[{"data":1,"prerenderedAt":2745},["ShallowReactive",2],{"content-\u002Fresources\u002Fmore\u002Fcompliance-agents-cross-border-stablecoin-payments":3,"resources-category-compliance-agents-cross-border-stablecoin-payments":365},{"id":4,"title":5,"authors":6,"body":7,"categories":6,"category":333,"categoryType":6,"compare":6,"contributors":6,"date":334,"description":335,"extension":336,"faq":337,"howto":6,"isBlog":356,"isChangelog":356,"meta":357,"navigation":359,"path":360,"pillar":356,"products":6,"rawbody":361,"seo":362,"stem":363,"thumbnail":6,"updated":334,"__hash__":364},"content\u002Fresources\u002Fmore\u002Fcompliance-agents-cross-border-stablecoin-payments.md","Compliance agents for cross-border stablecoin payments: a global regulatory guide",null,{"type":8,"value":9,"toc":315},"minimark",[10,17,24,27,32,35,38,41,45,48,51,140,143,147,150,153,156,159,162,166,169,172,175,178,182,185,188,191,200,204,207,212,220,224,232,236,239,243,246,250,253,281,284,288,291,310],[11,12,13],"p",{},[14,15,16],"em",{},"Reading time: about 8 minutes.",[11,18,19,23],{},[20,21,22],"strong",{},"Summary:"," Compliance agents handle cross-border stablecoin payment regulation by reading the context of each transaction, selecting the rule set for the jurisdictions involved, and running identity checks, sanctions screening, Travel Rule data exchange, and reporting before funds settle. The rules are maintained at the infrastructure level, so a business does not rebuild its compliance stack for every new market.",[11,25,26],{},"Cross-border stablecoin payments touch at least two regulatory regimes on every transfer: the sender's and the receiver's. Each regime has its own licensing body, sanctions authority, data-sharing threshold, and reporting obligation. This guide sets out what those regimes require and how a compliance layer can satisfy them without per-country engineering.",[28,29,31],"h2",{"id":30},"how-do-compliance-agents-handle-cross-border-stablecoin-payment-regulation","How do compliance agents handle cross-border stablecoin payment regulation?",[11,33,34],{},"A compliance agent is an automated component that sits in the payment flow and evaluates each transaction against the rules that apply to it. It reads the transaction context, meaning the sender's jurisdiction, the receiver's jurisdiction, the counterparty type, the asset, and the amount, and then selects the matching rule set.",[11,36,37],{},"The agent then runs the checks that rule set requires: customer verification status, sanctions screening across the relevant lists, Travel Rule data exchange with the counterparty institution, and threshold-based reporting. The transaction proceeds, holds for review, or is rejected based on the result.",[11,39,40],{},"The alternative is writing compliance logic per market inside the payment application. That approach works for one or two corridors and breaks when the third market has a different threshold, a different data format, or a different regulator.",[28,42,44],{"id":43},"what-are-the-global-regulatory-requirements-for-stablecoin-transfers","What are the global regulatory requirements for stablecoin transfers?",[11,46,47],{},"Every major market now regulates stablecoin transfers through a licensing regime for the intermediary and an anti-money laundering (AML) regime for the transaction. The licensing regime decides who may operate; the AML regime decides what each transfer must carry and when it must be reported.",[11,49,50],{},"The table below summarizes the primary requirement in six markets relevant to cross-border stablecoin payments.",[52,53,54,70],"table",{},[55,56,57],"thead",{},[58,59,60,64,67],"tr",{},[61,62,63],"th",{},"Jurisdiction",[61,65,66],{},"Regulatory body",[61,68,69],{},"Primary requirement",[71,72,73,85,96,107,118,129],"tbody",{},[58,74,75,79,82],{},[76,77,78],"td",{},"United States",[76,80,81],{},"Financial Crimes Enforcement Network (FinCEN), with state money transmitter regulators",[76,83,84],{},"Money Services Business (MSB) registration under the Bank Secrecy Act (BSA), an AML program, Travel Rule compliance at USD 3,000, and strict-liability sanctions compliance under the Office of Foreign Assets Control (OFAC)",[58,86,87,90,93],{},[76,88,89],{},"European Union",[76,91,92],{},"National competent authorities under the Markets in Crypto-Assets Regulation (MiCA), with the Anti-Money Laundering Directives (AMLD)",[76,94,95],{},"Crypto-Asset Service Provider (CASP) authorization, Travel Rule under the Transfer of Funds Regulation (TFR) with no minimum threshold, and use of MiCA-compliant e-money tokens",[58,97,98,101,104],{},[76,99,100],{},"United Kingdom",[76,102,103],{},"Financial Conduct Authority (FCA)",[76,105,106],{},"Cryptoasset registration under the Money Laundering Regulations (MLRs), Travel Rule compliance in force since September 2023, and sanctions compliance under the Office of Financial Sanctions Implementation (OFSI)",[58,108,109,112,115],{},[76,110,111],{},"Singapore",[76,113,114],{},"Monetary Authority of Singapore (MAS)",[76,116,117],{},"Digital Payment Token (DPT) service license under the Payment Services Act (PSA), with AML and Travel Rule obligations under MAS Notice PSN02 at SGD 1,500",[58,119,120,123,126],{},[76,121,122],{},"Brazil",[76,124,125],{},"Banco Central do Brasil (BCB)",[76,127,128],{},"Authorization as a Sociedade Prestadora de Serviços de Ativos Virtuais (SPSAV) under Resolutions 519, 520, and 521 of 2025, with AML reporting to the Conselho de Controle de Atividades Financeiras (COAF)",[58,130,131,134,137],{},[76,132,133],{},"Japan",[76,135,136],{},"Financial Services Agency (FSA)",[76,138,139],{},"Registration under the revised Payment Services Act, with stablecoin issuance limited to banks, trust companies, and licensed funds transfer providers",[11,141,142],{},"The pattern is consistent: the activity is regulated everywhere, but the regulator, the threshold, and the data format differ. A compliance program that hardcodes one market's assumptions will fail an examination in another.",[28,144,146],{"id":145},"what-does-the-fatf-travel-rule-require-for-stablecoin-payments","What does the FATF Travel Rule require for stablecoin payments?",[11,148,149],{},"The Financial Action Task Force (FATF) is the intergovernmental body that sets global AML standards. Its Recommendation 16, known as the Travel Rule, requires that originator and beneficiary information accompany a funds transfer so that each institution in the chain can screen the parties and respond to law enforcement requests.",[11,151,152],{},"In June 2019, FATF extended the Travel Rule to virtual assets and Virtual Asset Service Providers (VASPs) through an interpretive note to Recommendation 15. Stablecoins are virtual assets under that standard, so a USDC transfer between two VASPs carries the same data obligation as a wire transfer between two banks.",[11,154,155],{},"The required data set is the originator's name, account or wallet identifier, and one of address, national identity number, or date and place of birth, plus the beneficiary's name and account or wallet identifier. FATF recommends a USD or EUR 1,000 threshold, but each country sets its own.",[11,157,158],{},"Thresholds and formats diverge by market. The EU's Transfer of Funds Regulation applies with no minimum since December 30, 2024. The US applies the Bank Secrecy Act Travel Rule at USD 3,000. Singapore's threshold is SGD 1,500. The UK applies the rule to all transfers, with a reduced data set below EUR 1,000.",[11,160,161],{},"The Travel Rule matters for stablecoins specifically because a blockchain transfer carries no identity data by default. The information must move through a separate channel between the two VASPs, matched to the on-chain transaction, and the compliance layer has to do that matching before the payment is treated as complete.",[28,163,165],{"id":164},"how-does-sanctions-screening-work-for-cross-border-usdc-payments","How does sanctions screening work for cross-border USDC payments?",[11,167,168],{},"Sanctions screening checks every party to a payment against the lists maintained by the sanctioning authorities in the jurisdictions involved. For a cross-border USDC payment, that means screening the sender, the receiver, any beneficial owners, and the wallet addresses on both sides.",[11,170,171],{},"The core lists are the OFAC Specially Designated Nationals (SDN) and consolidated lists in the US, the EU consolidated sanctions list, the United Nations (UN) Security Council consolidated list, and the UK OFSI consolidated list. A payment from a US entity to a Brazilian receiver over EU rails must clear all of them, not just the sender's.",[11,173,174],{},"OFAC compliance is strict liability. A payment that reaches a sanctioned party is a violation regardless of intent, which is why screening runs before funds move and again when lists update, not only at onboarding.",[11,176,177],{},"Wallet address screening is the piece that has no analog in bank payments. OFAC has added blockchain addresses to the SDN list since 2018, and a compliance layer must screen the destination address against those entries and against analytics that flag exposure to sanctioned or illicit sources.",[28,179,181],{"id":180},"how-do-you-comply-with-regulations-across-multiple-jurisdictions-without-rebuilding-per-market","How do you comply with regulations across multiple jurisdictions without rebuilding per market?",[11,183,184],{},"Multi-jurisdictional compliance for crypto payments comes down to one architectural decision: whether jurisdiction-specific rules live in the payment application or in a compliance layer beneath it. The first approach means one codebase change per market per regulatory update. The second means the rules are data, selected at runtime by transaction context.",[11,186,187],{},"In a rule-set model, each jurisdiction has a definition of its licensing scope, Travel Rule threshold and data format, sanctions lists, reporting triggers, and receiver verification requirements. The agent loads the definitions for the sender's and receiver's jurisdictions and applies the stricter requirement wherever they conflict.",[11,189,190],{},"Regulatory updates then land in the rule set, not in customer code. When a threshold changes or a list is amended, the provider updates the definition once and every payment evaluated after that point uses it.",[11,192,193,194,199],{},"This is how BlindPay's compliance layer is built. Rule sets are maintained for the regimes described in this guide, including FinCEN, MiCA and AMLD, FCA, MAS, and BCB requirements, and customers inherit updates without code changes. Entity and license details by market are published on the ",[195,196,198],"a",{"href":197},"\u002Flicenses","licenses page",".",[28,201,203],{"id":202},"what-are-the-4-structural-components-of-a-compliant-stablecoin-payment-program","What are the 4 structural components of a compliant stablecoin payment program?",[11,205,206],{},"A compliant stablecoin payment program has four structural components. Regulators in every major market examine all four, and a gap in any one is a finding.",[208,209,211],"h3",{"id":210},"_1-licensing-and-registration","1. Licensing and registration",[11,213,214,215,219],{},"The entity performing the regulated activity must hold the authorization the jurisdiction requires: MSB registration and state licenses in the US, CASP authorization in the EU, FCA registration in the UK, a DPT license in Singapore, SPSAV authorization in Brazil. A business that builds on a licensed provider does not need these itself, but it must confirm the provider holds them for each market it serves. Our ",[195,216,218],{"href":217},"\u002Fresources\u002Fmore\u002Fwhat-is-a-vasp","VASP explainer"," covers who falls inside the licensing perimeter.",[208,221,223],{"id":222},"_2-customer-due-diligence","2. Customer due diligence",[11,225,226,227,231],{},"Know Your Customer (KYC) on individuals and ",[195,228,230],{"href":229},"\u002Fresources\u002Fmore\u002Fwhat-is-kyb","Know Your Business (KYB)"," on companies establish who the sender and receiver are before money moves. Due diligence includes identity verification, beneficial ownership, politically exposed person (PEP) checks, and risk rating, with enhanced due diligence on higher-risk relationships.",[208,233,235],{"id":234},"_3-transaction-controls","3. Transaction controls",[11,237,238],{},"Transaction controls are the checks that run on every payment: sanctions screening across all applicable lists, Travel Rule data exchange, wallet address analytics, and monitoring for patterns that indicate structuring or layering. These controls are where a compliance agent does most of its work, and they must complete before settlement, not after.",[208,240,242],{"id":241},"_4-reporting-and-recordkeeping","4. Reporting and recordkeeping",[11,244,245],{},"Each jurisdiction requires suspicious activity reports to its financial intelligence unit: FinCEN in the US, national units under AMLD in the EU, the National Crime Agency in the UK, the Suspicious Transaction Reporting Office in Singapore, and COAF in Brazil. Records of due diligence, screening results, and Travel Rule exchanges must be retained for the period each regulator sets, typically five years or more.",[28,247,249],{"id":248},"what-questions-should-you-ask-before-choosing-a-compliance-provider","What questions should you ask before choosing a compliance provider?",[11,251,252],{},"The questions below separate providers that hold compliance infrastructure from providers that hold a compliance vendor contract. Ask each one for every market you plan to serve.",[254,255,256,260,263,266,269,272,275,278],"ul",{},[257,258,259],"li",{},"Which entity holds the license or registration in each of my target markets, and can you show the public register entry?",[257,261,262],{},"How does the compliance layer determine which jurisdiction's rules apply to a given transaction, and what happens when the sender's and receiver's rules conflict?",[257,264,265],{},"Which sanctions lists are screened on every payment, how often are they refreshed, and are wallet addresses screened as well as named parties?",[257,267,268],{},"How is Travel Rule data exchanged with the counterparty VASP, and what happens when the counterparty cannot receive it?",[257,270,271],{},"When a regulator changes a threshold or a data requirement, what changes on my side?",[257,273,274],{},"Where does the compliance decision sit in the payment flow: before funds move, or as a post-settlement review?",[257,276,277],{},"What records are retained, for how long, and how do I retrieve them for an audit or regulatory request?",[257,279,280],{},"Which suspicious activity reporting obligations does the provider carry, and which remain mine?",[11,282,283],{},"A provider that answers these with references to its own registrations and rule sets is holding infrastructure. A provider that answers by naming a third-party vendor for each question is passing the integration and the regulatory risk back to you.",[28,285,287],{"id":286},"what-should-a-stablecoin-payment-company-do-next","What should a stablecoin payment company do next?",[11,289,290],{},"Cross-border stablecoin payments are regulated in every major market, and the requirements converge on the same four components: licensing, customer due diligence, transaction controls, and reporting. The details diverge by jurisdiction, which is why compliance logic belongs in a rule-set layer that selects the right requirements at runtime rather than in application code rewritten per market.",[11,292,293,294,298,299,303,304,199],{},"BlindPay provides cross-border stablecoin payment infrastructure with that compliance layer built in: jurisdiction-specific rule sets applied by transaction context, multi-list sanctions screening across OFAC, EU, UN, and UK lists, Travel Rule data exchange inside the payment flow, and regulatory updates applied at the infrastructure level. Receivers get local currency over Pix, SPEI, ACH, or SWIFT (POBO\u002FCOBO) after the checks clear. The compliance program is described on the ",[195,295,297],{"href":296},"\u002Fcompliance","compliance page",", and the team can walk through jurisdiction-specific questions via ",[195,300,302],{"href":301},"\u002Fcontact","contact"," at ",[195,305,309],{"href":306,"rel":307},"https:\u002F\u002Fblindpay.com",[308],"nofollow","blindpay.com",[11,311,312],{},[14,313,314],{},"This article is for general information only and is not legal, tax, or financial advice.",{"title":316,"searchDepth":317,"depth":317,"links":318},"",2,[319,320,321,322,323,324,331,332],{"id":30,"depth":317,"text":31},{"id":43,"depth":317,"text":44},{"id":145,"depth":317,"text":146},{"id":164,"depth":317,"text":165},{"id":180,"depth":317,"text":181},{"id":202,"depth":317,"text":203,"children":325},[326,328,329,330],{"id":210,"depth":327,"text":211},3,{"id":222,"depth":327,"text":223},{"id":234,"depth":327,"text":235},{"id":241,"depth":327,"text":242},{"id":248,"depth":317,"text":249},{"id":286,"depth":317,"text":287},"compliance","2026-09-04","How compliance agents apply FinCEN, MiCA, FCA, MAS, and Banco Central do Brasil rules to cross-border stablecoin payments: jurisdiction table, the FATF Travel Rule, multi-list sanctions screening, the four components of a compliant program, and questions to ask a compliance provider.","md",[338,341,344,347,350,353],{"q":339,"a":340},"Does the FATF Travel Rule apply to stablecoin payments?","Yes. FATF extended Recommendation 16 to virtual assets in 2019, and stablecoins are virtual assets under that standard. Any transfer between two virtual asset service providers must carry originator and beneficiary information, subject to each country's threshold.",{"q":342,"a":343},"What is the Travel Rule threshold for stablecoin transfers?","FATF recommends a threshold of USD or EUR 1,000, but countries set their own. The EU applies the rule with no minimum, the US uses USD 3,000 under the Bank Secrecy Act, Singapore uses SGD 1,500, and the UK applies it to all transfers with reduced data below EUR 1,000.",{"q":345,"a":346},"Which sanctions lists should a cross-border USDC payment be screened against?","At minimum the OFAC Specially Designated Nationals list, the EU consolidated sanctions list, the UN Security Council consolidated list, and the UK OFSI consolidated list. The set expands with each market served, and the wallet address itself should be screened, not just the named parties.",{"q":348,"a":349},"Do I need a license in every country where I send stablecoin payments?","Not if a licensed provider performs the regulated activity in that country. The provider carries registration, custody, and reporting obligations, and you remain responsible for giving it accurate customer and payment data.",{"q":351,"a":352},"What is a compliance agent in stablecoin payments?","A compliance agent is an automated component that evaluates a transaction against the rules of the jurisdictions involved and decides whether it proceeds, holds for review, or is rejected. It replaces per-country compliance code with a rule set selected at runtime.",{"q":354,"a":355},"How do regulatory updates reach a payment company using embedded compliance?","The provider updates the rule set at the infrastructure level and every customer inherits the change on the next transaction. No customer code changes, redeploys, or per-market patches are required.",false,{"author":358},"BlindPay Team",true,"\u002Fresources\u002Fmore\u002Fcompliance-agents-cross-border-stablecoin-payments","---\ntitle: \"Compliance agents for cross-border stablecoin payments: a global regulatory guide\"\ndescription: \"How compliance agents apply FinCEN, MiCA, FCA, MAS, and Banco Central do Brasil rules to cross-border stablecoin payments: jurisdiction table, the FATF Travel Rule, multi-list sanctions screening, the four components of a compliant program, and questions to ask a compliance provider.\"\ndate: \"2026-09-04\"\nupdated: \"2026-09-04\"\nauthor: \"BlindPay Team\"\ncategory: \"compliance\"\nfaq:\n  - q: \"Does the FATF Travel Rule apply to stablecoin payments?\"\n    a: \"Yes. FATF extended Recommendation 16 to virtual assets in 2019, and stablecoins are virtual assets under that standard. Any transfer between two virtual asset service providers must carry originator and beneficiary information, subject to each country's threshold.\"\n  - q: \"What is the Travel Rule threshold for stablecoin transfers?\"\n    a: \"FATF recommends a threshold of USD or EUR 1,000, but countries set their own. The EU applies the rule with no minimum, the US uses USD 3,000 under the Bank Secrecy Act, Singapore uses SGD 1,500, and the UK applies it to all transfers with reduced data below EUR 1,000.\"\n  - q: \"Which sanctions lists should a cross-border USDC payment be screened against?\"\n    a: \"At minimum the OFAC Specially Designated Nationals list, the EU consolidated sanctions list, the UN Security Council consolidated list, and the UK OFSI consolidated list. The set expands with each market served, and the wallet address itself should be screened, not just the named parties.\"\n  - q: \"Do I need a license in every country where I send stablecoin payments?\"\n    a: \"Not if a licensed provider performs the regulated activity in that country. The provider carries registration, custody, and reporting obligations, and you remain responsible for giving it accurate customer and payment data.\"\n  - q: \"What is a compliance agent in stablecoin payments?\"\n    a: \"A compliance agent is an automated component that evaluates a transaction against the rules of the jurisdictions involved and decides whether it proceeds, holds for review, or is rejected. It replaces per-country compliance code with a rule set selected at runtime.\"\n  - q: \"How do regulatory updates reach a payment company using embedded compliance?\"\n    a: \"The provider updates the rule set at the infrastructure level and every customer inherits the change on the next transaction. No customer code changes, redeploys, or per-market patches are required.\"\n---\n\n*Reading time: about 8 minutes.*\n\n**Summary:** Compliance agents handle cross-border stablecoin payment regulation by reading the context of each transaction, selecting the rule set for the jurisdictions involved, and running identity checks, sanctions screening, Travel Rule data exchange, and reporting before funds settle. The rules are maintained at the infrastructure level, so a business does not rebuild its compliance stack for every new market.\n\nCross-border stablecoin payments touch at least two regulatory regimes on every transfer: the sender's and the receiver's. Each regime has its own licensing body, sanctions authority, data-sharing threshold, and reporting obligation. This guide sets out what those regimes require and how a compliance layer can satisfy them without per-country engineering.\n\n## How do compliance agents handle cross-border stablecoin payment regulation?\n\nA compliance agent is an automated component that sits in the payment flow and evaluates each transaction against the rules that apply to it. It reads the transaction context, meaning the sender's jurisdiction, the receiver's jurisdiction, the counterparty type, the asset, and the amount, and then selects the matching rule set.\n\nThe agent then runs the checks that rule set requires: customer verification status, sanctions screening across the relevant lists, Travel Rule data exchange with the counterparty institution, and threshold-based reporting. The transaction proceeds, holds for review, or is rejected based on the result.\n\nThe alternative is writing compliance logic per market inside the payment application. That approach works for one or two corridors and breaks when the third market has a different threshold, a different data format, or a different regulator.\n\n## What are the global regulatory requirements for stablecoin transfers?\n\nEvery major market now regulates stablecoin transfers through a licensing regime for the intermediary and an anti-money laundering (AML) regime for the transaction. The licensing regime decides who may operate; the AML regime decides what each transfer must carry and when it must be reported.\n\nThe table below summarizes the primary requirement in six markets relevant to cross-border stablecoin payments.\n\n| Jurisdiction | Regulatory body | Primary requirement |\n|---|---|---|\n| United States | Financial Crimes Enforcement Network (FinCEN), with state money transmitter regulators | Money Services Business (MSB) registration under the Bank Secrecy Act (BSA), an AML program, Travel Rule compliance at USD 3,000, and strict-liability sanctions compliance under the Office of Foreign Assets Control (OFAC) |\n| European Union | National competent authorities under the Markets in Crypto-Assets Regulation (MiCA), with the Anti-Money Laundering Directives (AMLD) | Crypto-Asset Service Provider (CASP) authorization, Travel Rule under the Transfer of Funds Regulation (TFR) with no minimum threshold, and use of MiCA-compliant e-money tokens |\n| United Kingdom | Financial Conduct Authority (FCA) | Cryptoasset registration under the Money Laundering Regulations (MLRs), Travel Rule compliance in force since September 2023, and sanctions compliance under the Office of Financial Sanctions Implementation (OFSI) |\n| Singapore | Monetary Authority of Singapore (MAS) | Digital Payment Token (DPT) service license under the Payment Services Act (PSA), with AML and Travel Rule obligations under MAS Notice PSN02 at SGD 1,500 |\n| Brazil | Banco Central do Brasil (BCB) | Authorization as a Sociedade Prestadora de Serviços de Ativos Virtuais (SPSAV) under Resolutions 519, 520, and 521 of 2025, with AML reporting to the Conselho de Controle de Atividades Financeiras (COAF) |\n| Japan | Financial Services Agency (FSA) | Registration under the revised Payment Services Act, with stablecoin issuance limited to banks, trust companies, and licensed funds transfer providers |\n\nThe pattern is consistent: the activity is regulated everywhere, but the regulator, the threshold, and the data format differ. A compliance program that hardcodes one market's assumptions will fail an examination in another.\n\n## What does the FATF Travel Rule require for stablecoin payments?\n\nThe Financial Action Task Force (FATF) is the intergovernmental body that sets global AML standards. Its Recommendation 16, known as the Travel Rule, requires that originator and beneficiary information accompany a funds transfer so that each institution in the chain can screen the parties and respond to law enforcement requests.\n\nIn June 2019, FATF extended the Travel Rule to virtual assets and Virtual Asset Service Providers (VASPs) through an interpretive note to Recommendation 15. Stablecoins are virtual assets under that standard, so a USDC transfer between two VASPs carries the same data obligation as a wire transfer between two banks.\n\nThe required data set is the originator's name, account or wallet identifier, and one of address, national identity number, or date and place of birth, plus the beneficiary's name and account or wallet identifier. FATF recommends a USD or EUR 1,000 threshold, but each country sets its own.\n\nThresholds and formats diverge by market. The EU's Transfer of Funds Regulation applies with no minimum since December 30, 2024. The US applies the Bank Secrecy Act Travel Rule at USD 3,000. Singapore's threshold is SGD 1,500. The UK applies the rule to all transfers, with a reduced data set below EUR 1,000.\n\nThe Travel Rule matters for stablecoins specifically because a blockchain transfer carries no identity data by default. The information must move through a separate channel between the two VASPs, matched to the on-chain transaction, and the compliance layer has to do that matching before the payment is treated as complete.\n\n## How does sanctions screening work for cross-border USDC payments?\n\nSanctions screening checks every party to a payment against the lists maintained by the sanctioning authorities in the jurisdictions involved. For a cross-border USDC payment, that means screening the sender, the receiver, any beneficial owners, and the wallet addresses on both sides.