## ftnea2024002

## Source details

**Canonical URL:** [ftnea2024002](https://www.imf.org/-/media/files/publications/ftn063/2024/english/ftnea2024002.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/ftn063/2024/english/ftnea2024002.pdf.md)
- [Structured JSON version](/-/media/files/publications/ftn063/2024/english/ftnea2024002.pdf.json)

---

### H3: Introduction — context, scope, and analytical framework
- Context and motivation
  - Many central banks are currently exploring the possibility of issuing retail central bank digital currency (CBDC).
  - Improved cross-border payments are considered a potential benefit and previous work has shown that CBDC can help overcome some of the frictions in cross-border payments.
  - CBDC is a safe and liquid asset reducing the number of financial intermediaries and the settlement risk.
  - CBDC offers a window—a clean slate—to build cross-border payment functionality from the start; making legacy payment systems interoperable across borders has been difficult once systems are up and running and initially designed for domestic purposes (FSB 2020b).
  - CBDC is commonly meant to coexist with and complement existing options, increasing payment diversity and potentially stimulating resilience, competition, and efficiency.
  - Effects are potentially macro-critical, as faster, cheaper, and more inclusive payments could facilitate international commerce and remittance transfers.
  - In a CBDC setting, end users would directly hold a central bank liability, just as when they hold cash, and the central bank is likely to have a large role in establishing and operating the infrastructure and scheme.
- Scope and focus of the paper
  - Focuses on retail CBDC—a CBDC primarily targeting households and non-financial firms—and leaves wholesale CBDC considerations for future work, although many discussions are applicable to wholesale CBDC and other forms of money as well.
  - Draws lessons from ongoing experimentation and research, including Project Icebreaker and Project Nexus, and publications under the “G20 Roadmap for Enhancing Cross-Border Payments”.
  - Provides an analytical framework viewing cross-border CBDC payments through five interrelated elements: access, communication, currency conversion, compliance, and settlement.
- Analytical framework: five elements (definitions preserved)
  - Access: who is permitted to hold and transact a given currency and any potential restrictions on that access.
  - Communication: the way in which the payer, payee, intermediaries, devices, and systems communicate and link up during a payment.
  - Currency conversion: how and by whom one currency is exchanged for another.
  - Compliance: responsibilities and requirements for regulatory and legal adherence (the paper focuses on technical aspects and high-level policy considerations related to AML/CFT, privacy, anonymity, and CFMs).
  - Settlement: how the transfer of funds between the parties involved is completed.
- Roles, responsibilities, and actors
  - Typical actors: end users, PSPs, operators, and the central bank.
  - Responsibilities categories:
    - Technical services: providing the underlying infrastructure, an interface of payment device, digital wallet, or messaging.
    - Customer relationships: onboarding and addressing customer complaints and questions.
    - Financial functions: financial intermediation and foreign exchange provision.
- Key messages and policy-relevant findings
  - Factor in cross-border implications at an early stage.
  - International cooperation is important: information sharing, consistent messaging standards and regulatory approaches, and common infrastructure can facilitate CBDC interoperability.
  - Assessing access policies and roles and responsibilities is paramount.
  - Adoption of international standards for payment initiation, data, and messaging (for example, ISO 20022) helps.
  - Instant settlement and 24/7 availability help mitigate some risks.
  - Programmability can deliver efficiency gains (e.g., enable synchronous PvP).
  - Compliance with international regulatory frameworks and privacy-enhancing technologies should be factored in.
  - Flexible or modular technical designs can help adapt to evolving cross-border arrangements.
- Illustrative example
  - Alice and Bob envelope analogy maps to the five elements: access, addressing, intermediaries, compliance, and determination/timing of ownership transfer.

### H3: Prevailing models for cross-border payments (Box 1)
- Overview
  - Three prevailing models: correspondent banking, closed loops, and aggregators.
  - Hybrid forms are possible (for example, a closed-loop system utilizing correspondent banking relationships).
  - These models can be used for processing cross-border retail CBDC payments, with refinements.
- Correspondent banking
  - Involves two or more banks establishing relationships to facilitate cross-border transactions; one bank acts as correspondent providing services to a respondent bank, sometimes with intermediary banks.
- Closed-loop systems
  - Operate within a specific network owned by a single company where payer and payee interact with the same entity (examples cited: Western Union, PayPal, Wise, Revolut).
  - Can facilitate cross-border payments via local presence in multiple countries or agreements with banks/financial institutions.
- Aggregators
  - PSPs use a third party (the aggregator) to process cross-border payments (examples cited: VISA, MasterCard, Wise Platform).
  - Aggregators establish a global network and typically communicate with PSPs rather than end users; they may use correspondent banking or participate directly in local FMIs.

