Fed GENIUS Act Stablecoin Proposed Rules: Reserves, Capital, Architecture
For a year, a payment stablecoin issuer in the United States has been building against a statute whose operating details were still blank. On September 24, 2026, the Federal Reserve Board started filling them in, proposing two rulemaking packages that turn the GENIUS Act stablecoin rules from broad principles into things an engineer can put in a backlog: which assets may sit in the reserve pool, how much loss-absorbing capital must stand behind the tokens, and how a state member bank gets permission to issue at all.
The timing matters because the clock is already running. Reporting on the proposals says the Act’s issuer restrictions take effect on the earlier of January 18, 2027 or 120 days after final regulations, and the one-year statutory deadline for final rules has already passed. Any issuer, bank, custodian, or wallet provider that wants to be inside the perimeter on day one needs to design now, while the comment period is open.
This article is a systems analysis, not a legal reading. You will leave with a precise picture of what the Fed proposed, which numbers are confirmed and which are reported differently by different outlets, and a reference architecture showing how reserve, capital, redemption, and compliance controls map onto services you would actually build.
What this covers: the regulatory landscape across the OCC, FDIC, and Fed; the two Fed proposals; reserve asset rules and their engineering implications; the capital model; the application process; a mint-and-redeem compliance architecture; failure modes; and a checklist for issuer engineering teams.
Non-advisory notice: this post analyzes regulatory proposals and system design only. It is not legal, financial, or investment advice, and the proposals may change before they are final.
Context and Background
The Guiding and Establishing National Innovation for U.S. Stablecoins Act, known as the GENIUS Act, was signed into law on July 18, 2025. It created the first federal framework for “payment stablecoins”: tokens that are redeemable for a fixed amount of money and used for payment or settlement. The statute is on Congress.gov as S.1582 in the 119th Congress. Its structure is worth remembering because every proposed rule hangs off it. Only permitted issuers may offer payment stablecoins to US persons: subsidiaries of insured depository institutions, federally qualified nonbank issuers supervised by the Office of the Comptroller of the Currency (OCC), and state-qualified issuers below a size threshold. Holders may not be paid interest or yield by the issuer. Reserves must back every token one-to-one with a narrow list of liquid assets. And issuers must publish reserve composition regularly and meet Bank Secrecy Act obligations.
What the statute left to regulators was the hard part. “Permissible reserve assets” had to be turned into line items. “Capital” had to become a number or a formula. Supervision of banks that own issuing subsidiaries had to be allocated among agencies that each regulate a different slice of the banking system. The Act asked for final implementing rules within one year, a date that passed in July 2026 with the rulemaking still in progress, according to reporting I reviewed.
Meanwhile the market kept moving. Our earlier analysis of stablecoin payment infrastructure in 2026 described the stack that issuers, banks, and processors have been assembling, and the follow-up on stablecoin settlement over the Visa and Mastercard card networks showed how card rails are being rewired to settle in tokens. Those designs were built on assumptions about what regulators would eventually require. The September 24 proposals are the first time the Fed’s version of those requirements is on paper.
One caution on evidence. I could not retrieve the Fed’s own press release text for this write-up, so the details below come from the Fed’s announcement as relayed by law-firm commentary, trade press, and crypto news outlets. Where those outlets disagree, I say so. The Fed’s press-release archive is at federalreserve.gov, and the actual proposal text should be treated as the source of truth before anyone commits engineering budget to a specific parameter.
The Three-Regulator Map and the Two Fed Proposals
The Fed’s September 24, 2026 proposals are two separate packages: one setting reserve, capital, risk-management, and safekeeping rules for Fed-supervised payment stablecoin issuers, and one creating a tailored application process for state member banks. Each opens a 60-day comment period that starts when it is published in the Federal Register.

Figure 1: How GENIUS Act implementation splits across agencies, and where the two Fed proposals sit. Agency dates are as reported by trade press; confirm against primary documents.
Figure 1 shows why a single “stablecoin rule” does not exist. Implementation is divided by charter type. Reporting I reviewed describes the OCC’s proposals as covering national banks and the federal-qualified issuer track, with a framework published in February 2026 and a final rule targeted for November 2026. The FDIC proposed rules for state nonmember banks in April 2026. The Fed’s action on September 24 covers state member banks and the issuers it supervises. The Treasury Department and its Financial Crimes Enforcement Network carry the anti-money-laundering and sanctions layer, including customer identification proposals that one outlet dates to June 12, 2026. Each agency keeps its own supervisory package and its own application process.