\n\nThe core lists are the OFAC Specially Designated Nationals (SDN) and consolidated lists in the US, the EU consolidated sanctions list, the United Nations (UN) Security Council consolidated list, and the UK OFSI consolidated list. A payment from a US entity to a Brazilian receiver over EU rails must clear all of them, not just the sender's.\n\nOFAC compliance is strict liability. A payment that reaches a sanctioned party is a violation regardless of intent, which is why screening runs before funds move and again when lists update, not only at onboarding.\n\nWallet address screening is the piece that has no analog in bank payments. OFAC has added blockchain addresses to the SDN list since 2018, and a compliance layer must screen the destination address against those entries and against analytics that flag exposure to sanctioned or illicit sources.\n\n## How do you comply with regulations across multiple jurisdictions without rebuilding per market?\n\nMulti-jurisdictional compliance for crypto payments comes down to one architectural decision: whether jurisdiction-specific rules live in the payment application or in a compliance layer beneath it. The first approach means one codebase change per market per regulatory update. The second means the rules are data, selected at runtime by transaction context.\n\nIn a rule-set model, each jurisdiction has a definition of its licensing scope, Travel Rule threshold and data format, sanctions lists, reporting triggers, and receiver verification requirements. The agent loads the definitions for the sender's and receiver's jurisdictions and applies the stricter requirement wherever they conflict.\n\nRegulatory updates then land in the rule set, not in customer code. When a threshold changes or a list is amended, the provider updates the definition once and every payment evaluated after that point uses it.\n\nThis is how BlindPay's compliance layer is built. Rule sets are maintained for the regimes described in this guide, including FinCEN, MiCA and AMLD, FCA, MAS, and BCB requirements, and customers inherit updates without code changes. Entity and license details by market are published on the [licenses page](\u002Flicenses).\n\n## What are the 4 structural components of a compliant stablecoin payment program?\n\nA compliant stablecoin payment program has four structural components. Regulators in every major market examine all four, and a gap in any one is a finding.\n\n### 1. Licensing and registration\n\nThe entity performing the regulated activity must hold the authorization the jurisdiction requires: MSB registration and state licenses in the US, CASP authorization in the EU, FCA registration in the UK, a DPT license in Singapore, SPSAV authorization in Brazil. A business that builds on a licensed provider does not need these itself, but it must confirm the provider holds them for each market it serves. Our [VASP explainer](\u002Fresources\u002Fmore\u002Fwhat-is-a-vasp) covers who falls inside the licensing perimeter.\n\n### 2. Customer due diligence\n\nKnow Your Customer (KYC) on individuals and [Know Your Business (KYB)](\u002Fresources\u002Fmore\u002Fwhat-is-kyb) on companies establish who the sender and receiver are before money moves. Due diligence includes identity verification, beneficial ownership, politically exposed person (PEP) checks, and risk rating, with enhanced due diligence on higher-risk relationships.\n\n### 3. Transaction controls\n\nTransaction controls are the checks that run on every payment: sanctions screening across all applicable lists, Travel Rule data exchange, wallet address analytics, and monitoring for patterns that indicate structuring or layering. These controls are where a compliance agent does most of its work, and they must complete before settlement, not after.\n\n### 4. Reporting and recordkeeping\n\nEach jurisdiction requires suspicious activity reports to its financial intelligence unit: FinCEN in the US, national units under AMLD in the EU, the National Crime Agency in the UK, the Suspicious Transaction Reporting Office in Singapore, and COAF in Brazil. Records of due diligence, screening results, and Travel Rule exchanges must be retained for the period each regulator sets, typically five years or more.\n\n## What questions should you ask before choosing a compliance provider?\n\nThe questions below separate providers that hold compliance infrastructure from providers that hold a compliance vendor contract. Ask each one for every market you plan to serve.\n\n- Which entity holds the license or registration in each of my target markets, and can you show the public register entry?\n- How does the compliance layer determine which jurisdiction's rules apply to a given transaction, and what happens when the sender's and receiver's rules conflict?\n- Which sanctions lists are screened on every payment, how often are they refreshed, and are wallet addresses screened as well as named parties?\n- How is Travel Rule data exchanged with the counterparty VASP, and what happens when the counterparty cannot receive it?\n- When a regulator changes a threshold or a data requirement, what changes on my side?\n- Where does the compliance decision sit in the payment flow: before funds move, or as a post-settlement review?\n- What records are retained, for how long, and how do I retrieve them for an audit or regulatory request?\n- Which suspicious activity reporting obligations does the provider carry, and which remain mine?\n\nA provider that answers these with references to its own registrations and rule sets is holding infrastructure. A provider that answers by naming a third-party vendor for each question is passing the integration and the regulatory risk back to you.\n\n## What should a stablecoin payment company do next?\n\nCross-border stablecoin payments are regulated in every major market, and the requirements converge on the same four components: licensing, customer due diligence, transaction controls, and reporting. The details diverge by jurisdiction, which is why compliance logic belongs in a rule-set layer that selects the right requirements at runtime rather than in application code rewritten per market.\n\nBlindPay provides cross-border stablecoin payment infrastructure with that compliance layer built in: jurisdiction-specific rule sets applied by transaction context, multi-list sanctions screening across OFAC, EU, UN, and UK lists, Travel Rule data exchange inside the payment flow, and regulatory updates applied at the infrastructure level. Receivers get local currency over Pix, SPEI, ACH, or SWIFT (POBO\u002FCOBO) after the checks clear. The compliance program is described on the [compliance page](\u002Fcompliance), and the team can walk through jurisdiction-specific questions via [contact](\u002Fcontact) at [blindpay.com](https:\u002F\u002Fblindpay.com).\n\n*This article is for general information only and is not legal, tax, or financial advice.*\n",{"title":5,"description":335},"resources\u002Fmore\u002Fcompliance-agents-cross-border-stablecoin-payments","sSoE3sSya39NKLgqksngvzvdlo9SdAkb_LZ1Tnuk0bI",[366,552,766,1198,1484,1713,2044,2459,2597],{"id":367,"title":368,"authors":6,"body":369,"categories":6,"category":333,"categoryType":6,"compare":6,"contributors":6,"date":525,"description":526,"extension":336,"faq":527,"howto":6,"isBlog":356,"isChangelog":356,"meta":546,"navigation":359,"path":547,"pillar":356,"products":6,"rawbody":548,"seo":549,"stem":550,"thumbnail":6,"updated":6,"__hash__":551},"content\u002Fresources\u002Fmore\u002Fare-stablecoin-payments-reversible.md","Are stablecoin payments reversible? Finality, custody, and fraud explained",{"type":8,"value":370,"toc":517},[371,374,378,381,389,392,396,399,402,406,409,412,416,419,427,431,458,490,494,497],[11,372,373],{},"Most stablecoin explainers treat irreversibility as a warning: once a transfer settles, nobody can undo it. That framing misses the more useful half of the story. A stablecoin transfer being final is exactly what lets anyone trace who held custody of the funds at every step. The real weak point sits elsewhere: the ordinary bank transfer that funds the stablecoin leg, because that side of the payment stays reversible for days after the stablecoin side has already closed.",[28,375,377],{"id":376},"how-custody-actually-gets-proven","How custody actually gets proven",[11,379,380],{},"A stablecoin payment moves value through a set sequence: a bank account, a pooled account held for the benefit of customers, a conversion between fiat and stablecoin, an operational wallet, then the counterparty's wallet. At each step, one party and only one party legally holds the funds, and that fact locks in the moment the transfer settles.",[11,382,383,384,388],{},"Compare that to a wire routed through correspondent banks. Each intermediary bank confirms its leg only after the money has already moved, using SWIFT messaging customers never see. Reconstructing who held the money, and when, means asking each bank in the chain and waiting for an answer, sometimes over days. See our ",[195,385,387],{"href":386},"\u002Fresources\u002Fmore\u002Fwhat-is-a-stablecoin-api","stablecoin API primer"," for how this custody chain fits into a broader payment integration.",[11,390,391],{},"Whether a wallet is custodial or non-custodial gets treated as a minor implementation detail in most explainers, but it decides who is legally on the hook. A custodial wallet means the platform holds the private keys and carries legal responsibility for the asset. A non-custodial wallet means that responsibility ends the instant the stablecoin lands somewhere the counterparty controls.",[28,393,395],{"id":394},"what-finality-is-actually-worth","What finality is actually worth",[11,397,398],{},"With a reversible instrument, \"who held this money and when\" stays open to dispute after the fact, which is why reconciling a correspondent-banking wire is slow: two institutions comparing notes on a settlement that took days, based on messages sent back and forth.",[11,400,401],{},"An irreversible instrument closes that question the moment it settles: named custody, timestamped, no argument later. That is the real payoff of finality, and it barely gets mentioned across the wave of near-identical stablecoin explainers published through 2026.",[28,403,405],{"id":404},"where-the-exposure-really-sits","Where the exposure really sits",[11,407,408],{},"Stablecoin settlement closes in minutes. The fiat transfer that funds or receives it, an ACH payment or a wire, stays open to reversal for days afterward.",[11,410,411],{},"That gap is what a fraudster exploits: fund the fiat leg, receive stablecoins for it, then reverse the original ACH or wire while the return window is still open. The stablecoins have already moved on by then, and whoever processed the payment eats the loss. The fiat rail's dispute window simply outlasts the stablecoin rail's finality window. Fast finality on the stablecoin side isn't what creates the exposure; a fiat leg that stays reversible after the stablecoin leg has closed is.",[28,413,415],{"id":414},"why-identity-checks-alone-dont-catch-it","Why identity checks alone don't catch it",[11,417,418],{},"This scheme only exists because two settlement systems with different finality timelines sit next to each other, which is why it tends to get discovered by whoever ends up eating the loss rather than by a compliance checklist.",[11,420,421,422,426],{},"Know-your-customer checks at signup answer who a customer is, once. They don't answer whether a given transaction is timed to exploit a mismatch between two rails' settlement windows. Catching that takes continuous monitoring on the incoming fiat leg: velocity checks, funding-source risk scoring, and holds sized to the real reversal window of the rail in play, not a single gate that only fires at account opening. Our ",[195,423,425],{"href":424},"\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026","stablecoin regulation tracker"," covers where AML and sanctions rulemaking currently stands.",[28,428,430],{"id":429},"regulation-is-still-catching-up-and-volume-already-outpaces-it","Regulation is still catching up, and volume already outpaces it",[11,432,433,434,439,440,445,446,451,452,457],{},"Congress signed the GENIUS Act on July 18, 2025, but regulators ",[195,435,438],{"href":436,"rel":437},"https:\u002F\u002Fhome.treasury.gov\u002Fnews\u002Fpress-releases\u002Fsb0605",[308],"missed their own July 18, 2026 deadline"," to finalize implementing rules, so the effective date stays January 18, 2027. Treasury's proposed rule on who qualifies as a permitted issuer only ",[195,441,444],{"href":442,"rel":443},"https:\u002F\u002Fwww.federalregister.gov\u002Fdocuments\u002F2026\u002F08\u002F18\u002F2026-16796\u002Fgenius-act-regulations-on-payment-stablecoin-issuance-offer-and-sale",[308],"appeared August 18, 2026",", with comments open until October 19. The ",[195,447,450],{"href":448,"rel":449},"https:\u002F\u002Fwww.federalregister.gov\u002Fdocuments\u002F2026\u002F04\u002F10\u002F2026-06963\u002F",[308],"OCC's BSA\u002FAML and sanctions proposal"," closed for comment June 9, and the ",[195,453,456],{"href":454,"rel":455},"https:\u002F\u002Fwww.federalregister.gov\u002Fdocuments\u002F2026\u002F06\u002F05\u002F2026-11342\u002F",[308],"FDIC's parallel version"," closed August 4. More than a year after signing, no business holds a completed federal stablecoin issuer license.",[11,459,460,461,466,467,472,473,478,479,484,485,489],{},"The volume moving through this exact structure keeps growing regardless. McKinsey and Artemis put annualized B2B stablecoin flow at ",[195,462,465],{"href":463,"rel":464},"https:\u002F\u002Fwww.mckinsey.com\u002Ffeatured-insights\u002Fweek-in-charts\u002Fstablecoins-find-their-niche",[308],"$226 billion in 2025, a 733% jump year over year",". Mastercard ",[195,468,471],{"href":469,"rel":470},"https:\u002F\u002Fwww.mastercard.com\u002Fus\u002Fen\u002Fnews-and-trends\u002Fpress\u002F2026\u002Faugust\u002Fmastercard-completes-acquisition-of-bvnk-to-advance-global-stabl.html",[308],"finished acquiring BVNK for up to $1.8 billion on August 3, 2026",", CoinDesk reports ",[195,474,477],{"href":475,"rel":476},"https:\u002F\u002Fwww.coindesk.com\u002Fbusiness\u002F2026\u002F08\u002F18\u002Fvisa-is-looking-for-a-new-stablecoin-settlement-partner-now-that-bvnk-is-owned-by-mastercard",[308],"Visa is now shopping for a new stablecoin settlement partner",", and Western Union rolled out ",[195,480,483],{"href":481,"rel":482},"https:\u002F\u002Fwww.theblock.co\u002Fpost\u002F399890\u002Fwestern-union-launches-usdpt-stablecoin-anchorage-solana",[308],"USDPT on Solana"," back in May. Larger sums keep crossing rails with mismatched finality while the compliance framework everyone assumes is settled sits in open rulemaking dockets. Our ",[195,486,488],{"href":487},"\u002Fresources\u002Fmore\u002Fstablecoin-payments-guide","stablecoin payments guide"," covers how these flows work end to end.",[28,491,493],{"id":492},"what-to-ask-before-trusting-a-provider","What to ask before trusting a provider",[11,495,496],{},"Whether it can name the custodian at every hop, from the originating bank account to the counterparty's wallet, with a timestamped record for each one. Without that, \"compliant by design\" is marketing copy, not a working control. Whether the fiat leg gets monitored continuously or only checked once at onboarding. And whether the backup provider clears payouts on the same approval and settlement timeline as the primary, since a backup that technically works but settles slower just delays the same exposure.",[11,498,499,500,505,506,511,512,199],{},"See how this custody chain works in practice in ",[195,501,504],{"href":502,"rel":503},"https:\u002F\u002Fwww.blindpay.com\u002Fdocs\u002Fgetting-started\u002Foverview",[308],"BlindPay's flow of funds documentation",", or look at a live corridor like ",[195,507,510],{"href":508,"rel":509},"https:\u002F\u002Fwww.blindpay.com\u002Fusdc-to-brl",[308],"USDC to BRL",". If a current provider cannot answer the three questions above, ",[195,513,516],{"href":514,"rel":515},"https:\u002F\u002Fwww.blindpay.com\u002Fcontact",[308],"talk to BlindPay",{"title":316,"searchDepth":317,"depth":317,"links":518},[519,520,521,522,523,524],{"id":376,"depth":317,"text":377},{"id":394,"depth":317,"text":395},{"id":404,"depth":317,"text":405},{"id":414,"depth":317,"text":415},{"id":429,"depth":317,"text":430},{"id":492,"depth":317,"text":493},"2026-09-01","Stablecoin transfers settle final in minutes and cannot be reversed. That finality proves custody at every step, but it also opens a fraud gap on the fiat side of the payment.",[528,531,534,537,540,543],{"q":529,"a":530},"Can a stablecoin payment be reversed once it settles?","No. Once a stablecoin transfer confirms on-chain, it is final. There is no chargeback or recall mechanism the way there is with a card payment or a wire. That finality is usually framed as the downside of stablecoins, but it is also what lets a provider prove, hop by hop, who legally held the funds at every point in the transfer.",{"q":532,"a":533},"Does irreversibility create a fraud risk in stablecoin payments?","The risk is not the stablecoin leg. It is the fiat leg sitting next to it. A payment typically pairs a stablecoin transfer, final in minutes, with an ACH or wire transfer, which stays open to reversal for days. A bad actor can exploit that gap: fund the fiat side, receive stablecoins, then claw back the original fiat payment after the stablecoins have already moved on.",{"q":535,"a":536},"How does the fiat-leg reversal scheme actually work?","Someone sends a fiat deposit by ACH or wire and receives stablecoins in return. Days later, they trigger a standard ACH return or wire recall on that original deposit, well within the normal window banks allow for reversals. By then the stablecoins are long gone, and the provider is left holding the loss. It is not a hack or a stolen-wallet scam. It is two settlement rails with mismatched finality windows being played against each other.",{"q":538,"a":539},"What controls actually catch fiat-leg reversal fraud?","Onboarding KYC tells a provider who a customer is, once, at signup. It does not tell them whether a given transaction is timed to exploit the gap between fiat and stablecoin finality. Stopping this requires ongoing monitoring on the incoming fiat leg: velocity limits, funding-source risk scoring, and holds sized to the actual reversal window of whichever fiat rail is in play, not a one-time check done at account opening.",{"q":541,"a":542},"Has the GENIUS Act finalized US stablecoin regulation?","Not yet, as of September 2026. The law was signed in July 2025 with a January 18, 2027 effective date, but regulators missed their own July 2026 deadline to finish implementing rules. Treasury's proposal for who qualifies as a permitted issuer only came out August 18, 2026, with comments open into October. OCC and FDIC each have parallel proposals on BSA\u002FAML and sanctions compliance still pending. No federal stablecoin issuer license has been finalized more than a year after signing.",{"q":544,"a":545},"What should a business ask a stablecoin payment provider about reversibility and fraud?","Three things. First, can they trace custody at every hop from bank account to counterparty wallet, with timestamps, not just a summary. Second, do they monitor the fiat-in leg continuously, or only check identity once at signup. Third, does their backup provider clear payouts on the same schedule as the primary, since a slower backup just delays the same exposure rather than closing it.",{},"\u002Fresources\u002Fmore\u002Fare-stablecoin-payments-reversible","---\ntitle: \"Are stablecoin payments reversible? Finality, custody, and fraud explained\"\ndescription: \"Stablecoin transfers settle final in minutes and cannot be reversed. That finality proves custody at every step, but it also opens a fraud gap on the fiat side of the payment.\"\ndate: \"2026-09-01\"\ncategory: \"compliance\"\nfaq:\n  - q: \"Can a stablecoin payment be reversed once it settles?\"\n    a: \"No. Once a stablecoin transfer confirms on-chain, it is final. There is no chargeback or recall mechanism the way there is with a card payment or a wire. That finality is usually framed as the downside of stablecoins, but it is also what lets a provider prove, hop by hop, who legally held the funds at every point in the transfer.\"\n  - q: \"Does irreversibility create a fraud risk in stablecoin payments?\"\n    a: \"The risk is not the stablecoin leg. It is the fiat leg sitting next to it. A payment typically pairs a stablecoin transfer, final in minutes, with an ACH or wire transfer, which stays open to reversal for days. A bad actor can exploit that gap: fund the fiat side, receive stablecoins, then claw back the original fiat payment after the stablecoins have already moved on.\"\n  - q: \"How does the fiat-leg reversal scheme actually work?\"\n    a: \"Someone sends a fiat deposit by ACH or wire and receives stablecoins in return. Days later, they trigger a standard ACH return or wire recall on that original deposit, well within the normal window banks allow for reversals. By then the stablecoins are long gone, and the provider is left holding the loss. It is not a hack or a stolen-wallet scam. It is two settlement rails with mismatched finality windows being played against each other.\"\n  - q: \"What controls actually catch fiat-leg reversal fraud?\"\n    a: \"Onboarding KYC tells a provider who a customer is, once, at signup. It does not tell them whether a given transaction is timed to exploit the gap between fiat and stablecoin finality. Stopping this requires ongoing monitoring on the incoming fiat leg: velocity limits, funding-source risk scoring, and holds sized to the actual reversal window of whichever fiat rail is in play, not a one-time check done at account opening.\"\n  - q: \"Has the GENIUS Act finalized US stablecoin regulation?\"\n    a: \"Not yet, as of September 2026. The law was signed in July 2025 with a January 18, 2027 effective date, but regulators missed their own July 2026 deadline to finish implementing rules. Treasury's proposal for who qualifies as a permitted issuer only came out August 18, 2026, with comments open into October. OCC and FDIC each have parallel proposals on BSA\u002FAML and sanctions compliance still pending. No federal stablecoin issuer license has been finalized more than a year after signing.\"\n  - q: \"What should a business ask a stablecoin payment provider about reversibility and fraud?\"\n    a: \"Three things. First, can they trace custody at every hop from bank account to counterparty wallet, with timestamps, not just a summary. Second, do they monitor the fiat-in leg continuously, or only check identity once at signup. Third, does their backup provider clear payouts on the same schedule as the primary, since a slower backup just delays the same exposure rather than closing it.\"\n---\n\nMost stablecoin explainers treat irreversibility as a warning: once a transfer settles, nobody can undo it. That framing misses the more useful half of the story. A stablecoin transfer being final is exactly what lets anyone trace who held custody of the funds at every step. The real weak point sits elsewhere: the ordinary bank transfer that funds the stablecoin leg, because that side of the payment stays reversible for days after the stablecoin side has already closed.\n\n## How custody actually gets proven\n\nA stablecoin payment moves value through a set sequence: a bank account, a pooled account held for the benefit of customers, a conversion between fiat and stablecoin, an operational wallet, then the counterparty's wallet. At each step, one party and only one party legally holds the funds, and that fact locks in the moment the transfer settles.\n\nCompare that to a wire routed through correspondent banks. Each intermediary bank confirms its leg only after the money has already moved, using SWIFT messaging customers never see. Reconstructing who held the money, and when, means asking each bank in the chain and waiting for an answer, sometimes over days. See our [stablecoin API primer](\u002Fresources\u002Fmore\u002Fwhat-is-a-stablecoin-api) for how this custody chain fits into a broader payment integration.\n\nWhether a wallet is custodial or non-custodial gets treated as a minor implementation detail in most explainers, but it decides who is legally on the hook. A custodial wallet means the platform holds the private keys and carries legal responsibility for the asset. A non-custodial wallet means that responsibility ends the instant the stablecoin lands somewhere the counterparty controls.\n\n## What finality is actually worth\n\nWith a reversible instrument, \"who held this money and when\" stays open to dispute after the fact, which is why reconciling a correspondent-banking wire is slow: two institutions comparing notes on a settlement that took days, based on messages sent back and forth.\n\nAn irreversible instrument closes that question the moment it settles: named custody, timestamped, no argument later. That is the real payoff of finality, and it barely gets mentioned across the wave of near-identical stablecoin explainers published through 2026.\n\n## Where the exposure really sits\n\nStablecoin settlement closes in minutes. The fiat transfer that funds or receives it, an ACH payment or a wire, stays open to reversal for days afterward.\n\nThat gap is what a fraudster exploits: fund the fiat leg, receive stablecoins for it, then reverse the original ACH or wire while the return window is still open. The stablecoins have already moved on by then, and whoever processed the payment eats the loss. The fiat rail's dispute window simply outlasts the stablecoin rail's finality window. Fast finality on the stablecoin side isn't what creates the exposure; a fiat leg that stays reversible after the stablecoin leg has closed is.\n\n## Why identity checks alone don't catch it\n\nThis scheme only exists because two settlement systems with different finality timelines sit next to each other, which is why it tends to get discovered by whoever ends up eating the loss rather than by a compliance checklist.\n\nKnow-your-customer checks at signup answer who a customer is, once. They don't answer whether a given transaction is timed to exploit a mismatch between two rails' settlement windows. Catching that takes continuous monitoring on the incoming fiat leg: velocity checks, funding-source risk scoring, and holds sized to the real reversal window of the rail in play, not a single gate that only fires at account opening. Our [stablecoin regulation tracker](\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026) covers where AML and sanctions rulemaking currently stands.\n\n## Regulation is still catching up, and volume already outpaces it\n\nCongress signed the GENIUS Act on July 18, 2025, but regulators [missed their own July 18, 2026 deadline](https:\u002F\u002Fhome.treasury.gov\u002Fnews\u002Fpress-releases\u002Fsb0605) to finalize implementing rules, so the effective date stays January 18, 2027. Treasury's proposed rule on who qualifies as a permitted issuer only [appeared August 18, 2026](https:\u002F\u002Fwww.federalregister.gov\u002Fdocuments\u002F2026\u002F08\u002F18\u002F2026-16796\u002Fgenius-act-regulations-on-payment-stablecoin-issuance-offer-and-sale), with comments open until October 19. The [OCC's BSA\u002FAML and sanctions proposal](https:\u002F\u002Fwww.federalregister.gov\u002Fdocuments\u002F2026\u002F04\u002F10\u002F2026-06963\u002F) closed for comment June 9, and the [FDIC's parallel version](https:\u002F\u002Fwww.federalregister.gov\u002Fdocuments\u002F2026\u002F06\u002F05\u002F2026-11342\u002F) closed August 4. More than a year after signing, no business holds a completed federal stablecoin issuer license.