### H3: CBDC design considerations and policy — Element 1: Access
- Central banks must determine access policies for end users, financial intermediaries, and foreign exchange providers; access policies impact domestic CBDC and cross-border models.
- Key trade-offs
  - Wider access: increases risk sharing and currency diversification but raises risks of currency substitution in other jurisdictions.
  - Narrower access: increases need for financial intermediaries and foreign exchange providers; implies direct or indirect access models for entities that intermediate cross-border CBDC flows.
- End user access specifics
  - Most central banks consider CBDC mainly accessible to residents; non-resident citizens and non-resident foreigners may need access (remittances, tourism).
  - Direct holding and transacting of a foreign CBDC would eliminate the need for currency conversion; lack of direct access necessitates currency conversion and an intermediary.
  - Risks: widespread use of an issuing jurisdiction’s CBDC outside its borders could cause currency substitution, capital flow volatility, and faster transmission of shocks.
  - G7 Principle 7: “CBDCs should be designed to avoid risks of harm to the international monetary and financial system, including the monetary sovereignty and financial stability of other countries.”
  - Mitigation measures: limits on holdings and transactions; enhanced data frameworks (including international coordination on a standard data reporting framework as outlined in Recommendation 11 of the G-20 Data Gaps Initiative (DGI-3)).
- Intermediary access models
  - Direct access: entity directly holds and participates in the CBDC system and would be under supervision of their home government from the issuer’s perspective.
  - Indirect access: foreign entities gain access via domestic entities (correspondent banking, nostro accounts); indirect holdings are claims on private entities, not central bank liabilities, and introduce credit risk.
  - Example: Swiss RTGS allows foreign banks remote access if they meet supervision, AML/CFT, and communications infrastructure standards.
  - Trade-offs: broader access increases competition and market depth but raises supervisory complexity; central banks acting as intermediaries or FX providers would take on currency risk and may be constrained by mandate.
- Restrictions on holdings and transactions
  - Options include limiting maximum holdings, limiting transaction size, or limiting number of transactions in a timeframe.
  - Domestic rationale: limits can reduce short-term disintermediation risk but overly low limits can reduce digital financial inclusion and usability.
  - Cross-border rationale: limits can reduce capital flow volatility and currency substitution risks; differing limits for residents and non-residents can mitigate trade-offs but may be seen as discriminatory.
  - Conditional limits by whereabouts are possible (less stringent for tourists while visiting; more stringent when abroad).
  - Limits introduce complexity: require rules, regulations, monitoring systems, administrative costs, and technical solutions.
  - Waterfall models: allow payments that bring a wallet above a limit to be accepted but automatically transfer excess funds to another asset; wallet holders designate a “waterfall” account.
- Key Design Considerations: Access (explicit list)
  - Non-resident access
  - Domestic and foreign financial intermediary and foreign exchange provider access
  - Holding and transaction restrictions
  - Waterfall accounts

### H3: CBDC design considerations and policy — Element 2: Communication
- Payment initiation and messaging
  - Payer needs payee’s “address”; today often IBAN and BIC for credit transfers.
  - Many central banks investigate proxies (aliases) such as phone numbers, nicknames, and email addresses domestically.
  - Nexus allows payer to use the proxy format used in the payee’s system by sharing service-level descriptions.
  - Address books with proxies likely need to be available to foreign PSPs for validation and compliance checks; initiating cross-border CBDC payments with only a phone number would probably not meet most regulatory requirements.
  - Standardized digital ID frameworks across jurisdictions would facilitate cross-border communication and messaging.
  - Person-to-business payments require consumer devices to read/understand NFC or QR messages from foreign merchants.
  - Lack of standardization, incomplete/incorrect information, limited transparency, lack of security, and regulatory differences create cross-border messaging challenges.
  - G20 Roadmap: promoting adoption of ISO 20022 (Action 8 in FSB 2023); central banks are advised to follow CPMI guidance on harmonizing ISO 20022 implementation; central banks should use ISO 20022 in CBDC design.
- Communication infrastructure and connectivity
  - Options:
    - Leave messaging to PSPs (for example, SWIFT).
    - Interlink systems via APIs; central bank must ensure such functionality in CBDC infrastructure.
    - Mix of PSP-led and interlinking approaches is possible.
  - Architectural choices affect scalability:
    - Bilateral links suffer scalability problems; standardized data, messaging, and APIs mitigate scalability issues.
    - Hub-and-spoke model simplifies connectivity with one technical counterpart (the hub).
    - Examples: Project Nexus uses standardized gateways; Project Icebreaker uses a central routing hub.
- Operational and policy implications
  - Payment initiation, addressing, and messaging standards affect compliance checks, user convenience, and competition.
  - Coordination on international standards reduces technical burden and supports interoperability with domestic non-CBDC systems.
  - Privacy-enhancing technologies combined with identifiers may enable efficient identification while ensuring privacy (referenced projects: Project Aurora and Project Aurum 2.0).
- Key design considerations for communication
  - Payment initiation (proxies, QR code, NFC)
  - Data and messaging standards
  - Digital ID frameworks
  - Centralized or private communication solutions
  - Centralized versus decentralized architectures
  - Hosted versus unhosted wallets in decentralized architectures

