← Back to Archive
NCUA

PPSI Licensing Framework

Date submitted: March 29, 2026
Docket: NCUA-2026-0265
RIN: 3133-AF69
Tracking ID: mnk-icx3-0rd5
Executive Summary

This initial comment letter addresses the NCUA's proposed PPSI licensing framework for credit unions under the GENIUS Act. It recommends pre-licensure compliance testing requirements, standardized validation frameworks, federation and interoperability standards for credit union networks, and recognition of privacy-preserving zero-knowledge proof verification as an acceptable compliance mechanism.

Recommendations

  1. Require pre-licensure compliance testing as a condition of PPSI license approval, including synthetic data validation across all six compliance domains (CIP, OFAC, AML, Wallets, Attestation, Federation).
  2. Publish standardized compliance validation frameworks that credit unions can use to objectively assess PPSI readiness before examination, reducing examiner burden and ensuring consistent standards across institutions of varying size and sophistication.
  3. Establish federation and interoperability standards specific to the credit union context, including trust registry requirements, credential portability, and standardized cross-institution identity verification protocols.
  4. Recognize privacy-preserving compliance verification methods, including zero-knowledge proofs, as acceptable mechanisms for demonstrating regulatory compliance during PPSI examinations.

Full Letter Text

ZKProva Inc.
Compliance Technology & Infrastructure

March 29, 2026

National Credit Union Administration
1775 Duke Street
Alexandria, VA 22314

Re: Notice of Proposed Rulemaking — GENIUS Act Payment Stablecoin Issuer (PPSI) Licensing Framework for Federally Insured Credit Unions

Dear Members of the NCUA Board:

ZKProva Inc. respectfully submits this comment in response to the National Credit Union Administration's Notice of Proposed Rulemaking regarding the PPSI licensing framework for federally insured credit unions under the Guiding and Establishing National Innovation for U.S. Stablecoins (GENIUS) Act.

I. Identity and Interest of the Commenter

ZKProva Inc. is a compliance technology company that has developed GeniusComply, a production-deployed compliance testing infrastructure platform purpose-built for credit unions preparing for PPSI licensure. GeniusComply provides six integrated compliance validation modules covering Customer Identification Programs (CIP), OFAC sanctions screening, Anti-Money Laundering (AML) monitoring, stablecoin wallet compliance, reserve attestation, and inter-credit-union federation — each mapped to specific GENIUS Act sections and NCUA Q12 examination subsections.

ZKProva holds patent-pending innovations in this space, including U.S. Provisional Application PROV-010 (regulation-aware synthetic compliance test data generation), Continuation-in-Part of Application 63/994,522 (PROV-009) (zero-knowledge proof compliance test vector generation and verification), and Continuation-in-Part of PROV-007 (federated trust registry testing with Merkle verification). These applications represent novel technical approaches to the compliance challenges that credit unions will face under the GENIUS Act, and we offer our perspective as a company with direct, operational experience building the infrastructure that credit unions will need.

II. Comments on the Proposed Rulemaking

Comment 1: The Final Rule Should Require Pre-Licensure Compliance Testing Infrastructure, Not Merely Compliance Monitoring

The proposed rule appropriately establishes substantive compliance requirements for PPSI licensees across CIP (31 CFR 1020.220; NCUA Q12(3)), OFAC screening (31 CFR Part 501; NCUA Q12(4)(a)), AML programs (31 CFR 1020.210(b); NCUA Q12(4)(a)), wallet management (GENIUS Act Section 4(a); NCUA Q12(3)), reserve attestation (GENIUS Act Section 8(a); 12 CFR 706.110), and federation protocols (NCUA Q12(7)). However, the proposed rule focuses on ongoing compliance obligations without addressing the critical pre-licensure phase during which credit unions must build, validate, and demonstrate compliance readiness.

