The Short Answer: Issuers Face a Patchwork of FATF and MiCA Requirements
A stablecoin issuer does not answer to a single rulebook. It sits at the intersection of the FATF risk-based approach, the EU's MiCA framework, and regional rules, and it has to map all of them onto its own operations.
The reason is structural. FATF writes global standards that each jurisdiction is expected to transpose into local law. MiCA writes a directly applicable rulebook for the European Union. US and Singaporean rules add their own layers on top. A single issuer can therefore face several rule sets at once, each with a different scope, trigger, and deadline.
This article walks through the two anchors that matter most for an issuer, the FATF risk-based approach and MiCA, then maps the regional rules that sit around them. It ends with how a compliance platform can turn that fragmented map into a workable operating procedure.
Why this page exists is worth stating. Compliance teams search for a single, citable explanation of what stablecoin issuers owe under FATF and MiCA. This page is that reference. It stays at the level of the frameworks themselves, so it can be cited without depending on any one jurisdiction's year-to-year changes.
| FATF risk-based approach | MiCA | |
|---|---|---|
| What it is | Global standards each jurisdiction transposes into local law | A directly applicable rulebook for the European Union |
| Who it covers | Issuers in every transposing jurisdiction, scaled to their risk | Issuers of tokens offered into the EU |
| Core duties | Documented risk assessment, proportionate controls, monitoring after issuance | Authorization before issuing, reserve rules, and redemption rights |
FATF RBA Requirements for Stablecoin Issuers
The FATF risk-based approach, or RBA, asks an issuer to size its controls to the risk it actually faces rather than apply a fixed checklist. For a stablecoin issuer, the practical requirements have moved well beyond a one-time check at issuance. FATF's stablecoin work has shifted toward secondary market monitoring and expects enhanced due diligence on transactions that involve unhosted wallets.
This shift matters because a stablecoin keeps circulating long after it is issued. The issuer's exposure does not stop at the mint. It extends to how the token moves through secondary markets, including peer-to-peer transfers that never touch a licensed exchange. An issuer that only controls the point of issuance is controlling a fraction of the risk surface.
The RBA also means the requirement is proportional. A jurisdiction does not ask every issuer for the same level of control. It asks for controls that match the issuer's size, its holder base, and the markets where its token actually moves. The burden is highest where the token crosses borders or touches high-risk jurisdictions.
For an issuer, that usually translates into a documented risk assessment, controls that are demonstrably proportionate, monitoring that continues after issuance, and a way to escalate when a token flow matches a high-risk pattern. Each of these maps back to a FATF expectation rather than to a product feature.
Implementation is uneven, which is the issuer's real problem. In the FATF's targeted updates, most recently the July 2026 seventh update, only 1 of the 138 assessed jurisdictions was fully compliant, 29% were largely compliant, 21% were non-compliant, and 59% had not yet implemented the required measures, while 73% of jurisdictions (85 in total) had passed Travel Rule legislation. An issuer cannot assume that a FATF requirement is mirrored in the local rules of every market it serves.
MiCA and Other Regional Frameworks
The global map splits into MiCA in the European Union, BSA and FinCEN rules in the United States, the PSA in Singapore, and the FATF Travel Rule as the cross-border layer.
MiCA is the most complete regional rulebook so far. It gives the European Union a directly applicable authorization system for stablecoin issuers, with conditions tied to reserves, redemption, and ongoing oversight. Instead of relying on each member state to write its own rules, an issuer faces one framework across the bloc. Issuers outside the EU still touch it whenever their tokens are offered to EU holders.
The United States and Singapore take different routes. The US passed its first federal stablecoin statute, the GENIUS Act, signed on July 18, 2025: it sets a licensing regime for payment stablecoin issuers, with substantive requirements phasing in over an eighteen-month window that runs into early 2027. Alongside it, Bank Secrecy Act and FinCEN rules still treat stablecoin activity as a money transmission and reporting question. Singapore's Payment Services Act takes a licensing approach. Each of the three rulebooks now has statute-level weight, but they still read differently from MiCA.
Even with those frameworks in place, the global picture stays fragmented. The FSB's October 2025 report put the global stablecoin market above $150 billion, with 62% of jurisdictions permitting operations, 20% prohibiting them outright, and 18% still undecided. The FSB also flags the risks that come with that split: regulatory shopping, a race to the bottom, and cross-border contagion when oversight gaps spread risk across borders.
These rulebooks differ in scope, model, and what they ask of an issuer:
| Framework | Jurisdiction | Regulatory model | What it asks of issuers |
|---|---|---|---|
| FATF risk-based approach | Global | Standards transposed into local law | Size controls to actual risk, secondary-market monitoring, enhanced due diligence on unhosted wallets |
| MiCA | European Union | Directly applicable rulebook | Authorization with conditions tied to reserves, redemption, and ongoing supervision |
| BSA / FinCEN | United States | Money transmission and reporting | Treat stablecoin activity as a money-transmission and reporting question |
| Payment Services Act | Singapore | Licensing | Hold a license under payment-services rules |

How Phalcon Compliance Supports Regulatory Alignment
Phalcon Compliance aligns with FATF standards and covers multiple key jurisdictions, with one-click STR and SAR report generation.
This is how Phalcon Compliance supports regulatory alignment.
Two features do most of the work. First, Phalcon Compliance keeps the screening layer current. Sanctions and blacklist checks, freeze-status flags, and address risk labels update as the underlying lists change, so an issuer's checks run against the current state of the lists rather than a snapshot taken at onboarding.
Second, the platform turns the duty list into detection. Phalcon Compliance reads risk across all 17 Risk Indicator categories rather than one single label. That matters for an issuer because the FATF risk-based approach is only as strong as the risk picture underneath it. Sanctions exposure, high-risk jurisdiction ties, mixing, and laundering markers all read as separate signals, so a compliance team can show which risk it was measuring and why it acted.
In practice, an issuer brings its token contracts, treasury wallets, and the addresses it transacts with into the platform, runs them against current risk data, and keeps them under monitoring as the regulatory map changes. When a jurisdiction updates its rules, the team revisits only the affected requirements and does not re-read the entire landscape from scratch.
The point is to keep the operational layer, the monitoring and reporting, aligned with the map the issuer has already drawn. It does not replace legal advice. Legal counsel decides the requirements; the platform makes them visible.

What to Do Next
Start from the map, not the tool. Identify which rules apply to your token, your holders, and your route to market. Then wire the monitoring you already need to the requirements each set of rules imposes.
Manage stablecoin freeze risk with Phalcon Compliance to align screening with FATF and MiCA expectations. Download the stablecoin freeze risk whitepaper for the issuer-side risk framework behind those requirements.
For where each framework stands right now, the stablecoin regulation news tracker follows the developments by market. For the freeze and blacklist controls behind these duties, see how issuers manage freeze and blacklist risk.
For the full picture of stablecoin rules, freezing risk, and payment AML, start from the Stablecoin Compliance guide.