From the journal

Stablecoin regulation in the US, Hong Kong and Singapore

Stablecoin and digital-token regulation now combines market-entry authorization with continuous financial-crime controls in daily operations. The question is whether the United States’ proposed payment-stablecoin customer identification program, Hong Kong’s narrow first licensing round, and Singapore’s digital payment token (DPT) directory support a bank-like compliance characterization. They do, with material limits. The more accurate proposition is that compliance is moving beyond approval into continuous financial-institution-grade operations.

Illia ProkopievCo-Founder and CEO9 min read

Summary

United States

The GENIUS Act treats a permitted payment stablecoin issuer as a Bank Secrecy Act financial institution. Its general effective date has not arrived. 12 U.S.C. § 5903(a)(5); 91 Fed. Reg. 37,234 (proposed June 22, 2026).

The proposed CIP covers direct, formal issuer relationships in the primary market. Token ownership, indirect acquisition, and smart-contract-only interaction would not alone create an account. 91 Fed. Reg. 37,234, 37,239–40, 37,270–72.

A separate proposal would require technical capacity to block, freeze, reject, seize, burn, or prevent the transfer of tokens under lawful authority. It would not impose blanket issuer monitoring or suspicious-activity reporting for every secondary-market transfer. 91 Fed. Reg. 18,582, 18,591–92, 18,604–06, 18,666–67 (proposed Apr. 10, 2026).

Hong Kong

The Monetary Authority’s plan to grant only a handful of initial licences was supervisory policy, not a statutory quota. The Stablecoins Ordinance instead gives the Monetary Authority discretion subject to minimum licensing criteria and continuing compliance. Stablecoins Ordinance (Cap. 656) ss. 15, 24, sch. 2 § 10.

Hong Kong

Licensed issuers must operate customer, wallet, transaction, sanctions, reporting, recordkeeping, and control processes. The duties extend past customer onboarding into stablecoin circulation and wallet-risk monitoring. Stablecoins Ordinance (Cap. 656) sch. 2 § 10; HKMA Guideline, paras. 5.9–5.12, 6.40–6.41.

Singapore

The MAS Financial Institutions Directory records licensed activities. Its DPT filter returned 38 Major Payment Institution results and no Standard Payment Institution results on 12 August 2026. It is neither a stablecoin-issuer register nor proof that any listed firm has effective AML controls. MAS, Financial Institutions Directory, Digital Payment Token Service filter (Aug. 12, 2026).

Classification

“Financial-institution-like” is more precise than “bank-like.” These duties resemble bank compliance functions, but they do not confer bank status, deposit-taking authority, or deposit-insurance protection.

Approval and AML operations are cumulative

Daily operations require customer identification, beneficial-owner checks, sanctions screening, transaction monitoring, suspicious-transaction escalation, record retention, independent testing, and regulatory reporting. Stablecoin systems may also require wallet attribution, blockchain analytics, Travel Rule messaging, address restrictions, and token-level intervention.

The United States provisions concern permitted payment stablecoin issuers. Hong Kong regulates issuers of specified stablecoins within the Ordinance’s territorial scope. Singapore’s cited directory concerns licensed DPT services, not stablecoin issuance as a single category. A valid comparison therefore concerns operating functions, not identical licence classes. 12 U.S.C. §§ 5901–5903; Stablecoins Ordinance (Cap. 656) ss. 5, 14–15; Payment Services Act 2019, s. 2 and First Schedule pt. 3.

United States

The GENIUS Act supplies the strongest statutory basis for the “financial-institution-like” description. Section 5903(a)(5) treats each permitted payment stablecoin issuer as a financial institution under the Bank Secrecy Act. It specifies an AML program, an appointed officer, record retention, suspicious-transaction monitoring and reporting, transaction-intervention capabilities, a customer identification program, enhanced due diligence, and sanctions compliance. 12 U.S.C. § 5903(a)(5).

Those provisions are enacted but not yet generally effective. The Act takes effect on the earlier of 18 months after 18 July 2025 or 120 days after primary federal payment stablecoin regulators issue final implementing regulations. GENIUS Act § 20, Pub. L. No. 119-27, 139 Stat. 419, 466 (2025). The reviewed federal rulemakings remained proposals on 12 August 2026. The fixed 18-month date is 18 January 2027 unless final regulations trigger an earlier date.

The June 2026 CIP document is a joint proposed rule. It would require a written, risk-based CIP. The issuer would collect identifying data, verify identity, retain records, check designated lists, give notice, and govern permitted reliance. Permitted Payment Stablecoin Issuer Customer Identification Program, 91 Fed. Reg. 37,234, 37,270–72 (proposed June 22, 2026).

Its scope is narrower than universal know-your-wallet coverage. An “account” would require a formal relationship through which the issuer provides stablecoin services. Mere token ownership or control would not suffice. Neither would indirect acquisition, indirect redemption, or interaction solely through a smart contract without a direct issuer relationship. Id. at 37,239–40, 37,270.

