Summary
United States
The GENIUS Act treats a permitted payment stablecoin issuer as a Bank Secrecy Act financial institution. Its general effective date has not arrived. 12 U.S.C. § 5903(a)(5); 91 Fed. Reg. 37,234 (proposed June 22, 2026).
The proposed CIP covers direct, formal issuer relationships in the primary market. Token ownership, indirect acquisition, and smart-contract-only interaction would not alone create an account. 91 Fed. Reg. 37,234, 37,239–40, 37,270–72.
A separate proposal would require technical capacity to block, freeze, reject, seize, burn, or prevent the transfer of tokens under lawful authority. It would not impose blanket issuer monitoring or suspicious-activity reporting for every secondary-market transfer. 91 Fed. Reg. 18,582, 18,591–92, 18,604–06, 18,666–67 (proposed Apr. 10, 2026).
Hong Kong
The Monetary Authority’s plan to grant only a handful of initial licences was supervisory policy, not a statutory quota. The Stablecoins Ordinance instead gives the Monetary Authority discretion subject to minimum licensing criteria and continuing compliance. Stablecoins Ordinance (Cap. 656) ss. 15, 24, sch. 2 § 10.
Hong Kong
Licensed issuers must operate customer, wallet, transaction, sanctions, reporting, recordkeeping, and control processes. The duties extend past customer onboarding into stablecoin circulation and wallet-risk monitoring. Stablecoins Ordinance (Cap. 656) sch. 2 § 10; HKMA Guideline, paras. 5.9–5.12, 6.40–6.41.
Singapore
The MAS Financial Institutions Directory records licensed activities. Its DPT filter returned 38 Major Payment Institution results and no Standard Payment Institution results on 12 August 2026. It is neither a stablecoin-issuer register nor proof that any listed firm has effective AML controls. MAS, Financial Institutions Directory, Digital Payment Token Service filter (Aug. 12, 2026).
Classification
“Financial-institution-like” is more precise than “bank-like.” These duties resemble bank compliance functions, but they do not confer bank status, deposit-taking authority, or deposit-insurance protection.
Approval and AML operations are cumulative
Daily operations require customer identification, beneficial-owner checks, sanctions screening, transaction monitoring, suspicious-transaction escalation, record retention, independent testing, and regulatory reporting. Stablecoin systems may also require wallet attribution, blockchain analytics, Travel Rule messaging, address restrictions, and token-level intervention.
The United States provisions concern permitted payment stablecoin issuers. Hong Kong regulates issuers of specified stablecoins within the Ordinance’s territorial scope. Singapore’s cited directory concerns licensed DPT services, not stablecoin issuance as a single category. A valid comparison therefore concerns operating functions, not identical licence classes. 12 U.S.C. §§ 5901–5903; Stablecoins Ordinance (Cap. 656) ss. 5, 14–15; Payment Services Act 2019, s. 2 and First Schedule pt. 3.
United States
The GENIUS Act supplies the strongest statutory basis for the “financial-institution-like” description. Section 5903(a)(5) treats each permitted payment stablecoin issuer as a financial institution under the Bank Secrecy Act. It specifies an AML program, an appointed officer, record retention, suspicious-transaction monitoring and reporting, transaction-intervention capabilities, a customer identification program, enhanced due diligence, and sanctions compliance. 12 U.S.C. § 5903(a)(5).
Those provisions are enacted but not yet generally effective. The Act takes effect on the earlier of 18 months after 18 July 2025 or 120 days after primary federal payment stablecoin regulators issue final implementing regulations. GENIUS Act § 20, Pub. L. No. 119-27, 139 Stat. 419, 466 (2025). The reviewed federal rulemakings remained proposals on 12 August 2026. The fixed 18-month date is 18 January 2027 unless final regulations trigger an earlier date.
The June 2026 CIP document is a joint proposed rule. It would require a written, risk-based CIP. The issuer would collect identifying data, verify identity, retain records, check designated lists, give notice, and govern permitted reliance. Permitted Payment Stablecoin Issuer Customer Identification Program, 91 Fed. Reg. 37,234, 37,270–72 (proposed June 22, 2026).
