Skip to content
RiskTemplates · The Daily Brief Sunday, September 27, 2026
Wire OFAC Just Codified Its Penalty Playbook. What 31 CFR Part 505 Means for Your Sanctions Compliance Program. SEP 26

Feature Regulatory Compliance

Federal Reserve Stablecoin Rules: The Capital Math and Application Binder Banks Need Now

Federal Reserve stablecoin rules propose capital, reserve, reporting, custody, and application standards under the GENIUS Act.

By Rebecca Leung · September 25, 2026 ·
Table of Contents

TL;DR

  • The Federal Reserve’s September 24 proposals finally put numbers around bank stablecoin risk: operational-risk capital starts at 2% of the first $20 billion outstanding, then steps down as issuance grows.
  • A Board-supervised issuer would need 1:1 segregated reserves, redemption within two business days, weekly supervisory reporting, quarterly financial reporting, and an exam generally every 12 months.
  • The application is a control-evidence package, not a product pitch: three-year projections, reserve scenarios, third-party maps, private-key authority, draft policies, management background checks, and formal certifications.
  • These are proposals, not final rules. The comment period closes 60 days after Federal Register publication.

The Federal Reserve just turned “we may launch a stablecoin” from a strategy slide into a capital calculation and an application binder.

On September 24, 2026, the Board released two proposed Federal Reserve stablecoin rules under the GENIUS Act. One would govern Board-supervised payment stablecoin issuers, reserve custodians, and related banking activities. The other would tell insured state member banks exactly how to seek approval for a subsidiary to issue payment stablecoins.

The headline is 1:1 reserves. The operational story is much bigger: graduated capital charges, a two-business-day redemption clock, weekly data submissions, annual examinations, private-key governance, third-party documentation, and a 120-day decision period that does not start until the application is “substantially complete.”

For the compliance officer who was handed a stablecoin deck and told to “figure out the regulatory path,” this is the first Fed-specific build sheet worth using.

What the Federal Reserve stablecoin rules would cover

The Federal Reserve’s September 24 press release describes two linked proposals:

ProposalWho it affectsWhat it does
Prudential and operating frameworkBoard-supervised permitted payment stablecoin issuers, Board-supervised custodians, and banking organizations engaged in related activitiesSets reserve, capital, redemption, risk-management, custody, reporting, examination, activity, and anti-tying standards
Application frameworkInsured state member banks seeking approval for an issuing subsidiaryDefines the filing package, review factors, completeness test, decision timeline, denial process, appeal rights, and possible conditions

The core issuer framework applies to subsidiaries of insured state member banks approved by the Fed and certain state-qualified issuers with at least $10 billion in payment stablecoins outstanding that transition into Board supervision. But pieces reach further. Custody requirements apply to Board-supervised firms safeguarding reserve assets, stablecoins used as collateral, or private keys. The proposed anti-tying rule would apply to every permitted payment stablecoin issuer, even when the Fed is not its primary regulator.

That scope distinction matters. A bank that does not plan to mint a token can still be pulled into the framework as a reserve custodian, key custodian, affiliate, market-making counterparty, or parent company.

This is also why the proposal deserves its own treatment despite the site’s earlier GENIUS Act deadline analysis. That article covered the regulatory gap. The new proposal supplies the Fed’s missing operating numbers and filing mechanics.

The capital formula is no longer abstract

The Fed staff memo on the prudential proposal lays out three capital components for a Board-supervised issuer.

1. Operational risk from issuance and reserve management

The proposed charge is graduated by stablecoins outstanding:

Outstanding payment stablecoinsProposed operational-risk capital charge
First $20 billion2.0%
Next $30 billion1.5%
Amount above $50 billion1.0%

This is a marginal structure. A hypothetical issuer with $30 billion outstanding would not apply 1.5% to the full amount. It would calculate 2% on the first $20 billion and 1.5% on the next $10 billion, before other applicable components.

The proposal also adds a loss scalar that can move the operational-risk requirement up or down based on realized operational losses. That makes incident classification, loss capture, and root-cause data capital inputs. If the operational-loss database lives in a spreadsheet owned by Internal Audit and excludes near misses, Risk and Finance will be arguing over the capital number later.

2. Credit risk in selected reserve assets

A separate 2% capital requirement would apply to reserve assets held as uninsured deposit claims and undercollateralized reverse repurchase agreements. Eligible investment funds would receive a look-through treatment for those exposures.

The practical tradeoff is now visible: an asset may be legally permissible and still create a capital cost. Treasury, Risk, and Finance need one reserve-instrument inventory with fields for legal eligibility, maturity, counterparty, insurance status, collateralization, concentration, liquidity, and proposed capital treatment.

