Skip to content
All insights
TreasurySeptember 16, 2026 · 8 min read

USDC treasury operations at a bank: custody, sweeps, reconciliation and audit

USDC treasury operations at a bank, in operating detail: custody and key control, daily sweeps, three way reconciliation, and the evidence an auditor asks for.

By Jay Kambo
Illustration — USDC treasury operations at a bank: custody, sweeps, reconciliation and audit
Key takeaways
  • Holding USDC is a credit decision before it is an operations decision. The bank takes issuer risk, reserve risk and redemption risk, and those belong in the framework that governs any other short dated exposure.
  • Treat the operating wallet like a till and custody like a vault. Sweeps and draw downs should run off a written trigger, not a judgement call made each morning.
  • Fund the fee asset as deliberately as the USDC. A transfer needs the native asset of the chain to pay the network fee, and an empty fee wallet queues every payment behind it.
  • Reconcile three ways every day: the chain, the internal subledger and the general ledger. Store the transaction hash against the payment reference at the moment of confirmation.
  • An examiner follows one payment, not the policy. Who instructed it, what screening ran, who approved the release, which hash settled it, and where it sits in the ledger, all from one record.

A bank decides to settle some cross border payments in USDC. That decision takes a meeting. The work that follows takes a team. USDC treasury operations at a bank look nothing like holding a balance at a correspondent. There is no account statement and no cut off time. There is a wallet, a chain, a ledger and an auditor who will ask how the three agree. This article sets out the day to day detail: custody and key control, funding and sweeps, reconciliation, the controls a reviewer tests, and the month end close.

What does a bank actually own when it holds USDC?

Start with the asset, because the operating model follows from it. A payment stablecoin is a claim on a reserve held by a supervised issuer. It is not a deposit at the bank that holds it. It is not central bank money. The holder owns a token that the issuer has promised to redeem at par.

That promise rests on the reserve behind it. The GENIUS Act, enacted in the United States in 2025, requires a permitted payment stablecoin issuer to back each token at least one to one with cash and short dated Treasury instruments, and to publish the composition of those reserves each month. Circle publishes monthly reserve attestation reports for USDC, examined by an independent accounting firm. A treasury team should read those reports rather than assume them.

So the first question a bank faces is a credit question, not an operations question. The bank takes issuer risk, reserve risk and redemption risk. Those belong in the same framework that governs any other short dated exposure. The Basel Committee on Banking Supervision published its prudential standard for cryptoasset exposures in December 2022, and later deferred the implementation date to 1 January 2026. Know which treatment your supervisor expects before you fund a wallet.

Where should a bank custody USDC, and who can move it?

Three custody models are in common use. The bank can self custody, holding keys in hardware security modules under its own control. It can appoint a qualified custodian and hold an account there. Or it can use a regulated wallet provider that keeps keys in segregated infrastructure. Cost, control and recovery differ in each case. So does the evidence the bank can hand to a reviewer.

Permission to do this is now reasonably settled in the United States. The Office of the Comptroller of the Currency published Interpretive Letter 1183 in 2025, confirming that national banks may hold crypto assets in custody and may engage in certain stablecoin activities. Permission is not a control design. The bank still has to decide who initiates a transfer, who approves it, and how a key is recovered when a person leaves.

Four controls do most of the work in practice. Separate the officer who initiates a transfer from the officer who approves it. Require more than one key holder for any movement above a set size. Allowlist every destination address, and treat a new address as a change request rather than a payment detail. Test key recovery on a schedule, and write down the result.

What does a daily USDC funding and sweep cycle look like?

Treat the operating wallet like a till, not like a vault. It holds enough USDC to cover the day's expected settlement plus a buffer. Everything above that line sweeps to custody on a defined trigger. Everything below it draws down from custody, or from a purchase with the issuer. The trigger should be a written rule.

Network fees deserve their own small process. A transfer on a public blockchain needs the native asset of that chain to pay the fee. A treasury team that funds USDC but forgets the fee asset will find payments queued behind an empty fee wallet. Hold a small working balance of the fee asset on every chain in use, monitor it, and top it up on a rule.

A workable daily cycle for bank treasury operations runs in this order.

  • Confirm the opening position: on chain balances by wallet and by chain, custody balances, and the fee asset balance for each chain in use.
  • Pull the expected settlement pipeline for the day, and compare it against the operating wallet balance.
  • Fund or sweep once, against the written trigger, with the approval recorded before the transfer is signed.
  • Release settlements in batches, and record the transaction hash against the payment reference as each one confirms.
  • Reconcile on chain balances to the subledger at a fixed cut off, and log every break with an owner and a due date.
  • Return the operating wallet to its target balance, then leave the closing position and the open breaks in a handover note.

