CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

Stablecoin AML Compliance: How Banks Should Structure Their Controls

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING Stablecoin AML Compliance: How BanksShould Structure Their Controls

Stablecoins now represent a collective market capitalisation exceeding $300 billion. Banks and payment providers are no longer watching from the sidelines: they are actively building settlement, custody, and reserve services around these instruments. That commercial reality comes with a compliance obligation that is equally real. Stablecoins are the dominant rail for cryptoasset money laundering, and they feature with growing regularity in sanctions evasion. For any bank that wants to participate, building proportionate AML controls around stablecoins is not optional. It is the condition on which participation becomes defensible. This analysis, drawing on Elliptic's July 2026 guidance for financial institutions, sets out what that means in practice for accounting firms, CFOs, and compliance teams.

Stablecoin AML Compliance: How Banks Should Structure Their Controls

Why Stablecoins Attract Both Opportunity and Financial Crime Risk

The commercial case for banks is straightforward. Cross-border settlement that clears in minutes rather than days, at any hour, is a genuine improvement on correspondent banking infrastructure. The same characteristics, speed, low cost, and round-the-clock availability, are precisely what make stablecoins attractive for illicit finance. There is no contradiction here: the design features driving adoption are the same ones that create risk.

Stablecoins have become the primary vehicle for cryptoasset-related money laundering. They also appear in documented sanctions evasion cases, including instruments specifically engineered to move funds beyond the reach of Western financial controls. A ruble-pegged cryptoasset issued in Kyrgyzstan and backed by a sanctioned Russian state bank is one concrete example of how these instruments can be constructed with evasion as an explicit design goal.

The answer is not to avoid stablecoins. It is to manage the risk with controls calibrated to the specific exposure a bank carries. That starts with identifying which of three distinct exposure channels applies.

Three Channels of Stablecoin Exposure

Not all stablecoin risk reaches a bank the same way. Elliptic's framework identifies three separate channels, and the controls appropriate to each are different. Treating them as interchangeable is where compliance programs tend to develop blind spots.

Channel One: Direct Issuer Relationship

A bank that holds, distributes, or settles in a specific stablecoin has a direct relationship with the issuer. The issuer is effectively a counterparty, and standard correspondent banking due diligence applies as a starting point. What traditional due diligence cannot reveal, however, is whether the issuer's actual on-chain behaviour matches its stated controls. A bank needs the ability to monitor on-chain activity continuously, not just review paperwork at onboarding.

Channel Two: Proprietary Stablecoin Products

Where a bank designs and offers its own stablecoin product, it inherits the risk profile built into that design. The questions at the product-design stage include which stablecoins to support, which use cases to permit, what monitoring thresholds apply, and under what circumstances escalation is required. These are not purely technical decisions. They have direct compliance and accounting consequences that need to be embedded at the architecture stage, not retrofitted later.

Channel Three: Indirect Exposure Through Customers and VASPs

This is the channel banks most commonly underestimate. A bank may have no issuer relationship and no stablecoin product, yet still carry stablecoin exposure through customers or Virtual Asset Service Providers whose payment flows intersect with stablecoin rails. US authorities have documented how illicit actors convert cash into stablecoins several steps removed from the banking system, so the exposure can reach a bank without an issuer or a product ever appearing in the transaction record.

Managing indirect exposure requires mapping which customers and VASPs send or receive stablecoins, identifying the counterparties behind those flows, and assessing how often those flows intersect with known money laundering, sanctions evasion, and fraud typologies. Firms should also review the FATF's latest targeted update on crypto AML enforcement gaps, which sets out current expectations for VASP oversight that are directly relevant to this channel.

Five Design Factors That Shape a Stablecoin's Risk Profile

Once a bank has identified its exposure channel, the next task is assessing the risk profile of the specific stablecoin involved. Five design factors determine how much risk a given instrument carries into the financial system.

Where Illicit Activity Concentrates

Research indicates that most illicit stablecoin activity now occurs in the secondary market, as tokens move between holders and across chains without an AML-obligated intermediary involved. This is a critical insight for banks focused only on the primary issuance relationship: the highest-risk activity is often downstream of the issuer.

User Base and VASP Distribution

A stablecoin used primarily by institutional counterparties in lower-risk jurisdictions carries a different risk profile from one distributed broadly to retail holders through high-risk VASPs. The composition of the user base, and the regulatory standing of the distribution channels, are material factors in any risk assessment.