The April 2026 AML/CFT and sanctions proposal separates relationship-level AML duties from token-level control. It would require technical capabilities and procedures to block, freeze, or reject impermissible transactions. A lawful order could require seizure, freezing, burning, or prevention of transfer. Those capabilities may reach tokens moving in the secondary market. Permitted Payment Stablecoin Issuer AML/CFT Program and Sanctions Compliance Program Requirements, 91 Fed. Reg. 18,582, 18,604–06, 18,666–67 (proposed Apr. 10, 2026).

That proposal does not assign the issuer a general duty to monitor every secondary-market transfer or file a suspicious-activity report on every off-platform movement. The issuer’s duty would turn on its customer relationship, available information, legal obligations, and the transaction-control provisions. Id. at 18,591–92, 18,604–06. This boundary matters when designing blockchain surveillance and alert ownership.

The U.S. change is not a move from no AML duties to AML duties. Stablecoin issuers may already qualify as money transmitters and money services businesses under current FinCEN rules. Those classifications can carry AML-program, suspicious-activity-reporting, and recordkeeping duties. 31 C.F.R. §§ 1010.100(ff)(5), 1022.210, 1022.320, 1010.410(e)–(f); 91 Fed. Reg. 18,582, 18,590–92. The GENIUS Act would create a stablecoin-specific federal layer and a more explicit issuer operating model.

Hong Kong

Hong Kong’s initial licensing outcome supports a high-entry-threshold claim, but not a statutory licence cap. Before commencement, the Monetary Authority said it expected to grant only a handful of licences initially. HKMA, Robust and Sustainable Development of Stablecoins (June 23, 2025).

The Ordinance does not fix that number. Section 15 permits the Monetary Authority to grant a licence, but bars a grant unless the statutory conditions are met. Section 24 requires a licensee to keep satisfying the minimum criteria. Stablecoins Ordinance (Cap. 656) ss. 15, 24.

The Monetary Authority granted the first two licences on 10 April 2026 after receiving 36 applications. The official register listed Anchorpoint Financial Limited and The Hongkong and Shanghai Banking Corporation Limited on the as-of date. HKMA, Granting of Stablecoin Issuer Licences (Apr. 10, 2026); HKMA, Register of Licensees under the Stablecoins Ordinance (as of Aug. 12, 2026); HKMA statements on first-round licence applications (Oct. 1, 2025; Legislative Council, Feb. 2, 2026).

Schedule 2 requires adequate and appropriate systems of control to prevent and combat money laundering and terrorist financing. Stablecoins Ordinance (Cap. 656) sch. 2 § 10. The Anti-Money Laundering and Counter-Terrorist Financing Ordinance supplies related customer due-diligence and recordkeeping rules. Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) sch. 2.

The HKMA’s stablecoin-issuer AML/CFT Guideline turns that criterion into operating expectations. It addresses customer due diligence, beneficial ownership, ongoing monitoring, sanctions and proliferation-financing controls, suspicious-transaction reporting, recordkeeping, wallet controls, stablecoin circulation, and value-transfer information. HKMA, Guideline on Anti-Money Laundering and Counter-Financing of Terrorism (For Licensed Stablecoin Issuers), paras. 4.35–4.39, 5.9–5.12, 6.40–6.41 (effective Aug. 1, 2025).

The Guideline has a defined legal status. A guideline issued under the Stablecoins Ordinance is not subsidiary legislation. Its breach does not, by itself, create criminal liability. The guideline may be admitted in proceedings, and a court may consider compliance or noncompliance when the provision is relevant. Stablecoins Ordinance (Cap. 656) ss. 171, 174.

The HKMA expects an issuer to identify and assess wallet risks, monitor relevant stablecoin transactions and associated addresses, and monitor circulation after issuance. The final materials retain a targeted exception for certain peer-to-peer transfers between unhosted wallets held by non-customer holders. HKMA Guideline, paras. 5.9–5.12, 6.40–6.41

Singapore

Singapore’s “DPT register” is the MAS Financial Institutions Directory filtered by licence and activity. It listed 38 Major Payment Institution results for Digital Payment Token Service and no Standard Payment Institution results on 12 August 2026. MAS, Financial Institutions Directory, Digital Payment Token Service filter (Aug. 12, 2026).

The directory is a primary factual record of listed licence activity. It is not a separate statutory register of stablecoin issuers. Some entries also hold other licence types. It does not establish that every listed provider issues a stablecoin, or that any listed provider’s AML program performs effectively.

The Payment Services Act makes licensing activity-based. A person generally needs the applicable licence to provide a regulated payment service, subject to statutory exceptions. A licensed DPT service provider also faces added DPT-service requirements. Payment Services Act 2019, ss. 5–6, 21A, First Schedule pt. 3.

