Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Regulatory Compliance

GENIUS Act CIP Proposed Rule: Five Agencies Just Set the KYC Standard for Stablecoin Issuers — Comments Due August 21

On June 22, 2026, FinCEN and four banking regulators jointly proposed the first Customer Identification Program requirements for permitted payment stablecoin issuers. Here's what the rule requires, who it covers, and why the comment deadline matters.

By Rebecca Leung · June 29, 2026 ·
Table of Contents

TL;DR

  • On June 22, 2026, FinCEN and four federal banking agencies jointly published the first-ever CIP proposed rule for stablecoin issuers — requiring written programs, verified customer identities, and five-year records retention
  • The rule applies to Permitted Payment Stablecoin Issuers (PPSIs); FinCEN estimates roughly 50 initial-scope entities, with the proposed $200 million threshold capturing approximately 76% of qualifying issuers
  • Comments are due August 21, 2026; final rule compliance required 12 months after publication
  • This is the customer identification layer of a three-part framework — paired with April 2026’s AML/OFAC proposed rule and the overall GENIUS Act licensing structure

Eight agencies have now issued proposed GENIUS Act rules. Four banking agencies. FinCEN. OFAC. The OCC. The Fed. If you’re a permitted payment stablecoin issuer — or a bank that expects to partner with one — the rulemaking calendar has been aggressive. The June 22 joint CIP proposed rule is the most recent piece, and it answers a question that’s been open since the GENIUS Act passed: what does customer identification actually look like for a stablecoin issuer?

The short answer: it looks a lot like what a bank does, scaled for the stablecoin business model. The longer answer is where the compliance design questions start.


What the June 22 Proposed Rule Does

The Customer Identification Program proposed rule, published June 22, 2026 by FinCEN jointly with the OCC, Federal Reserve, FDIC, and NCUA, creates a separate CIP framework specifically for Permitted Payment Stablecoin Issuers. It’s technically distinct from the CIP rules that apply to banks and other depository institutions under 31 CFR 1020.220 — though it draws from the same BSA architecture.

The proposed rule would require every PPSI to establish, implement, and maintain a written CIP as part of its broader AML/CFT program. The CIP must be approved by the PPSI’s board of directors or senior management. It must include risk-based procedures for:

  • Collecting identifying information at account opening: name, date of birth, address, and identification number (Social Security Number or ITIN for U.S. persons; passport number or government-issued ID for non-U.S. persons)
  • Verifying customer identities using documentary methods (government-issued photo ID), non-documentary methods (data sources, credit files, public databases), or a combination
  • Resolving verification failures — what happens when identity can’t be confirmed, including circumstances under which accounts are closed or transactions declined
  • Retaining records for five years — five years from account opening for identifying information collected; five years from the date the record was made for verification documents and procedures

The five-year retention requirement matches existing bank CIP requirements, which matters for institutions building integrated compliance architectures across both licensed banking and stablecoin operations.


Who It Covers — And Who’s Counting

FinCEN estimates the proposed rule would initially apply to approximately 50 PPSIs. That’s a small universe, but it will grow. The GENIUS Act defines PPSIs to include federally chartered stablecoin issuers, bank subsidiaries that issue stablecoins, and qualifying state-licensed issuers — and the universe of state-licensed issuers expands as Treasury certifies state regimes as substantially similar to the federal framework.

The proposed $200 million outstanding stablecoin threshold is a key scaling mechanism. FinCEN estimates that threshold captures approximately 76% of current qualifying issuers. Issuers scaling through that threshold — crossing $200M in outstanding stablecoin during a year — need to have CIP infrastructure in place before they cross it, not after.

For bank partners of stablecoin issuers, this matters indirectly: your TPRM program for a PPSI relationship now needs to evaluate whether the issuer’s CIP meets the proposed standard. If the PPSI is a fintech you sponsor or service, its CIP gaps are a third-party risk item for your compliance program.


