PRA Dear CEO Letter: Separate, Insolvency-Remote Stablecoin Issuance

On 18 May 2026 the Prudential Regulation Authority sent a Dear CEO letter to the chief executives of UK banks and designated investment firms, reaffirming where the line sits between a deposit and everything that only looks like one. The PRA Dear CEO letter on innovations in the use of deposits, e-money and stablecoins, signed by David Bailey, Charlotte Gerken and Rebecca Jackson, supersedes the equivalent 2023 letter and follows significant progress in digital-money innovation, including the development of stablecoin regimes and the use of tokenised deposits.

The message for product and prudential teams is specific. A deposit-taker can innovate inside the deposit wrapper, including by issuing tokenised deposits structured as transferable liabilities. If it wants to issue e-money or a qualifying stablecoin to retail customers, the PRA expects issuance from a separate, distinctly branded, non-deposit-taking and insolvency-remote entity. Almost everything else in the letter follows from that one structural expectation.

This is a supervisory expectation, not a new rulebook module, and it does not replace existing requirements for deposits, e-money or stablecoins. It tells you how the PRA will read your product design, your entity structure and your liquidity assumptions when you take a digital-money proposal to your supervisor. Reviewing plans against it now costs far less than unwinding a co-branded stablecoin after launch.

Related reading: the Bank of England’s systemic stablecoin rules for UK issuers

Key dates behind the PRA Dear CEO letter

It sets no new filing deadline, but the expectations sit on a timeline worth keeping in front of your project plan:

  • November 2023: the original PRA Dear CEO letter setting out expectations for deposit-takers innovating in deposits, e-money and regulated stablecoins.
  • 4 February 2026: The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 (SI 2026/102) made, creating the UK perimeter for regulated cryptoasset activity and defining “qualifying stablecoins”. Most provisions commence later, with full commencement set for 25 October 2027.
  • 18 May 2026: this letter published, superseding the 2023 letter; the companion Dear CEO letter on the prudential treatment of tokenised assets, stablecoins and other cryptoasset exposures published the same day.
  • 1 January 2027: UK CRR market-risk provisions transfer into the PRA Rulebook, relevant to the capital treatment of unbacked cryptoassets covered by the companion letter.
  • 2028 at the earliest: when the PRA expects to consult on its future prudential framework for cryptoasset exposures, following the Basel Committee’s targeted review.

Why the PRA reissued its 2023 position

The core risks the PRA identified in 2023 have not changed. What changed is the surrounding market and the legal machinery around it. Since the first letter, the UK has enacted the statutory perimeter for qualifying-stablecoin and other cryptoasset activities. Under SI 2026/102, relevant FSMA cryptoasset permissions will be required from 25 October 2027 (the instrument’s full commencement day); stablecoin regimes have continued to develop internationally, and the use of tokenised deposits has progressed. The February 2026 secondary legislation is the anchor: the letter uses “stablecoins” to mean the “qualifying stablecoins” defined in that instrument.

So the PRA gave itself two jobs in this letter. The first is to restate the broad expectations from 2023, which remain in force. The second is to add detail on how those expectations should be read given everything that has happened since. The overall expectations remain the same; the letter adds detail on how firms should interpret distinct branding and insolvency-remoteness in practice.

One point is easy to miss. The letter is meant to be read alongside the PRA’s companion 18 May 2026 letter on the prudential treatment of tokenised assets, stablecoins and other cryptoasset exposures. The deposits letter sets supervisory expectations for deposit-takers’ customer-facing innovations in deposits, e-money and stablecoins; the companion letter sets interim expectations for the prudential treatment and risk management of cryptoasset exposures. A single tokenisation project may engage both letters, so firms should assess the customer-facing product structure and the prudential treatment of any resulting cryptoasset exposures together.

The contagion risk the branding rule is built to stop

The letter is aimed at a specific behavioural risk in a retail setting. Eligible deposits at protected firms are covered by the FSCS, subject to the scheme’s eligibility rules and compensation limits. E-money and stablecoins are not themselves protected as deposits under the FSCS. The PRA’s concern is that if a deposit-taker issued e-money or a stablecoin under the same brand as its deposits, trouble in the unprotected product could bleed into confidence in the protected one, and the reverse. Retail customers act on trust and brand recognition, and should not need to parse legal distinctions to know which of their balances is covered.

