Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

GENIUS Act AML requirements — GENIUS Act AML Requirements: The 6 Essential BSA Elements

GENIUS Act AML Requirements: The 6 Essential BSA Elements

GENIUS Act AML requirements start with one reclassification. Section 4(a)(5)(A) of Public Law 119-27 provides that a permitted payment stablecoin issuer shall be treated as a financial institution for purposes of the Bank Secrecy Act, and is therefore subject to all Federal law applicable to a financial institution located in the United States on economic sanctions, prevention of money laundering, customer identification and due diligence. Everything else in the paragraph is a list of what that must include.

This guide works through the six enumerated elements, the lawful-order condition in section 4(a)(6) that sits beside them, the annual certification in section 5(i) that attests to them, and the rules FinCEN and OFAC had proposed but not finalised when this was written. It reads the enrolled text on govinfo; the GENIUS Act AML requirements apply from 18 January 2027 whether or not the rules are final by then.

What this guide covers

GENIUS Act AML requirements explained
The six GENIUS Act AML requirements in section 4(a)(5)(A)

The six GENIUS Act AML requirements in section 4(a)(5)(A)

The word that matters in the GENIUS Act AML requirements is “including”. Section 4(a)(5)(A) subjects the issuer to the whole body of BSA and sanctions law and then names six things that body includes. They are not the whole program; they are the parts Congress chose to make explicit, and an examiner will look for each by name.

Clause Element What it means for a stablecoin issuer
(i) Maintenance of an effective anti-money laundering program, which shall include appropriate risk assessments and designation of an officer to supervise the program A written program, a documented risk assessment built on the issuer’s own customers, chains and usage, and a named officer with authority and resources
(ii) Retention of appropriate records Customer identification, transactions, monitoring, reports and lawful orders kept for the BSA periods and producible on request
(iii) Monitoring and reporting of any suspicious transaction relevant to a possible violation of law or regulation Transaction monitoring on direct customers and on the stablecoin’s on-chain movement, with suspicious activity reports filed with FinCEN
(iv) Technical capabilities, policies and procedures to block, freeze and reject specific or impermissible transactions that violate Federal or State law Contract-level freeze and denylist functions plus the operational procedure to invoke them, not just a policy that says the issuer will
(v) Maintenance of an effective customer identification program, including identification and verification of account holders, high-value transactions, and appropriate enhanced due diligence CIP on every person who buys from or redeems with the issuer; a high-value threshold; EDD triggers
(vi) Maintenance of an effective economic sanctions compliance program, including verification of sanctions lists, consistent with Federal law A sanctions program in its own right, screening persons and blockchain addresses against OFAC lists on every update

Why the GENIUS Act AML requirements reach beyond the customer

A bank’s AML program monitors the bank’s own accounts, and a reader coming to the GENIUS Act AML requirements from banking will expect the same shape. A stablecoin issuer’s direct customers are the people who buy from it and redeem with it, but its stablecoin, once issued, moves between addresses the issuer never onboarded. Clause (iii) requires monitoring of “any suspicious transaction”, and clause (iv) requires the capability to block and freeze “specific or impermissible transactions”. Neither is limited to the issuer’s customers, and the technical capability in (iv) only makes sense at the level of the token contract.

So the GENIUS Act AML requirements have two layers. Conventional customer due diligence on direct customers, and on-chain monitoring of the stablecoin’s movement with the ability to act on what it finds. An issuer that runs the first layer only is monitoring the door and ignoring the room. Section 9(d)(3) confirms the direction of travel: FinCEN is to issue, within three years of enactment, standards for issuers’ systems and practices to monitor transactions on blockchains and through mixing services, tumblers and similar services.

Lawful orders: the GENIUS Act AML requirement that is a condition of issuing

Section 4(a)(6)(B) is not in the list of six, and it is stronger than any of them. A permitted issuer may issue payment stablecoins only if it has the technological capability to comply, and will comply, with the terms of any lawful order. Section 2(16) defines a lawful order as a final and valid order under Federal law, from a court or an authorised Federal agency, that requires the issuer to seize, freeze, burn, or prevent the transfer of payment stablecoins it issued, specifying them with reasonable particularity, and subject to review.