That fragmentation is a design input, not a footnote. A consortium of banks issuing a shared token, or a fintech that wants to be a federally qualified issuer with a bank custodian under a different regulator, is touching several rulebooks at once. The Fed itself asked for comment on “applications involving several banks in a stablecoin consortium,” including whether one filing could cover multiple insured state member banks, as reported by crypto.news. If you are building multi-institution infrastructure, compare it against our analysis of the bank stablecoin consortium architecture involving U.S. Bank, Stellar, and Qivalis, which wrestles with the same question from the engineering side.
Proposal 1: reserves, capital, risk management, safekeeping
The first package is the prudential framework. According to the law-firm and trade summaries, it requires full backing of payment stablecoins with permissible reserve assets at all times, sets standardized capital requirements for credit and operational risk, establishes risk-management standards for payment stablecoin activities, covers the safekeeping of reserve assets by third parties, and clarifies which stablecoin-related activities Board-supervised banks may conduct. In the Fed’s phrasing as quoted in the ABA Banking Journal, the goal is to ensure that payment stablecoins are fully backed at all times by permissible reserve assets.
The word “always” carries engineering weight. A reserve requirement tested at month-end is a reporting problem. A requirement that holds at all times is a real-time systems problem, because mint, burn, custody movements, and market-value changes all have to keep the ratio intact between reports. We return to that in the architecture sections.
Proposal 2: the application process
The second package is procedural but not trivial. Per the summaries, insured state member banks that want to issue payment stablecoins through a subsidiary would file an application containing a business plan, financial information, and an explanation of how they meet GENIUS Act requirements. The proposal also sets up procedures for appeals, hearings, and a final Board determination. One outlet reports specific clocks: 30 days for the Fed to tell an applicant whether a filing is substantially complete, and 120 days after that to decide, with approval deemed granted if the Fed does not act in time. I could only find that timing in a single source, so treat it as reported and verify it in the proposal text.
Why the votes and the dissent-like language matter
Reports say the Board approved both proposals unanimously, yet Governor Michael Barr’s accompanying statement is notably cautionary. He is quoted as saying the proposal is an important step but “further work will undoubtedly be required if stablecoins are to be reliable payment instruments,” and, in a separate quote, that “stablecoins will only be stable if reliably redeemed at par across varied conditions, including market stress.” Those lines are a preview of where the comment fight will be: redemption credibility, interest-rate and foreign-currency risk, and the anti-money-laundering enforcement threshold. A signal like that is useful for planning, because the parts a Governor flags are the parts most likely to move before the rule is final.
Reserve Assets: What May Back a Token and What That Does to Your Treasury Stack
The reserve rule is where the proposal touches the daily operations of a treasury team. The statute lists the categories of eligible assets, and the Fed’s proposal elaborates how they apply to issuers it supervises. Sources agree on the broad shape and differ on the edges, so it helps to separate what is stable from what is contested.
The permissible list as reported
The Act’s reserve categories, as widely summarized, include United States currency, Federal Reserve balances, deposits at insured depository institutions, Treasury bills with a remaining maturity of 93 days or less, repurchase agreements collateralized by those Treasuries, and certain money market funds that invest only in those instruments. One summary of the Fed proposal lists US dollars, Federal Reserve balances, insured deposits, Treasuries maturing within 93 days, and Treasury-backed repurchase agreements. Another says the Fed identified “short-term U.S. Treasury bills and certain other high-quality, liquid assets.” A third, lower-quality source claims the Fed limits reserves to Treasuries of 93 days or less and describes that as narrower than the statute. I could not confirm that last claim against primary text, and since it conflicts with the other summaries, I treat it as unverified.
Two rules attract consistent mention: one-to-one backing and a prohibition on rehypothecation, meaning the issuer cannot re-lend or re-pledge the reserve assets for its own purposes, except in narrow, permitted repo arrangements. Whether the Fed proposal adds any allocation limits, concentration caps, or minimum liquidity percentages is, per one summary, not specified: “specific percentage allocations” are among the items the proposals do not settle.