Here is the part that catches teams out: FSCS coverage does not, on its own, neutralise this risk. A run driven by loss of confidence can happen even when it is not warranted by the actual protection available. The PRA points to the speed of the March 2023 banking turmoil as evidence that confidence contagion moves fast and is very hard to reverse once it starts, all the more so now that information spreads in minutes. The branding expectation exists to keep that contagion from having an easy path.

Scope matters when you apply this. In the letter, “retail customers” means natural persons and micro, small and medium-sized enterprises. For stablecoin use cases limited exclusively to wholesale customers, the PRA says confidence risks are less prevalent and supervisors should assess proposals proportionately; it does not state that the separate-entity, distinct-branding or insolvency-remoteness expectations are disapplied.

Deposits can innovate; e-money and stablecoins move out of the bank

The structural expectation is straightforward once you separate the two product families. Within its deposit-taking entity, a bank may innovate in the form of deposits. That expressly includes tokenised deposits, meaning deposit claims represented on programmable ledgers that support techniques such as atomic settlement and smart contracts, including claims structured as transferable liabilities. The PRA remains open to exploring where regulatory barriers to those models exist.

Where a deposit-taker wants to issue a stablecoin or e-money to retail customers, the letter expects that to be done from a non-deposit-taking, insolvency-remote entity with branding distinct from the deposit-taker. The summary in Annex 2 puts the outcome plainly: deposit-taking entities should only provide innovations in money to retail customers in the form of deposits.

Two misreadings are worth heading off. First, for retail issuance the letter expects e-money and stablecoins to be issued from a separate non-deposit-taking, distinctly branded and insolvency-remote entity; it does not prescribe a particular intra-group ownership structure. Second, a tokenised deposit remains a deposit claim on the bank, held inside the deposit-taking entity, and the PRA expects it to meet the FSCS depositor-protection rules and the associated operational requirements. Treating a tokenised deposit as if it were a stablecoin collapses the distinction the letter works to preserve.

There is a transition rule for firms coming the other way. Where a firm without a deposit-taking permission has already issued e-money or regulated stablecoins to retail customers and then seeks a deposit-taking permission for that issuing entity, the PRA expects the firm to transition its UK retail customers from e-money or regulated stablecoins to deposits at the new deposit-taking entity as soon as practicable; the letter does not state that every non-UK or wholesale balance must be converted.

How supervisors will read your customer experience

The 2023 letter set the outcome; this one explains how the PRA will judge whether you have met it. Where a banking group issues e-money or stablecoins, supervisors will look at the overall customer experience to decide whether the product is suitably differentiated from retail deposits. That assessment takes in the naming, the branding, the access arrangements and the information given to customers. Firms that bring worked examples of how a product will be differentiated will find those conversations with supervisors easier.

The letter gives firms room on method while holding the outcome firm. Two things should be true. The name and presentation of the e-money or stablecoin product should establish that it is clearly different from a deposit product. That could mean a reference to the parent brand, such as “by XYZ”, a different visual treatment, or placement in a different part of the website or app. Alongside that, customers should get clear, prominent and ongoing information about the different protections that apply, consistent with existing requirements.

The trap sits in over-relying on the second point. Disclosures, warnings, on-boarding screens and customer education matter, but the PRA is explicit that they should not be the sole means of managing the confusion risk. A product design that relies on disclosures, warnings, on-boarding or customer education as the sole means of mitigating confusion would not meet the PRA’s stated expectation; the product’s name and presentation must also establish clear differentiation from deposits.

Insolvency-remote issuance and the GENIUS Act parallel

The second structural expectation is that e-money and stablecoins are issued from a separate, non-deposit-taking, insolvency-remote entity. The PRA draws an explicit parallel with the requirements for US stablecoins under the GENIUS Act, the US federal law that established a framework for stablecoins. The outcome the PRA wants is that stress or failure at the issuing entity would not damage the wider deposit-taking group or interrupt the continuity of deposit-taking services.

