablecoins.
This is an automatic wind-down trigger, not a regulatory discretion call. The Voyager and Celsius failures that catalyzed stablecoin regulation happened precisely because reserve mismatches weren’t disclosed until collapse was imminent. The 15-business-day trigger is designed to force intervention while reserves remain. The operational implication: you need daily reserve monitoring, not monthly. If you’re only checking reserves when you publish disclosures, you’ll miss the 15-day window.
AML/BSA Obligations: The Financial Institution Standard
The AML framework under the GENIUS Act is being finalized through FinCEN and OFAC rulemaking. Their proposed rules, published April 10, 2026, would treat PPSIs as financial institutions under the Bank Secrecy Act — not money services businesses, but the full financial institution standard applied to banks and credit unions.
| BSA Obligation | What It Means for PPSIs |
|---|---|
| FinCEN registration | Register as a financial institution with FinCEN |
| Written AML program | Full BSA program with written policies, procedures, and internal controls |
| Compliance officer | Designated AML officer with sufficient authority and resources |
| Independent testing | Annual AML program audit, internal or third-party |
| Employee training | Role-specific BSA/AML training with documented completion records |
| Customer identification | CIP at account opening meeting financial institution standards |
| Customer due diligence | Ongoing CDD including beneficial ownership and enhanced due diligence for high-risk customers |
| Transaction monitoring | System-based monitoring with documented escalation and SAR filing for reportable activity |
| OFAC screening | Sanctions screening program reasonably designed to prevent violations |
The certification requirement adds an explicit accountability mechanism: PPSIs must certify their AML program implementation within 180 days of approval, and annually thereafter. That certification goes to the primary regulator — not an internal attestation, but a positive certification that the program is implemented and operating.
Issuers already registered as money services businesses need to compare their existing programs against the financial institution standard. The gap is real: MSB AML programs are adequate for MSBs, but the FS AI standard requires more — specifically on CDD, independent testing rigor, and the expectation of ongoing monitoring coverage comparable to a depository institution’s program.
For the blocking and sanctions screening component, see Sanctions Screening Techniques: Tuning False Positives Without Missing Real OFAC Hits for the methodology of building a program that works at transaction volume.
Consumer Protection Requirements
The consumer protection framework has three operational components that must be operational before July 18.
1. Redemption Policy Publication
Issuers must publish redemption policies in plain language disclosing:
- The redemption timeline (two-business-day maximum)
- All applicable fees, stated clearly
- The process for submitting a redemption request
Fee changes require seven days’ advance notice to holders before implementation. This is an operational constraint with no emergency exceptions — if your payment processor changes fees, you need the seven-day window built into your contracts with them.
2. Two-Business-Day Redemption
The two-business-day window is a hard operational requirement. Your payment infrastructure, banking relationships, and treasury operations must be able to execute a full redemption within that window, at scale, including during periods of elevated redemption demand. For issuers with multi-hop settlement paths — bridged tokens, custody arrangements, cross-chain mechanics — stress-testing the operational path from request to fiat delivery is essential before the deadline.
3. No Interest Payments
The prohibition on interest payments isn’t just a product design constraint — it has compliance implications for any existing or planned features. If your platform has any yield-generation mechanics (DeFi integrations, staking features, promotional rate programs), those features need to be reviewed against the prohibition before July 18. Indirect yield returns to holders may also trigger the prohibition depending on structure.
The State-Federal Track Decision
For issuers below $10 billion, the dual-track framework is an option — not an automatic alternative. The path to state-track eligibility requires:
- Your state must have a regulatory framework for stablecoin issuers
- Treasury must certify that framework as “substantially similar” to the federal standard
- You must comply with the state-certified requirements
The practical advice: don’t plan your compliance program around state-track eligibility unless you have confirmed information that your state is on track for certification before July 18. “Substantially similar” means the state-level requirements won’t be materially lighter than the federal framework anyway — particularly on AML, reserve management, and consumer protection. Building to federal standards is the right baseline regardless of which track you end up on.
For the ongoing sponsor bank relationship considerations that GENIUS Act compliance affects — particularly how bank partners will assess PPSI compliance in their TPRM oversight — see The BaaS Consent Order Playbook for the TPRM minimum standards that BaaS banks will apply to stablecoin custodians and issuers.
