Stablecoin regulations: a 5-point compliance assessment framework
Stablecoin regulations now separate issuers on five measurable axes: legal permission, reserve structure, redemption capacity, disclosure quality, and financial-crime controls. A token can show one-to-one collateralization and still fail the assessment.

A monthly attestation does not establish a legal redemption claim. A redemption right does not establish that the reserve is bankruptcy-remote. A license in one jurisdiction does not create cross-border compliance.
The relevant regulatory baseline has hardened. The stablecoin-specific titles of the EU Markets in Crypto-Assets Regulation, MiCA Titles III and IV, have applied since 30 June 2024. The U.S. GENIUS Act became law on 18 July 2025. FATF standards continue to define the information-transmission baseline for virtual-asset transfers, although national implementation remains uneven.
A five-point framework does not predict whether a token will trade at $1.00 in every market condition. It measures something narrower: whether the issuer’s legal architecture, reserves, operational procedures, reporting, and compliance perimeter support its stated fiat-equivalent claim.
Collateralization is an asset-side test. Compliance is a claim, control, and liquidity test.
1. Legal classification and issuer licensing
The first assessment point is not reserve composition. It is legal classification. The same token can be subject to different rules depending on the reference asset, redemption promise, issuance method, holder geography, and the functions performed by intermediaries.
Under MiCA, the primary distinction is between asset-referenced tokens, or ARTs, and e-money tokens, or EMTs.
An ART references another value or right, or a combination of assets. An EMT is designed to maintain a stable value by referencing one official currency. A USD-referenced token may therefore enter the EMT perimeter rather than the ART perimeter. Applying ART requirements mechanically to all stablecoins produces a false compliance result.
For an issuer assessment, the legal file should establish four points:
- Token classification. The issuer must identify whether the instrument is an EMT, ART, payment stablecoin, security, deposit-like instrument, or another regulated product under each relevant jurisdiction.
- Issuance authority. The entity minting tokens must be identified. A brand name, foundation, protocol, exchange, and operating subsidiary are not interchangeable legal persons.
- Regulatory perimeter. The analysis must distinguish token issuance from custody, exchange operation, wallet services, transfer execution, and redemption agency. These functions can trigger separate obligations.
- Holder claim. The governing documents must specify who owes redemption, in which currency, under what law, and with what priority if the issuer enters insolvency.
MiCA creates a measurable capital floor for ART issuers. Own funds must equal the highest of EUR 350,000, 2% of the average reserve amount, or one quarter of the preceding year’s fixed overheads. A competent authority may require an add-on of up to 20% above the 2% reserve-based requirement when risk warrants it.
This is not a reserve requirement. It is an issuer-loss-absorption requirement. The distinction matters. Reserves support token liabilities. Own funds absorb operating losses, legal costs, valuation errors, and other issuer-level exposures before they reach the reserve structure.
The GENIUS Act uses a different framework for permitted payment stablecoin issuers. It requires one-to-one reserves in U.S. currency or other specified liquid assets, monthly reserve-detail publication, a disclosed redemption policy, and Bank Secrecy Act compliance. The law also sets a stated threshold of USD 10 billion or less for certain state-regulated issuance arrangements. That threshold is not a blanket exemption from federal standards.
A practical jurisdictional regulatory risk score should penalize ambiguity. A token with a clear classification and identified issuer can be assessed. A token distributed through multiple entities, with unclear redemption obligors and fragmented terms, cannot be assigned a high legal-compliance score merely because it has market liquidity.
| Legal test | Higher-compliance condition | Structural deficiency |
|---|---|---|
| Token classification | Documented classification by jurisdiction | Marketing label substitutes for legal classification |
| Issuer identity | Named legal entity mints and redeems | Multiple affiliates perform undefined roles |
| Regulatory permission | Authorization, registration, or clearly stated exemption basis | No disclosed legal basis for issuance |
| Holder claim | Contractual redemption right and governing law are stated | Claim is discretionary, indirect, or undocumented |
| Capital buffer | Regulatory own-funds methodology is disclosed | Reserve assets are presented as the issuer’s only protection |
2. Reserve quality, segregation, and custody standards
The second point measures the reserve, but not only its gross value. A reserve report stating that assets exceed tokens in circulation is a limited data point. It does not by itself identify asset liquidity, encumbrance, concentration, custody risk, or legal segregation.
The correct starting equation is simple:
Reserve coverage ratio = eligible reserve assets / tokens outstanding
A ratio of 100% or more is necessary for a one-to-one model. It is not sufficient. The denominator must match the reporting timestamp. The numerator must exclude assets that cannot be realized for redemption without material delay, legal constraint, or valuation uncertainty.
MiCA requires ART reserve assets to be unencumbered and promptly accessible for redemption requests. They must be held with eligible custodians. Reserve concentration and custody concentration must be avoided. ART issuers must also arrange custody no later than five working days after issuance.
