SACF-06 — Governance & Control: who can authorize, move or restrict the company’s stablecoins?
Updated: Aug 29
RESEARCH & INTELLIGENCE • SACF 2026
BECTRA SACF — Stablecoin Accounting & Control Framework • Pillar 6 of 7 • Governance & Control
01 Classification → 02 Purpose & Exposure → 03 Accounting & Measurement → 04 Ownership & Evidence → 05 Counterparty & Infrastructure → 06 Governance & Control → 07 Reconciliation & Reporting
Who can decide, access and act on the company's stablecoins?
SACF CONNECTION — Governance of access and authority directly supports the evidence of control and ownership over corporate stablecoin positions. SACF-04 explores this point in greater detail.
SACF CONNECTION — Controls only have value if they leave usable evidence. Reconciliation and reporting should demonstrate that the controls were actually performed. SACF-07 explores this point in greater detail.
Holding stablecoins creates new operational powers: authorising a payment, signing a transaction, changing a whitelist, adding an address, changing a signer, modifying a configuration or triggering an emergency procedure. Those powers should be identified and controlled like any other sensitive corporate entitlement.
SACF PRINCIPLE — A control only exists if it is assigned, performed, evidenced and reviewed.
1. Formalise the stablecoin policy
The policy should specify authorised stablecoins, permitted uses, relevant legal entities, providers, networks, limits, approval rules, authorised addresses, emergency procedures and review responsibilities.
2. Define roles and powers
At a minimum, distinguish who may initiate, approve, sign, administer rights, modify whitelists, configure limits, reconcile positions and record transactions. Delegations should be explicit and limited.
SACF RULE — No material movement should be initiable, authorisable and executable by one person without a documented compensating control.
3. Control access and administrative rights
Administrator accounts, wallets, MPC consoles, custody platforms and related tools should be subject to formal access management, including MFA where appropriate, entitlement review, change logging and prompt revocation when staff leave or change roles.
4. Govern thresholds, approvals and new addresses
Approval thresholds should reflect risk. Adding a new address, beneficiary or network should be treated as a sensitive change requiring independent verification, approval, possible delay and logging.
5. Control configuration changes
Changes to signers, MPC policy, administrator roles, limits, authorised smart contracts or providers should follow a documented and reviewed change process. Risk often arises less from the transaction itself than from an earlier change to the rules that allow it.
6. Define emergency powers
Emergency procedures should state who can suspend operations, disable internal access, move funds to a backup wallet, contact the provider or trigger a continuity plan. These powers should be limited, evidenced and reviewed after use.
7. Review the framework periodically
Governance should include periodic review of access, delegations, limits, incidents, exceptions and controls actually performed. The objective is not merely to have a policy, but to prove that the framework operates over time.
SACF CONNECTION — SACF-05 identifies the dependencies to manage. SACF-06 assigns powers and controls. SACF-07 then provides evidence that preparation, approval and review controls were actually performed.
Sources
Continue through the BECTRA SACF framework
To extend this analysis, the following pillars are the most directly connected to the issues addressed in this article.




Comments