The Compliance Build Checklist: 39 Days
The timeline is tight. Here’s the prioritized build sequence:
Immediate (by June 23):
- Confirm PPSI eligibility path — federal charter or state-track (with state certification verification)
- Reserve composition audit: are current holdings in eligible assets? Identify any non-qualifying positions
- Establish daily reserve monitoring process with automated alerts for threshold breaches
- AML program gap assessment: current MSB program vs. BSA financial institution standard
Before July 1:
- Monthly reserve disclosure mechanism: process, publication channel, calculation methodology, sign-off
- Redemption policy publication (plain language, two-business-day commitment, fee schedule, seven-day change notice procedure)
- CIP procedures updated to financial institution standard for account opening
- AML compliance officer formally designated in writing
Before July 18:
- Transaction monitoring system configuration validated for stablecoin-specific scenarios
- OFAC sanctions screening program assessed and updated for PPSI volume
- Staff training completed on GENIUS Act obligations
- Board/risk committee briefed on reserve management obligations and the 15-business-day liquidation trigger
- AML program certification prepared for submission within 180-day post-approval window
- Interest/yield feature review completed and any prohibited features disabled
Ongoing after July 18:
- Monthly reserve disclosure publication
- Annual AML program certification
- 15-consecutive-business-day reserve monitoring — automated, not manual, with escalation triggers
What’s Still Being Finalized
The agencies haven’t issued final rules yet. The OCC, FDIC, and FinCEN/OFAC are all in proposed-rule status. July 18 is the deadline for agencies to finalize implementing regulations — not for issuers to achieve compliance. As a practical matter, final rules may publish in June or early July, giving issuers a compressed window to adapt to any changes between proposed and final.
Three areas where proposed rules may shift before finalization:
- State-track certification criteria: Treasury has proposed principles for what makes a state regime “substantially similar.” The final criteria may be more or less permissive than proposed.
- AML program specifics: FinCEN’s April proposal establishes the financial institution standard, but specific transaction monitoring requirements, SAR filing thresholds, and blockchain analytics expectations may be refined in the final rule.
- Capital requirements: The GENIUS Act directs agencies to establish capital and liquidity standards. As of June 2026, those requirements are still being developed.
The right approach: build to the proposed-rule standard now, with the architectural flexibility to adapt specific parameters when finals publish.
So What?
The GENIUS Act creates the first federal licensing framework for US stablecoin issuers. After July 18, 2026, issuing a payment stablecoin without being a PPSI isn’t just a regulatory gap — it’s a prohibited activity.
The four compliance pillars (licensing, reserves, AML, consumer protection) each require operational infrastructure, not just policy documentation. The reserve monitoring needs to be daily. The redemption process needs to be operationally tested. The AML program needs to meet the financial institution standard, not the MSB standard.
Thirty-nine days is enough time to build or close most of these gaps — if you start this week. The reserve composition audit and AML gap assessment are the two highest-priority starting points because the consequences of getting them wrong are operational and immediate: mandatory liquidation on sustained reserve failure, BSA enforcement on AML failures.
For institutions building the operational compliance infrastructure — consumer protection procedures, incident response for reserve breaches, third-party oversight documentation — across the domains that GENIUS Act bank partners will require, the Compliance Essentials bundle covers the data privacy, incident response, and BCP/DR documentation that the banking relationships your reserve management depends on will require you to have in place before you’re permitted to open or maintain reserve accounts.
For the BSA/AML independent testing program that PPSIs will need within 180 days of approval, see BSA/AML Independent Testing: Building a Program That Passes the FFIEC Exam.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Compliance Essentials
Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
When do GENIUS Act regulations take effect?
Do state-regulated stablecoin issuers have to comply with the GENIUS Act?
What are the GENIUS Act reserve requirements?
When does the AML/BSA obligation begin?
What is the redemption requirement under the GENIUS Act?
How does the GENIUS Act's AML framework differ from existing MSB requirements?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Compliance Essentials
Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.
◆ Keep reading
Related posts.
Regulatory Compliance
Effective Challenge in Model Risk Management: Document the Disagreement
Model risk management effective challenge needs a decision trail. Build a challenge memo that preserves evidence, responses, conditions, and escalation.
Jul 24, 2026
Regulatory Compliance
FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now
FinCEN's student aid fraud alert gives banks nine red flags, a SAR keyword, and a clear transaction-monitoring task for ACH refunds.
Jul 23, 2026
Regulatory Compliance
Magnolia Diagnostics False Claims Act Settlement: Why Investors Paid Part of the $24 Million
The Magnolia Diagnostics False Claims Act settlement reached investors, requisition controls, and $24M in payments. Here is what to fix.
Jul 23, 2026