\n\nThe volume moving through this exact structure keeps growing regardless. McKinsey and Artemis put annualized B2B stablecoin flow at [$226 billion in 2025, a 733% jump year over year](https:\u002F\u002Fwww.mckinsey.com\u002Ffeatured-insights\u002Fweek-in-charts\u002Fstablecoins-find-their-niche). Mastercard [finished acquiring BVNK for up to $1.8 billion on August 3, 2026](https:\u002F\u002Fwww.mastercard.com\u002Fus\u002Fen\u002Fnews-and-trends\u002Fpress\u002F2026\u002Faugust\u002Fmastercard-completes-acquisition-of-bvnk-to-advance-global-stabl.html), CoinDesk reports [Visa is now shopping for a new stablecoin settlement partner](https:\u002F\u002Fwww.coindesk.com\u002Fbusiness\u002F2026\u002F08\u002F18\u002Fvisa-is-looking-for-a-new-stablecoin-settlement-partner-now-that-bvnk-is-owned-by-mastercard), and Western Union rolled out [USDPT on Solana](https:\u002F\u002Fwww.theblock.co\u002Fpost\u002F399890\u002Fwestern-union-launches-usdpt-stablecoin-anchorage-solana) back in May. Larger sums keep crossing rails with mismatched finality while the compliance framework everyone assumes is settled sits in open rulemaking dockets. Our [stablecoin payments guide](\u002Fresources\u002Fmore\u002Fstablecoin-payments-guide) covers how these flows work end to end.\n\n## What to ask before trusting a provider\n\nWhether it can name the custodian at every hop, from the originating bank account to the counterparty's wallet, with a timestamped record for each one. Without that, \"compliant by design\" is marketing copy, not a working control. Whether the fiat leg gets monitored continuously or only checked once at onboarding. And whether the backup provider clears payouts on the same approval and settlement timeline as the primary, since a backup that technically works but settles slower just delays the same exposure.\n\nSee how this custody chain works in practice in [BlindPay's flow of funds documentation](https:\u002F\u002Fwww.blindpay.com\u002Fdocs\u002Fgetting-started\u002Foverview), or look at a live corridor like [USDC to BRL](https:\u002F\u002Fwww.blindpay.com\u002Fusdc-to-brl). If a current provider cannot answer the three questions above, [talk to BlindPay](https:\u002F\u002Fwww.blindpay.com\u002Fcontact).\n",{"title":368,"description":526},"resources\u002Fmore\u002Fare-stablecoin-payments-reversible","9WLDMe6P6lUyaYSjeLRYXEo2chBmGSKDXUdTLGc1uVI",{"id":4,"title":5,"authors":6,"body":553,"categories":6,"category":333,"categoryType":6,"compare":6,"contributors":6,"date":334,"description":335,"extension":336,"faq":757,"howto":6,"isBlog":356,"isChangelog":356,"meta":764,"navigation":359,"path":360,"pillar":356,"products":6,"rawbody":361,"seo":765,"stem":363,"thumbnail":6,"updated":334,"__hash__":364},{"type":8,"value":554,"toc":742},[555,559,563,565,567,569,571,573,575,577,579,641,643,645,647,649,651,653,655,657,659,661,663,665,667,669,671,673,677,679,681,683,687,689,693,695,697,699,701,703,705,723,725,727,729,738],[11,556,557],{},[14,558,16],{},[11,560,561,23],{},[20,562,22],{},[11,564,26],{},[28,566,31],{"id":30},[11,568,34],{},[11,570,37],{},[11,572,40],{},[28,574,44],{"id":43},[11,576,47],{},[11,578,50],{},[52,580,581,591],{},[55,582,583],{},[58,584,585,587,589],{},[61,586,63],{},[61,588,66],{},[61,590,69],{},[71,592,593,601,609,617,625,633],{},[58,594,595,597,599],{},[76,596,78],{},[76,598,81],{},[76,600,84],{},[58,602,603,605,607],{},[76,604,89],{},[76,606,92],{},[76,608,95],{},[58,610,611,613,615],{},[76,612,100],{},[76,614,103],{},[76,616,106],{},[58,618,619,621,623],{},[76,620,111],{},[76,622,114],{},[76,624,117],{},[58,626,627,629,631],{},[76,628,122],{},[76,630,125],{},[76,632,128],{},[58,634,635,637,639],{},[76,636,133],{},[76,638,136],{},[76,640,139],{},[11,642,142],{},[28,644,146],{"id":145},[11,646,149],{},[11,648,152],{},[11,650,155],{},[11,652,158],{},[11,654,161],{},[28,656,165],{"id":164},[11,658,168],{},[11,660,171],{},[11,662,174],{},[11,664,177],{},[28,666,181],{"id":180},[11,668,184],{},[11,670,187],{},[11,672,190],{},[11,674,193,675,199],{},[195,676,198],{"href":197},[28,678,203],{"id":202},[11,680,206],{},[208,682,211],{"id":210},[11,684,214,685,219],{},[195,686,218],{"href":217},[208,688,223],{"id":222},[11,690,226,691,231],{},[195,692,230],{"href":229},[208,694,235],{"id":234},[11,696,238],{},[208,698,242],{"id":241},[11,700,245],{},[28,702,249],{"id":248},[11,704,252],{},[254,706,707,709,711,713,715,717,719,721],{},[257,708,259],{},[257,710,262],{},[257,712,265],{},[257,714,268],{},[257,716,271],{},[257,718,274],{},[257,720,277],{},[257,722,280],{},[11,724,283],{},[28,726,287],{"id":286},[11,728,290],{},[11,730,293,731,298,733,303,735,199],{},[195,732,297],{"href":296},[195,734,302],{"href":301},[195,736,309],{"href":306,"rel":737},[308],[11,739,740],{},[14,741,314],{},{"title":316,"searchDepth":317,"depth":317,"links":743},[744,745,746,747,748,749,755,756],{"id":30,"depth":317,"text":31},{"id":43,"depth":317,"text":44},{"id":145,"depth":317,"text":146},{"id":164,"depth":317,"text":165},{"id":180,"depth":317,"text":181},{"id":202,"depth":317,"text":203,"children":750},[751,752,753,754],{"id":210,"depth":327,"text":211},{"id":222,"depth":327,"text":223},{"id":234,"depth":327,"text":235},{"id":241,"depth":327,"text":242},{"id":248,"depth":317,"text":249},{"id":286,"depth":317,"text":287},[758,759,760,761,762,763],{"q":339,"a":340},{"q":342,"a":343},{"q":345,"a":346},{"q":348,"a":349},{"q":351,"a":352},{"q":354,"a":355},{"author":358},{"title":5,"description":335},{"id":767,"title":768,"authors":6,"body":769,"categories":6,"category":333,"categoryType":6,"compare":6,"contributors":6,"date":1177,"description":1178,"extension":336,"faq":1179,"howto":6,"isBlog":356,"isChangelog":356,"meta":1192,"navigation":359,"path":1193,"pillar":356,"products":6,"rawbody":1194,"seo":1195,"stem":1196,"thumbnail":6,"updated":1177,"__hash__":1197},"content\u002Fresources\u002Fmore\u002Fhow-to-automate-kyc-kyb-stablecoin-payments.md","How to automate KYC and KYB for stablecoin payments",{"type":8,"value":770,"toc":1165},[771,775,780,783,787,790,793,800,804,807,852,855,859,862,906,909,913,916,948,956,960,963,1028,1040,1044,1047,1050,1053,1057,1060,1063,1067,1070,1101,1105,1111,1117,1123,1129,1135,1141,1145,1148,1161],[11,772,773],{},[14,774,16],{},[11,776,777,779],{},[20,778,22],{}," You automate KYC and KYB for stablecoin payments by making verification a step in the payment API itself. Create a receiver with identity or entity data, let automated KYC run document checks, sanctions screening, and risk scoring, receive the result by webhook, and only allow payouts once the receiver status is approved.",[11,781,782],{},"KYC automation matters for stablecoin companies because a payout on a public blockchain cannot be reversed. Every check has to finish before funds move, and manual review does not scale past a few hundred receivers.",[28,784,786],{"id":785},"what-is-the-difference-between-kyc-and-kyb-for-stablecoin-payments","What is the difference between KYC and KYB for stablecoin payments?",[11,788,789],{},"KYC, Know Your Customer, verifies an individual person. It confirms that a government ID is authentic, that the person presenting it is real and present, and that they are not on a sanctions or watch list.",[11,791,792],{},"KYB, Know Your Business, verifies a business entity. It confirms the company is registered and active, maps who owns and controls it, and then runs KYC on each of those individuals.",[11,794,795,796,799],{},"The split maps onto who you pay. Contractors and remittance recipients need KYC. Vendors, marketplaces, and corporate customers need KYB, which always includes KYC on their owners. The ",[195,797,798],{"href":229},"KYB explainer"," covers beneficial ownership rules in detail.",[28,801,803],{"id":802},"how-does-automated-kyc-work-for-stablecoin-users","How does automated KYC work for stablecoin users?",[11,805,806],{},"Automated KYC replaces an analyst reviewing a PDF with a pipeline of machine checks that return a decision and an audit trail.",[808,809,810,816,822,828,834,840,846],"ol",{},[257,811,812,815],{},[20,813,814],{},"Data collection."," Your app collects name, date of birth, address, tax ID, and ID document images, then sends them in one API request that creates the receiver.",[257,817,818,821],{},[20,819,820],{},"Document verification."," The system extracts fields from the document, checks security features and expiry, and compares the extracted data against what the user typed.",[257,823,824,827],{},[20,825,826],{},"Liveness and face match."," A selfie or short video is checked for presentation attacks, then matched against the document photo.",[257,829,830,833],{},[20,831,832],{},"Sanctions and PEP screening."," The name, date of birth, and country are screened against OFAC, EU, UK, UN, and local lists, plus politically exposed person databases.",[257,835,836,839],{},[20,837,838],{},"Risk scoring."," Country, document type, IP geolocation, and screening results combine into a risk tier that decides between auto-approval and manual review.",[257,841,842,845],{},[20,843,844],{},"Decision and webhook."," The receiver status becomes approved, rejected, or verifying, and your backend receives a webhook so it can unlock or block payouts.",[257,847,848,851],{},[20,849,850],{},"Audit logging."," Every input, check result, and decision is stored with timestamps so a regulator or bank partner can reconstruct the case.",[11,853,854],{},"A clean case clears all seven stages in under a minute. A name mismatch or screening hit stops at stage five for a human decision.",[28,856,858],{"id":857},"how-does-kyb-automation-work-for-business-receivers","How does KYB automation work for business receivers?",[11,860,861],{},"KYB automation follows the same shape but adds an entity layer before the individual checks. Ownership tracing is the hard part, because it has to end at real people.",[808,863,864,870,876,882,888,894,900],{},[257,865,866,869],{},[20,867,868],{},"Entity data collection."," Collect legal name, registration number, tax ID, incorporation date, registered address, business type, and industry, plus the incorporation document.",[257,871,872,875],{},[20,873,874],{},"Registry verification."," The registration number is checked against the jurisdiction's corporate registry to confirm the entity exists, is active, and matches the stated name and address.",[257,877,878,881],{},[20,879,880],{},"Ownership mapping."," The ownership structure is unwound through holding companies until every individual with 25 percent or more, or with control, is identified.",[257,883,884,887],{},[20,885,886],{},"Beneficial owner KYC."," Each identified owner and controller goes through the full individual KYC flow described above.",[257,889,890,893],{},[20,891,892],{},"Entity screening."," The company name and its owners are screened against sanctions lists, adverse media, and industry restrictions.",[257,895,896,899],{},[20,897,898],{},"Risk scoring and decision."," Entity type, industry, jurisdiction, and owner results combine into a tier. High-risk industries or complex ownership route to enhanced due diligence.",[257,901,902,905],{},[20,903,904],{},"Decision and monitoring."," The business receiver is approved or rejected, and the record is re-screened on a schedule and on every payout.",[11,907,908],{},"Registry availability sets the speed. A US LLC or UK Ltd clears in minutes, while an entity in a paper-registry jurisdiction can take days.",[28,910,912],{"id":911},"how-do-you-integrate-kyc-compliance-into-a-stablecoin-payment-api","How do you integrate KYC compliance into a stablecoin payment API?",[11,914,915],{},"The integration pattern that works at scale treats verification as a state machine on the receiver record, not as a separate system you poll.",[808,917,918,924,930,936,942],{},[257,919,920,923],{},[20,921,922],{},"Create the receiver."," Call the receivers endpoint with the KYC type, individual or business, and the collected data. The record is created with status verifying.",[257,925,926,929],{},[20,927,928],{},"Subscribe to status webhooks."," Register a webhook for receiver status changes so your backend learns about approval or rejection without polling.",[257,931,932,935],{},[20,933,934],{},"Gate payouts on status."," Your payout code checks that the receiver is approved before creating a quote. The API enforces this too, so a race cannot slip a payout through.",[257,937,938,941],{},[20,939,940],{},"Handle rejection and resubmission."," Surface the rejection reason to the user, collect corrected documents, and update the receiver to trigger a new verification run.",[257,943,944,947],{},[20,945,946],{},"Store the receiver ID, not the documents."," Keep the provider's receiver ID in your database and let the provider hold documents and audit logs.",[11,949,950,951,955],{},"With BlindPay, these steps use the same REST API and API key as quotes and payouts. The ",[195,952,954],{"href":953},"\u002Fdocs\u002Fapi\u002Freference","OpenAPI specification"," describes the receiver schema, status values, and webhook payloads, so client code can be generated rather than hand-written.",[28,957,959],{"id":958},"which-jurisdictions-have-specific-kyc-and-kyb-requirements-for-stablecoin-payments","Which jurisdictions have specific KYC and KYB requirements for stablecoin payments?",[11,961,962],{},"Requirements differ by country in thresholds, beneficial ownership definitions, and the licensing regulator. A multi-corridor provider needs a rule set per jurisdiction, applied automatically from the receiver country.",[52,964,965,976],{},[55,966,967],{},[58,968,969,971,973],{},[61,970,63],{},[61,972,66],{},[61,974,975],{},"Primary KYC\u002FKYB requirements",[71,977,978,988,998,1008,1018],{},[58,979,980,982,985],{},[76,981,78],{},[76,983,984],{},"FinCEN, state regulators",[76,986,987],{},"Customer Identification Program, beneficial ownership at 25 percent plus control prong under 31 CFR 1010.230, OFAC screening, SAR filing",[58,989,990,992,995],{},[76,991,89],{},[76,993,994],{},"National competent authorities under AMLD and MiCA",[76,996,997],{},"Customer due diligence, beneficial ownership at 25 percent, travel rule under the Transfer of Funds Regulation, CASP licensing under MiCA",[58,999,1000,1002,1005],{},[76,1001,100],{},[76,1003,1004],{},"FCA",[76,1006,1007],{},"Money Laundering Regulations 2017, cryptoasset firm registration, PSC register checks for beneficial owners, travel rule since September 2023",[58,1009,1010,1012,1015],{},[76,1011,111],{},[76,1013,1014],{},"MAS",[76,1016,1017],{},"Payment Services Act licensing, MAS Notice PSN02 customer due diligence, travel rule for digital payment token transfers",[58,1019,1020,1022,1025],{},[76,1021,122],{},[76,1023,1024],{},"Banco Central do Brasil, Receita Federal",[76,1026,1027],{},"CPF and CNPJ validation, name and tax ID matching on Pix, PSAV registration for virtual asset providers, Circular 3978 AML controls",[11,1029,1030,1031,1034,1035,1039],{},"The ",[195,1032,1033],{"href":424},"regulation tracker"," and ",[195,1036,1038],{"href":1037},"\u002Fresources\u002Fmore\u002Fmica-stablecoin-rules-explained","MiCA explainer"," go deeper on EU and Brazil rules.",[28,1041,1043],{"id":1042},"why-should-compliance-checks-run-before-settlement-instead-of-after","Why should compliance checks run before settlement instead of after?",[11,1045,1046],{},"On a card or ACH network, a payment flagged after the fact can be reversed. A stablecoin transfer on a public chain is final once confirmed, so a check that runs after settlement is a report, not a control.",[11,1048,1049],{},"Verification before the payout is created means a sanctions hit or failed document check blocks the transaction at zero cost. After settlement, the funds are already in a wallet you do not control.",[11,1051,1052],{},"BlindPay runs KYC, KYB, and per-payout sanctions screening before any quote is executed. A receiver that is not approved cannot receive a payout, and a payout that fails screening is rejected before funds move.",[28,1054,1056],{"id":1055},"can-a-stablecoin-company-reuse-kyc-it-already-performs","Can a stablecoin company reuse KYC it already performs?",[11,1058,1059],{},"Partly. A fintech with its own onboarding program can pass verified data through the payment API instead of running users through a second document flow, once the provider has reviewed that program against its own standard.",[11,1061,1062],{},"BlindPay applies this as a reliance model. Onboarding, fraud checks, and limit increase reviews can be relied upon after a review of the partner's policies, while transaction monitoring on every payout always runs on BlindPay's side. All customer data still flows through the API, and BlindPay keeps the right to inspect any partner check.",[28,1064,1066],{"id":1065},"what-should-developers-check-when-choosing-automated-identity-verification-for-a-stablecoin-company","What should developers check when choosing automated identity verification for a stablecoin company?",[11,1068,1069],{},"The decision comes down to whether verification is part of the payment flow or bolted on beside it. A separate KYC vendor means a second contract, a second SDK, and a sync problem between verification state and payout permission.",[254,1071,1072,1078,1084,1090],{},[257,1073,1074,1077],{},[20,1075,1076],{},"Single API surface."," Verification and payouts should share one authentication scheme, one webhook system, and one set of IDs.",[257,1079,1080,1083],{},[20,1081,1082],{},"Enforcement at the payout layer."," The API itself should refuse a payout to an unverified receiver, not just return a status your code has to remember to check.",[257,1085,1086,1089],{},[20,1087,1088],{},"Jurisdiction coverage."," Confirm the provider applies the right rules for every country you pay into, including local tax ID formats and name matching rules.",[257,1091,1092,1095,1096,1100],{},[20,1093,1094],{},"Sandbox parity."," The ",[195,1097,1099],{"href":1098},"\u002Fresources\u002Fmore\u002Fstablecoin-api-sandbox-vs-production","sandbox"," should return realistic verification states, including rejected and verifying, so every branch is tested before go-live.",[28,1102,1104],{"id":1103},"faq","FAQ",[11,1106,1107,1110],{},[20,1108,1109],{},"What is the difference between KYC and KYB?","\nKYC verifies an individual person: identity document, liveness, address, and sanctions screening. KYB verifies a business entity: registration, good standing, ownership structure, and then KYC on each beneficial owner and controller. A business account needs both.",[11,1112,1113,1116],{},[20,1114,1115],{},"Can KYC for stablecoin payments be fully automated?","\nFor most users, yes. Document extraction, face matching, sanctions screening, and risk scoring run without a human, and a clean case is approved in seconds to minutes. A small share of cases with mismatched data or screening hits still goes to manual review.",[11,1118,1119,1122],{},[20,1120,1121],{},"Do I need a separate KYC vendor if I use a stablecoin payment API?","\nNot if the payment API includes verification. BlindPay runs KYC and KYB through the same REST API used to create payouts, so there is no second vendor contract, SDK, or webhook pipeline to maintain.",[11,1124,1125,1128],{},[20,1126,1127],{},"What happens if a user fails automated KYC?","\nThe receiver record moves to a rejected status and no payout can be created for it. Your app should show the reason category returned by the API and, where allowed, offer a resubmission path with corrected documents.",[11,1130,1131,1134],{},[20,1132,1133],{},"How long does automated KYB take for a business?","\nMinutes to same day when registry data is available and ownership is simple. Entities with layered holding companies, trusts, or non-digitized registries can take several days because ownership must be traced to real people.",[11,1136,1137,1140],{},[20,1138,1139],{},"Does KYC need to run before every stablecoin payout?","\nVerification runs once per receiver, not per transaction. Sanctions screening and risk checks then run on each payout against the verified record, and the payout is blocked before settlement if anything changed.",[28,1142,1144],{"id":1143},"how-does-blindpay-fit-in","How does BlindPay fit in?",[11,1146,1147],{},"Automating KYC and KYB for stablecoin payments means treating verification as a state on the receiver, running every check before settlement, and letting the payment API enforce the result. Doing it inside the payment infrastructure removes the separate vendor integration and its synchronization bugs.",[11,1149,1150,1154,1155,1157,1158,199],{},[195,1151,1153],{"href":306,"rel":1152},[308],"BlindPay"," embeds KYC and KYB in the same REST API used for quotes and payouts, covering document verification, sanctions screening, risk scoring, and audit logging across the US, EU, UK, Singapore, Brazil, and other supported countries. The ",[195,1156,297],{"href":296}," covers the full program, and specific corridors are worth a ",[195,1159,1160],{"href":301},"conversation",[11,1162,1163],{},[14,1164,314],{},{"title":316,"searchDepth":317,"depth":317,"links":1166},[1167,1168,1169,1170,1171,1172,1173,1174,1175,1176],{"id":785,"depth":317,"text":786},{"id":802,"depth":317,"text":803},{"id":857,"depth":317,"text":858},{"id":911,"depth":317,"text":912},{"id":958,"depth":317,"text":959},{"id":1042,"depth":317,"text":1043},{"id":1055,"depth":317,"text":1056},{"id":1065,"depth":317,"text":1066},{"id":1103,"depth":317,"text":1104},{"id":1143,"depth":317,"text":1144},"2026-08-25","A developer guide to automated KYC and KYB for stablecoin payment flows: how verification runs inside a payment API, step-by-step workflows for individuals and businesses, jurisdiction requirements for the US, EU, UK, Singapore, and Brazil, and what to check before settlement.",[1180,1182,1184,1186,1188,1190],{"q":1109,"a":1181},"KYC verifies an individual person: identity document, liveness, address, and sanctions screening. KYB verifies a business entity: registration, good standing, ownership structure, and then KYC on each beneficial owner and controller. A business account needs both.",{"q":1115,"a":1183},"For most users, yes. Document extraction, face matching, sanctions screening, and risk scoring run without a human, and a clean case is approved in seconds to minutes. A small share of cases with mismatched data or screening hits still goes to manual review.",{"q":1121,"a":1185},"Not if the payment API includes verification. BlindPay runs KYC and KYB through the same REST API used to create payouts, so there is no second vendor contract, SDK, or webhook pipeline to maintain.",{"q":1127,"a":1187},"The receiver record moves to a rejected status and no payout can be created for it. Your app should show the reason category returned by the API and, where allowed, offer a resubmission path with corrected documents.",{"q":1133,"a":1189},"Minutes to same day when registry data is available and ownership is simple. Entities with layered holding companies, trusts, or non-digitized registries can take several days because ownership must be traced to real people.",{"q":1139,"a":1191},"Verification runs once per receiver, not per transaction. Sanctions screening and risk checks then run on each payout against the verified record, and the payout is blocked before settlement if anything changed.",{"author":358},"\u002Fresources\u002Fmore\u002Fhow-to-automate-kyc-kyb-stablecoin-payments","---\ntitle: \"How to automate KYC and KYB for stablecoin payments\"\ndescription: \"A developer guide to automated KYC and KYB for stablecoin payment flows: how verification runs inside a payment API, step-by-step workflows for individuals and businesses, jurisdiction requirements for the US, EU, UK, Singapore, and Brazil, and what to check before settlement.\"\ndate: \"2026-08-25\"\nupdated: \"2026-08-25\"\nauthor: \"BlindPay Team\"\ncategory: \"compliance\"\nfaq:\n  - q: \"What is the difference between KYC and KYB?\"\n    a: \"KYC verifies an individual person: identity document, liveness, address, and sanctions screening. KYB verifies a business entity: registration, good standing, ownership structure, and then KYC on each beneficial owner and controller. A business account needs both.\"\n  - q: \"Can KYC for stablecoin payments be fully automated?\"\n    a: \"For most users, yes. Document extraction, face matching, sanctions screening, and risk scoring run without a human, and a clean case is approved in seconds to minutes. A small share of cases with mismatched data or screening hits still goes to manual review.\"\n  - q: \"Do I need a separate KYC vendor if I use a stablecoin payment API?\"\n    a: \"Not if the payment API includes verification. BlindPay runs KYC and KYB through the same REST API used to create payouts, so there is no second vendor contract, SDK, or webhook pipeline to maintain.\"\n  - q: \"What happens if a user fails automated KYC?\"\n    a: \"The receiver record moves to a rejected status and no payout can be created for it. Your app should show the reason category returned by the API and, where allowed, offer a resubmission path with corrected documents.\"\n  - q: \"How long does automated KYB take for a business?\"\n    a: \"Minutes to same day when registry data is available and ownership is simple. Entities with layered holding companies, trusts, or non-digitized registries can take several days because ownership must be traced to real people.\"\n  - q: \"Does KYC need to run before every stablecoin payout?\"\n    a: \"Verification runs once per receiver, not per transaction. Sanctions screening and risk checks then run on each payout against the verified record, and the payout is blocked before settlement if anything changed.\"\n---\n\n*Reading time: about 8 minutes.*\n\n**Summary:** You automate KYC and KYB for stablecoin payments by making verification a step in the payment API itself. Create a receiver with identity or entity data, let automated KYC run document checks, sanctions screening, and risk scoring, receive the result by webhook, and only allow payouts once the receiver status is approved.\n\nKYC automation matters for stablecoin companies because a payout on a public blockchain cannot be reversed. Every check has to finish before funds move, and manual review does not scale past a few hundred receivers.\n\n## What is the difference between KYC and KYB for stablecoin payments?\n\nKYC, Know Your Customer, verifies an individual person. It confirms that a government ID is authentic, that the person presenting it is real and present, and that they are not on a sanctions or watch list.\n\nKYB, Know Your Business, verifies a business entity. It confirms the company is registered and active, maps who owns and controls it, and then runs KYC on each of those individuals.\n\nThe split maps onto who you pay. Contractors and remittance recipients need KYC. Vendors, marketplaces, and corporate customers need KYB, which always includes KYC on their owners. The [KYB explainer](\u002Fresources\u002Fmore\u002Fwhat-is-kyb) covers beneficial ownership rules in detail.\n\n## How does automated KYC work for stablecoin users?\n\nAutomated KYC replaces an analyst reviewing a PDF with a pipeline of machine checks that return a decision and an audit trail.\n\n1. **Data collection.** Your app collects name, date of birth, address, tax ID, and ID document images, then sends them in one API request that creates the receiver.\n2. **Document verification.** The system extracts fields from the document, checks security features and expiry, and compares the extracted data against what the user typed.\n3. **Liveness and face match.** A selfie or short video is checked for presentation attacks, then matched against the document photo.\n4. **Sanctions and PEP screening.** The name, date of birth, and country are screened against OFAC, EU, UK, UN, and local lists, plus politically exposed person databases.\n5. **Risk scoring.** Country, document type, IP geolocation, and screening results combine into a risk tier that decides between auto-approval and manual review.\n6. **Decision and webhook.** The receiver status becomes approved, rejected, or verifying, and your backend receives a webhook so it can unlock or block payouts.\n7. **Audit logging.** Every input, check result, and decision is stored with timestamps so a regulator or bank partner can reconstruct the case.\n\nA clean case clears all seven stages in under a minute. A name mismatch or screening hit stops at stage five for a human decision.\n\n## How does KYB automation work for business receivers?\n\nKYB automation follows the same shape but adds an entity layer before the individual checks. Ownership tracing is the hard part, because it has to end at real people.\n\n1. **Entity data collection.** Collect legal name, registration number, tax ID, incorporation date, registered address, business type, and industry, plus the incorporation document.