Its scope is narrower than universal know-your-wallet coverage. An “account” would require a formal relationship through which the issuer provides stablecoin services. Mere token ownership or control would not suffice. Neither would indirect acquisition, indirect redemption, or interaction solely through a smart contract without a direct issuer relationship. Id. at 37,239–40, 37,270.
The April 2026 AML/CFT and sanctions proposal separates relationship-level AML duties from token-level control. It would require technical capabilities and procedures to block, freeze, or reject impermissible transactions. A lawful order could require seizure, freezing, burning, or prevention of transfer. Those capabilities may reach tokens moving in the secondary market. Permitted Payment Stablecoin Issuer AML/CFT Program and Sanctions Compliance Program Requirements, 91 Fed. Reg. 18,582, 18,604–06, 18,666–67 (proposed Apr. 10, 2026).
That proposal does not assign the issuer a general duty to monitor every secondary-market transfer or file a suspicious-activity report on every off-platform movement. The issuer’s duty would turn on its customer relationship, available information, legal obligations, and the transaction-control provisions. Id. at 18,591–92, 18,604–06. This boundary matters when designing blockchain surveillance and alert ownership.
The U.S. change is not a move from no AML duties to AML duties. Stablecoin issuers may already qualify as money transmitters and money services businesses under current FinCEN rules. Those classifications can carry AML-program, suspicious-activity-reporting, and recordkeeping duties. 31 C.F.R. §§ 1010.100(ff)(5), 1022.210, 1022.320, 1010.410(e)–(f); 91 Fed. Reg. 18,582, 18,590–92. The GENIUS Act would create a stablecoin-specific federal layer and a more explicit issuer operating model.
Hong Kong
Hong Kong’s initial licensing outcome supports a high-entry-threshold claim, but not a statutory licence cap. Before commencement, the Monetary Authority said it expected to grant only a handful of licences initially. HKMA, Robust and Sustainable Development of Stablecoins (June 23, 2025).
The Ordinance does not fix that number. Section 15 permits the Monetary Authority to grant a licence, but bars a grant unless the statutory conditions are met. Section 24 requires a licensee to keep satisfying the minimum criteria. Stablecoins Ordinance (Cap. 656) ss. 15, 24.
The Monetary Authority granted the first two licences on 10 April 2026 after receiving 36 applications. The official register listed Anchorpoint Financial Limited and The Hongkong and Shanghai Banking Corporation Limited on the as-of date. HKMA, Granting of Stablecoin Issuer Licences (Apr. 10, 2026); HKMA, Register of Licensees under the Stablecoins Ordinance (as of Aug. 12, 2026); HKMA statements on first-round licence applications (Oct. 1, 2025; Legislative Council, Feb. 2, 2026).
Schedule 2 requires adequate and appropriate systems of control to prevent and combat money laundering and terrorist financing. Stablecoins Ordinance (Cap. 656) sch. 2 § 10. The Anti-Money Laundering and Counter-Terrorist Financing Ordinance supplies related customer due-diligence and recordkeeping rules. Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) sch. 2.
The HKMA’s stablecoin-issuer AML/CFT Guideline turns that criterion into operating expectations. It addresses customer due diligence, beneficial ownership, ongoing monitoring, sanctions and proliferation-financing controls, suspicious-transaction reporting, recordkeeping, wallet controls, stablecoin circulation, and value-transfer information. HKMA, Guideline on Anti-Money Laundering and Counter-Financing of Terrorism (For Licensed Stablecoin Issuers), paras. 4.35–4.39, 5.9–5.12, 6.40–6.41 (effective Aug. 1, 2025).
The Guideline has a defined legal status. A guideline issued under the Stablecoins Ordinance is not subsidiary legislation. Its breach does not, by itself, create criminal liability. The guideline may be admitted in proceedings, and a court may consider compliance or noncompliance when the provision is relevant. Stablecoins Ordinance (Cap. 656) ss. 171, 174.
