What compliance stablecoin card issuing requires: KYC vs. KYB, who is responsible for what, how rules differ in the US, EU, UK, and Latin America, and ongoing monitoring.
Reading time: about 8 minutes.
Summary: At minimum, issuing stablecoin-funded cards requires a licensed bank or e-money institution as BIN sponsor, KYC on every cardholder, KYB on every business in the program, sanctions screening on people and wallet addresses, transaction monitoring on card and on-chain activity, and a written AML program. Stablecoin rules add to card rules. They do not replace them.
That last sentence is the one to bring to a risk committee. A stablecoin card program is a card program first, subject to everything a traditional program is, plus a virtual asset layer with its own regulators.
This guide is written for compliance officers, legal and risk teams, and founders who need to explain the program to a bank partner or a regulator. For the product basics, read what stablecoin card issuing is.
Every company in the stack carries part of the obligation. Knowing who owns which part is the first thing an examiner will ask.
| Party | Main compliance duties |
|---|---|
| Card network (Visa, Mastercard) | Program rules, brand protection standards, dispute rules |
| Issuing bank or BIN sponsor | Legal issuer; owns the AML program, customer identification, and regulatory relationship; oversees everyone below |
| Program manager | Runs the program under the sponsor's policies: onboarding, monitoring, complaints, and reporting to the sponsor |
| Issuer processor | Secure card data handling, authorization controls, audit logs |
| Stablecoin conversion provider | Virtual asset licensing or registration, Travel Rule, wallet screening, its own AML program |
| Business customer (corporate programs) | Accurate KYB data, controls over which employees get cards |
The sponsor bank has the most at stake. It answers to its bank regulator for every card on its BIN, which is why its onboarding questions to a new program manager are long.
KYC applies to people. KYB applies to companies. Most programs need both.
| KYC | KYB | |
|---|---|---|
| Who is checked | Individual cardholders | Businesses running the program or holding corporate cards |
| What is collected | Name, date of birth, address, government ID number | Legal name, registration number, address, business activity, ownership structure |
| How it is verified | Document check with liveness, or data-source match; sanctions and PEP screening | Corporate registry lookup, document review, sanctions screening on the entity |
| People behind it | The cardholder | Every owner of 25 percent or more plus one controller, each verified with KYC |
| When | Before the card is issued | Before the program or corporate account is approved |
| US rule | Customer Identification Program, 31 CFR 1020.220 | FinCEN Customer Due Diligence rule |
In a consumer program every cardholder goes through full KYC. In a corporate program the company goes through KYB, and the employees who receive cards are identified to the level the sponsor bank's policy requires, which is usually lighter than full consumer KYC because the company is liable for the spend.
The KYB explainer covers the ownership rules, and how to automate KYC and KYB covers the tooling.
Two layers, two different anchors:
So one program serving customers in five countries can sit under one card regime and five virtual asset regimes at once. That is why a single license rarely covers a global program.
| Market | Card issuing | Stablecoin and virtual asset layer |
|---|---|---|
| United States | Bank issuer under its federal or state regulator; Bank Secrecy Act; Regulation E for consumer debit and prepaid | FinCEN money services business registration and state money transmitter licenses for conversion and custody; GENIUS Act for payment stablecoin issuers |
| European Union | Credit institution or e-money institution license; PSD2 | MiCA: CASP authorization for custody and exchange, EMT rules for stablecoins; Transfer of Funds Regulation (Travel Rule) |
| United Kingdom | FCA e-money or bank authorization | FCA cryptoasset registration under the Money Laundering Regulations |
| Brazil | BCB-authorized bank or payment institution | SPSAV authorization under BCB Resolutions 519, 520, and 521, in force February 2026 |
| Mexico | Bank or e-money institution under the Fintech Law | Fintech Law; Banco de México limits on regulated institutions offering virtual assets |
| Argentina | Bank or payment service provider under BCRA rules | PSAV registration with the CNV under Law 27,739 |
Two details trip up new programs. In the EU, MiCA restricts which stablecoins a CASP can offer, and major exchanges restricted USDT for EU customers after MiCA's stablecoin rules applied, so the funding token depends on the market. In Brazil, the SPSAV regime means the stablecoin provider's authorization status is now a diligence question, covered in the PSAV explainer.
The stablecoin regulation tracker and MiCA explainer go deeper on each regime. The Latin America card guide covers the regional card side.
Onboarding is where compliance starts. Most of the ongoing work happens after the card is live.
Transaction monitoring. Every authorization is scored. Card-side rules look at merchant category risk, velocity, cross-border patterns, and card testing (many small declined attempts). Stablecoin-side rules look at where funding came from: a deposit from a mixer, a sanctioned address, or a high-risk exchange changes the account's risk. The real-time transaction monitoring guide covers the rules.
Sanctions rescreening. Cardholders, business owners, and funding wallet addresses are rescreened each time a list updates. OFAC updates the SDN list several times a month and has listed blockchain addresses since 2018. OFAC compliance is strict liability: intent does not matter.
Periodic re-verification. Customer data is refreshed on a risk-based schedule. High-risk customers more often, low-risk less often, and anyone whose behavior changes sharply right away.
Fraud and disputes. Chargeback ratios above network thresholds put the whole program on a monitoring list. Dispute data also feeds fraud rules.
Reporting and records. Suspicious activity goes to the financial intelligence unit: FinCEN in the US, the COAF in Brazil, the UIF in Argentina. US Bank Secrecy Act records are kept for five years.
At a few hundred cardholders a team can review cases by hand. At tens of thousands the queue outgrows the team. Automation changes who looks at what, not what gets checked.
What does not change: a human owns the program, signs the policies, and makes the final call on reports. An examiner will ask for the trail on a sample of cases, and "the model decided" is not an answer.
BlindPay runs the same model for payouts: KYC and KYB inside the API, sanctions screening on customers and on each payout, and holds that show up as an on_hold status rather than a silent delay.
This is the last article in the stablecoin card series. Start from the top with what stablecoin card issuing is, or go back to the developer's guide to see where each checkpoint sits in the integration flow.
This article is for general information only and is not legal, tax, or financial advice.
Stablecoin transfers settle final in minutes and cannot be reversed. That finality proves custody at every step but opens a fraud gap on the fiat side.
Automated and manual KYC/KYB compared for fintechs: onboarding time, false positives, cost per verification, jurisdictions, and audit trails.
How compliance agents apply FinCEN, MiCA, FCA, MAS, and Banco Central do Brasil rules to cross-border stablecoin payments, plus the Travel Rule.