FinCEN’s Stablecoin CIP Boundary Leaves a Critical Role for Forensic and Blockchain Analytics

August 27, 2026
Maggie Holder

By Jason Vigeant

In stablecoin compliance, the key architectural question is where a permitted payment stablecoin issuer’s direct customer relationship ends and where other controls must provide visibility into downstream activity. On June 18, 2026, FinCEN, Office of the Comptroller of the Currency (OCC), Federal Reserve, Federal Deposit Insurance Corporation (FDIC), and National Credit Union Administration (NCUA) jointly proposed a rule implementing the GENIUS Act’s customer identification program (CIP) requirements for permitted payment stablecoin issuers (PPSIs).[i] The proposal draws a narrow boundary, providing a critical role for forensic data analytics and blockchain analytics within the broader AML/CFT and sanctions framework.


A Rule Built Around the Primary Market

The GENIUS Act requires PPSIs to be treated as financial institutions under the Bank Secrecy Act and to maintain an effective customer identification program, including identification and verification of account holders.[ii] The proposed rule implements that mandate through new definitions of “account,” “customer,” and “digital asset service provider” that are “designed to clarify that a PPSI’s CIP obligation extends to direct relationships, i.e., primary market activity, and does not extend to activity where the only interaction is with a PPSI’s smart contract.”[iii] Before opening an account, a PPSI would need to collect a customer’s name, date of birth (or date of formation for an entity), physical address, and identification number. The PPSI would then need to verify the customer’s identity within a reasonable period after account opening using risk-based procedures sufficient to form a belief that it knows the customer’s identity.[iv]

The agencies treating every stablecoin transfer as creating a CIP relationship would impose on issuers a “global obligation to collect and verify identifying information of individual users” that would be “nearly impossible for PPSIs to implement and could potentially cripple the industry.”[v] However, their regulatory impact analysis demonstrates how narrow the primary market is. FinCEN estimates that stablecoin users number in the hundreds of millions, but an average issuer may have roughly 1,000 direct primary market customers, with no more than 300,000 unique primary market customers across the industry.[vi] The proposed CIP would therefore reach a relatively small, mostly institutional segment of the ecosystem. Secondary market transfers sit outside its customer identification requirements, even though separate AML/CFT, sanctions, and lawful order obligations may still require issuers to understand or act on certain secondary market risks.

The Secondary Market Is Where the Risk Lives

Federal Reserve Governor Michael Barr voted for the proposal but paired that vote with a public statement flagging exactly the aforementioned gap. Barr wrote that he remains concerned “that the GENIUS Act regulatory framework does not do enough so far to address the risks of illicit finance conducted through secondary market transactions in payment stablecoins,” and that “it is far too easy for bad actors to evade these restrictions and operate without detection when transacting in digital assets.”[vii] He committed to reviewing comments on whether any part of the CIP rule should extend to secondary market activity, and to separately assessing whether the broader GENIUS Act framework provides adequate protection against stablecoin-related illicit finance.[viii]

The data behind this concern is significant. According to Chainalysis’s 2026 Crypto Crime Report, illicit cryptocurrency addresses received at least $154 billion in 2025, and stablecoins accounted for 84% of illicit cryptocurrency transaction volume.[ix] The illicit activity is concentrated well outside the primary market relationships this rule reaches: FinCEN’s own estimate of no more than 300,000 unique primary market customers, against a stablecoin user base numbering in the hundreds of millions, means the overwhelming majority of stablecoin transaction activity occurs in the secondary market.[x] Those transfers may occur on-chain between exchanges, self-hosted wallets, and peer-to-peer counterparties, or off-chain on an intermediary’s internal ledger. The proposed CIP was not designed to identify every holder or counterparty participating in those channels.

That distinction is important for analytics design. Blockchain analytics can provide visibility into on-chain secondary-market movement, but it cannot independently reconstruct activity occurring on an exchange’s internal ledger. A defensible control environment therefore requires integration of blockchain data with customer, wallet, exchange counterparty, sanctions, and off-chain transactional records.

Where the Rule Creates Operational Friction

The primary market boundary creates compliance problems for issuers, which is separate from the secondary market coverage gap:

  • Redemption from unknown holders: the proposed rule acknowledges that a person with no established relationship to a PPSI can acquire a stablecoin from an exchange and later seek to redeem it directly with the issuer. That redemption could establish an account relationship and make the holder a customer, although the agencies have requested comment on whether that treatment should be refined or clarified.[xi]
  • A reliance framework with built-in asymmetry: a PPSI may rely on another federally regulated financial institution to perform CIP procedures, but that reliance is limited to institutions overseen by a federal regulator. A state qualified PPSI can rely on a federally supervised PPSI’s CIP work, but a PPSI that is a subsidiary of a federally regulated depository institution cannot rely on a state qualified PPSI’s CIP work, since state-qualified issuers are not overseen by a federal regulator.[xii] That asymmetry can force redundant screening between institutions that are doing the same compliance work.
  • Digital identity tools with no settled standard: the agencies acknowledge that digital identity tools and verifiable credentials could satisfy verification requirements but decline to propose specific regulatory text governing their use, leaving the standard to each issuer’s own risk-based judgment.[xiii]

