Skip to content
Client Focus

Insights

The GENIUS Act implementing rules: the control framework supervisors will examine

The OCC proposed rules in February 2026 and the FDIC in April 2026 setting capital, liquidity, reserve and risk-management requirements for permitted issuers.

Regulatory briefings

Published
August 22, 2026
Covers
February to April 2026
Reading time
6 minutes
By
Client Focus

Implementing rulemaking for the federal payment stablecoin regime advanced in 2026. The OCC issued its proposal in February and the FDIC followed in April, addressing capital, liquidity, reserve composition and risk management for permitted issuers. Treasury separately advanced anti-money-laundering rulemaking affecting the same firms. Read together, the proposals describe the control framework an examiner will work through.

A board-approved information security risk and control framework

The proposals place the framework at board level rather than at the level of a security team. That has consequences for how it is written. It must state the scope of systems covered, the risk assessment method, the control set applied, the metrics reported to the board and the frequency of review. It must be capable of being audited against, which means each control statement needs an owner, a test and an evidence source.

Third-party due diligence, contract terms and ongoing monitoring

Issuers depend on custodians, reserve administrators, chain infrastructure and monitoring providers. The expectation follows the interagency third-party guidance: risk-tiered due diligence before engagement, contract terms covering performance, security, incident notification, audit rights and termination, and monitoring that continues through the life of the relationship rather than at renewal. For providers on the critical path, the file should include service level performance, incident history and the results of the most recent assessment.

The operating-expense backstop

The proposals contemplate resources sufficient to cover operating expenses independent of reserve assets, so that an issuer under stress does not fund operations from the reserve backing outstanding tokens. Operationally this reinforces the separation between the reserve ledger and the operating business, and the reconciliation discipline that keeps them distinct.

What a monitoring and operations partner must produce

For the examination file: continuous monitoring coverage of issuance and redemption contracts with privileged-action alerting; documented notification clocks with hop-by-hop timestamps; reconciliation output between reserve records and observed on-chain supply, with breaks tracked to closure; third-party monitoring evidence for the infrastructure providers behind the service; and incident records that show classification, decision and named accountability.

A timeline for preparing

Proposals are not final rules, and comment periods change detail. They do not usually change direction. The work that survives revision is the work that produces records: instrument the privileged actions, establish the reconciliation, define the notification clock and start retaining the evidence. Firms that begin after final publication will spend the implementation period building systems rather than demonstrating a track record, and a track record is what the first examination looks for.

Printed operational reports and a notebook on a desk in daylight

Continue reading

A printed policy binder open on a desk beside reading glasses

The GENIUS Act is law: what permitted stablecoin issuers should prepare for

Federal stablecoin legislation created a licensing regime for payment stablecoin issuers and set the stage for implementing rules on reserves, redemption, controls and third-party oversight.

A quiet office corridor with glass-walled meeting rooms in daylight

Privileged actions on-chain: the events a security operations center must treat as critical

Role grants, configuration-flag changes, proxy upgrades and pause-state changes are the highest-signal events in a contract's life.

Hands annotating a printed regulatory document with a pen on a desk

DORA is in force: what crypto-asset service providers must now evidence

From January 17, 2025 the Digital Operational Resilience Act applies to crypto-asset service providers as financial entities.

Apply this to your own operations.

Client Focus reviews the estate, the coverage required and the gaps, then sets out what changes.