Feature Regulatory Compliance
Stablecoin Issuers Just Got a Customer Identification Mandate. The Comment Deadline Is August 21.
On June 18, 2026, FinCEN and four federal banking agencies proposed the first-ever Customer Identification Program requirements for permitted payment stablecoin issuers under the GENIUS Act. The comment period closes August 21. Here's what the rule requires, where it matters most, and what stablecoin compliance programs need to build.
Table of Contents
TL;DR
- On June 18, 2026, FinCEN, OCC, Federal Reserve, FDIC, and NCUA jointly proposed Customer Identification Program (CIP) requirements for permitted payment stablecoin issuers (PPSIs) under the GENIUS Act
- The comment period closes August 21, 2026 — 18 days from today
- PPSIs must collect legal name, date of birth, address, and taxpayer identification number for each account holder — and retain those records for five years after account closure
- This is a bank-level CIP requirement, not the lighter MSB standard — stablecoin issuers that treat their current onboarding as “good enough” are likely to have gaps
- The final rule is expected in 2027, with compliance required 12 months after issuance — but building the program now reduces implementation risk
The July 18 Deadline Passed. The Rules Are Still Coming.
Most stablecoin compliance teams spent the first half of 2026 watching the July 18 clock — the GENIUS Act’s statutory deadline for federal agencies to issue implementing regulations. That deadline has passed. The rules are in varying stages of finalization.
What’s now active and time-sensitive is the comment period on the specific CIP rule. The June 18, 2026 notice of proposed rulemaking from FinCEN and four federal banking agencies — OCC, Federal Reserve, FDIC, and NCUA — closes on August 21, 2026. If you haven’t read it and don’t have a view on what it requires, you’re now 18 days from missing the opportunity to shape it.
More immediately: even if you don’t file a comment, the operational implications of this rule are real and specific. The CIP requirements for PPSIs are not the informal “know your customer” practices most crypto companies built around exchange onboarding or MSB registration. They are the bank-level CIP standard — written policies, verification requirements, five-year record retention, board-level accountability. Building that program requires lead time.
Here’s what the proposed rule requires and where the operational complexity actually lives.
Who This Rule Covers
The CIP NPRM applies to permitted payment stablecoin issuers (PPSIs) — the category of entities licensed to issue payment stablecoins under the GENIUS Act.
That includes:
- Federally chartered issuers licensed by the OCC or Federal Reserve
- Bank subsidiaries of insured depository institutions issuing stablecoins
- State-licensed issuers whose state regulatory frameworks have been certified by Treasury as “substantially similar” to the federal GENIUS Act standard
If you’re currently issuing stablecoins without a GENIUS Act license, you’re already prohibited under the statute — the CIP rule is for the licensed population. If you’re applying for a license or operating under a state regime pending Treasury certification, this rule defines the compliance obligations you’re accepting.
Volume threshold note: issuers with less than $10 billion in outstanding stablecoin can operate under state regimes — but only certified state regimes. That certification process is still underway for most states. Don’t assume your state qualifies until Treasury confirms it.
What the CIP Must Collect
The proposed rule establishes minimum data requirements that track the existing CIP rule applied to banks and broker-dealers.
For each account holder, a PPSI’s CIP must collect:
| Element | Requirement |
|---|---|
| Legal name | Full legal name — not a pseudonym or wallet address |
| Date of birth | For individuals; entity formation date for legal persons |
| Address | Residential or business address — P.O. Box insufficient as the sole address |
| Taxpayer Identification Number (TIN) | SSN for U.S. persons; ITIN or EIN for non-U.S. persons; foreign TIN where applicable |
The agencies borrowed this structure directly from the 31 CFR Part 1020 CIP rule applied to banks. That’s deliberate — PPSIs are being treated as financial institutions under the BSA, not as MSBs or tech companies. The CIP is where that treatment becomes operationally concrete.
What “account holder” means matters here. The proposed rule defines the CIP obligation around the account relationship between the PPSI and the person or entity holding an account directly with it. Wallets or accounts created by third-party applications that access the issuer’s infrastructure may create intermediary layers the rule addresses separately under the concept of reliance on third-party CIP.
