---
title: "Stablecoin card issuing compliance: KYC, KYB, and regulatory coverage explained"
seoTitle: "Stablecoin card issuing compliance: KYC, KYB, regulation"
description: "What compliance stablecoin card issuing requires: KYC vs. KYB, who is responsible for what, how rules differ in the US, EU, UK, and Latin America, and ongoing monitoring."
date: "2026-09-21"
category: "compliance"
author: "BlindPay Team"
faq:
  - q: "What compliance is required to issue stablecoin-funded cards?"
    a: "At minimum: a licensed bank or e-money institution as issuer and BIN sponsor, KYC on every cardholder, KYB on every business that runs or uses the program, sanctions screening on people and wallet addresses, transaction monitoring on card and on-chain activity, and a written anti-money-laundering program. The stablecoin conversion also needs a provider licensed or registered for virtual asset services where the customers are."
  - q: "What is the difference between KYC and KYB for card issuing?"
    a: "KYC verifies an individual cardholder: name, date of birth, address, and a government ID number, checked against documents or data sources and sanctions lists. KYB verifies a business: its registration and good standing, what it does, and the people who own or control it, each of whom then goes through KYC. A consumer program needs KYC per cardholder; a corporate program needs KYB on the company plus identification of the employees who get cards."
  - q: "Do stablecoin card issuing rules differ by country?"
    a: "Yes. Card issuing is licensed where the card is issued, while virtual asset services are usually regulated where the customer lives, so one program can fall under several regimes at once. The US, EU, UK, Brazil, Mexico, and Argentina each have different licenses, reporting duties, and rules on which stablecoins are allowed."
  - q: "What ongoing monitoring is required after a stablecoin card is issued?"
    a: "Transaction monitoring on every authorization and on-chain funding movement, sanctions rescreening of cardholders each time a list changes, periodic re-verification of customer data based on risk, and fraud and dispute monitoring. Suspicious activity must be reported to the local financial intelligence unit, such as FinCEN in the US, and records kept for the required period, five years under the US Bank Secrecy Act."
  - q: "Is stablecoin card issuing regulated the same way as traditional card issuing?"
    a: "The card leg is regulated the same way: the same sponsor bank oversight, card network rules, identification requirements, and consumer protection rules apply. The stablecoin leg adds a second layer on top, including virtual asset licensing, the Travel Rule for transfers, wallet address screening, and rules on which stablecoins are permitted, such as MiCA in the EU and the GENIUS Act in the US."
---

*Reading time: about 8 minutes.*

**Summary:** At minimum, issuing stablecoin-funded cards requires a licensed bank or e-money institution as BIN sponsor, KYC on every cardholder, KYB on every business in the program, sanctions screening on people and wallet addresses, transaction monitoring on card and on-chain activity, and a written AML program. Stablecoin rules add to card rules. They do not replace them.

That last sentence is the one to bring to a risk committee. A stablecoin card program is a card program first, subject to everything a traditional program is, plus a virtual asset layer with its own regulators.

This guide is written for compliance officers, legal and risk teams, and founders who need to explain the program to a bank partner or a regulator. For the product basics, read [what stablecoin card issuing is](/resources/more/what-is-stablecoin-card-issuing).

## Who is responsible for what?

Every company in the stack carries part of the obligation. Knowing who owns which part is the first thing an examiner will ask.

| Party | Main compliance duties |
|---|---|
| Card network (Visa, Mastercard) | Program rules, brand protection standards, dispute rules |
| Issuing bank or BIN sponsor | Legal issuer; owns the AML program, customer identification, and regulatory relationship; oversees everyone below |
| Program manager | Runs the program under the sponsor's policies: onboarding, monitoring, complaints, and reporting to the sponsor |
| Issuer processor | Secure card data handling, authorization controls, audit logs |
| Stablecoin conversion provider | Virtual asset licensing or registration, Travel Rule, wallet screening, its own AML program |
| Business customer (corporate programs) | Accurate KYB data, controls over which employees get cards |

The sponsor bank has the most at stake. It answers to its bank regulator for every card on its BIN, which is why its onboarding questions to a new program manager are long.

## KYC vs. KYB in card issuing

KYC applies to people. KYB applies to companies. Most programs need both.

| | KYC | KYB |
|---|---|---|
| Who is checked | Individual cardholders | Businesses running the program or holding corporate cards |
| What is collected | Name, date of birth, address, government ID number | Legal name, registration number, address, business activity, ownership structure |
| How it is verified | Document check with liveness, or data-source match; sanctions and PEP screening | Corporate registry lookup, document review, sanctions screening on the entity |
| People behind it | The cardholder | Every owner of 25 percent or more plus one controller, each verified with KYC |
| When | Before the card is issued | Before the program or corporate account is approved |
| US rule | Customer Identification Program, 31 CFR 1020.220 | FinCEN Customer Due Diligence rule |

In a consumer program every cardholder goes through full KYC. In a corporate program the company goes through KYB, and the employees who receive cards are identified to the level the sponsor bank's policy requires, which is usually lighter than full consumer KYC because the company is liable for the spend.

The [KYB explainer](/resources/more/what-is-kyb) covers the ownership rules, and [how to automate KYC and KYB](/resources/more/how-to-automate-kyc-kyb-stablecoin-payments) covers the tooling.

