CLARITY Act readiness checklist: 10 steps for banks, credit unions and MSBs
The CLARITY Act is not law yet, but the controls it would require are buildable now. A 10-step readiness checklist for banks, credit unions and MSBs.
- The CLARITY Act had not become law as of July 2026 — it passed the House and stalled short of the votes needed in the Senate — so nothing in this checklist is a present legal obligation arising from that bill.
- Almost every control the bill contemplates is already good practice, or already required of a regulated payments institution under existing money-transmission, AML and consumer-protection rules.
- Readiness is mostly documentary: knowing which digital assets you touch, who holds them, how customer assets are segregated, and who inside your institution owns each decision.
- The asymmetry favours preparing early. Institutions that build to a regulated-payments standard now lose little if the bill stalls further, and gain a head start if it passes.
- Preparation is also a commercial argument: banks assessing whether to serve an MSB read the same evidence an examiner would, so a documented control set directly affects your access to banking.
The CLARITY Act would establish which US regulator supervises which digital asset and impose market-structure obligations — registration, custody segregation, disclosure — on the intermediaries around them. As of July 2026 it is not law: it passed the House and then stalled in the Senate. Readiness therefore means building the controls the bill points toward, almost all of which are defensible under existing regulation anyway, so that a change in status is a filing exercise rather than a rebuild. The checklist below is written for banks, credit unions and MSBs that already move money and are adding, or considering, digital-asset settlement.
Why prepare for a bill that has not passed?
Because the cost of preparation is low and the cost of unpreparedness is concentrated at exactly the wrong moment. If market-structure legislation is enacted, implementation periods are typically measured in months and rulemaking follows for years afterwards; institutions that begin from zero at that point are competing for the same scarce compliance talent as everybody else. If instead the bill stalls indefinitely, an institution that built to a regulated-payments standard has still improved its examination posture and its attractiveness to banking partners. That asymmetry is the whole argument.
There is a second reason, less discussed. Bank de-risking of money service businesses has always been driven by the cost of supervising an opaque customer. The controls below are precisely the ones a correspondent or sponsor bank asks about during onboarding and annual review. Building them is not only regulatory hedging; it is how an MSB keeps or regains a bank account.
What belongs on the checklist?
- One: inventory every digital asset you touch. Which tokens, on which networks, held in which wallets, for which purpose — settlement, float, fee payment or customer balances. Institutions are routinely surprised by what turns up in this exercise.
- Two: classify each asset provisionally. Note whether it is a payment stablecoin, a digital commodity or something ambiguous, and record the reasoning. If a statutory classification later lands differently, you want a dated rationale rather than a blank page.
- Three: separate customer assets from institutional assets. Segregation of customer property is a recurring theme of market-structure proposals and an existing expectation of money transmitters. Document the account structure, the reconciliation frequency and who performs it.
- Four: pin down custody. Establish who legally holds each asset, under what agreement, with what bankruptcy-remoteness analysis and what key-management controls. “Our provider handles it” is not an answer an examiner accepts.
- Five: extend the AML programme explicitly to digital assets. Risk assessment, KYC and KYB, transaction monitoring calibrated to on-chain behaviour, sanctions screening including wallet-address screening, and Travel Rule data on qualifying transfers.
- Six: document your disclosure position. What do you tell customers about how their balance is held, what happens on failure, what fees and spreads apply, and how quickly funds are available. Write it before you are asked.
- Seven: name the owners. Board-level accountability, a named compliance officer with digital-asset responsibility, and a documented escalation path. Governance gaps are cited far more often than technical ones.
- Eight: assess your venues and counterparties. Where do you convert between fiat and digital assets, who are those entities, what licences do they hold, and what happens to your flows if one is suspended.
- Nine: make your records examiner-ready. Complete, retrievable, time-stamped transaction records that reconcile the on-chain record to your ledger and to the customer-facing statement, produced in days not months.
- Ten: rehearse the failure cases. A depeg, a frozen address, a sanctions hit mid-settlement, a custodian outage. A tested playbook is worth more than a policy nobody has read.
Which items matter most for a bank or credit union?
Depository institutions start from a stronger position on governance, records and AML, and a weaker one on asset classification, custody mechanics and counterparty assessment — simply because those questions are new to the risk committee rather than because the institution is careless. For a community bank or credit union evaluating stablecoin settlement, items four, eight and ten deserve disproportionate attention. Custody and counterparty exposure are where an unfamiliar risk enters a familiar balance sheet, and the failure rehearsal is what converts a board’s abstract discomfort into a decision it can actually take.
Credit unions in particular should note that member-facing disclosure, item six, carries reputational weight beyond its regulatory weight. Members hold institutions they own to a different standard, and a clear explanation of how a settlement asset is backed and held is worth writing well.
Nothing on this list becomes wasted work if the bill never passes. Every item is either already required of a regulated payments institution or already asked by the bank you want to keep.
Which items matter most for an MSB?
For money service businesses the centre of gravity shifts to items three, five and nine: segregation of customer funds, an AML programme that genuinely covers on-chain activity, and records that survive contact with an examiner. These are also the three questions a sponsor bank asks first. An MSB that can produce a clean licence register, a risk assessment that names digital-asset typologies specifically, monitoring rules calibrated to its actual corridors, and reconciled transaction records is answering the market-structure question and the de-risking question with one body of evidence.
Item two — provisional classification — deserves a note of caution for smaller operators. The point is not to reach a legally correct answer in advance of the statute; nobody can. The point is to show that the institution considered the question, applied a consistent methodology and recorded when and why each judgement was made. Regulators are considerably more forgiving of a documented judgement that later proves wrong than of no judgement at all.
How should you sequence the work?
Do the inventory first, because it is cheap and it usually reframes everything after it. Then close the two items most likely to be tested in the next twelve months regardless of legislation: segregation and the AML extension. Governance and documentation follow, since they are largely writing exercises once the facts are known. Leave the failure rehearsal until you have something real to rehearse against, but do not leave it out — it is the item most often deferred and most useful when needed. A reasonable target for a mid-sized institution is a quarter of part-time effort, not a programme.
Where StableNet fits
Several items on this checklist are easier when the settlement rail itself produces the evidence. StableNet attaches KYC, KYB, KYT, sanctions screening and Travel Rule data to each payment and reconciles the on-chain record against bank-standard SWIFT and ISO 20022 messaging, which turns items five and nine from a manual reconciliation project into a reporting one. Whatever happens to the bill in the Senate, an institution whose rails carry their own audit trail is in a better position on the day the rules are written.
See it on your corridors
Book a working session and we’ll map StableNet’s compliance and settlement to one of your live payment flows.