← Back to Archive
OCC

Comprehensive GENIUS Act Implementation

Date submitted: April 10, 2026
Docket: OCC-2025-0372
RIN: 1557-AF41
Tracking ID: mnt-kdlv-suv5
Executive Summary

This consolidated comment to the OCC presents all ten technical recommendations previously submitted to the NCUA, adapted for OCC-supervised institutions. It covers pre-licensure compliance testing, standardized validation frameworks, federation and interoperability, privacy-preserving verification, consumer disclosures, examiner tooling, reserve attestation, AML/FinCEN automation, shared service organization aggregation, and wallet credential state machine standards. It emphasizes cross-regulator consistency to avoid fragmented stablecoin ecosystems.

Recommendations (Consolidated)

  1. Pre-licensure compliance testing — require applicants to demonstrate compliance testing before license approval.
  2. Standardized validation frameworks — establish readiness criteria across six compliance domains.
  3. Federation and interoperability standards — address cross-institution identity verification, trust registries, credential portability, and Travel Rule compliance.
  4. Privacy-preserving compliance verification — recognize zero-knowledge proofs as acceptable examination mechanisms.
  5. Consumer disclosure standards — require three mandatory disclosures with individual acknowledgment and wallet activation gating.
  6. Examiner tooling and audit standards — establish role-based access, cryptographic proof verification, W3C VC signing, and standardized submission packages.
  7. Reserve attestation technical standards — recognize Groth16 proofs, require temporal chain linking, establish 35-day freshness, and define data lifecycle.
  8. AML threshold enforcement and FinCEN filing — require real-time enforcement, automated filing, Travel Rule tiers, and risk classification.
  9. Shared service organization aggregation — recognize aggregators for small/mid-sized institutions with delegation security.
  10. Wallet credential state machine — require four-state machine with cryptographic binding, compliance gating, and lawful order cascading.

Full Letter Text

ZKProva Inc.
Compliance Technology & Infrastructure

April 10, 2026

Office of the Comptroller of the Currency
400 7th Street SW
Washington, DC 20219

Re: Docket ID OCC-2025-0372; RIN 1557-AF41 — Notice of Proposed Rulemaking: Implementing the Guiding and Establishing National Innovation for U.S. Stablecoins Act for the Issuance of Stablecoins by Entities Subject to the Jurisdiction of the Office of the Comptroller of the Currency — Comprehensive Comment on Compliance Infrastructure Standards

Dear Comptroller of the Currency:

I. Identity and Interest of the Commenter

ZKProva Inc. is a compliance technology company that has developed GeniusComply (deployed at ppsiready.com), a production compliance testing infrastructure platform purpose-built for institutions preparing for permitted payment stablecoin issuer (PPSI) licensure under the GENIUS Act. GeniusComply provides six integrated compliance validation modules covering Customer Identification Programs (CIP), OFAC sanctions screening, Anti-Money Laundering (AML) monitoring, stablecoin wallet compliance, reserve attestation, and inter-institution federation — each mapped to specific GENIUS Act sections.

ZKProva has submitted seven comment letters to the NCUA on the parallel PPSI licensing rulemaking for credit unions (Docket No. NCUA-2026-0265; Tracking IDs: mnk-icx3-0rd5, mno-0mc6-didw, mno-0qt5-kz5r, mnq-s497-hxgm, mnq-sqc4-isv8, mnt-gxgw-810f, mnt-hnve-wmmg), covering pre-licensure compliance testing, consumer disclosures, examiner tooling, reserve attestation, AML/FinCEN automation, CUSO aggregation, and wallet credential state machine standards. We submit this comprehensive comment to the OCC to ensure that the technical standards we have recommended to the NCUA are also considered for OCC-supervised entities, promoting regulatory consistency across federal regulators implementing the same statute.

