← Back to Archive
NCUA

AML Threshold Enforcement & FinCEN Filing

Date submitted: April 6, 2026
Docket: NCUA-2026-0265
RIN: 3133-AF69
Tracking ID: mnq-s497-hxgm
Executive Summary

This supplemental comment addresses the gap between traditional batch-processed AML monitoring and the real-time requirements of stablecoin transactions. It recommends real-time AML threshold enforcement for CTR, MSB, and structuring detection, automated FinCEN filing with BSA XML generation, tiered Travel Rule compliance for inter-CU transfers, AML risk tier classification for wallets, and BSA record retention for all AML artifacts.

Recommendations

  1. Require real-time AML threshold enforcement for stablecoin transactions, covering CTR ($10,000/24h), MSB ($3,000), and structuring detection (80% of CTR across 3+ transactions), with each check recorded as an auditable compliance event.
  2. Require automated FinCEN filing with auto-creation on threshold breach, deadline tracking (15 days for CTR, 30 days for SAR), BSA XML v2.0 generation, and amendment chain support.
  3. Establish Travel Rule compliance tiers for inter-CU stablecoin transfers: exempt (below $3,000), standard ($3,000-$9,999 with hashed PII), and enhanced ($10,000+ with ZKP verification), with 24-hour message expiry.
  4. Require AML risk tier classification (low/medium/high) for stablecoin wallets, with tier assignment based on transaction patterns and compliance history, informing monitoring intensity.
  5. Clarify BSA retention requirements for AML artifacts, including threshold check records, FinCEN filings, Travel Rule messages, and risk tier assignments, with a minimum five-year retention period and legal hold support.

Full Letter Text

ZKProva Inc.
Compliance Technology & Infrastructure

April 6, 2026

National Credit Union Administration
1775 Duke Street
Alexandria, VA 22314

Re: Docket No. NCUA-2026-0265; RIN 3133-AF69 — Notice of Proposed Rulemaking: Investments in and Licensing of Permitted Payment Stablecoins Issuers (GENIUS Act PPSI Licensing Framework for Federally Insured Credit Unions), 91 FR 6531 — Supplemental Comment on AML Threshold Enforcement and FinCEN Filing Automation

Dear Members of the NCUA Board:

I. Identity and Interest of the Commenter

ZKProva Inc. previously submitted comments on this proposed rulemaking on April 4, 2026 (Tracking ID: mnk-icx3-0rd5) and April 6, 2026 (Tracking IDs: mno-0mc6-didw, mno-0qt5-kz5r). We submit this supplemental comment to address a critical operational gap in the proposed rule: the absence of technical standards for real-time AML threshold enforcement and automated FinCEN filing in stablecoin transaction environments.

ZKProva has developed GeniusComply (deployed at ppsiready.com), a production compliance testing infrastructure platform purpose-built for credit unions preparing for PPSI licensure. As part of this platform, ZKProva has built and deployed real-time AML threshold enforcement with automated SAR/CTR filing, Travel Rule compliance for inter-CU transfers, and cryptographic transaction accumulator chains. Our comments are informed by direct engineering experience with the unique AML challenges that stablecoin transactions present — specifically, the speed, volume, and cross-institutional nature of digital asset transfers compared to traditional credit union transactions.

II. Comments on AML Threshold Enforcement and FinCEN Filing Automation

Comment 8: The Final Rule Should Establish Technical Standards for Real-Time AML Threshold Enforcement, Automated FinCEN Filing, and Travel Rule Compliance in Stablecoin Operations

A. The Problem: Traditional AML Monitoring Is Insufficient for Stablecoin Transaction Speeds

The proposed rule requires PPSIs to maintain AML programs consistent with 31 CFR 1020.210(b) and NCUA Q12(4)(a). However, the proposed rule does not address the fundamental difference between AML monitoring for traditional credit union transactions — which settle in hours or days through ACH, wire, or share draft — and AML monitoring for stablecoin transactions, which settle in seconds on blockchain networks.

In a traditional credit union environment, batch-processed transaction monitoring can identify suspicious patterns after the fact, and SAR filings can be prepared over a period of days. In a stablecoin environment, a member can execute dozens of transactions within minutes, and funds can leave the PPSI's custody permanently within a single block confirmation. This speed differential means that AML enforcement must be real-time — evaluated at the point of transaction, not discovered in a batch review hours or days later.

B. Real-Time AML Threshold Enforcement

We recommend that the final rule require PPSIs to implement real-time AML threshold enforcement that evaluates every stablecoin transaction against regulatory thresholds before the transaction is executed. The enforcement should cover at minimum the following threshold types:

1. Currency Transaction Report (CTR) Threshold — $10,000 per 24-hour rolling window. Under 31 CFR 1010.311, financial institutions must file a CTR for currency transactions exceeding $10,000. For stablecoin PPSIs, this threshold should apply to the aggregate value of stablecoin transactions (mint, burn, and transfer) per member per rolling 24-hour window. When a proposed transaction would cause the member's rolling 24-hour total to exceed $10,000, the system should: (a) allow the transaction to proceed (blocking transactions at the CTR threshold would be inconsistent with the filing obligation, which requires reporting, not prevention); (b) automatically create a CTR filing in draft status; and (c) flag the member for enhanced monitoring.