Engineering consequence one: reserve eligibility is a data-model problem
If the permitted list is short and precisely defined, an issuer can encode it as an eligibility rule engine rather than a policy PDF. Every asset in the reserve pool needs attributes the rule engine can check: instrument type, issuer, remaining maturity in days, collateral type for repos, counterparty, custodian, and whether it is encumbered. A T-bill purchased at 91 days ages through the 93-day line and is fine; a note that started at 180 days and now has 80 days remaining may or may not qualify depending on how the final rule defines maturity. That is not a detail to discover in an examination. It is a question to put in a comment letter.

Figure 2: A reserve-management data flow. Customer dollars enter the mint ledger, an allocator splits them across eligible instruments, a custodian holds them, and reconciliation feeds both reporting and the redemption liquidity buffer.
Figure 2 sketches the flow I would expect any compliant issuer to converge on. The allocator is the policy-enforcing component: it should refuse to buy an ineligible asset, rather than relying on a later report to catch it. The custodian is a separate legal and technical party because the proposal reportedly includes standards for firms that safekeep reserve assets and raises bankruptcy-remoteness considerations for custodial arrangements. Daily reconciliation turns the ledger and the custodian’s records into one number: liabilities in circulation versus eligible assets at market value.
Engineering consequence two: the redemption window sets the liquidity floor
The most operationally important number in the reporting is the redemption standard. Two outlets report that issuers must publish redemption policies providing for redemption within no more than two business days, subject to specified exceptions. Cointelegraph’s summary gives the same two-business-day figure. A source with weaker reliability describes it as a 48-hour window, which is a looser paraphrase of the same idea, because business days are not hours.
Two business days defines the liquidity profile of the reserve pool. T-bills settle on a next-day basis in normal markets, cash and insured deposits are immediate, and term repo with a maturity longer than two days is not something you can rely on to fund a redemption wave. An issuer should therefore model a redemption stress as a function of the share of reserves that can be turned into cash within two business days, not within the instrument’s maturity. A 30-day bill is liquid because the market is deep, not because it matures soon. Under stress, that depth can shrink, which is why Barr’s quote about reliable par redemption in market stress is aimed at exactly this assumption.
Engineering consequence three: monthly disclosure and examination
Cointelegraph’s summary states that the framework requires monthly reports on outstanding stablecoins and reserve composition, an examination by an independent certified public accounting firm, and certification by the CEO and CFO. The statute itself, as commonly described, includes monthly reserve-composition disclosures and attestation by senior officers. Because the statute and the proposal speak the same language here, I would treat the monthly cadence as a safe design target, with the caveat that reporting formats are not yet final. Our practical advice: build the report as a query over the same reconciled reserve ledger that drives your daily control, so the published number is a view, not a re-computation.
What the reserve rules do not say yet
The honest list of unknowns is long. According to one summary, the proposals do not settle final calibrated capital ratios, specific reserve allocation percentages, redemption operational procedures and hours, or final AML enforcement standards. A team that hard-codes a threshold today is guessing. A team that parameterizes the threshold, with effective dates and jurisdiction tags, can absorb the final text with a configuration change.
Capital: Absorbing Losses Without Touching Reserves
Reserves protect token holders. Capital protects the reserves. The Fed’s proposal separates the two on purpose: an issuer should be able to suffer a credit loss, an operational failure, or a fraud event and still keep its reserve pool whole. That separation is the design principle behind the capital model, and it is why capital is its own section of the proposal and not a footnote to reserves.
The numbers, and a conflict worth flagging
Here the sources diverge, so precision matters. Cointelegraph reports a tiered standardized charge: 2% on the first $20 billion of outstanding stablecoins, 1.5% on the next $30 billion, and 1% on amounts above $50 billion, plus additional charges tied to credit and operational risk. Crypto Daily describes two loss-absorption charges: a 2% credit-risk charge on uninsured deposits and undercollateralized reverse repurchase agreements, and an operational-risk charge of 1% to 2% of outstanding stablecoins that varies by issuer size. A third outlet cites a “2% standardized ratio on the first $20 billion” and a $5 million minimum for new issuers under the OCC’s approach, and notes the OCC and Fed approaches differ. Two other outlets say outright that specific capital ratios are not in their coverage or are pending comment.