MAS Notice PSN02 supplies the core operating duties for covered DPT services. It addresses risk assessment, customer due diligence, beneficial ownership, ongoing monitoring, value-transfer information, record retention, suspicious-transaction reporting, internal policies, compliance management, audit, and training. MAS Notice PSN02, pts. 4, 6, 13–14 and provisions on value transfer, suspicious-transaction reporting, internal controls, audit, and training.

The current statutory definition of “digital payment token” excludes a token denominated in a currency or pegged by its issuer to a currency. Payment Services Act 2019, s. 2. A fiat-pegged stablecoin therefore cannot be placed in the DPT category solely because it uses distributed-ledger technology. The provider’s exact services, the token’s terms, and any other payment-service category must be assessed separately.

MAS’s July 2026 information paper on AML/CFT supervisory expectations for DPT service providers adds current supervisory detail. MAS, AML/CFT Supervisory Expectations for Digital Payment Token Service Providers (July 13, 2026). It is nonbinding guidance, not legislation or a notice. Its relevance lies in the evidence MAS expects during supervision, including risk assessment, customer-risk controls, transaction monitoring, sanctions screening, case management, testing, and management oversight.

Operational consequences for stablecoin and payment firms

The legal perimeter should drive the operating model. A firm needs a jurisdiction-by-jurisdiction map of entities, licences, products, customer relationships, wallets, transaction paths, outsourcing arrangements, and reporting duties. That map must distinguish issuance and redemption from exchange, custody, transfer, brokerage, and pure secondary-market activity.

The control stack should connect customer and beneficial-owner data with wallet ownership, blockchain analytics, fiat-ledger activity, sanctions screening, Travel Rule data, case management, and regulatory reporting. The firm should document which system owns each alert, which facts trigger escalation, and which entity files the report.

Secondary-market controls require exact scoping. The U.S. proposals distinguish direct customer relationships from technical intervention across circulating tokens. Hong Kong combines circulation and wallet monitoring with defined limits for non-customer unhosted-wallet transfers. Singapore ties PSN02 duties to the licensed DPT service and the provider’s customer and transaction activity.

Token-control procedures need legal and technical ownership. The issuer should identify who validates an order, who authorizes a freeze or burn, which contracts or keys execute it, how conflicting orders are handled, and how the action is recorded. A capability stated in policy but absent from production systems will not satisfy an operational requirement.

Outsourcing does not remove accountability. Contracts with KYC vendors, analytics firms, custodians, and Travel Rule providers should provide data access, testing rights, incident notice, retention, service continuity, and regulator access where required. Management should receive evidence on alert backlogs, sanctions hits, reporting timeliness, model changes, control failures, and remediation.

Illia Prokopiev

Written by

Illia Prokopiev

Co-Founder and CEO

Illia is the Managing Partner and founder of Licentium. With over 11 years of practice, he has guided innovators through cross-border M&A deals and the disputes that follow, combining transactional skill with courtroom resolve. Admitted to the bar in 2017, he pivoted early to Web3, serving as legal advisor to prominent crypto projects and carrying AML/MLRO duties that anchored complex token, DAO, and compliance questions on solid regulatory ground. Certified in money laundering prevention and an active crypto investor, Illia blends market intuition with a global network of specialists, enabling Licentium to untangle licensing knots for crypto and AI ventures anywhere in the world.

More from the journal

See all
Illia Prokopiev

MLR Registration and the FCA Cryptoasset Gateway to 25 October 2027

This matter concerns the transition of a United Kingdom cryptoasset business from FCA registration under the Money Laundering Regulations 2017 to Part 4A permission under the Financial Services and Markets Act 2000. The question is whether MLR registration gives conversion, grandfathering, priority, or a right to continue after 25 October 2027, and what an affected firm should do before the gateway closes. This analysis assumes an existing UK-facing cryptoasset business, no relevant Part 4A permission, and an intention to continue after commencement.

Illia Prokopiev

ESMA's 2026 Custody Resilience CSA and the Rules That Actually Bind

ESMA’s 2026 Common Supervisory Action is a coordinated national review of digital operational resilience in crypto-asset custody. It will test whether selected crypto-asset service providers can demonstrate effective controls across six announced workstreams. The legal questions are which requirements are binding, how national competent authorities may assess control effectiveness, and what consequences may follow from a deficiency. This analysis assumes that the firm is permitted under MiCA Article 59 to provide custody and administration within Article 3(1)(17).

Illia Prokopiev

The Legal Perimeter for DeFi Vault Curators: Panama, BVI, and Cayman Islands

Under the laws of Panama, the British Virgin Islands and the Cayman Islands: When can a tokenised DeFi vault constitute a regulated collective-investment vehicle? When can a compensated “curator” with authority over collateral, portfolio composition, rebalancing, valuation or oracle sources, emergency controls, execution, wallets or keys constitute a regulated investment manager, fund functionary, investment-business provider, mutual-fund administrator, custodian or virtual-asset service provider?