Credit unions are cooperative institutions with limited technology budgets. Unlike large banks with dedicated compliance technology teams, most credit unions will need to build PPSI compliance programs from the ground up. The difference between compliance monitoring (detecting violations after they occur) and compliance testing (validating that systems correctly handle edge cases, adversarial scenarios, and stress conditions before going live) is material to member safety.

We respectfully recommend that the NCUA include in the final rule a requirement that PPSI license applicants demonstrate pre-issuance compliance testing — including synthetic data validation of CIP identity verification workflows, simulated OFAC screening with known-positive and false-positive scenarios, and AML pattern detection testing with labeled suspicious activity scenarios — as a condition of license approval. This approach aligns with the GENIUS Act's emphasis on consumer protection and would reduce the risk of compliance failures in early PPSI operations that could undermine public confidence in credit union stablecoins.

ZKProva's patent-pending technology (PROV-010) addresses precisely this gap: generating regulation-aware synthetic test data that exercises compliance edge cases without exposing real member personally identifiable information.

Comment 2: The NCUA Should Establish Standardized Compliance Validation Frameworks for PPSI Readiness Assessment

The proposed rule would benefit from the inclusion of standardized validation criteria that credit unions can use to self-assess PPSI readiness before submitting license applications. Currently, the proposed rule establishes what a PPSI licensee must do but provides limited guidance on how a credit union can objectively determine whether its compliance infrastructure meets the required standard.

We observe from our work with the NCUA Q12 examination framework that the six compliance domains — CIP, OFAC, AML, Wallets, Attestation, and Federation — each involve multiple discrete compliance checks. For example, a robust OFAC compliance program requires not only SDN list screening but also disposition workflows for matches (block/clear/escalate), false positive review procedures, ongoing rescreening protocols, and comprehensive recordkeeping (31 CFR Part 501; NCUA Q12(4)(a)). Similarly, AML compliance under 31 CFR 1020.210(b) requires SAR filing procedures, transaction monitoring for structuring and layering patterns, CTR filing for transactions exceeding $10,000, risk-based member scoring, enhanced due diligence, BSA officer designation, and independent program auditing.

A standardized validation framework — whether published as an NCUA examination guide supplement or incorporated into the final rule as minimum testing benchmarks — would serve three purposes: (a) reduce the burden on NCUA examiners by ensuring that applicants arrive at the examination stage with demonstrably tested compliance programs; (b) create a level playing field among credit unions of varying size and technical sophistication; and (c) reduce the risk that credit unions invest in compliance infrastructure that ultimately fails to meet NCUA expectations. The GENIUS Act's requirement for monthly reserve attestation by a registered public accounting firm (Section 3) demonstrates Congress's intent that compliance be verifiable and auditable; extending this principle to pre-licensure compliance testing is a natural and prudent step.

Comment 3: The Final Rule Should Address Federation and Interoperability Standards Between Credit Union PPSIs

The proposed rule's treatment of interoperability (referenced in NCUA Q12(7) and GENIUS Act Section 6) should be expanded to address the unique federation requirements of credit unions operating as PPSIs. Unlike banks, credit unions have a long history of inter-institutional cooperation through Credit Union Service Organizations (CUSOs), shared branching networks, and league-based collaboration. The GENIUS Act's requirement that PPSI licensees "enable interoperability with other compliant issuers" (Section 6) takes on particular significance in the credit union context, where federation is not merely a regulatory requirement but an extension of the cooperative model.

Specific areas requiring regulatory attention include: (a) standardized cross-institution identity verification protocols that allow a member verified by one credit union PPSI to transact with another without redundant CIP procedures; (b) trust registry frameworks that enable credit unions to establish and verify bilateral and multilateral trust agreements for stablecoin interoperability; (c) credential portability standards that allow compliance credentials to travel with members across federated credit union networks; and (d) Travel Rule compliance for inter-CU stablecoin transfers exceeding $3,000, with standardized messaging formats (ISO 20022 or equivalent).

