CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

Elliptic Typologies Report: Stablecoin AML and Crypto Accounting Controls

CryptaCount Editorial · · 11 min read
AML / KYC / LICENSING Elliptic Typologies Report: StablecoinAML and Crypto Accounting Controls

Elliptic's Typologies Report, published in September 2026, signals a compliance inflection point that accounting firms, CFOs, and digital asset teams can no longer treat as background reading. The report maps how financial crime risks tied to cryptoassets have evolved since the previous edition, with dollar-denominated stablecoins emerging as the single most pressing area for sanctions exposure, issuer due diligence, and GENIUS Act readiness. For any firm that relies on crypto accounting software to manage and report on digital asset positions, the practical implications run deep.

Elliptic Typologies Report: Stablecoin AML and Crypto Accounting Controls

Why Stablecoins Are Now the Compliance Frontline

Dollar stablecoins were once treated as a relatively low-risk layer inside crypto portfolios — a place to park value, settle trades, or move funds across chains without the volatility of native tokens. That perception has been revised sharply. Elliptic's report identifies stablecoin issuers and the institutions that handle their tokens as carrying meaningful sanctions exposure risk, precisely because those instruments move freely across blockchains that may touch sanctioned jurisdictions.

The Sanctions Exposure Problem

When a stablecoin circulates on multiple chains, tracing the full history of a wallet's exposure becomes genuinely difficult. A firm may accept a stablecoin payment or hold a stablecoin balance without knowing whether earlier in that token's on-chain journey it passed through a sanctioned entity, a flagged mixer, or a jurisdiction subject to OFAC restrictions. That ignorance is not a legal defence under US sanctions law, which applies strict liability in many circumstances. Elliptic's report calls out this exposure risk explicitly, urging issuers and handlers to build controls that can identify cross-chain stablecoin activity and flag links to sanctioned jurisdictions before settlement occurs rather than after.

The accounting implication is direct: if your firm recognises stablecoin receipts as revenue or records them as liquid assets on the balance sheet, the underlying sanctions status of those tokens affects whether the transaction can legally stand. A stablecoin receipt later tied to a sanctioned counterparty is not simply a compliance problem — it becomes a question of whether the asset should ever have been recognised, and whether retrospective derecognition or disclosure is required.

Cross-Chain Visibility Gaps

The challenge is compounded by the multi-chain nature of modern stablecoin activity. A single dollar-pegged token may exist as a native issuance on one chain and as a bridged representation on several others. Each hop through a bridge or cross-chain protocol creates a new transaction trail that must be independently screened. Most legacy compliance tools, and indeed many early-generation crypto bookkeeping software solutions, were not built to follow an asset across chains in a single workflow. The report points to this gap as an area where firms need to invest in tooling that maps cross-chain exposure holistically rather than chain by chain.

GENIUS Act: Permitted vs. Non-Permitted Stablecoins

The passage of the GENIUS Act introduces a binary compliance test that every bank and regulated institution touching stablecoins must now apply. The framework creates a class of permitted stablecoins — those issued under a compliant federal or state licensing regime — and treats every other stablecoin as non-permitted. Accepting a non-permitted stablecoin as if it were permitted is characterised in the report as a compliance failure, full stop.

What Banks Must Do Under the New Framework

The practical demand is threefold. First, institutions need to identify which stablecoins in circulation qualify as permitted under the GENIUS Act's criteria. Second, they need to screen incoming and outgoing stablecoin flows to detect exposure to non-permitted tokens — including cases where a permitted stablecoin has been swapped for a non-permitted one at some point upstream. Third, they need to build internal controls that apply the right regulatory treatment to each token type, with documented procedures that can be shown to examiners.

This is not a one-time classification exercise. Stablecoin issuers' licensing status can change — a firm that loses its licence, or that never obtained one, shifts its token from potentially permitted to definitively non-permitted overnight. Controls must therefore be dynamic, with regular re-screening of issuer status built into the compliance calendar.

