Jun 25th, 2026
Stablecoins Got Their Framework. Now Comes the Control Problem.
TL;DR
Stablecoins are entering a more formal regulatory era, but clearer rules do not remove the operational control problem. The GENIUS Act creates a framework for payment stablecoins, while regulators are also removing references to reputation risk from supervisory materials. That may change how banks talk about certain relationships, but it does not eliminate the underlying obligations around AML, sanctions, reserves, redemption, custody, vendor oversight, fraud monitoring, cybersecurity, and customer support. For issuers, banks, fintechs, and platforms, the next phase is not just proving stablecoins can be innovative. It is proving stablecoin programs can be operated cleanly, documented clearly, supervised properly, and explained when something breaks.
Stablecoins Got Their Framework. Now Comes the Control Problem.
The funny thing about financial regulation is that everyone wants clarity until clarity shows up with homework.
Stablecoins have spent years living in the weird zone between crypto experiment, payment rail, stored value product, settlement tool, dollar wrapper, and “please do not ask too many questions about redemption during stress.”
Now the industry is moving into a different phase.
The GENIUS Act gave payment stablecoins a federal framework. Regulators are now working through the details: who can issue them, what reserves must look like, what reports are required, how custody works, and what AML, sanctions, and compliance obligations apply to permitted payment stablecoin issuers.
That is a big deal.
It also means stablecoins are becoming less of a crypto headline and more of a compliance operating model.
And while that is happening, federal banking regulators are also changing the way they talk about supervision. The OCC, FDIC, and Federal Reserve have been removing references to “reputation risk” from supervisory materials and interagency guidance, part of a broader effort to prevent examiners from using vague reputational concerns to pressure banks away from lawful customers or industries.
That is also a big deal.
But here is where platforms, fintechs, banks, and stablecoin issuers need to be careful:
Removing the words “reputation risk” does not remove the risk.
It does not remove BSA/AML obligations. It does not remove sanctions screening. It does not remove fraud exposure. It does not remove third-party oversight. It does not remove redemption risk, reserve management, consumer confusion, cyber risk, operational failures, or the need to prove that the program works when volume shows up.
It just changes the vocabulary.
The control problem is still very much alive.
Stablecoins Are Moving Out of the Sandbox
For years, stablecoins were often discussed like a parallel financial system.
Crypto people talked about them as programmable dollars. Payments people talked about them as faster settlement. Banks looked at them with a mix of curiosity and allergic reaction. Regulators looked at them and saw a product that sounded simple until you asked who was responsible when something broke.
A token worth one dollar sounds easy.
Keeping it worth one dollar, redeemable for one dollar, monitored for illicit activity, backed by appropriate reserves, integrated into payment workflows, protected from misuse, and understood by customers is not easy.
That is why the GENIUS Act matters. It moves stablecoins toward a more formal structure. The framework is designed to bring payment stablecoin issuance into a regulated environment, with permitted issuers, reserve requirements, supervision, reporting, and compliance obligations.
In plain English: stablecoins are growing up.
The industry asked for clearer rules. Now the rules are arriving.
That does not mean every question is answered. In fact, the opposite is true. Once the high-level framework exists, the hard implementation questions get louder.
Who is the issuer? Who is the custodian? Who holds the reserves? Who handles redemption? Who monitors transactions? Who screens wallets? Who owns sanctions exposure? Who manages third-party vendors? Who answers when a platform embeds stablecoin functionality into a product that customers experience as “just payments”?
A law can create the framework.
It cannot operate the program for you.
The Compliance Work Is Not Cosmetic
One of the easiest mistakes to make with stablecoins is to treat compliance as a wrapper.
Build the product. Add the policy. Add the monitoring vendor. Add the disclosures. Add the legal language. Launch.
That approach is tempting because stablecoins feel technical. The product conversations often revolve around wallets, APIs, tokens, smart contracts, settlement, reserves, redemption mechanics, and integrations. Those things matter.
But compliance cannot sit politely at the edge of the architecture hoping someone remembers to invite it into the transaction flow.
If a stablecoin is being used for payments, settlement, merchant acceptance, payouts, cross-border transfers, marketplace flows, or embedded finance, compliance has to be part of the system design.
That means basic questions need operational answers:
- How is customer identity verified?
- What activity is expected?
- What activity is suspicious?
- What sanctions screening happens, and when?
