← Resources

· 9 min read

What Is the GENIUS Act? A Plain-English Guide to Stablecoin Compliance

What satisfying these rules actually costs today

Originally published on Zero Trust Architecture. Republished here in full.

TL;DR

  • The GENIUS Act is a US law signed on July 18, 2025. It sets rules for permitted companies that issue payment stablecoins.

  • Issuers must fully back outstanding stablecoins with eligible reserves and publish reserve details every month.

  • A registered accounting firm must examine each monthly report, and the CEO and CFO must certify its accuracy.

  • Issuers must follow anti-money laundering and sanctions rules. They must also maintain the technical ability to block transactions.

  • Audit invoices capture only part of the cost. Staff must collect and reconcile records, while periodic reviews can find problems after transactions settle. Continuous compliance monitoring offers another approach by generating verifiable evidence for every transaction, though regulators must determine which evidence formats they accept.

What the GENIUS Act is and when it passed

The GENIUS Act created the first federal regulatory framework for payment stablecoins in the United States. Signed into law on July 18, 2025, the legislation establishes rules for companies that issue digital tokens intended to maintain a fixed monetary value.

A payment stablecoin is a digital asset designed for payments or settlement rather than price speculation. Its issuer promises to redeem each token for a set amount of money, such as one US dollar. Users therefore depend on the issuer holding reliable reserves and honoring that redemption promise.

Congress passed the law to create a consistent basis for trusting those promises. Before the GENIUS Act, issuers operated under a mix of state rules and limited federal guidance. The federal framework gives regulators, issuers, and stablecoin holders a common legal structure for assessing whether a payment stablecoin can maintain its stated value.

Who has to comply and what it requires in plain terms

Anyone issuing payment stablecoins in the United States must operate through one of the permitted issuer routes created by the GENIUS Act. A bank subsidiary can receive federal approval, while a qualified nonbank can apply for federal supervision. A state-qualified issuer can generally remain under state supervision while its consolidated outstanding stablecoins stay at or below $10 billion. An issuer that exceeds $10 billion must move to federal supervision unless its regulator grants a waiver.

Every permitted issuer must hold at least one dollar of eligible reserves for each dollar of stablecoins in circulation. Eligible assets include cash, insured deposits, short-dated Treasury bills, qualifying repurchase agreements, and government money market fund shares. Issuers must keep reserves separate from operating funds and cannot reuse customer collateral for other financing. They must also publish redemption policies and maintain procedures for timely redemptions.

Issuers must report their reserve position every month. Each public report must state the number of stablecoins outstanding and show the amount and composition of the supporting reserves. A registered public accounting firm must examine the previous month-end report, and the CEO and CFO must certify its accuracy. These are separate monthly obligations, so an accounting-firm examination does not replace executive certification.

Issuers with more than $50 billion in consolidated outstanding stablecoins face an additional annual requirement unless public-company reporting rules already cover them. They must prepare annual financial statements under generally accepted accounting principles and obtain an audit from a registered public accounting firm under applicable Public Company Accounting Oversight Board standards. The annual audit sits alongside the monthly reserve examination rather than replacing it.

The law treats permitted issuers as financial institutions under the Bank Secrecy Act. Each issuer must maintain an anti-money laundering program with a responsible compliance officer, identify customers, and report suspicious activity. The issuer must also operate an economic sanctions program. Most notably, the statute requires “technical capabilities and procedures to block transactions.” Monitoring and reporting alone do not satisfy the plain meaning of that requirement because the issuer must be able to intervene before or during execution.

Permitted issuers also face limits on how they operate and market stablecoins. They cannot pay interest or yield to holders, and their activities generally must remain tied to issuance, redemption, custody, and reserve management. Marketing cannot claim that a stablecoin carries United States government backing, federal insurance, or legal-tender status. Regulators can add capital, liquidity, and risk-management rules based on the issuer’s structure and risk profile.