Issuer Due Diligence as a Standing Obligation

Beyond the permitted/non-permitted binary, the report frames issuer due diligence as an ongoing obligation rather than an onboarding checkpoint. Licensed stablecoin issuers must themselves meet AML, sanctions, and risk requirements — but a bank or exchange handling those tokens cannot simply delegate that obligation upward. Holding a stablecoin issued by a firm that subsequently fails its own AML requirements creates downstream liability for every institution in the chain. Elliptic's position is that firms need continuous monitoring of issuer status, not just point-in-time checks at the time a stablecoin is first added to a supported asset list.

For accounting teams, this creates a new category of disclosure risk. If your institution holds stablecoins issued by a firm under regulatory investigation or sanction, the fair value and recoverability of that asset may need to be reassessed, and disclosure of the contingent liability may be required under applicable accounting standards.

Financial Crime Risk: an Evolving Threat Landscape

Beyond stablecoins, the report frames the broader financial crime risk landscape as one in continuous motion. Compliance teams that built their workflows around the threat typologies of 2021 or 2022 are, by definition, working with an outdated picture. Elliptic identifies the combination of regulatory acceleration and threat evolution as the central pressure on compliance functions — a two-front challenge that demands both rule-following agility and genuine investigative capability.

Implications for Compliance Team Resourcing

The report is directed explicitly at financial crime analysts and investigators, not just senior compliance officers. That targeting reflects a reality that many firms are still grappling with: the volume and complexity of crypto-related suspicious activity now requires specialist analytical capacity at the team level, not just policy-level sign-off at the top. Firms that have relied on generalist AML staff to handle crypto cases are increasingly exposed as the typologies diversify.

For accounting and professional services firms advising crypto businesses, this has a workforce implication. Audit and assurance engagements that touch digital asset clients now require staff who understand on-chain transaction analysis, cross-chain bridge mechanics, and the specific risk indicators Elliptic and similar investigators flag. That capability gap is widening faster than training pipelines are filling it.

Accounting and Reporting Controls That Follow from This Report

Translating the report's compliance findings into accounting practice requires firms to address three interlinked control areas.

Transaction-Level Classification in Digital Asset Accounting Software

Every stablecoin receipt, transfer, and settlement needs to carry a classification that records, at minimum, the issuer, the chain on which the token was received, and the sanctions screen result at the time of receipt. Digital asset accounting software that cannot attach these attributes to individual transactions creates a reconciliation problem the moment a regulator or auditor asks for evidence of the screening that took place. The report's emphasis on cross-chain visibility means that software relying on single-chain data feeds will increasingly miss the context needed to make that classification reliable.

Firms reviewing their AML obligations for DeFi operators under the revised CLARITY Act will find that the same transaction-level documentation standards apply here: the obligation to demonstrate that a control existed and functioned at the point of each transaction, not merely that a policy existed on paper.

Balance Sheet Treatment of Non-Permitted Stablecoins

If an institution discovers it holds stablecoins that do not qualify as permitted under the GENIUS Act, the accounting question is whether those assets can be carried at face value. Where there is a realistic prospect that a non-permitted stablecoin could become illiquid, lose its peg, or be subject to regulatory action against the issuer, fair value assessment becomes non-trivial. Firms should establish a documented methodology for reviewing the carrying value of stablecoin positions on a periodic basis, with the GENIUS Act permitted/non-permitted classification forming part of that review.

Sanctions Contingency Disclosures

The report's treatment of sanctions exposure risk for stablecoin handlers has a direct read-across to financial statement disclosure. Where a firm has identified — or should reasonably have identified — exposure to sanctioned counterparties through stablecoin transactions, the contingent liability arising from potential OFAC enforcement needs to be assessed and, where material, disclosed. The earlier OFAC sanctions action against Xinbi Guarantee and the accounting considerations that followed is a worked example of how rapidly that exposure can crystallise into an enforcement event requiring immediate balance sheet and disclosure review.

Practical Next Steps for Accounting Firms and CFOs

The Elliptic report is not prescriptive about implementation timelines, but the regulatory backdrop — particularly the GENIUS Act's live framework — means that the window for preparation is already narrowing. Several actions are immediately actionable.

