Growth

DIGITAL ASSET COMPLIANCE IN 2026

By Eric Williamson
AI & Data: Who Really Holds the Power?

A PRACTICAL GUIDE TO

DIGITAL ASSET COMPLIANCE

IN 2026

A comprehensive guide to the global regulatory landscape for digital assets: AML/KYC, risk management, the UK, EU, US, Asia-Pacific and Gulf regimes, and practical steps for lasting compliance.

Updated edition, August 2026

Contents

What Digital Asset Compliance Really Means          

The Three Pillars of Digital Asset Compliance          

1. Anti-Money Laundering (AML)      

2. Know Your Customer (KYC)         

3. Market integrity rules         

Navigating the Global Regulatory Landscape in 2026         

The United Kingdom: A New Cryptoasset Regime Takes Shape    

The Five Policy Statements   

Timeline to Commencement  

What the Regime Covers      

Scale of the UK Retail Market           

MiCA: The Transitional Period Has Ended   

The USDT Delisting   

The PSD2 Convergence        

The United States: Legislation in Place, Implementation Behind Schedule 

Key Provisions           

The Missed Rulemaking Deadline     

Market Response       

FATF's Travel Rule: Adoption Advancing, Enforcement Still Lagging         

The Enforcement Gap           

DeFi Remains Largely Unaddressed

Beyond the Big Three: Asia-Pacific and the Gulf      

Hong Kong     

Singapore       

South Korea   

The Gulf: UAE and Dubai      

Key Global Regulatory Frameworks at a Glance (August 2026)      

Building a Bulletproof Compliance Programme        

Establishing Strong Governance       

Conducting a Thorough Risk Assessment    

Implementing Essential Internal Controls      

Independent Testing and Audits        

The Technology Powering Modern Compliance       

Blockchain Analytics  

Proof-of-Reserves and Attestations  

The EU's New AML Architecture: AMLA       

What Compliance Means for Your Role        

Guidance for Investors          

Guidance for Developers       

Guidance for FinTech Leaders          

Guidance for Compliance Officers    

What's Next for Digital Asset Compliance?   

DeFi Compliance Is No Longer Optional       

Smarter Enforcement and Global Coordination        

The Regulatory Frontiers to Watch   

Frequently Asked Questions 

1. What Is the Difference Between AML and KYC? 

2. What Is the GENIUS Act? 

3. Does MiCA Apply to My Business Outside the EU?         

4. What Is the New UK Cryptoasset Regime, and When Does It Apply?    

5. Does Digital Asset Compliance Apply to DeFi?    

6. What Is the Crypto Travel Rule?   

7. Can I Still Buy or Hold USDT in the EU?  

8. What Should a UK Firm Do Before the FCA Authorisation Gateway Opens?

Introduction

Digital asset compliance is the set of rules and internal processes that allow cryptocurrencies and other tokens to operate within the same standards as the rest of the financial world. It covers everything built to prevent financial crime, protect consumers and keep the market fair.

Think of it as the bridge connecting the fast-paced world of digital assets with the established frameworks of global finance.


This edition has been substantially expanded and updated as at 6th August 2026. It reflects, among other developments, the United Kingdom's finalised cryptoasset regime (PS26/9 to PS26/13), the completion of MiCA's transitional period and the resulting delisting of non-compliant stablecoins, the United States' missed statutory deadline for GENIUS Act implementing rules, and the FATF's Seventh Targeted Update on virtual assets.

What Digital Asset Compliance Really Means

At its core, compliance is not about slowing things down. It is about building the trust needed for crypto to go mainstream.

Without rules, the digital marketplace would be chaotic, risky and a non-starter for serious institutional investors. Compliance brings the order and predictability that institutions and everyday users need to feel confident.

This framework stands on three core pillars. If one is weak, the entire structure is shaky.

The Three Pillars of Digital Asset Compliance

1. Anti-Money Laundering (AML)

Covers the procedures that stop bad actors from using crypto to wash dirty money. It means actively monitoring transactions for suspicious activity and reporting it to the relevant authorities.

2. Know Your Customer (KYC)

The process of verifying that customers are who they claim to be. This is a critical defence against fraud, identity theft and criminals seeking to open anonymous accounts. A credible AML programme cannot function without it.

3. Market integrity rules

Outlaw practices such as wash trading and insider trading, protecting investors and building genuine confidence in an asset's true value.


A strong compliance framework is the engine for institutional investment. It transforms digital assets from a speculative niche into a legitimate asset class, and more than half of traditional hedge funds now hold some form of digital asset exposure, the highest proportion ever recorded. That institutional momentum is not happening in spite of stricter compliance requirements. It is happening because of it.

 Navigating the Global Regulatory Landscape in 2026

The global regulatory picture looks fundamentally different in mid-2026 than it did even eighteen months ago. The United Kingdom has finalised its cryptoasset regime, the European Union's stablecoin transition has run its course, and the United States has legislated even as its implementing rules have fallen behind schedule. The ripple effects are reshaping compliance programmes everywhere.

Understanding the major frameworks is no longer optional. It is the baseline.

The United Kingdom: A New Cryptoasset Regime Takes Shape

The UK was conspicuously absent from earlier compliance guides written before mid-2026, largely because its framework existed only as a roadmap and a stack of consultation papers. That changed decisively on 30 June 2026, when the Financial Conduct Authority (FCA) published five policy statements setting out final rules for cryptoasset firms, alongside finalised guidance and two further guidance consultations.

The new regime sits on top of the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026, passed by Parliament on 4 February 2026. These regulations bring a broad range of cryptoasset activities within the FCA's regulatory perimeter for the first time, extending well beyond the anti-money laundering and financial promotions rules that previously defined the UK's approach.