3. Risk outside the reserve portfolio

For custody and other activities not captured by issuance volume, the proposal would impose a charge equal to 25% of the three-year average of annual non-reserve-asset revenue. Other non-reserve assets would remain subject to the capital rules applicable to state member banks under 12 CFR Part 217.

That is a reason to separate issuer economics from affiliate economics before filing. A vague “digital asset ecosystem” revenue model will not help Finance calculate capital or help the Fed understand which entity bears which risk.

If an issuer misses minimum capital at quarter-end, it would need a restoration plan. If noncompliance persists through the next quarter, the proposal would require liquidation of reserves and redemption of all outstanding stablecoins. Capital monitoring therefore needs a forward-looking trigger well before the regulatory minimum—not a quarter-end discovery.

The reserve rule creates daily control work

The proposal would require reserve assets to equal or exceed the par value of outstanding stablecoins at all times, not only at a monthly attestation date. Assets must be segregated and limited to specified categories, including U.S. dollars, Federal Reserve balances, demand deposits at insured depository institutions, Treasury securities with remaining maturities of 93 days or less, specified overnight repos and reverse repos, eligible funds invested only in permissible assets, and certain tokenized versions of permissible assets.

The proposed control stack is straightforward to describe and hard to operate:

RequirementControl ownerEvidence the examiner can test
1:1 backing at all timesTreasurer with Finance control supportDaily—or more frequent—token-supply-to-reserve reconciliation, exception log, signed review
Reserve segregationController and LegalCustody agreements, account titles, ledger mapping, legal-entity reconciliation
Concentration managementTreasury RiskCounterparty limits, affiliate aggregation, stress scenarios, breach escalation
Two-business-day redemptionPayments OperationsTime-stamped request-to-settlement data, failed-redemption log, capacity test results
Monthly public reserve disclosureFinance and CompliancePublished disclosure, source-data lineage, disclosure approval record
Weekly confidential reportingRegulatory ReportingIssuance, redemption, volume, and reserve-data submission with validation evidence

The starter thresholds in that table should come from the rule where the rule supplies them. Internal warning thresholds—such as a reserve coverage escalation buffer above 100%—must be calibrated to the issuer’s settlement timing, intraday minting, asset volatility, and operational history. They should not be copied from a generic benchmark.

A breach of 1:1 backing would trigger notice to the Federal Reserve and, absent an approved prompt-restoration plan, liquidation of reserve assets and redemption of outstanding tokens. That is not a monthly reporting issue. It is an incident-response scenario with Treasury, Operations, Legal, Compliance, Finance, Communications, and the Board on the call tree.

The proposal also expects a public redemption policy with a period no longer than two business days, except where a safe harbor applies. Fees must be clearly disclosed, and fee changes require at least seven days’ prior notice. Product cannot leave those terms in a versionless help-center page.

The stablecoin application is an evidence binder

The separate Fed application proposal says an insured state member bank would apply by letter. There is no proposed form. That does not make the filing lighter; it makes document architecture more important.

The full application proposal identifies the expected package:

  • a business plan describing the product, legal basis, governance, affiliate relationships, material third parties, and each entity’s role;
  • an explanation of how stable value will be maintained, including guarantees, market makers, distributors, and parties controlling private keys or mint-and-redeem authority;
  • initial and ongoing funding, projected reserve composition, reserve-management scenarios, and three years of financial projections with assumptions;
  • policies and agreements covering redemption, reserves, custody, recordkeeping, reconciliation, transaction processing, BSA/AML, sanctions, and counter-terrorist-financing compliance;
  • capital-structure information where the issuer is not wholly owned;
  • biographical submissions and background checks for relevant decision-makers and principal shareholders; and
  • certifications addressing disqualifying felony convictions and the absence of material misstatements or omissions in the filing.

The most common build mistake will be assigning the application to Legal and asking other teams for documents two weeks before filing. The better operating model is a requirements matrix with one row per proposed requirement, one accountable owner, one evidence artifact, one reviewer, and one open-gap decision.

The Fed would have 30 days after receipt to say whether an application is substantially complete. Once it is substantially complete, the Board would have 120 days to decide. If it fails to act within that period, the application is deemed approved. But a material change—deteriorating financial condition, a changed business plan, or new ownership, for example—can reset the submission date and restart the 120-day clock.

So the clock is useful, but only after the binder works. “We sent something four months ago” is not the same as “the Fed deemed it substantially complete four months ago.”

