Cross-border stablecoin payments are legal in both the US and the EU, but only when the sender and receiver each hold the right licenses for their end of the corridor. In the US that usually means state-by-state money transmitter licensing and federal BSA obligations; in the EU it means MiCA CASP registration; and on top of both sits the FATF Travel Rule, sanctions screening, and (since 2025) the GENIUS Act's restrictions on foreign issuers handling US-bound flows.
Key takeaways
- US outbound stablecoin corridors require money transmitter licenses in every destination state, plus a written BSA/AML program with Travel Rule data attached to every transfer.
- EU corridors now route through MiCA-registered CASPs, and most US firms access the EU through reverse solicitation or an EU-domiciled partner, not by licensing in 27 member states.
- The FATF Travel Rule applies to transfers above roughly 1,000 USD/EUR of originator and beneficiary information, but auditors increasingly expect Travel Rule fields on transfers well below that threshold.
- The GENIUS Act bars foreign stablecoin issuers from serving US customers without an OCC trust charter or a qualified US subsidiary, so legacy USDC and EURC corridors had to restructure in 2025.
Who this compliance map is actually for
This is a working document for compliance officers, treasury leads, and product engineers at fintechs, remittance companies, and neobanks that are either launching or scaling a stablecoin remittance corridor. The worked example is US to Mexico using USDC, but the same logic applies to most Latin American, European, and Southeast Asian corridors with the right substitutions.
Two assumptions before you read further. First, you already understand what a stablecoin is: a token on a public blockchain whose value is pegged to a fiat currency, typically 1 USD per token. Second, you understand the difference between custodial and non-custodial wallets: a custodial wallet is run by a licensed entity that holds the private keys for you, while a non-custodial wallet puts the user in control of their own keys. Both create distinct compliance duties, and both are addressed below.
If you are building a custodial product where your firm holds customer funds in stablecoins at any point in the flow, you are a money services business and you are subject to the full stack described here. If you are building a non-custodial wallet and never take custody, your obligations are narrower but not zero, and they shift quickly once transaction volume picks up.
The risk picture before you write a single policy
Stablecoin corridors look simple on a whiteboard and messy in production. The failure modes fall into a small number of buckets, and auditors see them constantly.
\p>Sub-threshold structuring. Criminals and ordinary users both split payments into chunks under 1,000 USD to avoid triggering the Travel Rule. The US PATRIOT Act, the EU's sixth AML Directive, and FATF Recommendation 16 all impose recordkeeping duties well below that figure in many cases, and FinCEN has historically expected monitoring of sub-threshold patterns as part of a risk-based program. The Travel Rule number is a data-sharing floor, not a monitoring ceiling.
Peer-to-peer leakage. Once a customer has USDC in a self-custody wallet, no VASP can stop them from sending it to an address you have never screened. Corridors that ignore this leakage and only screen at the on-ramp and off-ramp end up with most of their risk concentrated in flows that touch exchanges, OTC desks, and high-risk merchant acquirers on the receiving side.
Jurisdictional arbitrage. A US-domiciled customer sending to an EU-domiciled recipient can route through a CASP based in any member state, but the US firm still owes US obligations. Symmetrically, a Mexican recipient can cash out at a non-licensed local agent who later off-ramps through a different exchange, and the US originator's bank will want to know that the chain of intermediaries met local Mexican law.
Sanctions blind spots. OFAC, the EU's restrictive measures regime, and Mexican sanctions lists all move independently. A US firm that only screens against OFAC misses EU and Mexican designations; a firm that only screens at the wallet level misses the fact that the beneficial owner of an exchange deposit address may have changed hands.
Stablecoin depeg contagion. SVB in March 2023 showed that even USDC, then the second-largest dollar stablecoin, can trade briefly at 0.87 USD if its issuer's banking stack wobbles. FX corridors that promise recipients an exact peso amount create an FX risk on the books of someone, and that someone is usually the sender or the liquidity provider. Auditors ask who carries the depeg risk for every settlement.
Historical wipeouts. The 2022 USDC depeg during SVB stress, the TerraUSD collapse in May 2022 where billions of dollars of value vanished in days, and the Tether issues in 2018 are not edge cases. They are the reason the GENIUS Act requires 1:1 reserve backing with monthly attestations and short-term Treasuries.
The legal stack a US-to-Mexico USDC corridor sits on
A US-based originator sending USDC to a Mexican recipient touches at least five overlapping regimes. Pin them down before you draw a flowchart.