The Five Policy Statements

The FCA's package, the product of more than three years of consultation across four discussion papers and ten consultation papers, comprises:

•     PS26/9: Admissions and Disclosures (A&D) and the Market Abuse Regime for Cryptoassets (MARC), governing how a cryptoasset is brought onto a UK trading platform, the disclosure documents required, and a dedicated market abuse regime for qualifying cryptoassets.

•     PS26/10: Stablecoin Issuance, finalising requirements for fiat-backed stablecoin issuers, including reserve and redemption requirements.

•     PS26/11: Regulated Cryptoasset Activities, confirming the perimeter and conduct requirements for firms operating UK Qualifying Cryptoasset Trading Platforms (QCATPs), intermediaries (dealers and arrangers), lending and borrowing, staking and safeguarding, together with the FCA's interim approach to decentralised finance and to international firms.

•     PS26/12: the prudential regime for cryptoasset firms, setting out capital, liquidity and risk management requirements, supplemented by further consultations on non-Handbook prudential guidance (COREPRU and CRYPTOPRU).

•     PS26/13: application of the wider FCA Handbook to regulated cryptoasset activities, confirming how existing provisions, including the Consumer Duty and operational resilience requirements, extend to cryptoasset firms.

On the retail access perimeter, firms will only be permitted to deal or arrange cryptoasset trades for UK retail clients where the cryptoasset has been admitted to trading on a retail UK QCATP with a published Qualifying Cryptoasset Disclosure Document (QCDD). The FCA has, however, confirmed it will consult in September 2026 on an optional deferral mechanism, likely to extend by six months the time QCATP operators have to bring existing retail-traded assets up to A&D-compliant disclosure standards ahead of go-live.

Timeline to Commencement

The full scope of regulated activities under the new regime will not bite immediately. Firms have a defined runway to prepare:

•     30 June 2026: final policy statements and finalised guidance published.

•     30 September 2026: FCA authorisation gateway opens for firms seeking to carry on regulated cryptoasset activities.

•     25 October 2027: the Cryptoassets Regulations, and the FCA's regime built on top of them, formally commence.

Compliance and risk teams should treat the period between now and October 2027 as an implementation runway rather than a distant deadline. Authorisation applications, governance arrangements, prudential resourcing and Consumer Duty embedding all take time to build properly, and the FCA has signalled it expects firms to use the runway accordingly.

What the Regime Covers

The regime groups regulated activities broadly as follows:

•     Operating a UK Qualifying Cryptoasset Trading Platform (QCATP), including matched principal trading, best execution and pre-trade disclosure obligations, with certain deferrals for principal dealers under active consultation.

•     Dealing as principal or as agent, and arranging deals, in qualifying cryptoassets, together grouped by the FCA as 'Intermediaries'.

•     Lending and borrowing business models involving qualifying cryptoassets.

•     Staking services.

•     Safeguarding (custody) of qualifying cryptoassets.

The FCA has confirmed it will not require legal entity separation for principal dealers, though they may not deal on their own platform, and best execution obligations will not apply to UK QCATPs conducting matched principal trading on their own platform. In April 2026 the Government published a draft statutory instrument proposing to exclude activities involving UK-issued qualifying stablecoins from the arranging and dealing perimeter, with the intention of bringing those activities instead under a modernised future payments regime.

Scale of the UK Retail Market

The FCA's own research puts the scale of what is at stake in context. Its Cryptoasset Consumer Research series indicates demand among UK adults doubled between 2020 and 2025, from four per cent to eight per cent, with consumers primarily motivated by rapid asset price rises and the prospect of making money quickly. The FCA's Financial Lives Survey data separately suggests around 300,000 adults were affected by cryptoasset scams in 2024, a figure that underlines why consumer protection sits at the heart of the new regime rather than as an afterthought.


Practical takeaway for compliance and risk teams: the authorisation gateway opens on 30 September 2026. Firms intending to operate UK QCATPs, act as cryptoasset intermediaries, or provide lending, staking or safeguarding services to UK clients should be scoping their FSMA authorisation application, prudential resourcing under COREPRU/CRYPTOPRU, and Consumer Duty embedding well in advance of that date, notwithstanding the October 2027 commencement date for the wider regime.

MiCA: The Transitional Period Has Ended

For years, European crypto operators dealt with a patchwork of national rules. The EU's Markets in Crypto-Assets regulation (MiCA) ended that era.

MiCA's stablecoin provisions came into force on 30 June 2024. Full CASP licensing requirements followed on 30 December 2024. As of 1 July 2026, the grandfathering period for legacy operators has expired in every member state, and there is no further grace period.

The regulation created strict requirements for stablecoin issuers across all 27 member states: mandatory one-to-one reserve backing, comprehensive AML/KYC compliance, market abuse prevention and regular audits. MiCA also introduced passporting rights, allowing a CASP authorised in one EU country to operate across the entire bloc.

Implementation was not seamless. Transitional periods varied dramatically by jurisdiction: the Netherlands required compliance by July 2025, while France, Malta and Estonia extended theirs to July 2026. This fragmentation created regulatory arbitrage opportunities that the European Securities and Markets Authority (ESMA) has spent the past year working to close.

The USDT Delisting

The most consequential enforcement reality under MiCA has played out in real time over the course of 2026. Tether never applied for e-money token (EMT) authorisation, objecting publicly to MiCA's requirement that a substantial share of reserves sit in EU bank deposits. As of 1 July 2026, no MiCA-licensed exchange in the European Economic Area offers USDT trading pairs: Coinbase, Kraken, Crypto.com and other licensed venues pulled their EU order books for USDT ahead of the deadline.

