Skip to content
RiskTemplates · The Daily Brief Monday, August 3, 2026
Wire The Exodus OFAC Settlement: What a $3.1M Crypto Wallet Enforcement Action Teaches About Sanctions Compliance Programs JUL 30

Feature Regulatory Compliance

Stablecoin Issuers Just Got a Customer Identification Mandate. The Comment Deadline Is August 21.

On June 18, 2026, FinCEN and four federal banking agencies proposed the first-ever Customer Identification Program requirements for permitted payment stablecoin issuers under the GENIUS Act. The comment period closes August 21. Here's what the rule requires, where it matters most, and what stablecoin compliance programs need to build.

By Rebecca Leung · August 2, 2026 ·
Table of Contents

TL;DR

  • On June 18, 2026, FinCEN, OCC, Federal Reserve, FDIC, and NCUA jointly proposed Customer Identification Program (CIP) requirements for permitted payment stablecoin issuers (PPSIs) under the GENIUS Act
  • The comment period closes August 21, 2026 — 18 days from today
  • PPSIs must collect legal name, date of birth, address, and taxpayer identification number for each account holder — and retain those records for five years after account closure
  • This is a bank-level CIP requirement, not the lighter MSB standard — stablecoin issuers that treat their current onboarding as “good enough” are likely to have gaps
  • The final rule is expected in 2027, with compliance required 12 months after issuance — but building the program now reduces implementation risk

The July 18 Deadline Passed. The Rules Are Still Coming.

Most stablecoin compliance teams spent the first half of 2026 watching the July 18 clock — the GENIUS Act’s statutory deadline for federal agencies to issue implementing regulations. That deadline has passed. The rules are in varying stages of finalization.

What’s now active and time-sensitive is the comment period on the specific CIP rule. The June 18, 2026 notice of proposed rulemaking from FinCEN and four federal banking agencies — OCC, Federal Reserve, FDIC, and NCUA — closes on August 21, 2026. If you haven’t read it and don’t have a view on what it requires, you’re now 18 days from missing the opportunity to shape it.

More immediately: even if you don’t file a comment, the operational implications of this rule are real and specific. The CIP requirements for PPSIs are not the informal “know your customer” practices most crypto companies built around exchange onboarding or MSB registration. They are the bank-level CIP standard — written policies, verification requirements, five-year record retention, board-level accountability. Building that program requires lead time.

Here’s what the proposed rule requires and where the operational complexity actually lives.

Who This Rule Covers

The CIP NPRM applies to permitted payment stablecoin issuers (PPSIs) — the category of entities licensed to issue payment stablecoins under the GENIUS Act.

That includes:

  • Federally chartered issuers licensed by the OCC or Federal Reserve
  • Bank subsidiaries of insured depository institutions issuing stablecoins
  • State-licensed issuers whose state regulatory frameworks have been certified by Treasury as “substantially similar” to the federal GENIUS Act standard

If you’re currently issuing stablecoins without a GENIUS Act license, you’re already prohibited under the statute — the CIP rule is for the licensed population. If you’re applying for a license or operating under a state regime pending Treasury certification, this rule defines the compliance obligations you’re accepting.

Volume threshold note: issuers with less than $10 billion in outstanding stablecoin can operate under state regimes — but only certified state regimes. That certification process is still underway for most states. Don’t assume your state qualifies until Treasury confirms it.

What the CIP Must Collect

The proposed rule establishes minimum data requirements that track the existing CIP rule applied to banks and broker-dealers.

For each account holder, a PPSI’s CIP must collect:

ElementRequirement
Legal nameFull legal name — not a pseudonym or wallet address
Date of birthFor individuals; entity formation date for legal persons
AddressResidential or business address — P.O. Box insufficient as the sole address
Taxpayer Identification Number (TIN)SSN for U.S. persons; ITIN or EIN for non-U.S. persons; foreign TIN where applicable

The agencies borrowed this structure directly from the 31 CFR Part 1020 CIP rule applied to banks. That’s deliberate — PPSIs are being treated as financial institutions under the BSA, not as MSBs or tech companies. The CIP is where that treatment becomes operationally concrete.

What “account holder” means matters here. The proposed rule defines the CIP obligation around the account relationship between the PPSI and the person or entity holding an account directly with it. Wallets or accounts created by third-party applications that access the issuer’s infrastructure may create intermediary layers the rule addresses separately under the concept of reliance on third-party CIP.