An operating wallet is a till, not a vault. The balance left in it overnight is a decision somebody made, and it should be a decision somebody can point to in writing.

How do you reconcile on chain USDC to the general ledger?

Reconciliation is where USDC treasury operations at a bank earn trust or lose it. Run it three ways. The chain holds the truth about balances and movements. The internal subledger holds the truth about which customer or payment each movement belongs to. The general ledger holds the accounting position. All three must agree at a fixed cut off every day.

The chain gives treasury a control that a correspondent statement cannot. Every movement has a transaction hash, a block and a timestamp that both parties can verify for themselves. Store the hash against the payment reference at the moment of confirmation. A reconciliation that starts from hashes is faster than one that starts from a statement, and it does not wait for a file to arrive.

The hash is not the whole record. It does not carry the purpose of the payment, the parties, the charges or the remittance information. ISO 20022 messages carry that. A pacs.008 describes the customer credit transfer, a pacs.009 the interbank leg, a pacs.002 the status and a pacs.004 a return. The UETR joins the message to the settlement, so one reference answers both the accounting question and the compliance question.

Then design for the breaks, because breaks are routine. Expect an inbound transfer with no matching instruction. Expect a payment sent on the wrong chain. Expect a partial amount, a duplicate, and small residual balances that never quite clear. Each needs a named owner, a standard treatment and a time limit. An ageing break log is the most useful artefact a treasury team can put in front of an auditor.

Which controls will an examiner or an auditor test?

Expect the review to follow the money rather than the policy. The reviewer picks one payment and asks what happened. Who instructed it. What screening ran, and when. Who approved the release. Which wallet paid, which hash settled it, and where that sits in the ledger. The answer should come from one record, not from four systems and a spreadsheet.

Screening belongs inside treasury operations here, not beside them. Sanctions and politically exposed person checks run before value moves. Address screening runs against the destination too, because a wallet address carries its own history. FATF Recommendation 16, the Travel Rule, requires originator and beneficiary information to travel with transfers above a threshold set at one thousand US dollars or euros, and it applies to virtual asset transfers as well as to wires.

Speed raises the stakes rather than lowering them. In targets published with the G20 in 2021, the Financial Stability Board set a goal that 75 percent of wholesale cross border payments should reach the beneficiary within one hour by the end of 2027. On chain settlement already sits inside that window. A control that depends on a review after settlement has nothing left to review.

How should the month end close and the audit work?

Month end has three parts. Value the position and agree it to the chain, with the balance evidence captured and dated. Gather the external evidence: the issuer's reserve attestation for the period, the custodian's control report, and the exception log. Document the judgements, particularly the accounting treatment applied to the token and the basis for it.

Talk to the auditor before the first close, not after it. Agree what counts as sufficient evidence of ownership of an on chain balance, and how it will be obtained at the reporting date. Agree how a break sitting open at the cut off is treated. Those two conversations remove most of the friction from a first year audit, and they cost an afternoon.

Where StableNet fits

StableNet, built by SpendTheBits, is a cross border B2B payment and settlement platform for banks, credit unions, licensed money service businesses, exchange houses and remittance fintechs. Settlement is in regulated stablecoins such as USDC and USDT on public blockchains, completing in minutes with on chain auditability, which is what makes a same day treasury cycle possible in the first place. The platform is ISO 20022 native, with pacs.008 customer credit transfers, pacs.009 interbank legs, pacs.002 status reports and pacs.004 returns inside head.001 envelopes, tracked end to end by UETR, so the settlement hash and the instruction stay joined under one reference for reconciliation. Compliance is built in, with KYB and KYC onboarding, KYT, sanctions and PEP screening, FATF Travel Rule data in IVMS101 form, a compliance workbench and a tamper evident audit trail. SpendTheBits is a Bank of Canada registered payment service provider and a named finalist in the Swift Hackathon 2026 Technical Challenge.

See it on your corridors

Book a working session and we’ll map StableNet’s compliance and settlement to one of your live payment flows.

FAQ

Common questions

Neither, strictly. A payment stablecoin is a claim on a reserve held by the issuer, redeemable at par. It is not a deposit at the bank holding it and it is not central bank money. The accounting treatment and the prudential treatment are separate questions, and both should be agreed with the auditor and the supervisor before a wallet is funded rather than at the first reporting date.