Holding USDT in self-custody remains entirely legal. What has changed is that a MiCA-licensed venue cannot list or offer it to EU clients. Circle's USDC, and its euro-denominated sister token EURC, secured EU e-money institution authorisation and have consequently emerged as the default MiCA-compliant settlement rails, alongside a small number of bank-issued alternatives such as Société Générale's EUR CoinVertible. The licensed field has consolidated around roughly fourteen major consumer exchanges holding full trading licences, with the wider CASP register, including brokers, custodians and fintechs, standing at approximately 240 authorisations by the July 2026 deadline and still growing.

For operators and investors alike, the lesson is straightforward: an asset's regulatory status under MiCA is now a primary determinant of its accessibility to EU retail and institutional clients, independent of its market capitalisation or liquidity elsewhere.

The PSD2 Convergence

A second, quieter compliance story has run in parallel: the collision between MiCA and the EU's Payment Services Directive (PSD2). The European Banking Authority (EBA) concluded that transferring an e-money token can itself qualify as a payment service, because an EMT is legally electronic money. Two regulatory regimes therefore apply to the same transaction.

To manage the transition, the EBA issued a no-action letter on 10 June 2025 asking national authorities to hold off on enforcement. That grace window closed on 2 March 2026, and the EBA's follow-up Opinion (EBA/OP/2026/01), published on 12 February 2026, set out what happens next: a CASP executing EMT transfers that qualify as payment services must hold its own payment institution or e-money institution authorisation, partner with an authorised payment provider, or have an application already in the pipeline under strict conditions. Firms with none of the above face business cessation measures and mandated customer offboarding, in the EBA's own phrasing.

More than 100 CASPs had approached national authorities about PSD2 authorisation by the time the Opinion landed. Cyprus emerged as an early blueprint jurisdiction, with CySEC and the Central Bank of Cyprus issuing joint dual-licensing guidance for firms navigating both regimes simultaneously.

Operators should also note that PSD2 itself is being superseded: a Third Payment Services Directive (PSD3) and a directly applicable Payment Services Regulation (PSR) are in the pipeline. Any firm designing PSD2 compliance for its EMT business in 2026 is, in practice, designing for the next generation of the EU payments framework, not merely today's rules.


For a deeper look at how MiCA's stablecoin categories work in practice, see our full guide to stablecoin regulations.

The United States: Legislation in Place, Implementation Behind Schedule

For years, US crypto regulation was defined by enforcement actions. That era ended in 2025.

Gary Gensler resigned as SEC Chair in January 2025, concluding a period that produced over 100 enforcement actions against crypto firms. Paul Atkins was sworn in as the 34th SEC Chair in April 2025, signalling a decisive shift toward compliance enablement over prosecution.

The landmark development was the GENIUS Act, signed into law on 18 July 2025. It remains the first comprehensive federal framework for stablecoins in US history.

Key Provisions

•     100% reserve backing required, using only high-quality liquid assets including US dollars, short-term Treasuries and qualifying money market funds.

•     Monthly public reserve disclosures for all issuers; annual financial filings for large issuers.

•     Stablecoin issuers classified as financial institutions under the Bank Secrecy Act, making AML, KYC and OFAC sanctions compliance mandatory.

•     A dual licensing pathway, federal (OCC) or state-regulated, for permitted payment stablecoin issuers.

•     Federal regulators required to issue implementing regulations within one year of enactment; the Act's substantive provisions take effect on the earlier of 18 January 2027 or 120 days after final implementing regulations are issued.

The Missed Rulemaking Deadline

This is where the picture has shifted most significantly since the original edition of this guide was written. The GENIUS Act gave regulators exactly one year, until 18 July 2026, to finalise implementing rules. That deadline has now passed, and not one of the agencies involved, the Treasury, the OCC, the Federal Reserve, the FDIC, the NCUA or FinCEN, had issued final regulations by the statutory date.

Across the year, agencies collectively published around ten notices of proposed rulemaking rather than final rules. The Treasury led with four proposals, including its advance notice of proposed rulemaking in September 2025 and later work on the 'substantially similar' test that will determine when a state stablecoin regime can substitute for federal oversight of issuers with no more than ten billion dollars in outstanding stablecoins. The OCC published its principal implementing proposal, establishing a new 12 CFR Part 15 covering licensing, reserves, prudential standards, custody, capital and reporting, on 2 March 2026, followed by a dedicated Bank Secrecy Act and OFAC sanctions proposal on 22 June 2026. The FDIC issued the first agency-specific rulemaking in December 2025, addressing applications from subsidiaries of FDIC-supervised insured depository institutions. The NCUA issued a licensing proposal in February 2026 and a broader operational proposal in May 2026.

Several comment periods closed only in the days immediately before, or even after, the statutory deadline itself: the OCC's AML proposal on 24 July, the FDIC's compliance framework proposal on 4 August, and a joint five-agency customer identification programme rule on 21 August 2026, making completion of a fully coordinated final rule package before 18 July 2026 procedurally impossible under normal notice-and-comment requirements.

The GENIUS Act contains no penalty clause for a missed rulemaking deadline and no automatic fallback or interim framework. The statute itself remains fully in force: its core requirements, including full liquid reserves, monthly disclosure obligations and stablecoin holder priority in insolvency, remain binding regardless of the rulemaking delay, and the 18 January 2027 effective date is unchanged. The practical effect is prolonged uncertainty over final calibration, particularly around reserve composition, redemption service level agreements and the scope of the Act's prohibition on affiliate-arranged yield, rather than a suspension of the law.

