· 10 min read
The Real Cost of Periodic Stablecoin Compliance Audits (And What Replaces Them)
the real cost of that status quo beyond the audit invoice itself, covering internal compliance staff time spent pulling and reconciling transaction records
Originally published on Zero Trust Architecture. Republished here in full.
TL;DR
-
Stablecoin issuers often rely on monthly or quarterly third-party attestations. The GENIUS Act requires monthly reserve examinations and executive certifications.
-
Compliance staff must collect, reconcile, and explain transaction and reserve records before an accountant can examine them.
-
Periodic reviews create detection lag because they examine past records or point-in-time balances rather than every transaction as it occurs.
-
Late detection raises remediation costs because issuers must investigate completed activity, correct records, and address violations after settlement.
-
Continuous machine-verifiable evidence offers a distinct alternative. Inherence can enforce policy before execution and issue a cryptographic receipt for each approved transaction. Chainalysis and TRM Labs remain complementary sources of screening and risk data.
What the GENIUS Act actually requires today
The GENIUS Act requires permitted payment stablecoin issuers to maintain identifiable reserves that back outstanding coins at least one-to-one. Issuers must publish each month’s outstanding issuance and reserve composition, and a registered public accounting firm must examine the prior month-end disclosure every month. The law therefore sets a monthly examination cadence rather than a quarterly one for reserve reporting.
The CEO and CFO must certify the monthly report’s accuracy. Their certification remains separate from the accounting firm’s examination. Issuers with more than $50 billion in consolidated outstanding issuance must also produce annual GAAP financial statements audited by a registered public accounting firm unless they already report under the Securities Exchange Act.
The GENIUS Act also treats permitted issuers as financial institutions under the Bank Secrecy Act. Among its anti-money laundering requirements, the statute calls for “technical capabilities and procedures to block transactions.” That language requires an ability to intervene in transactions, while the monthly reserve provisions govern reporting and examination.
The statute does not specify which technical design must perform the blocking or what evidence format regulators must accept. Federal and state regulators must supply further operational detail through rulemaking. Issuers should therefore distinguish the Act’s stated obligations from assumptions about how a particular audit, monitoring tool, or cryptographic record will satisfy them.
The status quo: periodic audits and what issuers assume they buy
Stablecoin issuers commonly use recurring third-party attestations as their main evidence of reserve compliance. Circle and Paxos publish monthly attestations, while Tether has historically published them quarterly. The cadence varies because issuers have followed different assurance practices and standards, even as the GENIUS Act establishes monthly reporting as the federal baseline.
An attestation answers a narrower question than a full audit. Under AT-C 205, an accounting firm examines management’s assertion that reserves covered outstanding tokens at a specified point in time, usually month-end. The engagement does not assess ongoing internal controls, related-party transactions, counterparty risk, or the issuer’s financial condition. Those questions require broader audit procedures.
Periodic attestations therefore support a claim about one selected date. They do not show whether reserves remained sufficient during the rest of the month or whether every transaction followed policy when executed. Circle’s monthly reports have also appeared three to four weeks after month-end, which further separates the reviewed snapshot from current operations. These cadence and scope differences reflect the limits of periodic assurance rather than a failure by any single issuer.
Recurring attestations provide a necessary baseline for reserve reporting. Treating them as complete evidence of continuous stablecoin compliance creates the cost and detection gaps examined next.
The real cost of the status quo
The audit invoice captures only the external accounting fee. Periodic attestations also consume internal staff time, leave compliance events undetected between reviews, and increase the work required when a problem surfaces after settlement.
Internal staff time
Your compliance and finance staff must collect wallet activity, bank records, reserve balances, and token supply data before an accounting firm can examine them. Staff then reconcile mismatches and explain exceptions, and none of that labor shows up on the audit invoice.