\n2. **Registry verification.** The registration number is checked against the jurisdiction's corporate registry to confirm the entity exists, is active, and matches the stated name and address.\n3. **Ownership mapping.** The ownership structure is unwound through holding companies until every individual with 25 percent or more, or with control, is identified.\n4. **Beneficial owner KYC.** Each identified owner and controller goes through the full individual KYC flow described above.\n5. **Entity screening.** The company name and its owners are screened against sanctions lists, adverse media, and industry restrictions.\n6. **Risk scoring and decision.** Entity type, industry, jurisdiction, and owner results combine into a tier. High-risk industries or complex ownership route to enhanced due diligence.\n7. **Decision and monitoring.** The business receiver is approved or rejected, and the record is re-screened on a schedule and on every payout.\n\nRegistry availability sets the speed. A US LLC or UK Ltd clears in minutes, while an entity in a paper-registry jurisdiction can take days.\n\n## How do you integrate KYC compliance into a stablecoin payment API?\n\nThe integration pattern that works at scale treats verification as a state machine on the receiver record, not as a separate system you poll.\n\n1. **Create the receiver.** Call the receivers endpoint with the KYC type, individual or business, and the collected data. The record is created with status verifying.\n2. **Subscribe to status webhooks.** Register a webhook for receiver status changes so your backend learns about approval or rejection without polling.\n3. **Gate payouts on status.** Your payout code checks that the receiver is approved before creating a quote. The API enforces this too, so a race cannot slip a payout through.\n4. **Handle rejection and resubmission.** Surface the rejection reason to the user, collect corrected documents, and update the receiver to trigger a new verification run.\n5. **Store the receiver ID, not the documents.** Keep the provider's receiver ID in your database and let the provider hold documents and audit logs.\n\nWith BlindPay, these steps use the same REST API and API key as quotes and payouts. The [OpenAPI specification](\u002Fdocs\u002Fapi\u002Freference) describes the receiver schema, status values, and webhook payloads, so client code can be generated rather than hand-written.\n\n## Which jurisdictions have specific KYC and KYB requirements for stablecoin payments?\n\nRequirements differ by country in thresholds, beneficial ownership definitions, and the licensing regulator. A multi-corridor provider needs a rule set per jurisdiction, applied automatically from the receiver country.\n\n| Jurisdiction | Regulatory body | Primary KYC\u002FKYB requirements |\n|---|---|---|\n| United States | FinCEN, state regulators | Customer Identification Program, beneficial ownership at 25 percent plus control prong under 31 CFR 1010.230, OFAC screening, SAR filing |\n| European Union | National competent authorities under AMLD and MiCA | Customer due diligence, beneficial ownership at 25 percent, travel rule under the Transfer of Funds Regulation, CASP licensing under MiCA |\n| United Kingdom | FCA | Money Laundering Regulations 2017, cryptoasset firm registration, PSC register checks for beneficial owners, travel rule since September 2023 |\n| Singapore | MAS | Payment Services Act licensing, MAS Notice PSN02 customer due diligence, travel rule for digital payment token transfers |\n| Brazil | Banco Central do Brasil, Receita Federal | CPF and CNPJ validation, name and tax ID matching on Pix, PSAV registration for virtual asset providers, Circular 3978 AML controls |\n\nThe [regulation tracker](\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026) and [MiCA explainer](\u002Fresources\u002Fmore\u002Fmica-stablecoin-rules-explained) go deeper on EU and Brazil rules.\n\n## Why should compliance checks run before settlement instead of after?\n\nOn a card or ACH network, a payment flagged after the fact can be reversed. A stablecoin transfer on a public chain is final once confirmed, so a check that runs after settlement is a report, not a control.\n\nVerification before the payout is created means a sanctions hit or failed document check blocks the transaction at zero cost. After settlement, the funds are already in a wallet you do not control.\n\nBlindPay runs KYC, KYB, and per-payout sanctions screening before any quote is executed. A receiver that is not approved cannot receive a payout, and a payout that fails screening is rejected before funds move.\n\n## Can a stablecoin company reuse KYC it already performs?\n\nPartly. A fintech with its own onboarding program can pass verified data through the payment API instead of running users through a second document flow, once the provider has reviewed that program against its own standard.\n\nBlindPay applies this as a reliance model. Onboarding, fraud checks, and limit increase reviews can be relied upon after a review of the partner's policies, while transaction monitoring on every payout always runs on BlindPay's side. All customer data still flows through the API, and BlindPay keeps the right to inspect any partner check.\n\n## What should developers check when choosing automated identity verification for a stablecoin company?\n\nThe decision comes down to whether verification is part of the payment flow or bolted on beside it. A separate KYC vendor means a second contract, a second SDK, and a sync problem between verification state and payout permission.\n\n- **Single API surface.** Verification and payouts should share one authentication scheme, one webhook system, and one set of IDs.\n- **Enforcement at the payout layer.** The API itself should refuse a payout to an unverified receiver, not just return a status your code has to remember to check.\n- **Jurisdiction coverage.** Confirm the provider applies the right rules for every country you pay into, including local tax ID formats and name matching rules.\n- **Sandbox parity.** The [sandbox](\u002Fresources\u002Fmore\u002Fstablecoin-api-sandbox-vs-production) should return realistic verification states, including rejected and verifying, so every branch is tested before go-live.\n\n## FAQ\n\n**What is the difference between KYC and KYB?**\nKYC verifies an individual person: identity document, liveness, address, and sanctions screening. KYB verifies a business entity: registration, good standing, ownership structure, and then KYC on each beneficial owner and controller. A business account needs both.\n\n**Can KYC for stablecoin payments be fully automated?**\nFor most users, yes. Document extraction, face matching, sanctions screening, and risk scoring run without a human, and a clean case is approved in seconds to minutes. A small share of cases with mismatched data or screening hits still goes to manual review.\n\n**Do I need a separate KYC vendor if I use a stablecoin payment API?**\nNot if the payment API includes verification. BlindPay runs KYC and KYB through the same REST API used to create payouts, so there is no second vendor contract, SDK, or webhook pipeline to maintain.\n\n**What happens if a user fails automated KYC?**\nThe receiver record moves to a rejected status and no payout can be created for it. Your app should show the reason category returned by the API and, where allowed, offer a resubmission path with corrected documents.\n\n**How long does automated KYB take for a business?**\nMinutes to same day when registry data is available and ownership is simple. Entities with layered holding companies, trusts, or non-digitized registries can take several days because ownership must be traced to real people.\n\n**Does KYC need to run before every stablecoin payout?**\nVerification runs once per receiver, not per transaction. Sanctions screening and risk checks then run on each payout against the verified record, and the payout is blocked before settlement if anything changed.\n\n## How does BlindPay fit in?\n\nAutomating KYC and KYB for stablecoin payments means treating verification as a state on the receiver, running every check before settlement, and letting the payment API enforce the result. Doing it inside the payment infrastructure removes the separate vendor integration and its synchronization bugs.\n\n[BlindPay](https:\u002F\u002Fblindpay.com) embeds KYC and KYB in the same REST API used for quotes and payouts, covering document verification, sanctions screening, risk scoring, and audit logging across the US, EU, UK, Singapore, Brazil, and other supported countries. The [compliance page](\u002Fcompliance) covers the full program, and specific corridors are worth a [conversation](\u002Fcontact).\n\n*This article is for general information only and is not legal, tax, or financial advice.*\n",{"title":768,"description":1178},"resources\u002Fmore\u002Fhow-to-automate-kyc-kyb-stablecoin-payments","tRu0PP7Igm_3lK0twYtc3SE6J_ahR3KUgScPtVqDSNY",{"id":1199,"title":1200,"authors":6,"body":1201,"categories":6,"category":333,"categoryType":6,"compare":6,"contributors":6,"date":1464,"description":1465,"extension":336,"faq":1466,"howto":6,"isBlog":356,"isChangelog":356,"meta":1479,"navigation":359,"path":1037,"pillar":356,"products":6,"rawbody":1480,"seo":1481,"stem":1482,"thumbnail":6,"updated":6,"__hash__":1483},"content\u002Fresources\u002Fmore\u002Fmica-stablecoin-rules-explained.md","MiCA stablecoin rules explained for payment companies",{"type":8,"value":1202,"toc":1452},[1203,1206,1211,1215,1218,1221,1225,1228,1231,1234,1238,1241,1279,1283,1286,1289,1296,1300,1303,1325,1329,1332,1358,1361,1365,1368,1371,1375,1378,1382,1385,1402,1406,1426,1447],[11,1204,1205],{},"MiCA, the EU's Markets in Crypto-Assets regulation (Regulation (EU) 2023\u002F1114), is the single rulebook that decides which stablecoins can circulate in the European Union and who may issue them. Its stablecoin provisions have applied since June 30, 2024. The practical outcome for payment companies is simple: dollar and euro stablecoins in the EU must be e-money tokens issued by licensed institutions, USDC qualifies, USDT does not, and businesses that use compliant tokens through licensed providers carry none of the issuer obligations themselves.",[11,1207,1208,1209,199],{},"This article explains the parts of MiCA that matter if you pay or get paid with stablecoins. For the wider global picture, see our ",[195,1210,425],{"href":424},[28,1212,1214],{"id":1213},"what-does-mica-actually-regulate","What does MiCA actually regulate?",[11,1216,1217],{},"MiCA covers crypto-assets that were not already regulated under EU financial law. It creates three regimes: one for e-money tokens (EMTs), one for asset-referenced tokens (ARTs), and one for other crypto-assets, plus a licensing regime for crypto-asset service providers (CASPs) such as exchanges and custodians.",[11,1219,1220],{},"The stablecoin rules (Titles III and IV) took effect June 30, 2024. CASP rules followed on December 30, 2024, with national grandfathering periods that ran into 2026 for firms already operating. As of 2026, the transition is essentially over: the EU market runs on authorized issuers and licensed service providers.",[28,1222,1224],{"id":1223},"what-is-the-difference-between-an-emt-and-an-art","What is the difference between an EMT and an ART?",[11,1226,1227],{},"An e-money token references a single official currency: a dollar stablecoin or a euro stablecoin is an EMT. Under MiCA, only authorized credit institutions and electronic money institutions may issue EMTs, holders get a legal claim to redeem at par at any time, and issuers may not pay interest on holdings.",[11,1229,1230],{},"An asset-referenced token references a basket: multiple currencies, commodities, or crypto-assets. ARTs carry heavier capital, governance, and disclosure requirements and are rare in practice.",[11,1232,1233],{},"For payment flows, the distinction is almost academic: every stablecoin a business would use for payouts or settlement (USDC, EURC, and their peers) is an EMT. The label to look for is whether the issuer holds an EU authorization.",[28,1235,1237],{"id":1236},"what-must-emt-issuers-do-under-mica","What must EMT issuers do under MiCA?",[11,1239,1240],{},"The issuer requirements explain why the compliant list is short:",[254,1242,1243,1249,1255,1261,1267,1273],{},[257,1244,1245,1248],{},[20,1246,1247],{},"Authorization."," The issuer must be a licensed credit institution or electronic money institution in an EU member state.",[257,1250,1251,1254],{},[20,1252,1253],{},"A white paper"," notified to the regulator, describing the token, the reserve, and redemption rights.",[257,1256,1257,1260],{},[20,1258,1259],{},"Full reserves"," backing every token, segregated from the issuer's own assets, invested conservatively, with strict custody rules.",[257,1262,1263,1266],{},[20,1264,1265],{},"Redemption at par, at any time",", free of charge for holders.",[257,1268,1269,1272],{},[20,1270,1271],{},"No interest"," paid on the token, which draws the line between payment instruments and deposit-like products.",[257,1274,1275,1278],{},[20,1276,1277],{},"Significant EMT rules."," Tokens above thresholds for holders, market value, or transaction volume face extra requirements supervised by the European Banking Authority, including transaction-volume monitoring for tokens denominated in non-EU currencies used as a means of exchange.",[28,1280,1282],{"id":1281},"why-is-usdc-available-in-the-eu-and-usdt-not","Why is USDC available in the EU and USDT not?",[11,1284,1285],{},"Circle became the first major global stablecoin issuer to comply: it obtained an electronic money institution license in France (supervised by the ACPR) on July 1, 2024, and issues both USDC and EURC as MiCA-compliant EMTs. That license passports across all EU member states.",[11,1287,1288],{},"Tether publicly chose not to seek MiCA authorization, criticizing the reserve requirements. The consequence arrived through the service-provider side: CASPs cannot offer non-compliant EMTs to EU customers, so regulated exchanges (Coinbase, Crypto.com, Binance for EEA users, and others) delisted USDT for EU customers between late 2024 and the first quarter of 2025.",[11,1290,1291,1292,199],{},"The market read the signal. For any product that touches EU users, USDC became the default dollar stablecoin. Our comparison of the two tokens for payment use cases: ",[195,1293,1295],{"href":1294},"\u002Fresources\u002Fmore\u002Fusdc-vs-usdt-for-payments","USDC vs USDT for payments",[28,1297,1299],{"id":1298},"what-does-mica-mean-for-a-business-that-uses-stablecoins","What does MiCA mean for a business that uses stablecoins?",[11,1301,1302],{},"If your company sends payouts, settles invoices, or holds working balances in stablecoins, MiCA does not turn you into a regulated entity. The obligations attach to issuers and service providers. Your responsibilities are choices:",[254,1304,1305,1311,1319],{},[257,1306,1307,1310],{},[20,1308,1309],{},"Choose compliant tokens for EU-touching flows."," USDC (and EURC for euro flows) as of 2026. A payout that starts in USDT can still reach an EU-adjacent receiver in local fiat, but the stablecoin leg should not be marketed or offered to EU users.",[257,1312,1313,1316,1317,199],{},[20,1314,1315],{},"Choose licensed partners."," If a provider custodies stablecoins or converts them for you in the EU, it should hold CASP authorization or operate through appropriately licensed entities. Ask; serious providers publish this. Ours is documented on the ",[195,1318,297],{"href":296},[257,1320,1321,1324],{},[20,1322,1323],{},"Mind where your users are."," MiCA applies to tokens offered to persons in the EU. A LatAm payout flow run by a US company is outside its scope, but the same company onboarding EU businesses is not.",[28,1326,1328],{"id":1327},"how-did-the-mica-timeline-unfold","How did the MiCA timeline unfold?",[11,1330,1331],{},"The rollout took three years and explains why 2026 feels settled:",[254,1333,1334,1340,1346,1352],{},[257,1335,1336,1339],{},[20,1337,1338],{},"June 2023",": MiCA entered into force, starting the clock.",[257,1341,1342,1345],{},[20,1343,1344],{},"June 30, 2024",": Titles III and IV applied; EMT and ART issuance without authorization became unlawful in the EU. Circle's French EMI license landed on July 1, 2024, making USDC the first major compliant dollar stablecoin.",[257,1347,1348,1351],{},[20,1349,1350],{},"Late 2024 to Q1 2025",": CASP rules applied (December 30, 2024) and regulated exchanges completed USDT delistings for EU customers, following ESMA's guidance that non-compliant EMTs should be restricted.",[257,1353,1354,1357],{},[20,1355,1356],{},"Through 2026",": national grandfathering periods for existing CASPs expired member state by member state; the EU market now runs end to end on authorized firms.",[11,1359,1360],{},"The lesson for payment companies watching other jurisdictions (Brazil's VASP transition, GENIUS Act rulemaking in the US): the binding date is rarely the law's publication, it is the moment service providers must drop non-compliant tokens. Distribution, not issuance, is where enforcement bites.",[28,1362,1364],{"id":1363},"who-enforces-mica","Who enforces MiCA?",[11,1366,1367],{},"Supervision is layered. National competent authorities (the AMF and ACPR in France, BaFin in Germany, and their peers) license issuers and CASPs and police conduct in their markets. The European Banking Authority (EBA) takes direct supervision of significant EMTs and ARTs, the tokens large enough to matter for financial stability, and the European Securities and Markets Authority (ESMA) coordinates the CASP side and keeps the public registers of authorized firms.",[11,1369,1370],{},"Enforcement so far has been structural rather than punitive: the effective sanction for a non-compliant token is exclusion from regulated distribution, as the USDT delistings showed. For a payment business, the practical check is not reading enforcement actions, it is checking the registers: an issuer should appear as an authorized EMI or credit institution, and an exchange or custodian should appear in ESMA's CASP register. If a partner is on neither list and claims EU coverage, that is the red flag.",[28,1372,1374],{"id":1373},"what-about-euro-stablecoins","What about euro stablecoins?",[11,1376,1377],{},"MiCA did for the euro what no market force had: it created a regulated euro stablecoin category. EURC (Circle) and a handful of bank-issued euro EMTs now circulate, and EU merchants and platforms increasingly quote in them for on-chain settlement. Volumes remain a fraction of dollar tokens, but for EU-domestic flows a euro EMT avoids FX entirely: a payout that starts and ends in euros has no reason to route through a dollar. Significant-EMT rules also cap how far a non-euro (that is, dollar) token can go as a day-to-day means of exchange inside the EU, a deliberate nudge toward euro-denominated tokens for domestic European payments.",[28,1379,1381],{"id":1380},"what-is-the-practical-checklist","What is the practical checklist?",[11,1383,1384],{},"For a payment company reviewing MiCA exposure in 2026:",[808,1386,1387,1390,1393,1396,1399],{},[257,1388,1389],{},"Inventory which stablecoins your flows touch and which user geographies can hold them.",[257,1391,1392],{},"Default EU-facing flows to MiCA-compliant EMTs (USDC, EURC).",[257,1394,1395],{},"Verify your providers' licensing: EMI or credit institution status for issuers, CASP status for exchanges and custodians.",[257,1397,1398],{},"Check redemption terms: compliant tokens redeem at par, always, free.",[257,1400,1401],{},"Document the above; MiCA compliance questions now appear in enterprise procurement and bank due diligence.",[28,1403,1405],{"id":1404},"how-blindpay-fits-in","How BlindPay fits in",[11,1407,1408,1409,1413,1414,1418,1419,1423,1424,199],{},"BlindPay is a stablecoin API for ",[195,1410,1412],{"href":1411},"\u002Fglobal-payments","global payments",": businesses send USDC or USDT and receivers get local currency over Pix, SPEI, ACH, or wire in ",[195,1415,1417],{"href":1416},"\u002Fcoverage","100+ countries",", with KYC, sanctions screening, and travel rule handling built into the flow. USDC, the EU-compliant token, is a first-class asset across the platform, including ",[195,1420,1422],{"href":1421},"\u002Fvirtual-accounts","virtual accounts"," that convert incoming bank transfers to USDC automatically. Regulatory questions about a specific corridor are the kind of thing worth a ",[195,1425,1160],{"href":301},[11,1427,1428,1429,1434,1435,1440,1441,1446],{},"Primary sources: the MiCA text on ",[195,1430,1433],{"href":1431,"rel":1432},"https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002F?uri=CELEX%3A32023R1114",[308],"EUR-Lex",", ESMA's ",[195,1436,1439],{"href":1437,"rel":1438},"https:\u002F\u002Fwww.esma.europa.eu\u002Fesmas-activities\u002Fdigital-finance-and-innovation\u002Fmarkets-crypto-assets-regulation-mica",[308],"MiCA hub",", and the EBA's guidance on ARTs and EMTs (",[195,1442,1445],{"href":1443,"rel":1444},"https:\u002F\u002Fwww.eba.europa.eu\u002Fregulation-and-policy\u002Fmarkets-crypto-assets-mica",[308],"eba.europa.eu","). Status described as of August 2026.",[11,1448,1449],{},[14,1450,1451],{},"This article is general information, not legal, tax, or financial advice.",{"title":316,"searchDepth":317,"depth":317,"links":1453},[1454,1455,1456,1457,1458,1459,1460,1461,1462,1463],{"id":1213,"depth":317,"text":1214},{"id":1223,"depth":317,"text":1224},{"id":1236,"depth":317,"text":1237},{"id":1281,"depth":317,"text":1282},{"id":1298,"depth":317,"text":1299},{"id":1327,"depth":317,"text":1328},{"id":1363,"depth":317,"text":1364},{"id":1373,"depth":317,"text":1374},{"id":1380,"depth":317,"text":1381},{"id":1404,"depth":317,"text":1405},"2026-08-15","What MiCA means if your business uses stablecoins in the EU: EMTs vs ARTs, issuer requirements, why USDC is compliant and USDT was delisted, and a practical checklist.",[1467,1470,1473,1476],{"q":1468,"a":1469},"Is USDC MiCA-compliant?","Yes. Circle obtained an electronic money institution license in France in 2024 and issues USDC and EURC as MiCA-compliant e-money tokens. As of 2026, USDC is the most widely supported compliant dollar stablecoin in the EU.",{"q":1471,"a":1472},"Can EU businesses still use USDT?","Not through regulated channels. Tether did not pursue MiCA authorization, and EU-regulated exchanges delisted USDT for EU customers starting in early 2025. Businesses serving EU users should default to MiCA-compliant tokens like USDC.",{"q":1474,"a":1475},"Does MiCA apply to my company if we only use stablecoins for payouts?","Using a compliant stablecoin through a licensed provider does not itself make you an issuer or a crypto-asset service provider. The obligations sit with the issuer and the provider. You are responsible for choosing compliant tokens and licensed partners.",{"q":1477,"a":1478},"What is the difference between an EMT and an ART under MiCA?","An e-money token (EMT) references a single fiat currency, like a dollar or euro stablecoin. An asset-referenced token (ART) references a basket of assets. EMTs can only be issued by licensed credit institutions or electronic money institutions, and payment stablecoins are almost always EMTs.",{"author":358},"---\ntitle: \"MiCA stablecoin rules explained for payment companies\"\ndescription: \"What MiCA means if your business uses stablecoins in the EU: EMTs vs ARTs, issuer requirements, why USDC is compliant and USDT was delisted, and a practical checklist.\"\ndate: \"2026-08-15\"\ncategory: \"compliance\"\nauthor: \"BlindPay Team\"\nfaq:\n  - q: \"Is USDC MiCA-compliant?\"\n    a: \"Yes. Circle obtained an electronic money institution license in France in 2024 and issues USDC and EURC as MiCA-compliant e-money tokens. As of 2026, USDC is the most widely supported compliant dollar stablecoin in the EU.\"\n  - q: \"Can EU businesses still use USDT?\"\n    a: \"Not through regulated channels. Tether did not pursue MiCA authorization, and EU-regulated exchanges delisted USDT for EU customers starting in early 2025. Businesses serving EU users should default to MiCA-compliant tokens like USDC.\"\n  - q: \"Does MiCA apply to my company if we only use stablecoins for payouts?\"\n    a: \"Using a compliant stablecoin through a licensed provider does not itself make you an issuer or a crypto-asset service provider. The obligations sit with the issuer and the provider. You are responsible for choosing compliant tokens and licensed partners.\"\n  - q: \"What is the difference between an EMT and an ART under MiCA?\"\n    a: \"An e-money token (EMT) references a single fiat currency, like a dollar or euro stablecoin. An asset-referenced token (ART) references a basket of assets. EMTs can only be issued by licensed credit institutions or electronic money institutions, and payment stablecoins are almost always EMTs.\"\n---\n\nMiCA, the EU's Markets in Crypto-Assets regulation (Regulation (EU) 2023\u002F1114), is the single rulebook that decides which stablecoins can circulate in the European Union and who may issue them. Its stablecoin provisions have applied since June 30, 2024. The practical outcome for payment companies is simple: dollar and euro stablecoins in the EU must be e-money tokens issued by licensed institutions, USDC qualifies, USDT does not, and businesses that use compliant tokens through licensed providers carry none of the issuer obligations themselves.\n\nThis article explains the parts of MiCA that matter if you pay or get paid with stablecoins. For the wider global picture, see our [stablecoin regulation tracker](\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026).\n\n## What does MiCA actually regulate?\n\nMiCA covers crypto-assets that were not already regulated under EU financial law. It creates three regimes: one for e-money tokens (EMTs), one for asset-referenced tokens (ARTs), and one for other crypto-assets, plus a licensing regime for crypto-asset service providers (CASPs) such as exchanges and custodians.\n\nThe stablecoin rules (Titles III and IV) took effect June 30, 2024. CASP rules followed on December 30, 2024, with national grandfathering periods that ran into 2026 for firms already operating. As of 2026, the transition is essentially over: the EU market runs on authorized issuers and licensed service providers.\n\n## What is the difference between an EMT and an ART?\n\nAn e-money token references a single official currency: a dollar stablecoin or a euro stablecoin is an EMT. Under MiCA, only authorized credit institutions and electronic money institutions may issue EMTs, holders get a legal claim to redeem at par at any time, and issuers may not pay interest on holdings.\n\nAn asset-referenced token references a basket: multiple currencies, commodities, or crypto-assets. ARTs carry heavier capital, governance, and disclosure requirements and are rare in practice.\n\nFor payment flows, the distinction is almost academic: every stablecoin a business would use for payouts or settlement (USDC, EURC, and their peers) is an EMT. The label to look for is whether the issuer holds an EU authorization.\n\n## What must EMT issuers do under MiCA?\n\nThe issuer requirements explain why the compliant list is short:\n\n- **Authorization.** The issuer must be a licensed credit institution or electronic money institution in an EU member state.\n- **A white paper** notified to the regulator, describing the token, the reserve, and redemption rights.\n- **Full reserves** backing every token, segregated from the issuer's own assets, invested conservatively, with strict custody rules.\n- **Redemption at par, at any time**, free of charge for holders.\n- **No interest** paid on the token, which draws the line between payment instruments and deposit-like products.\n- **Significant EMT rules.** Tokens above thresholds for holders, market value, or transaction volume face extra requirements supervised by the European Banking Authority, including transaction-volume monitoring for tokens denominated in non-EU currencies used as a means of exchange.\n\n## Why is USDC available in the EU and USDT not?