Regulatory Framework of Issuance

A stablecoin issued under a structured regulatory framework, such as the US GENIUS Act or the EU's Markets in Crypto-Assets Regulation (MiCA), operates within oversight arrangements that reduce certain categories of risk. One issued without meaningful regulatory oversight does not carry those safeguards. This distinction should be reflected directly in how a bank classifies the instrument for AML purposes. For context on how MiCA is shaping the European stablecoin landscape, the FCA stablecoin sprint findings on cross-border payment flows provide a useful comparative reference.

Issuer Type and Governance

Whether the issuer is a regulated financial institution, a licensed VASP, or an unregulated crypto company affects both the quality of its internal controls and its accountability to supervisory bodies. Issuer governance is a due diligence factor, not a secondary consideration.

Smart Contract Controls: Freeze and Block Capability

Some stablecoin issuers build freeze and block functionality into their smart contracts, which supports fraud recovery and sanctions compliance enforcement. Others deliberately exclude these capabilities, sometimes as a feature rather than an oversight. An issuer without freeze-and-block capability carries materially higher risk, because the bank cannot rely on the issuer to act when a sanctioned wallet or fraudulent transaction is identified. This factor should be a standard line item in any stablecoin due diligence checklist.

The On-Chain Verification Gap and What It Means for Controls

The central limitation of traditional correspondent banking due diligence, when applied to stablecoin counterparties, is that it captures what an issuer claims, not what it does. An issuer can represent that it screens wallets, enforces sanctions lists, and monitors transaction flows. Without on-chain verification, a bank cannot confirm any of that.

Blockchain analytics addresses this gap directly. A bank with access to on-chain monitoring can measure an issuer's actual wallet behaviour against the stated risk profile, identify counterparties involved in minting and redemption activity, and flag divergences between represented controls and observable on-chain conduct. This capability is not a nice-to-have: it is the specific addition that makes stablecoin due diligence defensible under current regulatory expectations.

The same capability applies to ongoing monitoring. A relationship that passes onboarding due diligence can deteriorate if an issuer's counterparty mix shifts toward higher-risk wallets or jurisdictions over time. Static, point-in-time due diligence does not capture this. Continuous on-chain monitoring does.

Accounting and Reporting Implications for CFOs and Finance Teams

The compliance framework above has direct accounting consequences that CFOs and finance teams need to anticipate, particularly as crypto accounting software and digital asset accounting software become central to how firms manage their on-chain positions.

Balance Sheet Classification and Measurement

Stablecoins held as part of a settlement or treasury operation need to be classified correctly on the balance sheet. Under IFRS 9, a stablecoin held for settlement purposes is likely to be classified as a financial asset measured at amortised cost or fair value, depending on the business model and cash flow characteristics. Under current US GAAP guidance, most crypto assets including stablecoins are treated as indefinite-lived intangible assets unless they meet the definition of a cash equivalent, which most do not. The FASB's fair value measurement requirement, which took effect for fiscal years beginning after 15 December 2024, changes how unrealised gains and losses on qualifying crypto assets flow through the income statement. Finance teams need to confirm whether their stablecoin holdings fall within the FASB scope and adjust their reporting accordingly.

AML Event Logging and Audit Trail Requirements

When a bank's blockchain analytics system flags a suspicious stablecoin transaction or counterparty, that event needs to be captured in a way that supports both Suspicious Activity Report filing and internal audit review. The logging architecture of any crypto bookkeeping software used by the firm needs to be able to record on-chain transaction identifiers, wallet addresses, flag categories, and disposition decisions in a format auditors can interrogate. This is not a standard feature of general-purpose accounting systems, and it is a gap that needs to be closed before a firm scales its stablecoin activity.

Sanctions Exposure and Impairment

Where a stablecoin holding is linked to a sanctioned entity or jurisdiction, impairment considerations arise immediately. An asset that cannot be transferred or redeemed due to a freeze order, or that is linked to a counterparty subject to OFAC or EU sanctions designations, may need to be written down or disclosed separately. Finance teams should have a documented protocol for what happens to a stablecoin position when a sanction event is identified, covering both the accounting treatment and the regulatory notification obligations.

Reserve and Collateral Verification

For banks holding stablecoins as part of a reserve or liquidity management strategy, the composition and verifiability of the issuer's reserves are directly relevant to the carrying value of the asset. An issuer whose reserve claims cannot be independently verified on-chain introduces measurement uncertainty that needs to be reflected in disclosures and, potentially, in the choice of measurement basis. Auditors reviewing stablecoin positions should be asking for on-chain reserve verification, not just relying on attestation letters.

