Skip to content
All insights
ComplianceSeptember 18, 2026 · 8 min read

Third party risk management for a stablecoin payment provider: what a bank or credit union must assess

Third party risk management for a stablecoin payment provider: the due diligence, contract terms, monitoring and exit plan a bank or credit union needs.

By Jay Kambo
Illustration — Third party risk management for a stablecoin payment provider: what a bank or credit union must assess
Key takeaways
  • Outsourcing the work does not outsource the obligation. The interagency guidance issued by the Federal Reserve, the FDIC and the OCC in June 2023 is explicit that a bank keeps responsibility for an activity performed by a third party.
  • A stablecoin payment provider sits inside the payment, not beside it. It touches customer data, screening decisions and the settlement record, so it belongs in the highest diligence tier rather than the software tier.
  • The provider is not the issuer. A bank that accepts a token takes issuer risk as well as vendor risk, and both files need their own evidence.
  • Write the exit into the contract on the day you sign it. Records, addresses, keys and in flight payments all have to survive a termination that neither side planned.
  • Credit unions carry more of this weight themselves, because the NCUA has asked Congress for authority to examine third party vendors and does not have it.

A bank or credit union that settles cross border payments in stablecoins rarely does the work alone. It buys a platform. It appoints a custodian. It trades with a liquidity provider. Each of those is a vendor, and each sits inside the payment rather than beside it. Third party risk management is the discipline that keeps the arrangement supervisable. The stablecoin part is new. The framework is not. Supervisors have expected a bank to own the risk of an outsourced activity for years, and the 2023 interagency guidance restated it plainly. This article sets out how to apply third party risk management to a stablecoin payment provider. What to ask before signing. What to write into the contract. What to watch afterwards. And how to leave.

What makes a stablecoin payment provider a third party risk?

Start with what the provider actually touches. It moves value, or it instructs the movement of value. It holds customer and beneficiary data. It often runs sanctions screening. It produces the record an examiner will later read. That is not a software purchase. That is an operating unit the institution does not employ.

Three exposures follow. Operational risk, because an outage stops payments the institution promised. Compliance risk, because a screening miss belongs to the institution as well as the vendor. Financial risk, because a provider failure can strand funds in transit. Concentration risk sits on top when one provider covers a corridor with no alternative.

The key point in the June 2023 Interagency Guidance on Third-Party Relationships, issued by the Federal Reserve, the FDIC and the OCC, is that responsibility does not transfer. The guidance replaced each agency's earlier statements, including OCC Bulletin 2013-29. A banking organisation remains responsible for conducting its activities in a safe and sound manner, whoever performs them. The vendor contract allocates work and cost. It does not allocate the supervisor's expectations.

Which rules govern third party risk management at banks and credit unions?

For banks, the 2023 interagency guidance is the reference document. It describes a relationship lifecycle: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination. It is deliberately risk based rather than prescriptive. A critical activity gets deep diligence. A low risk tool does not. The same three agencies published a guide for community banks in May 2024 with worked examples, which is the more practical starting point for a smaller institution.

Credit unions work from a different shelf. The NCUA set out its position on member facing digital asset relationships in Letter to Credit Unions 21-CU-16 in December 2021, and on distributed ledger technology in Letter to Credit Unions 22-CU-07 in May 2022. Both letters point back to due diligence, board oversight and a written risk assessment. There is also a structural gap worth naming. The NCUA has asked Congress for authority to examine third party vendors directly and does not have it, so a credit union cannot lean on a supervisory examination of its provider. Its own file is the record.

Neither regime gives a checklist to tick. Both ask the institution to tier its relationships by criticality and to match the depth of work to the tier. A stablecoin settlement provider belongs near the top of that tier list.

What should due diligence on a stablecoin payment provider cover?

Diligence on this kind of vendor has to reach past the sales deck. The useful questions are about licences, controls, money and evidence. Work through them in a fixed order so the file reads the same way every year.

  • Confirm the legal entity and its registrations. Which entity signs the contract, where is it incorporated, and which money transmission, MSB or virtual asset registrations does it hold in each jurisdiction it serves.
  • Test financial condition. Audited statements, ownership, funding runway and insurance, because a provider holding funds in transit is a counterparty as well as a supplier.
  • Read the control reports rather than the summary. A SOC 1 or SOC 2 Type II report covers a period and lists exceptions; ask for the full report and the management response to each exception.
  • Inspect the compliance programme. Screening vendors and list coverage, Travel Rule handling under FATF Recommendation 16, KYB and KYC procedures, and who decides when a payment is held.
  • Map custody and key control. Who holds the private keys, under what approval model, and what happens to your balances if the provider fails.
  • Establish resilience and dependencies. Uptime history, incident record, named subcontractors, chain coverage, and the recovery time the provider will commit to in writing.