\n\nCircle became the first major global stablecoin issuer to comply: it obtained an electronic money institution license in France (supervised by the ACPR) on July 1, 2024, and issues both USDC and EURC as MiCA-compliant EMTs. That license passports across all EU member states.\n\nTether publicly chose not to seek MiCA authorization, criticizing the reserve requirements. The consequence arrived through the service-provider side: CASPs cannot offer non-compliant EMTs to EU customers, so regulated exchanges (Coinbase, Crypto.com, Binance for EEA users, and others) delisted USDT for EU customers between late 2024 and the first quarter of 2025.\n\nThe market read the signal. For any product that touches EU users, USDC became the default dollar stablecoin. Our comparison of the two tokens for payment use cases: [USDC vs USDT for payments](\u002Fresources\u002Fmore\u002Fusdc-vs-usdt-for-payments).\n\n## What does MiCA mean for a business that uses stablecoins?\n\nIf your company sends payouts, settles invoices, or holds working balances in stablecoins, MiCA does not turn you into a regulated entity. The obligations attach to issuers and service providers. Your responsibilities are choices:\n\n- **Choose compliant tokens for EU-touching flows.** USDC (and EURC for euro flows) as of 2026. A payout that starts in USDT can still reach an EU-adjacent receiver in local fiat, but the stablecoin leg should not be marketed or offered to EU users.\n- **Choose licensed partners.** If a provider custodies stablecoins or converts them for you in the EU, it should hold CASP authorization or operate through appropriately licensed entities. Ask; serious providers publish this. Ours is documented on the [compliance page](\u002Fcompliance).\n- **Mind where your users are.** MiCA applies to tokens offered to persons in the EU. A LatAm payout flow run by a US company is outside its scope, but the same company onboarding EU businesses is not.\n\n## How did the MiCA timeline unfold?\n\nThe rollout took three years and explains why 2026 feels settled:\n\n- **June 2023**: MiCA entered into force, starting the clock.\n- **June 30, 2024**: Titles III and IV applied; EMT and ART issuance without authorization became unlawful in the EU. Circle's French EMI license landed on July 1, 2024, making USDC the first major compliant dollar stablecoin.\n- **Late 2024 to Q1 2025**: CASP rules applied (December 30, 2024) and regulated exchanges completed USDT delistings for EU customers, following ESMA's guidance that non-compliant EMTs should be restricted.\n- **Through 2026**: national grandfathering periods for existing CASPs expired member state by member state; the EU market now runs end to end on authorized firms.\n\nThe lesson for payment companies watching other jurisdictions (Brazil's VASP transition, GENIUS Act rulemaking in the US): the binding date is rarely the law's publication, it is the moment service providers must drop non-compliant tokens. Distribution, not issuance, is where enforcement bites.\n\n## Who enforces MiCA?\n\nSupervision is layered. National competent authorities (the AMF and ACPR in France, BaFin in Germany, and their peers) license issuers and CASPs and police conduct in their markets. The European Banking Authority (EBA) takes direct supervision of significant EMTs and ARTs, the tokens large enough to matter for financial stability, and the European Securities and Markets Authority (ESMA) coordinates the CASP side and keeps the public registers of authorized firms.\n\nEnforcement so far has been structural rather than punitive: the effective sanction for a non-compliant token is exclusion from regulated distribution, as the USDT delistings showed. For a payment business, the practical check is not reading enforcement actions, it is checking the registers: an issuer should appear as an authorized EMI or credit institution, and an exchange or custodian should appear in ESMA's CASP register. If a partner is on neither list and claims EU coverage, that is the red flag.\n\n## What about euro stablecoins?\n\nMiCA did for the euro what no market force had: it created a regulated euro stablecoin category. EURC (Circle) and a handful of bank-issued euro EMTs now circulate, and EU merchants and platforms increasingly quote in them for on-chain settlement. Volumes remain a fraction of dollar tokens, but for EU-domestic flows a euro EMT avoids FX entirely: a payout that starts and ends in euros has no reason to route through a dollar. Significant-EMT rules also cap how far a non-euro (that is, dollar) token can go as a day-to-day means of exchange inside the EU, a deliberate nudge toward euro-denominated tokens for domestic European payments.\n\n## What is the practical checklist?\n\nFor a payment company reviewing MiCA exposure in 2026:\n\n1. Inventory which stablecoins your flows touch and which user geographies can hold them.\n2. Default EU-facing flows to MiCA-compliant EMTs (USDC, EURC).\n3. Verify your providers' licensing: EMI or credit institution status for issuers, CASP status for exchanges and custodians.\n4. Check redemption terms: compliant tokens redeem at par, always, free.\n5. Document the above; MiCA compliance questions now appear in enterprise procurement and bank due diligence.\n\n## How BlindPay fits in\n\nBlindPay is a stablecoin API for [global payments](\u002Fglobal-payments): businesses send USDC or USDT and receivers get local currency over Pix, SPEI, ACH, or wire in [100+ countries](\u002Fcoverage), with KYC, sanctions screening, and travel rule handling built into the flow. USDC, the EU-compliant token, is a first-class asset across the platform, including [virtual accounts](\u002Fvirtual-accounts) that convert incoming bank transfers to USDC automatically. Regulatory questions about a specific corridor are the kind of thing worth a [conversation](\u002Fcontact).\n\nPrimary sources: the MiCA text on [EUR-Lex](https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002F?uri=CELEX%3A32023R1114), ESMA's [MiCA hub](https:\u002F\u002Fwww.esma.europa.eu\u002Fesmas-activities\u002Fdigital-finance-and-innovation\u002Fmarkets-crypto-assets-regulation-mica), and the EBA's guidance on ARTs and EMTs ([eba.europa.eu](https:\u002F\u002Fwww.eba.europa.eu\u002Fregulation-and-policy\u002Fmarkets-crypto-assets-mica)). Status described as of August 2026.\n\n*This article is general information, not legal, tax, or financial advice.*\n",{"title":1200,"description":1465},"resources\u002Fmore\u002Fmica-stablecoin-rules-explained","FeLtqf1hnOXSUQ3Tn6Ba52AMXiY0QSr2ZdkIfYKN4o4",{"id":1485,"title":1486,"authors":6,"body":1487,"categories":6,"category":333,"categoryType":6,"compare":6,"contributors":6,"date":1464,"description":1693,"extension":336,"faq":1694,"howto":6,"isBlog":356,"isChangelog":356,"meta":1707,"navigation":359,"path":1708,"pillar":356,"products":6,"rawbody":1709,"seo":1710,"stem":1711,"thumbnail":6,"updated":6,"__hash__":1712},"content\u002Fresources\u002Fmore\u002Fpsav-brazil-explained.md","PSAV in Brazil: the Central Bank's virtual asset license explained",{"type":8,"value":1488,"toc":1684},[1489,1492,1495,1499,1502,1509,1513,1516,1542,1547,1551,1554,1557,1561,1564,1596,1599,1603,1606,1634,1638,1652,1656,1679],[11,1490,1491],{},"PSAV (Prestadora de Serviços de Ativos Virtuais) is Brazil's regulatory regime for companies that provide virtual asset services: exchanging, transferring, custodying, or intermediating crypto and stablecoins for Brazilian customers. The Banco Central do Brasil created the authorization framework in Resolutions 519, 520, and 521, published November 10, 2025 and effective February 2, 2026, under the legal foundation of Law 14.478\u002F2022. Since that date, providing these services in Brazil without authorization or a transitional-regime position is illegal.",[11,1493,1494],{},"Brazil is not a side market for this regime. It is one of the largest stablecoin markets in the world, and Pix, the Central Bank's instant payment system used by over 150 million people, is where most stablecoin conversions land. The PSAV rules are the Central Bank taking direct supervision of the companies connecting those two worlds.",[28,1496,1498],{"id":1497},"what-is-a-psav","What is a PSAV?",[11,1500,1501],{},"A PSAV is a company authorized by the Banco Central do Brasil to provide virtual asset services. The resolutions define the authorized corporate form as an SPSAV, a Sociedade Prestadora de Serviços de Ativos Virtuais: a Brazilian legal entity whose corporate purpose is virtual asset services and which meets the Central Bank's requirements for capital, governance, and compliance. In practice the terms PSAV and SPSAV describe the same regime from two angles: the activity and the entity that performs it.",[11,1503,1504,1505,199],{},"The covered services follow the FATF definition of a virtual asset service provider (VASP): exchange between virtual assets and fiat currency, exchange between virtual assets, transfer of virtual assets, custody or administration of virtual assets, and participation in financial services related to an issuer's offer or sale of a virtual asset. A stablecoin off-ramp that converts USDC into reais over Pix sits squarely inside the first category. How those conversions work route by route is covered in ",[195,1506,1508],{"href":1507},"\u002Fresources\u002Fmore\u002Fusdc-to-brl-routes-2026","USDC to BRL in 2026",[28,1510,1512],{"id":1511},"which-rules-make-up-the-regime","Which rules make up the regime?",[11,1514,1515],{},"Three resolutions, one law, as of 2026:",[254,1517,1518,1524,1530,1536],{},[257,1519,1520,1523],{},[20,1521,1522],{},"Law 14.478\u002F2022"," created the legal framework for virtual asset services in Brazil and assigned supervision to the Banco Central do Brasil.",[257,1525,1526,1529],{},[20,1527,1528],{},"Resolution 519\u002F2025"," defines the regulated activities and classifies virtual asset services within the national financial system.",[257,1531,1532,1535],{},[20,1533,1534],{},"Resolution 520\u002F2025"," is the authorization rulebook: entity form, minimum capital, governance, fit-and-proper requirements for controllers and officers, and the application process. Its Article 88 created the transitional regime for companies already operating.",[257,1537,1538,1541],{},[20,1539,1540],{},"Resolution 521\u002F2025"," sets the ongoing conduct rules: AML\u002FCFT obligations, customer asset segregation, reporting, and operational requirements.",[11,1543,1544,1545,199],{},"Together they moved Brazil from a market where crypto companies operated under general law to one where the Central Bank licenses and supervises them the way it supervises payment institutions. The broader global picture, including MiCA and the GENIUS Act, is in the ",[195,1546,425],{"href":424},[28,1548,1550],{"id":1549},"who-needs-the-authorization","Who needs the authorization?",[11,1552,1553],{},"Any company serving Brazilian residents with virtual asset services, whether from inside Brazil or offshore. The regime deliberately closes the offshore loophole: targeting the Brazilian market triggers the requirement regardless of where the servers or the corporate entity sit. Foreign exchanges and stablecoin infrastructure companies serving Brazil face the same choice as local ones: incorporate an SPSAV and apply, or exit the market.",[11,1555,1556],{},"Two groups matter for the transition. Companies that started operating before the regime took effect could invoke Article 88 of Resolution 520: they file for authorization within the transitional window and continue operating legally while the Central Bank processes the application. Companies that were not operating before the cutoff must obtain authorization first and operate second. The Central Bank has shown it will enforce the boundary; it has moved against institutions running virtual asset operations outside the permitted structure.",[28,1558,1560],{"id":1559},"what-does-a-psav-have-to-do-in-practice","What does a PSAV have to do in practice?",[11,1562,1563],{},"The obligations look like what Brazil already requires of payment institutions, adapted to virtual assets:",[254,1565,1566,1572,1578,1584,1590],{},[257,1567,1568,1571],{},[20,1569,1570],{},"Corporate substance."," A Brazilian entity (the SPSAV) with the required minimum capital, local governance, and named responsible officers who pass fit-and-proper review.",[257,1573,1574,1577],{},[20,1575,1576],{},"AML\u002FCFT program."," Customer identification (CPF\u002FCNPJ), transaction monitoring, sanctions screening, suspicious activity reporting to COAF, and travel rule data handling on transfers.",[257,1579,1580,1583],{},[20,1581,1582],{},"Asset segregation."," Customer virtual assets separated from the company's own, with controls the Central Bank can examine.",[257,1585,1586,1589],{},[20,1587,1588],{},"Reporting and transparency."," Periodic regulatory reporting, incident notification, and cooperation with Central Bank supervision.",[257,1591,1592,1595],{},[20,1593,1594],{},"Tax reporting."," Alongside the BCB regime, Receita Federal expanded crypto transaction reporting through Normative Instruction 2,291\u002F2025.",[11,1597,1598],{},"For a business using a provider rather than becoming one, the checklist inverts: you do not need your own PSAV authorization to pay contractors in Brazil through an authorized provider. You need your provider to have one, or to be lawfully inside the transitional regime, because that is what makes the reais leg of your payout legal, supervised, and recoverable if something breaks.",[28,1600,1602],{"id":1601},"how-does-this-affect-stablecoin-payouts-to-brazil","How does this affect stablecoin payouts to Brazil?",[11,1604,1605],{},"Concretely, three things changed for cross-border money movement in 2026:",[808,1607,1608,1614,1623],{},[257,1609,1610,1613],{},[20,1611,1612],{},"Provider due diligence became a compliance requirement, not a preference."," If your payout provider's Brazil leg runs through an unauthorized intermediary, your payments inherit that risk. Ask any provider for its SPSAV entity, CNPJ, and regime status; a serious one publishes them.",[257,1615,1616,1619,1620,199],{},[20,1617,1618],{},"Receiver verification got stricter rails."," Pix already rejects transfers where the beneficiary name and CPF\u002FCNPJ do not match the receiving account, and PSAV-regulated providers must run KYC and sanctions screening on receivers before converting. The full picture of what providers verify is in ",[195,1621,1622],{"href":487},"stablecoin payments explained",[257,1624,1625,1628,1629,1633],{},[20,1626,1627],{},"The market cleaned up."," Offshore providers without a Brazilian entity are exiting or restructuring, which concentrates volume in authorized providers and makes the \"which provider\" question, covered in ",[195,1630,1632],{"href":1631},"\u002Fresources\u002Fmore\u002Fbest-stablecoin-payment-providers-2026","best stablecoin payment providers in 2026",", largely a regulatory question in Brazil.",[28,1635,1637],{"id":1636},"how-does-blindpay-operate-under-the-psav-regime","How does BlindPay operate under the PSAV regime?",[11,1639,1640,1641,1643,1644,1646,1647,1651],{},"BlindPay's Brazilian operating entity is BLIND PAY SOCIEDADE PRESTADORA DE SERVIÇOS DE ATIVOS VIRTUAIS LTDA, a dedicated SPSAV. The company is completing the regulatory adaptation process required by Central Bank Resolution 520\u002F2025 and operates under the transitional regime set forth in Article 88 of that Resolution, which authorizes continued operation while the application is processed. Entity details, CNPJ numbers, and the full registration picture across markets are published on the ",[195,1642,198],{"href":197},", and our ",[195,1645,297],{"href":296}," describes the program that runs on top: KYC and KYB, sanctions screening, and travel rule handling on every ",[195,1648,1650],{"href":1649},"\u002Fusdc-to-brl","USDC or USDT to BRL"," payout.",[28,1653,1655],{"id":1654},"methodology-and-sources","Methodology and sources",[11,1657,1658,1659,1664,1665,1670,1671,1676,1677,199],{},"Regulatory facts from primary sources as of August 2026: Law 14.478\u002F2022 (",[195,1660,1663],{"href":1661,"rel":1662},"https:\u002F\u002Fwww.planalto.gov.br\u002Fccivil_03\u002F_ato2019-2022\u002F2022\u002Flei\u002FL14478.htm",[308],"planalto.gov.br","), Banco Central do Brasil Resolutions 519, 520, and 521 of November 10, 2025 (",[195,1666,1669],{"href":1667,"rel":1668},"https:\u002F\u002Fwww.bcb.gov.br",[308],"bcb.gov.br","), the BCB's Pix documentation (",[195,1672,1675],{"href":1673,"rel":1674},"https:\u002F\u002Fwww.bcb.gov.br\u002Fen\u002Ffinancialstability\u002Fpix_en",[308],"bcb.gov.br\u002Fen\u002Ffinancialstability\u002Fpix_en","), and Receita Federal Normative Instruction 2,291\u002F2025. BlindPay entity and status details from the published ",[195,1678,198],{"href":197},[11,1680,1681],{},[14,1682,1683],{},"This article is general information, not legal, tax, or financial advice. Businesses operating in or serving Brazil should consult Brazilian counsel on their specific regulatory position.",{"title":316,"searchDepth":317,"depth":317,"links":1685},[1686,1687,1688,1689,1690,1691,1692],{"id":1497,"depth":317,"text":1498},{"id":1511,"depth":317,"text":1512},{"id":1549,"depth":317,"text":1550},{"id":1559,"depth":317,"text":1560},{"id":1601,"depth":317,"text":1602},{"id":1636,"depth":317,"text":1637},{"id":1654,"depth":317,"text":1655},"PSAV is Brazil's authorization for virtual asset service providers, created by BCB Resolutions 519, 520, and 521 under Law 14.478\u002F2022. What it requires and who needs it.",[1695,1698,1701,1704],{"q":1696,"a":1697},"What does PSAV stand for?","Prestadora de Serviços de Ativos Virtuais, provider of virtual asset services. The Central Bank's resolutions use the corporate form SPSAV, Sociedade Prestadora de Serviços de Ativos Virtuais, for the authorized entity. Both refer to the same regime.",{"q":1699,"a":1700},"Who needs a PSAV authorization in Brazil?","Any company providing virtual asset services to people or businesses in Brazil: exchanging crypto for reais, transferring virtual assets, custodying them, or intermediating those services. This includes stablecoin on-ramps and off-ramps.",{"q":1702,"a":1703},"When did Brazil's PSAV rules take effect?","The Central Bank published Resolutions 519, 520, and 521 on November 10, 2025, effective February 2, 2026. Companies already operating got a transitional window under Article 88 of Resolution 520 to apply for authorization while continuing to operate.",{"q":1705,"a":1706},"Is BlindPay authorized to operate in Brazil?","BlindPay's Brazilian operating entity is a Sociedade Prestadora de Serviços de Ativos Virtuais completing the adaptation process required by Resolution 520\u002F2025, and operates under the transitional regime of Article 88. Details are on the licenses page.",{"author":358},"\u002Fresources\u002Fmore\u002Fpsav-brazil-explained","---\ntitle: \"PSAV in Brazil: the Central Bank's virtual asset license explained\"\ndescription: \"PSAV is Brazil's authorization for virtual asset service providers, created by BCB Resolutions 519, 520, and 521 under Law 14.478\u002F2022. What it requires and who needs it.\"\ndate: \"2026-08-15\"\ncategory: \"compliance\"\nauthor: \"BlindPay Team\"\nfaq:\n  - q: \"What does PSAV stand for?\"\n    a: \"Prestadora de Serviços de Ativos Virtuais, provider of virtual asset services. The Central Bank's resolutions use the corporate form SPSAV, Sociedade Prestadora de Serviços de Ativos Virtuais, for the authorized entity. Both refer to the same regime.\"\n  - q: \"Who needs a PSAV authorization in Brazil?\"\n    a: \"Any company providing virtual asset services to people or businesses in Brazil: exchanging crypto for reais, transferring virtual assets, custodying them, or intermediating those services. This includes stablecoin on-ramps and off-ramps.\"\n  - q: \"When did Brazil's PSAV rules take effect?\"\n    a: \"The Central Bank published Resolutions 519, 520, and 521 on November 10, 2025, effective February 2, 2026. Companies already operating got a transitional window under Article 88 of Resolution 520 to apply for authorization while continuing to operate.\"\n  - q: \"Is BlindPay authorized to operate in Brazil?\"\n    a: \"BlindPay's Brazilian operating entity is a Sociedade Prestadora de Serviços de Ativos Virtuais completing the adaptation process required by Resolution 520\u002F2025, and operates under the transitional regime of Article 88. Details are on the licenses page.\"\n---\n\nPSAV (Prestadora de Serviços de Ativos Virtuais) is Brazil's regulatory regime for companies that provide virtual asset services: exchanging, transferring, custodying, or intermediating crypto and stablecoins for Brazilian customers. The Banco Central do Brasil created the authorization framework in Resolutions 519, 520, and 521, published November 10, 2025 and effective February 2, 2026, under the legal foundation of Law 14.478\u002F2022. Since that date, providing these services in Brazil without authorization or a transitional-regime position is illegal.\n\nBrazil is not a side market for this regime. It is one of the largest stablecoin markets in the world, and Pix, the Central Bank's instant payment system used by over 150 million people, is where most stablecoin conversions land. The PSAV rules are the Central Bank taking direct supervision of the companies connecting those two worlds.\n\n## What is a PSAV?\n\nA PSAV is a company authorized by the Banco Central do Brasil to provide virtual asset services. The resolutions define the authorized corporate form as an SPSAV, a Sociedade Prestadora de Serviços de Ativos Virtuais: a Brazilian legal entity whose corporate purpose is virtual asset services and which meets the Central Bank's requirements for capital, governance, and compliance. In practice the terms PSAV and SPSAV describe the same regime from two angles: the activity and the entity that performs it.\n\nThe covered services follow the FATF definition of a virtual asset service provider (VASP): exchange between virtual assets and fiat currency, exchange between virtual assets, transfer of virtual assets, custody or administration of virtual assets, and participation in financial services related to an issuer's offer or sale of a virtual asset. A stablecoin off-ramp that converts USDC into reais over Pix sits squarely inside the first category. How those conversions work route by route is covered in [USDC to BRL in 2026](\u002Fresources\u002Fmore\u002Fusdc-to-brl-routes-2026).\n\n## Which rules make up the regime?\n\nThree resolutions, one law, as of 2026:\n\n- **Law 14.478\u002F2022** created the legal framework for virtual asset services in Brazil and assigned supervision to the Banco Central do Brasil.\n- **Resolution 519\u002F2025** defines the regulated activities and classifies virtual asset services within the national financial system.\n- **Resolution 520\u002F2025** is the authorization rulebook: entity form, minimum capital, governance, fit-and-proper requirements for controllers and officers, and the application process. Its Article 88 created the transitional regime for companies already operating.\n- **Resolution 521\u002F2025** sets the ongoing conduct rules: AML\u002FCFT obligations, customer asset segregation, reporting, and operational requirements.\n\nTogether they moved Brazil from a market where crypto companies operated under general law to one where the Central Bank licenses and supervises them the way it supervises payment institutions. The broader global picture, including MiCA and the GENIUS Act, is in the [stablecoin regulation tracker](\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026).\n\n## Who needs the authorization?\n\nAny company serving Brazilian residents with virtual asset services, whether from inside Brazil or offshore. The regime deliberately closes the offshore loophole: targeting the Brazilian market triggers the requirement regardless of where the servers or the corporate entity sit. Foreign exchanges and stablecoin infrastructure companies serving Brazil face the same choice as local ones: incorporate an SPSAV and apply, or exit the market.\n\nTwo groups matter for the transition. Companies that started operating before the regime took effect could invoke Article 88 of Resolution 520: they file for authorization within the transitional window and continue operating legally while the Central Bank processes the application. Companies that were not operating before the cutoff must obtain authorization first and operate second. The Central Bank has shown it will enforce the boundary; it has moved against institutions running virtual asset operations outside the permitted structure.\n\n## What does a PSAV have to do in practice?\n\nThe obligations look like what Brazil already requires of payment institutions, adapted to virtual assets:\n\n- **Corporate substance.** A Brazilian entity (the SPSAV) with the required minimum capital, local governance, and named responsible officers who pass fit-and-proper review.\n- **AML\u002FCFT program.** Customer identification (CPF\u002FCNPJ), transaction monitoring, sanctions screening, suspicious activity reporting to COAF, and travel rule data handling on transfers.\n- **Asset segregation.** Customer virtual assets separated from the company's own, with controls the Central Bank can examine.\n- **Reporting and transparency.** Periodic regulatory reporting, incident notification, and cooperation with Central Bank supervision.\n- **Tax reporting.** Alongside the BCB regime, Receita Federal expanded crypto transaction reporting through Normative Instruction 2,291\u002F2025.\n\nFor a business using a provider rather than becoming one, the checklist inverts: you do not need your own PSAV authorization to pay contractors in Brazil through an authorized provider. You need your provider to have one, or to be lawfully inside the transitional regime, because that is what makes the reais leg of your payout legal, supervised, and recoverable if something breaks.\n\n## How does this affect stablecoin payouts to Brazil?\n\nConcretely, three things changed for cross-border money movement in 2026:\n\n1. **Provider due diligence became a compliance requirement, not a preference.** If your payout provider's Brazil leg runs through an unauthorized intermediary, your payments inherit that risk. Ask any provider for its SPSAV entity, CNPJ, and regime status; a serious one publishes them.\n2. **Receiver verification got stricter rails.** Pix already rejects transfers where the beneficiary name and CPF\u002FCNPJ do not match the receiving account, and PSAV-regulated providers must run KYC and sanctions screening on receivers before converting. The full picture of what providers verify is in [stablecoin payments explained](\u002Fresources\u002Fmore\u002Fstablecoin-payments-guide).\n3. **The market cleaned up.** Offshore providers without a Brazilian entity are exiting or restructuring, which concentrates volume in authorized providers and makes the \"which provider\" question, covered in [best stablecoin payment providers in 2026](\u002Fresources\u002Fmore\u002Fbest-stablecoin-payment-providers-2026), largely a regulatory question in Brazil.\n\n## How does BlindPay operate under the PSAV regime?\n\nBlindPay's Brazilian operating entity is BLIND PAY SOCIEDADE PRESTADORA DE SERVIÇOS DE ATIVOS VIRTUAIS LTDA, a dedicated SPSAV. The company is completing the regulatory adaptation process required by Central Bank Resolution 520\u002F2025 and operates under the transitional regime set forth in Article 88 of that Resolution, which authorizes continued operation while the application is processed. Entity details, CNPJ numbers, and the full registration picture across markets are published on the [licenses page](\u002Flicenses), and our [compliance page](\u002Fcompliance) describes the program that runs on top: KYC and KYB, sanctions screening, and travel rule handling on every [USDC or USDT to BRL](\u002Fusdc-to-brl) payout.\n\n## Methodology and sources\n\nRegulatory facts from primary sources as of August 2026: Law 14.478\u002F2022 ([planalto.gov.br](https:\u002F\u002Fwww.planalto.gov.br\u002Fccivil_03\u002F_ato2019-2022\u002F2022\u002Flei\u002FL14478.htm)), Banco Central do Brasil Resolutions 519, 520, and 521 of November 10, 2025 ([bcb.gov.br](https:\u002F\u002Fwww.bcb.gov.br)), the BCB's Pix documentation ([bcb.gov.br\u002Fen\u002Ffinancialstability\u002Fpix_en](https:\u002F\u002Fwww.bcb.gov.br\u002Fen\u002Ffinancialstability\u002Fpix_en)), and Receita Federal Normative Instruction 2,291\u002F2025. BlindPay entity and status details from the published [licenses page](\u002Flicenses).