- How are wallets, counterparties, and transaction patterns monitored?
- What happens when an alert is generated?
- Who investigates?
- Who freezes, rejects, or blocks activity?
- What gets reported?
- What evidence is retained?
- How are third-party platforms supervised?
- What happens when redemption demand spikes?
- What happens when a partner changes the use case?
Those are not footnotes.
Those are the product.
If the stablecoin is supposed to move money faster, compliance needs to keep up with the money movement. If the product operates 24/7, monitoring cannot be built around banker’s hours and a shared inbox. If the rail is programmable, the controls need to understand what is being programmed.
Otherwise, the innovation story becomes a very expensive way to discover that the control environment was still in beta.
Reputation Risk May Be Leaving the Script
The removal of reputation risk references from bank supervisory materials is meaningful.
The concern behind the change is understandable. If “reputation risk” is too vague, it can become a catch-all phrase that allows examiners to pressure banks away from lawful businesses without tying the concern to concrete safety and soundness, compliance, legal, or operational issues. That is a real policy debate, and the agencies have clearly been moving to take reputation risk out of the formal supervisory vocabulary.
For banks and fintechs, that shift may matter in practical ways.
Banks may feel more pressure to make decisions based on specific, documented risks rather than broad discomfort with an industry, customer type, or politically sensitive business. Fintechs and stablecoin companies may see the change as reducing one barrier to banking access. Lawful businesses that have struggled with debanking concerns may view it as a step toward fairer treatment.
But nobody should confuse that with a free pass.
A bank may not be able to say, “We are exiting this relationship because of vague reputation risk.”
But it can still say, “We cannot support this relationship because the AML controls are weak.”
Or: “The sanctions risk is not adequately managed.”
Or: “The transaction monitoring data is incomplete.”
Or: “The partner cannot produce evidence.”
Or: “The operational model has outgrown the compliance program.”
Or: “The customer base no longer matches the approved risk profile.”
That is the distinction that matters.
Regulators may be narrowing the language, but they are not eliminating the underlying responsibilities.
The words changed.
The homework stayed.
Stablecoins Will Still Need Bank Partners
Stablecoin companies may be tempted to read the new framework and think the industry is finally moving around the banking system.
Not exactly.
Even in a more mature stablecoin regime, banks still matter.
Reserves need to sit somewhere. Custody relationships matter. Payment flows may touch banks. Redemption mechanics may rely on banking relationships. Platforms may need fiat on-ramps and off-ramps. Treasury management matters. Settlement accounts matter. Operational resilience matters. Vendor oversight matters.
The bank-fintech relationship is not disappearing.
It is being redesigned.
That means stablecoin issuers and platforms should expect bank partners to ask sharper questions, not fewer questions.
A bank may be more willing to support a lawful stablecoin business if the supervisory framework is clearer and reputation-risk language is less prominent. But the bank is still going to care about the specific risks it has to own or oversee.
That includes:
- Reserve structure and liquidity.
- Redemption procedures.
- AML and sanctions controls.
- Wallet screening.
- Customer identification.
- Transaction monitoring.
- Cybersecurity.
- Smart contract and technology risk.
- Vendor dependencies.
- Complaints and error resolution.
- Governance and board reporting.
- Exit planning.
If the answer to those questions is “we have a vendor,” keep going.
A vendor is not a control environment.
A vendor is one component inside a control environment. The issuer, bank, fintech, or platform still needs governance, procedures, testing, escalation paths, documentation, and evidence that the system works.
The examiner is not grading the logo on the compliance dashboard.
The examiner is grading the program.
Platforms Can Inherit the Mess
Stablecoin compliance is not just an issuer problem.
That is where software platforms need to pay attention.
A platform may not issue the stablecoin. It may not hold reserves. It may not be the regulated entity. It may simply offer stablecoin settlement, stablecoin payouts, stablecoin wallet functionality, or stablecoin-funded transactions through a partner.
That can still create real responsibility.
If the platform controls the user experience, customers will hold the platform responsible. If the platform markets the product, customers will rely on the platform’s explanation. If the platform collects onboarding information, that data may matter for compliance. If the platform sees transaction behavior first, that visibility may matter for monitoring. If the platform controls merchant access, it may shape the risk profile before the issuer or bank sees the full picture.
This is the familiar embedded-payments problem in a new outfit.
The regulated entity may own the formal obligation, but the platform may own the workflow where the risk is created.
