Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Back to blog
Blog · August 18, 2026

The stablecoin identity rule covers issuance and redemption, not what happens next

Five US agencies proposed a customer identification program for stablecoin issuers on 22 June 2026. Comments close 21 August. Four fields, five-year retention, and a duty that stops at the primary market.

By DiditUpdated
Didit Blog card on a lavender-blue gradient: 'The stablecoin identity rule covers issuance and redemption, not what happens next', with a large banknote line icon.

Five United States agencies proposed a customer identification program for stablecoin issuers on 22 June 2026. Comments close on 21 August. A Federal Reserve Governor has said on the record that the framework does not yet reach the secondary market, and that gap is the story.

The short version

  • The proposal. On 22 June 2026 the Financial Crimes Enforcement Network (FinCEN), the Office of the Comptroller of the Currency (OCC), the Federal Reserve Board, the Federal Deposit Insurance Corporation (FDIC) and the National Credit Union Administration (NCUA) jointly proposed a customer identification program for permitted payment stablecoin issuers.
  • The deadline. Comments must be received by 21 August 2026, under docket FINCEN-2026-0101 and RIN 1506-AB74. The rule would create a new 31 CFR Part 1033.
  • The duty. An issuer would collect four items before opening an account: name, date of birth or formation, address, and an identification number. Records are kept for five years after the account closes.
  • The boundary. The duty attaches to what the rule calls the primary market: the issuer dealing directly with a customer. Transfers between other holders sit outside it, and the agencies ask whether they should.
  • The scale. FinCEN estimates the rule would reach about 50 issuers in its first three years, each with an average of 1,000 customers.

A stablecoin can change hands without anyone checking who holds it

Governor Michael S. Barr of the Federal Reserve said on 18 June 2026 that it is "far too easy for bad actors to evade these restrictions and operate without detection when transacting in digital assets". A payment stablecoin is a token designed to hold a fixed value. Once issued, it moves between wallets without the issuer being party to the transfer.

That is the problem this rule is aimed at. A bank knows who holds a deposit because the deposit exists only on the bank's own ledger. A stablecoin works differently: the issuer creates the token and redeems it, but in between it circulates on a public network where the issuer is not a counterparty to any of the movements.

Congress addressed part of this in the Guiding and Establishing National Innovation for U.S. Stablecoins Act, known as the GENIUS Act. The statute directs that permitted payment stablecoin issuers be treated as financial institutions under the Bank Secrecy Act, the 1970 law that requires banks to identify their customers and report suspicious activity. Treating an issuer as a financial institution is what makes an identity duty possible at all.

Barr supported the proposal and set out a reservation in the same statement. It deserves quoting in full: it is the clearest description of the boundary this post is about, and it comes from one of the regulators issuing the rule.

I remain concerned, however, that the GENIUS Act regulatory framework does not do enough so far to address the risks of illicit finance conducted through secondary market transactions in payment stablecoins.

Michael S. Barr, Governor, Board of Governors of the Federal Reserve System. Statement of 18 June 2026

Underneath sits a proportionality question the agencies leave open. Identity checks are being attached to a new instrument, and nobody has yet settled whether the point at which they attach is the point where the harm occurs.

One statute is being implemented through five separate rulemakings

The GENIUS Act is not being implemented by a single rule. Between 18 May and 9 July 2026 five agencies published five separate proposed rules covering stablecoin issuers, each with its own comment period. Two of those periods have already closed. The identity rule closes on 21 August 2026.

This matters for anyone planning to respond. A firm that read one announcement and diarised one date has probably missed at least one window already. The table below lists all five as published in the Federal Register, with closed periods marked.

The pattern will be familiar to anyone who has watched a regulator import bank rules into a newer sector. The Federal Communications Commission did the same for telecoms when it built a know-your-customer proposal directly on the Bank Secrecy Act's customer identification program, and Australia has been pulling entire sectors into an identity regime for the first time.

