Skip to content
Client Focus

Regulatory readiness

The GENIUS Act: the control framework permitted stablecoin issuers must operate

Federal stablecoin legislation created a licensing regime for payment stablecoin issuers, with reserve, redemption, control and third-party oversight requirements. Implementing rules proposed in 2026 set out the control framework supervisors will examine.

What the regime is

The GENIUS Act established permitted payment stablecoin issuers with federal and state pathways, reserve and redemption requirements and ongoing supervision. The OCC proposed implementing rules in February 2026 and the FDIC followed in April 2026, addressing capital, liquidity, reserve composition and risk management.

The operational consequence is a board-approved information security risk and control framework, third-party due diligence with ongoing monitoring, incident records, and reporting that reconciles reserve records with on-chain supply. Issuers that build mint and burn controls with policy hooks now will not be retrofitting them under examination.

Who it applies to

  • Permitted payment stablecoin issuers under the federal or a qualifying state pathway.
  • Banks and bank subsidiaries issuing or supporting payment stablecoins.
  • Service providers operating issuance, redemption, monitoring or reserve reporting for an issuer.
  • Payment companies distributing a permitted payment stablecoin.

Last reviewed: August 22, 2026

A payments operations team at workstations in daylight

What the rules require in operation

Each obligation is stated with the operating consequence and the evidence a supervisor or auditor asks to see.

Obligations, operational meaning and evidence for GENIUS Act
ObligationWhat it means for a digital asset operationEvidence to produce
Reserve composition and reportingContinuous reconciliation between reserve records and circulating on-chain supply, with breaks investigated.Reconciliation output, exception logs and periodic reserve reporting.
Redemption at parRedemption availability treated as a monitored service with published targets and escalation.Availability reporting, incident records and client notification history.
Information security risk and control frameworkA board-approved framework covering keys, privileged roles, change control and monitoring of the issuing contracts.Approved framework, control testing results and access and change records.
Third-party due diligence and monitoringAssessment and ongoing oversight of chain infrastructure, monitoring and analytics providers.Due diligence files, contract terms and oversight records.
Privileged action controlMint, burn, freeze, pause and role changes gated by policy and monitored as critical events.Privileged-action alerts mapped to approved instructions and change tickets.
Incident recordsDetection to notification measured on a clock, with a named owner at each hop.Incident timelines, notification acknowledgments and post-incident reviews.

Key dates

  1. July 2025

    The GENIUS Act is signed into law.

  2. February 2026

    OCC proposes implementing rules (Bulletin 2026-3).

  3. April 2026

    FDIC issues its notice of proposed rulemaking.

  4. Ongoing

    Comment periods and final rules; issuers prepare control evidence.

How Client Focus supports it

Secure

Continuous monitoring, analyst validation and a published notification clock, with incident records retained for reporting.

Run

ITIL-based incident, problem and change management with named service owners and hop-by-hop timestamps on every escalation.

Trust and compliance

Control frameworks, separation of duties and the due-diligence pack supervisors and procurement teams ask for.

Prepare for supervisory review.

Whether you are designing a new system, running one in production, or defending one, Client Focus brings engineering, network operations and security operations under one accountable model. Every request is reviewed by a principal of the firm.