Issuer Control vs. Decentralization: The Tension at the Heart of Stablecoins
Stablecoins are often described as digital dollars that move across decentralized networks. That description is useful, but it leaves out one of their most important
For years, the stablecoin debate has focused heavily on reserves. Are the assets really there? What are they invested in? Are they liquid? Has an independent party verified them?
Those questions remain important. A stablecoin cannot function reliably if its issuer lacks sufficient assets to support redemption. But reserve transparency alone does not prove that an issuer can operate safely under pressure.
An attestation may show what an issuer held at a particular moment. It does not necessarily reveal how quickly those assets can be converted to cash, how the company would respond to a surge in redemptions, whether its technology can withstand an operational disruption, or whether its compliance controls work as intended.
As stablecoins become more integrated into payments and financial markets, regulators will likely move from asking whether reserves exist to examining how the entire stablecoin system functions.
The next phase of stablecoin oversight will be about more than backing. It will focus on liquidity, governance, financial crime controls, operational resilience, data quality, redemption capacity, and the relationships connecting issuers with the rest of the financial system.
Reserve transparency was a logical starting point for stablecoin regulation. If a stablecoin is marketed as redeemable for one dollar, users need confidence that the issuer holds sufficient assets to meet that promise.
The GENIUS Act reflects this concern by requiring permitted payment stablecoin issuers to maintain identifiable reserves on at least a one-to-one basis. Proposed implementing rules also address the types of assets that may be held as reserves and how issuers must report their financial condition.
These requirements create an important foundation, but they do not answer every question.
An issuer may appear fully backed on paper while still facing liquidity problems. Some reserve assets may need to be sold before redemptions can be completed. A rapid sale during market stress could introduce delays, losses, or operational complications.
Timing also matters. A monthly disclosure or periodic attestation provides a snapshot. It may not reveal significant changes that occur between reporting dates or show how reserve levels respond to changes in stablecoin issuance and redemption activity.
Regulators are already signaling interest in more frequent information. The OCC’s proposed framework includes confidential weekly reporting for each payment stablecoin issued, along with quarterly financial-condition reports. According to the agency, regular reporting would help supervisors identify emerging risks and tailor examinations to an issuer’s business model.
That is a significant change. Oversight is moving from periodic public confirmation toward continuous supervisory visibility.
Holding sufficient reserves is not the same as being prepared to meet redemptions.
If stablecoin holders lose confidence or need immediate access to traditional currency, an issuer may face a sudden increase in redemption requests. Regulators will likely want to know whether the issuer can process those requests without disrupting customers, counterparties, or broader markets.
This could bring closer attention to:
Stablecoin issuers may also be expected to demonstrate what would happen under adverse conditions. This could include scenarios involving the failure of a banking partner, a disruption at a custodian, a sudden loss of market confidence, or a significant decline in the value of a reserve asset.
The purpose of this analysis is not merely to confirm that the issuer is solvent. It is to determine whether the redemption mechanism can continue functioning when demand is highest.
A stablecoin’s reliability ultimately depends on whether users can convert it into the referenced currency according to the terms they were promised. Regulators are unlikely to treat that as a disclosure issue alone. It is an operational capability that may need to be documented, monitored, and tested.
Stablecoin oversight will also likely place greater emphasis on who makes decisions and how those decisions are reviewed.
A reserve report may confirm the amount and composition of backing assets, but it does not explain who controls those assets, who approves changes to reserve strategy, or what happens when the company encounters a conflict between commercial goals and compliance obligations.
Regulators may expect issuers to establish clear accountability across senior management, compliance, risk, finance, technology, and the board. They may examine whether decision-makers receive accurate information, whether material issues are escalated promptly, and whether independent functions can challenge the business effectively.
Governance becomes especially important when an issuer must decide whether to restrict a wallet, delay a redemption, change a banking partner, respond to a technology incident, or modify the assets held in reserve.
Those decisions should not depend on informal conversations or unclear authority. They should follow approved policies, defined escalation procedures, and documented decision-making standards.
Regulators may also examine whether an issuer has grown faster than its governance structure. A company that handled a modest amount of stablecoin activity may find that its original processes are no longer appropriate after transaction volume, customer reach, or geographic exposure expands.
The question will not simply be whether policies exist. Supervisors will want to know whether those policies remain appropriate for the size, complexity, and risk profile of the business.
Reserve transparency addresses whether a stablecoin is backed. It does not address how the stablecoin may be used after issuance.
Stablecoins can move rapidly across wallets, exchanges, decentralized applications, bridges, and multiple blockchains. They may also be transferred internationally without passing through the same sequence of intermediaries involved in a traditional payment.
This creates challenges for anti-money laundering and sanctions compliance.
Under the GENIUS Act, permitted payment stablecoin issuers are treated as financial institutions for purposes of the Bank Secrecy Act. Treasury’s proposed implementing rules would subject those issuers to AML obligations and require effective sanctions compliance programs. Federal agencies have also proposed customer identification requirements for permitted issuers.
As implementation continues, regulators will likely examine whether issuers can connect customer information with on-chain activity. They may also assess whether transaction-monitoring systems reflect the issuer’s actual exposure rather than relying on generic digital asset rules.
Key areas may include the treatment of self-hosted wallets, indirect exposure to illicit services, unusual minting and redemption activity, cross-chain transfers, sanctions-related wallet activity, and transactions involving high-risk jurisdictions.
The existence of blockchain analytics software will not be enough. Issuers will need to show how alerts are generated, reviewed, escalated, documented, and incorporated into regulatory reporting.
Technology can identify potential exposure, but the compliance program must determine what that exposure means.