ZKProva holds patent-pending innovations in this space, including U.S. Provisional Application PROV-010 (regulation-aware synthetic compliance test data generation), Continuation-in-Part of Application 63/994,522 (PROV-009) (zero-knowledge proof compliance test vector generation and verification), and Continuation-in-Part of PROV-007 (federated trust registry testing with Merkle verification).

II. Summary of Recommendations

We respectfully request that the OCC consider the following technical standards for incorporation into the final rule. Each recommendation is drawn from our production experience building GENIUS Act compliance infrastructure and from our parallel comments to the NCUA.

A. Pre-Licensure Compliance Testing (NCUA Comment 1)

The final rule should require PPSI license applicants to demonstrate pre-issuance compliance testing — including synthetic data validation of CIP identity verification workflows, simulated OFAC screening with known-positive and false-positive scenarios, and AML pattern detection testing with labeled suspicious activity scenarios — as a condition of license approval. Compliance monitoring (detecting violations after they occur) is insufficient; compliance testing (validating that systems correctly handle edge cases before going live) is essential for consumer protection, particularly in the early stages of GENIUS Act implementation when operational experience with stablecoin compliance is limited.

B. Standardized Compliance Validation Frameworks (NCUA Comment 2)

The final rule should establish — or encourage the development of — standardized validation criteria that institutions can use to self-assess PPSI readiness before submitting license applications. A readiness framework covering six compliance domains (CIP, OFAC, AML, Wallets, Attestation, Federation) with weighted scoring and objective grading criteria would reduce examiner burden, create a level playing field, and reduce the risk of compliance infrastructure investments that fail to meet regulatory expectations.

C. Federation and Interoperability Standards (NCUA Comment 3)

The GENIUS Act's interoperability requirement (Section 6) requires regulatory attention to: standardized cross-institution identity verification protocols, trust registry frameworks for bilateral and multilateral trust agreements, credential portability standards, and Travel Rule compliance for inter-institution stablecoin transfers exceeding $3,000. For OCC-supervised institutions, interoperability with both other OCC-supervised PPSIs and with PPSIs supervised by other regulators (NCUA, FDIC, state regulators) is particularly important to avoid fragmented stablecoin ecosystems.

D. Privacy-Preserving Compliance Verification (NCUA Comment 4)

The final rule should recognize zero-knowledge proofs (ZKPs) as an acceptable mechanism for demonstrating compliance during PPSI examinations. ZKP-based verification can prove that CIP verification was correctly performed, that OFAC screening checked against current SDN lists, that AML monitoring detected suspicious patterns, and that reserve attestation calculations are correct — all without revealing the underlying member data to the verifier. This is particularly important for institutions competing for privacy-conscious customers.

E. Consumer Disclosure Standards (NCUA Comment 5)

The final rule should require three mandatory disclosures before wallet activation (no insurance coverage, not legal tender, redemption rights), specify acceptable delivery methods with audit trail requirements, require individual acknowledgment per disclosure type, gate wallet activation on disclosure completion as a programmatic technical control, and establish disclosure versioning with SHA-256 hashing for tamper-evidence.

F. Examiner Tooling and Audit Standards (NCUA Comment 6)

The final rule should establish technical standards for PPSI examination, including: role-based examiner access (OCC examiner with unrestricted access; CPA firm scoped to authorized issuers); cryptographic proof verification (single proof, temporal chain, batch verification with session recording); W3C Verifiable Credential v2 with Ed25519Signature2020 for signed examination findings; and a standardized submission package format. Consistent examination standards across OCC and NCUA would benefit institutions subject to both regulators and would enable examination teams to develop shared expertise in cryptographic compliance verification.

G. Reserve Attestation Technical Standards (NCUA Comment 7)

The final rule should recognize cryptographic reserve sufficiency proofs (Groth16 zk-SNARKs) as an acceptable mechanism for demonstrating 1:1 reserve backing, require temporal accumulator chain linking of monthly attestations for tamper-evidence, establish a 35-day reserve freshness requirement for stablecoin minting (enforced programmatically), define reserve data lifecycle standards with atomic attestation generation, and recognize on-chain proof verification via smart contract as an additional assurance mechanism.