Audit Your Stablecoin Inventory Now

Produce a full inventory of every stablecoin your institution holds, transacts in, or clears on behalf of clients. For each, document the issuer, the issuer's current licensing status under the GENIUS Act framework, the chains on which the token operates, and the last date on which a sanctions screen was performed. Where gaps exist — tokens with no documented screen, or issuers whose status has not been verified since listing — treat those as priority remediation items.

Review Crypto Accounting Software Capabilities Against the New Requirements

The GENIUS Act's permitted/non-permitted classification and the report's cross-chain screening requirements both demand that your crypto accounting software can ingest multi-chain data, attach compliance attributes to individual transactions, and flag positions that require manual review. If your current tooling cannot do this, the gap needs to be documented, escalated, and addressed through either software upgrade or supplementary manual controls — with that compensating control documented for auditors.

Update AML Policies to Reflect Current Typologies

AML policies written before the GENIUS Act and before the typologies identified in this report became mainstream need revision. The specific risk indicators Elliptic highlights — cross-chain stablecoin movement, issuer due diligence gaps, sanctions exposure through multi-hop transfers — should be named explicitly in your firm's risk appetite statement and transaction monitoring procedures. Generic "crypto risk" language is unlikely to satisfy an examiner who asks whether your controls were calibrated to known current typologies.

Elliptic Typologies Report: Stablecoin AML and Crypto Accounting Controls

Frequently Asked Questions

What does the GENIUS Act's permitted/non-permitted stablecoin framework mean for banks in practice?

Under the GENIUS Act, every stablecoin a bank handles must be assessed against the federal licensing criteria. Stablecoins from issuers that meet those criteria are permitted; all others are not. Treating a non-permitted stablecoin as if it were permitted — accepting it as collateral, clearing it, or holding it as a liquid asset — constitutes a compliance failure. Banks need classification procedures, regular re-screening of issuer status, and controls that prevent non-permitted tokens from being processed without appropriate review.

Why does cross-chain stablecoin activity create a sanctions screening gap?

When a stablecoin moves across chains via a bridge or wrapped token mechanism, each leg of that journey creates a separate transaction record on a different blockchain. A screening tool that only monitors one chain will miss exposure that occurred on another. To satisfy sanctions obligations, firms need screening coverage that follows the asset across its full chain history, not just the final leg received.

How should accounting teams handle stablecoins from issuers under regulatory investigation?

Where a stablecoin issuer is under investigation or has had enforcement action taken against it, the carrying value and liquidity of the token should be reassessed. If recoverability at face value is in doubt, an impairment assessment may be required. Additionally, the contingent liability arising from holding or having transacted in that token should be evaluated for disclosure under applicable accounting standards. The assessment should be documented and reviewed at each reporting date until the regulatory position is resolved.

What is issuer due diligence and how often should it be performed?

Issuer due diligence is the process of verifying that a stablecoin's issuer meets the AML, sanctions, and risk requirements applicable to licensed issuers under the relevant regulatory regime. It goes beyond a one-time onboarding check: because an issuer's licensing status, AML programme, and sanctions exposure can change, firms should perform periodic re-screening — at minimum annually, and on an event-driven basis whenever material news about an issuer emerges.

What should a firm do if its crypto accounting software cannot classify stablecoins by GENIUS Act status?

If the software cannot natively classify stablecoins as permitted or non-permitted, the firm should implement a compensating control: a manual or semi-automated process that applies the classification to each stablecoin position and attaches it to the relevant transaction records. That compensating control needs to be documented, tested, and evidenced for audit purposes. The longer-term solution is to source tooling that can perform this classification automatically, with an auditable data trail, as part of the standard transaction ingestion workflow.

Source: Elliptic

USGLOBAL#stablecoinsEffectiveAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Blockchain Analytics and Sanctions Compliance: What Crypto Firms Must Do Now
AML/KYC & Licensing
EU's 21st Russia Sanctions Package: What Crypto Firms Must Do Now
AML/KYC & Licensing
NYDFS-EBA Stablecoin MOU, HK VATP Rules, and CFTC Perps: What Firms Must Know
AML/KYC & Licensing
Five Crypto Financial Crime Typologies for FI Compliance Programs