ZKProva's patent-pending federated trust registry testing framework (Continuation-in-Part of PROV-007) addresses the verification layer of this problem — specifically, the use of Merkle tree-based verification to validate the integrity of trust agreements in multi-institution federation networks. We recommend that the NCUA establish minimum interoperability standards for credit union PPSIs in the final rule, with specific attention to trust registry requirements, credential portability, and the unique cooperative structure of credit union networks under NCUA Section 701.21(c)(8).

Comment 4: The NCUA Should Recognize Privacy-Preserving Compliance Verification Through Zero-Knowledge Proofs

The GENIUS Act creates a tension between two legitimate objectives: comprehensive compliance verification (requiring credit unions to demonstrate that their CIP, OFAC, AML, wallet, attestation, and federation programs meet regulatory standards) and member privacy (requiring that sensitive member data not be unnecessarily exposed during compliance validation and examination processes).

Zero-knowledge proof (ZKP) technology offers a path to resolving this tension. A ZKP-based compliance verification system can prove that a credit union's CIP program correctly verified a member's identity — including name, date of birth, address, and government-issued identification number per 31 CFR 1020.220 — without revealing the underlying member data to the verifier. Similarly, ZKP techniques can demonstrate that OFAC screening was performed against current SDN lists, that AML transaction monitoring detected and reported suspicious patterns, and that reserve attestation calculations are mathematically correct, all without exposing the specific member transactions or account details involved.

We respectfully recommend that the NCUA include in the final rule a recognition of privacy-preserving compliance verification methods, including zero-knowledge proofs, as an acceptable mechanism for demonstrating compliance during PPSI examinations. This is particularly important for credit unions, whose members have a reasonable expectation that their cooperative institution will minimize unnecessary data exposure. ZKProva's patent-pending ZKP compliance test vector generation framework (Continuation-in-Part of Application 63/994,522, PROV-009) demonstrates that ZKP-based compliance verification is technically feasible for the specific regulatory requirements of the GENIUS Act.

The inclusion of ZKP-based compliance verification in the final rule would position the NCUA as a forward-looking regulator, encourage innovation in privacy-preserving financial technology, and provide credit unions with a competitive advantage over bank-based stablecoin issuers in attracting privacy-conscious consumers.

III. Summary of Recommendations

We respectfully request that the NCUA consider the following modifications to the proposed rule:

  1. Require pre-licensure compliance testing as a condition of PPSI license approval, including synthetic data validation across all six compliance domains (CIP, OFAC, AML, Wallets, Attestation, Federation).
  2. Publish standardized compliance validation frameworks that credit unions can use to objectively assess PPSI readiness before examination, reducing examiner burden and ensuring consistent standards across institutions of varying size and sophistication.
  3. Establish federation and interoperability standards specific to the credit union context, including trust registry requirements, credential portability, and standardized cross-institution identity verification protocols under NCUA Q12(7) and GENIUS Act Section 6.
  4. Recognize privacy-preserving compliance verification methods, including zero-knowledge proofs, as acceptable mechanisms for demonstrating regulatory compliance during PPSI examinations.

IV. Conclusion

The GENIUS Act represents a historic opportunity for credit unions to participate in the stablecoin economy. The NCUA's proposed PPSI licensing framework appropriately establishes substantive compliance requirements. We believe the additions recommended in this letter — pre-licensure testing requirements, standardized validation frameworks, federation standards, and privacy-preserving verification — will strengthen the final rule and better equip credit unions to serve their members safely and competitively.

ZKProva Inc. welcomes the opportunity to provide additional technical detail, demonstrations, or testimony in support of these comments.

Respectfully submitted,

Viswanadha Pratap Kondoju
Founder & CEO
ZKProva Inc.

Disclaimer: This page is an informational archive of a public regulatory comment. It does not constitute legal advice. ZKProva Inc. is not a law firm and no attorney-client relationship is created. Not affiliated with, endorsed by, or sponsored by the NCUA, OCC, or U.S. Department of the Treasury.