Five workstreams to open Monday morning

1. Make Finance run the capital calculation

Build a scenario model at expected launch volume, year-one volume, and stress volume. Include the graduated issuance charge, credit-risk charge for affected reserves, non-reserve revenue charge, and parent-company capital treatment. Document assumptions and link each input to a source system.

2. Make Treasury prove redemption capacity

Run a realistic hypothetical stress: elevated redemptions during a Treasury-market disruption plus the outage of the largest deposit counterparty. Measure how long it takes to source cash, authorize movement, screen the transaction, and settle. Record failures as issues with owners and due dates.

3. Map every party that can touch a token or reserve dollar

The map should include the issuer, parent bank, reserve custodian, subcustodian, blockchain infrastructure provider, smart-contract administrator, private-key holder, market maker, distributor, sanctions-screening vendor, and any party with mint or burn authority. Attach the contract, service-level agreement, audit right, incident-notice term, and exit plan for each material third party.

4. Build the reporting lineage before the report template

The proposal calls for confidential weekly information on issuance, redemptions, trading volume, and reserves, plus quarterly financial-condition reporting. Regulatory Reporting should trace every field to its system of record and define reconciliation, validation, correction, and sign-off steps. A dashboard without lineage is presentation, not evidence.

5. Open a controlled comment log

The comment period will run for 60 days after Federal Register publication. Assign Regulatory Affairs to collect operational questions from Treasury, Finance, Compliance, Technology, and Payments Operations. The strongest comment is not “this is burdensome.” It identifies a specific provision, explains the operating conflict with evidence, and proposes workable text.

Governor Michael Barr’s statement supporting the proposal flags unresolved questions on interest-rate risk, foreign-currency risk, universal redemption rights, and the proposed “significant or systemic” threshold for AML-related supervisory or enforcement action. Reuters also reported that the Fed’s framework would add reserve, capital, and redemption requirements as GENIUS Act implementation continues. Those are useful signals for the comment agenda—not permission to wait.

So what?

The Fed’s proposal changes the stablecoin conversation from legal classification to operating proof. A bank applicant must show who controls issuance, where every reserve asset sits, how redemptions clear during stress, how capital absorbs losses, how third parties are governed, and where each reported number came from.

That is the practical takeaway for the CRO and CCO: treat the proposal as a pre-launch control specification. Give Finance the capital model, Treasury the reserve and redemption design, Technology the key-management evidence, Compliance the BSA and sanctions controls, and Regulatory Affairs the filing matrix. Then make Internal Audit or an independent second-line reviewer challenge the package before the Fed does.

For teams converting a stablecoin concept into a documented approval package, the New Product Risk Assessment includes a worked stablecoin assessment and pre-launch control checklist.

For adjacent buildouts, see the site’s GENIUS Act AML/CFT breakdown and stablecoin custodian due-diligence framework.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the Federal Reserve propose for bank-issued stablecoins?
The Federal Reserve proposed one rule covering reserves, capital, redemption, risk management, custody, reporting, examinations, and related bank activities, plus a separate rule establishing the application process for an insured state member bank that wants a subsidiary to issue payment stablecoins. Both proposals are subject to public comment and are not final.
How much capital would a Federal Reserve-supervised stablecoin issuer need?
The proposal includes an operational-risk charge of 2% on the first $20 billion of stablecoins outstanding, 1.5% on the next $30 billion, and 1% above $50 billion. It also proposes a 2% charge on certain uninsured deposits and undercollateralized reverse repos, plus a charge equal to 25% of average annual non-reserve-asset revenue over three years. Actual capital would depend on the issuer's activities and reserve mix.
Which stablecoin issuers would the Federal Reserve rules cover?
The issuer-specific framework would cover subsidiaries of insured state member banks approved to issue payment stablecoins and certain state-qualified issuers with at least $10 billion outstanding that transition to Federal Reserve supervision. Other provisions reach Board-supervised custodians, banking organizations engaged in stablecoin activities, and, for the anti-tying rule, all permitted payment stablecoin issuers.
What would a bank need to include in a stablecoin application?
An insured state member bank would submit an application by letter with a business plan, three-year financial projections and assumptions, reserve composition and management plans, relevant policies and agreements, capital-structure documentation, biographical information, and certifications. The application would also need to explain material third parties, private-key control, mint-and-redeem authority, governance, and compliance with the GENIUS Act.
How long would the Federal Reserve have to decide a stablecoin application?
The proposal says the Federal Reserve must notify the applicant within 30 days whether the filing is substantially complete. Once substantially complete, the Board has 120 days to decide; if it does not act within that period, the application is deemed approved. A material change can restart the 120-day clock.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

New Product Risk Assessment

Structured risk review process for new products, services, and business initiatives.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.