AML + Sanctions for Stablecoin Payroll: A Practical Screening Checklist
AML and sanctions screening in stablecoin payroll is not a setup exercise. It is a per-cycle requirement. This checklist covers what payroll teams need to screen, verify, and document before every payout batch executes.
Updated on: July 29, 2026


TL;DR
- Sanctions and AML program obligations sit primarily with stablecoin issuers and the platforms processing transfers. Employer-side payroll teams typically don’t run bank-grade AML programs, but they should maintain their own per-cycle sanctions and destination controls (and not rely solely on provider screening) before each batch executes.
- OFAC administers the Specially Designated Nationals and Blocked Persons (SDN) list. U.S. persons and entities are prohibited from transacting with anyone on the SDN list, regardless of payment method. This prohibition applies to stablecoin payroll.
- The Bank Secrecy Act (BSA), administered by FinCEN, requires financial institutions to implement AML programs covering customer identification, due diligence, transaction monitoring, and suspicious activity reporting. The GENIUS Act extends these obligations to Permitted Payment Stablecoin Issuers (PPSIs).
- Screening should happen before each cycle executes, not just at worker onboarding. OFAC’s SDN list is updated continuously. A worker or wallet address that was clean last cycle may not be clean this cycle.
- Wallet address screening is as important as identity screening. OFAC publishes designated digital currency addresses within SDN entries; sending stablecoin payroll to a designated address is prohibited even if a name-based check was run separately.
- Documentation of screening outcomes, including the list/version used and the date/time of the check, belongs in the per-cycle compliance evidence package.
Disclaimer: This guide is for general informational and educational purposes only. It does not constitute legal, tax, financial, or compliance advice. AML and sanctions requirements vary by jurisdiction and evolve over time. Always confirm current requirements with qualified legal counsel and compliance experts for your specific program structure, jurisdictions, and worker populations.
Direct answer
AML and sanctions screening for stablecoin payroll requires two parallel checks before every pay cycle: identity screening of in-scope workers against applicable sanctions lists (including OFAC’s SDN list for U.S.-connected programs), and wallet address screening of destination addresses against the same lists. The primary compliance obligations sit with stablecoin issuers and the platforms processing transfers (which, under the GENIUS Act, are classified as financial institutions subject to bank-level AML and sanctions requirements). For most employer-side programs, the practical per-cycle control is sanctions screening (people + wallets) and documentation; full BSA AML program requirements sit with regulated issuers and transfer platforms. Employer-side programs should layer their own screening on top of provider controls, retain per-cycle documentation, and have a defined process for handling flags before the payout batch executes.
The regulatory framework: who carries what obligation
Understanding AML and sanctions in stablecoin payroll starts with clarity on who carries which obligation, because the structure is layered.
At the issuer and platform level
The GENIUS Act, signed into law on July 18, 2025, classifies Permitted Payment Stablecoin Issuers (PPSIs) as financial institutions under the Bank Secrecy Act. That means issuer/platform layer obligations include bank-grade AML expectations: customer identification programs, customer due diligence, transaction monitoring, suspicious activity reporting to FinCEN, and effective sanctions compliance programs (including OFAC screening). The joint FinCEN and OFAC notice of proposed rulemaking issued on April 8, 2026 implements these requirements in detail, including screening expectations and the technical capability to block or freeze prohibited transactions, plus periodic certification expectations.
Regulatory status as of 29 July 2026
None of the stablecoin AML and sanctions rulemakings is final. Every one is still a proposal. That matters for planning: the employer-side controls described in this checklist rest on OFAC prohibitions that are already in force, not on rules that are still being written.
The joint FinCEN and OFAC proposal above closed for comment on 9 June 2026. Five further rulemakings on the same subject have been published since:
| Published | Rulemaking | Federal Register | Comment period |
|---|---|---|---|
| 10 Apr 2026 | Joint FinCEN/OFAC — issuer AML/CFT and sanctions compliance programs | 91 FR 18582 | Closed 9 Jun 2026 |
| 18 May 2026 | Implementing the GENIUS Act for the issuance of stablecoins | 91 FR 28956 | Closed 17 Jul 2026 |
| 5 Jun 2026 | BSA and sanctions compliance standards for FDIC-supervised issuers | 91 FR 34171 | Closes 4 Aug 2026 |
| 22 Jun 2026 | Issuer Customer Identification Program | 91 FR 37234 | Closes 21 Aug 2026 |
| 24 Jun 2026 | Issuer AML/CFT and sanctions compliance (further proposal) | 91 FR 37840 | Closed 24 Jul 2026 |
| 9 Jul 2026 | AML/CFT Programs (FinCEN) | 91 FR 42363 | Closes 8 Sep 2026 |
Sources, in order: 91 FR 18582 · 91 FR 28956 · 91 FR 34171 · 91 FR 37234 · 91 FR 37840 · 91 FR 42363.