\n\n*This article is general information, not legal, tax, or financial advice. Businesses operating in or serving Brazil should consult Brazilian counsel on their specific regulatory position.*\n",{"title":1486,"description":1693},"resources\u002Fmore\u002Fpsav-brazil-explained","BWVQp4yU7GOJd_VGq_Ogxim6cT0Z0YabM0C1ExnO5b0",{"id":1714,"title":1715,"authors":6,"body":1716,"categories":6,"category":333,"categoryType":6,"compare":6,"contributors":6,"date":1464,"description":2025,"extension":336,"faq":2026,"howto":6,"isBlog":356,"isChangelog":356,"meta":2039,"navigation":359,"path":424,"pillar":356,"products":6,"rawbody":2040,"seo":2041,"stem":2042,"thumbnail":6,"updated":6,"__hash__":2043},"content\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026.md","Stablecoin regulation in 2026: MiCA, the GENIUS Act, Brazil, and Japan",{"type":8,"value":1717,"toc":2014},[1718,1721,1727,1731,1734,1737,1744,1748,1751,1754,1757,1761,1764,1767,1777,1781,1784,1787,1791,1882,1885,1889,1892,1912,1915,1919,1922,1951,1958,1962,1979,1981,2010],[11,1719,1720],{},"Stablecoin regulation stopped being a gray zone. As of 2026, the four markets that matter most to cross-border payment businesses all have dedicated rules in force: the EU's Markets in Crypto-Assets regulation (MiCA), the US GENIUS Act, Brazil's virtual asset framework under Law 14.478\u002F2022 and Central Bank Resolutions 519, 520, and 521, and Japan's revised Payment Services Act. The direction is the same everywhere: fully reserved, licensed, auditable digital dollars (and euros, and yen) are welcome; everything else is being pushed out of the regulated system.",[11,1722,1723,1724,199],{},"This tracker summarizes each regime and what it means in practice for businesses that pay or get paid with stablecoins. For the basics of how these payments work, start with our ",[195,1725,1726],{"href":487},"guide to stablecoin payments",[28,1728,1730],{"id":1729},"what-does-mica-require-of-stablecoin-issuers","What does MiCA require of stablecoin issuers?",[11,1732,1733],{},"MiCA (Regulation (EU) 2023\u002F1114) is the EU's single rulebook for crypto-assets. Its stablecoin provisions have applied since June 30, 2024, and full application for crypto-asset service providers began at the end of 2024, with national transition periods running through 2026.",[11,1735,1736],{},"MiCA splits stablecoins into two categories. E-money tokens (EMTs) reference a single fiat currency and can only be issued by licensed credit institutions or electronic money institutions. Asset-referenced tokens (ARTs) reference baskets of assets and carry heavier requirements. For payment businesses, EMTs are the category that matters: a dollar or euro stablecoin used for payouts is an EMT.",[11,1738,1739,1740,1743],{},"The practical consequences showed up fast. Circle obtained an electronic money institution license in France and issues USDC and EURC as MiCA-compliant EMTs. Tether chose not to pursue authorization, and USDT was delisted from most EU-regulated exchanges. If your business touches EU customers or EU rails, your stablecoin choice is effectively made for you. Our ",[195,1741,1742],{"href":1037},"MiCA explainer for payment companies"," covers the details.",[28,1745,1747],{"id":1746},"what-is-the-genius-act","What is the GENIUS Act?",[11,1749,1750],{},"The GENIUS Act (Guiding and Establishing National Innovation for US Stablecoins Act), signed in July 2025, is the first US federal law dedicated to payment stablecoins. Before it, US stablecoin issuers operated under a patchwork of state money transmitter licenses and trust charters.",[11,1752,1753],{},"The core requirements: payment stablecoin issuers must hold reserves 1:1 in cash, insured deposits, and short-term US Treasuries; they must be licensed either federally or under a qualifying state regime; they must publish monthly reserve disclosures; and they face restrictions on paying interest to holders. Issuers of a certain size fall under federal supervision.",[11,1755,1756],{},"For payment businesses, the GENIUS Act removed the biggest US legal question: whether regulated companies could rely on stablecoins at all. The answer is now yes, provided the stablecoin comes from a licensed issuer. It also accelerated bank and fintech adoption; Reuters reported stablecoin circulation passing 250 billion dollars in 2025, with regulated issuers taking a growing share.",[28,1758,1760],{"id":1759},"how-does-brazil-regulate-stablecoins-and-vasps","How does Brazil regulate stablecoins and VASPs?",[11,1762,1763],{},"Brazil moved earlier than most. Law 14.478\u002F2022 created the legal framework for virtual asset service providers (VASPs) and assigned supervision to the Banco Central do Brasil (BCB). In November 2025 the BCB published Resolutions 519, 520, and 521, which took effect on February 2, 2026, and created the SPSAV regime: companies providing virtual asset services in Brazil must obtain authorization, with a transition window under Article 88 of Resolution 520 for companies already operating.",[11,1765,1766],{},"Two things make Brazil special for stablecoin payments. First, Pix: the BCB's instant payment system settles transfers in seconds, 24\u002F7, and is the default way Brazilians move money. A stablecoin payout that ends in Pix reaches the receiver faster than an international wire by days. Second, enforcement is practical: Pix payouts require the receiver's name and tax ID (CPF or CNPJ) to match the receiving account, so accurate beneficiary data is a hard requirement, not a nice-to-have.",[11,1768,1769,1770,1773,1774,199],{},"The authorization regime itself, who needs it, and what it requires are covered in ",[195,1771,1772],{"href":1708},"PSAV in Brazil explained",", and we compare the concrete cash-out options, fees, and rules in ",[195,1775,1776],{"href":1507},"USDC to BRL in 2026: routes, fees, and rules compared",[28,1778,1780],{"id":1779},"what-are-japans-stablecoin-rules","What are Japan's stablecoin rules?",[11,1782,1783],{},"Japan regulated stablecoins before either the EU or the US. The revised Payment Services Act, in force since June 2023, treats fiat-pegged stablecoins as electronic payment instruments. Only licensed banks, registered money transfer agents, and trust companies may issue them, and issuers must guarantee redemption at face value. Distribution requires registration as an electronic payment instruments service provider with the Financial Services Agency (FSA).",[11,1785,1786],{},"The first yen-denominated stablecoins under this regime launched in 2025, and Japan continues to refine the framework, with the FSA studying reserve flexibility and intermediary rules. For global payment businesses, Japan matters less for day-to-day payouts than the EU, US, or Brazil, but it shows where regulation converges: licensed issuers, full reserves, guaranteed redemption.",[28,1788,1790],{"id":1789},"how-do-the-four-regimes-compare","How do the four regimes compare?",[52,1792,1793,1812],{},[55,1794,1795],{},[58,1796,1797,1800,1803,1806,1809],{},[61,1798,1799],{},"Regime",[61,1801,1802],{},"In force",[61,1804,1805],{},"Who may issue",[61,1807,1808],{},"Reserve rule",[61,1810,1811],{},"Supervisor",[71,1813,1814,1831,1848,1865],{},[58,1815,1816,1819,1822,1825,1828],{},[76,1817,1818],{},"MiCA (EU)",[76,1820,1821],{},"Stablecoin titles since June 2024",[76,1823,1824],{},"Credit institutions, licensed EMIs",[76,1826,1827],{},"Full backing, segregated, redemption at par",[76,1829,1830],{},"National regulators, EBA for significant tokens",[58,1832,1833,1836,1839,1842,1845],{},[76,1834,1835],{},"GENIUS Act (US)",[76,1837,1838],{},"Signed July 2025",[76,1840,1841],{},"Federally or state-licensed payment stablecoin issuers",[76,1843,1844],{},"1:1 in cash, insured deposits, short-term Treasuries; monthly disclosure",[76,1846,1847],{},"OCC and state regulators",[58,1849,1850,1853,1856,1859,1862],{},[76,1851,1852],{},"Brazil (Law 14.478 + BCB 519\u002F520\u002F521)",[76,1854,1855],{},"VASP regime effective February 2026",[76,1857,1858],{},"Issuance and services by authorized SPSAVs",[76,1860,1861],{},"Governance and segregation duties under BCB rules",[76,1863,1864],{},"Banco Central do Brasil",[58,1866,1867,1870,1873,1876,1879],{},[76,1868,1869],{},"Japan (Payment Services Act)",[76,1871,1872],{},"Revised rules since June 2023",[76,1874,1875],{},"Banks, money transfer agents, trust companies",[76,1877,1878],{},"Redemption at face value guaranteed",[76,1880,1881],{},"Financial Services Agency",[11,1883,1884],{},"Differences remain in the details (interest bans, disclosure cadence, licensing paths), but the convergence is unmistakable. A stablecoin that is fully reserved, redeemable at par, and issued by a licensed institution clears the bar everywhere; anything else faces shrinking room.",[28,1886,1888],{"id":1887},"where-is-regulation-still-unsettled","Where is regulation still unsettled?",[11,1890,1891],{},"Three open fronts worth tracking through the rest of 2026:",[254,1893,1894,1900,1906],{},[257,1895,1896,1899],{},[20,1897,1898],{},"Interest and yield."," The GENIUS Act bars issuers from paying interest on payment stablecoins, and MiCA does the same for EMTs. Yield-bearing wrappers and tokenized money market funds sit outside these definitions, and regulators on both sides of the Atlantic are still deciding how to treat them when they behave like payment balances.",[257,1901,1902,1905],{},[20,1903,1904],{},"Foreign-issuer access."," Both the EU and the US are refining how offshore issuers reach their markets: MiCA through equivalence-style conditions on non-EU EMTs, the US through GENIUS Act rules on foreign payment stablecoin issuers. Where these land will decide how global a single token's distribution can be.",[257,1907,1908,1911],{},[20,1909,1910],{},"Brazil's transition window."," Companies operating before Resolutions 519\u002F520\u002F521 have Article 88 transition status while their SPSAV authorizations process. Expect the authorized list to firm up through 2026 and diligence questions to shift from \"are you applying?\" to \"are you authorized?\".",[11,1913,1914],{},"None of these change the direction. They change who is allowed to distribute, and how fast.",[28,1916,1918],{"id":1917},"what-should-payment-businesses-do-about-it","What should payment businesses do about it?",[11,1920,1921],{},"The pattern across all four regimes is consistent, and it points to a short checklist:",[254,1923,1924,1930,1936,1945],{},[257,1925,1926,1929],{},[20,1927,1928],{},"Use stablecoins from regulated issuers."," USDC and other licensed EMT\u002FGENIUS-compliant tokens are accepted across all four regimes. Unregulated tokens increasingly are not.",[257,1931,1932,1935],{},[20,1933,1934],{},"Let a licensed provider carry the regulatory load."," Payout providers that hold the required registrations (money transmission in the US, VASP authorization in Brazil, CASP status in the EU) take on custody, KYC, sanctions screening, and travel rule obligations. Building this yourself means acquiring licenses market by market.",[257,1937,1938,1941,1942,199],{},[20,1939,1940],{},"Get beneficiary data right."," Brazil's name and tax ID matching is the strictest example, but every regime requires accurate sender and receiver information under travel rule requirements. Thresholds and data formats by market are in our ",[195,1943,1944],{"href":360},"cross-border compliance guide",[257,1946,1947,1950],{},[20,1948,1949],{},"Watch reserve and redemption terms."," Regulation now guarantees that a compliant stablecoin redeems 1:1. If a token's terms do not say that plainly, it does not belong in a payment flow.",[11,1952,1953,1954,1957],{},"Compliance is becoming the differentiator between providers, not an afterthought. Our own ",[195,1955,1956],{"href":296},"compliance framework"," documents how we approach it.",[28,1959,1961],{"id":1960},"how-blindpay-handles-regulation-for-you","How BlindPay handles regulation for you",[11,1963,1964,1965,1967,1968,1971,1972,1976,1977,199],{},"BlindPay is a stablecoin API for global payments: businesses send USDC or USDT and receivers get local currency over Pix, SPEI, ACH, or wire, in ",[195,1966,1417],{"href":1416},". The regulatory work is built into the flow: KYC and KYB on receivers before money moves, sanctions screening, travel rule data handling, and local rail requirements like Brazil's name and tax ID matching. ",[195,1969,1970],{"href":1421},"Virtual accounts"," extend the same model to collections, converting incoming bank transfers to stablecoins automatically. Pricing is public on the ",[195,1973,1975],{"href":1974},"\u002Fpricing","pricing page",", and the team can walk through specific regulatory questions via ",[195,1978,302],{"href":301},[28,1980,1655],{"id":1654},[11,1982,1983,1984,1988,1989,1993,1994,1999,2000,2003,2004,2009],{},"Regime details from primary sources: MiCA text, Regulation (EU) 2023\u002F1114 (",[195,1985,1987],{"href":1431,"rel":1986},[308],"eur-lex.europa.eu",") and ESMA's MiCA hub (",[195,1990,1992],{"href":1437,"rel":1991},[308],"esma.europa.eu","); the GENIUS Act, S.1582, 119th Congress (",[195,1995,1998],{"href":1996,"rel":1997},"https:\u002F\u002Fwww.congress.gov\u002Fbill\u002F119th-congress\u002Fsenate-bill\u002F1582",[308],"congress.gov","); Brazil's Law 14.478\u002F2022 and BCB Resolutions 519, 520, and 521 plus the Pix system description (",[195,2001,1669],{"href":1673,"rel":2002},[308],"); Japan's Payment Services Act framework via the Financial Services Agency (",[195,2005,2008],{"href":2006,"rel":2007},"https:\u002F\u002Fwww.fsa.go.jp\u002Fen\u002F",[308],"fsa.go.jp","). Regulatory status described as of August 2026.",[11,2011,2012],{},[14,2013,1451],{},{"title":316,"searchDepth":317,"depth":317,"links":2015},[2016,2017,2018,2019,2020,2021,2022,2023,2024],{"id":1729,"depth":317,"text":1730},{"id":1746,"depth":317,"text":1747},{"id":1759,"depth":317,"text":1760},{"id":1779,"depth":317,"text":1780},{"id":1789,"depth":317,"text":1790},{"id":1887,"depth":317,"text":1888},{"id":1917,"depth":317,"text":1918},{"id":1960,"depth":317,"text":1961},{"id":1654,"depth":317,"text":1655},"Where stablecoin regulation stands in 2026: MiCA in the EU, the GENIUS Act in the US, Brazil's VASP regime, and Japan's issuer rules, compared for payment businesses.",[2027,2030,2033,2036],{"q":2028,"a":2029},"Is it legal for businesses to use stablecoins for payments?","Yes, in most major markets, provided the business or its provider complies with local rules. The EU regulates stablecoins under MiCA, the US under the GENIUS Act and money transmission laws, Brazil under Law 14.478\u002F2022 and BCB resolutions, and Japan under the revised Payment Services Act. What matters is who issues the stablecoin and who handles the conversion to fiat.",{"q":2031,"a":2032},"Which stablecoins are compliant in the EU under MiCA?","As of 2026, USDC is available in the EU because Circle obtained an electronic money institution license in France and issues USDC as a MiCA-compliant e-money token. USDT has been delisted from most EU-regulated exchanges because Tether did not pursue MiCA authorization.",{"q":2034,"a":2035},"What is the GENIUS Act in simple terms?","The GENIUS Act is the first US federal law dedicated to payment stablecoins. It requires issuers to hold 1:1 reserves in cash and short-term Treasuries, to be licensed at the federal or state level, and to publish regular reserve disclosures. It gives US businesses a clear legal footing for using regulated dollar stablecoins.",{"q":2037,"a":2038},"Do I need my own license to send stablecoin payouts?","Usually not. If you build on a licensed provider, the provider carries the regulatory obligations: registration, custody arrangements, KYC, sanctions screening, and travel rule compliance. You are still responsible for giving the provider accurate customer and payment information.",{"author":358},"---\ntitle: \"Stablecoin regulation in 2026: MiCA, the GENIUS Act, Brazil, and Japan\"\ndescription: \"Where stablecoin regulation stands in 2026: MiCA in the EU, the GENIUS Act in the US, Brazil's VASP regime, and Japan's issuer rules, compared for payment businesses.\"\ndate: \"2026-08-15\"\ncategory: \"compliance\"\nauthor: \"BlindPay Team\"\nfaq:\n  - q: \"Is it legal for businesses to use stablecoins for payments?\"\n    a: \"Yes, in most major markets, provided the business or its provider complies with local rules. The EU regulates stablecoins under MiCA, the US under the GENIUS Act and money transmission laws, Brazil under Law 14.478\u002F2022 and BCB resolutions, and Japan under the revised Payment Services Act. What matters is who issues the stablecoin and who handles the conversion to fiat.\"\n  - q: \"Which stablecoins are compliant in the EU under MiCA?\"\n    a: \"As of 2026, USDC is available in the EU because Circle obtained an electronic money institution license in France and issues USDC as a MiCA-compliant e-money token. USDT has been delisted from most EU-regulated exchanges because Tether did not pursue MiCA authorization.\"\n  - q: \"What is the GENIUS Act in simple terms?\"\n    a: \"The GENIUS Act is the first US federal law dedicated to payment stablecoins. It requires issuers to hold 1:1 reserves in cash and short-term Treasuries, to be licensed at the federal or state level, and to publish regular reserve disclosures. It gives US businesses a clear legal footing for using regulated dollar stablecoins.\"\n  - q: \"Do I need my own license to send stablecoin payouts?\"\n    a: \"Usually not. If you build on a licensed provider, the provider carries the regulatory obligations: registration, custody arrangements, KYC, sanctions screening, and travel rule compliance. You are still responsible for giving the provider accurate customer and payment information.\"\n---\n\nStablecoin regulation stopped being a gray zone. As of 2026, the four markets that matter most to cross-border payment businesses all have dedicated rules in force: the EU's Markets in Crypto-Assets regulation (MiCA), the US GENIUS Act, Brazil's virtual asset framework under Law 14.478\u002F2022 and Central Bank Resolutions 519, 520, and 521, and Japan's revised Payment Services Act. The direction is the same everywhere: fully reserved, licensed, auditable digital dollars (and euros, and yen) are welcome; everything else is being pushed out of the regulated system.\n\nThis tracker summarizes each regime and what it means in practice for businesses that pay or get paid with stablecoins. For the basics of how these payments work, start with our [guide to stablecoin payments](\u002Fresources\u002Fmore\u002Fstablecoin-payments-guide).\n\n## What does MiCA require of stablecoin issuers?\n\nMiCA (Regulation (EU) 2023\u002F1114) is the EU's single rulebook for crypto-assets. Its stablecoin provisions have applied since June 30, 2024, and full application for crypto-asset service providers began at the end of 2024, with national transition periods running through 2026.\n\nMiCA splits stablecoins into two categories. E-money tokens (EMTs) reference a single fiat currency and can only be issued by licensed credit institutions or electronic money institutions. Asset-referenced tokens (ARTs) reference baskets of assets and carry heavier requirements. For payment businesses, EMTs are the category that matters: a dollar or euro stablecoin used for payouts is an EMT.\n\nThe practical consequences showed up fast. Circle obtained an electronic money institution license in France and issues USDC and EURC as MiCA-compliant EMTs. Tether chose not to pursue authorization, and USDT was delisted from most EU-regulated exchanges. If your business touches EU customers or EU rails, your stablecoin choice is effectively made for you. Our [MiCA explainer for payment companies](\u002Fresources\u002Fmore\u002Fmica-stablecoin-rules-explained) covers the details.\n\n## What is the GENIUS Act?\n\nThe GENIUS Act (Guiding and Establishing National Innovation for US Stablecoins Act), signed in July 2025, is the first US federal law dedicated to payment stablecoins. Before it, US stablecoin issuers operated under a patchwork of state money transmitter licenses and trust charters.\n\nThe core requirements: payment stablecoin issuers must hold reserves 1:1 in cash, insured deposits, and short-term US Treasuries; they must be licensed either federally or under a qualifying state regime; they must publish monthly reserve disclosures; and they face restrictions on paying interest to holders. Issuers of a certain size fall under federal supervision.\n\nFor payment businesses, the GENIUS Act removed the biggest US legal question: whether regulated companies could rely on stablecoins at all. The answer is now yes, provided the stablecoin comes from a licensed issuer. It also accelerated bank and fintech adoption; Reuters reported stablecoin circulation passing 250 billion dollars in 2025, with regulated issuers taking a growing share.\n\n## How does Brazil regulate stablecoins and VASPs?\n\nBrazil moved earlier than most. Law 14.478\u002F2022 created the legal framework for virtual asset service providers (VASPs) and assigned supervision to the Banco Central do Brasil (BCB). In November 2025 the BCB published Resolutions 519, 520, and 521, which took effect on February 2, 2026, and created the SPSAV regime: companies providing virtual asset services in Brazil must obtain authorization, with a transition window under Article 88 of Resolution 520 for companies already operating.\n\nTwo things make Brazil special for stablecoin payments. First, Pix: the BCB's instant payment system settles transfers in seconds, 24\u002F7, and is the default way Brazilians move money. A stablecoin payout that ends in Pix reaches the receiver faster than an international wire by days. Second, enforcement is practical: Pix payouts require the receiver's name and tax ID (CPF or CNPJ) to match the receiving account, so accurate beneficiary data is a hard requirement, not a nice-to-have.\n\nThe authorization regime itself, who needs it, and what it requires are covered in [PSAV in Brazil explained](\u002Fresources\u002Fmore\u002Fpsav-brazil-explained), and we compare the concrete cash-out options, fees, and rules in [USDC to BRL in 2026: routes, fees, and rules compared](\u002Fresources\u002Fmore\u002Fusdc-to-brl-routes-2026).\n\n## What are Japan's stablecoin rules?\n\nJapan regulated stablecoins before either the EU or the US. The revised Payment Services Act, in force since June 2023, treats fiat-pegged stablecoins as electronic payment instruments. Only licensed banks, registered money transfer agents, and trust companies may issue them, and issuers must guarantee redemption at face value. Distribution requires registration as an electronic payment instruments service provider with the Financial Services Agency (FSA).\n\nThe first yen-denominated stablecoins under this regime launched in 2025, and Japan continues to refine the framework, with the FSA studying reserve flexibility and intermediary rules. For global payment businesses, Japan matters less for day-to-day payouts than the EU, US, or Brazil, but it shows where regulation converges: licensed issuers, full reserves, guaranteed redemption.\n\n## How do the four regimes compare?\n\n| Regime | In force | Who may issue | Reserve rule | Supervisor |\n|---|---|---|---|---|\n| MiCA (EU) | Stablecoin titles since June 2024 | Credit institutions, licensed EMIs | Full backing, segregated, redemption at par | National regulators, EBA for significant tokens |\n| GENIUS Act (US) | Signed July 2025 | Federally or state-licensed payment stablecoin issuers | 1:1 in cash, insured deposits, short-term Treasuries; monthly disclosure | OCC and state regulators |\n| Brazil (Law 14.478 + BCB 519\u002F520\u002F521) | VASP regime effective February 2026 | Issuance and services by authorized SPSAVs | Governance and segregation duties under BCB rules | Banco Central do Brasil |\n| Japan (Payment Services Act) | Revised rules since June 2023 | Banks, money transfer agents, trust companies | Redemption at face value guaranteed | Financial Services Agency |\n\nDifferences remain in the details (interest bans, disclosure cadence, licensing paths), but the convergence is unmistakable. A stablecoin that is fully reserved, redeemable at par, and issued by a licensed institution clears the bar everywhere; anything else faces shrinking room.\n\n## Where is regulation still unsettled?\n\nThree open fronts worth tracking through the rest of 2026:\n\n- **Interest and yield.** The GENIUS Act bars issuers from paying interest on payment stablecoins, and MiCA does the same for EMTs. Yield-bearing wrappers and tokenized money market funds sit outside these definitions, and regulators on both sides of the Atlantic are still deciding how to treat them when they behave like payment balances.\n- **Foreign-issuer access.** Both the EU and the US are refining how offshore issuers reach their markets: MiCA through equivalence-style conditions on non-EU EMTs, the US through GENIUS Act rules on foreign payment stablecoin issuers. Where these land will decide how global a single token's distribution can be.\n- **Brazil's transition window.** Companies operating before Resolutions 519\u002F520\u002F521 have Article 88 transition status while their SPSAV authorizations process. Expect the authorized list to firm up through 2026 and diligence questions to shift from \"are you applying?\" to \"are you authorized?\".\n\nNone of these change the direction. They change who is allowed to distribute, and how fast.\n\n## What should payment businesses do about it?\n\nThe pattern across all four regimes is consistent, and it points to a short checklist:\n\n- **Use stablecoins from regulated issuers.** USDC and other licensed EMT\u002FGENIUS-compliant tokens are accepted across all four regimes. Unregulated tokens increasingly are not.\n- **Let a licensed provider carry the regulatory load.** Payout providers that hold the required registrations (money transmission in the US, VASP authorization in Brazil, CASP status in the EU) take on custody, KYC, sanctions screening, and travel rule obligations. Building this yourself means acquiring licenses market by market.\n- **Get beneficiary data right.** Brazil's name and tax ID matching is the strictest example, but every regime requires accurate sender and receiver information under travel rule requirements. Thresholds and data formats by market are in our [cross-border compliance guide](\u002Fresources\u002Fmore\u002Fcompliance-agents-cross-border-stablecoin-payments).\n- **Watch reserve and redemption terms.** Regulation now guarantees that a compliant stablecoin redeems 1:1. If a token's terms do not say that plainly, it does not belong in a payment flow.\n\nCompliance is becoming the differentiator between providers, not an afterthought. Our own [compliance framework](\u002Fcompliance) documents how we approach it.\n\n## How BlindPay handles regulation for you\n\nBlindPay is a stablecoin API for global payments: businesses send USDC or USDT and receivers get local currency over Pix, SPEI, ACH, or wire, in [100+ countries](\u002Fcoverage). The regulatory work is built into the flow: KYC and KYB on receivers before money moves, sanctions screening, travel rule data handling, and local rail requirements like Brazil's name and tax ID matching. [Virtual accounts](\u002Fvirtual-accounts) extend the same model to collections, converting incoming bank transfers to stablecoins automatically. Pricing is public on the [pricing page](\u002Fpricing), and the team can walk through specific regulatory questions via [contact](\u002Fcontact).