Firms are expected to design for that outcome from the outset. The letter does allow a proportionate transitional period where legal and operational arrangements are still being put in place, but only if the firm can show a credible and timely plan to reach insolvency-remoteness. In other words, a transition runway exists, but only against a plan the supervisor can test.

For international deposit-takers operating in the UK through branches, the letter is firm that the risk of contagion does not scale with the size of the operation. Because FSCS protection extends to deposits in branches of international banks, these firms are expected to follow the same approach as domestic deposit-takers for their UK operations, read together with the PRA’s expectations for international banks in SS5/21.

Wholesale-only stablecoins receive proportionate supervisory assessment

The 2023 letter focused primarily on retail risk. For stablecoin use cases limited exclusively to wholesale customers, the PRA considers confidence risks less prevalent than for individual retail customers and expects early engagement so supervisors can assess the proposal proportionately. The letter does not expressly disapply the separate-entity, distinct-branding or insolvency-remoteness expectations.

Firms weighing a wholesale-only stablecoin are expected to engage supervisors early, before the design hardens. In that engagement, be ready to set out how access will be restricted to wholesale users, how the associated risks will be managed, and which stablecoin regulatory regime would apply to the product. Firms should identify which stablecoin regulatory regime would apply to the proposal. The FCA published final rules and guidance for UK qualifying-stablecoin issuers on 30 June 2026. The Bank’s Code of Practice for systemic sterling-denominated stablecoin issuers remained in draft and was expected to be finalised by the end of 2026. Under SI 2026/102, relevant FSMA cryptoasset permissions will be required from 25 October 2027.

The June 2026 update to the DSS guidance expanded the range of acceptable settlement assets to include stablecoins that meet the minimum requirements. The PRA letter says the DSS may provide an appropriate environment for exploring wholesale stablecoin proposals; it does not make the DSS the required venue. Firms should still check how their model interacts with the FCA’s UK cryptoasset authorisation gateway before assuming a wholesale label removes them from a regime.

The prudential mechanics: liquidity, operational resilience and financial crime

Annex 3 is where the letter turns from product design to the prudential and reporting plumbing, and it is the part a reporting or risk function should read most closely. The framing throughout is that the existing framework is flexible and risk-sensitive, so it can stretch to cover these products, but firms may need to adjust their methodologies and calibrations to do so honestly.

On liquidity, the concern is that a new digital-money product may behave less stably than a traditional retail liability. The PRA expects deposit-takers to actively consider the right outflow rates for new types of retail liability when they calculate the Liquidity Coverage Ratio, taking account of the customer relationship, the nature of the liability and the remuneration rate compared with similar retail liabilities. Firms should also capture the liquidity risk of these liabilities in internal liquidity stress testing under the Internal Liquidity Adequacy Assessment requirements. Where an innovative product is delivered through third parties and grows to a material share of the balance sheet, the letter warns it can create a concentrated liquidity risk, echoing the earlier PRA and FCA work on deposit aggregators. Our guide to LCR, NSFR and ALMM liquidity reporting covers the mechanics those outflow assumptions feed.

On operational risk and resilience, the letter is candid that some of these products rely on new and relatively untested payment rails, and that limited historical data makes the operational risk hard to model. Deposit-takers are expected to develop reliable ways of identifying, measuring and mitigating those risks as a priority, and to have fully understood the impact on operational resilience, meeting the expectations in SS1/21 and SS2/21, before offering a product to customers in any material way. Third-party wallet providers and deposit aggregators, in part enabled by open banking, are called out specifically; the PRA expects them to be managed within the wider operational-resilience and SS2/21 outsourcing and third-party risk framework.

On financial crime, the letter reminds firms that money laundering and terrorist financing concerns feed the PRA’s prudential assessments. A deposit-taker moving into any form of digital money is expected to meet its obligations under the PRA’s General Organisational Requirements to identify, manage, monitor and report ML/TF risks, and, consistent with Fundamental Rule 1 on integrity, to comply with the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 and the FCA’s SYSC provisions. The letter also folds in the accountability angle: it expects deposit-takers to consider these challenges at a senior level, which lines up with senior managers’ responsibilities under the Senior Managers and Certification Regime.