The HKMA expects an issuer to identify and assess wallet risks, monitor relevant stablecoin transactions and associated addresses, and monitor circulation after issuance. The final materials retain a targeted exception for certain peer-to-peer transfers between unhosted wallets held by non-customer holders. HKMA Guideline, paras. 5.9–5.12, 6.40–6.41
Singapore
Singapore’s “DPT register” is the MAS Financial Institutions Directory filtered by licence and activity. It listed 38 Major Payment Institution results for Digital Payment Token Service and no Standard Payment Institution results on 12 August 2026. MAS, Financial Institutions Directory, Digital Payment Token Service filter (Aug. 12, 2026).
The directory is a primary factual record of listed licence activity. It is not a separate statutory register of stablecoin issuers. Some entries also hold other licence types. It does not establish that every listed provider issues a stablecoin, or that any listed provider’s AML program performs effectively.
The Payment Services Act makes licensing activity-based. A person generally needs the applicable licence to provide a regulated payment service, subject to statutory exceptions. A licensed DPT service provider also faces added DPT-service requirements. Payment Services Act 2019, ss. 5–6, 21A, First Schedule pt. 3.
MAS Notice PSN02 supplies the core operating duties for covered DPT services. It addresses risk assessment, customer due diligence, beneficial ownership, ongoing monitoring, value-transfer information, record retention, suspicious-transaction reporting, internal policies, compliance management, audit, and training. MAS Notice PSN02, pts. 4, 6, 13–14 and provisions on value transfer, suspicious-transaction reporting, internal controls, audit, and training.
The current statutory definition of “digital payment token” excludes a token denominated in a currency or pegged by its issuer to a currency. Payment Services Act 2019, s. 2. A fiat-pegged stablecoin therefore cannot be placed in the DPT category solely because it uses distributed-ledger technology. The provider’s exact services, the token’s terms, and any other payment-service category must be assessed separately.
MAS’s July 2026 information paper on AML/CFT supervisory expectations for DPT service providers adds current supervisory detail. MAS, AML/CFT Supervisory Expectations for Digital Payment Token Service Providers (July 13, 2026). It is nonbinding guidance, not legislation or a notice. Its relevance lies in the evidence MAS expects during supervision, including risk assessment, customer-risk controls, transaction monitoring, sanctions screening, case management, testing, and management oversight.
Operational consequences for stablecoin and payment firms
The legal perimeter should drive the operating model. A firm needs a jurisdiction-by-jurisdiction map of entities, licences, products, customer relationships, wallets, transaction paths, outsourcing arrangements, and reporting duties. That map must distinguish issuance and redemption from exchange, custody, transfer, brokerage, and pure secondary-market activity.
The control stack should connect customer and beneficial-owner data with wallet ownership, blockchain analytics, fiat-ledger activity, sanctions screening, Travel Rule data, case management, and regulatory reporting. The firm should document which system owns each alert, which facts trigger escalation, and which entity files the report.
Secondary-market controls require exact scoping. The U.S. proposals distinguish direct customer relationships from technical intervention across circulating tokens. Hong Kong combines circulation and wallet monitoring with defined limits for non-customer unhosted-wallet transfers. Singapore ties PSN02 duties to the licensed DPT service and the provider’s customer and transaction activity.
Token-control procedures need legal and technical ownership. The issuer should identify who validates an order, who authorizes a freeze or burn, which contracts or keys execute it, how conflicting orders are handled, and how the action is recorded. A capability stated in policy but absent from production systems will not satisfy an operational requirement.
Outsourcing does not remove accountability. Contracts with KYC vendors, analytics firms, custodians, and Travel Rule providers should provide data access, testing rights, incident notice, retention, service continuity, and regulator access where required. Management should receive evidence on alert backlogs, sanctions hits, reporting timeliness, model changes, control failures, and remediation.
