Comment from XSOC CORP

XSOC CORPSupportBusiness
Summary: XSOC CORP, a pre-commercial technology provider developing transaction authorization and compliance infrastructure, supports the proposed rule's objectives and its technology-neutral approach. The company argues that the final rule should explicitly recognize proactive, cryptographic pre-authorization enforcement as a valid method for meeting technical capability requirements, alongside traditional reactive controls. They also advocate for an outcome-based effectiveness standard, recognition of cryptographic records as compliance evidence, and the inclusion of post-quantum cryptographic migration requirements.
XSOC CORP respectfully submits the attached comment letter in response to the joint NPRM issued by FinCEN and OFAC implementing the AML/CFT and sanctions compliance provisions of the GENIUS Act. 91 Fed. Reg. 18582 (Apr. 10, 2026). XSOC submits seven comments: 1. The final rule should confirm that the § 1033.240 technical capability requirement encompasses both reactive post-transaction controls and proactive pre-authorization cryptographic enforcement, evaluated by outcome rather than mechanism. 2. The final rule should adopt a five-factor effectiveness standard — coverage, reliability, speed, evidence quality, and testability — for evaluating § 1033.240 technical capability. 3. Cryptographically generated, tamper-evident authorization records should be confirmed as satisfying AML/CFT program documentation requirements. 4. The secondary market technical capability standard should be bounded by actual PPSI control, with a response standard of as soon as technically practicable, not to exceed 24 hours, for blocklisting following an OFAC designation or lawful order, running from actual or constructive notice to the PPSI. 5. FinCEN and OFAC should issue examination guidance recognizing deployment of qualifying cryptographic authorization systems as strong evidence of § 1033.240 compliance. 6. The final rule should require PPSIs to maintain a cryptographic algorithm inventory and written quantum-safe migration roadmap, updated annually. 7. Good-faith pre-effective-date deployment of qualifying controls should receive favorable supervisory recognition, including as evidence of senior management commitment under the OFAC five-pillar framework. The full comment letter, including technical background and supporting citations, is provided in the attached PDF.

View on Regulations.gov