What satisfying these rules actually costs today

Most stablecoin issuers rely on monthly or quarterly third-party attestations, with annual audits added where required. Each reporting cycle requires internal staff to reconcile token supply across chains against bank balances, custodian records, mint and burn activity, and general ledger entries. An accounting firm then examines management’s assertion using records assembled for a specific reporting date. Public sources do not disclose typical stablecoin attestation fees, so any industry-wide price estimate for the external engagement would be speculative.

Internal preparation often costs more than the invoice suggests. Compliance, finance, engineering, and legal staff must extract records, resolve mismatches, answer auditor questions, and document corrections. Across financial institutions, financial crime compliance consumes an estimated $206 billion each year, while compliance spending averages about 19 percent of annual revenue. A Bank Policy Institute survey also found that employee hours devoted to compliance rose 61 percent between 2016 and 2023. Those benchmarks cover financial services broadly rather than stablecoin issuers, but they show how labor drives compliance costs.

Periodic attestations also leave a detection gap between reporting dates. A point-in-time examination usually verifies reserve backing on the final day of a reporting period, and it does not establish what happened during the preceding weeks. Circle’s latest Deloitte attestation showed USDC as fully backed before Silicon Valley Bank failed in March 2023, yet $3.3 billion of reserves became trapped and USDC briefly traded near $0.87. The attestation verified that the reserves existed at its measurement date, but it could not account for the custodian failure that followed.

Tether’s enforcement history shows how activity between reviews can change the conclusion. The CFTC found that USDT was fully backed for only 27.6 percent of a 26-month period and cited a $382 million transfer into Tether’s bank account before a reserve review. The agency imposed a $41 million penalty for misleading reserve statements.

Late discovery creates work that the original attestation fee does not capture. Staff must investigate historical transactions, determine affected counterparties, correct records, respond to regulators, and repair controls after activity has already settled. No reliable source supplies a standard multiplier for that remediation cost. The mechanism is still clear. Periodic review finds a past violation after its operational and legal consequences have begun, while pre-execution enforcement can stop a noncompliant transaction before settlement.

The alternative: continuous, per-transaction compliance evidence

Continuous, machine-verifiable evidence gives an issuer a record for each transaction when it occurs. Most issuers have not evaluated this category because conventional stablecoin compliance relies on periodic record collection, review, and attestation. The technology sits in the transaction path rather than replacing an auditor or screening provider.

Inherence illustrates how the model works. Inherence compiles a written policy into an inline enforcement gate that evaluates each transaction before execution. The policy can cover sanctions requirements, eligible counterparties, transaction limits, and approval conditions. The gate blocks a transaction that fails those rules. A transaction that passes produces a cryptographic receipt tied to the policy that governed it.

Each receipt lets a counterparty, auditor, or regulator verify policy compliance without trusting the issuer’s logs. Zero-knowledge proofs can also keep transaction details and policy thresholds private while confirming that the transaction satisfied the applicable rules. Screening services and other data providers can supply risk verdicts upstream, while Inherence binds those verdicts to the execution decision.

The measured performance supports per-transaction use. For a reference policy with 112 constraints, the enforcement gate took 27 to 250 nanoseconds measured. Proof generation took approximately 2.6 milliseconds measured on an Apple M4 using 10 threads. Verification took 0.96 milliseconds measured, and the measured Groth16 proof size was 128 bytes.

For stablecoin compliance, continuous evidence could support the GENIUS Act’s requirement for technical capabilities to block transactions. Per-transaction receipts could also give issuers structured evidence for reporting, examination, and internal review. A compliance team could trace a blocked or approved payment to the exact policy applied at execution instead of reconstructing the decision months later.

No public evidence establishes that a regulator will accept this receipt format as a substitute for a required examination, certification, or audit. Issuers would still need legal and accounting advice on each obligation. Continuous evidence instead offers a different operating model. Controls run before settlement, and verifiable records accumulate as transactions occur. That model may reduce manual evidence collection and detection lag while strengthening the records available to auditors and regulators.

