## Distributed Ledger Technology Experiments in Payments and Settlements (ftnea2020001)

## Source details

**Canonical URL:** [Distributed Ledger Technology Experiments in Payments and Settlements (ftnea2020001)](https://www.imf.org/-/media/files/publications/ftn063/2020/english/ftnea2020001.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/ftn063/2020/english/ftnea2020001.pdf.md)
- [Structured JSON version](/-/media/files/publications/ftn063/2020/english/ftnea2020001.pdf.json)

---

### Overview and purpose
- Takes stock of DLT experiments and research in payments and settlement systems, describing DLT protocols, summarizing experiments and research projects, discussing emerging risk management issues, implications for international standards, and potential implications for the international monetary system.
- Aim: provide a balanced view with considerations for practical implementation and probable long-term applications and benefits for payment system developments.
- Retail payment applications are out of scope; Annex I lists the experiments and research projects (stock-taking based on public information).

### High-level findings from experiments and research
- DLT has triggered innovations, experiments, research, and analysis of policy issues with potential implications for international standards for financial infrastructures to ensure safety and efficiency.
- Experiments point to potential moves toward real-time settlement, flatter structures, continuous operations (24/7/365), and global reach in financial infrastructures.
- Projects partly demonstrated technical feasibility of DLT for large-value payments and securities settlement systems while analyzing operational capacity, resiliency, liquidity savings, settlement finality, and privacy.
- DLT-based solutions can facilitate delivery versus payment of securities, payment versus payment of foreign exchange transactions, and efficient cross-border payments.
- Key implementation caveats from reviewed projects:
  - Most experiments were conducted under controlled and technology-focused environments.
  - All reviewed projects concluded DLT is, at least to some extent, feasible as the basis for a large-value payment system (LVPS) infrastructure; some views warned about immaturity and lack of interoperability.
  - Very few projects explicitly and rigorously assessed risks against international standards for large-value payments and securities settlement systems.
  - Almost none of the projects involved a cost-benefit analysis; no conclusions could be reached on whether DLT-based or improved legacy systems would be the more efficient alternative.
  - Liquidity, credit, transaction delay, settlement finality, counterparty, and operational risks could change in varying degrees in a new environment.

### Distributed ledger technology characteristics highlighted
- DLT enables transactions without necessarily relying on a central authority to maintain a single ledger; networks can be open or permissioned.
- Validation protocol: how transactions are validated and included; main objectives are to prevent double spending and reconcile distributed parts of the ledger.
- Main protocol differences:
  - Construction of the consensus mechanism (how validation is done and by what kind of validators).
  - Transparency of the transaction history, which affects auditability.
- Early setups: token-based for maintaining accounts of funds; later generations: smart contracts and registers for different asset representations.
- All central bank–led proof-of-concept tests indicate only permissioned DLT networks are suitable for financial market infrastructures (FMIs), considering compliance and regulatory requirements.
- Protocols differ in features; ongoing projects seek continuous improvement; additional research needed to establish a stable and sustainable protocol.

### Findings for large-value payment systems (LVPS)
- Prototypes confirmed feasibility of using DLT as a transaction booking method.
- Bitcoin-type proof-of-work designs and completely transparent transaction databases were deemed unsuitable for large-value payments due to processing capacity needs and lack of privacy.
- Prototypes used consensus protocols with less processing resource needs and more privacy, requiring more trust in validator nodes (acceptable in systems maintained by central banks or trusted authorities).
- Prototypes insufficiently focused on production operational criteria (throughput, reliability, resiliency); thus insufficient proof for production feasibility.
- Almost all prototypes were stand-alone add-on payment processing layers upon or in parallel with existing LVPS.
- Real-time interfaces with central banks’ or financial institutions’ internal payment systems were not tested except for one prototype (in Singapore) which had a direct operation link with the current RTGS system.
- Definition note: Throughput refers to intraday deadlines by which banks need to send a proportion of the value of their day’s payments to a payment system.

### Securities settlement findings
- DLT prototypes demonstrated viability for post-trade securities processing; projects concluded securities settlement is a highly suitable environment for DLT-based solutions.
- One project in Australia aimed for production implementation in 2021.
- Some prototypes focused on delivery-versus-payment (DvP) implementation and concluded that DvP with finality is achievable within DLT-based systems.
- DvP models can vary considerably; customization can improve efficiency/security in specific markets, but interoperability and common elements/standards across settlement systems and markets will be important.
- No conclusive analysis identified the most suitable DvP transaction dialogues for production environments; prototypes generally assumed existing market structures operating in similar roles.
- Prototype DvP approaches included:
  - Consensus-node asset-blocking methods to ensure DvP before ledger addition.
  - Specialized DvP controlling nodes.
  - Splitting transactions into incremental sub-DvP transactions to reduce principal settlement risk.

