- Published
- August 22, 2026
- Covers
- February to April 2026
- Reading time
- 6 minutes
- By
- Client Focus
Implementing rulemaking for the federal payment stablecoin regime advanced in 2026. The OCC issued its proposal in February and the FDIC followed in April, addressing capital, liquidity, reserve composition and risk management for permitted issuers. Treasury separately advanced anti-money-laundering rulemaking affecting the same firms. Read together, the proposals describe the control framework an examiner will work through.
A board-approved information security risk and control framework
The proposals place the framework at board level rather than at the level of a security team. That has consequences for how it is written. It must state the scope of systems covered, the risk assessment method, the control set applied, the metrics reported to the board and the frequency of review. It must be capable of being audited against, which means each control statement needs an owner, a test and an evidence source.
Third-party due diligence, contract terms and ongoing monitoring
Issuers depend on custodians, reserve administrators, chain infrastructure and monitoring providers. The expectation follows the interagency third-party guidance: risk-tiered due diligence before engagement, contract terms covering performance, security, incident notification, audit rights and termination, and monitoring that continues through the life of the relationship rather than at renewal. For providers on the critical path, the file should include service level performance, incident history and the results of the most recent assessment.
The operating-expense backstop
The proposals contemplate resources sufficient to cover operating expenses independent of reserve assets, so that an issuer under stress does not fund operations from the reserve backing outstanding tokens. Operationally this reinforces the separation between the reserve ledger and the operating business, and the reconciliation discipline that keeps them distinct.
What a monitoring and operations partner must produce
For the examination file: continuous monitoring coverage of issuance and redemption contracts with privileged-action alerting; documented notification clocks with hop-by-hop timestamps; reconciliation output between reserve records and observed on-chain supply, with breaks tracked to closure; third-party monitoring evidence for the infrastructure providers behind the service; and incident records that show classification, decision and named accountability.
A timeline for preparing
Proposals are not final rules, and comment periods change detail. They do not usually change direction. The work that survives revision is the work that produces records: instrument the privileged actions, establish the reconciliation, define the notification clock and start retaining the evidence. Firms that begin after final publication will spend the implementation period building systems rather than demonstrating a track record, and a track record is what the first examination looks for.