1. US money transmitter licensing. If you transmit USDC on behalf of customers as part of a remittance business, you are a money transmitter under the Bank Secrecy Act and most state money transmitter statutes. Practically that means MTL licenses in every state you serve, plus registration with FinCEN as an MSB. Several states, including New York and Texas, treat stablecoin custody and transmission as money transmission even if no fiat ever touches your balance sheet.
2. The GENIUS Act (2025). The Guiding and Establishing National Innovation for US Stablecoins Act creates a federal framework for payment stablecoins issued by US persons. For cross-border flows the two clauses that matter are the foreign-issuer restrictions and the insolvency priority. Non-US issuers of payment stablecoins cannot serve US customers unless they hold an OCC trust charter or operate through a US-incorporated subsidiary that meets the same standards (1:1 reserves, monthly attestations, redemption at par). That is why Circle's USDC and Ripple's RLUSD have re-papered US distribution, and why foreign stablecoins like Tether have largely exited direct US retail. Cross-border corridors that depended on offshore issuers had to migrate to licensed issuers between mid and late 2025.
3. MiCA CASP registration. The EU's Markets in Crypto-Assets Regulation took full effect in 2024. Any firm that issues or distributes asset-referenced tokens or e-money tokens (including USDC and EURC) to EU customers needs to register as a Crypto-Asset Service Provider. To handle both US and EU sides of a corridor you either obtain CASP authorization in one member state and passport across the bloc, or you partner with an existing CASP who serves the EU customer while you serve the US customer. Auditors expect a written distributor agreement covering customer segregation, complaint handling, and white-label liability.
4. The FATF Travel Rule. Recommendation 16 requires originators and beneficiaries to share full payer and payee information for transfers above a national threshold, generally 1,000 USD/EUR but lower in many jurisdictions. The original counterparty must collect the originator's name, address, account number, and a national identifier, plus the beneficiary's name and account number. In practice that means your wallet infrastructure speaks a Travel Rule protocol (the leading open options are TRISA for the US side and Codefi Notabene and others for the EU side) and that your partners do too.
5. Mexican and local-issuer rules. Mexico does not yet have a unified crypto law equivalent to MiCA, but the Ley Fintech (2018) covers electronic payment institutions, and CNBV guidance treats virtual asset service providers with increasing scrutiny. Cash-out partners need to be licensed under Mexican law for the peso leg to be defensible to your US bank.
Designing the corridor: where compliance actually breaks down
Take a US firm, licensed in every relevant state, registered with FinCEN, holding CASP authorization through reverse solicitation or an EU partner, planning to send USDC from US customers to Mexican recipients who cash out in pesos at local agents. The skeleton looks fine. The interesting work is at the joints.
Onboarding. You need customer identification at the originator side at whatever the BSA threshold is for the product tier (usually CIP at account opening regardless of size). You also need a contractual basis to share that data with the Travel Rule counterparty on the receiving side. Recipients in Mexico are usually identified by the cash-out partner before payout; recipients in self-custody have to be identified at the point they on-ramp, which is a step many corridors skip.
The transfer. Send 5,000 USDC across the corridor. Step 1, your system fires the originator and beneficiary data to the receiving partner over a Travel Rule messaging channel. Step 2, you screen both addresses and their beneficial owners against OFAC, EU, and Mexican lists. Step 3, you push the USDC on Ethereum (or, cheaper, on a layer 2 like Base). Step 4, the receiving partner validates the data against your message, credits the recipient, and pays out in pesos. The audit hot spots at this step are missing counterparty due diligence on the receiving VASP, slow Travel Rule messaging that lets transactions land before the data does, and a lack of automated sanctions screening on layer-2 addresses.
Where things break. Sub-1,000 transfers that should still be monitored, peer-to-peer handoffs that bypass the regulated handoff, jurisdictional arbitrage where a customer routes through a friend in a more permissive state, and stablecoin depeg moments that turn a routine settlement into a shortage on one party's books. The next two sub-sections cover each.
The sub-1,000 problem and the Travel Rule, in practice
FATF Recommendation 16 sets a national threshold of roughly 1,000 USD/EUR. In the US, FinCEN's 2020 guidance and the Bank Secrecy Act itself have long required collecting and retaining originator information on transmittor funds over 3,000 USD, but the FATF-aligned expectation, and the one the Treasury expects you to follow as part of a risk-based program, covers any transfer a reasonable person would flag as suspicious. Auditors increasingly test two things.
First, do you have a written policy stating that sub-threshold transfers still get screened against sanctions lists and monitored for structuring? A policy that does not say this fails the first time a customer makes 10 transfers of 800 USD in a single afternoon. Second, does your Travel Rule technical integration actually carry beneficiary and originator data on those sub-threshold transfers, or only on transfers above the threshold? Practitioners call the gap 'silent sub-threshold', and it is a frequent matter requiring attention in SOC 1 reports.