The operational implication is direct. A stablecoin issuer should not treat a bank balance, a short-duration sovereign instrument, a repurchase agreement, a money-market exposure, and a receivable as equivalent simply because each is reported near par. Their liquidity delta under redemption pressure differs.
Liquidity delta is the gap between the book value shown in a reserve statement and the cash that can be mobilized within the required redemption window. The larger the delta, the weaker the reserve for a token marketed as fiat-equivalent.
Reserve assessment should isolate the following components:
1. Cash and demand deposits. These provide immediate settlement capacity but create bank concentration and bank-resolution exposure. The relevant question is not whether cash exists. It is whether it is distributed among eligible custodians and legally available to the token reserve.
2. Short-term government securities. These can provide high-quality liquidity, but settlement timing, collateral arrangements, and repo dependencies still matter. A Treasury bill is not the same as intraday cash.
3. Reverse repurchase agreements and similar instruments. These require analysis of counterparties, collateral, maturity, substitution rights, and settlement mechanics. The reported value may be stable while the operational conversion path is conditional.
4. Corporate debt, secured lending, or other credit assets. These introduce credit and market-liquidity exposure. They require valuation methodology and concentration disclosure. They should not be aggregated with cash without a separate liquidity treatment.
5. Related-party and encumbered assets. These require a hard deduction unless the issuer demonstrates enforceable priority, unrestricted access, and legal separation from group liabilities.
Reserve composition is not a percentage chart. It is a timeline from token burn to fiat settlement.
Segregation determines whether assets are structurally available to holders. An issuer can hold sufficient assets on a consolidated basis while creditors of an operating company retain claims against those same assets. The holder’s legal position must be tested under the applicable insolvency regime, not inferred from a reserve dashboard.
The assessment should therefore distinguish three layers:
- Economic backing: assets have a reported value at or above tokens outstanding.
- Operational access: assets can be transferred or liquidated within the redemption process.
- Legal ring-fencing: assets are insulated from issuer creditors and clearly allocated to token liabilities.
Only the third layer addresses a full reserve-protection analysis. Even then, it does not eliminate depeg risk in secondary markets.
3. Redemption mechanics and liquidity resilience
A stablecoin becomes fiat-equivalent only through a credible redemption mechanism. Secondary-market trading is not redemption. A token can trade near par on exchanges while direct redemption is restricted, delayed, limited to certain counterparties, or dependent on intermediaries.
MiCA requires ART holders to have a right of redemption at all times. Policies must cover redemption conditions, timeframes, stressed-market procedures, valuation, and settlement. Redemption generally may not carry a fee, except within the regulation’s recovery-plan provisions.
For EMTs, the framework is more specific. Tokens must be issued at par upon receipt of funds and redeemed at any time and at par value in funds. Issuers and crypto-asset service providers may not grant interest related to holding an EMT.
The FSB’s global-stablecoin recommendations set a comparable baseline for stablecoins referenced to a single fiat currency: a robust legal claim, timely redemption, and redemption at par into fiat. This is a systemic standard, not a universal operating rule automatically enforced in every jurisdiction.
A redemption assessment should trace the full transaction path:
1. The holder submits a redemption request through the issuer or an authorized agent.
2. The issuer validates eligibility, sanctions status, wallet provenance, and any account requirements.
3. Tokens are transferred, frozen, or burned under the issuer’s stated process.
4. Reserve assets are mobilized through banks, custodians, dealers, or settlement systems.
5. Fiat is delivered to the verified beneficiary account.
6. Outstanding token supply is reduced or otherwise reconciled against redeemed liabilities.
Each step can create delay. KYC onboarding may exclude retail holders from direct redemption. Banking cut-off times can defer settlement. Custodian outages can prevent asset transfer. A reserve composed of liquid securities can still face a timing mismatch if cash must arrive before asset settlement completes.
The assessment should score redemption on actual terms rather than generic claims.
| Redemption variable | Stronger structure | Weaker structure |
|---|---|---|
| Legal right | Clear contractual claim against identified issuer | Redemption at issuer discretion |
| Par basis | Fiat redemption at stated par value | Value based on discretionary market pricing |
| Access | Published eligibility and direct process | Undefined or intermediary-dependent route |
| Timing | Stated operational timeline and stress procedure | No disclosed settlement expectation |
| Fees | Limited and rule-based fee structure | Open-ended charges or spread-based deductions |
| Supply reconciliation | Burns and liabilities reconciled to redemptions | Circulating supply changes are not explained |
No published reserve ratio guarantees immediate redemption for every holder at the same time. The relevant test is whether the issuer has disclosed how it handles stress, what assets fund the first liquidity tranche, and how it manages the sequence between token cancellation and fiat settlement.
A stablecoin with narrow direct-redemption access can still maintain a market peg. That does not convert exchange liquidity into a universal holder right. The distinction should remain explicit in any compliance score.
4. Transparency: disclosure and independent assurance
Transparency is the fourth point. It is often overstated because the vocabulary is used loosely. “Audit,” “attestation,” “reserve report,” “proof of reserves,” and “review” describe different procedures and different assurance levels.