### Cross-border payments: experiments and observations
- Central banks currently provide settlement services only for domestic participants; correspondent banking (nostro accounts) enabled cross-border settlements.
- Permissioned DLT networks that restrict cross-border participation may not change reliance on correspondent banking.
- Key technical challenge: lack of a common settlement platform and network providing global reach for efficient interbank cross-border settlement of large-value payments.
- Central bank experiments:
  - Bank of Canada (BOC) and Monetary Authority of Singapore (MAS) linked experimental domestic payment networks to enable cross-border and cross-currency payments using central bank digital currency (CBDC); experiment connected two different DLT platforms and facilitated payment-versus-payment (PvP) settlement without a trusted third party.
  - BOC, MAS, and Bank of England (BOE) explored alternative models including enhancing domestic interbank systems with current technology up to using wholesale CBDC; identified need for a more fundamental paradigm shift and holistic view.
  - Wholesale digital token design requires clarity on the nature of claims, legal underpinnings, and institutional and risk management.
- Industry initiatives noted (descriptions preserved in source): CLSNet (2018 DLT-based bilateral netting service), SWIFT GPI research, JPM Coin, Utility Settlement Coin (USC), and others.
- Potential market effects: international banks could establish cross-border payment facilities through innovation and collaboration, affecting domestic RTGS volumes via a cross-border settlement engine processing domestic transactions; benefits include more efficient liquidity pooling and longer operational hours.
- Policy recommendation: a common and coordinated strategy involving the financial sector, central banks, and other authorities could rapidly achieve benefits of advanced payment technology and DLT while mitigating risks and costs from uncoordinated developments.

### Risk management issues and detailed considerations
- Advanced technologies can alter liquidity, credit, transaction delay, settlement finality, counterparty, and operational risks; securities markets may see the largest changes.
- Liquidity risks:
  - Real-time immediate settlement could increase liquidity needs but does not necessarily require liquidity higher than currently available; historical transaction patterns and simulation models can forecast normal-day needs.
  - Real-time availability: continuous 24/7/365 flow of liquidity without end-of-day breaks.
  - Central banks would need to update liquidity provision policies to function globally without day breaks and with automated solutions for globally sufficient liquidity supply.
  - Moving to immediate settlement of securities trading could affect trading conventions and liquidity needs (most securities settlement systems operate on T+2 or T+3 basis).
  - Flatter structures: each participant overseeing its own liquidity could reduce dependence on large clearing banks.
  - Global connections: interoperable global DLT-based systems could pool available liquidity into a common fund, potentially reducing liquidity needs.
- Credit risks:
  - Traditional credit risk management may conflict with DLT’s bilateral settlement nature; credit risk and liquidity needs are interlinked.
  - Bilateral real-time imbalances could require continuously operating intermediaries and collateral, conflicting with DLT bilateral principles.
  - Efficient real-time solution: liquidity-based settlements where each participant ensures sufficient liquidity (central bank money or automated short-term liquidity markets priced by credit risks and costs).
- Delayed transactions and LSMs:
  - RTGS uses Liquidity Saving Mechanisms (LSMs) with transaction queuing and (partial/complete) netting; a pure bilateral real-time DLT system may only allow internal queuing.
  - Introducing LSMs in real-time DLT systems could require a centralized layer for queued payments and liquidity holdings; acceptance may be difficult due to risks of random delays.
- Settlement finality:
  - In DLT systems, transactions are updated immediately on relevant accounts; corrections are made via new transactions—overall ledger is additive.
  - Settlement finality can be defined when a specific transaction is booked on both the correct sending and receiving account within a few seconds.
  - In a real-time end-to-end system, absence of settlement windows could generate Herstatt-type settlement risk.
  - For permissioned DLT, most node validators or a specific higher-rights node could fork the chain from a previous block, reversing transactions.
- Counterparty and operational risks:
  - DLT could produce global, flat systems with larger numbers of counterparties and higher shares of cross-border transactions; liabilities and requirements on counterparties must be clear and similar across the network.
  - Enforcing settlement in central bank money (or comparable low-risk assets) can reduce counterparty risks; strict rules needed on payment initiation and handling of fraudulent/criminal transactions.
  - Operational and cyber incidents could rapidly affect many transactions in real time, requiring very fast and highly automated error-handling and improved monitoring systems.
  - In Bitcoin-type DLT, lost funds cannot be recreated; in LVPSs and securities settlement systems, ability to recreate funds of lost nodes may be important for major operational events.
  - Recovery time objectives: resumption of operations within two hours after disruptive events is highlighted as an objective requiring robust planning.

