Compliance Frameworks for Embedding an MPC Wallet in Payments
A practical framework for assessing AML, licensing, SOC 2, ISO 27001, privacy, Travel Rule, PCI DSS and operational resilience obligations when embedding an MPC wallet.
Embedding an MPC wallet into a payment product changes how transactions are authorized, but it does not determine the product’s regulatory classification. Regulators generally look at the service being provided, who controls customer assets, how funds move and which parties can stop or initiate a transaction.
Multi-party computation, or MPC, divides the cryptographic signing process across multiple key shares. A complete private key does not need to exist in one location. This can reduce single-key risk and support quorum approvals, but it does not automatically make a product self-custodial, compliant or exempt from licensing.
The correct compliance scope depends on product design and jurisdiction. The following framework helps finance, legal and engineering teams identify the questions that should be resolved before launch.
Start with the payment and custody model
Document the full movement of fiat and stablecoins before selecting frameworks or commissioning audits. The analysis should cover account opening, deposits, conversion, wallet creation, transaction approval, settlement, reversals and account closure.
| Design question | Why it matters |
|---|---|
| Whose funds are held? | Holding customer funds can trigger custody, safeguarding, money transmission or payment-services obligations. |
| Who controls the MPC key shares? | A provider that can independently or jointly move assets may be treated differently from a vendor supplying software only. |
| Can the customer transact without the provider? | Recovery, transaction vetoes and unilateral control affect whether the arrangement is meaningfully self-custodial. |
| Does the product exchange fiat and stablecoins? | Conversion may introduce virtual-asset, money-services, payments and banking-partner requirements. |
| Are payments made for customers or only for the company’s own treasury? | Moving third-party funds generally creates more licensing exposure than managing a company’s own assets. |
| Which countries, networks and counterparties are supported? | Obligations can attach to the customer, recipient, legal entity, transaction corridor or blockchain network. |
Write the answers into the product specification and contractual model. Marketing language such as “non-custodial” is not conclusive if the technical and operational arrangements show that the provider can control transfers.
AML, KYC and sanctions controls
AML and know-your-customer requirements may apply where the business qualifies as a money services business, payment institution, cryptoasset service provider or another regulated intermediary. A typical program may include:
- Customer or business identification, including beneficial-owner checks.
- Risk classification by jurisdiction, industry, product and expected activity.
- Sanctions and politically exposed person screening.
- Blockchain wallet screening and transaction monitoring.
- Escalation, investigation and regulatory reporting procedures.
- Record retention and periodic customer reviews.
Sanctions controls should address both names and wallet addresses. In the United States, this includes exposure to Office of Foreign Assets Control requirements. Other jurisdictions maintain separate sanctions lists and reporting rules. Screening should occur at onboarding and, based on risk, before or after transactions. Teams also need a documented process for false positives, blocked activity and funds associated with newly sanctioned addresses.
Wallet risk can be reviewed before a payment using Stablerail’s wallet checker, but screening technology is only one part of a complete payment compliance program.
Licensing depends on what the product does
United States
A provider accepting and transmitting value may need to assess federal registration as a money services business under FinCEN rules and state-by-state money transmitter licensing. The analysis can differ based on whether the provider controls funds, acts as an agent, supplies software or moves money between users. Stablecoin activity does not create a general exemption.
European Union
MiCA establishes authorization and conduct requirements for cryptoasset service providers. The EU Transfer of Funds Regulation extends information requirements to certain cryptoasset transfers. PSD2 and local payment-services rules may also be relevant where the product handles fiat accounts, executes payment transactions or provides regulated payment services. The interaction between these regimes should be assessed for each flow rather than assuming one authorization covers everything.
United Kingdom
Businesses may need to consider FCA registration under the Money Laundering Regulations for in-scope cryptoasset activities. Fiat payment or stored-value features may separately engage the Payment Services Regulations or Electronic Money Regulations. Registration for AML supervision is not the same as authorization to provide all payment services.
Other jurisdictions use different definitions and thresholds. Before enabling a country, record the legal entity serving the customer, regulated activity, licensing basis, banking or liquidity providers, and any geographic restrictions.
Travel Rule considerations
The Travel Rule can require specified originator and beneficiary information to accompany transfers between regulated virtual-asset businesses. Required data, thresholds and handling of transfers to self-hosted wallets vary by jurisdiction.