### H3: Annex IV excerpt — Communication technical notes and models
- Models and connectivity
  - Bilateral link versus hub-and-spoke; number of links in bilateral link calculated by the formula n(n-1)/2, while hub-and-spoke number of links is n.
  - Project Icebreaker: uses a hub-and-spoke communicator-like model connecting CBDC test systems of the central banks of Israel, Norway and Sweden via a central API hub; the API hub acts as a router and includes additional functionalities such as a foreign exchange marketplace.
  - Nexus: uses standardized gateways (Nexus Gateway) to manage proxy resolution, foreign exchange quote generation and payment processing; each Gateway connects to domestic IPS infrastructure and to Nexus Gateways in other countries.
  - Technical scalability: common platforms and hub-and-spoke interlinking standardize connections so each system has one technical counterpart and can facilitate all communication within the platform, increasing efficiency. Governance challenges remain.
- Synchronous vs asynchronous communication
  - Synchronous communication and processing require payer and payee wallets to be online simultaneously and provide immediate responses.
  - HTLC (Hashed Time Lock Contract) used by Project Icebreaker to facilitate PvP settlement in two separate currencies and decentralized systems; HTLC places money in technical escrow until conditions are met and typically requires synchronous execution with all wallets online or represented by an online agent.
  - Autonomous (unhosted) wallets may not be online, forcing asynchronous protocols and potentially significantly slower execution unless payees use services acting on their behalf.
  - Fully centralized systems remove the autonomy issue since “wallets” cannot be autonomous.
- Design trade-offs
  - Consider whether cross-border communication is integrated into core infrastructure (e.g., national gateway, APIs) or left to PSPs; centralization can improve competition and reduce end-user costs.
- Key design considerations for communication (reiterated)
  - Payment initiation (proxies, QR code, NFC)
  - Data and messaging standards
  - Digital ID frameworks
  - Centralized or private communication solutions
  - Centralized versus decentralized architectures
  - Hosted versus unhosted wallets in decentralized architectures

### H3: Annex IV excerpt — Currency conversion
- Three conceptual models for currency conversion in a retail cross-border payment
  1. Payer uses a foreign exchange provider to exchange CBDC-A for CBDC-B before sending CBDC-B to the payee (payer must be able to hold both CBDC-A and CBDC-B).
  2. Payer transfers CBDC-A to a financial intermediary that uses a third-party foreign exchange provider to exchange CBDC-A for CBDC-B before sending to payee (intermediary must be able to hold and transact both CBDC-A and CBDC-B).
  3. One PSP acts as both financial intermediary and foreign exchange provider: payer pays CBDC-A to foreign exchange provider, who pays CBDC-B to payee.
- Counterparty risk
  - Involvement of intermediaries and foreign exchange providers creates counterparty risk unless conditionality ensures all legs occur or none do; more actors increase risk (relevant to PvP in settlement element).
- Liquidity and market considerations
  - Foreign exchange providers carry currency risk and need liquidity in two currencies; financial intermediaries may avoid currency risk if processing and settlement occur instantly or on a PvP basis.
  - Market liquidity can be improved by concentrating order flows, improving price transparency, centralization (hub-and-spoke), or on-platform services like multi-currency auctions.
  - Icebreaker demonstrated a central hub foreign exchange marketplace decoupling foreign exchange provision and financial intermediation from wallet provision to promote competition; participation incentives remain a concern.
  - Risk of multiple exchange rates if markets segment or trades in CBDC are constrained; segmentation of liquidity and regulatory heterogeneity increase complexity and operational risk.
- Foreign exchange liquidity management
  - Central banks may consider limits on transaction or holding that could impact providers’ liquidity; access policies and holding/transaction limits are important.
  - Reverse waterfall accounts can fund CBDC accounts instantly from another form of money (reserve accounts or commercial bank accounts).
  - If reserve accounts are required for foreign exchange providers, the pool of potential providers could shrink if access to central bank balance sheet is restrictive.
  - 24/7 ability to fund CBDC accounts is important because many central bank RTGS systems do not operate 24/7.
  - Cross-border arrangements can offer liquidity facilities such as central bank liquidity bridges or Automated Market Makers (AMMs).
    - Liquidity bridges: central banks provide short-term liquidity pools; local CBDC can be used as collateral to borrow foreign CBDC from counterparty central banks.
    - AMMs: decentralized algorithms and smart contracts providing continuous liquidity and pricing; challenges include limited fund supply costs, price discrepancies without reliable oracles, operational complexity, cybersecurity, scalability, and network congestion.
  - AMMs and liquidity bridges decisions are made at later stages but can impact optimal CBDC design (e.g., need for smart-contract or escrow functionality).
- Key design considerations for currency conversion
  - PSP access and limits (see Access)
  - PSP competition aspects
  - Foreign exchange liquidity management
  - Escrow functionality
  - 24/7 CBDC funding ability

### H3: Annex IV excerpt — Compliance
- Legal and regulatory compliance
  - Cross-border CBDC arrangements must adhere to AML/CFT standards and laws, with FATF standards applying to CBDCs as to other fiat currency.
- Roles and responsibilities
  - Design choices affect which intermediaries are subject to AML/CFT regulation; intermediaries covered by FATF standards would need to be regulated and supervised for AML/CFT purposes.
- Complexity factors
  - Retail and cross-border CBDC ecosystems are more complex than wholesale or domestic settings; introduction of new intermediaries or service changes can create novel compliance complexities.
  - CBDC does not solve uneven application of AML/CFT rules across jurisdictions; counterparties may refuse to service jurisdictions with weak AML/CFT implementation.
  - Reductions in the number of intermediaries could decrease some compliance burdens if transaction chains shorten.
- Anonymity and privacy
  - Some central banks consider limited anonymous low-value domestic CBDC transactions; such models remain vulnerable to misuse and must comply with FATF standards.
  - Cross-border arrangements raise challenges if jurisdictions differ on anonymity or privacy levels; privacy-enhancing technologies (Project Aurora and Project Aurum 2.0) may help.
- Capital Flow Management Measures (CFMs)
  - CFMs include authorizations, taxes, fees, or quantity limits and traditionally rely on intermediaries collecting transaction and beneficiary information.
  - “Smart CFMs” can be coded as algorithms within CBDC systems; rule-based CFMs may be preferable to discretionary ones to enable digital automation.
  - Smart CFMs can be implemented on three levels:
    1. User technical interface
    2. Core CBDC system operated by the central bank
    3. Multilateral platform coordination among central banks
  - User-interface CFMs suit simple, infrequently updated rules; central-bank-implemented CFMs offer higher effectiveness and access to required information.
  - Governance and legal constraints may limit CFMs on multilateral platforms; modular approaches (for example, Lego-Bricks in project mBridge) can allow flexible combinations of payment, FX, capital management, and AML/CFT modules.
- Key design considerations for compliance
  - Roles and responsibilities in the ecosystem
  - Anonymity and privacy measures
  - Smart CFMs

