ComplyFactor helps payment stablecoin issuers and fintechs preparing to issue stablecoins build the compliance work that comes with it β regulatory readiness, AML/CFT program design, sanctions controls, customer identification, stablecoin-specific risk assessment, policies and procedures, gap assessment, and remediation.
The GENIUS Act is enacted federal law; the rules that will govern the day-to-day mechanics are still moving through federal rulemaking. ComplyFactor scopes and builds compliance work against where that framework currently stands, not against an assumption of what it will eventually say.
Signed into law July 2025. Federal agencies are still finalizing the rules that will govern AML/CFT, sanctions, and customer identification for payment stablecoin issuers.
The first thing that gets assessed isn't the law β it's what the business actually does. A prospective issuer, an existing nonbank issuer transitioning toward permitted status, a bank or credit union considering a stablecoin subsidiary, a fintech adding issuance as a new product line, and a payments or crypto business entering the space for the first time are not the same engagement, even before any specific rule gets applied.
The engagement starts by confirming which side of that line a business is actually on, so the work builds controls for the obligations that apply and doesn't build for ones that don't.
The entity responsible for minting and redeeming a payment stablecoin sits in a different position from an exchange, custodian, or payment processor using someone else's stablecoin β those businesses don't become issuers by virtue of that activity alone.
The assessment covers issuer status and pathway β bank subsidiary, federal qualification through the OCC, or state qualification β the actual product and redemption model, existing registrations or licenses, customers, counterparties, jurisdictions involved, and what AML and sanctions controls are already in place.
Building around an enacted requirement is different from preparing against a proposal whose final details may still change, so the assessment identifies the current legal status of each control before program design begins.
Support generally falls into a handful of areas, scoped to where a business actually sits β planning to issue, mid-application, or already operating and adjusting to the framework as it firms up:
Where agreed
Not every engagement touches every item above β the sections below explain how each area is actually scoped and delivered, and ComplyFactor doesn't grant regulatory approval, certify GENIUS Act compliance, or guarantee licensing outcomes as part of any of it.
Customer identification work covers classifying which relationships actually require identification and verification under the proposed standard, designing the verification and recordkeeping procedures themselves, documenting customer-notice requirements, and β where it's a genuine fit β structuring reliance arrangements with another BSA-regulated institution rather than duplicating verification work.
FinCEN and the federal banking agencies proposed a customer identification rule for issuers in June 2026; it is not yet final. Nonbank issuers running crypto-style onboarding should generally expect the eventual standard to be more formal than what they use today β which is where this work usually starts.
Support generally falls into a handful of areas, scoped to where a business actually sits β planning to issue, mid-application, or already operating and adjusting to the framework as it firms up:
The GENIUS Act directs that permitted payment stablecoin issuers be treated as financial institutions under the Bank Secrecy Act. FinCEN and OFAC's joint proposed rule addressing this β issued April 2026 β remains a proposed rule as of this writing, not a final one. Programs are built toward its direction while staying adjustable as it moves toward finalization.
AML/CFT and sanctions compliance are related but legally separate functions, and a stablecoin program needs both built to work together rather than merged into one control. This work covers sanctions-screening design, blocked-party and geographic exposure assessment, counterparty and wallet-level exposure, and the escalation and policy documentation that ties screening decisions to an actual process.
ComplyFactor's OFAC & Sanctions Compliance Services cover a full, standalone sanctions-program build; this work is specifically about integrating that function into a stablecoin issuer's broader compliance framework rather than duplicating that page.
Rather than applying controls generically, this work maps where risk actually enters a specific stablecoin's operation β the issuer's own governance, the customer relationship at onboarding, the funding and minting event itself, the transfer once the stablecoin is issued and moving (often outside the issuer's direct visibility), the redemption event where the issuer is back in a direct relationship with the counterparty, and the counterparty, wallet, and geographic exposure running through all of it.