Market Response

The market has not waited for regulatory certainty. Stablecoin market capitalisation reached approximately 310 billion US dollars by mid-2026, with USDT and USDC together accounting for roughly 83% of total supply. Tether's own response to the GENIUS Act's foreign-issuer restrictions was to launch a separate, US-domiciled token, USAT, on 27 January 2026 through Anchorage Digital Bank, a nationally chartered trust institution under OCC supervision. The structure keeps USDT itself offshore and globally distributed while giving Tether a GENIUS Act-compliant vehicle for the regulated US market, a sophisticated but entirely lawful separation of brand from regulatory exposure.

The OCC has also reopened channels for national banks to provide digital asset custody and issue stablecoins under supervisory standards. The FDIC has separately advanced proposed rulemaking for insured depository institutions seeking to issue stablecoins through subsidiaries.

The US is, in short, no longer a patchwork defined by enforcement actions. It is a jurisdiction with a clear legislative framework whose detailed implementation is running later than Congress intended, a distinction that matters enormously for firms sequencing their own compliance build-out.


Compliance implication: firms preparing for GENIUS Act compliance should map draft rule provisions, not final text, against existing KYC/CIP, sanctions screening and liquidity playbooks, and build in flexibility for calibration to shift once final rules eventually land. Waiting for regulatory certainty before beginning implementation work is no longer a viable strategy given the compressed runway to the January 2027 effective date.

FATF's Travel Rule: Adoption Advancing, Enforcement Still Lagging

Even as individual nations develop their own frameworks, the Financial Action Task Force (FATF) continues to set the global floor for fighting financial crime.

The Travel Rule requires Virtual Asset Service Providers (VASPs) to collect and share originator and beneficiary information for qualifying transactions. On 16 July 2026, the FATF published its Seventh Targeted Update on Implementation of the FATF Standards on Virtual Assets and VASPs, drawing on survey responses from 147 jurisdictions and 149 mutual evaluations and follow-up reports.

The headline figures show continued progress: 83% of surveyed jurisdictions (91 of 109) now have Travel Rule legislation in force, up from 73% in 2025. Adding jurisdictions with legislation in progress brings the combined figure to 93% (102 of 109), compared with 85% a year earlier. Jurisdictions rated 'Largely Compliant' with FATF Recommendation 15 rose from 29% to 34% over the same period, and among the 95 jurisdictions that require VASP licensing, 81% are now conducting supervisory inspections, up from 73% the previous year.

The Enforcement Gap

The FATF's own framing of the report is candid: having rules on the books is no longer where the real gap lies. Only around 40% of jurisdictions with Travel Rule legislation in force have taken any supervisory or enforcement action against non-compliant entities. Roughly 60% of jurisdictions with enforceable legislation have yet to issue a single finding, supervisory directive or enforcement action.

The FATF's update highlights the practical consequences of that gap, citing a Cambodia-based financial services group that laundered at least four billion US dollars over several years, and continuing to flag risks tied to scam centres, DPRK-linked cyber theft operations, unhosted wallets and freeze-resistant stablecoin designs. The direction of travel is unmistakable: the Travel Rule is no longer an emerging standard, but converting legislative adoption into meaningful, resourced supervision is now the central challenge for the next phase of implementation.

DeFi Remains Largely Unaddressed

The Seventh Targeted Update also breaks new ground on decentralised finance. It finds that 93% of jurisdictions have not yet identified so-called 'qualifying DeFi arrangements', protocols with an identifiable owner or operator that would make the arrangement subject to VASP regulation under existing FATF standards. Only four jurisdictions have imposed DeFi licensing requirements; two have actually licensed an arrangement, and just one has taken enforcement action. The FATF has published an accompanying Targeted Report on Regulatory Challenges from Decentralised Finance to guide jurisdictions through this gap. The report's survey annex also now tracks stablecoin issuer licensing separately for the first time, reflecting the focus the FATF established in its March 2026 stablecoin-specific report.

Beyond the Big Three: Asia-Pacific and the Gulf

The regulatory story is no longer just the UK, US and EU. Several other jurisdictions have made landmark moves through 2025 and into 2026 that compliance teams cannot afford to ignore.

Hong Kong

Hong Kong's Stablecoins Ordinance (Cap. 656) came into force on 1 August 2025, establishing a licensing regime for any entity issuing a fiat-referenced stablecoin in Hong Kong, or issuing one overseas designed to maintain a stable value against the Hong Kong dollar. The Hong Kong Monetary Authority (HKMA) received 36 formal applications by the September 2025 deadline, drawing interest from Standard Chartered, HSBC, Ant Group, JD.com and others.

After an initial target of March 2026 slipped by roughly six weeks, the HKMA granted its first two stablecoin issuer licences on 10 April 2026, to Anchorpoint Financial Limited, a joint venture between Standard Chartered Bank (Hong Kong), HKT and Animoca Brands, and to HSBC. The approval rate from the first cohort, two of thirty-six applicants, underlines just how selective the HKMA has chosen to be: licensing is being used deliberately to signal scope and calibrate market entry rather than to maximise the number of issuers. HSBC is targeting an HKD-denominated stablecoin integrated into its PayMe wallet and corporate banking flows in the second half of 2026; Anchorpoint is targeting phased issuance from the second quarter of 2026, focused on cross-border B2B settlement and tokenised asset distribution.

Firms disputing an HKMA licensing decision may appeal to a newly created Stablecoin Review Tribunal, and ultimately the Court of Appeal, giving Hong Kong a more structured dispute-resolution route than several comparable jurisdictions.

Singapore

The Monetary Authority of Singapore (MAS) finalised its tailored stablecoin framework in 2023, applying to single-currency stablecoins pegged to the Singapore dollar or a G10 currency and issued in Singapore. Through 2026 that framework has moved from design toward force, with 100% high-quality liquid asset backing, daily mark-to-market valuation, monthly independent reserve checks, annual external audits and par-value redemption within five business days among its core requirements. MAS has separately restricted retail lending and staking, judging both activities too opaque and risky for non-institutional investors, while continuing to explore tokenisation through pilots involving tokenised MAS bills settled via wholesale CBDC.