2. Money Services Business (MSB) Threshold — $3,000 for specific counterparty types. Under 31 CFR 1010.100(ff), transactions with money services businesses are subject to enhanced scrutiny above $3,000. For stablecoin PPSIs, this threshold should apply when the counterparty is identified as an MSB, a virtual asset service provider (VASP), or an unhosted wallet. The system should evaluate the counterparty type at transaction time and apply the lower threshold when applicable.

3. Structuring Detection — 80% of CTR threshold across multiple transactions. Under 31 U.S.C. § 5324, structuring transactions to evade reporting requirements is a federal crime. For stablecoin PPSIs, the system should detect patterns where a member's aggregate transactions within a 24-hour window reach 80% or more of the CTR threshold across three or more individual transactions. This pattern — executing multiple transactions just below the reporting threshold — is a hallmark of structuring and should trigger a SAR filing rather than a CTR.

Each threshold check should be recorded as an auditable compliance event, including: the wallet identifier, the proposed transaction amount, the threshold type evaluated, the compliance determination (pass or breach), the rolling window calculation, and the timestamp. These records form a cryptographic accumulator chain — each check's result is hashed into a running root using a collision-resistant hash function (such as Poseidon), enabling examiners to verify after the fact that every transaction was evaluated against AML thresholds.

C. Automated FinCEN Filing

When an AML threshold is breached, the PPSI should automatically generate a FinCEN filing. We recommend that the final rule require PPSIs to implement automated filing with the following characteristics:

1. Auto-creation on breach. When the AML enforcement system detects a threshold breach (CTR or structuring), it should automatically create a filing record in draft status. The filing should capture: the filing type (SAR or CTR), the triggering wallet and member, the trigger amount, the detection date, and a system-generated narrative describing the triggering event.

2. Filing deadline tracking. Under 31 CFR 1010.320 (CTR) and 31 CFR 1020.320 (SAR), financial institutions must file within specific timeframes. For SARs, the filing deadline is 30 calendar days from the date of initial detection (extendable to 60 days if no suspect is identified). For CTRs, the deadline is 15 calendar days following the day of the transaction. The PPSI's system should track these deadlines, provide alerts for upcoming deadlines, and flag overdue filings for immediate supervisory attention.

3. FinCEN BSA XML generation. The PPSI should be able to generate filing documents in FinCEN's BSA E-Filing XML format (XML Schema v2.0), enabling electronic submission through FinCEN's established channels. Manual re-entry of filing data into FinCEN's web portal is error-prone and should be unnecessary for PPSIs with automated filing infrastructure.

4. Amendment chain. When a previously submitted filing requires amendment — for example, when additional suspicious activity is discovered related to the same member — the PPSI should maintain an amendment chain linking the amended filing to the original, preserving the complete filing history for examination.

D. Travel Rule Compliance for Inter-CU Stablecoin Transfers

The proposed rule's treatment of inter-institutional transfers should be expanded to address Travel Rule compliance (31 CFR 1010.410) for stablecoin transfers between credit union PPSIs. Unlike traditional wire transfers, stablecoin transfers between PPSIs will occur on blockchain networks where the sending and receiving institutions may not have a pre-existing correspondent banking relationship. The Travel Rule requires that certain identifying information about the originator and beneficiary travel with the transfer.

We recommend that the final rule establish three tiers of Travel Rule compliance for inter-CU stablecoin transfers, based on transfer amount:

1. Exempt tier (below $3,000). Transfers below $3,000 should be exempt from Travel Rule information requirements, consistent with the existing exemption for funds transfers under this threshold. No record creation is required beyond the standard transaction log.

2. Standard tier ($3,000 to $9,999). Transfers in this range should require the sending PPSI to collect and transmit originator information (name, account number, institution identifier) and beneficiary information (name, account number, institution identifier) to the receiving PPSI. To protect member privacy, this personally identifiable information should be transmitted as cryptographic hashes (SHA-256) rather than in cleartext, with the original data retained by the sending PPSI for the BSA five-year retention period. A Travel Rule message record should be created with a 24-hour expiry — if the receiving PPSI does not acknowledge receipt within 24 hours, the transfer should be flagged for review.

3. Enhanced tier ($10,000 and above). Transfers at or above $10,000 should require all Standard tier information plus a zero-knowledge proof demonstrating that the originator's AML threshold status is compliant. This proof enables the receiving PPSI to verify that the originator has not exceeded CTR thresholds without obtaining the originator's full transaction history. Settlement should not be authorized until the receiving PPSI has verified the Travel Rule message and the accompanying proof.