What this means in practice: build the employer-side controls now, because the OFAC obligations they address already apply. Expect the issuer and platform layer to tighten when these proposals are finalised, and ask your provider how it is preparing rather than assuming its current controls will still be sufficient.
At the employer level
Employer obligations are different - but not absent. U.S. persons and entities are broadly prohibited by OFAC from transacting with SDNs and from engaging in prohibited dealings under applicable sanctions programs, regardless of the payment rail used. An employer should not rely solely on provider-side screening as the only control, especially when the employer is directing payments as part of a repeatable payroll process.
Practical consequence: a defensible stablecoin payroll program uses two layers of sanctions controls:
1) the provider’s controls, and
2) the employer’s per-cycle payroll controls (identity + destination wallet screening + documentation + exception handling).
The employer-side layer does not need to replicate a bank AML program. It should cover the payroll exposure points: worker identity screening and destination wallet screening before each cycle executes, plus a documented process for handling any flags.

Issuer-layer and employer-layer obligations are distinct — but both must be active.
The practical screening checklist
All five checks run before the payout batch executes. The table summarises them; each is expanded below with what to screen, when, and the minimum documentation to retain.
| Check | What to screen | When | Minimum documentation |
|---|---|---|---|
| 1. Worker sanctions screening | Full legal name plus known aliases of every worker due a payout this cycle | Before each cycle, against the current version of each list | Lists screened · list version and date · timestamp · outcome · who performed and approved |
| 2. Wallet address screening | Every destination address in the cycle — new and previously used | Before each cycle, against current SDN data | Address · chain context · list version and date · timestamp · outcome · change approvals |
| 3. Jurisdiction check | Each worker's country of residence against the programme's eligibility record | Before each cycle; escalate relocations and new markets first | Eligibility and jurisdiction confirmation record, plus an exception note where reviewed |
| 4. Provider screening confirmation | That your provider or transfer platform ran its own controls for this batch | Per batch | Provider batch confirmation (date, time, batch identifier, scope) and outcome |
| 5. Flag handling | Any name match, wallet match or jurisdiction concern | Process defined in advance; executed before the cycle closes | Exception log entry · disposition notes and basis · action taken · approval record |
The list set depends on your footprint. For US-connected programmes, the OFAC SDN list is the minimum. EU programmes should screen the EU consolidated sanctions list, and UK programmes the UK HMT Consolidated List of Financial Sanctions Targets.
Check 1: Screen all in-scope workers against current sanctions lists before each cycle
What to screen: The full legal name of each worker scheduled to receive a stablecoin payout in the current cycle, plus known aliases and common variations. For EOR programs with workers in multiple countries, account for transliteration/alternate spellings where relevant.
Which lists to screen against:
U.S.-connected programs: at minimum, OFAC SDN list
EU programs: EU consolidated sanctions list
UK programs: UK HMT Consolidated List of Financial Sanctions Targets
Add additional national lists depending on where the program operates and who is in-scope.
Timing: Before each cycle executes, against the current version of each list. Prior-cycle results are not sufficient.
Documentation (minimum):
Store a per-cycle log entry that includes:
- list(s) screened,
- list/version/date pulled,
- timestamp of check,
- outcome (no match / potential match),
- and who performed/approved the check.
Check 2: Screen all destination wallet addresses against OFAC-designated digital currency addresses
What to screen: Every wallet address scheduled to receive a stablecoin payout in the current cycle - both new addresses and previously used addresses.
Why this matters separately from identity screening: OFAC publishes designated digital currency addresses within SDN entries (often tagged by asset/network). A destination address can become designated even when a name-based screen does not surface a clear match.
Timing: Before each cycle executes, against the current SDN data.
Documentation (minimum):
Per-cycle wallet screening log that includes:
- wallet address,
- chain/network context if relevant,
- list/version/date pulled,
- timestamp of check,
- outcome,
- and any address changes since the last cycle (with approval record).
Check 3: Verify no worker is located in a comprehensively sanctioned jurisdiction (as applicable)
What to check: Some sanctions programs restrict dealings involving certain jurisdictions (and/or specific regions, sectors, or parties). A “clean” name screen does not automatically clear a jurisdiction-based exposure.
How to verify (payroll-friendly):
- Confirm each in-scope worker’s country of residence/location aligns to the program’s eligibility record (and EOR jurisdiction coverage where applicable).
- Escalate any edge cases (new markets, relocations, unusual residency facts) to legal/compliance before running the cycle.
Documentation (minimum):
A per-cycle eligibility/jurisdiction confirmation record, plus an exception note for any worker that required review.
Check 4: Confirm provider screening ran (and retain confirmation records)
What to confirm: Your stablecoin payroll provider (or the VASP/CASP processing transfers) should run sanctions controls for the current batch. Confirm screening is active pre-run and obtain confirmation post-run.