South Korea

South Korea is advancing competing stablecoin bills following its first prosecutions under the Virtual Asset User Protection Act, with the Bank of Korea and the Financial Services Commission continuing to contest the appropriate locus of stablecoin oversight. Compliance teams operating in or into South Korea should expect the legislative picture to remain unsettled through the remainder of 2026.

The Gulf: UAE and Dubai

The UAE's approach has matured from rulebook design toward active supervision. More than 80 virtual asset service providers now hold licences or approvals across the UAE's federal and emirate-level regulators, principally the Dubai Virtual Assets Regulatory Authority (VARA), the Abu Dhabi Global Market's Financial Services Regulatory Authority (FSRA), the Dubai Financial Services Authority (DFSA) and the Central Bank of the UAE.

On 12 June 2026, VARA published new AML/CFT Business Risk Assessment guidance following its 2026 thematic review, which identified gaps in data use and governance across licensed firms. Licensed VASPs must now review their risk assessments at least quarterly, or sooner if their products, services, business model, ownership or corporate structure change materially, and must incorporate FATF high-risk and increased-monitoring jurisdictions into those assessments in close to real time. VARA has backed the guidance with visible enforcement: in June 2026 it fined Peken Global Limited and MX Global Ltd for operating unlicensed broker-dealer and exchange services, and issued a separate supervisory enforcement notice against the already-licensed VASP CoinMENA FZE over AML programme control failures. Since early 2025, the UAE Central Bank has imposed more than AED 370 million, in excess of 100 million US dollars, in AML and counter-terrorist financing penalties across the wider financial sector.

The UAE's continued removal from the EU's high-risk AML watchlist in 2025 remains a significant signal of improved regulatory credibility, though the pace of 2026 enforcement activity suggests VARA and its federal counterparts intend to consolidate that credibility through visible supervision rather than rest on the legislative architecture alone.


Key Global Regulatory Frameworks at a Glance (August 2026)

Framework

Jurisdiction

Primary Focus

Key Impact on Stablecoins / Firms

UK Cryptoasset Regime (PS26/9 to PS26/13)

United Kingdom

Comprehensive conduct, prudential and market abuse regime for regulated cryptoasset activities

Authorisation gateway opens 30 September 2026; regime commences 25 October 2027; stablecoin issuance rules under PS26/10

MiCA

European Union (27 member states)

Harmonised licensing and operational rules for crypto-assets and CASPs

1:1 reserve backing, AML/KYC compliance, audits, passporting rights; USDT non-compliant and delisted by EU exchanges from 1 July 2026; PSD2 dual-licensing convergence from 2 March 2026

GENIUS Act

United States

First federal framework for payment stablecoins under OCC / state dual licensing

100% liquid reserve backing, monthly disclosures, full BSA/AML coverage, OFAC sanctions compliance; implementing rules missed their 18 July 2026 statutory deadline

FATF Standards

Global (109+ surveyed jurisdictions)

International AML/CFT baseline via the Travel Rule and Recommendation 15

83% of jurisdictions now implementing the Travel Rule; enforcement action taken by only around 40% of those with legislation in force

Hong Kong Stablecoin Ordinance

Hong Kong SAR

Licensing framework for fiat-referenced stablecoin issuers

First two licences (HSBC, Anchorpoint) granted 10 April 2026; reserve, governance and redemption requirements; Stablecoin Review Tribunal for disputes

MAS Stablecoin Framework

Singapore

Licensing and prudential regime for SGD/G10-pegged single-currency stablecoins

100% HQLA backing, daily mark-to-market, par redemption within five business days; retail staking and lending restricted

VARA / UAE Framework

United Arab Emirates (Dubai / federal)

Multi-regulator AML/CFT and licensing regime across VARA, FSRA, DFSA and CBUAE

Quarterly risk-assessment reviews mandated from June 2026; active 2026 enforcement action against unlicensed and non-compliant VASPs


Building a Bulletproof Compliance Programme

Knowing the rules is one thing. Building a system that can navigate them safely is another.

A robust compliance programme is not a policy document on a shelf. It is a living system embedded in a company's operations, updated continuously as rules evolve and the underlying risk profile changes.

Every solid programme rests on four pillars: governance, risk assessment, internal controls and independent testing.

Establishing Strong Governance

Compliance always starts at the top. Without board-level buy-in, no programme survives contact with real risk.

Strong governance means documented, board-approved policies covering AML, KYC and sanctions screening. It means defined accountability at every level, not just a Chief Compliance Officer title. It means ongoing training, not a one-time onboarding module.

When leadership actively champions compliance, it becomes a shared operating standard rather than one department's problem. With the UK's Consumer Duty now extending to cryptoasset firms under PS26/13, and the FCA's Senior Managers and Certification Regime applying to authorised UK cryptoasset businesses, governance accountability in that jurisdiction now carries direct, named individual consequences in a way it did not eighteen months ago.

Conducting a Thorough Risk Assessment

A business cannot defend against threats it has not identified. A risk assessment is the process for systematically mapping the illicit finance risks specific to a business.

This is a continuous exercise. Every new product, new market or new customer type demands a fresh review, and regulators including VARA now expect that review to happen on a defined cadence, at minimum quarterly, rather than on an ad hoc basis.

An assessment should interrogate three core dimensions: who customers are, including Politically Exposed Persons; what products enable, especially cross-border or privacy-adjacent features; and where the business operates, including jurisdictions with elevated sanctions or AML risk.