H. AML Threshold Enforcement and FinCEN Filing Automation (NCUA Comment 8)

The final rule should require real-time AML threshold enforcement for stablecoin transactions (CTR at $10,000/24h, MSB at $3,000, structuring detection at 80% of CTR across 3+ transactions), automated SAR/CTR filing with deadline tracking and BSA XML v2.0 generation, Travel Rule compliance tiers for inter-institution transfers (exempt below $3,000, standard $3,000-$9,999, enhanced $10,000+), AML risk tier classification on wallets, and BSA five-year record retention with legal hold support.

I. Shared Service Organization Aggregation (NCUA Comment 9)

The final rule should recognize shared service organizations — whether structured as credit union service organizations (CUSOs), bankers' banks, or similar aggregation entities — as authorized PPSI compliance aggregators. Small and mid-sized OCC-supervised institutions will face the same cost-of-compliance challenges as small credit unions, and the cooperative aggregation model enables these institutions to share compliance infrastructure, aggregate readiness reporting, delegate operations under explicit authorization, and facilitate shared examination. The final rule should establish aggregator governance requirements, delegation security standards (explicit authorization, audit trail, scope limitation), and aggregate readiness reporting standards.

J. Wallet Credential State Machine Standards (NCUA Comment 10)

The final rule should require a formally defined wallet credential state machine with four states (UNBOUND, ACTIVE, REVOKED, EXPIRED), explicit permitted and prohibited transitions, cryptographic wallet binding via Pedersen commitments, compliance-gated activation preconditions, lawful order cascading (freeze triggers credential revocation, seizure executes forced transfer), and credential expiration with mandatory re-verification on renewal.

III. Cross-Regulator Consistency

The GENIUS Act establishes a single statutory framework implemented by multiple regulators — the OCC, NCUA, FDIC, and state regulators. Technical standards for PPSI compliance should be consistent across regulators to the greatest extent possible. Inconsistent standards would create regulatory arbitrage opportunities, increase compliance costs for institutions supervised by multiple regulators, and fragment the stablecoin ecosystem.

We encourage the OCC to coordinate with the NCUA, FDIC, and state regulators on the technical standards recommended in this comment. Where the OCC's final rule adopts specific technical standards — for example, for reserve attestation proof formats, examination submission package formats, or wallet state machine definitions — those standards should be interoperable with standards adopted by other regulators under the same statute.

IV. Technical Feasibility

ZKProva has implemented all of the technical standards recommended in this comment as part of the GeniusComply platform (deployed at ppsiready.com). The platform is purpose-built for credit unions preparing for PPSI licensure, but the underlying technology is regulator-agnostic and can be adapted for OCC-supervised institutions. The standards recommended in this comment are technically proven through our deployed implementation and designed for the specific compliance requirements of the GENIUS Act.

V. Conclusion

The GENIUS Act creates a historic opportunity for regulated financial institutions to participate in the stablecoin economy. The OCC's proposed rule appropriately establishes the framework for licensure and supervision. The technical standards recommended in this comment — drawn from production experience and parallel NCUA comments — would strengthen the final rule, promote cross-regulator consistency, and ensure that OCC-supervised PPSIs operate with the same rigor and transparency that the GENIUS Act demands.

ZKProva Inc. welcomes the opportunity to provide additional technical detail, demonstrations, or testimony in support of these comments.

Respectfully submitted,

Viswanadha Pratap Kondoju
Inventor & Technical Advisor
ZKProva Inc. (incorporation pending)

Disclaimer: This page is an informational archive of a public regulatory comment. It does not constitute legal advice. ZKProva Inc. is not a law firm and no attorney-client relationship is created. Not affiliated with, endorsed by, or sponsored by the NCUA, OCC, or U.S. Department of the Treasury.