If stablecoins are used for payments and settlement, their availability becomes an important part of their reliability.
A fully reserved stablecoin may still create significant problems if customers cannot access it, transfer it, or redeem it because of a technology failure. Smart contract vulnerabilities, cyberattacks, compromised administrative keys, network congestion, and vendor outages can all interfere with normal operations.
The next phase of stablecoin oversight will likely examine whether issuers can continue providing essential services during a disruption.
Regulators may expect companies to demonstrate that they have:
These expectations may extend beyond the issuer’s internal systems. A stablecoin may depend on custodians, cloud platforms, banks, blockchain infrastructure providers, analytics services, and other third parties.
If one of those providers experiences an outage, the issuer still needs to understand how its customers and operations will be affected.
A contract with a vendor does not transfer the underlying operational risk. Regulators will likely expect issuers to evaluate critical providers, monitor their performance, establish contingency plans, and document how services would continue if a vendor became unavailable.
Regulatory reporting is likely to become more frequent and more detailed.
The OCC’s proposed framework includes weekly confidential reporting and quarterly financial-condition reporting for payment stablecoin issuers under its supervision. The information could help regulators monitor reserves, outstanding issuance, financial condition, and risks unique to an issuer’s business model.
Producing that information consistently may be harder than it appears.
An issuer must be able to reconcile tokens issued across supported networks with reserve assets held at banks, custodians, or other permitted institutions. It may also need to account for tokens that have been minted but not released, tokens awaiting redemption, transactions that have not fully settled, and operational activity occurring near the reporting cutoff.
If data is collected from multiple systems, the issuer must know whether those systems use consistent definitions and timing standards. Small discrepancies can become significant as issuance grows.
Reliable reporting will therefore require more than a spreadsheet assembled at the end of each reporting period. Issuers may need stronger data governance, reconciliation procedures, exception management, documentation, and internal review.
Regulators will likely examine whether reported information can be traced back to reliable source systems and whether discrepancies are identified and resolved promptly.
Stablecoin issuers rarely operate independently.
They may rely on banks to hold cash, custodians to safeguard reserve assets, exchanges to distribute the stablecoin, identity providers to verify customers, blockchain analytics companies to monitor activity, and technology vendors to support issuance and redemption.
Each relationship can introduce additional risk.
If reserve assets are concentrated with one institution, the issuer may be vulnerable to a disruption at that institution. If a distributor applies weak customer controls, the stablecoin may gain exposure to activity the issuer did not anticipate. If a technology provider fails, issuance or redemption services may be interrupted.
Regulators will likely expect issuers to understand these dependencies rather than treating them as matters controlled entirely by outside parties.
This means third-party oversight may need to address more than initial vendor due diligence. Issuers may be expected to monitor service levels, compliance performance, financial condition, security incidents, geographic exposure, and changes in a provider’s business.
They may also need contingency plans for replacing critical partners without disrupting reserve access or customer redemptions.
Transparency remains important, but the quality and consistency of disclosures are likely to receive greater attention.
Stablecoin reserve disclosures currently vary in format, frequency, terminology, and level of detail. One issuer may provide an attestation, another may publish a reserve breakdown, and another may release only broad information about its backing.
These differences can make meaningful comparisons difficult.
Future oversight may push toward clearer standards for describing reserve assets, valuation methods, custody arrangements, redemption rights, fees, and material risks. Regulators may also scrutinize the language issuers use when discussing safety, stability, or government protection.
This is particularly important because payment stablecoins are not necessarily protected in the same way as bank deposits. The FDIC’s proposed GENIUS Act framework specifies that deposits held as stablecoin reserves would not be insured directly to stablecoin holders.
Customers should understand what they own, what redemption rights they have, and what protections do or do not apply.
Clear disclosures cannot replace effective risk management, but it can help prevent customers and counterparties from making decisions based on incomplete or misleading assumptions.
Companies should not wait until every implementing rule is final before evaluating whether their programs can meet the likely direction of supervision.
A practical readiness review should consider:
The goal is not to build controls around speculation. It is to recognize that the regulatory framework is already moving beyond a single measure of reserve sufficiency.
Issuers should be able to demonstrate not only that assets are present, but that the company can manage those assets, meet redemptions, detect suspicious activity, respond to sanctions exposure, recover from disruptions, and produce reliable information for supervisors.
Reserve transparency remains essential. Without reliable backing, confidence in a payment stablecoin can deteriorate quickly.
But transparency is only one component of trust.
A stablecoin can be fully backed and still experience governance failures, liquidity problems, sanctions exposure, technology outages, weak customer controls, or inaccurate reporting. Those risks become more significant as stablecoins move deeper into payments and financial markets.
The next phase of stablecoin oversight will focus on whether the entire system works—not simply whether the reserve account appears sufficient at a particular moment.
For issuers, the message is straightforward: proving the assets exist is the starting point. The larger challenge is proving that the organization surrounding those assets is prepared to operate like financial infrastructure.
The stablecoin regulatory landscape is evolving rapidly, and organizations that prepare early will have a meaningful advantage. Building a scalable compliance program today can reduce regulatory risk and position your business for long-term growth.
Have questions about stablecoin compliance? Reach out to BitAML to discuss your organization’s AML program, governance framework, or regulatory strategy. We’re here to help.
Stablecoins are often described as digital dollars that move across decentralized networks. That description is useful, but it leaves out one of their most important
The clearest lessons regulators are sending—and what your program should do next. If you want to know what regulators care about, don’t start with
Derivatives, Commodities, or Gambling? The Regulatory Crossroads Ahead From Signal to Scrutiny In Part 1, we looked at why prediction markets have captured so much