Stablecoin-specific labor figures are not publicly disclosed, but the broader financial compliance industry shows the scale of the problem it belongs to. Banks and fintechs spend an estimated $206 billion a year on financial crime compliance, and compliance now averages close to 19% of a financial firm’s annual revenue, according to data summarized by Flagright. That spending has kept climbing. Employee hours devoted to compliance work rose 61% between 2016 and 2023, IT spending on compliance grew from 9.6% to 13.4% of IT budgets over the same period, and 98% of institutions reported higher compliance costs in 2023 than the year before. One global bank found its analysts spent four hours investigating each false-positive alert. These figures describe the traditional AML and banking compliance function rather than stablecoin issuers specifically, so treat them as a proxy for the scale of the labor problem rather than a stablecoin-specific number.
The pattern behind those figures is consistent regardless of institution type. Reconciliation, exception review, and evidence preparation are manual, recurring, and priced by the hour, so cost rises with transaction volume and headcount rather than with better technology. Machine-verifiable evidence changes that relationship. When a policy is enforced automatically at the moment of execution and produces its own cryptographic receipt, an issuer’s staff no longer needs to manually assemble wallet activity, bank records, and token supply data into a case for an accountant to examine. The receipt already states which policy governed the transaction and whether it was satisfied. That does not eliminate the accounting examination the GENIUS Act requires, but it removes the labor-intensive reconstruction work that currently sits in front of it, which is the same labor driving the cost figures above.
Detection lag
A periodic review can verify the records presented for its measurement date, but transactions and counterparty risks keep changing afterward. Circle’s most recent attestation before the March 2023 banking crisis showed full reserve coverage. Days later, Silicon Valley Bank’s failure trapped $3.3 billion of USDC reserves, and USDC traded near $0.87. The attestation confirmed that the reserves existed at the review date, but its scope did not assess the custodian bank’s future credit risk.
Tether’s regulatory history illustrates another form of timing risk. The CFTC found that $382 million moved into Tether’s bank account before a reserve review. The agency later imposed a $41 million penalty after finding that USDT had been fully backed for 27.6% of a 26-month period, while the New York Attorney General reached a separate $18.5 million settlement over reserve representations. These documented cases show how a favorable snapshot can coexist with different conditions between reporting dates. They do not establish that every periodic attestation suffers the same problem.
Remediation after execution
Late discovery requires more work than preventing a noncompliant transaction. Your staff may need to trace completed transfers, notify counterparties, prepare regulator responses, revise controls, and manage legal proceedings. A completed transaction can also involve funds that have moved through additional wallets or entered another institution’s custody. Periodic evidence therefore moves much of the compliance effort downstream, where investigation and correction depend on records assembled after the event.
Why periodic evidence structurally can’t catch everything
A month-end examination samples conditions at a specified time, while reserve movements and transactions continue throughout the month. Balances can change before or after the measurement date without affecting the snapshot that an accounting firm examines.
Historical enforcement shows how little a point-in-time result can reveal about the period around it. The CFTC found that USDT was fully backed only 27.6% of the time over a 26-month period. A favorable observation on one date could not establish continuous backing across that interval.
More frequent examinations shorten the unobserved interval, but sampling still leaves time between checks. A monthly attestation can support the required reserve report, but it cannot by itself prove that every transaction followed policy or that a prohibited transaction was blocked before settlement. Continuous evidence requires a record tied to each relevant event, rather than a reconstruction assembled after the reporting period ends.
Continuous, machine-verifiable evidence: a category most issuers haven’t evaluated
Continuous, machine-verifiable evidence gives an issuer a record for every covered transaction rather than requiring an auditor to reconstruct activity later. Inherence converts a written policy into an inline enforcement gate that evaluates each transaction before execution. The gate blocks transactions that fail the policy. Transactions that pass receive a zero-knowledge cryptographic receipt binding the action to the policy that governed it.
Inherence measured the enforcement gate at 27 to 250 nanoseconds using a reference policy with 112 constraints, with the scope limited to policy evaluation. Proof generation took approximately 2.6 milliseconds, measured on an Apple M4 using 10 threads. Verification took 0.96 milliseconds, measured. The measured Groth16 proof was 128 bytes.