That means platform teams need to understand the difference between offering a feature and operating a financial capability.
Stablecoin settlement is not just “faster payouts.”
It may involve liquidity, redemption risk, sanctions exposure, wallet screening, disclosures, tax reporting questions, reconciliation, customer support, volatility around depegging headlines, and operational dependencies that do not look obvious from the product page.
Stablecoin acceptance is not just “another payment method.”
It may change refund flows, chargeback expectations, customer recourse, settlement timing, fraud monitoring, and support language.
Stablecoin wallets are not just “balances.”
They raise questions about custody, ownership, access, recovery, security, complaints, and what the customer thinks they are holding.
If your platform wraps all of that in a friendly interface and calls it seamless, congratulations.
You now own the part customers will yell at.
The New Regulatory Posture Rewards Specificity
There is a practical lesson in the collision between GENIUS Act implementation and the reputation-risk rollback.
The future belongs to specific risk management.
Not vague discomfort. Not broad labels. Not “crypto is risky.” Not “stablecoins are innovative.” Not “our partner handles it.” Not “we have controls.”
Specificity.
What is the risk? Who owns it? What control addresses it? What evidence proves the control works? What happens when the control fails? Who gets notified? Who has authority to stop activity? How is the decision documented? How does the board know the program is still inside the approved risk appetite?
That is the compliance architecture that matters.
For stablecoin programs, this could mean mapping responsibilities across issuers, custodians, banks, exchanges, wallets, processors, merchants, platforms, and vendors. It could mean building monitoring that understands both blockchain activity and customer context. It could mean reserve reporting that finance can actually reconcile. It could mean customer communications that explain redemption and recourse without sounding like a terms-of-service escape tunnel.
The market is moving toward legitimacy.
Legitimacy is not vibes.
Legitimacy is evidence.
What Stablecoin Platforms Should Be Doing Now
If you are a stablecoin issuer, payments company, embedded finance platform, marketplace, PayFac, or software company considering stablecoin functionality, now is the time to get boring on purpose.
Start with role clarity.
Are you the issuer, distributor, custodian, wallet provider, settlement partner, payment facilitator, merchant platform, technology provider, or customer-facing interface? What do you actually control? What do customers think you control? What do your contracts say you control?
Then map the risk ownership.
Who owns AML? Who owns sanctions screening? Who owns fraud monitoring? Who owns redemption? Who owns customer complaints? Who owns transaction freezes? Who owns lost access? Who owns smart contract risk? Who owns vendor failures? Who owns data retention? Who owns regulatory reporting?
Then test the evidence.
Can you produce customer records, transaction history, wallet screening results, alert investigations, reserve reports, redemption logs, partner oversight records, policy exceptions, and board reporting without creating a compliance bonfire with search functionality?
If not, the program is not ready.
Finally, do not let product language outrun the operating model.
Do not call something instant if exceptions take days to explain. Do not call something safe if customers do not understand recourse. Do not call something regulated if the partner structure is doing all the heavy lifting and nobody can explain who owns the control. Do not call something compliant because a vendor dashboard has green checkmarks.
Green checkmarks are nice.
Evidence is better.
The Takeaway
The GENIUS Act is pushing stablecoins into a more formal regulatory era.
That is good for the industry. Clearer rules can create better products, stronger supervision, more serious participants, and fewer arguments about whether stablecoins are financial infrastructure or a very complicated group chat with a dollar sign.
At the same time, the removal of reputation risk from bank supervisory language changes how some risks may be discussed, but it does not eliminate the underlying obligations that matter in real programs.
Stablecoin companies still need AML controls. They still need sanctions compliance. They still need reserve discipline. They still need redemption processes. They still need vendor oversight. They still need fraud monitoring. They still need cybersecurity. They still need customer support that can explain what happened when money moved faster than the human expected.
The old world let stablecoins argue for legitimacy.
The new world asks them to prove it.
That is the shift.
Not whether stablecoins can be innovative.
Whether stablecoin programs can be operated cleanly, documented clearly, supervised properly, and explained when something breaks.
Because regulators may be removing reputation risk from the script.
But if your controls are weak, your evidence is missing, your partner model is blurry, or your customers do not understand what they are using, the risk is still there.
It just has a more specific name.
Want to get featured on the Cents Chat podcast? Complete our survey.
Featuring

Chris
The Lawyer