This mapping is what determines which controls actually get built where, rather than applying the same checklist regardless of how a specific issuer's flow works.
For an issuer that already has some compliance infrastructure β often built for a prior money-transmitter or crypto-platform status β the work starts with a gap assessment rather than a build from zero.
Reviewed as they stand
Against actual activity
Not generic ones
And rule-finalization stage
Implementation where agreed
The output is a remediation roadmap, not just a findings list.
Understanding what's actually being issued, minted, transferred, and redeemed, and by whom.
Confirming which issuer pathway, if any, is realistic and relevant.
Mapping current controls against the flow above.
Building or revising what the assessment calls for.
Sequencing fixes by risk and by where the underlying rule stands.
Where agreed as part of the engagement.
Depending on scope: a regulatory-readiness assessment, a stablecoin-specific risk assessment, AML/CFT program documentation, written policies and procedures, a customer identification and control framework, a transaction-monitoring framework, a sanctions-control framework, governance and responsibility documentation, a gap-assessment report with a prioritized remediation roadmap, implementation recommendations, a training framework, and independent-review readiness recommendations.
Deliverables depend on the agreed scope and the business's actual model β a pre-launch readiness assessment and a full program build for an operating issuer don't produce the same set of documents.
A few points are worth treating as a natural prompt to review rather than waiting for a fixed date:
The GENIUS Act was signed into law in July 2025 and is enacted federal statute, not a proposal. It takes effect on the earlier of January 18, 2027, or 120 days after federal regulators finalize their implementing rules; since no final rules exist as of this writing and the window for beating that date has effectively closed, January 18, 2027 currently governs. A second deadline, July 18, 2028, separately restricts digital asset service providers from offering stablecoins to U.S. persons unless they come from a permitted issuer.
As of this writing, the OCC, Federal Reserve, FDIC, NCUA, Treasury, FinCEN, and OFAC have collectively issued proposed rules covering issuer licensing, AML/CFT and sanctions programs, and customer identification β none of them final. The OCC has indicated it is targeting a final rule around November 2026, but that had not been issued as of this writing. ComplyFactor scopes stablecoin compliance work against this current status and updates it as rules move toward finalization, rather than treating any current proposal as settled law.
ComplyFactor approaches stablecoin compliance as an extension of its existing U.S. BSA/AML and sanctions practice, not as a separate specialty applied on top of a generic crypto AML template β the same grounding that goes into building BSA/AML programs and OFAC sanctions frameworks for U.S. MSBs and payment businesses applies directly to issuer-specific obligations. Scoping is built around the specific issuance model and pathway a business is actually pursuing and tracked against where the underlying rulemaking currently stands, rather than a fixed assumption about final requirements. Where a business also needs related work β a broader BSA/AML program, sanctions program, or money transmitter licensing β that work is coordinated rather than duplicated across separate engagements.
Yes β the engagement can be scoped as an independent gap and readiness review of an existing program rather than a full rebuild.
Yes. A gap assessment against your current controls and actual regulatory classification is a common starting point, with a full program build only where the assessment shows it's needed.
Yes β a review can be scoped before launch to assess the proposed issuance model, customer flow, and required controls. This isn't a guarantee of regulatory approval or launch readiness certification.
Yes. The engagement can be scoped to a specific area β AML/CFT program design, sanctions integration, customer identification, or another agreed component β rather than the full framework.
Yes β where appropriate, the engagement can be scoped around the specific findings raised, rather than a broader program assessment.
Typically the business model and issuance plans, jurisdictions and customer types involved, current launch stage, any existing licenses or registrations, current policies and compliance controls, and any known findings or gaps.
No. Scope can be limited to specific gaps, controls, or program components depending on what the business already has in place and what the assessment finds.
Tell us about your issuance model, launch stage, likely regulatory pathway, current AML/CFT and sanctions framework, customer controls, and any gaps you're already aware of. We'll confirm scope before anything begins.