### Implications for market structure, trading, and stability
- Real-time DLT systems could accelerate bank runs; critical banks could lose available liquidity rapidly.
- Real-time monitoring (for example, artificial intelligence) could detect and stop bank-run situations in early phases.
- DLT could reduce or eliminate naked short selling and buying risks by enabling immediate, automatic settlement on trader/investor accounts.
- High-frequency trading strategies based on sending and canceling many orders would be constrained because trades would be immediately settled with finality and cannot be canceled (assets can be retraded after settlement).
- For Delivery-versus-Delivery (DvD) and DvP transactions, counterparties and clearing participants must ensure immediate availability of corresponding assets and settlement funds (for example, central bank money) and improve liquidity forecasts and reserves.

### FMI standards, oversight, and interoperability
- The IOSCO Principles for Financial Market Infrastructures (PFMI) are the international standard for assessing efficiency and risks in payment and settlement systems; principles are technology neutral.
- DLT developments are being included in FMI assessments in IMF-World Bank financial sector assessment programs (Australia, Canada, Singapore, Switzerland).
- Early experiments suggest new interpretations of PFMI could be necessary, particularly with bilateral settlements; clarity on which DLT-type structures are covered by PFMI could be helpful.
- DLT systems may feature different risk liability programs because organizational setups may differ from centralized settlement systems (for example, token-based systems may have no settlement accounts on balance sheets; transactions booked in one ledger distributed across the network).
- Centralized operational services (certification authorities, transaction validation) could be separate legal entities and not considered FMIs.
- The CPMI analytical framework for DLT-based arrangements provides a basis to examine efficiency and safety implications and assists central banks and authorities in oversight and catalytic roles.
- Interoperability must be addressed to avoid fragmentation at two levels:
  - Interoperability of DLT systems with legacy infrastructures.
  - Interoperability between distributed ledgers across multiple counterparties.
- PFMI recommends internationally accepted communication procedures and standards; where such standards are not adopted, interoperability features should support translation or conversion between FMIs across jurisdictions.

### Research and testing recommendations (selected)
- Stakeholder consultations; review of system rules and market conventions; transaction reconciliation practices for synchronized distributed ledgers; analysis of the impact on continuous operations (24/7/365).
- More explicit and rigorous analysis of potential risks against international standards for financial market infrastructures and against the CPMI analytical framework for DLT introduction in payment, clearing, and settlement.
- Determine investment and operational costs and include them in a transparent cost-recovery pricing policy as part of any cost-benefit analysis before implementation.
- Address interoperability issues to avoid fragmentation risk; improve interoperability across different DLT implementations.
- Payments-specific recommendations:
  - Implement DLT-type solutions for reconciling and securing central bank and RTGS participants’ payment transfers using PKI-encrypted transactions and automated transaction-level reconciliation.
  - Design a liquidity saving mechanism (LSM) based on splitting DLT payment transactions to allow partial settlements using tokens in the correct priority order.
  - Analyze policy and operational changes needed for 24/7/365 operations with no need for end-of-day processing.
  - Assess benefits and risks of using a universal digital asset, or basket of assets, to settle payments across borders.
  - Perform cost and benefit analysis of different kinds of DLT implementations.
- Securities settlement research/testing considerations:
  - Analyze impact of true, real-time 24/7/365 processing on system design and conventions.
  - Consider structural changes toward flatter markets to maximize DLT benefits.
  - Conduct cost-benefit analysis of operational cost savings, security, and stability.

### Key questions, remaining uncertainties, and conclusion
- Key uncertainties:
  - When will technologies be mature enough to move from controlled experiments to implementation?
  - Can public policy objectives of safety and efficiency be fully observed if legacy infrastructures are replaced with DLT-based systems or if new entrants introduce innovative services?
  - What new interpretations may be needed under existing international standards?
  - What are the implications for regulation, supervision, and oversight as systems move toward greater real-time settlement, flatter structures, continuous operations, and global reach?
- Interaction with existing LVPS and systemic risk mitigation:
  - Until these questions are addressed and given the global adoption of RTGS systems that have helped mitigate systemic risks, it is not clear that DLT will gain broad traction as a basis for LVPS.

