Secure
Continuous monitoring, analyst validation and a published notification clock, with incident records retained for reporting.
Federal stablecoin legislation created a licensing regime for payment stablecoin issuers, with reserve, redemption, control and third-party oversight requirements. Implementing rules proposed in 2026 set out the control framework supervisors will examine.
Overview
The GENIUS Act established permitted payment stablecoin issuers with federal and state pathways, reserve and redemption requirements and ongoing supervision. The OCC proposed implementing rules in February 2026 and the FDIC followed in April 2026, addressing capital, liquidity, reserve composition and risk management.
The operational consequence is a board-approved information security risk and control framework, third-party due diligence with ongoing monitoring, incident records, and reporting that reconciles reserve records with on-chain supply. Issuers that build mint and burn controls with policy hooks now will not be retrofitting them under examination.

Obligations
Each obligation is stated with the operating consequence and the evidence a supervisor or auditor asks to see.
| Obligation | What it means for a digital asset operation | Evidence to produce |
|---|---|---|
| Reserve composition and reporting | Continuous reconciliation between reserve records and circulating on-chain supply, with breaks investigated. | Reconciliation output, exception logs and periodic reserve reporting. |
| Redemption at par | Redemption availability treated as a monitored service with published targets and escalation. | Availability reporting, incident records and client notification history. |
| Information security risk and control framework | A board-approved framework covering keys, privileged roles, change control and monitoring of the issuing contracts. | Approved framework, control testing results and access and change records. |
| Third-party due diligence and monitoring | Assessment and ongoing oversight of chain infrastructure, monitoring and analytics providers. | Due diligence files, contract terms and oversight records. |
| Privileged action control | Mint, burn, freeze, pause and role changes gated by policy and monitored as critical events. | Privileged-action alerts mapped to approved instructions and change tickets. |
| Incident records | Detection to notification measured on a clock, with a named owner at each hop. | Incident timelines, notification acknowledgments and post-incident reviews. |
Timeline
The GENIUS Act is signed into law.
OCC proposes implementing rules (Bulletin 2026-3).
FDIC issues its notice of proposed rulemaking.
Comment periods and final rules; issuers prepare control evidence.
Support
Continuous monitoring, analyst validation and a published notification clock, with incident records retained for reporting.
ITIL-based incident, problem and change management with named service owners and hop-by-hop timestamps on every escalation.
Control frameworks, separation of duties and the due-diligence pack supervisors and procurement teams ask for.
Related
Terms used on this page are defined in the digital asset operations glossary.
Whether you are designing a new system, running one in production, or defending one, Client Focus brings engineering, network operations and security operations under one accountable model. Every request is reviewed by a principal of the firm.