These descriptions are consistent with one reading: an operational-risk charge that declines from 2% to 1% as outstanding supply crosses size bands, plus a separate credit-risk charge applied to the portion of reserves that carries credit exposure (uninsured bank deposits and weakly collateralized repo). But that is my synthesis of secondary reporting, not a confirmed reading of the rule text. Any capital model built from this article should be re-baselined against the proposal itself.

Figure 3: Loss-absorbing capital sits between operating losses and the reserve pool. The tiered operational charge and the credit charge are as reported by trade press; calibrated ratios are pending comment.
A worked illustration, clearly hypothetical
To see why the tier structure matters, take a purely illustrative issuer with $40 billion of tokens outstanding, and apply the reported tiers to the operational charge only. The first $20 billion at 2% is $400 million. The next $20 billion at 1.5% is $300 million. The total is $700 million, an effective rate of 1.75% on the supply. At $60 billion, the third band adds $10 billion at 1%, or $100 million, so the total is $400 million plus $450 million plus $100 million, equal to $950 million, an effective rate of about 1.58%. The illustration is arithmetic on a reported formula and not a statement about any real issuer, and it ignores the credit charge and any minimum-capital floor.
The pattern is the point: capital intensity falls as scale rises, which rewards consolidation and penalizes small issuers. That is also why the application rules and the de novo minimum that one outlet attributes to the OCC ($5 million, as reported) matter, since a new entrant starts well below the tiers.
Why the credit charge shapes treasury choices
A charge on uninsured deposits and undercollateralized reverse repo, if confirmed, changes the economics of how an issuer parks cash. Holding reserves in Treasury bills or in insured deposits up to the coverage limit attracts less credit capital than parking large balances uninsured at one bank. In architectural terms, that argues for custodian diversification and for a position-level view of insured-versus-uninsured balances by institution. Your treasury service should compute deposit insurance headroom per bank account in near real time, because a balance that crosses the insured limit is a capital event, not just a concentration note.
Integration with bank capital
For the Board-supervised banks that own issuing subsidiaries, one summary says the framework integrates with existing bank capital planning, including CET1 and stress capital buffers. For engineers inside a bank, this means the stablecoin subsidiary’s capital will not be a standalone spreadsheet. It feeds the parent’s capital planning, and the reporting pipeline needs to carry the same lineage as other regulatory reports.
Operational risk is the quiet part
The operational-risk charge reflects a point engineers know well: most failures that hurt token holders are not market losses. They are key-management errors, smart contract faults, bridge or custodian outages, and reconciliation breaks. Capital cannot prevent them, but it gives the issuer room to absorb them without burning reserves. If your incident postmortems regularly list a minted-without-funding or burned-without-payout discrepancy, treat each of those as a potential operational-loss event with a dollar value, because a supervisor will.
Timeline, Applications, and the GENIUS Act Effective Date
The calendar drives engineering sequencing, so it deserves its own section. Sources agree on the broad outline. The Act was signed July 18, 2025. A one-year deadline for final rules lapsed in July 2026. The Fed proposals were announced September 24, 2026, and each carries a 60-day comment period running from Federal Register publication, so the exact close date is not yet fixed. The GENIUS Act effective date, per Cointelegraph and Fintechspecs, is the earlier of January 18, 2027 or 120 days after the primary federal regulators issue final regulations. Another outlet describes the Treasury-side date as January 18, 2027 for the main issuer restrictions, which is consistent.
Reading the effective-date rule
“Earlier of” cuts in a way that is easy to miss. The 120-day trigger only beats the fixed date if the primary regulators finalize their rules before roughly September 20, 2026, which has already not happened, since the proposals only opened comment on September 24. On that arithmetic, January 18, 2027 is the operative planning date unless a final rule arrives earlier than the dates imply. The OCC is reported to be targeting a November 2026 final rule, and the Fed is expected, per one source, to finalize in early 2027. Which regulators must have finalized for the 120-day clock to start is a question I could not settle without the primary text, so treat this as my reading of reported dates, not a legal conclusion.
That asymmetry is worth planning around. An issuer that is not yet permitted by the effective date faces a restriction on offering payment stablecoins to US persons. A bank applying through the Fed pathway cannot wait for the final rule to begin its application work, because the proposal itself says what the application must contain.