Where screening vendors fit versus continuous evidence

Chainalysis and TRM Labs provide upstream blockchain intelligence that an issuer can use when applying transaction policies. Their wallet attribution, sanctions screening, and risk signals help answer a specific question. Does this address present known risk? Those inputs can inform a separate pre-execution enforcement layer.

Independent coverage describes Chainalysis as offering continuous transaction monitoring and pre-transaction address screening. Its tools can check wallets or liquidity pools and route or block activity according to policy. Chainalysis also produces decision logs and exports for later audit review, but the cited product descriptions do not include an independently verifiable cryptographic receipt for each transaction (stablecoin compliance tools).

TRM Labs similarly supplies wallet risk data and transaction-monitoring alerts. One documented integration sends those alerts into case-management queues for investigation. The integration described post-transaction wallet monitoring as live and real-time transaction screening as a future roadmap item, which places human review and reporting after the risk signal (TRM Labs integration).

Continuous evidence answers a separate question. Did this specific transaction satisfy the issuer’s policy at execution? An issuer could use a Chainalysis or TRM verdict as one policy input, block a noncompliant transaction before settlement, and generate a cryptographic receipt of the decision. A compliance lead should therefore compare periodic manual attestation with continuous automated evidence, rather than treating screening and enforcement as competing product categories.

Questions to ask before assuming periodic audits are your only option

Before renewing another periodic audit engagement, document how your current controls perform between review dates.

  • How long can a prohibited transaction remain undiscovered before monitoring or an auditor catches it?

  • How many staff hours does each reporting cycle consume for collecting records, reconciling discrepancies, and answering auditor questions?

  • What remediation costs arise when your controls detect a violation after settlement rather than blocking it before execution?

  • Can a counterparty independently verify that each covered transaction followed policy, or must the counterparty trust your logs and auditor?

  • Would a regulator accept your proposed evidence without additional review, and what validation would the regulator require?

  • Can your screening data feed a control that evaluates policy before execution and produces a verifiable record afterward?

  • Which transaction class offers a narrow, measurable pilot for continuous compliance monitoring?

Regulatory acceptance of any evidence format requires direct confirmation. Inherence offers one implementation worth evaluating. Its approach applies policy before execution and generates a privacy-preserving cryptographic receipt for each approved transaction.

FAQ

What is the GENIUS Act?

The GENIUS Act is a U.S. law signed July 18, 2025 that establishes federal rules for payment stablecoins. Inherence addresses the transaction-level policy enforcement that issuers may need within that framework. Issuers can use the law’s requirements to evaluate which controls and evidence formats their compliance programs need.

How can the GENIUS Act be explained in simple terms?

The law requires permitted issuers to back stablecoins with qualifying reserves, report those reserves monthly, obtain outside examination, and maintain financial-crime controls. Inherence focuses on enforcing defined transaction policies before execution and producing verifiable receipts afterward. Issuers can investigate continuous evidence while retaining accounting firms for required examinations.

Who does the GENIUS Act apply to?

The law applies to permitted U.S. payment stablecoin issuers operating under federal or qualifying state supervision. Inherence can support issuers that need transaction controls across automated payment activity. Each issuer should confirm its classification and obligations with qualified legal counsel.

What happens if a stablecoin issuer exceeds $50 billion?

An issuer with more than $50 billion in consolidated outstanding issuance must prepare annual GAAP financial statements through a registered public accounting firm unless SEC reporting already covers it. Inherence does not replace that annual requirement or the separate monthly examination. Continuous transaction evidence may reduce the manual work needed to assemble and test supporting records.

What does continuous compliance monitoring mean for stablecoins?

Continuous compliance monitoring evaluates each covered transaction against defined policies when the transaction occurs. Inherence can block a transaction that fails those policies and produce a cryptographic receipt for one that passes. Regulators have not guaranteed acceptance of any specific receipt format, but issuers can assess whether such evidence supports reporting, examinations, and counterparty review.