DateRuleStatus
18 May 2026NCUA, GENIUS Act stablecoin issuance. Implementing the GENIUS Act for entities subject to National Credit Union Administration jurisdiction. Federal Register 2026-09915.Closed 17 Jul
5 Jun 2026FDIC, Bank Secrecy Act and sanctions standards. Standards for FDIC-supervised permitted payment stablecoin issuers. Federal Register 2026-11342.Closes 4 Aug
22 Jun 2026Joint, Customer Identification Program. FinCEN with the OCC, the Federal Reserve Board, the FDIC and the NCUA. Proposed 31 CFR Part 1033. RIN 1506-AB74, docket FINCEN-2026-0101. This is the identity rule.Closes 21 Aug
24 Jun 2026OCC, AML/CFT and sanctions risk management. Programme, reporting and recordkeeping obligations for issuers. Federal Register 2026-12692.Closed 24 Jul
9 Jul 2026Federal Reserve Board, AML/CFT programs. Anti-money laundering and countering the financing of terrorism programmes. Federal Register 2026-13919.Closes 8 Sep

The rule asks stablecoin issuers for what banks already collect

Proposed section 1033.220 would require a permitted payment stablecoin issuer to obtain four items from each customer before opening an account: name; date of birth for an individual, or date of formation otherwise; address; and an identification number. The agencies modelled this directly on the customer identification program that has applied to banks since 2003 at 31 CFR 1020.220.

The address requirement is stricter than it first appears. For an individual the rule asks for a residential or business street address, along with a mailing address. For anything other than an individual it asks for a principal place of business, local office or other physical address, plus a mailing address. A post-office box alone would not satisfy it.

There is one carve-out. Someone who has applied for a taxpayer identification number but does not yet have one may open an account, provided the issuer's programme confirms the application was filed and obtains the number within a reasonable period afterwards.

Collecting is only half of it. The programme must also contain procedures for verifying each new customer's identity within a reasonable time before or after the account is opened, using documents, non-documentary methods, or both. The non-documentary methods the rule names are contacting the customer, comparing what the customer supplied against a consumer reporting agency, public database or other source, checking references with another financial institution, and obtaining a financial statement.

Two further duties sit alongside. The issuer must check each customer against any list of known or suspected terrorists issued by a Federal agency and designated by Treasury, which implements section 5318(l)(2)(C) of title 31 of the United States Code. And it must keep records: the identifying information for five years after the account closes, and the record of how identity was verified for five years after that record is made.

Any final rule would take effect 12 months after issuance, which the agencies say is to give issuers time to build. Nothing here is in force today.

The duty attaches where the issuer is a counterparty, and stops there

The joint proposed rule of 22 June 2026 defines two zones. The primary market is the issuer dealing directly with a holder: issuing, converting, redeeming, repurchasing, burning and reissuing stablecoins, plus associated services such as custody. The secondary market is payment stablecoin activity between other parties. The identity duty attaches to the first and stops there.

That describes the rule as drafted; it is not a criticism of it. The logic is conventional. A customer identification programme is built around the moment an account is opened, and an issuer only has an account relationship with the people it deals with directly.

What makes the boundary worth stating plainly is that the agencies themselves treat it as unsettled. The proposal asks for comment on whether any portion of the identity requirements should extend to secondary market activity, and Barr said he would review those comments and assess whether the framework as a whole gives adequate protection.

So the open question is not buried in the drafting. It is question one on the agencies' own list, and it is why the 21 August date matters to anyone with a view.

The agencies expect the rule to reach about fifty issuers

FinCEN's own estimate in the 22 June 2026 proposal is that roughly 50 permitted payment stablecoin issuers would be covered in the first three years: about 20 that are not subsidiaries of insured depository institutions and 30 that are. It expects each to hold an average of 1,000 customers and to take on about 650 new ones a year.

Hold those figures next to the obligation. The regime proposed is the one that applies to banks, and the population it would initially reach is roughly fifty firms with a customer base measured in tens of thousands.

Two readings are available and the rule does not choose between them. One is that a small, well-defined population is exactly where a demanding standard is cheapest to apply, and setting it now avoids retrofitting later. The other is that the volume of stablecoin activity is not concentrated in the issuance moment the rule governs, so the reach of the identity duty and the location of the risk are two different things. Barr's statement is closer to the second.

Anyone forming a view has until 21 August. After that the record closes and the agencies decide.

Key takeaways

It is five rules, not one.

Five agencies published five proposed rules between 18 May and 9 July 2026. Two comment periods have closed, one closes today, and the identity rule closes on 21 August.

Nothing is in force.

These are proposals. A final rule would take effect 12 months after issuance, and no final rule has been made.

The duty is the bank customer identification program.

