Stablecoin Compliance Checklist
A practical stablecoin compliance checklist for finance teams using USDC or USDT, covering regulatory scope, counterparties, sanctions, approvals, accounting, tax and audit records.
A stablecoin compliance checklist should establish where and how the business uses stablecoins, determine whether licensing or financial-crime rules apply, verify counterparties, screen wallet addresses, control transaction approvals, and preserve accounting and audit records. Requirements depend on the company’s activities, counterparties and jurisdictions, so finance teams should validate the checklist with qualified legal, tax and accounting advisers before launching or expanding a stablecoin program.

A business using stablecoins should first define its activities and jurisdictions, then address licensing, counterparty due diligence, sanctions screening, transaction approvals, custody, accounting, tax and record retention. The controls must follow the entire transaction lifecycle, not just wallet setup. Because obligations vary significantly by country and business model, the final framework should be reviewed by legal, tax and accounting professionals familiar with the relevant entities.
Why stablecoin compliance starts with the business model
There is no universal compliance checklist for every stablecoin transaction. A company holding USDC or USDT for its own treasury presents a different regulatory profile from a company issuing a token, exchanging assets for customers, operating custodial wallets or transmitting value on behalf of third parties.
Before writing procedures, document exactly what each legal entity does. Include whether it buys or sells stablecoins, accepts customer payments, pays suppliers, runs global payroll or contractor payouts, provides an off-ramp, safeguards customer assets or controls transactions for another party.
This activity map determines which questions matter. Depending on the jurisdiction, exchanging, transferring, arranging or safeguarding cryptoassets for others may trigger registration, licensing, financial-crime or safeguarding requirements. Using stablecoins solely for the company’s own payments may be treated differently, but it does not remove sanctions, tax, accounting or governance obligations.
Stablecoin compliance decision table
| Area | Question to answer | Control or evidence to maintain |
|---|---|---|
| Regulatory perimeter | Is the company acting only for itself, or exchanging, transmitting, issuing or safeguarding assets for others? | Entity-by-entity legal analysis, product descriptions and counsel conclusions |
| Jurisdictions | Where are the entities, customers, beneficiaries, banks, exchanges and wallet providers located? | Country matrix showing applicable rules, restrictions and responsible owners |
| Stablecoin and network | Which token contract and blockchain will be used? | Approved asset list, verified contract addresses and supported-network controls |
| Counterparties | Who owns or controls the receiving or sending party? | KYC or KYB records, beneficial-owner information and risk classification |
| Financial crime | Could the transaction involve sanctions, fraud, money laundering or illicit wallet activity? | Address-screening results, investigation notes, escalation decisions and case records |
| Transfer information | Do Travel Rule or equivalent originator and beneficiary requirements apply? | Required transfer data, provider communications and proof of transmission |
| Accounting and tax | How will balances, fees, gains, losses and tax consequences be recorded? | Accounting policy, transaction-level ledger, valuations and tax workpapers |
| Custody and security | Who can initiate, approve and sign a transaction? | Access register, signing quorum, approval history and key-management procedures |
Pre-launch stablecoin compliance checklist
- Define the permitted use cases. State which entities may hold stablecoins, why they may use them, approved payment types, transaction limits and prohibited activity. A narrow initial scope is easier to govern than an open-ended mandate.
- Map every relevant jurisdiction. Include the company’s place of incorporation and operation, as well as the locations of customers, suppliers, employees, exchanges, custodians and banking partners. Do not assume the law of the wallet provider’s home country is the only law that matters.
- Confirm the regulatory perimeter. Obtain advice on whether the activity involves money transmission, payment services, virtual-asset services, custody, exchange, brokerage, issuance or another regulated service. Record the conclusion, assumptions and activities that would require reassessment.
- Approve assets and networks. Identify stablecoins by issuer, ticker, blockchain and verified token contract. USDC and USDT exist on multiple networks, and sending a legitimate token over an unsupported network can still result in loss. Review issuer terms, redemption access, reserve disclosures and any technical ability to freeze addresses or tokens.
- Perform proportionate counterparty checks. Collect legal name, registration details, business purpose, beneficial ownership and payment instructions where required by law or risk policy. Higher-risk relationships may justify additional source-of-funds, source-of-wealth or transaction-purpose evidence.
- Screen relevant parties and wallet addresses. Check names against applicable sanctions lists and screen sending and receiving addresses before execution. Define what happens when a tool reports direct exposure, indirect exposure, a sanctioned party or another risk indicator. Screening output is an input to a documented decision, not proof that a transaction is lawful.
- Assess transfer-data obligations. The Travel Rule may require regulated firms to collect and transmit originator and beneficiary information for covered transfers. Applicability, thresholds and required fields differ by jurisdiction, so the procedure should identify when it applies and how data is exchanged securely.
- Design approval and signing controls. Separate transaction initiation, approval and signing where practical. Use role-based access, approval thresholds and a signing quorum instead of shared credentials or informal approval in messaging applications. Changes to beneficiary details should trigger independent verification.
- Document accounting and tax treatment. Set policies for initial recognition, subsequent measurement, network fees, exchange fees, foreign-currency effects and gains or losses. The correct treatment depends on the applicable accounting framework and facts. Preserve transaction hashes and wallet data, but also record the legal entity, counterparty, invoice, business purpose and functional-currency value.