Read it with the cryptoasset-exposures letter, not instead of it

The companion letter published the same day replaces the PRA’s 2022 expectations on cryptoasset exposures and runs on a different axis. Where the deposits letter is about customer-facing money, the companion letter is about how a bank capitalises its own crypto exposures. It keeps the expectation that a 100% capital requirement remains appropriate for unbacked cryptoassets under the market-risk framework, and notes that directly held cryptoassets classified as intangibles are deducted from Common Equity Tier 1 under the Own Funds part of the PRA Rulebook.

Its most useful signal for tokenisation projects is the “same risk, same regulatory outcome” position. Tokenised traditional assets would generally receive the same prudential treatment as their non-tokenised equivalents where the legal rights are identical and the underlying risks are comparable, with the type of ledger, permissioned or permissionless, treated as secondary to the risk. That principle is what would let a digital gilt issued in the Digital Securities Sandbox be treated in line with a conventional government bond. It does not mean tokenisation automatically lowers a capital charge; the risk has to genuinely match. The companion letter also flags that these expectations are interim, with a consultation on the future framework expected in 2028 at the earliest. Our note on the PRA’s cryptoasset capital expectations works through that treatment in detail.

What the letter asks you to do next

The operative obligation at the end is disclosure. Fundamental Rule 7 requires deposit-takers to deal with regulators openly and to disclose anything the PRA would reasonably expect notice of. The letter turns that into a standing expectation to keep supervisors informed of material developments in any plans for digital money, and to show how those plans meet the expectations in this letter and the 2023 one. The PRA says it will keep monitoring and will work with other UK authorities as the stablecoin and digital-money framework develops.

Frequently Asked Questions

Does the PRA Dear CEO letter ban banks from issuing stablecoins?

No. It reaffirms that a deposit-taker should not issue stablecoins or e-money to retail customers from within the bank itself. The route the letter expects is issuance from a separate, non-deposit-taking, insolvency-remote entity with branding distinct from the deposit-taker. The bank can be in the stablecoin business; the deposit-taking legal entity should not be the issuer.

Is a tokenised deposit treated as a stablecoin under the letter?

No, and keeping them apart is the point. A tokenised deposit is a deposit claim on the issuing bank, represented on a programmable ledger and potentially structured as a transferable liability. It stays inside the deposit-taking entity and must meet the FSCS depositor-protection rules and associated operational requirements. A qualifying stablecoin is a cryptoasset under the February 2026 regulations and is expected to sit in the separate issuing entity.

What does “insolvency-remote” mean in practice here?

The letter defines it by outcome rather than a single legal test: stress or failure of the issuing entity should not have adverse impacts on the wider deposit-taking group or on the continuity of deposit-taking services. Firms are expected to design for that from the outset, though supervisors will consider a proportionate transitional period where a firm can demonstrate a credible and timely plan to get there.

How will supervisors judge whether branding is “distinct” enough?

By looking at the overall customer experience, not a single label. That includes the product name and presentation, the visual treatment, access arrangements and the information customers receive. Acceptable approaches can include a “by XYZ” parent-brand reference or placing the product in a different part of the app. Disclosures and warnings support the outcome but are not accepted as the only means of preventing confusion.

Do these expectations apply to wholesale-only stablecoins?

For stablecoin use cases limited exclusively to wholesale customers, the PRA considers confidence risks less prevalent than for individual retail customers and expects early supervisory engagement on access restrictions, risk management and the applicable regime. The letter does not expressly disapply the separate-entity, distinct-branding or insolvency-remoteness expectations. The June 2026 update to the DSS guidance expanded the range of acceptable settlement assets to include stablecoins that meet the minimum requirements. For the current process and conditions, consult the Bank of England’s Guidance on the Operation of the Digital Securities Sandbox.

What does the letter change for liquidity and prudential reporting?