The output is a risk heat map that tells a firm exactly where to deploy its defences.

Implementing Essential Internal Controls

Policies define what a firm needs to do. Internal controls define how it does that every day.

Controls must cover, at minimum: a Customer Identification Programme (CIP) for rigorous KYC verification, transaction monitoring using blockchain analytics tools to flag suspicious patterns, continuous sanctions screening against lists such as OFAC's SDN list, and a documented process for filing Suspicious Activity Reports (SARs) and maintaining records for at least five years.

For operators subject to MiCA, DORA (the EU's Digital Operational Resilience Act) adds another layer, significantly raising expectations around cybersecurity and operational resilience. UK firms face a close analogue in the operational resilience requirements now confirmed for cryptoasset activities under PS26/13. In both jurisdictions, this is now a compliance requirement, not a best practice.

Independent Testing and Audits

No programme is bulletproof without regular external stress-testing. Independent audits identify the gaps internal teams miss and demonstrate to regulators, investors and partners that a firm's compliance posture is genuine, not merely documented.

Third-party attestations, particularly for stablecoin reserve verification, are now a regulatory requirement across the UK, EU and US, under PS26/10, MiCA and the GENIUS Act respectively.

The Technology Powering Modern Compliance

Smart compliance in digital assets is not just about the right policies. It requires the right technology to enforce them at scale.

Regulatory Technology (RegTech) is the central nervous system of any serious compliance programme. It turns abstract rules into real-time actions.

Blockchain Analytics

At the core of any digital asset compliance setup is blockchain analytics. Platforms such as Chainalysis, TRM Labs and Elliptic trace the flow of funds across public ledgers and automatically flag suspicious activity.

Core capabilities include real-time screening of transactions against databases of sanctioned and illicit addresses, wallet risk scoring based on full transaction history, and source-of-funds tracing to determine whether inbound assets originate from regulated exchanges or high-risk unhosted wallets.

This technology is essential for meeting AML obligations and producing the audit trails regulators now expect as a baseline. Global enforcement agencies are, if anything, ahead of where they were even two years ago: the FATF's Seventh Targeted Update notes that cross-chain and cross-jurisdiction tracing has reached a level of precision that would have been impossible in 2022, and the US, South Korea and Japan have issued joint warnings about North Korean crypto theft operations using exactly this class of tooling.

Proof-of-Reserves and Attestations

Regulators in the UK, EU and US now require stablecoin issuers to prove their reserve holdings, not simply claim them.

This requires secure, tamper-resistant record-keeping systems and third-party attestations, typically conducted by major accounting firms using cryptographic verification methods.

MiCA mandates independently verified reserve data for all Asset-Referenced Token (ART) and EMT issuers. The GENIUS Act, once its implementing rules are finalised, requires monthly public reserve disclosures for all US-permitted issuers and annual financials for large ones. The UK's PS26/10 imports a broadly equivalent reserve and redemption standard. The direction of travel is now unmistakably global: claims without proof are no longer acceptable in any major jurisdiction.


For a detailed look at how custody architecture supports these requirements, see our overview of digital asset custody solutions.

The EU's New AML Architecture: AMLA

Alongside MiCA, a second EU institution is now central to the digital asset compliance picture: the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA), a decentralised EU agency headquartered in Frankfurt.

AMLA became operational on 1 July 2025 and assumed the AML and counter-terrorist financing mandates previously held by the European Banking Authority on 1 January 2026. Its first Chair, Bruna Szego, took office in early 2026. AMLA's direct supervisory powers are being phased in rather than switched on immediately: it is expected to select and begin directly supervising up to 40 high-risk, cross-border financial institutions, including credit institutions, other financial institutions and crypto-asset service providers operating in at least six member states, with selection criteria finalised through 2026 and 2027 and direct supervision beginning around 2028. Full operational capacity is scheduled for mid-2027.

The Anti-Money Laundering Regulation (AMLR) and the Sixth Anti-Money Laundering Directive (AMLD6) apply directly across all 27 member states from 10 July 2027, replacing the previous patchwork of five AML directives with a single harmonised rulebook. Between now and that date, AMLA must publish 23 Level 2 and Level 3 technical standards, most of them due by 10 July 2026, making the remainder of 2026 the practical window for compliance teams to close gaps before the new rulebook becomes directly applicable.

AMLA has explicitly identified crypto-asset supervision as an early priority area, alongside emerging risks from novel payment channels. Firms with EU cross-border exposure, particularly CASPs operating in multiple member states, should expect AMLA, rather than national competent authorities alone, to become an increasingly direct supervisory presence over the remainder of this decade.

What Compliance Means for Your Role

Digital asset compliance looks entirely different depending on where a person sits. A developer architecting a new protocol has a different set of obligations than an investor, a compliance officer or a FinTech executive.

The key is understanding a specific slice of the responsibility, and acting on it before regulators force the issue.

Guidance for Investors

For investors, compliance due diligence is one of the most powerful risk management tools available.

A project cavalier about its regulatory obligations is signalling that it does not care about long-term stability. That is a material risk factor.

Due diligence should go beyond tokenomics. Look for a documented AML/KYC policy that is not just marketing copy. Verify where the project is legally domiciled: an entity authorised under the UK's cryptoasset regime, MiCA or the GENIUS Act now carries materially less regulatory risk than one in an unregulated jurisdiction. Demand evidence of independent audits for both code and reserves, and ask specifically whether the entity's chosen stablecoin exposure, if any, remains listable on regulated venues; the USDT delisting across MiCA-licensed exchanges is a live illustration of how quickly an asset's practical accessibility can change even where the underlying protocol itself has not.