Four verbs, and the third is the one contracts miss. It is the point where the GENIUS Act AML requirements become an engineering specification. A token contract that can freeze a balance and block a transfer but cannot destroy a specified amount at a specified address without the holder’s signature does not have the capability the Act requires, and an issuer without it may not issue. The capability has to exist on every chain, has to survive every contract upgrade, and has to be tested rather than asserted. Section 4(a)(6)(A) adds that Treasury will coordinate with issuers before blocking a foreign person’s property “to the best of the Secretary’s ability” but is not required to give notice, so the issuer’s ability to act within hours of a designation is its own problem.

The section 5(i) certification of the GENIUS Act AML requirements

Within 180 days of approval and annually thereafter, section 5(i)(1) requires the issuer to submit to its regulator a certification that it has implemented anti-money laundering and economic sanctions compliance programs reasonably designed to prevent it from facilitating money laundering, in particular for cartels and organisations designated as foreign terrorist organisations under section 219 of the Immigration and Nationality Act, and the financing of terrorist activities.

The consequences of failing that certification of the GENIUS Act AML requirements are in section 5(i)(3). The regulator may revoke approval for failure to submit the certification. A person who knowingly submits a false one is subject to the criminal penalties in 18 U.S.C. 1001, and the regulator may refer the matter to the Attorney General or the host State’s attorney general. “Reasonably designed” is the standard, not “nothing bad ever happened”, but it has to be true of the program as operated for the period, and the evidence is the operating records, the independent testing and the training log, not the policy binder.

What the FinCEN and OFAC proposals would add to the GENIUS Act AML requirements

Section 4(a)(5)(B) requires Treasury to adopt rules implementing the six elements, tailored to the size and complexity of permitted issuers. FinCEN and OFAC jointly proposed that rule on 8 April 2026, published in the Federal Register two days later. It would add permitted issuers to FinCEN’s regulations as financial institutions, require an AML/CFT program with the familiar pillars, and, for the first time, expressly require a category of United States persons to maintain a sanctions compliance program. FinCEN and the banking agencies followed in June with a proposed customer identification program rule for permitted issuers.

Both were proposals when this was written. Their content will shape the program’s detail, and an issuer should read them; but the GENIUS Act AML requirements bind from the statute, and a program built on section 4(a)(5)(A) now adopts the final rules when they land rather than waiting for them.

Building a program to the GENIUS Act AML requirements

The documents that answer the GENIUS Act AML requirements map to the six clauses and the condition beside them. A program with a risk assessment methodology and a designated officer’s terms of reference for clause (i). A retention schedule for (ii). Monitoring and reporting procedures, plus an on-chain monitoring standard, for (iii). A blocking, freezing and rejection procedure that names the contract functions and the grounds for (iv). A customer identification program with EDD and a high-value threshold for (v). A sanctions program and a screening procedure for (vi). And a lawful-order procedure that applies the three-part section 2(16) test before anything is executed, with a technical capability standard and a test record behind it.

The type of issuer does not change any of this. A State qualified issuer certifies to its State regulator instead of a Federal one; the six elements and the lawful-order condition are the same.

Frequently asked questions

Do the GENIUS Act AML requirements apply to a State qualified issuer?

Yes. Section 4(a)(5)(A) applies to every permitted payment stablecoin issuer, and section 5(i) requires the certification to the State regulator “as applicable”. The regulator changes; the requirements do not.

Is the designated officer in the GENIUS Act AML requirements the same as a bank’s BSA officer?

Functionally, yes. Section 4(a)(5)(A)(i) requires “designation of an officer to supervise the program” and gives no title. The role needs authority to stop transactions, freeze addresses and file reports without executive approval, and direct access to the board; a title without that authority does not meet the clause.

Does “burn” really mean destroying a holder’s tokens?

Yes. Section 2(16)(A) lists seize, freeze, burn and prevent transfer as the things a lawful order may require, and section 4(a)(6)(B) makes the capability to comply with any of them a condition of issuing. An issuer that cannot burn on order cannot lawfully issue.

When is the first certification due?

Not later than 180 days after approval under section 5, and annually thereafter. The clock runs from the approval date, not from the effective date of the Act.

Seventeen documents in our GENIUS Act Toolkit carry the GENIUS Act AML requirements: the program, the risk assessment methodology and workbook, the officer’s appointment, CIP and EDD, monitoring, blocking and freezing, records, the sanctions program and screening, the lawful-order procedure and register, the section 5(i) certification template, training, independent testing and on-chain monitoring. The rest of section 4 sits around them.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.