Verification: The Gap Between Collecting and Confirming
Collecting the four data elements isn’t the same as verifying them. The proposed rule requires PPSIs to verify the information — though the verification methodology is risk-based, not prescriptive.
Banks typically use two methods: documentary (government-issued ID, passport) and non-documentary (credit bureau cross-reference, public database verification, comparison of social security number against death records). The proposed rule allows similar flexibility but requires the PPSI to document its verification methodology and apply it consistently.
Where this creates operational complexity for stablecoin issuers:
Pseudonymous wallet history doesn’t verify identity. Crypto companies have historically relied on wallet behavior as a proxy for identity risk. The CIP rule requires documentary or non-documentary verification of the account holder’s legal identity — behavioral signals are risk indicators, not CIP substitutes.
Non-U.S. persons require TIN collection that many onboarding flows aren’t built for. A GENIUS Act stablecoin has the potential to be globally accessible. Non-U.S. account holders require foreign TIN or, in cases where that’s unavailable, an explanation of why the TIN was not collected — which itself needs to be documented.
Third-party CIP reliance is available but regulated. The proposed rule allows PPSIs to rely on a third party (such as a bank that has already completed CIP on a shared customer) — but requires a written agreement specifying the third party’s obligations and the PPSI’s right to access CIP records promptly. If your stablecoin onboarding is downstream of a partner bank’s KYC, verify whether that arrangement meets the formal reliance standard.
Record Retention: Five Years Is the Floor
The proposed rule establishes two separate retention clocks:
Customer identifying information: retained for five years after the account is closed.
Verification records — documents reviewed, methods applied, results, discrepancies resolved: retained for five years after the record is created.
For long-lived accounts, the verification records start their five-year clock when collected, while the identifying information clock doesn’t start until closure. A customer who opens an account in 2027 and closes it in 2040 would require retention of their identifying information until 2045 — but their 2027 verification records could expire in 2032 under the second retention clock.
For compliance programs used to treating crypto wallet records as indefinitely ephemeral or governed only by their own product policies, this creates a retention framework that needs to be built deliberately. It can’t be bolted on retrospectively when the examiner asks.
What This Means for Your Current Onboarding
The honest assessment for most stablecoin issuers: current onboarding flows have gaps relative to what this rule requires.
Common gaps:
- No date of birth collection for individual account holders. Many crypto onboarding flows collect a wallet address and an email — not the four statutory elements.
- No systematic TIN collection. CIP requires it; typical crypto KYC practices don’t uniformly collect TINs.
- Address verification treated as optional. CIP requires address at account opening — not as an optional field or a billing address placeholder.
- No five-year retention architecture. Records are retained per internal data policies, not the BSA-derived five-year floor.
- Verification is risk-stratified in ways that skip low-risk accounts. The CIP minimum applies to all accounts, not just high-risk ones. Risk-based approaches govern the depth of verification, not whether it occurs.
If you’re a stablecoin issuer building toward a GENIUS Act license, the time to address these gaps is now — before you’re operating under an approved program and subject to examination.
If you already have an AML program built for MSB registration, the upgrade path is specific: add the four-element collection, build documentary and non-documentary verification workflows, establish the five-year retention system, and formalize any third-party CIP reliance arrangements in written agreements.
A baseline BSA/AML risk assessment structured on the FFIEC’s four risk categories — products and services, customer types, geographies, and delivery channels — is also the right starting document for understanding where your stablecoin program’s residual risk sits after controls. The AML/BSA Risk Assessment Template is built for this framework and can help structure the program documentation before it goes in front of an examiner or licensing authority.
The Comment Deadline: What’s Worth Commenting On
August 21 is the practical deadline for shaping this rule before it’s finalized. Comments that are specific and operational have the most impact. Areas where the proposed rule leaves interpretive room that the final rule will need to resolve:
The definition of “account holder” in distributed infrastructure. When a stablecoin operates across multiple blockchain networks and wallets are created by third-party applications, identifying which entity is the “account holder” in a CIP sense is non-trivial. Comments from issuers about how this definition should apply in distributed architectures would help the agencies write a workable standard.