### H3: Annex IV excerpt — Settlement
- Core issues
  - Cross-currency payments require settlement of both currency legs; settlement finality (irrevocable and unconditional transfer) is central to reducing settlement risk.
- Two design levers to reduce settlement risk
  1. 24/7 availability and instant settlement to remove timing and operating-hour mismatch risk.
  2. Payment versus Payment (PvP) settlement functions to reduce counterparty (principal/Herstatt) risk.
- Instant settlement
  - Processed and settled individually and continuously; participants must maintain adequate balances at any time.
  - Instant settlement implies foreign exchange providers must hold liquidity in the target currency at trade moment or have instant funding mechanisms such as intraday credit or instant CBDC issuance.
  - Central banks considering 24/7 CBDC designs must evaluate liquidity management implications for foreign exchange providers and intermediaries.
  - Challenges include real-time liquidity management, 24/7 operational and cybersecurity resilience, and difficulty in recalling payments to prevent fraud.
- PvP forms and implementation
  - Two PvP classifications:
    - Traditional PvP: two actors exchange currencies directly (two-way).
    - Coordinated (one-directional) PvP: involves an intermediary between payer and payee.
  - Retail CBDC cross-border arrangements are likely to require intermediaries, implying coordinated PvP.
  - PvP implementation approaches:
    - Third-party-based: trusted third party or central counterparty (CCP) verifies receipts and releases assets.
    - Peer-to-peer: technical escrow or smart contracts, oracles that countersign transactions, or atomic swaps/HTLC.
      - HTLC: payer locks payment with hash of secret, payee mirrors, payer reveals secret to unlock payee’s payment initiating chained releases; used in Project Icebreaker for coordinated PvP.
  - Trust trade-offs: third-party arrangements rely on trust in the entity, peer-to-peer relies on trust in technology implementation.
  - Ledger technology considerations: smart contract–capable ledgers can facilitate peer-to-peer protocols, but similar outcomes can be achieved via less advanced technologies using trusted third parties.
- Key design considerations for settlement
  - Instant settlement
  - 24/7 availability
  - Programmability

### H3: Annex IV — Icebreaker protocol: eight phases (detailed process)
- Phase 1: Payer enters currency and amount, and the payer wallet sends a quote request to the hub.
- Phase 2: The hub retrieves the best available quote from its foreign exchange database and responds with the best quote and the identity of the associated foreign exchange provider.
- Phase 3: If the payer accepts the quote, she proceeds by entering the payee’s payment address/alias and the payer wallet sends a payment request to the payee wallet.
- Phase 4: The payee wallet validates its wallet address and generates a secret and sends the verification results and returns a hash value of the secret to the payer wallet.
- Phase 5: The payer wallet creates a locked payment to the foreign exchange provider’s payer-currency wallet.
- Phase 6: The foreign exchange provider’s payer-currency wallet sends the payment information and the hash value to the foreign exchange provider’s payee-currency wallet where it creates a locked payment in the payee currency to the payee wallet.
- Phase 7: The payee wallet recognizes there is a locked incoming payment and presents the secret (generated in phase 4) to the smart contract locking the incoming payment, and the funds are released to the payee wallet only if the calculated hash value of the presented secret matches the hash value used to lock the payment.
- Phase 8: The secret is now revealed to the foreign exchange provider’s payee-currency wallet and the secret is sent to the foreign exchange provider’s payer-currency wallet where it presents the secret to the smart contract to unlock the incoming payer currency payment.
- Icebreaker design implications and considerations (key points)
  - Compatibility of QR codes, NFC messages, and aliases with foreign systems; whether wallet providers or systems must identify cross-border payments.
  - Connectivity choices: hub versus national gateways; wallets/PSPs may communicate via a hub, via national gateways, or direct wallet connections.
  - HTLC-based conditional settlement: each CBDC system must be able to implement HTLC-based conditional settlement; HTLC functionality can be implemented in different ways depending on underlying technology.
  - Smart contracts versus trusted escrow agents: DLT systems may use smart contracts as “technical escrow”; non-DLT systems may require a trusted escrow agent to emulate HTLC behavior.
  - Liquidity reservation: production systems might reserve liquidity between quote request and locking phases; design must address potential spamming of quote requests.
  - Approval timing and spamming: three potential places for payer approval (before phase 1, in phase 3, or before phase 5) each have trade-offs between information availability and spamming risk; balancing approval processes and misbehavior rules is necessary.