Why this matters: Provider controls don’t replace employer controls, but they strengthen defensibility. In audits and reviews, evidence of layered controls is stronger than a single check.
Documentation (minimum):
- provider batch confirmation (date/time, batch identifier, scope),
- screening outcome (incl. flags and resolution summary if any).
Check 5: Maintain a defined process for handling screening flags before the cycle closes
What the process should cover:
- what counts as a “flag” (name match, wallet match, jurisdiction concern),
- who owns first review,
- escalation path to legal/compliance,
- true positive vs false positive disposition steps,
- and required documentation before releasing/holding a payout.
Why it must be defined in advance: Flags found during cycle-close are where informal decisions and missing documentation happen.
Documentation (minimum):
- per-cycle exception log entry for each flag,
- disposition notes + basis,
- action taken (hold/block/escalate),
- and approval record.

All five checks must complete before the payout batch executes.
Per-cycle artifacts to store (minimum viable evidence package)
Store these alongside your payroll register and payout proof:
1) Worker sanctions screening log (lists + version/date + timestamp + outcome)
2) Wallet screening log (address + list/version/date + timestamp + outcome)
3) Eligibility/jurisdiction confirmation record (or exception note)
4) Provider screening confirmation record (batch + timestamp + outcome)
5) Exception/flag log + disposition notes (if any)
What a compliant stablecoin payroll program looks like (AML + sanctions)
A defensible program has five elements live before the first cycle runs:
1) Defined screening scope covering both identities and destination wallets before every cycle
2) Documented list set (OFAC + any required EU/UK/other lists based on footprint)
3) Per-cycle logs that capture list version/date, timestamps, and outcomes
4) Defined flag resolution process (owner, escalation path, required documentation)
5) Provider confirmation records retained alongside employer-side logs
Programs that have some but not all of these elements often discover the gap at the worst time: during cycle-close pressure, a regulatory inquiry, or an audit.

These five records should be retained alongside the payroll register after every cycle.
FAQs
Does OFAC sanctions screening apply to all employers running stablecoin payroll, or only to financial institutions?
OFAC prohibitions apply broadly to U.S. persons and entities, not only to financial institutions. The GENIUS Act adds additional program requirements for stablecoin issuers/platforms, but employer-side programs should still ensure they are not causing prohibited transactions.
How often is the OFAC SDN list updated?
OFAC updates the SDN list continuously, often multiple times per month (and sometimes multiple times per week). This is why per-cycle screening is required rather than an onboarding-only step.
Does screening a worker’s name against the SDN list also cover their wallet address?
No. Wallet address screening and identity screening are separate checks. OFAC publishes designated digital currency addresses within SDN entries, and an address can be designated in a way that won’t reliably surface in a name-only screen.
What should we do if a screening check returns a match for a current worker?
Do not proceed with the payout for the flagged worker until the match is reviewed and dispositioned. Many name matches are false positives; true positives require immediate escalation to legal/compliance. Document the review, the basis for the decision, and the action taken.
Is sanctions screening the same as AML screening?
They’re related but distinct. Sanctions screening checks whether a person/address is prohibited. AML covers broader risk controls (transaction monitoring, suspicious activity, due diligence). For most employer-side stablecoin payroll programs, the immediate per-cycle requirement is sanctions screening plus documentation; broader AML program requirements sit with regulated issuers and transfer platforms.
Are the stablecoin AML and sanctions rules final?
No. As of 29 July 2026 every relevant rulemaking is still a proposal. The joint FinCEN and OFAC proposal (91 FR 18582) closed for comment on 9 June 2026, and five further proposals followed through July 2026. The employer-side controls in this checklist rest on OFAC prohibitions already in force, so they are unaffected by that timing.
Does the GENIUS Act change employer obligations directly?
Mostly no. It classifies Permitted Payment Stablecoin Issuers as financial institutions under the Bank Secrecy Act, so the new programme obligations sit with issuers and transfer platforms. Employer-side OFAC prohibitions applied before the Act and are unchanged by it — what changes is the strength of your provider's layer.
How often should we re-check the regulatory position?
Screen against current sanctions lists every cycle, because the SDN list changes continuously. Review rulemaking status quarterly while these proposals remain open — comment periods on related proposals run into September 2026, and final rules will tighten the issuer and platform layer.
Build both layers before the first cycle runs
AML and sanctions compliance for stablecoin payroll is not conceptually complex, but it requires two things many programs underestimate: screening must cover both identities and wallet addresses, and it must run before every cycle against current list versions - not just at onboarding. Programs that build layered controls with per-cycle evidence and a defined flag process can demonstrate defensible compliance under scrutiny. Programs that screen once and assume coverage thereafter carry a risk that compounds with every cycle.