This tiered approach balances regulatory compliance with operational efficiency for small-value transfers and provides enhanced scrutiny for larger transfers where the risk of money laundering is greater.

E. AML Risk Tier Classification

The final rule should require PPSIs to assign AML risk tiers to stablecoin wallets based on transaction patterns and compliance history. We recommend three tiers:

Tier 1 (Low Risk): Members with no threshold breaches, no structuring patterns, current OFAC screening, and transaction volumes within normal ranges. Standard monitoring applies.

Tier 2 (Medium Risk): Members who have triggered CTR filings, have transactions with MSB/VASP counterparties, or whose transaction patterns show elevated but non-suspicious volume. Enhanced monitoring applies, including more frequent OFAC rescreening and lower structuring detection thresholds.

Tier 3 (High Risk): Members who have triggered SAR filings, have confirmed structuring patterns, or have been flagged by law enforcement. Continuous monitoring applies, with every transaction subject to manual review before execution.

Risk tier assignment should be recorded on the wallet record and should inform the AML threshold enforcement parameters. The risk tier should be visible to examiners and included in the PPSI's compliance reports.

F. BSA Record Retention for AML Artifacts

All AML threshold check records, FinCEN filings (including drafts, submissions, and amendments), Travel Rule messages, and risk tier assignments should be retained for the BSA five-year minimum retention period (31 U.S.C. § 5313; 31 CFR 1010.430). The PPSI should maintain these records in a format that supports examiner query — specifically, the ability to retrieve all AML events for a given wallet, member, or time period on demand. Records subject to active legal holds should be retained beyond the five-year period until the hold is released.

III. Technical Feasibility

ZKProva has implemented the AML enforcement framework described above in production as part of the GeniusComply platform (ppsiready.com). Our implementation includes: real-time threshold enforcement for CTR ($10,000/24h), MSB ($3,000), and structuring (80% of CTR across 3+ transactions); a Poseidon hash accumulator chain recording every AML check; automated SAR/CTR filing creation on threshold breach with 15-day deadline tracking; FinCEN BSA XML v2.0 generation; amendment chain support; Travel Rule compliance with three-tier classification ($3K/$10K), SHA-256 PII hashing, and 24-hour message expiry; AML risk tier assignment (1/2/3) on wallet records; and BSA five-year retention with legal hold support.

This implementation demonstrates that the standards recommended in this comment are technically achievable with standard database and web application infrastructure and do not require exotic technology or disproportionate investment by credit unions or their technology vendors.

IV. Summary of Recommendations

We respectfully request that the NCUA include the following AML and FinCEN standards in the final rule:

  1. Require real-time AML threshold enforcement for stablecoin transactions, covering CTR ($10,000/24h), MSB ($3,000), and structuring detection (80% of CTR across 3+ transactions), with each check recorded as an auditable compliance event.
  2. Require automated FinCEN filing with auto-creation on threshold breach, deadline tracking (15 days for CTR, 30 days for SAR), BSA XML v2.0 generation, and amendment chain support.
  3. Establish Travel Rule compliance tiers for inter-CU stablecoin transfers: exempt (below $3,000), standard ($3,000-$9,999 with hashed PII), and enhanced ($10,000+ with ZKP verification), with 24-hour message expiry.
  4. Require AML risk tier classification (low/medium/high) for stablecoin wallets, with tier assignment based on transaction patterns and compliance history, informing monitoring intensity.
  5. Clarify BSA retention requirements for AML artifacts, including threshold check records, FinCEN filings, Travel Rule messages, and risk tier assignments, with a minimum five-year retention period and legal hold support.

V. Conclusion

Stablecoin transactions settle in seconds. AML enforcement must keep pace. The proposed rule establishes the obligation to maintain AML programs; the final rule should establish how those programs operate in a real-time digital asset environment. Batch-processed, after-the-fact transaction monitoring — adequate for traditional credit union operations — is insufficient for stablecoin velocities. The standards recommended in this comment are technically proven, operationally deployed, and designed to ensure that credit union PPSIs can meet their BSA/AML obligations without compromising the speed and efficiency that make stablecoins valuable to members.

ZKProva Inc. welcomes the opportunity to provide technical demonstrations, implementation specifications, or testimony in support of these comments.

Respectfully submitted,

Viswanadha Pratap Kondoju
Founder & CEO
ZKProva Inc. (incorporation pending)

Disclaimer: This page is an informational archive of a public regulatory comment. It does not constitute legal advice. ZKProva Inc. is not a law firm and no attorney-client relationship is created. Not affiliated with, endorsed by, or sponsored by the NCUA, OCC, or U.S. Department of the Treasury.