### H3: Conclusions — policy guidance and operational recommendations
- Cross-border implications in retail CBDC design
  - Factor in cross-border implications from the start to avoid unintended barriers for later stages.
  - G20 Roadmap Building block 19 considers “Factoring an international dimension into CBDC design”.
- Retail versus wholesale CBDC considerations
  - Many lessons apply to both retail and wholesale CBDC.
  - Retail CBDC intended for households; wholesale CBDC typically only for banks and financial institutions.
  - Retail CBDC can reduce the total number of intermediaries needed in cross-border payments and can lower credit and settlement risks for users.
  - If retail CBDC is not available for cross-border payments, retail users can still benefit from cross-border wholesale CBDC arrangements that deliver more efficient interbank cross-border payments.
- Flexible, modular system design
  - Systems should be able to “plug in” to different arrangements; flexible or modular design enables components to be modified, replaced, or extended without major architecture changes.
- International collaboration and coordination
  - Strong international collaboration with other central banks is important for information sharing and policy coordination.
  - International organizations (IMF, World Bank, BIS) play significant roles in fostering cooperation, capacity development, and guidance.
  - Global-level cooperation can help avoid fragmentation and walled gardens.
- Operational recommendation: cross-border workstream
  - Central banks can establish a cross-border workstream in their CBDC exploration to consider cross-border implications.
  - The paper presents the five-element lens and provides questions (Box 3) for guidance.
- Box 3. Guiding Baseline Questions (preserved list)
  - General
    1. What are the cross-border-related objectives?
    2. What role should the central bank play in facilitating cross-border payments?
  - Access
    3. Do non-residents have access to the CBDC, and what are the rules and criteria for that access?
    4. What are the rules and access criteria for financial intermediaries and foreign exchange providers?
  - Communication
    5. What data and messaging standard(s) do the system support?
    6. Are we following the guidance from CPMI on ISO 20022 implementation?
    7. What standards are used for payment initiation (for example, proxies, QR code, NFC)?
    8. What digital ID framework is necessary to ensure smooth and efficient cross-border transactions?
    9. Is the system or the wallet providers responsible for identifying that it is a cross-border payment?
    10. Should there be a national gateway for any formal interlinking with other systems?
  - Currency conversion
    11. Who is providing foreign exchange and how are end users matched with the foreign exchange provider?
    12. What is the role of the central bank in facilitating foreign exchange transactions and liquidity?
  - Compliance
    13. How will international AML/CFT standards be incorporated into the system's compliance framework?
    14. Who is responsible for AML/CFT compliance checks (including KYC)?
    15. Who is responsible for CFM compliance checks?
    16. Should AML/CFT compliance checks (including KYC) be automated and/or centralized?
    17. Should “smart CFMs” be implemented, and at what level?
  - Settlement
    18. Should the system offer programmability options, for example, smart contracts, to facilitate PvP?
    19. Should a centralized trusted oracle/CCP be part of the baseline CBDC ecosystem?

_Italic: Source: ftnea2024002 - Cross-border Payments with Retail CBDC: Design and Policy Considerations (PDF chapter)_

### 1. Introduction.........................................................................................................

### 1. Introduction

### Context and motivation
- Many central banks are currently exploring the possibility of issuing retail central bank digital currency (CBDC).  
- Improved cross-border payments are considered a potential benefit and previous work has shown that CBDC can help overcome some of the frictions in cross-border payments.  
- CBDC is a safe and liquid asset reducing the number of financial intermediaries and the settlement risk.  
- CBDC offers a window—a clean slate—to build cross-border payment functionality from the start; making legacy payment systems interoperable across borders has been difficult once systems are up and running and initially designed for domestic purposes (FSB 2020b).  
- CBDC is commonly meant to coexist with and complement existing options, increasing payment diversity and potentially stimulating resilience, competition, and efficiency.  
- Effects are potentially macro-critical, as faster, cheaper, and more inclusive payments could facilitate international commerce and remittance transfers.  
- In a CBDC setting, end users would directly hold a central bank liability, just as when they hold cash, and the central bank is likely to have a large role in establishing and operating the infrastructure and scheme.

### Scope and focus of the paper
- The paper focuses on retail CBDC—a CBDC primarily targeting households and non-financial firms—and leaves wholesale CBDC considerations for future work, although many discussions are applicable to wholesale CBDC and other forms of money as well.  
- The paper draws lessons from ongoing experimentation and research, including Project Icebreaker and Project Nexus, and publications under the “G20 Roadmap for Enhancing Cross-Border Payments” (see FSB 2020a).  
- The paper provides an analytical framework viewing cross-border CBDC payments through five interrelated elements: access, communication, currency conversion, compliance, and settlement.

### Analytical framework: five elements
- The five key elements that form the fundamental components of a cross-border payment are:  
  - Access: who is permitted to hold and transact a given currency and any potential restrictions on that access.  
  - Communication: the way in which the payer, payee, intermediaries, devices, and systems communicate and link up during a payment.  
  - Currency conversion: how and by whom one currency is exchanged for another.  
  - Compliance: responsibilities and requirements for regulatory and legal adherence (the paper focuses on technical aspects and high-level policy considerations related to AML/CFT, privacy, anonymity, and CFMs).  
  - Settlement: how the transfer of funds between the parties involved is completed.  
- The elements are interconnected; access policies determine the need for currency conversion and who can offer foreign exchange services, influence the need for intermediaries, and affect how settlement is achieved. Compliance needs depend on the participants determined by access and conversion models.  