A counterparty, auditor, or regulator can verify each receipt without accessing the private transaction inputs or relying on the issuer’s logs. Per-transaction receipts can give reviewers evidence covering the full transaction population rather than a point-in-time sample. Zero-knowledge proofs can also confirm that a policy held without exposing confidential amounts, thresholds, or other protected data.
Cryptographic receipts do not guarantee that a regulator will accept a particular evidence format. They also do not remove statutory reports, examinations, or certifications. Continuous evidence can support those obligations by giving issuers and reviewers a machine-verifiable record of which policy governed each transaction and whether the transaction satisfied it.
Most issuers have not evaluated this model because it falls outside the familiar categories of audits and transaction screening. Chainalysis and TRM Labs can continue supplying sanctions, identity, and risk verdicts as upstream inputs. Inherence uses those inputs when enforcing an issuer’s policy, so adoption does not require replacing screening vendors. The relevant comparison concerns when controls operate and how evidence gets produced.
Where screening vendors fit — and where they don’t overlap
Chainalysis supplies wallet risk data before and after transactions. Its address screening checks wallets or liquidity pools before a transfer, while KYT monitors inbound and outbound transfers through APIs and analyst workflows. The product description focuses on risk scoring, policy actions, decision logs, and auditor exports rather than independently verifiable cryptographic receipts for each transaction.
TRM Labs also centers on wallet intelligence and investigation workflows. A Unit21 integration announcement says, “Post-transaction wallet monitoring is live today,” while real-time wallet screening remained on the roadmap. TRM alerts can populate cases and reports, but analysts still review risk signals and manage follow-up work.
Adopting continuous execution-time evidence does not require a vendor swap. You can feed Chainalysis or TRM Labs screening results into Inherence’s pre-execution policy layer, which can block a transaction that violates policy and produce a cryptographic receipt for an allowed transaction. The screening provider supplies the risk verdict, while Inherence binds that verdict to an execution decision and verifiable evidence.
Questions a compliance lead should ask before assuming audits are the only option
-
How many staff hours does each examination consume for collecting, reconciling, and explaining transaction records?
-
How long can a policy violation remain undetected between periodic reviews?
-
What remediation work follows when you detect a violation after settlement?
-
Can your controls block a prohibited transaction before execution, as contemplated by the GENIUS Act requirement for technical capabilities and procedures to block transactions?
-
Can an auditor, counterparty, or regulator independently verify the policy decision for each transaction without reconstructing it from internal logs?
-
Which screening data could feed an execution-time control, and which tools only generate alerts for later review?
-
Would continuous evidence reduce manual preparation or detection lag even if required accounting examinations remain in place?
Continuous evidence does not guarantee regulatory acceptance or eliminate statutory examinations. It offers a separate category for enforcing policy and documenting each decision as transactions occur. Inherence Labs provides one starting point for evaluating that category.
FAQ
How often does GENIUS Act reporting happen?
Permitted issuers must publish reserve information monthly, obtain a monthly accounting-firm examination, and submit monthly CEO and CFO certifications under the GENIUS Act requirements. Inherence can produce transaction-level evidence between those reporting dates. Issuers can use continuous records to support oversight without treating monthly reporting as continuous review.
What is the difference between an attestation and an audit?
An attestation examines a defined claim or set of information, while a financial statement audit evaluates financial statements under a broader assurance framework. Inherence produces cryptographic receipts for covered transactions rather than performing either engagement. Those receipts can give auditors and counterparties independently verifiable evidence about whether defined policies governed each transaction.
What does continuous compliance monitoring mean compared with periodic audits?
Continuous compliance monitoring evaluates activity as it occurs, while periodic audits review selected records or reporting periods afterward. Inherence checks defined policies before execution and creates a cryptographic receipt for each approved transaction. You can block covered violations before settlement and retain evidence that outside parties can verify without accessing private inputs.
Do Chainalysis or TRM Labs already provide continuous compliance evidence?
Chainalysis and TRM Labs screen addresses, assess transaction risk, and generate alerts for investigation. Inherence can use their risk data as an input while enforcing transaction policies and producing verifiable receipts. Screening identifies relevant risk signals, while execution-time enforcement determines whether a covered transaction may proceed.