This supplemental comment addresses a structural gap in the proposed rule: the absence of a framework for Credit Union Service Organizations (CUSOs) to serve as compliance aggregators for member credit unions pursuing PPSI licensure. Most of the approximately 4,600 federally insured credit unions lack the resources to build PPSI compliance infrastructure independently. The CUSO aggregation model enables shared compliance infrastructure, delegated operations, aggregate readiness reporting, and shared examination.
ZKProva Inc.
Compliance Technology & Infrastructure
April 8, 2026
National Credit Union Administration
1775 Duke Street
Alexandria, VA 22314
Re: Docket No. NCUA-2026-0265; RIN 3133-AF69 — Notice of Proposed Rulemaking: Investments in and Licensing of Permitted Payment Stablecoins Issuers (GENIUS Act PPSI Licensing Framework for Federally Insured Credit Unions), 91 FR 6531 — Supplemental Comment on CUSO-Mediated PPSI Compliance
Dear Members of the NCUA Board:
ZKProva Inc. previously submitted comments on this proposed rulemaking (Tracking IDs: mnk-icx3-0rd5, mno-0mc6-didw, mno-0qt5-kz5r, mnq-s497-hxgm, mnq-sqc4-isv8). We submit this supplemental comment to address a structural gap in the proposed rule: the absence of a framework for Credit Union Service Organizations (CUSOs) to serve as compliance aggregators for member credit unions pursuing PPSI licensure.
ZKProva has developed GeniusComply (deployed at ppsiready.com), a production compliance testing infrastructure platform purpose-built for credit unions preparing for PPSI licensure. GeniusComply includes a complete CUSO management layer — enabling CUSO operators to create compliance organizations, invite member credit unions, aggregate readiness scores across members, and delegate compliance operations on behalf of member institutions. Our comments are informed by direct engineering experience with the CUSO aggregation model and the unique compliance challenges it presents.
The proposed rule establishes compliance requirements that assume each credit union PPSI will independently build, maintain, and demonstrate compliance across CIP, OFAC, AML, wallet management, reserve attestation, and federation domains. This assumption is unrealistic for the majority of federally insured credit unions.
Of the approximately 4,600 federally insured credit unions, the vast majority have fewer than $500 million in assets and lack dedicated compliance technology teams. Building the infrastructure required for PPSI licensure — including real-time AML monitoring, cryptographic reserve attestation, consumer disclosure systems, and examiner-ready audit trails — represents a significant technology investment that is beyond the reach of most individual credit unions.
Credit unions have historically addressed this challenge through CUSOs — cooperatively owned service organizations that provide shared technology, compliance, and operational services to multiple credit unions under NCUA Regulation 712. CUSOs already serve as shared compliance platforms for BSA/AML, lending operations, core banking, and payments processing. Extending this model to PPSI compliance is a natural and necessary step.
The proposed rule does not address CUSOs in the PPSI context. This omission risks creating a regulatory framework that is accessible only to the largest credit unions, undermining the cooperative principle that distinguishes credit unions from banks and contradicting the GENIUS Act's intent to enable broad participation in the stablecoin economy.
We recommend that the final rule explicitly recognize CUSOs as authorized compliance aggregators for PPSI licensure. A CUSO operating in this capacity should be permitted to:
1. Operate shared compliance infrastructure. A CUSO should be able to operate a single compliance testing and monitoring platform that serves multiple member credit unions. Each member credit union would maintain its own PPSI license, but the underlying compliance infrastructure — including CIP verification systems, OFAC screening, AML monitoring, wallet management, reserve attestation, and consumer disclosure delivery — would be operated by the CUSO on behalf of its members.
2. Aggregate compliance readiness across members. The CUSO should be able to generate aggregate readiness reports that show the compliance status of all member credit unions in a single dashboard. This aggregation enables the CUSO to identify members that are falling behind, allocate compliance support resources efficiently, and provide the NCUA with a consolidated view of compliance across the CUSO's membership.
3. Delegate compliance operations. A CUSO-scoped API key should be able to perform compliance operations on behalf of any member credit union, subject to the member's authorization. This delegation model — where the CUSO operator acts on behalf of the member using a delegation header (e.g., "X-Act-As-Org") — enables centralized compliance management without requiring each member credit union to independently operate compliance systems.
4. Facilitate shared examination. When the NCUA examines a CUSO-operated PPSI compliance platform, the examination should cover the shared infrastructure once rather than requiring redundant examination of identical systems at each member credit union. This reduces examiner burden and ensures consistent examination standards across the CUSO's membership.