*Executive Summary vii; Box 1. The Evolving Payments System Landscape; Conclusion; Annex I; Annex II — Distributed Ledger Technology Experiments in Payments and Settlements (ftnea2020001).*

### Executive Summary vii

### Executive Summary vii

### Overview
- The last decade prompted many explorations into the use of distributed ledger technology (DLT) for payments and settlements.
- DLT has triggered innovations, experiments, research, and analysis of policy issues that could have implications for international standards for financial infrastructures to ensure safety and efficiency in the public’s interest.
- Experiments point to potential moves toward real-time settlement, flatter structures, continuous operations, and global reach in financial infrastructures.
- Projects have partly demonstrated technical feasibility of DLT for large-value payments and securities settlement systems while analyzing operational capacity, resiliency, liquidity savings, settlement finality, and privacy.
- DLT-based solutions can facilitate delivery versus payment of securities, payment versus payment of foreign exchange transactions, and efficient cross-border payments.
- Key issues requiring further attention:
  - Most experiments were conducted under controlled and technology-focused environments.
  - All reviewed projects concluded DLT is, at least to some extent, feasible as the basis for a large-value payment system (LVPS) infrastructure, but some views warned about immaturity and lack of interoperability.
  - Very few projects explicitly and rigorously assessed risks against international standards for large-value payments and securities settlement systems.
  - Almost none of the projects involved a cost-benefit analysis; no conclusions could be reached on whether DLT-based or improved legacy systems would be the more efficient alternative.
  - Liquidity, credit, transaction delay, settlement finality, counterparty, and operational risks could change in varying degrees in a new environment.
- Four priority areas identified:
  - Stakeholder consultations, review of system rules and market conventions, transaction reconciliation practices for synchronized distributed ledgers, and analysis of the impact on continuous operations (based on 24/7/365).
  - More explicit and rigorous analysis of potential risks against the international standards for financial market infrastructures and against the analytical framework for DLT introduction in payment, clearing, and settlement.
  - Determination of investment and operational costs and inclusion in a transparent cost-recovery pricing policy as part of any cost-benefit analysis before implementation.
  - Addressing interoperability issues to avoid fragmentation risk.

### Introduction
- Payments and settlements have evolved through generations:
  - First generation: paper-based, delivery times of several days domestically and weeks internationally.
  - Second generation: computerization with batch processing, manual or file-based interfaces; long changeover periods; some paper instruments like checks and cash remain in use.
  - Third generation (emerging): electronic and mobile payment programs enabling integrated, immediate, end-to-end payment and settlement transfers; RTGS systems available in almost all countries.
- DLT is viewed as a potential platform for the next generation of payment systems, enhancing integration and reconciliation of settlement accounts and their ledgers.
- Large-value interbank payment projects have been completed in Brazil, Canada, the Euro Area/Japan, Singapore, South Africa, and Thailand.
- Securities settlement projects have been investigated in Australia, Canada, the Euro Area/Japan, Germany, Singapore, and the United States.
- Central banks and the private sector have also analyzed DLT improvements for cross-border payments.
- Scope and purpose of the note:
  - Takes stock of DLT experiments and research in payments and settlement systems.
  - Describes DLT and its protocols, summarizes experiments and research projects, discusses emerging risk management issues, implications for international standards, and potential implications for the international monetary system.
  - Aims to provide a balanced view with considerations for practical implementation and probable long-term applications and benefits for payment system developments.
- Annex I includes a list of the experiments and research projects; the stock-taking exercise is based on public information availability. Retail payment applications are out of scope for this note.

### Distributed Ledger Technology
- DLT enables entities to carry out transactions without necessarily relying on a central authority to maintain a single ledger.
- DLT networks can be open or closed (permissioned) depending on participation policies.
- Various DLT protocols have been used in experiments in payments and securities settlement arrangements.
- A validation protocol defines how transactions are validated and included in the transaction history; the main objectives of the transaction history are to prevent double spending and reconcile distributed parts of the ledger.
- Main protocol differences:
  - Construction of the consensus mechanism (how validation is done and by what kind of validators).
  - Transparency of the transaction history, which affects auditability.
- Early DLT setups were token-based for maintaining accounts of funds; later generations enabled smart contract solutions and new applications for maintaining different kinds of distributed registers.
- Securities can be represented as asset accounts of tokens or registers of smart contracts transferring ownership titles.
- All proof-of-concept tests from central bank-led initiatives indicate only permissioned DLT networks are suitable for financial market infrastructures (FMIs), considering compliance and regulatory requirements (access, know your customer, and so on).
- Protocols have different features; ongoing projects seek continuous improvement protocols while additional research is needed to establish a stable and sustainable protocol.

### Experiments and Research
- Central banks (with oversight and operational responsibilities in payment and settlement systems) and industry participants have used experiments to test prototypes and analyze potential safety and efficiency implications.
- Large-value interbank payment projects and securities settlement investigations have been conducted across multiple jurisdictions (see Introduction for list of jurisdictions).
- The stock-taking is based on public information; Annex I lists experiments and research projects.