Operationally you have three choices. You apply full Travel Rule messaging to every transfer regardless of size, which is the strongest posture but adds cost. You apply sanctions and AML screening to every transfer regardless of size while only carrying the full Travel Rule payload above the threshold, which is acceptable if your policy is clear. You carry Travel Rule data only above the threshold, which is the weakest and rarely survives an external audit.
Peer-to-peer handoffs and what auditors want you to do about them
Every corridor loses flow into peer-to-peer. A customer in California sends USDC from their custody account to their own non-custodial wallet, then from that wallet to a recipient's exchange deposit address in Mexico. Your firm never handled the second hop. Auditors still ask what you did.
The conservative answer is to monitor your own on-ramp and off-ramp hard, treat the gap in the middle as a fact of life, and document it. The stronger answer is to apply risk-based monitoring to recipients at the first hop, including cluster analysis and behavioral scoring, so that you can identify cases where a US customer is consistently sending to addresses associated with Mexico-bound cash-out services. A small share of compliance teams use blockchain analytics from firms such as Chainalysis, TRM Labs, or Elliptic at the wallet level to assign risk scores to recipient addresses even when those addresses are non-custodial.
A peer-to-peer clause in your terms of service forbidding sanctioned or unlawful use of your platform is necessary but not sufficient. Auditors also look for an exit strategy: how do you offboard a customer you have evidence is using your platform to funnel funds to sanctioned addresses, and how do you file a SAR within the 30-day window the Bank Secrecy Act allows?
What auditors actually require on day one
Practical walk-throughs of what shows up on a SOC 1 Type 2 audit or a state money-transmitter examination tend to share a common checklist.
- A written AML program. Designated compliance officer, written policies, independent testing, ongoing training, and a risk assessment refreshed at least annually. The Department of the Treasury expects these elements to exist before you process your first transfer.
- Travel Rule technical implementation. Not a slide deck. A working counterparty integration on a Travel Rule messaging protocol, with countersigned evidence in your logs that data was exchanged on the transactions covered.
- Sanctions screening on Ethereum and layer 2s. OFAC screening on Ethereum mainnet is table stakes. Auditors also expect to see that you screen addresses on Base, Arbitrum, and Optimism, and that you have a written policy on how often you refresh addresses against updated SDN lists.
- Stablecoin issuer diligence. For corridors using USDC, EURC, or RLUSD, a current reserve attestation, a recent SOC report from the issuer, and a written analysis of redemption mechanics and depeg risk. The GENIUS Act's 1:1 backing and monthly attestations make this easier than it was in 2022, but examiners still ask.
- Counterparty VASP due diligence. For each exchange, OTC desk, liquidity provider, and cash-out agent, a written risk assessment including license status, regulator, jurisdiction, beneficial ownership where knowable, and the controls you rely on for the segments of the flow they handle.
- SAR and incident-response runbooks. Filed, filed-in-time runbooks for structuring, sanctions hits, depeg events, and Travel Rule messaging failures. Auditors test these by asking for the most recent mock scenario.
None of these are exotic. They are what an examiner has come to expect from any payments business, and they are what your bank partner's BSA officer will ask for at your next quarterly review.
Practical implications for your team
Three takeaways for the compliance and treasury teams who actually have to ship this. First, build the corridor with the licensed issuer in mind. If you assume your corridor will use USDC via Circle, design the contract and the operational integration around an OCC-trust-chartered path that survives the GENIUS Act's foreign-issuer rules. If you assume EURC will appear on the EU side of a future corridor, design for MiCA CASPs to white-label you. Retrofitting these decisions later is the most expensive failure mode in this space.
Second, treat the Travel Rule as a product feature, not a back-office compliance box. Customers will increasingly expect to see what data is being shared and why, and a clear privacy notice that names the receiving VASP is a feature you can market. Hiding Travel Rule mechanics until a regulator asks creates avoidable friction.
Third, plan for the next regime change. The GENIUS Act is a 2025 statute; the EU has MiCA; Mexico is finalizing its own framework. Assume the licensing map you draw today will need a refresh in 18 months. Build the policies, vendor contracts, and counterparty agreements so that they can absorb a new rule without re-platforming.
Track stablecoin payments and the regulation around them
Stablecoin corridors and the rules around them move quickly, and so does the news. Tracking GENIUS Act guidance, MiCA CASP notices, FATF updates, and bank enforcement actions manually is a losing game. Zippfeed surfaces stablecoin and payments-regulation headlines with sentiment scoring (bullish, neutral, or bearish) and an importance rating, so you can see what matters before your next quarterly review.