What to Look for in a Compliant Stablecoin Platform
A practical due diligence guide to stablecoin platform compliance, covering KYB, eligibility, wallet screening, custody, payment approvals and audit evidence.
A compliant stablecoin platform should give your finance team the controls and evidence needed to meet its own obligations: entity verification, jurisdiction and industry eligibility, sanctions and wallet screening, segregated payment approvals, clear custody arrangements and exportable audit records. No platform makes a company compliant automatically. Assess the exact legal entities, assets, networks, fiat partners and transaction flows your business will use.
A compliant stablecoin platform should give your finance team the controls and evidence needed to meet its own obligations: entity verification, jurisdiction and industry eligibility, sanctions and wallet screening, segregated payment approvals, clear custody arrangements and exportable audit records. No platform makes a company compliant automatically. Assess the exact legal entities, assets, networks, fiat partners and transaction flows your business will use.
Start with capabilities and evidence, not compliance claims
There is no universal designation that makes a stablecoin platform compliant for every company, jurisdiction or payment flow. Your obligations depend on where your entities operate, who they pay, the nature of their business, how funds are sourced and whether they hold or transfer assets for anyone else.
Ask the provider to map the complete operating model. Which entity contracts with your company? Which entity provides the wallet, fiat account, exchange or payment service? Which activities are performed by banks, custodians or other regulated partners? What checks does the platform perform, and what decisions remain with your team?
The following table turns those questions into an evidence request:
| Area | What to verify | Evidence to request |
|---|---|---|
| KYB | Entities, owners, directors and authorised users covered by verification | Document requirements, review process and refresh triggers |
| Eligibility | Supported jurisdictions, industries, use cases, assets and legal entities | Current eligibility matrix and restricted-activity criteria |
| Screening | Sanctions, recipient-address and transaction screening on each intended network | Sample result, alert workflow and disposition record |
| Approvals | Separation of beneficiary creation, payment preparation and release | Permission matrix, quorum configuration and approval log |
| Custody | Who controls assets, keys or signing credentials at each stage | Custody diagram, signer structure and recovery procedure |
| Fiat rails | Provider of each account, conversion service and payment rail | Entity-specific currency and corridor availability |
| Records | Events retained, export formats and access after termination | Sample evidence pack and contractual retention terms |
Check KYB and product eligibility separately
Know Your Business, or KYB, identifies the legal entity opening the account and the people who own or control it. A typical review may require a registry extract, constitutional documents, registered and operating addresses, an ownership chart, director details, authorised-user identification, business activities, expected transaction volumes and source-of-funds information.
Beneficial ownership thresholds differ by jurisdiction and provider. A 25% threshold appears in many KYB processes, but a provider may use a lower threshold or identify a senior managing official when no individual meets the applicable ownership test. Ask how layered ownership, trusts, nominees and recently formed entities are handled.
Approval at onboarding is not the end of the process. Determine what triggers a refresh, such as a change in ownership, directors, address, expected activity or document validity. Your company should have an internal process for notifying the provider when material facts change.
Eligibility is a separate decision. A company can pass identity verification but remain unsupported because of its jurisdiction, industry, ownership structure or proposed use. Confirm eligibility for the contracting entity and intended activity before building operational processes around the platform.
Evaluate screening on the actual asset and network
Stablecoin payments use blockchain addresses, so diligence must extend beyond conventional counterparty names and bank details. Sanctions screening checks relevant people and entities against applicable lists. Address screening examines blockchain exposure associated with a wallet, while transaction monitoring evaluates transfers and related activity.
Coverage must be network-specific. USDT on Tron and USDT on Ethereum operate in different blockchain environments, even though both use the USDT symbol. The same principle applies to USDC across Ethereum, Base, Arbitrum, Polygon, Solana and other supported networks. Confirm screening coverage for every asset-network combination your treasury intends to use.
Ask when a destination is screened, whether it is checked again when beneficiary details change and whether the transfer can be paused before broadcast. The alert record should show the address, network, result, review time, reviewer, decision and any supporting notes. Stablerail, for example, provides sanctions and address screening before send alongside approvals and signing quorum for a company’s own USDC or USDT.
A risk score is an input, not proof that a wallet is safe or prohibited. Indirect exposure, attribution confidence and activity recency can affect a result. Your company should define who can clear an alert, when legal or compliance review is required and what evidence must support the decision.
Test approvals and segregation of duties
Stablecoin payment authority should be controlled as carefully as bank payment authority. One person should not ordinarily be able to add a destination, prepare a transfer and release it without independent review.
Review permissions for beneficiary and allowlist changes, individual and batch payments, approvals, signing, user administration, corporate cards and evidence exports. Determine whether controls can distinguish between preparation, approval and execution, and whether sensitive user or destination changes produce an auditable event.