### Large-value Payment Systems (findings)
- Prototypes confirmed the feasibility of using DLT as a transaction booking method.
- Bitcoin-type proof-of-work designs and completely transparent transaction databases were deemed unsuitable for large-value payments because of processing capacity needs and lack of privacy.
- Prototypes used DLT consensus protocols with less processing resource needs and more privacy, requiring more trust in validator nodes (acceptable in systems maintained by central banks or trusted authorities).
- Prototypes insufficiently focused on production operational criteria, including throughput, reliability, and resiliency; thus could not be viewed as sufficient proof for production feasibility.
- Almost all prototypes were stand-alone add-on payment processing layers upon or in parallel with existing LVPS.
- Real-time interfaces with central banks’ or financial institutions’ internal payment systems were not tested except for one prototype (in Singapore), which had a direct operation link with the current RTGS system.
- Definition note: Throughput refers to intraday deadlines by which banks need to send a proportion of the value of their day’s payments to a payment system.

### Key Factors Driving the Evolution of the Payments System Landscape
- Rapidly rising information technology processing power and storage capacity at low investment cost (for example, through cloud computing), capacity to process big data sets, and real-time access to all systems and applications on a 24/7/365 basis, with immediate transaction-based processing; significant advances in artificial intelligence underpin these developments.
- Greatly increased communication capacity and connectivity at very low costs directly point-to-point within networks.
- Low-cost user-interface hardware and software platforms (for example, mobile phones, personal computers, tablets, and so on) for secure interfaces and for connecting to automated devices.
- Advances in application programming interfaces between different system components across service providers resulting in modular structures of large systems.
- Enhanced common processing platforms, operative systems, open source, freeware and shareware, free libraries of apps, and widely used complex financial software applications or external software services that will facilitate the rapid development of new payment features within all kinds of systems.
- Widespread use of encryption, digital identity, and e-signature services for safeguarding data and funds, recognizing business partners remotely and verifying transactions transferred over common and open telecommunication connections.

*Executive Summary vii, Distributed Ledger Technology Experiments in Payments and Settlements, Monetary and Capital Markets Department, International Monetary Fund | June 2020*

### Box 1. The Evolving Payments System Landscape

### Box 1. The Evolving Payments System Landscape

### DLT experiments in payments and settlements — key findings
- Prototypes used token-based central bank money (deposit receipts of the central bank) and were block-chained with several transactions in a block.
- System setups were comparable to current RTGS systems and fulfilled settlement finality requirements and credit risk limitations.
- Prototypes depended on prefunded liquidity imported to the system; liquidity savings and privacy were high-priority issues for central banks.
- Most experiments did not contain cost-benefit analyses.
- The European Central Bank and Bank of Japan reported higher levels of reliability and resiliency for DLT-based systems compared with traditional RTGS systems, without cost-benefit comparisons.
- Features often cited as DLT benefits (peer-to-peer communication, secured cryptography, smart contracts, immutability, real-time settlement) can also be implemented in traditional payment systems (for example, parallel transaction databases, parallel account balances secured by public key infrastructure (PKI) encryption, and multiple validators).

### Research and testing recommendations (payments)
- Implement DLT-type solutions for reconciling and securing central bank and RTGS participants’ payment transfers using PKI-encrypted transactions and automated transaction-level reconciliation.
- Design a liquidity saving mechanism (LSM) based on splitting DLT payment transactions to allow several partial settlements using readily available tokens in the correct priority order, enabling efficient use of even small token amounts.
- Analyze policy and operational changes needed for 24/7/365 operations with no need for end-of-day processing.
- Improve interoperability across different DLT implementations.
- Assess benefits and risks of using a universal digital asset, or basket of assets, to settle payments across borders.
- Perform cost and benefit analysis of different kinds of DLT implementations.

### Securities settlement systems — findings and recommendations
- DLT prototypes demonstrated viability for post-trade securities processing; projects concluded securities settlement is a highly suitable environment for DLT-based solutions.
- One project in Australia aimed for production implementation in 2021.
- Some prototypes focused on delivery-versus-payment (DvP) implementation and concluded that DvP with finality is achievable within DLT-based systems.
- DvP models can vary considerably; DLT solutions can be customized for improved efficiency and security in specific markets, but interoperability and common elements/standards across settlement systems and markets will be important.
- No conclusive analysis identified the most suitable DvP transaction dialogues for production environments; prototypes generally assumed existing market structures (exchanges, dealers, CCPs, CSDs, custodians, central banks) operating in similar roles.
- Prototypes tested options such as: (i) specific DvP dialogue and asset-blocking methods used by consensus node(s) to ensure DvP before ledger addition; (ii) specialized DvP controlling nodes; (iii) splitting transactions into incremental sub-DvP transactions to reduce principal settlement risk to subtransaction size.
- Research and testing could consider:
  - Impact of true, real-time 24/7/365 processing on system design and convention changes.
  - Structural changes toward flatter markets and processing conventions needed to maximize DLT benefits and efficient implementation paths.
  - Cost-benefit analysis of operational cost savings, security, and stability.

### Cross-border payments — experiments and observations
- Central banks currently provide settlement services only for domestic participants; correspondent banking (nostro accounts) developed to enable cross-border settlements.
- Permissioned DLT networks that restrict cross-border participation may not change reliance on correspondent banking.
- A key technical challenge: lack of a common settlement platform and network providing global reach for efficient interbank cross-border settlement of large-value payments.
- Central bank experiments:
  - Bank of Canada (BOC) and Monetary Authority of Singapore (MAS) linked experimental domestic payment networks to enable cross-border and cross-currency payments using central bank digital currency (CBDC); the experiment connected two different DLT platforms and facilitated payment-versus-payment (PvP) settlement without a trusted third party.
  - BOC, MAS, and Bank of England (BOE) explored alternative models including enhancing domestic interbank systems with current technology up to using wholesale CBDC; identified need for a more fundamental paradigm shift and holistic view.
  - Central banks emphasize that wholesale digital token design requires clarity on the nature of claims underlying assets or funds, legal underpinnings, and institutional and risk management.
- Industry initiatives:
  - CLSNet launched by CLS Bank International in 2018 as a DLT-based bilateral netting service for foreign exchange trades; associated payments processed separately via correspondent banking relationships.
  - SWIFT’s Global Payments Innovation (GPI) aims to improve speed, security, transparency; research ongoing to allow blockchain companies to connect to the GPI platform.
  - JPM Coin designed as a digital representation of a fiat currency for instantaneous payments between J.P. Morgan’s institutional clients (still under development).
  - Utility Settlement Coin (USC), managed by Fnality International, designed as a digital cash settlement asset backed by fiat held at the central bank for wholesale markets (still under development).
- Potential market effects:
  - International banks could establish cross-border payment facilities through new innovations and collaboration, affecting domestic RTGS volumes via a cross-border settlement engine processing domestic transactions.
  - Benefits include more efficient liquidity pooling and longer operational hours.
- Policy recommendation:
  - A common and coordinated strategy involving the financial sector, central banks, and other authorities could rapidly achieve benefits of advanced payment technology and DLT while mitigating risks and costs from uncoordinated developments.

### Risk management issues — overview
- Advanced technologies can alter liquidity, credit, transaction delay, settlement finality, counterparty, and operational risks, particularly due to global financial market interconnections.
- Payment and settlement systems may become multicurrency platforms handling different currencies and types of funds in parallel, with the securities trading market potentially experiencing the largest changes (including trading and short selling/buying conventions).

### Liquidity risks — findings and considerations
- Movement to real-time immediate settlement could increase liquidity needs but does not necessarily require liquidity higher than currently available; historic transaction patterns and simulation models can forecast normal-day needs.
- Issues implying major changes compared to the current environment:
  - Real-time availability: continuous 24/7/365 flow of liquidity without end-of-day breaks.
  - Liquidity needs: central banks would need to update liquidity provision policies to function globally without day breaks and with automated solutions for globally sufficient liquidity supply.
  - Moving to immediate settlement of securities trading could affect trading conventions and liquidity needs; most securities settlement systems operate on T+2 or T+3 basis.
  - Flatter structures: each participant could oversee its own liquidity requirements, making the overall system less dependent on individual large clearing banks.
  - Global connections: interoperable global DLT-based systems could pool available liquidity into a common fund, potentially reducing liquidity needs.

### Credit risks
- Traditional credit risk management may conflict with DLT’s bilateral settlement nature; credit risk and liquidity needs are interlinked.
- Bilateral real-time imbalances (some banks with sending surplus, others with receiving surplus) could require continuously operating intermediaries and collateral, conflicting with DLT bilateral settlement principles.
- A more efficient real-time solution: liquidity-based settlements where each participant ensures sufficient liquidity (potentially central bank money or automated short-term liquidity markets priced by credit risks and costs), reducing credit risks.

### Delayed transactions and LSMs
- RTGS uses LSMs with transaction queuing and partial/complete netting; in a pure bilateral real-time DLT system, senders can delay payments only by internal queuing.
- Introducing LSMs in real-time DLT systems could require a separate centralized layer for queued payments and liquidity holdings; acceptance may be difficult due to potential random delays affecting customer agreements.
- Netting-based liquidity mechanisms’ efficiency may depend on the possibility of queueing low-priority payments.

### Settlement finality
- In DLT systems, transactions are updated immediately on relevant accounts; corrections are made via new transactions—overall ledger is additive.
- Settlement finality can be defined when a specific transaction is booked on both the correct sending and receiving account within a few seconds.
- In a real-time end-to-end system, there is no settlement window, which could generate Herstatt-type settlement risk.
- All successfully booked transactions are final; old accepted blocks and transactions cannot be changed. For permissioned DLT, most node validators or a specific higher-rights node could fork the chain from a previous block, reversing transactions.

### Counterparty and operational risks
- DLT could produce global, flat systems with larger numbers of counterparties and higher shares of cross-border transactions; liabilities and requirements on counterparties must be clear and similar across the network.
- Enforcing settlement in central bank money (or comparable low-risk assets) can reduce counterparty risks; strict rules needed on payment initiation and handling of fraudulent/criminal transactions.
- Operational and cyber risk incidents could rapidly affect many transactions in real time, requiring very fast and highly automated error-handling and improved monitoring systems.
- In Bitcoin-type DLT applications, lost funds cannot be recreated; each node must safeguard its funds. In LVPSs and securities settlement systems, ability to recreate funds of lost nodes may be important for major operational risk events.
- Large-scale cyberattacks could compromise data confidentiality, service availability, and systems integrity, affecting settlement finality rules and recovery time objectives (which require resumption of operations within two hours after disruptive events).

### Stability, bank-run risk, and trading convention changes
- Real-time DLT systems could accelerate bank runs; critical banks could lose available liquidity rapidly. Real-time monitoring (e.g., artificial intelligence) could detect and stop bank-run situations in early phases.
- DLT could create an environment eliminating naked short selling and buying risks: with flat, real-time ledgers, trades could be immediately and automatically settled on investor/trader accounts, preventing naked short selling.
- Implications for trading practices:
  - High-frequency trading strategies based on sending and canceling many orders would be constrained because trades would be immediately settled with finality and cannot be canceled (though assets can be retraded after settlement).
  - For Delivery-versus-Delivery (DvD) transactions, trading partners must ensure corresponding assets are available for immediate settlement; the buyer could provide securitized monetary assets like central bank certificates as payment.
  - For DvP transactions, investors/traders must ensure funds in bank accounts, but clearing participants must ensure sufficient settlement funds (e.g., central bank money) for buy trades during peak periods and improve liquidity forecasts and reserves.

### Financial Market Infrastructure (FMI) standards and oversight
- The IOSCO Principles for Financial Market Infrastructures (PFMI) are the international standard for assessing efficiency and risks in payment and settlement systems; principles are technology neutral.
- DLT developments are being included in FMI assessments in IMF-World Bank financial sector assessment programs (Australia, Canada, Singapore, Switzerland).
- Early experiments suggest new interpretations of PFMI could be necessary, particularly with bilateral settlements; clarity on DLT-type structures covered by the PFMI could be helpful.
- DLT systems could feature different risk liability programs because organizational setups may differ from centralized settlement systems (e.g., FMIs in token-based systems may have no settlement accounts on balance sheets; transactions booked in one ledger distributed across the network).
- Centralized operational services (certification authorities, transaction validation) could be separate legal entities and not considered FMIs.
- The CPMI analytical framework for DLT-based arrangements provides a basis to examine efficiency and safety implications and assists central banks and authorities in oversight and catalytic roles.

### Potential impact on the international monetary system
- The international monetary system, which largely operates on universal financial messaging standards, could face DLT-related challenges.
- More than 200 market infrastructures use SWIFT and about 11,000 institutions across 200 countries and territories are connected to SWIFT.
- Interoperability issues must be addressed to avoid fragmentation at two levels: (i) interoperability of DLT systems with legacy infrastructures, and (ii) interoperability between distributed ledgers across multiple counterparties.
- PFMI recommends internationally accepted communication procedures and standards; where such standards are not adopted, interoperability features should support translation or conversion between FMIs across jurisdictions.

*Source: ftnea2020001 - Box 1. The Evolving Payments System Landscape*

### Conclusion

### Conclusion

### Key questions and remaining uncertainties
- When would such new technologies be mature enough to move from controlled experiments to implementation?
- Could the public policy objectives of safety and efficiency be fully observed with the replacement of legacy infrastructures with DLT-based systems or the introduction of innovative service offerings from new entrants in the market?
- What new interpretations may be needed under existing international standards?
- What are the implications for regulation, supervision, and oversight in a world that is moving toward greater real-time settlement, flatter structures, continuous operations, and global reach?

### Interaction with existing LVPS and systemic risk mitigation
- Until we begin to answer these questions and consider the adoption of RTGS systems in most countries around the world, which has helped mitigate systemic risks and safeguard financial stability, it is not clear that DLT will gain broad traction as a basis for LVPS.