## Why do the rules differ country by country?

Two layers, two different anchors:

- **Card issuing is licensed where the card is issued.** A US-issued card is governed by US banking rules even when used in Brazil.
- **Virtual asset services are regulated where the customer is.** A company converting stablecoins for residents of the EU, Brazil, or Argentina needs to meet those countries' virtual asset rules.

So one program serving customers in five countries can sit under one card regime and five virtual asset regimes at once. That is why a single license rarely covers a global program.

| Market | Card issuing | Stablecoin and virtual asset layer |
|---|---|---|
| United States | Bank issuer under its federal or state regulator; Bank Secrecy Act; Regulation E for consumer debit and prepaid | FinCEN money services business registration and state money transmitter licenses for conversion and custody; GENIUS Act for payment stablecoin issuers |
| European Union | Credit institution or e-money institution license; PSD2 | MiCA: CASP authorization for custody and exchange, EMT rules for stablecoins; Transfer of Funds Regulation (Travel Rule) |
| United Kingdom | FCA e-money or bank authorization | FCA cryptoasset registration under the Money Laundering Regulations |
| Brazil | BCB-authorized bank or payment institution | SPSAV authorization under BCB Resolutions 519, 520, and 521, in force February 2026 |
| Mexico | Bank or e-money institution under the Fintech Law | Fintech Law; Banco de México limits on regulated institutions offering virtual assets |
| Argentina | Bank or payment service provider under BCRA rules | PSAV registration with the CNV under Law 27,739 |

Two details trip up new programs. In the EU, MiCA restricts which stablecoins a CASP can offer, and major exchanges restricted USDT for EU customers after MiCA's stablecoin rules applied, so the funding token depends on the market. In Brazil, the SPSAV regime means the stablecoin provider's authorization status is now a diligence question, covered in the [PSAV explainer](/resources/more/psav-brazil-explained).

The [stablecoin regulation tracker](/resources/more/stablecoin-regulation-tracker-2026) and [MiCA explainer](/resources/more/mica-stablecoin-rules-explained) go deeper on each regime. The [Latin America card guide](/resources/more/stablecoin-cards-latin-america) covers the regional card side.

## What monitoring is required after a card is issued?

Onboarding is where compliance starts. Most of the ongoing work happens after the card is live.

**Transaction monitoring.** Every authorization is scored. Card-side rules look at merchant category risk, velocity, cross-border patterns, and card testing (many small declined attempts). Stablecoin-side rules look at where funding came from: a deposit from a mixer, a sanctioned address, or a high-risk exchange changes the account's risk. The [real-time transaction monitoring guide](/resources/more/real-time-transaction-monitoring-stablecoin-payments) covers the rules.

**Sanctions rescreening.** Cardholders, business owners, and funding wallet addresses are rescreened each time a list updates. OFAC updates the SDN list several times a month and has listed blockchain addresses since 2018. OFAC compliance is strict liability: intent does not matter.

**Periodic re-verification.** Customer data is refreshed on a risk-based schedule. High-risk customers more often, low-risk less often, and anyone whose behavior changes sharply right away.

**Fraud and disputes.** Chargeback ratios above network thresholds put the whole program on a monitoring list. Dispute data also feeds fraud rules.

**Reporting and records.** Suspicious activity goes to the financial intelligence unit: FinCEN in the US, the COAF in Brazil, the UIF in Argentina. US Bank Secrecy Act records are kept for five years.

## How automation reduces review without skipping steps

At a few hundred cardholders a team can review cases by hand. At tens of thousands the queue outgrows the team. Automation changes who looks at what, not what gets checked.

- **Automated KYC and KYB** approve clean cases in seconds to minutes and route edge cases to review, instead of sending every application to an analyst. The [automated vs. manual onboarding comparison](/resources/more/automated-kyc-kyb-vs-manual-onboarding) shows the tradeoffs.
- **Rules and models on every transaction** replace sampling. Every authorization is scored, not a percentage.
- **List-triggered rescreening** runs against the full customer base each time a sanctions list updates, instead of quarterly batches.
- **Compliance agents** triage alerts, close obvious false positives, and draft case narratives, while the filing decision stays with a named human. The [compliance agents explainer](/resources/more/what-are-compliance-agents-in-fintech) covers where they fit.

What does not change: a human owns the program, signs the policies, and makes the final call on reports. An examiner will ask for the trail on a sample of cases, and "the model decided" is not an answer.

BlindPay runs the same model for payouts: KYC and KYB inside the API, sanctions screening on customers and on each payout, and holds that show up as an `on_hold` status rather than a silent delay.

## Pre-launch compliance checklist

- Sponsor bank named, program approved, card types and countries confirmed in writing
- Written AML program covering both the card leg and the stablecoin leg
- KYC and KYB flows mapped to the sponsor's policy, with rejection handling
- Stablecoin provider's license or registration verified in each customer market
- Permitted stablecoins confirmed per market (for example, MiCA rules in the EU)
- Wallet screening on every funding source
- Transaction monitoring rules for card and on-chain activity, with an owner for tuning
- Sanctions rescreening on list updates
- Suspicious activity reporting process and record retention

## What to read next

This is the last article in the stablecoin card series. Start from the top with [what stablecoin card issuing is](/resources/more/what-is-stablecoin-card-issuing), or go back to the [developer's guide](/resources/more/how-to-issue-stablecoin-cards-api) to see where each checkpoint sits in the integration flow.

*This article is for general information only and is not legal, tax, or financial advice.*