\n\n## Methodology and sources\n\nRegime details from primary sources: MiCA text, Regulation (EU) 2023\u002F1114 ([eur-lex.europa.eu](https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002F?uri=CELEX%3A32023R1114)) and ESMA's MiCA hub ([esma.europa.eu](https:\u002F\u002Fwww.esma.europa.eu\u002Fesmas-activities\u002Fdigital-finance-and-innovation\u002Fmarkets-crypto-assets-regulation-mica)); the GENIUS Act, S.1582, 119th Congress ([congress.gov](https:\u002F\u002Fwww.congress.gov\u002Fbill\u002F119th-congress\u002Fsenate-bill\u002F1582)); Brazil's Law 14.478\u002F2022 and BCB Resolutions 519, 520, and 521 plus the Pix system description ([bcb.gov.br](https:\u002F\u002Fwww.bcb.gov.br\u002Fen\u002Ffinancialstability\u002Fpix_en)); Japan's Payment Services Act framework via the Financial Services Agency ([fsa.go.jp](https:\u002F\u002Fwww.fsa.go.jp\u002Fen\u002F)). Regulatory status described as of August 2026.\n\n*This article is general information, not legal, tax, or financial advice.*\n",{"title":1715,"description":2025},"resources\u002Fmore\u002Fstablecoin-regulation-tracker-2026","9qaUUgVskR0EmYxYR3CzuBoRgfpbKfu8-zfiw3LB0e0",{"id":2045,"title":2046,"authors":6,"body":2047,"categories":6,"category":333,"categoryType":6,"compare":6,"contributors":6,"date":2432,"description":2433,"extension":336,"faq":2434,"howto":6,"isBlog":356,"isChangelog":356,"meta":2453,"navigation":359,"path":2454,"pillar":356,"products":6,"rawbody":2455,"seo":2456,"stem":2457,"thumbnail":6,"updated":2432,"__hash__":2458},"content\u002Fresources\u002Fmore\u002Fwhat-are-compliance-agents-in-fintech.md","What are compliance agents in fintech? How they work and what they do for payments",{"type":8,"value":2048,"toc":2425},[2049,2054,2059,2063,2066,2069,2072,2108,2112,2115,2153,2156,2163,2167,2170,2173,2211,2218,2222,2225,2228,2332,2335,2339,2344,2347,2350,2388,2391,2412,2415,2421],[11,2050,2051],{},[14,2052,2053],{},"Reading time: about 7 minutes.",[11,2055,2056,2058],{},[20,2057,22],{}," Compliance agents are autonomous software components that execute regulatory checks inside a payment flow. They verify identities (KYC and KYB), screen counterparties against sanctions lists, monitor transactions for money laundering patterns, and write an audit record for every decision. Unlike traditional compliance software, which produces alerts for humans to work, compliance agents act on the result and escalate only the cases that need judgment.",[28,2060,2062],{"id":2061},"what-are-compliance-agents-in-fintech","What are compliance agents in fintech?",[11,2064,2065],{},"A compliance agent is a piece of software that owns one regulatory task end to end: it gathers the inputs, applies the rules, reaches a decision, and records the evidence. The word \"agent\" signals that it acts rather than reports.",[11,2067,2068],{},"In a payments company, compliance agents sit between the request to move money and the movement itself. A payout does not settle until the relevant agents return a pass.",[11,2070,2071],{},"Most fintech compliance programs decompose into a small set of agents, each mapped to a regulatory obligation:",[254,2073,2074,2084,2090,2096,2102],{},[257,2075,2076,2079,2080,2083],{},[20,2077,2078],{},"Identity agent."," Runs KYC on individuals and ",[195,2081,2082],{"href":229},"KYB"," on businesses, reading documents, matching them to registries, and verifying beneficial owners.",[257,2085,2086,2089],{},[20,2087,2088],{},"Sanctions agent."," Screens names, addresses, wallet addresses, and bank accounts against OFAC, UN, EU, and local lists, and resolves fuzzy matches.",[257,2091,2092,2095],{},[20,2093,2094],{},"Monitoring agent."," Watches transaction patterns for structuring, velocity spikes, and counterparties that do not fit the customer's stated profile.",[257,2097,2098,2101],{},[20,2099,2100],{},"Blockchain screening agent."," Traces the source of on-chain funds and blocks deposits linked to mixers, hacks, or sanctioned wallets.",[257,2103,2104,2107],{},[20,2105,2106],{},"Audit agent."," Stores the inputs, the rule version, the decision, and the timestamp for every check so a regulator can reconstruct it later.",[28,2109,2111],{"id":2110},"how-do-compliance-agents-work","How do compliance agents work?",[11,2113,2114],{},"Compliance agents run a loop: observe, decide, act, record. Each step is deterministic enough to audit and fast enough to run before a payment settles.",[808,2116,2117,2123,2129,2135,2141,2147],{},[257,2118,2119,2122],{},[20,2120,2121],{},"Trigger."," An event in the payment system fires the agent: a new customer, a new bank account, a payout request, or an on-chain deposit.",[257,2124,2125,2128],{},[20,2126,2127],{},"Collect."," The agent pulls what it needs: uploaded documents, registry data, list feeds, transaction history, and blockchain analytics.",[257,2130,2131,2134],{},[20,2132,2133],{},"Evaluate."," It applies the rule set for the customer's jurisdiction and risk tier. Rules can be deterministic thresholds, machine learning scores, or both.",[257,2136,2137,2140],{},[20,2138,2139],{},"Decide."," The output is one of three states: pass, block, or escalate to a human reviewer.",[257,2142,2143,2146],{},[20,2144,2145],{},"Act."," A pass lets the payment proceed. A block stops it and notifies the customer. An escalation opens a case with the evidence already attached.",[257,2148,2149,2152],{},[20,2150,2151],{},"Record."," Every input and decision is written to an immutable log tied to the transaction ID.",[11,2154,2155],{},"The escalation path is what separates a well-designed agent from a black box. The agent does not guess on ambiguous cases; it routes them to a person with the file already assembled.",[11,2157,2158,2159,2162],{},"Rule sets change by jurisdiction. A single agent may hold one policy for Brazilian virtual asset service providers, another for US money transmitters, and a third for ",[195,2160,2161],{"href":1037},"MiCA"," in the EU, selecting the right one from the customer's country and entity type.",[28,2164,2166],{"id":2165},"what-do-compliance-agents-do-for-payments","What do compliance agents do for payments?",[11,2168,2169],{},"For a payments company, compliance agents turn a set of legal obligations into checks that execute on every transaction without slowing it down. They are the reason a cross-border payout can be both instant and defensible.",[11,2171,2172],{},"The concrete jobs are:",[254,2174,2175,2181,2187,2193,2199,2205],{},[257,2176,2177,2180],{},[20,2178,2179],{},"Onboarding."," Verify the sender and the receiver before the first payment, so the money never touches an unverified account.",[257,2182,2183,2186],{},[20,2184,2185],{},"Pre-settlement screening."," Screen every payout against sanctions lists at the moment it is created, not in a nightly batch, because a stablecoin transfer is final once confirmed.",[257,2188,2189,2192],{},[20,2190,2191],{},"Ongoing monitoring."," Re-screen existing customers as lists update and flag transaction patterns that drift from the profile established at onboarding.",[257,2194,2195,2198],{},[20,2196,2197],{},"Source-of-funds checks."," Trace inbound stablecoin deposits to confirm they did not originate from a sanctioned or hacked wallet.",[257,2200,2201,2204],{},[20,2202,2203],{},"Regulatory reporting."," Assemble suspicious activity reports and threshold reports from the audit log instead of from analyst memory.",[257,2206,2207,2210],{},[20,2208,2209],{},"Evidence retention."," Keep the decision trail for the five to ten years most regulators require.",[11,2212,2213,2214,2217],{},"Stablecoin payments raise the stakes. A wire can be recalled; an on-chain transfer ",[195,2215,2216],{"href":547},"cannot",". Compliance agents that run inline are the only practical way to check a transaction before an irreversible settlement.",[28,2219,2221],{"id":2220},"what-is-the-difference-between-compliance-agents-and-traditional-compliance-software","What is the difference between compliance agents and traditional compliance software?",[11,2223,2224],{},"Traditional compliance software is a system of record and alerting. It ingests transactions, flags the ones that match a rule, and queues them for analysts to review. The software informs; people decide.",[11,2226,2227],{},"Compliance agents invert that division of labor. The agent decides the routine cases and reserves human attention for the exceptions.",[52,2229,2230,2242],{},[55,2231,2232],{},[58,2233,2234,2236,2239],{},[61,2235],{},[61,2237,2238],{},"Compliance agents",[61,2240,2241],{},"Traditional compliance software",[71,2243,2244,2255,2266,2277,2288,2299,2310,2321],{},[58,2245,2246,2249,2252],{},[76,2247,2248],{},"Where it runs",[76,2250,2251],{},"Inside the payment API, before settlement",[76,2253,2254],{},"Alongside the payment system, often in batch",[58,2256,2257,2260,2263],{},[76,2258,2259],{},"Output",[76,2261,2262],{},"A decision: pass, block, or escalate",[76,2264,2265],{},"An alert for a human to review",[58,2267,2268,2271,2274],{},[76,2269,2270],{},"Speed",[76,2272,2273],{},"Milliseconds to minutes, per transaction",[76,2275,2276],{},"Hours to days, per alert queue",[58,2278,2279,2282,2285],{},[76,2280,2281],{},"Human role",[76,2283,2284],{},"Handles escalations and owns the policy",[76,2286,2287],{},"Works every alert, including the obvious ones",[58,2289,2290,2293,2296],{},[76,2291,2292],{},"Integration",[76,2294,2295],{},"Inherited with the payment API",[76,2297,2298],{},"Separate vendor, separate contract, separate integration",[58,2300,2301,2304,2307],{},[76,2302,2303],{},"Audit trail",[76,2305,2306],{},"Written automatically with each decision",[76,2308,2309],{},"Assembled from case notes and system exports",[58,2311,2312,2315,2318],{},[76,2313,2314],{},"Jurisdiction coverage",[76,2316,2317],{},"Rule set selected per customer and country",[76,2319,2320],{},"Usually configured for one primary jurisdiction",[58,2322,2323,2326,2329],{},[76,2324,2325],{},"Scaling cost",[76,2327,2328],{},"Flat per transaction",[76,2330,2331],{},"Grows with analyst headcount",[11,2333,2334],{},"The trade-off is control. Traditional software gives a compliance team full visibility into every rule and every case. Agents require the team to trust the rules, review the escalation rate, and audit decisions by sampling rather than by reviewing each one.",[28,2336,2338],{"id":2337},"how-does-blindpay-use-compliance-agents","How does BlindPay use compliance agents?",[11,2340,2341,2343],{},[195,2342,1153],{"href":1411}," embeds its compliance layer directly in the payment API. There is no separate compliance product to buy, integrate, or keep in sync with the money movement.",[11,2345,2346],{},"When a developer creates a receiver, BlindPay runs KYC or KYB on that entity before it can send or receive funds. When the developer requests a payout, sanctions screening and AML monitoring execute inline, and the payout does not settle until they pass.",[11,2348,2349],{},"What a developer inherits by integrating the API:",[254,2351,2352,2358,2364,2370,2376,2382],{},[257,2353,2354,2357],{},[20,2355,2356],{},"KYC and KYB"," for individuals and businesses, including beneficial owner verification, run at receiver creation.",[257,2359,2360,2363],{},[20,2361,2362],{},"Sanctions screening"," on every counterparty, bank account, and wallet address, at onboarding and at each transaction.",[257,2365,2366,2369],{},[20,2367,2368],{},"AML transaction monitoring"," that watches patterns across the customer's payment history, not just the current payout.",[257,2371,2372,2375],{},[20,2373,2374],{},"Blockchain screening"," on inbound stablecoin deposits to block funds from sanctioned or compromised wallets.",[257,2377,2378,2381],{},[20,2379,2380],{},"Audit logging"," for every decision, retained and available for regulatory review.",[257,2383,2384,2387],{},[20,2385,2386],{},"Multi-jurisdiction rule sets"," covering the countries BlindPay operates in, including Brazil, Mexico, Colombia, Argentina, the US, and the EU.",[11,2389,2390],{},"The developer writes one integration. Compliance state surfaces through the same objects and webhooks used for payments, so a blocked payout looks like any other failed payout with a reason attached.",[11,2392,2393,2394,2396,2397,2399,2400,2404,2405,2408,2409,199],{},"BlindPay holds the licenses and registrations the agents enforce against, listed on the ",[195,2395,198],{"href":197},". The ",[195,2398,297],{"href":296}," describes the full program, and the ",[195,2401,2403],{"href":2402},"\u002Fresources\u002Fmore","resources hub"," has related explainers on ",[195,2406,2407],{"href":217},"what a VASP is"," and how ",[195,2410,2411],{"href":424},"regulation is changing",[2413,2414],"hr",{},[11,2416,2417,2418,199],{},"Compliance agents are autonomous components that run KYC, KYB, sanctions screening, AML monitoring, and audit logging inside the payment flow, deciding routine cases and escalating exceptions. They differ from traditional compliance software by acting on results rather than producing alerts, which is what makes instant, irreversible stablecoin settlement defensible. BlindPay builds this layer into its payment API, so developers inherit global compliance coverage with a single integration. See how it works at ",[195,2419,309],{"href":306,"rel":2420},[308],[11,2422,2423],{},[14,2424,1451],{},{"title":316,"searchDepth":317,"depth":317,"links":2426},[2427,2428,2429,2430,2431],{"id":2061,"depth":317,"text":2062},{"id":2110,"depth":317,"text":2111},{"id":2165,"depth":317,"text":2166},{"id":2220,"depth":317,"text":2221},{"id":2337,"depth":317,"text":2338},"2026-08-12","Compliance agents are autonomous software components that run KYC, KYB, sanctions screening, and transaction monitoring inside a payment flow, then document every decision. How they work, what they do for payments, how they differ from traditional compliance software, and how BlindPay embeds them in its API.",[2435,2438,2441,2444,2447,2450],{"q":2436,"a":2437},"What is a compliance agent in simple terms?","A compliance agent is software that performs a regulatory check on its own, decides whether a payment or customer passes, and records why. It replaces a human analyst for routine work and hands the unusual cases to one.",{"q":2439,"a":2440},"Do compliance agents replace a compliance officer?","No. Agents handle volume: document checks, list screening, and routine alert review. A compliance officer still owns the policy, approves high-risk decisions, and answers to the regulator.",{"q":2442,"a":2443},"Are compliance agents the same as AI?","Not always. Many agents combine deterministic rules with machine learning for document reading, entity matching, and anomaly detection. The defining feature is autonomous action inside a workflow, not the model behind it.",{"q":2445,"a":2446},"How fast do compliance agents make a decision?","Sanctions screening and transaction monitoring return in milliseconds, so they run inline before a payment settles. Identity verification takes seconds to a few minutes when a document must be read and matched to a face or a registry.",{"q":2448,"a":2449},"Can compliance agents work across multiple countries?","Yes, if the provider maintains rules and data sources per jurisdiction. The same agent screens a Brazilian company against Central Bank requirements and a US company against FinCEN and OFAC requirements, using the rule set that applies to each.",{"q":2451,"a":2452},"How does BlindPay handle compliance for developers?","Compliance runs inside the BlindPay payment API. When a developer creates a receiver or a payout, KYC or KYB, sanctions screening, AML monitoring, and audit logging execute automatically, with no separate compliance vendor to integrate.",{"author":358},"\u002Fresources\u002Fmore\u002Fwhat-are-compliance-agents-in-fintech","---\ntitle: \"What are compliance agents in fintech? How they work and what they do for payments\"\ndescription: \"Compliance agents are autonomous software components that run KYC, KYB, sanctions screening, and transaction monitoring inside a payment flow, then document every decision. How they work, what they do for payments, how they differ from traditional compliance software, and how BlindPay embeds them in its API.\"\ndate: \"2026-08-12\"\nupdated: \"2026-08-12\"\nauthor: \"BlindPay Team\"\ncategory: \"compliance\"\nfaq:\n  - q: \"What is a compliance agent in simple terms?\"\n    a: \"A compliance agent is software that performs a regulatory check on its own, decides whether a payment or customer passes, and records why. It replaces a human analyst for routine work and hands the unusual cases to one.\"\n  - q: \"Do compliance agents replace a compliance officer?\"\n    a: \"No. Agents handle volume: document checks, list screening, and routine alert review. A compliance officer still owns the policy, approves high-risk decisions, and answers to the regulator.\"\n  - q: \"Are compliance agents the same as AI?\"\n    a: \"Not always. Many agents combine deterministic rules with machine learning for document reading, entity matching, and anomaly detection. The defining feature is autonomous action inside a workflow, not the model behind it.\"\n  - q: \"How fast do compliance agents make a decision?\"\n    a: \"Sanctions screening and transaction monitoring return in milliseconds, so they run inline before a payment settles. Identity verification takes seconds to a few minutes when a document must be read and matched to a face or a registry.\"\n  - q: \"Can compliance agents work across multiple countries?\"\n    a: \"Yes, if the provider maintains rules and data sources per jurisdiction. The same agent screens a Brazilian company against Central Bank requirements and a US company against FinCEN and OFAC requirements, using the rule set that applies to each.\"\n  - q: \"How does BlindPay handle compliance for developers?\"\n    a: \"Compliance runs inside the BlindPay payment API. When a developer creates a receiver or a payout, KYC or KYB, sanctions screening, AML monitoring, and audit logging execute automatically, with no separate compliance vendor to integrate.\"\n---\n\n*Reading time: about 7 minutes.*\n\n**Summary:** Compliance agents are autonomous software components that execute regulatory checks inside a payment flow. They verify identities (KYC and KYB), screen counterparties against sanctions lists, monitor transactions for money laundering patterns, and write an audit record for every decision. Unlike traditional compliance software, which produces alerts for humans to work, compliance agents act on the result and escalate only the cases that need judgment.\n\n## What are compliance agents in fintech?\n\nA compliance agent is a piece of software that owns one regulatory task end to end: it gathers the inputs, applies the rules, reaches a decision, and records the evidence. The word \"agent\" signals that it acts rather than reports.\n\nIn a payments company, compliance agents sit between the request to move money and the movement itself. A payout does not settle until the relevant agents return a pass.\n\nMost fintech compliance programs decompose into a small set of agents, each mapped to a regulatory obligation:\n\n- **Identity agent.** Runs KYC on individuals and [KYB](\u002Fresources\u002Fmore\u002Fwhat-is-kyb) on businesses, reading documents, matching them to registries, and verifying beneficial owners.\n- **Sanctions agent.** Screens names, addresses, wallet addresses, and bank accounts against OFAC, UN, EU, and local lists, and resolves fuzzy matches.\n- **Monitoring agent.** Watches transaction patterns for structuring, velocity spikes, and counterparties that do not fit the customer's stated profile.\n- **Blockchain screening agent.** Traces the source of on-chain funds and blocks deposits linked to mixers, hacks, or sanctioned wallets.\n- **Audit agent.** Stores the inputs, the rule version, the decision, and the timestamp for every check so a regulator can reconstruct it later.\n\n## How do compliance agents work?\n\nCompliance agents run a loop: observe, decide, act, record. Each step is deterministic enough to audit and fast enough to run before a payment settles.\n\n1. **Trigger.** An event in the payment system fires the agent: a new customer, a new bank account, a payout request, or an on-chain deposit.\n2. **Collect.** The agent pulls what it needs: uploaded documents, registry data, list feeds, transaction history, and blockchain analytics.\n3. **Evaluate.** It applies the rule set for the customer's jurisdiction and risk tier. Rules can be deterministic thresholds, machine learning scores, or both.\n4. **Decide.** The output is one of three states: pass, block, or escalate to a human reviewer.\n5. **Act.** A pass lets the payment proceed. A block stops it and notifies the customer. An escalation opens a case with the evidence already attached.\n6. **Record.** Every input and decision is written to an immutable log tied to the transaction ID.\n\nThe escalation path is what separates a well-designed agent from a black box. The agent does not guess on ambiguous cases; it routes them to a person with the file already assembled.\n\nRule sets change by jurisdiction. A single agent may hold one policy for Brazilian virtual asset service providers, another for US money transmitters, and a third for [MiCA](\u002Fresources\u002Fmore\u002Fmica-stablecoin-rules-explained) in the EU, selecting the right one from the customer's country and entity type.\n\n## What do compliance agents do for payments?\n\nFor a payments company, compliance agents turn a set of legal obligations into checks that execute on every transaction without slowing it down. They are the reason a cross-border payout can be both instant and defensible.\n\nThe concrete jobs are:\n\n- **Onboarding.** Verify the sender and the receiver before the first payment, so the money never touches an unverified account.\n- **Pre-settlement screening.** Screen every payout against sanctions lists at the moment it is created, not in a nightly batch, because a stablecoin transfer is final once confirmed.\n- **Ongoing monitoring.** Re-screen existing customers as lists update and flag transaction patterns that drift from the profile established at onboarding.\n- **Source-of-funds checks.** Trace inbound stablecoin deposits to confirm they did not originate from a sanctioned or hacked wallet.\n- **Regulatory reporting.** Assemble suspicious activity reports and threshold reports from the audit log instead of from analyst memory.\n- **Evidence retention.** Keep the decision trail for the five to ten years most regulators require.\n\nStablecoin payments raise the stakes. A wire can be recalled; an on-chain transfer [cannot](\u002Fresources\u002Fmore\u002Fare-stablecoin-payments-reversible). Compliance agents that run inline are the only practical way to check a transaction before an irreversible settlement.\n\n## What is the difference between compliance agents and traditional compliance software?\n\nTraditional compliance software is a system of record and alerting. It ingests transactions, flags the ones that match a rule, and queues them for analysts to review. The software informs; people decide.\n\nCompliance agents invert that division of labor. The agent decides the routine cases and reserves human attention for the exceptions.\n\n| | Compliance agents | Traditional compliance software |\n| --- | --- | --- |\n| Where it runs | Inside the payment API, before settlement | Alongside the payment system, often in batch |\n| Output | A decision: pass, block, or escalate | An alert for a human to review |\n| Speed | Milliseconds to minutes, per transaction | Hours to days, per alert queue |\n| Human role | Handles escalations and owns the policy | Works every alert, including the obvious ones |\n| Integration | Inherited with the payment API | Separate vendor, separate contract, separate integration |\n| Audit trail | Written automatically with each decision | Assembled from case notes and system exports |\n| Jurisdiction coverage | Rule set selected per customer and country | Usually configured for one primary jurisdiction |\n| Scaling cost | Flat per transaction | Grows with analyst headcount |\n\nThe trade-off is control. Traditional software gives a compliance team full visibility into every rule and every case. Agents require the team to trust the rules, review the escalation rate, and audit decisions by sampling rather than by reviewing each one.\n\n## How does BlindPay use compliance agents?\n\n[BlindPay](\u002Fglobal-payments) embeds its compliance layer directly in the payment API. There is no separate compliance product to buy, integrate, or keep in sync with the money movement.\n\nWhen a developer creates a receiver, BlindPay runs KYC or KYB on that entity before it can send or receive funds. When the developer requests a payout, sanctions screening and AML monitoring execute inline, and the payout does not settle until they pass.\n\nWhat a developer inherits by integrating the API:\n\n- **KYC and KYB** for individuals and businesses, including beneficial owner verification, run at receiver creation.\n- **Sanctions screening** on every counterparty, bank account, and wallet address, at onboarding and at each transaction.\n- **AML transaction monitoring** that watches patterns across the customer's payment history, not just the current payout.\n- **Blockchain screening** on inbound stablecoin deposits to block funds from sanctioned or compromised wallets.\n- **Audit logging** for every decision, retained and available for regulatory review.\n- **Multi-jurisdiction rule sets** covering the countries BlindPay operates in, including Brazil, Mexico, Colombia, Argentina, the US, and the EU.\n\nThe developer writes one integration. Compliance state surfaces through the same objects and webhooks used for payments, so a blocked payout looks like any other failed payout with a reason attached.\n\nBlindPay holds the licenses and registrations the agents enforce against, listed on the [licenses page](\u002Flicenses). The [compliance page](\u002Fcompliance) describes the full program, and the [resources hub](\u002Fresources\u002Fmore) has related explainers on [what a VASP is](\u002Fresources\u002Fmore\u002Fwhat-is-a-vasp) and how [regulation is changing](\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026).\n\n---\n\nCompliance agents are autonomous components that run KYC, KYB, sanctions screening, AML monitoring, and audit logging inside the payment flow, deciding routine cases and escalating exceptions. They differ from traditional compliance software by acting on results rather than producing alerts, which is what makes instant, irreversible stablecoin settlement defensible. BlindPay builds this layer into its payment API, so developers inherit global compliance coverage with a single integration. See how it works at [blindpay.com](https:\u002F\u002Fblindpay.com).\n\n*This article is general information, not legal, tax, or financial advice.*\n",{"title":2046,"description":2433},"resources\u002Fmore\u002Fwhat-are-compliance-agents-in-fintech","FPbTJeGNtN_S_5OGsQePNHH5whktVkxHhgHgV940vhQ",{"id":2460,"title":2461,"authors":6,"body":2462,"categories":6,"category":333,"categoryType":6,"compare":6,"contributors":6,"date":525,"description":2579,"extension":336,"faq":2580,"howto":6,"isBlog":356,"isChangelog":356,"meta":2592,"navigation":359,"path":229,"pillar":356,"products":6,"rawbody":2593,"seo":2594,"stem":2595,"thumbnail":6,"updated":525,"__hash__":2596},"content\u002Fresources\u002Fmore\u002Fwhat-is-kyb.md","What is KYB? Know Your Business verification explained",{"type":8,"value":2463,"toc":2572},[2464,2467,2470,2474,2477,2503,2506,2510,2518,2521,2525,2528,2531,2535,2547,2549,2568],[11,2465,2466],{},"KYB, Know Your Business, verifies that a company legally exists, confirms who owns and controls it, and screens those individuals before the company is allowed to send or receive money. It is the business-side counterpart to KYC: a payment provider cannot know whether it is safe to pay a company without first knowing who actually stands behind it.",[11,2468,2469],{},"KYB exists because a shell company is an easy way to hide who is really moving money. A registered business name and a bank account look legitimate on the surface; the ownership and control behind them are where risk actually lives, which is why regulators require providers to look past the entity to the humans running it.",[28,2471,2473],{"id":2472},"what-does-kyb-actually-verify","What does KYB actually verify?",[11,2475,2476],{},"A complete KYB check covers four layers:",[254,2478,2479,2485,2491,2497],{},[257,2480,2481,2484],{},[20,2482,2483],{},"Legal existence."," Confirming the company is registered, active, and in good standing with the relevant corporate registry, not dissolved or dormant.",[257,2486,2487,2490],{},[20,2488,2489],{},"Ownership structure."," Mapping who owns what percentage of the company, including through holding companies or trusts, until it reaches actual people.",[257,2492,2493,2496],{},[20,2494,2495],{},"Beneficial owners."," Identifying and verifying the individuals who meet the ownership or control threshold, then running standard identity and sanctions checks on each of them.",[257,2498,2499,2502],{},[20,2500,2501],{},"Business activity."," Confirming the company's stated business matches what it actually does, since a mismatch between registered activity and real transaction patterns is a common fraud and money laundering signal.",[11,2504,2505],{},"Skipping any layer leaves a gap. A provider that checks only registration, without tracing ownership to real people, can end up doing business with a company controlled by someone on a sanctions list.",[28,2507,2509],{"id":2508},"who-counts-as-a-beneficial-owner","Who counts as a beneficial owner?",[11,2511,2512,2513,199],{},"The clearest definition comes from FinCEN's Customer Due Diligence rule, built on two prongs. The ownership prong: any individual who, \"directly or indirectly, through any contract, arrangement, understanding, relationship or otherwise, owns 25 percent or more of the equity interests of a legal entity customer.