A project's stance on compliance is a direct proxy for its maturity. Serious operators treat compliance as infrastructure. Short-term operators treat it as an obstacle.

Guidance for Developers

Developers are the first line of defence. The code written either bakes compliance in or creates a costly retrofit problem later.

Compliance-by-design means integrating KYC hooks and identity verification APIs from the initial architecture, not bolting them on post-launch. It means building immutable, auditable transaction logs from day one, knowing regulators require records for at least five years. It means hardcoding sanctions screening against OFAC's SDN list directly into the transaction flow.

Building with compliance in mind is not about constraining creativity. It is about future-proofing the work so it can plug into the regulated global financial system, in whichever jurisdiction, or combination of jurisdictions, that system ultimately operates.

Guidance for FinTech Leaders

For established FinTechs and banks entering digital assets, regulators will apply the same standard of discipline to crypto as to any other regulated product. No concessions will be made for novelty.

An existing compliance framework needs to extend, not just adapt, to cover crypto-specific risks. This includes cryptographic key management, tracing funds from unhosted wallets, and smart contract exploit risk in counterparty assessments.

Four priorities stand out for the remainder of 2026 and into 2027:

•     If partnering with crypto sub-custodians or liquidity providers, vendor due diligence must be exhaustive; their failures become your regulatory problem.

•     If operating any EMT-related services in the EU, audit exposure to the MiCA/PSD2 dual-licensing requirement, now in force since 2 March 2026, rather than treating it as a future item.

•     If serving UK clients or planning to operate a UK QCATP, begin scoping the FCA authorisation application well ahead of the 30 September 2026 gateway opening, notwithstanding the October 2027 commencement date.

•     Update risk models to cover DORA's operational resilience requirements in the EU and the analogous operational resilience expectations under PS26/13 in the UK, both of which now apply to cryptoasset firms alongside their existing licensing obligations.

Guidance for Compliance Officers

For the compliance officer or MLRO tasked with actually running the programme day to day, 2026 has been defined less by any single new rule than by the sheer number of moving parts across jurisdictions operating on different clocks at once: a finalised UK regime with a runway to October 2027, an EU regime that has just completed its own transition while a new EU-level supervisor spins up in parallel, and a US regime that is legislated but whose implementing detail remains provisional.

Three practical disciplines matter most in that environment. First, maintain a live regulatory calendar rather than a static one: UK authorisation windows, EU technical standards deadlines and US comment period closures are all moving targets, and a calendar built in January 2026 is materially out of date by July. Second, build policies around outcomes rather than specific rule citations wherever possible, since draft US rules in particular will be recalibrated before finalisation. Third, treat cross-border consistency as a design principle rather than an afterthought: a firm operating across the UK, EU and US is, in practice, complying with three frameworks that share broad objectives but differ in mechanics, and a control designed once to meet the strictest applicable standard is usually cheaper than three parallel, narrowly tailored controls.

What's Next for Digital Asset Compliance?

The regulatory trajectory is clear: more coverage, more enforcement, more cross-border coordination. The open questions are now about implementation quality, not whether regulation is coming.

DeFi Compliance Is No Longer Optional

Regulators worldwide are applying time-tested financial rules to DeFi protocols. The debate about whether AML and KYC apply to decentralised systems is effectively over, even as the FATF's own data shows most jurisdictions have not yet operationalised how to identify a 'qualifying DeFi arrangement' in practice.

The more interesting development is in the solutions. On-chain identity tools using verifiable credentials and non-transferable soulbound tokens are in active deployment, linking wallet addresses to real-world verified identities without centralised data storage. Permissioned liquidity pools give institutions a compliant entry point to DeFi. Zero-knowledge proofs allow users to attest compliance, proving they are not on a sanctions list, without revealing the underlying personal data.

These are not experimental concepts. They are production infrastructure being used right now by protocols that need to maintain both compliance and decentralised architecture, even as regulators themselves, per the FATF's own admission, remain some way behind in defining exactly how DeFi arrangements fit their existing rulebooks.

Smarter Enforcement and Global Coordination

Regulators are significantly more capable than they were two years ago. Sophisticated blockchain analytics tools allow global enforcement agencies to trace illicit funds across chains and jurisdictions with precision that would have been impossible in 2022.

Cross-border coordination has also intensified. The US, South Korea and Japan have issued joint warnings about North Korean crypto theft operations. The US, UK and EU have coordinated targeted sanctions against Russian sanctions evasion via crypto.

The blockchain's permanent record is no longer an advantage for bad actors. It is the primary tool regulators use against them.

The Regulatory Frontiers to Watch

Several issues will define the compliance landscape through 2027 and beyond.

•     AMLA, the EU's new Anti-Money Laundering Authority, has identified crypto-assets as an early supervisory priority and is expected to begin direct oversight of the highest-risk CASPs from around 2028, with its full rulebook applying across the EU from 10 July 2027. This represents a shift toward more centralised, data-driven AML enforcement at EU level.

•     Self-custodial wallets remain a major open debate. FinCEN's long-standing proposal to reduce the de minimis Travel Rule threshold for cross-border transactions from 3,000 US dollars to 250 US dollars remains under consideration rather than finalised; if adopted, it would bring a dramatically larger volume of transactions into scope.

•     Privacy-enhancing technologies, including mixers and privacy coins, remain under active regulatory scrutiny. Regulators are trying to draw a workable line between legitimate privacy use cases and tools purpose-built for obfuscating illicit flows.

•     Stablecoin oversight will intensify in every major jurisdiction. The interaction between the UK's newly finalised regime, MiCA's now-completed transition, and the GENIUS Act's delayed implementing rules means that, for the first time, three major economies are operating live stablecoin regimes simultaneously, each with materially different reserve, redemption and disclosure mechanics.