The application pipeline as a workflow
Take the reported application contents: a business plan, financial information, capital-structure documentation, and an explanation of GENIUS Act compliance. Then add the reported clocks: 30 days to determine substantial completeness, 120 days to decide, and a deemed approval if the agency is silent. Whether or not those specific clocks survive, any workable application is a project plan with a regulator-controlled critical path. The preparation work divides into four streams.
- Business plan and product definition. Which token, which chains, which customers, and which activities are in scope. The proposal clarifies permissible activities for Board-supervised banks, so the plan must stay inside those lines.
- Financial and capital documentation. Pro forma capital against the standardized charges, with scenarios for tier crossings.
- Controls evidence. Reserve management, custody, risk management, and AML program documents, tied to systems that exist and not to promises.
- Governance and certification. The CEO and CFO certification, independent examination, and monthly reporting mean accountability must be traceable to named owners.
Consortium filings
The Fed’s own question on consortium applications signals that multi-bank issuance is not yet well accommodated by a bank-by-bank process. If a single filing could cover several insured state member banks, the consortium’s shared infrastructure, such as a common mint-and-burn service, would be reviewed once rather than N times. That is a commercial incentive for shared platforms, and it will shape comment letters from industry groups. It is also why the shared-ledger choices discussed in our piece on Circle’s Arc mainnet and stablecoin-native Layer 1 design are now regulatory choices as well as technical ones: where the token lives determines which controls the issuer can enforce at the protocol level.
The industry timing pressure
Reporting from one source says major banks have asked for comment-period extensions in order to slow implementation timelines. The source is a secondary summary of a research aggregator, so I would treat it as a signal and not a fact. What can be said with confidence is that the interests are not aligned: issuers want certainty before January, banks want time, and consumer-oriented commenters, including Governor Barr in his statement, want the redemption and AML language tightened before the rule is final.
Reference Architecture: Mint, Reserve, Redeem, Comply
With the regulatory facts established, the useful question is what an issuer’s technical stack must guarantee. I propose thinking in four control planes. They are my own framing, derived from the proposal’s reported structure and not from the text of the rule.
- The ledger plane records liabilities: every token minted and burned, tied to a dollar movement.
- The reserve plane records assets: positions, custodians, eligibility, valuation, encumbrance.
- The compliance plane screens people and transactions: KYC, sanctions, monitoring, and the ability to act on lawful orders.
- The reporting plane produces the monthly composition report, supervisory submissions, and the evidence behind certifications.

Figure 4: A payment stablecoin compliance architecture sequence. Minting is gated by screening and reserve funding confirmation; redemption is gated by screening, burn confirmation, and payout inside the published window.
Mint: fund first, issue second
Figure 4 encodes one ordering decision that I would defend strongly: the token is minted only after the custodian confirms the funds have settled. Many early designs issued first and reconciled afterwards, creating a window during which tokens in circulation exceeded reserves. Under a requirement that backing hold at all times, that window is a violation by construction. The safer pattern is a two-phase mint: book the liability as pending, confirm reserve funding, then release the mint. Pending liabilities are visible in the ledger but do not circulate.
The compliance engine sits in front of the ledger. The statute applies Bank Secrecy Act obligations to issuers, and Treasury has separate proposals in this area, so the screening step is not optional. The Fed’s own reported concern, in Governor Barr’s statement, is that account-based monitoring is inadequate for tokens that circulate continuously on-chain. That points to a second compliance layer beyond the issuer’s own customers: blockchain analytics on secondary-market flows, with the ability to freeze or burn under lawful order where the token contract supports it.
Redeem: burn first, pay second
The mirror image holds for redemption. The token is burned and confirmed before the custodian releases funds, so the same dollar is never claimed twice. The two-business-day publication standard becomes a service level for the whole chain: screening, burn confirmation, treasury liquidation if needed, and payout. If your design requires a manual approval step, count it against the window.
A subtle failure appears at the boundary between chains. If a token exists on several networks, the burn must be provable on the chain where the redemption was requested, and the ledger needs a canonical supply number across all networks. Cross-chain bridges that wrap or lock tokens complicate that canonical number, and the reserve plane must count each unit of liability exactly once.