Verification: The Gap Between Collecting and Confirming

Collecting the four data elements isn’t the same as verifying them. The proposed rule requires PPSIs to verify the information — though the verification methodology is risk-based, not prescriptive.

Banks typically use two methods: documentary (government-issued ID, passport) and non-documentary (credit bureau cross-reference, public database verification, comparison of social security number against death records). The proposed rule allows similar flexibility but requires the PPSI to document its verification methodology and apply it consistently.

Where this creates operational complexity for stablecoin issuers:

Pseudonymous wallet history doesn’t verify identity. Crypto companies have historically relied on wallet behavior as a proxy for identity risk. The CIP rule requires documentary or non-documentary verification of the account holder’s legal identity — behavioral signals are risk indicators, not CIP substitutes.

Non-U.S. persons require TIN collection that many onboarding flows aren’t built for. A GENIUS Act stablecoin has the potential to be globally accessible. Non-U.S. account holders require foreign TIN or, in cases where that’s unavailable, an explanation of why the TIN was not collected — which itself needs to be documented.

Third-party CIP reliance is available but regulated. The proposed rule allows PPSIs to rely on a third party (such as a bank that has already completed CIP on a shared customer) — but requires a written agreement specifying the third party’s obligations and the PPSI’s right to access CIP records promptly. If your stablecoin onboarding is downstream of a partner bank’s KYC, verify whether that arrangement meets the formal reliance standard.

Record Retention: Five Years Is the Floor

The proposed rule establishes two separate retention clocks:

Customer identifying information: retained for five years after the account is closed.

Verification records — documents reviewed, methods applied, results, discrepancies resolved: retained for five years after the record is created.

For long-lived accounts, the verification records start their five-year clock when collected, while the identifying information clock doesn’t start until closure. A customer who opens an account in 2027 and closes it in 2040 would require retention of their identifying information until 2045 — but their 2027 verification records could expire in 2032 under the second retention clock.

For compliance programs used to treating crypto wallet records as indefinitely ephemeral or governed only by their own product policies, this creates a retention framework that needs to be built deliberately. It can’t be bolted on retrospectively when the examiner asks.

What This Means for Your Current Onboarding

The honest assessment for most stablecoin issuers: current onboarding flows have gaps relative to what this rule requires.

Common gaps:

  • No date of birth collection for individual account holders. Many crypto onboarding flows collect a wallet address and an email — not the four statutory elements.
  • No systematic TIN collection. CIP requires it; typical crypto KYC practices don’t uniformly collect TINs.
  • Address verification treated as optional. CIP requires address at account opening — not as an optional field or a billing address placeholder.
  • No five-year retention architecture. Records are retained per internal data policies, not the BSA-derived five-year floor.
  • Verification is risk-stratified in ways that skip low-risk accounts. The CIP minimum applies to all accounts, not just high-risk ones. Risk-based approaches govern the depth of verification, not whether it occurs.

If you’re a stablecoin issuer building toward a GENIUS Act license, the time to address these gaps is now — before you’re operating under an approved program and subject to examination.

If you already have an AML program built for MSB registration, the upgrade path is specific: add the four-element collection, build documentary and non-documentary verification workflows, establish the five-year retention system, and formalize any third-party CIP reliance arrangements in written agreements.

A baseline BSA/AML risk assessment structured on the FFIEC’s four risk categories — products and services, customer types, geographies, and delivery channels — is also the right starting document for understanding where your stablecoin program’s residual risk sits after controls. The AML/BSA Risk Assessment Template is built for this framework and can help structure the program documentation before it goes in front of an examiner or licensing authority.

The Comment Deadline: What’s Worth Commenting On

August 21 is the practical deadline for shaping this rule before it’s finalized. Comments that are specific and operational have the most impact. Areas where the proposed rule leaves interpretive room that the final rule will need to resolve:

The definition of “account holder” in distributed infrastructure. When a stablecoin operates across multiple blockchain networks and wallets are created by third-party applications, identifying which entity is the “account holder” in a CIP sense is non-trivial. Comments from issuers about how this definition should apply in distributed architectures would help the agencies write a workable standard.

Third-party reliance standards for embedded stablecoin. If a bank has onboarded a customer through its own full CIP process and that same customer accesses a stablecoin product through the bank, requiring a second CIP is operationally redundant. The proposed rule permits reliance arrangements — comments should clarify what evidence of a prior compliant CIP is sufficient to trigger reliance.