### Roles, responsibilities, and actors
- Typical actors in CBDC systems include end users, PSPs, operators, and the central bank. Responsibilities fall into three main categories:  
  - Technical services: providing the underlying infrastructure, an interface of payment device, digital wallet, or messaging.  
  - Customer relationships: onboarding and addressing customer complaints and questions.  
  - Financial functions: financial intermediation and foreign exchange provision.

### Key messages and policy-relevant findings
- Factor in cross-border implications at an early stage: making early design decisions can diminish the risk of having to redesign or adjust a domestic CBDC system later. Clear objectives on cross-border use help make early design choices even if the CBDC is initially only used domestically.  
- International cooperation is important: information sharing, consistent messaging standards and regulatory approaches, and common infrastructure can facilitate CBDC interoperability. Global-level cooperation can help avoid fragmentation and walled gardens.  
- Other key messages from the work:  
  - Assessing access policies and roles and responsibilities is paramount: Central banks should carefully evaluate access policies for end users and intermediaries. Wide access could reduce the cost associated with foreign exchange provision but might cause macrofinancial risks such as capital flow volatility or currency substitution.  
  - The adoption of international standards for payment initiation, data, and messaging helps: Even in a CBDC environment, these standards, such as ISO 20022, will continue playing a role.  
  - Having instant settlement and 24/7 availability helps mitigate some risks: By providing instant payments and 24/7 availability, settlement and liquidity risks can decrease.  
  - Programmability can deliver efficiency gains: Experiments suggest that programmability could lower settlement risks by allowing synchronous payment versus payment (PvP).  
  - Compliance with international regulatory frameworks should be factored in: These include technologies to ensure privacy and enhance regulatory compliance such as for anti-money laundering/combating the financing of terrorism (AML/CFT).  
  - Flexible or modular technical designs can help: Solutions that can “plug into” different arrangements can more easily adapt to the likely continuous evolution of the future cross-border CBDC payments landscape.

### Illustrative example and interpretation
- The Alice and Bob envelope analogy illustrates the five elements and cross-border frictions: access to the instrument, addressing (recipient identification), intermediary services (postal or digital intermediaries), compliance with rules and regulations, and the determination and timing of ownership transfer.  
- The analogy shows that even when payments are digital, analogous requirements—access, addressing, intermediaries, compliance, and settlement—remain central considerations for cross-border CBDC design.

_Italic: Source: ftnea2024002 - 1. Introduction (PDF chapter)_.

### Box 1. Prevailing Models for Cross-Border Payments

### Box 1. Prevailing Models for Cross-Border Payments

### Overview
- There are three prevailing models for processing cross-border payments: correspondent banking, closed loops, and aggregators.
- Hybrid forms are also possible, for example a closed-loop system utilizing correspondent banking relationships to maintain its liquidity and manage risks.
- The three models described above can be used also for processing cross-border retail CBDC payments, although some refinements of the models would occur.
- See Annex II for an example of the process for inbound diaspora remittances using the eNaira.
- See CPMI (2018) for more on cross-border retail payments. See also Annex I for how the above models are viewed through the five elements.

### Correspondent banking
- Correspondent banking is one of the most common methods to facilitate cross-border payments.
- It involves two or more banks, typically located in different countries, establishing relationships to facilitate cross-border transactions.
- In this relationship, one bank acts as a correspondent bank and provides services to another bank, the respondent bank, sometimes with the use of intermediary banks.
- The respondent bank uses the correspondent bank’s services to facilitate cross-border payments for its customers.

### Closed-loop systems
- A closed-loop system operates within a specific network, usually owned by a single company, such that the payer and the payee interact with the same entity—exemplified by Western Union, PayPal, Wise, and Revolut.
- The payment is processed within the network, allowing quick and secure transfer of funds between accounts.
- The closed-loop system can facilitate cross-border payments because it has a local presence in multiple countries or has agreements with banks or financial institutions in the countries where the payment is being sent or received.

### Aggregators
- Cross-border payments via aggregators refer to the process of PSPs using a third party, the aggregator, to process cross-border payments—exemplified by VISA, MasterCard, and Wise Platform.
- These payment aggregators establish a global network and do not communicate directly with end users but with PSPs, who interact with the end users.
- The aggregators typically use a correspondent banking network to gain access, but can also participate directly in local financial market infrastructures (FMIs).

*International Monetary Fund — FINTECH NOTES: Cross-Border Payments with Retail CBDC: Design and Policy Considerations (Box 1).*