Stablecoin AML Compliance: How Banks Should Structure Their Controls

Practical Next Steps for Compliance and Finance Teams

The framework above translates into a short set of priority actions for banks and accounting firms operating in or advising on the stablecoin space.

First, identify which of the three exposure channels applies to the institution. The controls required for a bank with a direct issuer relationship are different from those needed for indirect exposure through customer flows. Applying the wrong framework wastes resources and leaves gaps.

Second, build or procure on-chain monitoring capability before expanding stablecoin activity, not after. Traditional due diligence frameworks are necessary but not sufficient. On-chain verification is the additional layer that regulators in both the US and EU are increasingly expecting to see evidenced.

Third, review the five design factors for every stablecoin the institution touches, whether as a product, a settlement currency, or a customer flow. The freeze-and-block capability question in particular should be a standard item in due diligence checklists and in VASP onboarding questionnaires.

Fourth, ensure that the firm's crypto accounting software can produce an audit-ready record of AML events linked to on-chain transaction data. The gap between general-purpose accounting systems and the on-chain evidence trail is one of the most common weaknesses identified in regulatory reviews of financial institution crypto programs.

Fifth, document the rationale for every stablecoin relationship and product decision. Regulators conducting enforcement reviews look for evidence that institutions made informed, documented choices, not that they simply avoided the worst outcomes by chance.

Source: Elliptic

USEUGLOBAL#stablecoinsEnforcementAML/KYC & Licensing

FAQ

What are the three channels through which a bank can be exposed to stablecoin financial crime risk?

The three channels are: a direct relationship with a stablecoin issuer (as a settlement or custody counterparty), exposure through a proprietary stablecoin product the bank designs and offers, and indirect exposure through customers or VASPs whose payment flows intersect with stablecoin rails. Indirect exposure is the channel most often missed, because it can reach a bank without any issuer relationship or stablecoin product being present.

Which design features of a stablecoin affect its AML risk profile?

Five factors matter: where illicit activity concentrates in the token's lifecycle (primary issuance or secondary market trading), the composition of the user base and the regulatory standing of distribution VASPs, the regulatory framework under which the stablecoin is issued (such as MiCA or the US GENIUS Act), the type and governance structure of the issuer, and whether the smart contract includes freeze and block capabilities that allow enforcement of sanctions and fraud recovery.

Why is traditional due diligence insufficient for stablecoin issuers?

Traditional due diligence captures what an issuer claims about its controls. It cannot verify whether actual on-chain behaviour matches those claims. Blockchain analytics provides the additional layer needed: a bank can monitor the issuer's wallet activity, check counterparty flows, and identify divergences between represented and actual conduct. Regulators in both the US and EU are increasingly expecting this on-chain verification to be evidenced in compliance programs.

How should stablecoins be treated for accounting and financial reporting purposes?

Under IFRS 9, stablecoins held for settlement are likely classified as financial assets at amortised cost or fair value depending on business model and cash flow tests. Under US GAAP, most stablecoins are treated as indefinite-lived intangible assets unless they qualify as cash equivalents, which most do not. The FASB's fair value measurement requirement, effective for fiscal years beginning after 15 December 2024, changes how unrealised gains and losses on qualifying crypto assets flow through the income statement. Finance teams should confirm the scope classification and adjust reporting accordingly.

What logging requirements should crypto accounting software meet for stablecoin AML compliance?

When a monitoring system flags a suspicious stablecoin transaction, the system needs to record on-chain transaction identifiers, wallet addresses, flag categories, and the disposition decision in a format that supports both SAR filing and internal audit review. Standard general-purpose accounting systems typically cannot produce this audit trail. Institutions scaling stablecoin activity should verify that their crypto bookkeeping software or digital asset accounting software can generate this linked on-chain evidence record before expanding operations.

Related articles

AML/KYC & Licensing
A7A5: How Sanctions and Blockchain Analytics Collapsed a Ruble Stablecoin
AML/KYC & Licensing
Huione Guarantee: $11B USDT Marketplace and the AML Obligations It Creates
AML/KYC & Licensing
Huione Group: World's Largest Illicit Marketplace and the USDH Stablecoin Risk
AML/KYC & Licensing
EU Sanctions 'Stern': Trickbot Boss and the $300M Ransom Trail