Non-U.S. person TIN collection in jurisdictions without equivalent identifiers. The TIN requirement works cleanly for U.S. persons. For international holders in jurisdictions without a standardized taxpayer identification number system, the rule’s approach needs clarification. Comments from issuers with global user bases would help.

So What? What to Do Before the Final Rule Lands

Given the expected 2027 finalization timeline and 12-month compliance window, a stablecoin issuer that starts building now has a workable runway. Three things to do immediately:

1. Gap assessment. Run your current onboarding against the proposed four-element minimum. Identify which elements aren’t collected, which verification workflows don’t meet documentary or non-documentary standards, and what your current retention architecture is. This takes days, not weeks.

2. Comment if you have specific technical issues. The agencies asked for comments specifically on the scope of covered accounts, the definition of account holder, and third-party reliance standards. If your infrastructure raises interpretive questions, August 21 is your opportunity to put them in the administrative record.

3. Build toward the bank CIP standard, not the MSB standard. If your program was built for MSB registration, the gap to bank-level CIP is real but bridgeable. The core architecture — four-element collection, risk-based verification, five-year retention — is well-understood. The stablecoin specifics are new; the framework isn’t.

This rule isn’t the last piece of the GENIUS Act compliance puzzle. The AML/sanctions NPRM from April 2026 covers SAR filing, sanctions program requirements, and ongoing monitoring. The June 2026 compliance deadline post laid out the full reserve and redemption framework. The CIP rule is the identity verification layer that operates alongside all of them.

The agencies are treating PPSIs like banks. Build the CIP like one.


Sources: FinCEN GENIUS Act CIP NPRM Press Release | Sullivan & Cromwell CIP NPRM Analysis | McGuireWoods Alert: FinCEN CIP Regime for Stablecoins | NCUA Press Release: CIP Requirements for Stablecoin Issuers

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Who is required to implement a CIP under the GENIUS Act's proposed rule?
The proposed rule applies to permitted payment stablecoin issuers (PPSIs) — entities that have obtained or applied for a license to issue payment stablecoins under the GENIUS Act. This includes federally chartered issuers licensed by the OCC or Federal Reserve, bank subsidiaries issuing stablecoins, and state-licensed issuers whose state frameworks have been certified as substantially similar to the federal standard by Treasury. Non-licensed entities issuing stablecoins are prohibited outright under the GENIUS Act; the CIP rule is for the licensed ones.
What is the minimum information a PPSI must collect under the proposed CIP rule?
At minimum, PPSIs must collect four data elements for each account holder: legal name, date of birth (for individuals), address (residential or business), and a taxpayer identification number (TIN — Social Security number for US persons, individual taxpayer identification number or employer identification number for non-US persons). This mirrors the minimum CIP data requirements that apply to banks and broker-dealers under existing BSA rules.
How long does a PPSI need to retain CIP records?
The proposed rule establishes two retention periods. Customer identifying information must be retained for five years after the account is closed. Records concerning verification — the documents reviewed, the verification methods and results, and any discrepancy resolution — must be retained for five years after the record is made. For an account that stays open, that means the verification records are retained from the date they were created, not from account closure.
How does the PPSI CIP rule differ from what a money services business must do today?
Existing MSB requirements do not include a formal CIP requirement. MSBs must maintain a risk-based AML program, file SARs and CTRs, and implement customer due diligence — but the specific CIP structure (collect and verify four data elements at account opening; retain records for five years) is a bank-level obligation that was not previously applied to crypto companies or MSBs. The GENIUS Act treats PPSIs as financial institutions under the BSA, not as MSBs, and the CIP rule reflects that elevated standard.
When is the comment period on the CIP NPRM and how can I file a comment?
The CIP NPRM was published in the Federal Register on June 22, 2026. The 60-day comment period closes August 21, 2026. Comments are submitted via regulations.gov using the docket number listed in the Federal Register notice. Comments should address specific provisions — the scope of covered accounts, verification standards, third-party reliance rules, or record retention requirements — rather than general opposition or support.
Does the CIP rule cover secondary market transactions — when someone buys a stablecoin from another holder rather than directly from the issuer?
The proposed rule is structured around the account relationship between the PPSI and the account holder. Secondary market transactions — transfers between holders who don't have a direct account with the issuer — are treated differently. The agencies proposed limiting CIP obligations to primary issuance account relationships, consistent with how the AML/sanctions NPRM from April 2026 handled secondary market SAR obligations. Issuers should track this distinction carefully, as secondary market accounts opened directly with the issuer would still be subject to CIP.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AML/BSA Risk Assessment Template (Fintech Edition)

32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.