One test is worth more than the others. Ask the provider to produce the full evidence trail for a single past payment: the instruction, the screening result, the approval, the settlement reference and the ledger entry. A provider that can assemble that in an afternoon will make your next examination straightforward. A provider that cannot will make it expensive.

How do you assess the stablecoin issuer behind the provider?

The provider is not the issuer, and the institution takes both risks. A payment stablecoin is a claim on a reserve held by the issuer. If the reserve is weak, no amount of vendor diligence on the platform will help.

The GENIUS Act, enacted in the United States in 2025, requires a permitted payment stablecoin issuer to back each token at least one to one with cash and short dated Treasury instruments and to publish the composition of its reserves each month. That gives a counterparty something concrete to read. Check the monthly report, the examining firm, the redemption terms, and how long a redemption takes in practice. Check who can freeze a balance and on what authority. Then decide which tokens the institution will accept and write the answer into policy.

A vendor file that only describes the platform is half a file. The institution settles in someone else's liability, and the issuer behind that liability deserves the same scrutiny as the software in front of it.

What belongs in the contract, and what belongs in ongoing monitoring?

Contract negotiation is the one stage where leverage exists. Use it on the terms that are hard to retrofit. Service levels with a remedy attached. Audit and information rights, including the right to receive control reports without asking twice. Notice and consent for material subcontractors. Data location and deletion. Incident notification inside a stated number of hours, not at the provider's discretion. Records retention that outlives the contract, because an examiner may ask about a payment years after the relationship ends.

Monitoring is where most programmes quietly decay. Give each relationship a named owner inside the institution, not a shared mailbox. Set a review frequency by tier and hold to it. Read each new control report and each monthly reserve report when it lands. Track incidents, screening quality and reconciliation breaks as running metrics rather than annual anecdotes. Report the tier one relationships to the board or its risk committee on a schedule.

A short annual test helps more than a long questionnaire. Pick one payment at random. Rebuild it end to end from the records the provider gives you. If the rebuild is clean, the monitoring is working.

How do you exit a stablecoin provider without stranding payments?

Write the exit plan on the day you sign, while both parties are agreeable. Termination is the stage the 2023 interagency guidance treats as part of the lifecycle, and it is the stage most institutions document last.

Four questions decide how painful a departure will be. Where do the records go, and in what format. Who controls the wallet addresses and keys, and how are balances returned. What happens to payments already in flight at the cut off. And how long will the provider assist after notice is served. Portable formats matter more here than anywhere else. Settlement records written as ISO 20022 messages, a pacs.008 customer credit transfer with its pacs.002 status and any pacs.004 return, each tied to a UETR, move to another provider intact. A proprietary export usually does not.

Keep a second option warm as well. A corridor served by one provider with no tested alternative is a concentration the board should see in writing. Running a small volume through a second route is cheaper than discovering the switching cost during an incident.

Where StableNet fits

StableNet, built by SpendTheBits, is a cross border B2B payment and settlement platform for banks, credit unions, licensed money service businesses, exchange houses and remittance fintechs. Settlement runs in regulated stablecoins such as USDC and USDT on public blockchains, completing in minutes with on chain auditability, so the evidence a vendor review asks for is produced as the payment settles rather than assembled afterwards. The platform is ISO 20022 native, with pacs.008 customer credit transfers, pacs.009 interbank legs, pacs.002 status reports and pacs.004 returns inside head.001 envelopes, tracked end to end by UETR, which keeps the settlement record portable if the institution ever changes provider. Compliance is built in, with KYB and KYC onboarding, KYT, sanctions and PEP screening, FATF Travel Rule data in IVMS101 form, a compliance workbench and a tamper evident audit trail. SpendTheBits is a Bank of Canada registered payment service provider and a named finalist in the Swift Hackathon 2026 Technical Challenge.

See it on your corridors

Book a working session and we’ll map StableNet’s compliance and settlement to one of your live payment flows.

FAQ

Common questions

No. The Interagency Guidance on Third-Party Relationships issued by the Federal Reserve, the FDIC and the OCC in June 2023 states that a banking organisation remains responsible for conducting its activities in a safe and sound manner and in compliance with applicable law, whether it performs them itself or through a third party. The contract allocates work. It does not allocate the supervisor's expectations.