\" The control prong: at least one individual with \"significant responsibility to control, manage, or direct\" the entity, such as a CEO, CFO, or managing member, regardless of ownership percentage. Full detail is in ",[195,2514,2517],{"href":2515,"rel":2516},"https:\u002F\u002Fwww.ecfr.gov\u002Fcurrent\u002Ftitle-31\u002Fsubtitle-B\u002Fchapter-X\u002Fpart-1010\u002Fsubpart-C\u002Fsection-1010.230",[308],"31 CFR 1010.230(d)",[11,2519,2520],{},"That two-prong structure exists because ownership alone misses control. A company can be owned by a diffuse group of investors, none crossing 25 percent, while one individual runs every decision. The control prong catches that person even when the ownership math would not.",[28,2522,2524],{"id":2523},"how-is-kyb-different-from-kyc","How is KYB different from KYC?",[11,2526,2527],{},"KYC (Know Your Customer) verifies one individual: identity documents, address, and screening against sanctions and watchlists. KYB verifies a legal entity and then applies KYC to the people who own or control it. Opening a business account almost always triggers both: KYB on the company, KYC on each beneficial owner and often on signers and directors too.",[11,2529,2530],{},"The practical difference shows up in documentation. KYC needs a passport or ID and a selfie. KYB needs incorporation documents, a certificate of good standing, an ownership chart, and identity documents for every beneficial owner identified along the way, which is why KYB usually takes longer and involves more back-and-forth than an individual signup.",[28,2532,2534],{"id":2533},"when-does-a-payments-company-require-kyb","When does a payments company require KYB?",[11,2536,2537,2538,2540,2541,2544,2545,199],{},"Any time a business, not an individual, is the account holder or the counterparty receiving payment above a threshold set by the provider's risk policy. Marketplaces onboarding seller accounts, platforms paying out to vendor companies rather than individual contractors, and any B2B cross-border payment all trigger KYB somewhere in the flow. Our ",[195,2539,488],{"href":487}," covers where compliance checks like KYB sit inside a payout flow, and the broader VASP licensing context that requires programs like this is in ",[195,2542,2543],{"href":217},"what is a VASP",". Requirements also shift as rules like MiCA and the GENIUS Act take effect, tracked in our ",[195,2546,1033],{"href":424},[28,2548,1144],{"id":1143},[11,2550,2551,2553,2554,2556,2557,2559,2560,2563,2564,2567],{},[195,2552,1153],{"href":1411}," runs KYB on every business account before it can send or receive a payout: entity verification, ownership mapping, beneficial owner screening, and sanctions checks, built into the same API used to move USDC and USDT over local rails like Pix and SPEI. The ",[195,2555,297],{"href":296}," covers the full program, and the ",[195,2558,2403],{"href":2402}," has more on how the pieces fit together, including ",[195,2561,2562],{"href":386},"what a stablecoin API does"," end to end and ",[195,2565,2566],{"href":1193},"how to automate KYC and KYB"," inside a payment flow.",[11,2569,2570],{},[14,2571,314],{},{"title":316,"searchDepth":317,"depth":317,"links":2573},[2574,2575,2576,2577,2578],{"id":2472,"depth":317,"text":2473},{"id":2508,"depth":317,"text":2509},{"id":2523,"depth":317,"text":2524},{"id":2533,"depth":317,"text":2534},{"id":1143,"depth":317,"text":1144},"KYB verifies a company's legal existence, ownership, and control before it can transact. What it checks, who counts as a beneficial owner, and how it differs from KYC.",[2581,2584,2587,2589],{"q":2582,"a":2583},"What does KYB stand for?","Know Your Business. It is the process of verifying a company's legal existence, ownership structure, and the individuals who own or control it before that company is allowed to open an account or transact.",{"q":2585,"a":2586},"What is a beneficial owner?","Under FinCEN's rule, an individual who directly or indirectly owns 25 percent or more of a legal entity's equity, or who controls and directs it, such as a CEO or managing member. A company can have several beneficial owners.",{"q":2524,"a":2588},"KYC verifies an individual person. KYB verifies a company, and then applies KYC-style checks to the individuals who own or control that company. A business account almost always requires both.",{"q":2590,"a":2591},"How long does KYB take?","With registry data available and clean documents, minutes to same-day. It slows down for entities with layered ownership, trusts, or jurisdictions where corporate registries are not digitized, sometimes taking days.",{"author":358},"---\ntitle: \"What is KYB? Know Your Business verification explained\"\ndescription: \"KYB verifies a company's legal existence, ownership, and control before it can transact. What it checks, who counts as a beneficial owner, and how it differs from KYC.\"\ndate: \"2026-09-01\"\nauthor: \"BlindPay Team\"\nupdated: \"2026-09-01\"\ncategory: \"compliance\"\nfaq:\n  - q: \"What does KYB stand for?\"\n    a: \"Know Your Business. It is the process of verifying a company's legal existence, ownership structure, and the individuals who own or control it before that company is allowed to open an account or transact.\"\n  - q: \"What is a beneficial owner?\"\n    a: \"Under FinCEN's rule, an individual who directly or indirectly owns 25 percent or more of a legal entity's equity, or who controls and directs it, such as a CEO or managing member. A company can have several beneficial owners.\"\n  - q: \"How is KYB different from KYC?\"\n    a: \"KYC verifies an individual person. KYB verifies a company, and then applies KYC-style checks to the individuals who own or control that company. A business account almost always requires both.\"\n  - q: \"How long does KYB take?\"\n    a: \"With registry data available and clean documents, minutes to same-day. It slows down for entities with layered ownership, trusts, or jurisdictions where corporate registries are not digitized, sometimes taking days.\"\n---\n\nKYB, Know Your Business, verifies that a company legally exists, confirms who owns and controls it, and screens those individuals before the company is allowed to send or receive money. It is the business-side counterpart to KYC: a payment provider cannot know whether it is safe to pay a company without first knowing who actually stands behind it.\n\nKYB exists because a shell company is an easy way to hide who is really moving money. A registered business name and a bank account look legitimate on the surface; the ownership and control behind them are where risk actually lives, which is why regulators require providers to look past the entity to the humans running it.\n\n## What does KYB actually verify?\n\nA complete KYB check covers four layers:\n\n- **Legal existence.** Confirming the company is registered, active, and in good standing with the relevant corporate registry, not dissolved or dormant.\n- **Ownership structure.** Mapping who owns what percentage of the company, including through holding companies or trusts, until it reaches actual people.\n- **Beneficial owners.** Identifying and verifying the individuals who meet the ownership or control threshold, then running standard identity and sanctions checks on each of them.\n- **Business activity.** Confirming the company's stated business matches what it actually does, since a mismatch between registered activity and real transaction patterns is a common fraud and money laundering signal.\n\nSkipping any layer leaves a gap. A provider that checks only registration, without tracing ownership to real people, can end up doing business with a company controlled by someone on a sanctions list.\n\n## Who counts as a beneficial owner?\n\nThe clearest definition comes from FinCEN's Customer Due Diligence rule, built on two prongs. The ownership prong: any individual who, \"directly or indirectly, through any contract, arrangement, understanding, relationship or otherwise, owns 25 percent or more of the equity interests of a legal entity customer.\" The control prong: at least one individual with \"significant responsibility to control, manage, or direct\" the entity, such as a CEO, CFO, or managing member, regardless of ownership percentage. Full detail is in [31 CFR 1010.230(d)](https:\u002F\u002Fwww.ecfr.gov\u002Fcurrent\u002Ftitle-31\u002Fsubtitle-B\u002Fchapter-X\u002Fpart-1010\u002Fsubpart-C\u002Fsection-1010.230).\n\nThat two-prong structure exists because ownership alone misses control. A company can be owned by a diffuse group of investors, none crossing 25 percent, while one individual runs every decision. The control prong catches that person even when the ownership math would not.\n\n## How is KYB different from KYC?\n\nKYC (Know Your Customer) verifies one individual: identity documents, address, and screening against sanctions and watchlists. KYB verifies a legal entity and then applies KYC to the people who own or control it. Opening a business account almost always triggers both: KYB on the company, KYC on each beneficial owner and often on signers and directors too.\n\nThe practical difference shows up in documentation. KYC needs a passport or ID and a selfie. KYB needs incorporation documents, a certificate of good standing, an ownership chart, and identity documents for every beneficial owner identified along the way, which is why KYB usually takes longer and involves more back-and-forth than an individual signup.\n\n## When does a payments company require KYB?\n\nAny time a business, not an individual, is the account holder or the counterparty receiving payment above a threshold set by the provider's risk policy. Marketplaces onboarding seller accounts, platforms paying out to vendor companies rather than individual contractors, and any B2B cross-border payment all trigger KYB somewhere in the flow. Our [stablecoin payments guide](\u002Fresources\u002Fmore\u002Fstablecoin-payments-guide) covers where compliance checks like KYB sit inside a payout flow, and the broader VASP licensing context that requires programs like this is in [what is a VASP](\u002Fresources\u002Fmore\u002Fwhat-is-a-vasp). Requirements also shift as rules like MiCA and the GENIUS Act take effect, tracked in our [regulation tracker](\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026).\n\n## How does BlindPay fit in?\n\n[BlindPay](\u002Fglobal-payments) runs KYB on every business account before it can send or receive a payout: entity verification, ownership mapping, beneficial owner screening, and sanctions checks, built into the same API used to move USDC and USDT over local rails like Pix and SPEI. The [compliance page](\u002Fcompliance) covers the full program, and the [resources hub](\u002Fresources\u002Fmore) has more on how the pieces fit together, including [what a stablecoin API does](\u002Fresources\u002Fmore\u002Fwhat-is-a-stablecoin-api) end to end and [how to automate KYC and KYB](\u002Fresources\u002Fmore\u002Fhow-to-automate-kyc-kyb-stablecoin-payments) inside a payment flow.\n\n*This article is for general information only and is not legal, tax, or financial advice.*\n",{"title":2461,"description":2579},"resources\u002Fmore\u002Fwhat-is-kyb","RcvaaKuDOppww4h3x2ONBAduPxrnzi1WiqrYTD4VgIw",{"id":2598,"title":2599,"authors":6,"body":2600,"categories":6,"category":333,"categoryType":6,"compare":6,"contributors":6,"date":525,"description":2727,"extension":336,"faq":2728,"howto":6,"isBlog":356,"isChangelog":356,"meta":2740,"navigation":359,"path":217,"pillar":356,"products":6,"rawbody":2741,"seo":2742,"stem":2743,"thumbnail":6,"updated":525,"__hash__":2744},"content\u002Fresources\u002Fmore\u002Fwhat-is-a-vasp.md","What is a VASP? Virtual asset service provider explained",{"type":8,"value":2601,"toc":2720},[2602,2605,2608,2612,2615,2647,2659,2663,2666,2672,2676,2688,2691,2695,2701,2703,2716],[11,2603,2604],{},"A VASP, virtual asset service provider, is any business that exchanges, transfers, custodies, or safeguards virtual assets like stablecoins on behalf of customers. FATF, the intergovernmental body that sets global anti-money laundering standards, created the category in 2019 to pull crypto and stablecoin companies under the same AML rules banks already follow.",[11,2606,2607],{},"The category matters because it decides who needs a license. If a company's activity fits FATF's VASP definition, the countries it operates in expect registration, AML controls, and reporting, the same obligations a bank or money transmitter carries, not a lighter version built for crypto.",[28,2609,2611],{"id":2610},"what-activities-make-a-company-a-vasp","What activities make a company a VASP?",[11,2613,2614],{},"FATF Recommendation 15 defines a VASP as any natural or legal person who, as a business, conducts one or more of the following on behalf of another person:",[254,2616,2617,2623,2629,2635,2641],{},[257,2618,2619,2622],{},[20,2620,2621],{},"Exchange between virtual assets and fiat currency."," Converting crypto or stablecoins to dollars, reais, or any other fiat currency, and back.",[257,2624,2625,2628],{},[20,2626,2627],{},"Exchange between forms of virtual assets."," Swapping one token for another, including stablecoin pairs.",[257,2630,2631,2634],{},[20,2632,2633],{},"Transfer of virtual assets."," Moving a virtual asset from one address or account to another on behalf of a customer.",[257,2636,2637,2640],{},[20,2638,2639],{},"Safekeeping or administration."," Custodying virtual assets or the instruments that control them, such as private keys.",[257,2642,2643,2646],{},[20,2644,2645],{},"Participation in financial services related to an issuer's offer or sale of a virtual asset."," Involvement in a token issuance or sale, such as underwriting or distribution.",[11,2648,2649,2650,2654,2655,2658],{},"Classification is activity-based: a company doing any one of these as a business, for someone else, is a VASP, regardless of what it calls itself. A stablecoin off-ramp that converts USDC to reais sits directly in the first category; background on that specific flow is in ",[195,2651,2653],{"href":2652},"\u002Fresources\u002Fmore\u002Fwhat-is-a-stablecoin-offramp","what is a stablecoin off-ramp",". Most VASPs package these activities behind a ",[195,2656,2657],{"href":386},"stablecoin API"," rather than exposing raw wallets and exchange rails.",[28,2660,2662],{"id":2661},"who-has-to-register-or-license-as-a-vasp","Who has to register or license as a VASP?",[11,2664,2665],{},"Any business performing the activities above, in a jurisdiction that has implemented Recommendation 15. That covers most of the world's major markets by now, since FATF membership and mutual evaluation pressure pushed adoption broadly through the early 2020s. The details, though, are set by each country individually: registration with a financial intelligence unit in some places, a full authorization regime with capital and governance requirements in others.",[11,2667,2668,2669,199],{},"Brazil is a concrete example worth studying because the rules are recent and specific: the Banco Central do Brasil built its PSAV authorization directly on the FATF categories, requiring companies that exchange, transfer, or custody virtual assets for Brazilian customers to obtain a license under Resolutions 519, 520, and 521. The full breakdown is in our ",[195,2670,2671],{"href":1708},"PSAV explainer",[28,2673,2675],{"id":2674},"what-does-vasp-status-require-in-practice","What does VASP status require in practice?",[11,2677,2678,2679,2681,2682,2684,2685,2687],{},"Once a company is classified as a VASP, the recurring obligations look similar everywhere: customer identification and KYC on individuals, ",[195,2680,2082],{"href":229}," on business customers, sanctions and watchlist screening, transaction monitoring for suspicious activity, and increasingly the travel rule, which requires sharing sender and receiver information on transfers above a threshold, the same way a wire transfer carries originator data today. How the travel rule and sanctions screening work across jurisdictions is covered in our ",[195,2683,1944],{"href":360},". Our ",[195,2686,488],{"href":487}," covers how these checks sit inside an actual payout.",[11,2689,2690],{},"None of this is optional once the activity test is met. A company that calls itself a \"technology platform\" rather than a payment provider is still a VASP if it exchanges or transfers virtual assets for customers; regulators evaluate the activity, not the label on the pitch deck.",[28,2692,2694],{"id":2693},"how-does-vasp-regulation-differ-by-country","How does VASP regulation differ by country?",[11,2696,2697,2698,2700],{},"The activities FATF defines are consistent; the implementation is not. The EU folds virtual asset services into MiCA's authorization regime. The US applies its existing money transmitter and money services business framework, state by state, to the same activities. Brazil built a dedicated PSAV license from scratch in 2025. Details on how these regimes compare are in our ",[195,2699,425],{"href":424},". A company operating across borders typically needs a different license, or license-equivalent, in each market it serves, which is one reason global stablecoin payment coverage is hard to build and harder to fake.",[28,2702,1144],{"id":1143},[11,2704,2705,2707,2708,2710,2711,2713,2714,199],{},[195,2706,1153],{"href":1411}," operates as a licensed entity in the markets it serves, including as a VASP-equivalent authorized provider in Brazil under the transitional PSAV regime, with KYC, KYB, sanctions screening, and travel rule handling built into every payout. Entity and license details by market are published on the ",[195,2709,198],{"href":197},", and how the full compliance program runs is on the ",[195,2712,297],{"href":296},". More on the mechanics behind the API is in the ",[195,2715,2403],{"href":2402},[11,2717,2718],{},[14,2719,314],{},{"title":316,"searchDepth":317,"depth":317,"links":2721},[2722,2723,2724,2725,2726],{"id":2610,"depth":317,"text":2611},{"id":2661,"depth":317,"text":2662},{"id":2674,"depth":317,"text":2675},{"id":2693,"depth":317,"text":2694},{"id":1143,"depth":317,"text":1144},"A VASP is any business that exchanges, transfers, or custodies virtual assets like stablecoins for customers. FATF's definition and what it requires in practice.",[2729,2732,2734,2737],{"q":2730,"a":2731},"What does VASP stand for?","Virtual Asset Service Provider. FATF, the global anti-money laundering standard setter, uses the term to define any business that handles virtual assets, including stablecoins, on behalf of customers.",{"q":2611,"a":2733},"Exchanging virtual assets for fiat, exchanging one virtual asset for another, transferring virtual assets, safekeeping or administering them, or participating in financial services tied to an issuer's offer or sale of a virtual asset. Doing any one of these as a business, for someone else, is enough.",{"q":2735,"a":2736},"Does a stablecoin payments company count as a VASP?","Yes, in almost every case. Converting stablecoins to fiat and transferring them for customers falls squarely under the exchange and transfer categories, which is why payment providers built on stablecoins need VASP-equivalent licenses wherever they operate.",{"q":2738,"a":2739},"Is VASP regulation the same in every country?","No. FATF sets the standard, but each country implements it through its own law. Brazil's PSAV, the EU's MiCA authorization, and US state money transmitter licenses are three different implementations of roughly the same underlying activities.",{"author":358},"---\ntitle: \"What is a VASP? Virtual asset service provider explained\"\ndescription: \"A VASP is any business that exchanges, transfers, or custodies virtual assets like stablecoins for customers. FATF's definition and what it requires in practice.\"\ndate: \"2026-09-01\"\nauthor: \"BlindPay Team\"\nupdated: \"2026-09-01\"\ncategory: \"compliance\"\nfaq:\n  - q: \"What does VASP stand for?\"\n    a: \"Virtual Asset Service Provider. FATF, the global anti-money laundering standard setter, uses the term to define any business that handles virtual assets, including stablecoins, on behalf of customers.\"\n  - q: \"What activities make a company a VASP?\"\n    a: \"Exchanging virtual assets for fiat, exchanging one virtual asset for another, transferring virtual assets, safekeeping or administering them, or participating in financial services tied to an issuer's offer or sale of a virtual asset. Doing any one of these as a business, for someone else, is enough.\"\n  - q: \"Does a stablecoin payments company count as a VASP?\"\n    a: \"Yes, in almost every case. Converting stablecoins to fiat and transferring them for customers falls squarely under the exchange and transfer categories, which is why payment providers built on stablecoins need VASP-equivalent licenses wherever they operate.\"\n  - q: \"Is VASP regulation the same in every country?\"\n    a: \"No. FATF sets the standard, but each country implements it through its own law. Brazil's PSAV, the EU's MiCA authorization, and US state money transmitter licenses are three different implementations of roughly the same underlying activities.\"\n---\n\nA VASP, virtual asset service provider, is any business that exchanges, transfers, custodies, or safeguards virtual assets like stablecoins on behalf of customers. FATF, the intergovernmental body that sets global anti-money laundering standards, created the category in 2019 to pull crypto and stablecoin companies under the same AML rules banks already follow.\n\nThe category matters because it decides who needs a license. If a company's activity fits FATF's VASP definition, the countries it operates in expect registration, AML controls, and reporting, the same obligations a bank or money transmitter carries, not a lighter version built for crypto.\n\n## What activities make a company a VASP?\n\nFATF Recommendation 15 defines a VASP as any natural or legal person who, as a business, conducts one or more of the following on behalf of another person:\n\n- **Exchange between virtual assets and fiat currency.** Converting crypto or stablecoins to dollars, reais, or any other fiat currency, and back.\n- **Exchange between forms of virtual assets.** Swapping one token for another, including stablecoin pairs.\n- **Transfer of virtual assets.** Moving a virtual asset from one address or account to another on behalf of a customer.\n- **Safekeeping or administration.** Custodying virtual assets or the instruments that control them, such as private keys.\n- **Participation in financial services related to an issuer's offer or sale of a virtual asset.** Involvement in a token issuance or sale, such as underwriting or distribution.\n\nClassification is activity-based: a company doing any one of these as a business, for someone else, is a VASP, regardless of what it calls itself. A stablecoin off-ramp that converts USDC to reais sits directly in the first category; background on that specific flow is in [what is a stablecoin off-ramp](\u002Fresources\u002Fmore\u002Fwhat-is-a-stablecoin-offramp). Most VASPs package these activities behind a [stablecoin API](\u002Fresources\u002Fmore\u002Fwhat-is-a-stablecoin-api) rather than exposing raw wallets and exchange rails.\n\n## Who has to register or license as a VASP?\n\nAny business performing the activities above, in a jurisdiction that has implemented Recommendation 15. That covers most of the world's major markets by now, since FATF membership and mutual evaluation pressure pushed adoption broadly through the early 2020s. The details, though, are set by each country individually: registration with a financial intelligence unit in some places, a full authorization regime with capital and governance requirements in others.\n\nBrazil is a concrete example worth studying because the rules are recent and specific: the Banco Central do Brasil built its PSAV authorization directly on the FATF categories, requiring companies that exchange, transfer, or custody virtual assets for Brazilian customers to obtain a license under Resolutions 519, 520, and 521. The full breakdown is in our [PSAV explainer](\u002Fresources\u002Fmore\u002Fpsav-brazil-explained).\n\n## What does VASP status require in practice?\n\nOnce a company is classified as a VASP, the recurring obligations look similar everywhere: customer identification and KYC on individuals, [KYB](\u002Fresources\u002Fmore\u002Fwhat-is-kyb) on business customers, sanctions and watchlist screening, transaction monitoring for suspicious activity, and increasingly the travel rule, which requires sharing sender and receiver information on transfers above a threshold, the same way a wire transfer carries originator data today. How the travel rule and sanctions screening work across jurisdictions is covered in our [cross-border compliance guide](\u002Fresources\u002Fmore\u002Fcompliance-agents-cross-border-stablecoin-payments). Our [stablecoin payments guide](\u002Fresources\u002Fmore\u002Fstablecoin-payments-guide) covers how these checks sit inside an actual payout.\n\nNone of this is optional once the activity test is met. A company that calls itself a \"technology platform\" rather than a payment provider is still a VASP if it exchanges or transfers virtual assets for customers; regulators evaluate the activity, not the label on the pitch deck.\n\n## How does VASP regulation differ by country?\n\nThe activities FATF defines are consistent; the implementation is not. The EU folds virtual asset services into MiCA's authorization regime. The US applies its existing money transmitter and money services business framework, state by state, to the same activities. Brazil built a dedicated PSAV license from scratch in 2025. Details on how these regimes compare are in our [stablecoin regulation tracker](\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026). A company operating across borders typically needs a different license, or license-equivalent, in each market it serves, which is one reason global stablecoin payment coverage is hard to build and harder to fake.\n\n## How does BlindPay fit in?\n\n[BlindPay](\u002Fglobal-payments) operates as a licensed entity in the markets it serves, including as a VASP-equivalent authorized provider in Brazil under the transitional PSAV regime, with KYC, KYB, sanctions screening, and travel rule handling built into every payout. Entity and license details by market are published on the [licenses page](\u002Flicenses), and how the full compliance program runs is on the [compliance page](\u002Fcompliance). More on the mechanics behind the API is in the [resources hub](\u002Fresources\u002Fmore).\n\n*This article is for general information only and is not legal, tax, or financial advice.*\n",{"title":2599,"description":2727},"resources\u002Fmore\u002Fwhat-is-a-vasp","Gwln3ExV0K_L3zpCNm9AVy-916hEV9QvDFLqsu7jkNc",1789051990420]