The always-on reserve ratio
Because backing must hold continuously, the reserve plane should expose a live coverage ratio: eligible assets at current market value divided by tokens outstanding plus pending liabilities. Three alarms follow naturally. A soft alarm fires when coverage trends toward a configured buffer. A hard alarm halts minting. A third alarm fires when eligibility changes, for example when an asset’s remaining maturity crosses a line. The rule text is still pending, but the engineering pattern is stable regardless of the final numbers.
The proposal reportedly includes a shortfall protocol, according to Cointelegraph: notify the Fed, restore reserves through a remediation plan, or liquidate and redeem the stablecoins. A shortfall runbook is therefore part of the architecture. It should specify who is paged, which regulator contact is notified, how minting is halted, and how redemption continues during remediation. Writing that runbook after the first incident is too late.
Custody and bankruptcy remoteness
The proposal’s reported attention to third-party safekeeping, including bankruptcy remoteness, translates into account structure. Reserve assets should be held in segregated, titled accounts at custodians in a way that a court would treat as the property of token holders, rather than as general assets of the issuer or the custodian. For engineers, the relevant artifacts are account titling data, custodian attestations, and a clear mapping from custody accounts to the ledger. Our recommendation is to model the custody account as a first-class entity in the reserve plane with its legal title attached, not as a free-text field.
Tokenized deposits versus payment stablecoins
Fintechspecs reports that the proposals call for a distinction between payment stablecoins and tokenized deposits to be reflected in product labeling. This matters for banks that run both. A tokenized deposit is a liability of the bank and sits on its balance sheet. A payment stablecoin from a subsidiary is a separate instrument backed by reserves. Labeling is not just marketing: it determines which control plane, which capital rule, and which disclosure applies. A shared wallet or API that handles both should carry the product type as a mandatory attribute on every transaction.
Deeper Analysis: Where the Proposals Create Real Engineering Work
Reading the proposals as a backlog, the work falls into a handful of concrete workstreams. The table below ranks them by how confident I am that the requirement will survive into the final rules, with notes on what to build now and what to parameterize.
| Workstream | Confidence it survives | Build now | Parameterize |
|---|---|---|---|
| Full-backing reserve coverage at all times | High, statutory | Live coverage ratio, mint gating | Buffer thresholds |
| Eligible asset rule engine | High, statutory list | Instrument attributes, maturity ageing | Maturity limit, repo collateral rules |
| Two-business-day redemption policy | Medium to high, widely reported | Redemption SLA tracking, liquidity ladder | Window length and exceptions |
| Standardized capital charges | Medium, ratios pending | Capital calculator with tiers | Ratios, bands, minimums |
| Monthly reserve report and examination | High | Reporting view over reconciled ledger | Format and fields |
| Custody and bankruptcy remoteness | Medium to high | Account titling data model | Custodian eligibility |
| AML and sanctions on-chain monitoring | High, Treasury track | Screening, analytics, freeze capability | Enforcement thresholds |
| Application workflow | Medium, procedural | Evidence repository, project plan | Clock lengths |
A liquidity ladder for the redemption window
If redemption must be honored within two business days, the reserve plane should maintain a liquidity ladder: cash and balances available same day, T-bills sellable by next day, repo maturing within the window, and everything else. The ladder is a table of buckets, each with a haircut under stress. A simple stress test applies a redemption shock, say a configurable percentage of supply in two days, and checks whether bucket one plus bucket two with haircuts covers it. The shock size is a risk-management choice for the issuer, not a regulatory number, and the proposal’s reported emphasis on stress means supervisors will ask how you chose it. Illustrative numbers in an internal model are fine; presenting them as regulatory requirements is not.
Interest-rate and foreign-currency risk
Barr’s flagged concerns include interest-rate risk and foreign-currency risk, and the proposal asks for comment on both. Interest-rate risk shows up when reserves hold Treasuries that lose market value as rates rise: a bill with 90 days left has little duration, but a large portfolio sold quickly into a thin market can still suffer. Foreign-currency risk is more specific: a token redeemable in dollars but backed partly by non-dollar assets or deposits abroad has an exposure that the standard list avoids. Reserve assets in the permissible list are dollar-denominated, so a foreign-currency risk question mainly concerns operations: foreign custodians, foreign payment rails, and foreign issuers, which is a topic the Act treats separately.
Data lineage as a compliance feature
An examiner who reads a monthly report will ask how each number was produced. If the report is a view over the reconciled ledger with immutable snapshots, the answer is a query and a timestamp. If it is a spreadsheet, the answer is a person. Lineage is therefore not an optional engineering virtue but the mechanism that makes the CEO and CFO certification credible. We recommend append-only storage for ledger and reserve events, daily signed snapshots, and a clear separation between the operational database and the reporting store.
Where tokens live matters
The proposals address issuers and banks, but the token lives on a network. Public chains, permissioned ledgers, and purpose-built stablecoin networks give the issuer different levels of control: freeze, burn, blocklist, upgradeability, and finality. A design that cannot freeze an address on request cannot satisfy a lawful order. A design with an upgradeable contract needs key-management controls that count as operational-risk mitigation. For card-network settlement patterns where those choices play out, see our analysis of stablecoin settlement across Visa and Mastercard.
Trade-offs, Gotchas, and What Goes Wrong
Treating proposed numbers as final. The most common failure will be hard-coding a capital ratio, a maturity limit, or a reporting field from a news summary. As this article shows, secondary sources disagree on capital figures. A parameterized rule engine with effective dates costs a few days of design and saves a rewrite.
Issue-then-reconcile minting. Systems that mint first and reconcile at the end of the day create a regular window in which supply exceeds funded reserves. Under a continuous-backing requirement, that is a recurring exception. Two-phase minting removes it, at the cost of some latency for the customer.
Redemption that works until it does not. An issuer can redeem comfortably in normal markets and fail in a stress event because the liquidity ladder was never tested against a shock. Barr’s emphasis on par redemption “including market stress” is the supervisory lens. Run the stress test on the same data the real-time ratio uses, or the two numbers will diverge exactly when it matters.
Concentration in uninsured deposits. If the credit-risk charge applies to uninsured deposits as reported, a large cash balance at a single bank is not only a counterparty concentration but a capital cost. Teams that optimize yield by consolidating balances may find the capital charge erases the gain.
Cross-chain supply ambiguity. Multichain tokens make the canonical supply a hard computation. Wrapped or bridged representations can double count liabilities or hide burns. The ledger plane should own the single supply number, and any chain-level representation is a reconciled view.
Compliance by account, not by token. The reported concern about account-based monitoring is a real gap for continuously circulating tokens. An issuer that screens only at mint and redemption sees a small slice of activity. Secondary-market analytics help, but they require legal and operational decisions about when to freeze and who decides.
Over-reading dates and clocks. The 30-day and 120-day application clocks come from a single report. The effective-date logic involves the earlier of two triggers. Plan against the conservative interpretation and re-check when the Federal Register notice appears.
Single points of regulatory dependency. Because OCC, FDIC, and Fed rules are separate, a design that works for one charter may not map to another. A bank that changes charter or partners with a custodian under a different regulator can reopen questions it thought were closed. Keep jurisdiction as a tag in your control library, so a requirement can be traced to the rule that created it.
What the proposals may not address. Reporting says the Fed’s rules apply to Board-supervised issuers and do not address non-bank or uninsured institutions, which fall under other tracks. A reader who assumes the Fed proposal is the whole picture will miss the OCC and state regimes entirely.
Practical Recommendations
Start from the principle that the engineering goal is evidence, not just control. A regulator or an auditor will want to know that the reserve is whole at all times, that redemption works in stress, and that the issuer can prove both after the fact. Controls that cannot produce evidence are, for supervisory purposes, controls that do not exist.
Second, invest first in the reserve plane. The ledger and compliance planes are familiar to any payments team. The reserve plane, with eligibility rules, maturity ageing, custodian mapping, and live coverage, is where issuers differ most and where the proposal is most specific. Build it as a service with a clear API so mint gating, reporting, and stress tests all read the same truth.
Third, write your comment-letter questions while you design. Teams that discover ambiguities while building, for example how maturity is measured or how a consortium files, have unusually concrete input for the comment process. The 60-day window runs from Federal Register publication, so check for the notice and the docket details when they appear.