Under MiCA, ART issuers must disclose the amount in circulation and the value and composition of reserve assets on a public website at least monthly. They must publish both a summary and the full, unredacted reserve audit report as soon as possible.
The GENIUS Act also requires monthly publication of reserve details for permitted payment stablecoin issuers. Frequency alone does not determine quality. A monthly document can be timely but narrow in scope. It may report a point-in-time asset balance without testing liabilities, beneficial ownership, encumbrances, control of private keys, or subsequent settlement events.
PCAOB standards distinguish between an examination and a review. An examination reduces attestation risk to an appropriately low level and expresses an opinion. A review provides only moderate assurance. Neither term should be replaced casually with “audit” unless the engagement is in fact a financial-statement audit.
A disclosure package should be read in this order:
- Reporting date. Determine the exact timestamp. A reserve report is a snapshot, not a continuous balance-sheet history.
- Scope. Identify whether the work covers reserve assets, token liabilities, internal controls, legal rights, or a defined subset.
- Assurance level. Separate examination, review, audit, and agreed-upon procedures.
- Asset categories. Check whether cash, securities, repos, funds, loans, and other positions are disaggregated.
- Custody and concentration. Identify banks, custodians, counterparties, and material single-point exposures where disclosed.
- Limitations. Read the exclusions. These often define what the report does not establish.
- Supply methodology. Determine how tokens outstanding are measured across chains, treasury wallets, authorized but unissued units, and burned supply.
Reserve transparency rules should be scored against verifiability, not document volume. A 40-page report with aggregated assets and no liability reconciliation can provide less usable evidence than a concise attestation with clear scope, dated balances, identified custodians, and supply reconciliation.
The core question is whether an external reader can reconstruct the collateralization position at the reporting date. If reserve assets equal $X and tokens outstanding equal $Y, the report should make both variables identifiable without relying on issuer marketing language.
5. AML/CFT governance and cross-border controls
The fifth point is the least visible in a reserve chart and the most jurisdiction-dependent. Stablecoins circulate through issuers, exchanges, custodians, wallets, decentralized protocols, market makers, and payment interfaces. The compliance perimeter is therefore wider than the issuer’s balance sheet.
The U.S. GENIUS Act subjects permitted payment stablecoin issuers to Bank Secrecy Act requirements. At the global level, FATF standards require virtual-asset service providers and other financial institutions to transmit relevant originator and beneficiary information with virtual-asset transfers under the Travel Rule framework.
Implementation is incomplete. FATF reported in June 2022 that only 29 of 98 surveyed jurisdictions had passed relevant Travel Rule laws. This figure does not mean the other jurisdictions impose no AML/CFT obligations. It shows that formal Travel Rule implementation was fragmented across the surveyed sample at that point.
A stablecoin compliance review should test whether governance controls operate across the actual transfer network:
- Customer identification and beneficial-owner procedures for direct issuer clients.
- Sanctions screening and escalation procedures for minting, redemption, and controlled wallet activity.
- Transaction-monitoring methods, including treatment of on-chain alerts and false positives.
- Wallet-address restriction, freezing, or blocking authority where the token design provides it.
- Travel Rule data collection and transmission through regulated counterparties.
- Record retention, suspicious-activity reporting, and audit trails.
- Cross-border decision rights: which entity can halt issuance, redemption, or transfer support in each jurisdiction.
These controls are not interchangeable with on-chain analytics. Blockchain tracing can identify transaction patterns. It does not itself establish customer due diligence, reporting compliance, or lawful data transmission. Conversely, a formal KYC process does not eliminate exposure when a token moves into self-custody or through unhosted-wallet flows.
The scoring consequence is straightforward. An issuer with strong reserve disclosure but no disclosed AML/CFT governance cannot be treated as globally compliant. A token’s compliance status changes with customer location, service-provider role, and the local adoption of FATF-aligned requirements.
The score is a structural measure, not a peg forecast
A usable framework assigns one score to each of the five points: legal classification, reserves, redemption, transparency, and AML/CFT governance. The final result should retain the component scores. A single aggregate number can conceal a critical weakness.
A token may score strongly on reported collateralization and weakly on direct redemption. It may meet one jurisdiction’s issuer licensing requirements while lacking a clear basis for distribution in another. It may publish a monthly attestation while providing only moderate assurance over a limited reporting date.
The resulting assessment is not a claim that a stablecoin is safe, solvent, or permanently fixed to its reference currency. It is a measure of disclosed regulatory and operational structure.
Stablecoin regulations are converging around the same underlying requirements: identifiable issuers, segregated reserves, par redemption, recurring disclosure, and financial-crime controls. MiCA, the GENIUS Act, FATF standards, and FSB recommendations do not produce a single global rulebook. They do provide a consistent audit path.
The most defensible conclusion is narrow. A stablecoin merits a higher compliance assessment only when its legal claim, reserve assets, redemption process, assurance scope, and cross-border control framework can be tested separately and reconciled as one system.