Stablecoin card issuing compliance: KYC, KYB, and regulatory coverage explained

What compliance stablecoin card issuing requires: KYC vs. KYB, who is responsible for what, how rules differ in the US, EU, UK, and Latin America, and ongoing monitoring.

Reading time: about 8 minutes.

Summary: At minimum, issuing stablecoin-funded cards requires a licensed bank or e-money institution as BIN sponsor, KYC on every cardholder, KYB on every business in the program, sanctions screening on people and wallet addresses, transaction monitoring on card and on-chain activity, and a written AML program. Stablecoin rules add to card rules. They do not replace them.

That last sentence is the one to bring to a risk committee. A stablecoin card program is a card program first, subject to everything a traditional program is, plus a virtual asset layer with its own regulators.

This guide is written for compliance officers, legal and risk teams, and founders who need to explain the program to a bank partner or a regulator. For the product basics, read what stablecoin card issuing is.

Who is responsible for what?

Every company in the stack carries part of the obligation. Knowing who owns which part is the first thing an examiner will ask.

PartyMain compliance duties
Card network (Visa, Mastercard)Program rules, brand protection standards, dispute rules
Issuing bank or BIN sponsorLegal issuer; owns the AML program, customer identification, and regulatory relationship; oversees everyone below
Program managerRuns the program under the sponsor's policies: onboarding, monitoring, complaints, and reporting to the sponsor
Issuer processorSecure card data handling, authorization controls, audit logs
Stablecoin conversion providerVirtual asset licensing or registration, Travel Rule, wallet screening, its own AML program
Business customer (corporate programs)Accurate KYB data, controls over which employees get cards

The sponsor bank has the most at stake. It answers to its bank regulator for every card on its BIN, which is why its onboarding questions to a new program manager are long.

KYC vs. KYB in card issuing

KYC applies to people. KYB applies to companies. Most programs need both.

KYCKYB
Who is checkedIndividual cardholdersBusinesses running the program or holding corporate cards
What is collectedName, date of birth, address, government ID numberLegal name, registration number, address, business activity, ownership structure
How it is verifiedDocument check with liveness, or data-source match; sanctions and PEP screeningCorporate registry lookup, document review, sanctions screening on the entity
People behind itThe cardholderEvery owner of 25 percent or more plus one controller, each verified with KYC
WhenBefore the card is issuedBefore the program or corporate account is approved
US ruleCustomer Identification Program, 31 CFR 1020.220FinCEN Customer Due Diligence rule

In a consumer program every cardholder goes through full KYC. In a corporate program the company goes through KYB, and the employees who receive cards are identified to the level the sponsor bank's policy requires, which is usually lighter than full consumer KYC because the company is liable for the spend.

The KYB explainer covers the ownership rules, and how to automate KYC and KYB covers the tooling.

Why do the rules differ country by country?

Two layers, two different anchors:

  • Card issuing is licensed where the card is issued. A US-issued card is governed by US banking rules even when used in Brazil.
  • Virtual asset services are regulated where the customer is. A company converting stablecoins for residents of the EU, Brazil, or Argentina needs to meet those countries' virtual asset rules.

So one program serving customers in five countries can sit under one card regime and five virtual asset regimes at once. That is why a single license rarely covers a global program.

MarketCard issuingStablecoin and virtual asset layer
United StatesBank issuer under its federal or state regulator; Bank Secrecy Act; Regulation E for consumer debit and prepaidFinCEN money services business registration and state money transmitter licenses for conversion and custody; GENIUS Act for payment stablecoin issuers
European UnionCredit institution or e-money institution license; PSD2MiCA: CASP authorization for custody and exchange, EMT rules for stablecoins; Transfer of Funds Regulation (Travel Rule)
United KingdomFCA e-money or bank authorizationFCA cryptoasset registration under the Money Laundering Regulations
BrazilBCB-authorized bank or payment institutionSPSAV authorization under BCB Resolutions 519, 520, and 521, in force February 2026
MexicoBank or e-money institution under the Fintech LawFintech Law; Banco de México limits on regulated institutions offering virtual assets
ArgentinaBank or payment service provider under BCRA rulesPSAV registration with the CNV under Law 27,739

Two details trip up new programs. In the EU, MiCA restricts which stablecoins a CASP can offer, and major exchanges restricted USDT for EU customers after MiCA's stablecoin rules applied, so the funding token depends on the market. In Brazil, the SPSAV regime means the stablecoin provider's authorization status is now a diligence question, covered in the PSAV explainer.

The stablecoin regulation tracker and MiCA explainer go deeper on each regime. The Latin America card guide covers the regional card side.

What monitoring is required after a card is issued?

Onboarding is where compliance starts. Most of the ongoing work happens after the card is live.

Transaction monitoring. Every authorization is scored. Card-side rules look at merchant category risk, velocity, cross-border patterns, and card testing (many small declined attempts). Stablecoin-side rules look at where funding came from: a deposit from a mixer, a sanctioned address, or a high-risk exchange changes the account's risk. The real-time transaction monitoring guide covers the rules.

Sanctions rescreening. Cardholders, business owners, and funding wallet addresses are rescreened each time a list updates. OFAC updates the SDN list several times a month and has listed blockchain addresses since 2018. OFAC compliance is strict liability: intent does not matter.

Periodic re-verification. Customer data is refreshed on a risk-based schedule. High-risk customers more often, low-risk less often, and anyone whose behavior changes sharply right away.

Fraud and disputes. Chargeback ratios above network thresholds put the whole program on a monitoring list. Dispute data also feeds fraud rules.

Reporting and records. Suspicious activity goes to the financial intelligence unit: FinCEN in the US, the COAF in Brazil, the UIF in Argentina. US Bank Secrecy Act records are kept for five years.

How automation reduces review without skipping steps

At a few hundred cardholders a team can review cases by hand. At tens of thousands the queue outgrows the team. Automation changes who looks at what, not what gets checked.

  • Automated KYC and KYB approve clean cases in seconds to minutes and route edge cases to review, instead of sending every application to an analyst. The automated vs. manual onboarding comparison shows the tradeoffs.
  • Rules and models on every transaction replace sampling. Every authorization is scored, not a percentage.
  • List-triggered rescreening runs against the full customer base each time a sanctions list updates, instead of quarterly batches.
  • Compliance agents triage alerts, close obvious false positives, and draft case narratives, while the filing decision stays with a named human. The compliance agents explainer covers where they fit.

What does not change: a human owns the program, signs the policies, and makes the final call on reports. An examiner will ask for the trail on a sample of cases, and "the model decided" is not an answer.

BlindPay runs the same model for payouts: KYC and KYB inside the API, sanctions screening on customers and on each payout, and holds that show up as an on_hold status rather than a silent delay.

Pre-launch compliance checklist

  • Sponsor bank named, program approved, card types and countries confirmed in writing
  • Written AML program covering both the card leg and the stablecoin leg
  • KYC and KYB flows mapped to the sponsor's policy, with rejection handling
  • Stablecoin provider's license or registration verified in each customer market
  • Permitted stablecoins confirmed per market (for example, MiCA rules in the EU)
  • Wallet screening on every funding source
  • Transaction monitoring rules for card and on-chain activity, with an owner for tuning
  • Sanctions rescreening on list updates
  • Suspicious activity reporting process and record retention

This is the last article in the stablecoin card series. Start from the top with what stablecoin card issuing is, or go back to the developer's guide to see where each checkpoint sits in the integration flow.

This article is for general information only and is not legal, tax, or financial advice.

FAQ