How It Fits the Broader GENIUS Act Compliance Framework

The CIP rule is one piece of a three-layer structure:

Layer 1: AML/CFT Program and Sanctions Compliance — The April 2026 FinCEN/OFAC proposed rule established the BSA compliance backbone: SARs at the $5,000 threshold, customer due diligence, a designated U.S.-based compliance officer, an effective sanctions compliance program, and the full range of BSA obligations that will apply once PPSIs are treated as financial institutions.

Layer 2: Customer Identification — The June 22 CIP rule adds the specific account-opening identification requirements: what you have to collect, how you have to verify it, and how long you have to keep it. CIP sits inside the AML/CFT program, not separate from it, which means a PPSI’s written AML policy will need to cross-reference the CIP procedures.

Layer 3: Licensing and Prudential Standards — OCC proposed its stablecoin licensing framework in March 2026, and the FDIC followed in April. These establish the operational and capital conditions for obtaining and maintaining a PPSI license — the framework inside which these compliance rules apply.

If you’re building a PPSI compliance program, the sequencing matters: licensing requirements define who the rules apply to, the AML rule defines the program structure, and the CIP rule defines the specific customer onboarding obligations. The GENIUS Act compliance deadline post covered the overall rulemaking calendar, but the June 22 CIP rule is the piece compliance programs need to operationalize now.


The Compliance Design Questions the Rule Leaves Open

The NPRM creates a framework but leaves several operational questions for the comment period and the final rule to resolve.

Wallet-level identification in embedded models. Many stablecoin issuers don’t interface directly with end users. A PPSI might issue stablecoins distributed through embedded wallet providers, fintech apps, or custodians. The CIP rule requires the PPSI to “establish and maintain” a CIP, but doesn’t clearly resolve how responsibility flows when end-user identity is collected by an intermediary rather than the PPSI itself. The bank CIP model for third-party reliance requires formal contractual arrangements and annual certifications — a similar model likely applies here, but the rule doesn’t make it explicit.

Blockchain-based identity verification. The proposed rule describes documentary and non-documentary verification methods drawn from the existing bank CIP playbook. Whether on-chain identity attestations (DIDs, verifiable credentials, reusable KYC tokens) qualify under those categories isn’t addressed. Given that PPSIs by definition operate in a blockchain environment, this is a significant gap commenters are likely to flag.

Cross-border customers. The rule requires collection of identification number — SSN or ITIN for U.S. persons, or passport/government ID for non-U.S. persons. Stablecoin issuers with significant international exposure will need verification workflows that accommodate non-U.S. ID formats without creating friction that drives users to unregulated alternatives.


The Timeline (and Why the July 18 Deadline Already Slipped)

The GENIUS Act required federal agencies to finalize all implementing regulations by July 18, 2026. As of today, June 30, the CIP rule is still in proposed form — and the comment period doesn’t close until August 21. The July 18 deadline has effectively slipped. Agencies issued rules in proposed, not final, form ahead of the statutory deadline, which means the final rules will follow by some months.

The practical compliance timeline: once a final CIP rule is published (likely late 2026 or early 2027), PPSIs have 12 months to comply. The GENIUS Act’s operative provisions take effect the earlier of January 18, 2027 or 120 days after final rules are issued. If final rules publish in October 2026, the Act takes effect February 2027, giving PPSIs a window into early 2028 for full CIP implementation.

This is not an invitation to wait. PPSIs that haven’t started building their CIP frameworks now — especially those approaching the $200M threshold — will face a compressed implementation window that compliance-by-deadline programs consistently fail.


What to Do Before August 21

The August 21 comment deadline is the first action item. Whether to comment depends on whether your organization has specific questions or objections the agencies need to hear.

Issues worth raising in comments:

  • Third-party reliance standards for issuers that don’t collect customer data directly
  • Treatment of blockchain-native identity verification as a documentary method
  • Clarification on the $200M threshold measurement period and mid-year crossings
  • CIP obligations for secondary-market stablecoin transactions where KYC wasn’t collected at the primary transaction

Even if you don’t file a comment, start the compliance build now:

Inventory your customer touchpoints. Where does customer data actually get collected — by you, by a wallet provider, by a bank partner? Map every point where CIP-relevant data is created or could be created. This is your gap analysis starting point.