Third-party reliance standards for embedded stablecoin. If a bank has onboarded a customer through its own full CIP process and that same customer accesses a stablecoin product through the bank, requiring a second CIP is operationally redundant. The proposed rule permits reliance arrangements — comments should clarify what evidence of a prior compliant CIP is sufficient to trigger reliance.
Non-U.S. person TIN collection in jurisdictions without equivalent identifiers. The TIN requirement works cleanly for U.S. persons. For international holders in jurisdictions without a standardized taxpayer identification number system, the rule’s approach needs clarification. Comments from issuers with global user bases would help.
So What? What to Do Before the Final Rule Lands
Given the expected 2027 finalization timeline and 12-month compliance window, a stablecoin issuer that starts building now has a workable runway. Three things to do immediately:
1. Gap assessment. Run your current onboarding against the proposed four-element minimum. Identify which elements aren’t collected, which verification workflows don’t meet documentary or non-documentary standards, and what your current retention architecture is. This takes days, not weeks.
2. Comment if you have specific technical issues. The agencies asked for comments specifically on the scope of covered accounts, the definition of account holder, and third-party reliance standards. If your infrastructure raises interpretive questions, August 21 is your opportunity to put them in the administrative record.
3. Build toward the bank CIP standard, not the MSB standard. If your program was built for MSB registration, the gap to bank-level CIP is real but bridgeable. The core architecture — four-element collection, risk-based verification, five-year retention — is well-understood. The stablecoin specifics are new; the framework isn’t.
This rule isn’t the last piece of the GENIUS Act compliance puzzle. The AML/sanctions NPRM from April 2026 covers SAR filing, sanctions program requirements, and ongoing monitoring. The June 2026 compliance deadline post laid out the full reserve and redemption framework. The CIP rule is the identity verification layer that operates alongside all of them.
The agencies are treating PPSIs like banks. Build the CIP like one.
Sources: FinCEN GENIUS Act CIP NPRM Press Release | Sullivan & Cromwell CIP NPRM Analysis | McGuireWoods Alert: FinCEN CIP Regime for Stablecoins | NCUA Press Release: CIP Requirements for Stablecoin Issuers
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AML/BSA Risk Assessment Template (Fintech Edition)
32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Who is required to implement a CIP under the GENIUS Act's proposed rule?
What is the minimum information a PPSI must collect under the proposed CIP rule?
How long does a PPSI need to retain CIP records?
How does the PPSI CIP rule differ from what a money services business must do today?
When is the comment period on the CIP NPRM and how can I file a comment?
Does the CIP rule cover secondary market transactions — when someone buys a stablecoin from another holder rather than directly from the issuer?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AML/BSA Risk Assessment Template (Fintech Edition)
32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.
◆ Keep reading
Related posts.
Regulatory Compliance
UBS $125 Million AML Penalty: The Data Failures Behind the Repeat Violation
The UBS AML penalty exposes FX wire data gaps, weak CDD, and failed remediation. Here is what compliance teams should test now.
Aug 2, 2026
Regulatory Compliance
Examiners Are Now Asking About Your Non-Work-Authorized Borrower Portfolio: What the July 2026 Interagency Guidance Requires
On July 13, 2026, the OCC, FDIC, and NCUA issued interagency guidance telling financial institutions to apply safe-and-sound credit risk practices when lending to borrowers not legally authorized to work in the US. Here's what examiners will actually look for — and how to build a defensible program.
Aug 1, 2026
Regulatory Compliance
The CFPB Gutted Federal Disparate Impact. Now AI-Driven Lenders Have a State Fair Lending Problem.
The CFPB's Reg B final rule, effective July 21, 2026, removed the effects test from ECOA — but five states immediately reaffirmed their own disparate impact regimes, NYDFS issued an industry letter the same day, and CFPB Circular 2026-03 kept adverse action notice requirements fully in place for AI models. For any lender using algorithmic underwriting, this isn't deregulation. It's a compliance map with more moving parts.
Jul 31, 2026