Also identify where approval is enforced. An application-level approval records authorisation in the platform, while a signing quorum requires the configured participants or credentials before a blockchain transaction can be signed. Multi-party computation can distribute signing authority without storing one complete private key in one place, but it does not remove the need for secure devices, disciplined user administration and tested recovery procedures.
Run practical exception scenarios. What happens if an approver leaves, loses a device or is unavailable? Can an administrator lower a quorum alone? Can the provider execute a transfer without the customer’s required approval? The answers determine whether the control remains effective under pressure.
Understand custody and the full movement of funds
The word custody can describe materially different arrangements. In a custodial model, a custodian controls the signing keys. In a self-custodial model, the customer retains control, although software providers may facilitate signing. Other structures divide responsibilities among the customer, platform and specialist providers.
Map control at every stage rather than accepting a single label. Establish which legal entity holds fiat balances, who controls stablecoin vaults, whether assets are separated from provider operating funds and how access is recovered. Ask what happens during a service interruption, account restriction, insolvency event or account closure.
Fiat services require the same scrutiny. If a platform supports ACH, Fedwire, SWIFT, SEPA, Faster Payments or named account details, identify the institution providing each service. Availability can vary by customer entity, currency, country and corridor. Confirm whether conversion occurs before deposit, on instruction or during payout, and identify the rate and fee records available for reconciliation.
Demand audit-ready records
A finance team should be able to reconstruct who did what, when and why. Logs should cover user and role changes, beneficiary edits, screening results, payment creation, approvals, signatures, execution, failures and reversals where applicable.
For each transfer, useful evidence includes the blockchain transaction hash or bank reference, asset, network, amount, network fee, conversion details, source and destination, creator and approver timestamps, screening outcome and attached invoice, payroll file or other supporting document. Exports should be usable outside the platform and align with the fields needed by accounting, audit and compliance teams.
Ask for the exact retention period and what happens after account closure. Recordkeeping duties often extend for years, but the applicable period depends on the jurisdiction, activity and record type. The company remains responsible for determining how long it must retain its own evidence.
Run a controlled pre-launch test
Before moving material treasury funds, complete an end-to-end test for every important asset, network and fiat route:
- Onboard the correct legal entity and confirm its product eligibility.
- Create separate preparer, approver and administrator roles.
- Add and screen a test beneficiary on the intended network.
- Send a low-value transfer using the required approval and signing quorum.
- Test a rejected, paused or expired approval.
- Export the screening, approval and transaction evidence.
- Reconcile the principal, network fee and any fiat conversion in the ledger.
- Document recovery and employee-offboarding procedures.
Repeat the exercise when adding a network, asset, entity or payment corridor. Support for USDC, USDT or a fiat currency does not necessarily mean that every combination is available to every corporate entity.
Make the decision on demonstrable controls
The strongest platform is not the one making the broadest compliance claim. It is the one that can clearly explain its legal and operational model, screen the transfers your company actually makes, enforce appropriate payment authority and produce evidence that survives audit.
Finance, legal, compliance, security and accounting teams should sign off on their respective areas. Record accepted limitations, assign control owners and schedule periodic reviews. A platform can make compliant operation easier to execute and demonstrate, but accountability for the company’s funds and obligations remains with the company.
Frequently asked questions
Can a stablecoin platform make my company compliant?
No. A platform can provide KYB, screening, approvals and records, but the company remains responsible for its legal, regulatory and internal policy obligations. Those obligations depend on the company’s jurisdictions, counterparties, business model and use of stablecoins.
What compliance documents should I request from a stablecoin platform?
Request the KYB process, eligibility criteria, network-specific screening workflow, permission matrix, custody and signing diagram, recovery procedure, partner responsibilities and a sample audit export. Verify that each document applies to your contracting entity and intended payment routes.
What is the difference between sanctions screening and wallet screening?
Sanctions screening checks people, entities and identified addresses against applicable sanctions lists. Wallet screening examines blockchain activity and exposure linked to an address, such as connections to sanctioned actors, theft or fraud. Neither result should replace a documented review and escalation process.
Should stablecoin recipient addresses be screened before payment?
Yes, screening before broadcast can identify concerns while the transfer can still be stopped. The platform should retain the address, network, result, timestamp and review decision, and the address should be checked again when beneficiary details change.
What audit evidence is needed for a stablecoin payment?
Retain the transaction hash, asset, network, amount, fees, source and destination, screening result, approval history and supporting business document. If fiat conversion is involved, also retain the exchange rate, conversion reference and bank or payment-rail record.
Finance writers covering stablecoin treasury, payments, compliance, and risk controls.
More about the Stablerail team- Stablecoin treasury managementApprovals, limits, yield and reporting on one balance.
- Stablecoin payoutsBatch contractor and vendor payments with screening.
- USDT vs USDCWhich stablecoin your company should settle in.
- Stablecoin finance glossaryMPC, off-ramp, travel rule and the rest, in plain English.
- Product updatesEverything we ship, month by month.