Four fields before account opening, documentary or non-documentary verification, a government-list check, and five-year retention, modelled on 31 CFR 1020.220.

It reaches issuance and redemption only.

The rule defines a primary and a secondary market and applies to the first. Whether it should reach the second is question one on the agencies' own comment list.

The initial population is small.

About 50 issuers with roughly 1,000 customers each, on FinCEN's own estimate.

Using Didit for a stablecoin customer identification program

The proposed programme is a list of checks, and checks are what a verification provider carries. Mapped to the modules an issuer would actually wire in: the four fields at proposed section 1033.220 plus documentary verification are what ID Verification at $0.15 per check covers. The rule's insistence on a residential or business street address rather than a post-office box is what Proof of Address at $0.20 per check tests. The government-list comparison at proposed section 1033.220(a)(4) is a screening step: AML Screening runs at $0.20 per check, and because a customer who was clear at onboarding can appear on a list later, Ongoing AML Monitoring runs at $0.07 per user per year. The companion AML proposal from the OCC also carries transfer-level duties, which is what Travel Rule at $0.02 per transaction addresses. Current module prices are listed on the pricing page.

What stays with the issuer is most of it. Didit does not determine whether an entity is a permitted payment stablecoin issuer, does not decide what a reasonable period for verification means in your risk assessment, does not resolve a possible match against a terrorist list or make the judgement call that follows, and does not file your comment before 21 August. The five-year retention of identity and verification records after an account closes is the issuer's obligation, and so is the programme document itself, which the rule expects to be written, risk-based and approved. Verification helps you collect and check what the proposal asks for; nothing purchased makes an issuer compliant with a rule that has not yet been made final.

Frequently asked questions

When do comments close on the stablecoin customer identification rule?

21 August 2026. The joint proposed rule was published in the Federal Register on 22 June 2026 under RIN 1506-AB74, and the notice states that comments must be received by August 21, 2026. Comments go to docket FINCEN-2026-0101.

What information would a stablecoin issuer have to collect?

Four items before an account is opened: name; date of birth for an individual or date of formation for a non-individual; address, meaning a residential and mailing address for individuals or a physical and mailing address for entities; and an identification number. A residential or business street address is required for individuals.

Is this rule in force?

No. It is a joint proposed rule and no final rule has been issued. The agencies propose that a final rule would take effect 12 months after issuance, to give permitted payment stablecoin issuers time to implement it.

Does the rule apply to stablecoin transactions between users?

As proposed, no. The rule attaches to the issuer's own customer relationship, which it calls the primary market: issuing, converting, redeeming, repurchasing, burning and reissuing stablecoins, and associated services such as custody. Activity between other parties is what the rule calls the secondary market, and the agencies ask for comment on whether any part of the rule should extend to it.

How long must stablecoin issuers keep identity records?

Five years. Under the proposal, identifying information about a customer is kept for five years after the account is closed, and records of how the customer's identity was verified are kept for five years after the record is made.

Related reading

Sources

  1. Permitted Payment Stablecoin Issuer Customer Identification Program, joint proposed rule — FinCEN, OCC, Federal Reserve Board, FDIC and NCUA · Federal Register · 22 June 2026 · RIN 1506-AB74
  2. Statement on the proposal for customer identification program requirements for payment stablecoin issuers — Governor Michael S. Barr, Board of Governors of the Federal Reserve System · 18 June 2026
  3. Permitted Payment Stablecoin Issuer AML/CFT and Sanctions Compliance Risk Management — Office of the Comptroller of the Currency · Federal Register · 24 June 2026
  4. Bank Secrecy Act and Sanctions Compliance Standards for FDIC-Supervised Permitted Payment Stablecoin Issuers — Federal Deposit Insurance Corporation · Federal Register · 5 June 2026
  5. Anti-Money Laundering and Countering the Financing of Terrorism Programs — Board of Governors of the Federal Reserve System · Federal Register · 9 July 2026
  6. Implementing the GENIUS Act for the issuance of stablecoins by entities subject to NCUA jurisdiction — National Credit Union Administration · Federal Register · 18 May 2026
  7. 31 CFR 1020.220: Customer identification program requirements for banks — Electronic Code of Federal Regulations · the model the proposal is built on

Who wrote this

Tuan Nguyen — Growth · Didit

Writes about identity verification, fraud and compliance at Didit.

Last reviewed 4 Aug 2026 against the sources above

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page