It creates no new return. Deposit-takers are expected to consider the appropriate outflow rates for novel retail liabilities when calculating the Liquidity Coverage Ratio and to capture their risks through internal liquidity stress testing under the ILAAP. Adjustments should follow the product-specific assessment; the letter does not require an automatic change to every existing LCR assumption. Third-party delivery may create concentrated liquidity risk where the product represents a significant portion of the balance sheet. Operational-resilience expectations under SS1/21 and SS2/21 should be met before the product is offered to customers in any material way.

How do international banks with UK branches fit in?

The same way as domestic deposit-takers for their UK operations. Because FSCS protection reaches deposits in UK branches of international banks, the letter expects those firms to apply the same approach, read together with the PRA’s SS5/21 expectations for international banks. The PRA is explicit that contagion risk does not depend on the scale of the UK operation.

Key Takeaways

  • The PRA Dear CEO letter of 18 May 2026 supersedes the 2023 letter and reaffirms, with added detail, how deposit-takers should innovate in deposits, e-money and regulated stablecoins.
  • Deposit-takers may innovate inside the deposit wrapper, including tokenised deposits structured as transferable liabilities, which stay in the deposit-taking entity and must meet FSCS depositor-protection rules.
  • E-money and stablecoins issued to retail customers should come from a separate, non-deposit-taking, insolvency-remote entity with branding distinct from the bank.
  • Supervisors will assess the overall customer experience (naming, branding, access, information) and will not accept disclosures alone as the means of preventing confusion.
  • For stablecoin proposals limited exclusively to wholesale use, firms should engage supervisors early and be prepared to explain access restrictions, risk management and the applicable regime; the PRA says the Digital Securities Sandbox may provide an appropriate environment for exploring such proposals.
  • Annex 3 expects firms to consider appropriate LCR outflow rates, capture the risks through internal liquidity stress testing under the ILAAP, meet SS1/21 and SS2/21 operational-resilience expectations, and maintain ML/TF controls under the General Organisational Requirements and MLR 2017.
  • The letter must be read alongside the companion 18 May 2026 cryptoasset-exposures letter, which keeps a 100% capital treatment for unbacked cryptoassets and applies a “same risk, same regulatory outcome” test to tokenised traditional assets.
  • Fundamental Rule 7 requires firms to keep supervisors informed of material digital-money plans and how they meet these expectations.

Sources and References

  • Bank of England / PRA, Dear CEO letter, “Reaffirming the PRA’s position and clarifying expectations on innovations in the use of deposits, e-money and stablecoins” (18 May 2026): landing page and letter (PDF).
  • Bank of England / PRA, Dear CEO letter, “Prudential treatment of tokenised assets, stablecoins, and other cryptoasset exposures” (18 May 2026): letter (PDF).
  • PRA, 2023 Dear CEO letter, “Innovations in the use of deposits, e-money and regulated stablecoins” (November 2023): letter (PDF).
  • The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 (SI 2026/102), made 4 February 2026: legislation.gov.uk.
  • The Financial Services and Markets Act 2000 (Regulated Activities) Order 2001 (SI 2001/544), Article 5 (definition of a deposit): legislation.gov.uk.
  • The Electronic Money Regulations 2011 (SI 2011/99): legislation.gov.uk.
  • Bank of England, “Guidance on the operation of the Digital Securities Sandbox” (June 2026 update): bankofengland.co.uk.

What to put in front of your supervisor first

If you take one action from this letter, make it a structural review before a marketing review. For retail products, confirm that planned stablecoin or e-money issuance is from a separate non-deposit-taking, distinctly branded and insolvency-remote entity, and document any credible and timely transition plan needed to achieve insolvency-remoteness. For wholesale-only stablecoin proposals, engage the PRA early and document the proposed access restrictions, risk management and applicable regulatory regime. Then check the softer edges: whether the customer experience genuinely differentiates the product, whether your LCR outflow assumptions and ILAAP stress tests reflect a liability that may not behave like a normal deposit, and whether your ML/TF and operational-resilience controls are ready. The PRA has told you how it will read the file. Bringing it a worked example, rather than a finished product, is the difference the letter is inviting.

Last updated: July 2026

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts