The Federal Reserve's proposed AML rule requires stablecoin issuers to implement bank-style customer identification programs, exempting secondary market transactions. If your team is building or updating a compliance program for a stablecoin issuer, you need a framework that addresses primary market obligations without overreaching into peer-to-peer transfers you don't control.
This template provides a starting structure for a Customer Identification Program (CIP) policy that aligns with the proposed requirements under the GENIUS Act. It's designed for permitted payment stablecoin issuers (PPSI) who must now treat themselves as financial institutions under the Bank Secrecy Act.
Purpose of This Template
This CIP policy template establishes identity verification procedures for direct customers in the primary market, those who receive stablecoins directly from your organization or redeem them back to you. It does not cover secondary market participants who acquire tokens through peer-to-peer transfers, consistent with the proposed rule's recognition that monitoring every downstream holder would create an unworkable global compliance obligation.
Use this template when:
- Onboarding new direct customers who will receive stablecoins from your treasury
- Processing redemption requests from holders who acquired tokens on secondary markets
- Documenting your AML program for regulatory examination
- Training your operations team on when identity verification is required
Prerequisites
Before implementing this template, confirm:
- Your organization qualifies as a permitted payment stablecoin issuer under the GENIUS Act
- You've designated a BSA compliance officer with authority to implement the program
- Your system can distinguish between primary market transactions (issuance and redemption) and secondary market transfers
- You have access to identity verification services that can validate government-issued documents
- Your data retention infrastructure can securely store customer identification records for five years after account closure
If you're also subject to state money transmitter licensing, layer those requirements on top of this baseline. Many states impose customer identification obligations that exceed federal minimums.
The Template
CUSTOMER IDENTIFICATION PROGRAM POLICY
Permitted Payment Stablecoin Issuer
1. SCOPE AND APPLICABILITY
This policy applies to all persons or entities who:
- Request direct issuance of [Stablecoin Name] from [Issuer Name]
- Submit redemption requests to [Issuer Name], regardless of where they acquired the tokens
This policy does NOT apply to:
- Secondary market transfers between third parties
- Holders who acquired tokens through decentralized exchanges, peer-to-peer platforms, or other non-issuer sources, unless they request direct redemption
2. CUSTOMER IDENTIFICATION REQUIREMENTS
For Individual Customers:
Before issuing or redeeming stablecoins, collect and verify:
- Full legal name
- Date of birth
- Residential address (no P.O. boxes for primary residence)
- Government-issued identification number (SSN, passport, or national ID)
Verification Method:
- Review government-issued photo ID (driver's license, passport)
- Cross-reference against third-party identity verification service
- For non-documentary verification: confirm identity through two independent sources (credit bureau, utility records, or financial account verification)
For Entity Customers:
Before issuing or redeeming stablecoins, collect and verify:
- Legal entity name and formation documents
- Principal place of business
- Taxpayer identification number
- Beneficial ownership information (individuals owning 25% or more)
- Authorized representative identity (using individual verification procedures)
Verification Method:
- Review formation documents filed with Secretary of State
- Confirm EIN through IRS records or business credit report
- Apply individual verification procedures to beneficial owners and authorized signers
3. ENHANCED DUE DILIGENCE TRIGGERS
Escalate to enhanced review if:
- Customer is a [Politically Exposed Person](/glossary/politically-exposed-person) (PEP) or immediate family member
- Redemption request exceeds $100,000 in a single transaction
- Customer operates in a high-risk jurisdiction per [FATF](https://www.fatf-gafi.org/) listings
- Beneficial ownership structure involves multiple layers or offshore entities
- Pattern of activity inconsistent with stated business purpose
Enhanced procedures include:
- Senior management approval for account opening
- Source of funds documentation
- Ongoing [transaction monitoring](/glossary/transaction-monitoring) with lower thresholds
4. RECORDKEEPING REQUIREMENTS
Maintain for five years after account closure:
- Copy of identification documents or verification results
- Description of verification method and date completed
- Name and title of employee who performed verification
- All redemption and issuance transaction records
- Any SAR filings related to the customer
5. SECONDARY MARKET REDEMPTION PROTOCOL
When a holder requests redemption but did not acquire tokens directly from us:
- Treat as new customer for CIP purposes
- Collect and verify identity before processing redemption
- Document acquisition source if disclosed
- Apply enhanced due diligence if redemption amount or pattern raises concerns
We do NOT:
- Monitor secondary market transfers between third parties
- Collect identity information on holders who never interact with us directly
- Block transfers based on downstream holder identity
6. TRAINING AND OVERSIGHT
- BSA Compliance Officer reviews this policy annually
- All staff handling issuance or redemption complete CIP training within 30 days of hire
- Quarterly testing of verification procedures on sample transactions
- Annual independent audit of CIP effectiveness
Customization Options
Jurisdiction-Specific Requirements: If you operate in New York, add NYDFS cybersecurity and transaction monitoring requirements. California requires specific data privacy notices. Layer these on in Section 2.
Risk Appetite: The $100,000 enhanced due diligence threshold is a starting point. If you're targeting institutional customers, raise it. If your primary market consists of retail users, lower it to $10,000 or $25,000.
Verification Vendors: Name your specific identity verification service in Section 2. If you use Jumio, Onfido, or another provider, document their role and your fallback procedure if the service is unavailable.
Beneficial Ownership: The 25% threshold matches FinCEN’s Customer Due Diligence Rule. If your risk assessment identifies concerns with your customer base, lower it to 10% or require disclosure of all owners above 5%.
PEP Screening: Define which PEP lists you're screening against. OFAC's SDN list is mandatory. Consider adding Dow Jones Watchlist, World-Check, or regional sanctions lists based on your customer geography.
Validation Steps
After implementing this policy:
Test Primary vs. Secondary Distinction: Process a test redemption from a wallet address that never received tokens directly from your treasury. Confirm your system flags it for identity verification.
Audit Verification Quality: Pull 20 recent customer records. Verify each contains all required data points and that verification was completed before issuance or redemption.
Check Recordkeeping: Confirm customer records are stored in a system with automated retention controls. Spot-check that records older than five years post-closure are purged.
Review EDD Triggers: Simulate a $150,000 redemption request. Confirm it routes to senior management for approval before processing.
Gap Analysis: Compare this policy against your state money transmitter license conditions. Document any additional requirements and update Sections 2 or 3 accordingly.
The proposed rule remains open for 60 days of public comment, so expect refinements. But the core obligation is clear: you must verify identity in the primary market. Build your program now, and you'll be ready when the final rule takes effect.