### 3.   CBDC Design Considerations and Policy

### 3.   CBDC Design Considerations and Policy

### Element 1: Access
- Central banks must determine access policies for end users, financial intermediaries, and foreign exchange providers; access policies—who has access to what currency and under what rules—impact both the domestic CBDC system and possible cross-border payment models.
- Key trade-offs:
  - Wider access may increase risk sharing and currency diversification but raises risks associated with currency substitution in other jurisdictions.
  - Narrower access increases need for financial intermediaries and foreign exchange providers in cross-border settings; implies direct or indirect access models for entities that intermediate cross-border CBDC flows.
- End user access:
  - Most central banks consider CBDC mainly accessible to residents, but non-resident citizens (remittances) and non-resident foreigners (tourism) may need access.
  - Non-resident adoption depends on whether PSPs find onboarding, customer service, and regulatory conditions profitable and workable.
  - Direct holding and transacting of a foreign CBDC would eliminate the need for currency conversion; lack of direct access necessitates currency conversion and an intermediary.
  - Widespread use of an issuing jurisdiction’s CBDC outside its borders could cause macrofinancial implications including currency substitution, capital flow volatility, and faster transmission of shocks.
  - G7 Principle 7: “CBDCs should be designed to avoid risks of harm to the international monetary and financial system, including the monetary sovereignty and financial stability of other countries.”
  - Mitigation measures include limits on holdings and transactions and enhanced data frameworks (including international coordination on a standard data reporting framework as outlined in Recommendation 11 of the G-20 Data Gaps Initiative (DGI-3)).
- Access by financial intermediaries and foreign exchange providers:
  - Direct access: a domestic or foreign entity directly holds and participates in the CBDC system; such entities would be under supervision of their home government from the issuer’s perspective.
  - Indirect access: foreign entities gain access via domestic entities (correspondent banking, nostro accounts); indirect holdings constitute a claim on a private entity, not a central bank liability, and introduce credit risk.
  - Examples: Swiss RTGS allows foreign banks remote access if they meet supervision, AML/CFT, and communications infrastructure standards.
  - Trade-offs: broader access can increase competition and market depth but raises supervisory complexity; central banks acting as intermediaries or foreign exchange providers would take on currency risk and may be constrained by mandate.
  - Avoid replicating correspondent banking challenges (long chains, unserved corridors); CBDC interlinking and greater diversity of intermediaries can reduce transaction chains and dependencies on correspondent banks.
- Restrictions on holdings and transactions:
  - Options include limiting maximum holdings, limiting transaction size (to ensure low-value payments), or limiting number of transactions in a timeframe.
  - Domestic rationale: limits can reduce short-term disintermediation risk but overly low limits can reduce digital financial inclusion and usability.
  - Cross-border rationale: limits can reduce capital flow volatility and currency substitution risks; differing limits for residents and non-residents can mitigate trade-offs but may be seen as discriminatory.
  - Conditional limits by whereabouts (less stringent for tourists while visiting; more stringent when abroad) are possible; actual usage still depends on local demand.
  - Limits introduce complexity: require rules, regulations, monitoring systems, administrative costs, and technical solutions to handle payments hitting limits.
  - Waterfall models: allow payments that bring a wallet above a limit to be accepted but automatically transfer excess funds to another asset (e.g., a commercial bank account); wallet holders designate a “waterfall” account.
- Key Design Considerations: Access (explicit list from source)
  - Non-resident access
  - Domestic and foreign financial intermediary and foreign exchange provider access
  - Holding and transaction restrictions
  - Waterfall accounts

### Element 2: Communication
- Two main parts: payment initiation and messaging; infrastructure and connectivity.
- Payment initiation and messaging:
  - Payer needs the payee’s “address”; today often IBAN and BIC for credit transfers.
  - Many central banks investigate proxies (aliases) such as phone numbers, nicknames, and email addresses for addressing CBDC payments domestically.
  - Cross-border addressing would be simpler if domestic proxies could be used cross-border; Nexus allows payer to use the proxy format used in the payee’s system by sharing service-level descriptions (account number format and proxy format).
  - Address books with proxies would likely need to be available to foreign PSPs for validation and compliance checks (AML/CFT). Initiating cross-border CBDC payments with only a phone number would probably not meet most regulatory requirements.
  - Standardized digital ID frameworks across jurisdictions would facilitate more efficient cross-border communication and messaging.
  - Person-to-business payments add complexity: consumer devices must be able to read and understand NFC or QR messages from foreign merchants; following international standards facilitates interoperability and reduces technical burden on PSPs.
  - Lack of standardization, incomplete/incorrect information, limited transparency, lack of security, and regulatory differences create cross-border messaging challenges.
  - G20 Roadmap and standards:
    - G20 Roadmap promoting adoption of ISO 20022 (Action 8 in FSB 2023); harmonizing ISO 20022 implementation for cross-border payments requires coordinated effort.
    - Central banks are advised to follow CPMI guidance on harmonizing ISO 20022 implementation; central banks should use ISO 20022 in CBDC design.
- Communication infrastructure and connectivity:
  - Options for cross-border messaging:
    - Leave messaging infrastructure to PSPs (for example, SWIFT).
    - Interlink systems via APIs; central bank must ensure such functionality in CBDC infrastructure.
    - Mix of PSP-led and interlinking approaches is possible.
  - Architectural choices affect scalability:
    - Bilateral links suffer scalability problems as many links and channels must be established; standardized data, messaging, and APIs mitigate scalability issues.
    - Hub-and-spoke model simplifies connectivity with one technical counterpart (the hub).
    - Examples: Project Nexus uses standardized gateways; Project Icebreaker uses a central routing hub.
- Operational and policy implications:
  - Payment initiation, addressing, and messaging standards affect compliance checks, user convenience, and competition.
  - Coordination on international standards reduces technical burden and supports interoperability with domestic non-CBDC systems.
  - Privacy-enhancing technologies combined with identifiers may enable efficient identification while ensuring privacy (referenced projects: Project Aurora and Project Aurum 2.0).

