
Public comments are due August 21 on a U.S. proposal that would require permitted payment stablecoin issuers to establish formal customer identification programs under the Bank Secrecy Act. The rulemaking is one of the main compliance measures being developed under the GENIUS Act, the federal stablecoin law enacted in July 2025.
The Financial Crimes Enforcement Network, Office of the Comptroller of the Currency, Federal Reserve, Federal Deposit Insurance Corporation and National Credit Union Administration jointly issued the proposal. The Federal Register notice, published June 22, says comments must be received by August 21 and identifies the rule as 91 FR 37234.
The deadline does not make the proposal effective. Regulators must review the public record before deciding how to shape a final rule, and the agencies have proposed a compliance date 12 months after any final rule is issued. Until then, the customer identification standards remain proposed requirements rather than binding new obligations.
Proposed program would bring bank-style identity checks to stablecoin issuers
The GENIUS Act directs permitted payment stablecoin issuers, known in the proposal as PPSIs, to be treated as financial institutions for Bank Secrecy Act purposes and to maintain an effective customer identification program. FinCEN said when the proposal was announced that the framework is intended to be comparable to customer identification requirements already used by banks and credit unions, while being tailored to stablecoin issuers.
Under the proposed rule, an issuer’s written program would need risk-based procedures designed to form a reasonable belief that it knows the identity of each customer. Before opening an account, the issuer generally would collect a name, date of birth for an individual or formation date for a legal entity, a physical address and an identification number. For a U.S. person, that number would generally be a taxpayer identification number. The proposal provides alternatives for non-U.S. customers, including passport or other government-issued identification information.
Identity could be verified through documents, non-documentary methods or a combination of the two. A driver’s license or passport is among the examples for individuals. For companies, partnerships or trusts, the proposal lists records such as certified articles of incorporation, a government-issued business license, partnership agreement or trust instrument. Non-documentary checks could include comparing information with a consumer reporting agency or public database, contacting the customer, checking references with another financial institution or obtaining a financial statement.
The proposed program also addresses failed verification. An issuer would need procedures covering when it should decline to open an account, what access may be allowed while verification is pending, when an account should be closed after unsuccessful verification attempts and when a Suspicious Activity Report may be appropriate under existing law.
Recordkeeping is another part of the framework. Customer identifying information would generally have to be retained for five years after an account closes, while records describing verification methods, documents and the resolution of material discrepancies would generally be retained for five years after the record is made. Prospective customers would also have to receive notice that the issuer is requesting information to verify identity.
Secondary-market stablecoin activity remains outside the proposal’s main customer-ID perimeter
A central issue in the rulemaking is where an issuer’s direct customer relationship ends and ordinary secondary-market stablecoin use begins. The agencies define an account around a formal relationship with the issuer, including activities such as issuing or redeeming payment stablecoins, custody and certain related services. Mere ownership or control of the issuer’s stablecoin, without other indicators of a formal relationship, would not by itself create an account under the proposed definition.
The proposal also excludes activity that does not directly involve the issuer as a party other than through a smart contract. A person who acquires or redeems a payment stablecoin through a means other than directly from or directly to the issuer would generally fall outside the proposed definition of customer. That distinction means the proposal is not written as a requirement for every holder in the secondary market to submit identification directly to the stablecoin issuer.
Regulators have left that boundary open for comment. One of the questions in the notice asks whether any customer identification requirement should be extended to secondary-market activity and, if so, under what circumstances. The agencies also ask whether the definitions of account, customer and digital asset service provider need further refinement, and whether the concept of a “formal relationship” should remain part of the account definition.
Digital identity is another unresolved area. The proposal asks whether the final regulatory text should expressly address digital identity solutions or verifiable credentials and what benefits or risks those tools could bring to customer verification. The agencies are therefore setting minimum identification concepts while seeking feedback on how newer identity technology might fit the stablecoin market’s largely digital onboarding process.
Existing customers are treated differently from new ones. A person with an existing account may be excluded from the customer definition when the issuer already has a reasonable belief that it knows the person’s true identity. The agencies’ economic analysis says the proposed requirements generally do not require new information collection for existing customers on that assumption, although regulators specifically requested feedback on whether that assumption is realistic.
Comment deadline advances a broader GENIUS Act compliance rollout
The customer-ID proposal sits within a larger set of rules implementing the GENIUS Act. The law, enacted as Public Law 119-27 on July 18, 2025, created a federal framework for payment stablecoins and directed regulators to develop rules covering licensing, reserves, supervision and financial-crime controls. The customer identification proposal focuses on one specific part of that framework rather than the full set of anti-money-laundering obligations for issuers.
That distinction matters because FinCEN has also pursued separate rulemaking on broader anti-money-laundering, countering-the-financing-of-terrorism and sanctions compliance requirements. In its June announcement of the customer identification proposal, FinCEN said the agencies were implementing the GENIUS Act’s direction to treat permitted payment stablecoin issuers as financial institutions under the Bank Secrecy Act while creating an appropriately tailored identity program.
The new framework would also change the regulatory baseline for issuers that have historically operated under money-services-business rules. The Federal Register notice says stablecoin issuers are presently subject to Bank Secrecy Act obligations as money transmitters, but money transmitters do not have the same formal customer identification program obligation applied to banks, broker-dealers, mutual funds and some other regulated financial institutions. The proposed PPSI rule is designed to close that specific gap for issuers covered by the GENIUS Act.
Issuers would be allowed in some circumstances to rely on another federally regulated financial institution to perform a required customer identification procedure, provided the reliance is reasonable and backed by the required contractual arrangements and annual certification. The stablecoin issuer would still remain responsible for its own compliance. The proposal also makes clear that third-party service providers may assist with customer identification without shifting the legal obligation away from the issuer.
With the August 21 comment period reaching its end, the next step belongs to the five agencies. They will have to evaluate feedback on the scope of customer relationships, secondary-market activity, digital identity tools, recordkeeping and operational burden before publishing any final standard. The proposed 12-month implementation period would begin only after a final rule is issued, leaving the current deadline as the close of the public input phase rather than the start of a new compliance mandate.
Latest News
View all news- NHTSA Opens Probe Into Nearly 1 Million GM Trucks and SUVs Over Engine Failures
- U.S. AI Debt Boom Reaches $220 Billion as Bond Investors Start Demanding More Yield
- Apollo Global Confirms Data Breach After Hackers Access Personal Information
- Wall Street Rebounds as Banks Rise, but Treasury Yield Surge Threatens Weekly Losses
- German Manufacturing PMI Hits 51-Month High as Services Remain in Contraction