•     The GENIUS Act's outstanding rulemaking, and in particular the treatment of coordinated affiliate yield arrangements as presumptively evasive of the statute's no-yield prohibition, remains one of the most commercially significant open questions in US digital asset policy heading into 2027.

The projects that will survive and scale are the ones that treat compliance as product infrastructure rather than legal paperwork. That mindset is the difference between building for the next cycle and building for the next decade.

  Frequently Asked Questions

1. What Is the Difference Between AML and KYC?

KYC (Know Your Customer) is one of the most critical tools within an AML (Anti-Money Laundering) strategy. AML is the complete playbook: the full system of policies, controls and technology a firm deploys to prevent financial crime.

2. What Is the GENIUS Act?

The GENIUS Act is the first comprehensive federal law regulating stablecoins in the United States, signed on 18 July 2025. It requires all payment stablecoins to be 100% backed by liquid assets, mandates monthly reserve disclosures, classifies stablecoin issuers as financial institutions under the Bank Secrecy Act, and establishes a dual licensing pathway through either the OCC or state regulators. Its implementing rules missed their statutory 18 July 2026 deadline, though the Act itself and its 18 January 2027 effective date remain in force.

3. Does MiCA Apply to My Business Outside the EU?

If a business serves EU customers or operates through EU-domiciled entities, MiCA applies regardless of where the company is headquartered. Non-EU stablecoin issuers who want their tokens tradeable on EU-licensed exchanges must meet MiCA's reserve, governance and redemption requirements or face delisting, as USDT's experience from 1 July 2026 demonstrates. There is no equivalence regime allowing direct third-country market access.

4. What Is the New UK Cryptoasset Regime, and When Does It Apply?

The UK's regime, built on the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 and finalised through FCA policy statements PS26/9 to PS26/13 on 30 June 2026, brings a broad range of cryptoasset activities, including operating trading platforms, dealing, arranging, lending, staking and safeguarding, within the FCA's regulatory perimeter for the first time. The FCA authorisation gateway opens on 30 September 2026, and the regime commences fully on 25 October 2027.

5. Does Digital Asset Compliance Apply to DeFi?

Yes, and increasingly so. Regulators worldwide have made clear that if a DeFi protocol performs the functions of a traditional financial service, such as lending, exchange or custody, it is subject to equivalent compliance obligations. The compliance obligation follows the financial activity, not the technology architecture, even though the FATF's own July 2026 update acknowledges that most jurisdictions have not yet operationalised exactly how that principle applies to a given DeFi arrangement in practice.

6. What Is the Crypto Travel Rule?

The Travel Rule is a FATF global standard requiring VASPs to collect and transmit originator and beneficiary information for qualifying crypto transactions, the crypto equivalent of wire transfer information-sharing requirements in traditional banking. As of the FATF's July 2026 update, 83% of surveyed jurisdictions have passed Travel Rule legislation, up from 73% in 2025, though only around 40% of those jurisdictions have taken supervisory or enforcement action to date. It remains the foundation of international AML coordination for virtual assets.

7. Can I Still Buy or Hold USDT in the EU?

Holding USDT in a self-custody wallet remains legal. What changed on 1 July 2026 is that MiCA-licensed exchanges and custodians can no longer list or offer USDT trading pairs to clients in the European Economic Area, because Tether has not obtained the e-money token authorisation MiCA requires. Compliant alternatives such as USDC and EURC remain listed on regulated EU venues.

8. What Should a UK Firm Do Before the FCA Authorisation Gateway Opens?

Firms intending to carry on a regulated cryptoasset activity in the UK, whether operating a trading platform, acting as an intermediary, or providing lending, staking or safeguarding services, should use the period before the gateway opens on 30 September 2026 to prepare a complete FSMA authorisation application, resource prudential compliance under COREPRU and CRYPTOPRU, and embed the Consumer Duty and applicable operational resilience requirements confirmed under PS26/13. Given the volume of firms expected to apply, early preparation materially improves the likelihood of authorisation well ahead of the October 2027 commencement date.

Disclaimer

This article is provided for educational and informational purposes only and does not constitute professional advice of any kind, including legal, financial, technical, or regulatory guidance. The content provides a general overview of complex topics in artificial intelligence, quantum computing, and risk management that evolve rapidly; information accurate at publication may become outdated as these fields advance.

The strategic recommendations presented reflect general principles rather than prescriptive solutions. Every organisation faces unique circumstances, including specific regulatory obligations, technical infrastructure, risk profiles, and resource constraints, that require customised approaches developed in consultation with qualified professionals. Organisations should engage appropriate legal advisors, technology specialists, compliance experts, and risk management consultants who understand their specific context and applicable jurisdictional requirements before implementing significant technology initiatives or making organisational changes based on this content.

While every effort has been made to ensure accuracy, no warranties or guarantees are provided regarding the completeness, reliability, or suitability of information contained herein. The author and publisher disclaim liability for decisions made or actions taken based on this article. Technology implementations carry inherent risks, and organisations must conduct appropriate due diligence, testing, and risk assessment before deploying new systems or modifying existing infrastructure. References to specific technologies, standards, or approaches do not constitute endorsements or recommendations.

Readers should verify current information from authoritative sources and recognise that subsequent developments may alter or supersede the perspectives presented here. Maintaining ongoing awareness of developments in artificial intelligence, quantum computing, cryptography, and risk management remains essential for organisations operating in these rapidly evolving domains.

Date: August 6th, 2026

Document Analysis Prepared by: Eric Williamson Director of Compliance and Risk

The Digital Commonwealth Limited Classification: Industry Analysis - Public

EAJW © 2026 DCW Research. All rights reserved