- Prepare incident and exception procedures. Assign owners for suspected sanctions matches, compromised credentials, mistaken networks, incorrect addresses, depegging events and unavailable off-ramps. Stablecoin transfers are generally not reversible through the blockchain, so prevention and rapid escalation matter.
Controls for each stablecoin transaction
Compliance should be embedded in the payment workflow. A policy that is disconnected from wallet operations will not reliably prevent an unapproved or high-risk transfer.
| Transaction stage | Minimum finance control | Evidence to retain |
|---|---|---|
| Request | Capture beneficiary, purpose, amount, asset, network and supporting invoice or agreement | Payment request and business justification |
| Verification | Confirm beneficiary identity and independently verify new or changed wallet details | KYB or KYC result and verification record |
| Pre-send review | Screen parties and addresses, check the network, and assess regulatory or Travel Rule requirements | Timestamped screening result and reviewer decision |
| Approval | Apply approval thresholds, segregation of duties and signing quorum | Named approval and signing history |
| Execution | Validate the address and token contract; use a test transfer when risk warrants it | Transaction hash, wallet addresses and execution timestamp |
| Reconciliation | Match the on-chain transfer to the invoice, ledger entry, fees and applicable exchange rate | Reconciliation file and exception resolution |
| Retention | Store the complete record under the applicable legal and tax retention schedule | Exportable case, approval and accounting evidence |
Finance teams should avoid relying on a block explorer as the accounting record. A transaction hash shows that an on-chain event occurred, but it does not establish the commercial purpose, authorized approver, beneficial owner, sanctions review or accounting conclusion.
A platform such as Stablerail can bring USDC and USDT treasury activity into one business account with approvals and signing quorum, sanctions and address screening before send, corporate cards, global payouts, fiat off-ramp and exportable audit evidence. The company remains responsible for determining which laws apply and configuring its operating procedures accordingly.
Accounting, reconciliation and audit readiness
Maintain a subledger that ties each stablecoin movement to the general ledger. It should distinguish purchases, sales, customer receipts, supplier payments, internal wallet transfers, fees and conversions. Internal transfers should not be mistaken for revenue or expense merely because they appear as separate on-chain transactions.
Define a consistent valuation source and timestamp for financial reporting. Reconcile wallet balances to the subledger and general ledger at a frequency appropriate to transaction volume and risk. Investigate differences caused by fees, unsupported tokens, duplicate imports, pending transactions or transfers between company-controlled wallets.
Auditors may need evidence that the entity controls a wallet as well as evidence of the balance. Preserve access-control records, approval histories and ownership documentation. Never disclose seed phrases or private keys as audit evidence.
Keep the checklist current
Stablecoin rules, sanctions designations, issuer terms and supported networks can change. Assign an owner to review the program on a defined schedule and when a trigger event occurs, such as entering a new country, adding a stablecoin, changing custody arrangements or launching customer-facing transfers.
- Review approved entities, use cases, assets and networks.
- Test access, approval and signing permissions.
- Sample transactions for due diligence, screening and reconciliation evidence.
- Review unresolved alerts, exceptions and incidents.
- Update legal, accounting and tax conclusions when facts change.
A checklist is most effective when every requirement has an owner, evidence standard and escalation route. It organizes the work, but it does not replace jurisdiction-specific professional advice or management accountability.
Frequently asked questions
What compliance is required to use USDC or USDT for business payments?
Requirements depend on whether the company is paying on its own behalf or providing exchange, transfer, custody or payment services for others. Businesses should assess licensing, sanctions, counterparty due diligence, Travel Rule applicability, tax, accounting and record-retention obligations in every relevant jurisdiction.
Does a business need KYC for every stablecoin payment?
Not necessarily. The legal requirement depends on the company’s regulated status, jurisdiction, counterparty and transaction type, but businesses should still know who they are paying and retain evidence of the commercial purpose. A risk-based policy should define when basic verification or enhanced due diligence is required.
How should a company screen stablecoin wallet addresses?
Screen sending and receiving addresses before execution using the sanctions lists and risk criteria applicable to the business. Document the result, reviewer and escalation decision, and do not treat a low-risk score as a guarantee that the transaction is lawful.
Does the Travel Rule apply to stablecoin transfers?
It can apply when a regulated virtual-asset or financial-services provider conducts a covered transfer. Thresholds, data fields and treatment of self-hosted wallets vary by jurisdiction, so businesses should document where the rule applies and how required originator and beneficiary data will be handled.
What stablecoin records should a business keep for an audit?
Keep the transaction hash, addresses, token and network, amount, timestamp, fees, valuation, counterparty, invoice, business purpose, screening result and approval history. These records should reconcile to the stablecoin subledger and general ledger while preserving evidence of wallet access and control.
Former CEO of Simple, a self-custodial wallet with $2B+ in transaction volume across 75+ countries.
More about the Stablerail team- Stablecoin treasury managementApprovals, limits, yield and reporting on one balance.
- Stablecoin payoutsBatch contractor and vendor payments with screening.
- USDT vs USDCWhich stablecoin your company should settle in.
- Stablecoin finance glossaryMPC, off-ramp, travel rule and the rest, in plain English.
- Product updatesEverything we ship, month by month.