The final rule should address the governance framework for CUSOs operating as PPSI compliance aggregators:
1. CUSO registration. CUSOs providing PPSI compliance services should be required to register with the NCUA under an enhanced registration framework that identifies: the CUSO operator (the parent credit union), the member credit unions served, the compliance services provided, and the technology platform used.
2. Member invitation and onboarding. The CUSO should have a standardized process for inviting member credit unions to join the compliance platform. The invitation should specify the services provided, the terms of the relationship, and the member's obligations. Invitations should expire after a reasonable period (e.g., 7 days) and should require affirmative acceptance by an authorized officer of the member credit union.
3. PPSI license status tracking. The CUSO should maintain a record of each member's PPSI license application status (not applied, applied, pending, approved, denied). This tracking enables the CUSO to coordinate compliance readiness with the licensing timeline and to ensure that no member operates stablecoin services without an approved license.
4. Enterprise tier access. CUSOs should automatically qualify for enterprise-tier access to compliance testing infrastructure, reflecting the aggregated scale and compliance responsibility of the CUSO model. This ensures that CUSOs have access to production-mode compliance validation, all six compliance modules, and both traditional and ZKP verification tracks.
The final rule should require CUSOs to produce aggregate readiness reports that the NCUA can use to assess the compliance posture of the CUSO's membership as a whole. The aggregate report should include:
1. Per-member scores. The PPSI readiness score (0-100, weighted across six compliance domains) for each member credit union, enabling the NCUA to identify specific members that require attention.
2. Aggregate statistics. The mean, median, minimum, and maximum readiness scores across the membership, along with the distribution of grades (A through F). These statistics provide a high-level view of the CUSO's overall compliance posture.
3. Module-level detail. Per-module scores (CIP, OFAC, AML, Wallets, Attestation, Federation) aggregated across the membership, identifying systemic weaknesses that may indicate a shared infrastructure deficiency rather than an individual member failing.
4. Trend tracking. Historical readiness scores over time (e.g., 90-day trend), enabling the NCUA to assess whether the CUSO's compliance posture is improving or deteriorating.
The delegation model — where a CUSO operator performs compliance actions on behalf of a member — requires specific security controls:
1. Explicit authorization. A CUSO should only be able to act on behalf of a member credit union that has explicitly authorized the delegation through the CUSO membership process. Unauthorized delegation attempts should be rejected.
2. Audit trail. Every delegated action should be logged with: the CUSO operator identity, the member credit union on whose behalf the action was performed, the action taken, and the timestamp. This audit trail enables the NCUA to distinguish between actions taken by the member directly and actions taken by the CUSO on the member's behalf.
3. Scope limitation. CUSO delegation should be limited to compliance operations (testing, monitoring, reporting). CUSOs should not be able to perform member-facing operations (e.g., wallet activation, stablecoin issuance) on behalf of a member without separate, specific authorization for each such operation.
ZKProva has implemented the CUSO aggregation framework described above in production as part of the GeniusComply platform (ppsiready.com). Our implementation includes: CUSO creation with parent organization designation; member invitation with token-based acceptance and 7-day expiry; PPSI license status tracking (not applied, applied, pending, approved, denied); CUSO-scoped API keys with X-Act-As-Org delegation header; delegation guard middleware that validates authorization before permitting cross-organization operations; aggregate readiness reporting across member credit unions; per-member and per-module score aggregation; and enterprise tier automatic qualification for CUSOs.
This implementation demonstrates that the standards recommended in this comment are technically achievable and can be deployed by credit union technology vendors without disproportionate complexity.
We respectfully request that the NCUA include the following CUSO-related standards in the final rule:
Credit unions are cooperatives. CUSOs are the cooperative mechanism through which small credit unions access services they cannot build individually. The GENIUS Act's promise of broad credit union participation in the stablecoin economy will not be realized if the PPSI licensing framework is accessible only to institutions large enough to build compliance infrastructure independently. The CUSO aggregation model recommended in this comment enables credit unions of all sizes to participate safely, compliantly, and cooperatively.
ZKProva Inc. welcomes the opportunity to provide technical demonstrations, implementation specifications, or testimony in support of these comments.
Respectfully submitted,
Viswanadha Pratap Kondoju
Founder & CEO
ZKProva Inc. (incorporation pending)
Disclaimer: This page is an informational archive of a public regulatory comment. It does not constitute legal advice. ZKProva Inc. is not a law firm and no attorney-client relationship is created. Not affiliated with, endorsed by, or sponsored by the NCUA, OCC, or U.S. Department of the Treasury.