Where Forensic and Blockchain Analytics Close the Gap

Comments on the proposed rule closed August 21, 2026, and the agencies have proposed a 12-month implementation runway once a final rule issues.[xiv] Issuers, banks entering the stablecoin space, and the exchanges and wallet providers that sit downstream of them need capabilities that go beyond the account-opening paperwork the rule describes:

  • Primary-market CIP program design and testing: this includes risk-based verification procedures calibrated to account type, onboarding method, and customer base, built to withstand examiner and auditor scrutiny under the reasonable belief standard.
  • Redemption-workflow analytics: this reconciles CIP completion against the rule’s redemption obligations, identifying where an issuer’s direct-redemption policy creates CIP exposure to previously unknown holders and modeling an alternative.
  • Customer-to-wallet attribution and exposure analytics: linking verified primary-market customers, authorized wallets, mint and redemption activity, exchange counterparties, and downstream on-chain exposure to identify concentration, sanctions, and counterparty risks that are not visible from CIP records.
  • Blockchain forensic tracing: across both primary and secondary market activity, applying clustering and attribution methods to connect known customers to downstream wallets, assessing mixer and other obfuscation service exposure, and trace cross-chain movement where technically supportable.
  • Government list and sanctions screening validation: distinguishing CIP’s customer list comparison requirement from the broader OFAC sanctions controls applicable to payment-stablecoin activity, and testing wallet screening, escalation, and reporting logic.
  • Transaction monitoring model validation: calibrated to primary market account activity but tuned using on-chain typologies from secondary market illicit flows, so that monitoring reflects how stablecoins move once they leave the issuer’s direct relationship.
  • Investigative and regulatory response support: for SAR decisioning, examiner inquiries, or enforcement actions once the rule takes effect, reconstructing account relationships and transaction history in a form that can withstand scrutiny.

Why This Matters

The proposed CIP establishes the identity verification floor for direct customer relationships.  It does not, by itself, address the full range of illicit finance, sanctions, and downstream transactional risks surrounding a payment stablecoin.[xv] That is the opportunity for forensic data analytics and blockchain analytics, which connects verified customers to wallets and transaction activity, integrating on-chain and off-chain information, validating sanctions and monitoring controls, and producing an evidentiary record that can withstand regulatory scrutiny.

  1. [i] https://www.federalregister.gov/documents/2026/06/22/2026-12460/permitted-payment-stablecoin-issuer-customer-identification-program: Permitted Payment Stablecoin Issuer Customer Identification Program, 91 Fed. Reg. 37234 (June 22, 2026).
  2. https://www.fincen.gov/system/files/2026-06/GENIUS-CIP-NPRM-FactSheet.pdf: FinCEN, Fact Sheet: Proposed Rule to Implement GENIUS Act Customer Identification Program Requirements (June 2026).
  3. [ii] https://www.law.cornell.edu/uscode/text/12/5903.
  4. [iii] https://www.federalregister.gov/documents/2026/06/22/2026-12460/permitted-payment-stablecoin-issuer-customer-identification-program — 91 Fed. Reg. at 37239.
  5. [iv] https://www.fincen.gov/system/files/2026-06/GENIUS-CIP-NPRM-FactSheet.pdf.
  6. [v] https://www.federalregister.gov/documents/2026/06/22/2026-12460/permitted-payment-stablecoin-issuer-customer-identification-program — 91 Fed. Reg. at 37239.
  7. [vi] https://www.federalregister.gov/documents/2026/06/22/2026-12460/permitted-payment-stablecoin-issuer-customer-identification-program — 91 Fed. Reg. at 37247–48.
  8. [vii] https://www.federalreserve.gov/newsevents/pressreleases/barr-statement-20260618.htm.
  9. [viii] https://www.federalreserve.gov/newsevents/pressreleases/barr-statement-20260618.htm.
  10. [ix] https://www.chainalysis.com/blog/2026-crypto-crime-report-introduction/.
  11. [x] https://www.federalregister.gov/documents/2026/06/22/2026-12460/permitted-payment-stablecoin-issuer-customer-identification-program — 91 Fed. Reg. at 37247–48.
  12. [xi] https://www.federalregister.gov/documents/2026/06/22/2026-12460/permitted-payment-stablecoin-issuer-customer-identification-program — 91 Fed. Reg. at 37239–40, 37244.
  13. [xii] https://www.federalregister.gov/documents/2026/06/22/2026-12460/permitted-payment-stablecoin-issuer-customer-identification-program — 91 Fed. Reg. at 37239–40, 37244.
  14. [xiii] https://www.federalregister.gov/documents/2026/06/22/2026-12460/permitted-payment-stablecoin-issuer-customer-identification-program — 91 Fed. Reg. at 37242.
  15. [xiv] https://www.federalregister.gov/documents/2026/06/22/2026-12460/permitted-payment-stablecoin-issuer-customer-identification-program — 91 Fed. Reg. at 37234, 37243.
  16. [xv] https://www.federalregister.gov/documents/2026/06/22/2026-12460/permitted-payment-stablecoin-issuer-customer-identification-program — 91 Fed. Reg. at 37247–48.
  17. https://www.chainalysis.com/blog/2026-crypto-crime-report-introduction/.