Fourth, make the capital calculator a living artifact. Even before ratios are final, a calculator with tiers and a credit charge lets finance and engineering argue with numbers instead of adjectives.
Checklist for issuer engineering teams
- [ ] Reserve coverage computed continuously, with mint gating on a hard threshold.
- [ ] Two-phase mint and burn-first redemption with idempotent, auditable steps.
- [ ] Eligibility rule engine with instrument attributes and maturity ageing.
- [ ] Liquidity ladder and a stress test tied to the redemption window.
- [ ] Insured-versus-uninsured balance tracking per bank account.
- [ ] Segregated, titled custody accounts modeled as first-class entities.
- [ ] Monthly report generated as a view over the reconciled ledger.
- [ ] Shortfall and remediation runbook with named owners and regulator contacts.
- [ ] Canonical supply across chains owned by the ledger plane.
- [ ] Rule parameters stored with effective dates and jurisdiction tags.
- [ ] Product-type attribute separating payment stablecoins from tokenized deposits.
- [ ] Evidence repository ready for an application filing.
Frequently Asked Questions
What did the Fed propose on September 24, 2026?
The Federal Reserve Board announced two proposals under the GENIUS Act. The first covers reserve backing, standardized capital for credit and operational risk, risk-management standards, and safekeeping for payment stablecoin issuers it supervises. The second sets a tailored application process for state member banks that want to issue payment stablecoins through subsidiaries. Reporting says both were approved unanimously and both carry a 60-day comment period that begins when they are published in the Federal Register.
What is the GENIUS Act effective date?
According to Cointelegraph and Fintechspecs, the Act takes effect on the earlier of January 18, 2027 or 120 days after the primary federal regulators issue final regulations. The one-year statutory deadline for final rules passed in July 2026 without final rules. Because the proposals only opened comment in late September, January 18, 2027 looks like the more likely operative date, though the final text and the precise trigger mechanics should be confirmed in primary sources.
What counts as a GENIUS Act reserve asset?
The statute lists United States currency, Federal Reserve balances, deposits at insured depository institutions, Treasury bills with a remaining maturity of 93 days or less, repurchase agreements backed by those Treasuries, and certain qualifying money market funds. Summaries of the Fed proposal repeat the core list. One reported detail is that rehypothecation is restricted. Specific allocation percentages are not settled in the proposals, according to one summary, so check the rule text.
How much capital will stablecoin issuers need to hold?
It is not settled. Cointelegraph reports a tiered standardized charge of 2% on the first $20 billion of outstanding supply, 1.5% on the next $30 billion, and 1% above $50 billion, with additional charges for credit and operational risk. Crypto Daily describes a 2% credit-risk charge on uninsured deposits and weak repo plus a 1% to 2% operational charge. Other outlets say ratios are pending. Treat all figures as reported until verified against the proposal.
How fast must issuers redeem stablecoins?
Reporting says issuers must publish redemption policies providing for redemption within no more than two business days, subject to specified exceptions. Governor Barr emphasized that stablecoins are only stable if they can be reliably redeemed at par, including in market stress. The final rule may clarify universal redemption rights and operating hours, so design the redemption service around a configurable window and test it against stress scenarios.
Do the Fed’s proposals cover every stablecoin issuer?
No. The Fed packages apply to issuers and banks under Federal Reserve supervision, mainly state member banks and their subsidiaries. The OCC covers national banks and federal-qualified issuers, with a final rule reportedly targeted for November 2026, while the FDIC proposed rules for state nonmember banks in April 2026. Treasury handles anti-money-laundering and sanctions rules. A multi-institution design may therefore need to satisfy several rulebooks at once.
Further Reading
- Stablecoin payment infrastructure in 2026: the full stack from issuance to settlement that these rules now constrain.
- Stablecoin settlement over Visa and Mastercard rails: how card networks are being re-plumbed for token settlement.
- Bank stablecoin consortium architecture with U.S. Bank, Stellar, and Qivalis: the multi-bank design question the Fed raised in its consortium comment request.
- Circle Arc mainnet and stablecoin-native Layer 1 design: how protocol-level controls affect compliance.
- External: the GENIUS Act text on Congress.gov, the Federal Reserve press release archive, and the ABA Banking Journal report on the Fed proposals.
By Riju — about