Document what you collect today. Many stablecoin issuers or pre-PPSI applicants already collect name, email, and wallet address. Almost none have a structured program for collecting DOB and TIN for every account holder. Gap analysis against the proposed minimum is the first practical step.

Draft your written CIP policy. The rule requires a written, board-approved program. You don’t need to wait for the final rule to start drafting — the proposed rule is specific enough about the minimum content that a working draft is achievable now.

Evaluate your verification toolset. Non-documentary verification — data sources, credit bureaus, identity verification platforms — is what most digital-native firms rely on. Evaluate whether your current vendor is configured for the data elements the rule requires and whether the vendor relationship includes the contractual provisions that CIP reliance arrangements require.

The New Product Risk Assessment Template is relevant here for issuers treating their PPSI program as a new compliance build — it covers the structured assessment of regulatory requirements, operational controls, and control gaps that a CIP implementation plan needs before it goes to the board.


So What?

The GENIUS Act CIP proposed rule is the customer identification piece of a compliance framework that, in its final form, will impose bank-equivalent obligations on stablecoin issuers. The five agencies involved — FinCEN, OCC, Federal Reserve, FDIC, NCUA — represent the full scope of federal financial regulation. That’s not an accident: it signals that regulators view stablecoin issuers as financial institutions that happen to use blockchain, not tech companies that happen to touch money.

August 21 is when the comment period closes. The question between now and then is whether your organization has enough program built to evaluate whether the proposed rule works for your business model. If you can’t answer that, you don’t have enough program.


Sources: Federal Register — Permitted Payment Stablecoin Issuer Customer Identification Program (June 22, 2026) · FinCEN Press Release — GENIUS Act CIP Proposed Rule · Sullivan & Cromwell — GENIUS Act CIP Analysis · FDIC Notice — CIP Proposed Rulemaking · NCUA Press Release — CIP NPRM

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is the GENIUS Act CIP proposed rule?
On June 22, 2026, FinCEN — jointly with the OCC, Federal Reserve, FDIC, and NCUA — published a proposed rule to establish Customer Identification Program requirements for permitted payment stablecoin issuers (PPSIs). The rule would require PPSIs to collect name, date of birth, address, and a taxpayer identification number from each account holder, maintain a written CIP, and retain records for five years. Comments are due August 21, 2026.
Who does the GENIUS Act CIP rule apply to?
The rule applies to Permitted Payment Stablecoin Issuers (PPSIs) — entities licensed to issue payment stablecoins under the GENIUS Act, including federally chartered issuers, bank subsidiaries, and qualifying state-licensed issuers. FinCEN estimates roughly 50 entities currently meet the PPSI definition, with the proposed $200 million threshold capturing approximately 76% of qualifying issuers.
What does a PPSI's CIP program need to include?
At minimum: a written CIP program approved by the board or senior management, risk-based procedures for collecting name, date of birth, address, and identification number, procedures for verifying customer identity using documentary and non-documentary methods, processes for resolving failed verifications, and record retention for five years.
When will the GENIUS Act CIP rule take effect?
The agencies are still in the proposed rule stage. Comments are due August 21, 2026. Once a final rule is published, PPSIs will have 12 months to comply. The GENIUS Act itself takes effect the earlier of January 18, 2027 or 120 days after final rules are issued.
How does the CIP rule relate to the April 2026 AML/OFAC proposed rule?
They are companion rules. The April 2026 AML/OFAC rule proposed that PPSIs file SARs, maintain a CDD program, designate a U.S.-based compliance officer, and maintain a sanctions compliance program — the full BSA/AML structure. The June 2026 CIP rule adds the customer identification layer: specific requirements for how PPSIs collect and verify the identity of account holders.
Should a stablecoin issuer file a comment on the CIP proposed rule?
Any issuer that expects to be a PPSI should evaluate whether to comment. Practical questions worth raising: how CIP applies when the issuer has limited direct customer data; whether blockchain-based identity verification qualifies as a documentary method; and how the $200M threshold interacts with issuers scaling across that threshold mid-year. Comments are due August 21, 2026.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

New Product Risk Assessment

Structured risk review process for new products, services, and business initiatives.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.