### Annex I — List of DLT Experiments and Research in Payments and Settlements
- Large-value Payment Systems
  - Project Jasper (Phase 1) (Canada)
  - Project Jasper (Phase 2) (Canada)
  - Project Khokha (South Africa)
  - Project Stella (Phase 1) (Euro Area/Japan)
  - Project Ubin (Phase 1) (Singapore)
  - Project Ubin (Phase 2) (Singapore)
  - Project Inthanon (Phase 1) (Thailand)
  - Project Salt (Brazil)
- Securities Settlement Systems
  - Project Blockbaster (Germany)
  - Project by Depository Trust and Clearing Corporation (United States)
  - Project ASX replacement of CHESS (Australia)
  - Project Jasper (Phase 3) (Canada)
  - Project Stella (Phase 2) (Euro Area/Japan)
  - Project Ubin (Phase 3) (Singapore)
  - Project Inthanon (Phase 2) (Thailand)
- Cross-Border Payment Arrangements
  - CLSNet foreign exchange netting service (United States)
  - SWIFT DLT research (Belgium)
  - Utility Settlement Coin (Switzerland)
  - JPM Coin (United States)
  - Project Jasper (Phase 4)—Project Ubin (Phase 4) (Canada, Singapore)
  - Cross-border interbank settlements (Canada, United Kingdom, Singapore)
  - Project Stella (Phase 3) (Euro Area/Japan)
  - Project Inthanon (Phase 3)—LionRock (Thailand, Hong Kong)

### Annex II — Distributed Ledger Technology Protocols (selected descriptions)
- Bitcoin DLT protocol (2008)
  - First token-based DLT protocol; based on a “proof-of-work” protocol used by “miners.”
  - Anonymous or pseudonymous miners compete to solve an encryption task for adding new blocks to the public block-chained transaction database.
  - Double spending is controlled by accepting only the first instance of the next transaction generated by a bitcoin node—that is, it considers that all transactions sent by a node are sequentially numbered.
  - Because the miners in the network are unknown, it is impossible to control to what extent they collaborate, which increases the risk for so-called 51 percent abuse of mining power (Ali and Barrdear 2014).
  - In the Bitcoin protocol, the transaction database is public; users’ Bitcoin account addresses are pseudonymous, and it is possible to identify all transactions belonging to a person once the pseudonym is revealed.
- Digital Asset Platform (Digital Asset 2016)
  - Contains the Digital Asset Modeling Language for management of contracts and contract transactions using a private contract store and a global sync log.
- Elements (Blockstream)
  - A blockchain platform developed from Bitcoin that supports transaction confidentiality and PvP- and DvP-type cross-ledger transfers.
- Ethereum
  - An open-source DLT protocol for smart contracts, maintained by the non-profit organization Enterprise Ethereum Alliance.
- Hyperledger Fabric (Linux Foundation’s Hyperledger Initiative)
  - Open-source protocol based on smart contracts.
  - Validation nodes validate transactions; validating nodes are assigned validation tasks and other validating nodes can audit the results.
  - Validation is efficient, but users need to trust the validator nodes.
  - All nodes, user and validation nodes, need to be recognized by a DLT network membership service; privacy is ensured toward other nodes, but the membership service will know the identity of all other nodes.
- Quorum
  - An Ethereum-based enterprise-focused DLT environment for smart contracts with “network and peer permissions management, enhanced transaction and contract privacy, voting-based consensus mechanisms, and better performance,” as reported by the Blockchain Council.
  - J.P. Morgan facilitated the creation of Quorum.
- R3/Corda (R3 consortium)
  - Open-source protocol developed especially for the financial industry.
  - Can run both transaction accounts and smart contracts.
  - Unlike other DLT solutions, it has only bilateral transaction histories and therefore no common transaction database.
  - Transactions are validated by the sending and receiving nodes and specialized notary nodes; the notary node’s task is to hinder double spending.
  - Validation is a rapid process; participants need to trust the notary node(s).
  - The notary node will see all transactions and its processing speed and accuracy will affect the network; any security problems within the notary node can jeopardize the whole network.
  - Its structure will require different kinds of backup solutions for sufficient resiliency compared with other DLT networks.
- Sequence (Chain)
  - Protocol for managing account balances based on tokens in a ledger-as-a-service environment.
- Zilliqa (Anquan Capital)
  - DLT protocol closely related to the Elastico DLT protocol.
  - Uses “sharding” to share mining activities among subgroups of miners, facilitating parallel processing.
  - This feature increases the scalability of this protocol considerably to be close to linear with increased volumes.

*Distributed Ledger Technology Experiments in Payments and Settlements — Conclusion, Annex I, and Annex II (ftnea2020001 — Conclusion).*

---


_Source: https://www.imf.org/-/media/files/publications/ftn063/2020/english/ftnea2020001.pdf_