An MPC wallet integration should therefore support counterparty classification, collection of required identity fields, secure data exchange, retention and exception handling. Blockchain transaction data alone usually does not contain all required Travel Rule information. The operational process should also cover missing data, unsupported counterparties and transfers involving an unhosted wallet.
SOC 2 and ISO 27001
SOC 2 and ISO 27001 are assurance and security frameworks, not substitutes for financial-services licenses.
A SOC 2 examination evaluates controls against selected Trust Services Criteria over a stated system boundary and period. Buyers should inspect the report’s scope, type, exceptions, subservice organizations and complementary user-entity controls rather than relying on a logo.
ISO 27001 specifies requirements for an information security management system. Certification scope matters: an organization can be certified while a particular wallet service, cloud environment or operating entity sits outside the defined boundary.
For an MPC wallet, relevant controls commonly include key-share generation, privileged access, code changes, transaction policy configuration, backups, incident response, vendor management and employee access removal.
Privacy and data location
Wallet addresses may become personal data when they can be linked to an identifiable person. KYC records, device data, IP addresses and transaction histories also create privacy obligations.
Under frameworks such as the EU GDPR and UK GDPR, teams should identify a lawful basis, issue appropriate notices, minimize collection, set retention periods and manage processor agreements and international transfers. Similar reviews may be required under US state privacy laws and other national regimes.
Blockchain records are difficult or impossible to erase. Avoid placing personal information directly on-chain. Store necessary identity data off-chain and link it using controlled internal references.
Operational resilience and transaction recovery
Operational resilience covers the ability to prevent, withstand and recover from disruptions. Depending on the business, requirements may arise from financial-services rules, the EU Digital Operational Resilience Act, outsourcing guidance or contractual commitments to regulated customers.
An embedded wallet plan should define:
- Recovery procedures for lost, unavailable or compromised key shares.
- Quorum rules and emergency approval paths.
- Dependencies on cloud providers, MPC vendors, blockchain nodes and screening services.
- Response procedures for network congestion, chain reorganizations and stablecoin contract restrictions.
- Recovery time and data-loss objectives supported by testing.
- Incident notification responsibilities and evidence retention.
Quorum signing can reduce dependence on one person or device, but poorly designed recovery procedures can introduce a new single point of failure.
When PCI DSS applies
PCI DSS applies to environments that store, process or transmit payment card account data, or can affect the security of that environment. It does not generally apply merely because an application includes a stablecoin wallet.
It becomes relevant when the product accepts cards, issues or manages card credentials, displays primary account numbers, or operates systems connected to the cardholder data environment. Tokenization and hosted payment pages can reduce scope, but scope reduction must be validated. A corporate card funded from a treasury balance still requires a clear division of PCI DSS responsibilities between the platform, issuer, processor and customer.
A practical pre-launch evidence pack
Before production use, assemble a review pack containing:
- Funds-flow and data-flow diagrams.
- MPC key-share ownership, signing and recovery documentation.
- Country-by-country licensing analysis and launch restrictions.
- AML, sanctions, wallet-screening and Travel Rule procedures.
- SOC 2 reports, ISO 27001 certificates and scope statements where applicable.
- Privacy impact and international data-transfer assessments.
- PCI DSS responsibility mapping if card data is involved.
- Incident, business continuity and disaster-recovery test results.
- Vendor contracts, service dependencies and exit plans.
For corporate stablecoin operations, Stablerail combines self-custodial MPC vaults and quorum signing with approval limits, allowlists, screening, audit logs and evidence packs. Teams can use these controls alongside fiat rails, stablecoin conversions and stablecoin payouts. The applicable regulatory obligations still depend on the company’s activities, customers and jurisdictions.
The central conclusion is simple: MPC is a security and authorization architecture. Regulatory classification follows the actual payment, custody and control model—not the cryptography alone.
Finance writers covering stablecoin treasury, payments, compliance, and risk controls.
More about the Stablerail team- Stablecoin treasury managementApprovals, limits, yield and reporting on one balance.
- Stablecoin payoutsBatch contractor and vendor payments with screening.
- USDT vs USDCWhich stablecoin your company should settle in.
- Stablecoin finance glossaryMPC, off-ramp, travel rule and the rest, in plain English.
- Product updatesEverything we ship, month by month.