*FINTECH NOTES Cross-Border Payments with Retail CBDC: Design and Policy Considerations — Chapter 3*

### Annex IV for more information on Project Icebreaker).

### ftnea2024002 - Annex IV for more information on Project Icebreaker)

### Communication
- Models: bilateral link versus hub-and-spoke; number of links in bilateral link calculated by the formula n(n-1)/2, while hub-and-spoke number of links is n.  
- Project Icebreaker: uses a hub-and-spoke communicator-like model connecting CBDC test systems of the central banks of Israel, Norway and Sweden via a central API hub; the API hub acts as a router and includes additional functionalities such as a foreign exchange marketplace (see element 3 and Annex IV).  
- Alternative: Nexus uses standardized gateways (Nexus Gateway) to manage proxy resolution, foreign exchange quote generation and payment processing; each Gateway connects to domestic IPS infrastructure and to Nexus Gateways in other countries (BISIH 2021).  
- Technical scalability: common platforms and hub-and-spoke interlinking standardize connections so each system has one technical counterpart and can facilitate all communication within the platform, increasing efficiency. Governance challenges remain (BIS, IMF, and World Bank 2022).  
- Synchronous vs asynchronous communication:
  - Synchronous communication and processing require payer and payee wallets to be online simultaneously and provide immediate responses.
  - HTLC (Hashed Time Lock Contract) used by Project Icebreaker to facilitate PvP settlement in two separate currencies and decentralized systems; HTLC places money in technical escrow until conditions are met and typically requires synchronous execution with all wallets online or represented by an online agent.
  - Autonomous (unhosted) wallets may not be online, forcing asynchronous protocols and potentially significantly slower execution unless payees use services acting on their behalf.
  - Fully centralized systems remove the autonomy issue since “wallets” cannot be autonomous.
- Design trade-offs: central banks should consider whether cross-border communication is integrated into core infrastructure (e.g., national gateway, APIs) or left to PSPs; centralization can improve competition and reduce end-user costs.
- Key design considerations for communication:
  - Payment initiation (proxies, QR code, NFC)
  - Data and messaging standards
  - Digital ID frameworks
  - Centralized or private communication solutions
  - Centralized versus decentralized architectures
  - Hosted versus unhosted wallets in decentralized architectures

### Currency Conversion
- Three conceptual models for currency conversion in a retail cross-border payment:
  1. Payer uses a foreign exchange provider to exchange CBDC-A for CBDC-B before sending CBDC-B to the payee (payer must be able to hold both CBDC-A and CBDC-B).
  2. Payer transfers CBDC-A to a financial intermediary that uses a third-party foreign exchange provider to exchange CBDC-A for CBDC-B before sending to payee (intermediary must be able to hold and transact both CBDC-A and CBDC-B).
  3. One PSP acts as both financial intermediary and foreign exchange provider: payer pays CBDC-A to foreign exchange provider, who pays CBDC-B to payee.
- Counterparty risk: involvement of intermediaries and foreign exchange providers creates counterparty risk unless conditionality ensures all legs occur or none do; more actors increase risk (relevant to PvP in settlement element).
- Liquidity and market considerations:
  - Foreign exchange providers carry currency risk and need liquidity in two currencies; financial intermediaries may avoid currency risk if processing and settlement occur instantly or on a PvP basis.
  - Market liquidity can be improved by concentrating order flows, improving price transparency, centralization (hub-and-spoke), or on-platform services like multi-currency auctions (Adrian and others 2022).
  - Icebreaker demonstrated a central hub foreign exchange marketplace decoupling foreign exchange provision and financial intermediation from wallet provision to promote competition; participation incentives remain a concern and lack of providers can reduce liquidity.
  - Risk of multiple exchange rates if markets segment or trades in CBDC are constrained; segmentation of liquidity and regulatory heterogeneity increase complexity and operational risk.
- Foreign exchange liquidity management:
  - Central banks may consider limits on transaction or holding that could impact providers’ liquidity; access policies and holding/transaction limits are important.
  - Reverse waterfall accounts can fund CBDC accounts instantly from another form of money (reserve accounts or commercial bank accounts) to support instant cross-border payments.
  - If reserve accounts are required for foreign exchange providers, the pool of potential providers could shrink if access to central bank balance sheet is restrictive.
  - 24/7 ability to fund CBDC accounts is important because many central bank RTGS systems do not operate 24/7.
  - Cross-border arrangements can offer liquidity facilities such as central bank liquidity bridges (CPMI 2022c) or Automated Market Makers (AMMs) (BISIH and others 2023a).
    - Liquidity bridges: central banks provide short-term liquidity pools; local CBDC can be used as collateral to borrow foreign CBDC from counterparty central banks.
    - AMMs: decentralized algorithms and smart contracts providing continuous liquidity and pricing; challenges include limited fund supply costs, price discrepancies without reliable oracles, operational complexity, cybersecurity, scalability, and network congestion.
  - AMMs and liquidity bridges decisions are made at later stages but can impact optimal CBDC design (e.g., need for smart-contract or escrow functionality).
- Key design considerations for currency conversion:
  - PSP access and limits (see Access)
  - PSP competition aspects
  - Foreign exchange liquidity management
  - Escrow functionality
  - 24/7 CBDC funding ability

### Compliance
- Legal and regulatory compliance: cross-border CBDC arrangements must adhere to AML/CFT standards and laws, with FATF standards applying to CBDCs as to other fiat currency.
- Roles and responsibilities: design choices affect which intermediaries are subject to AML/CFT regulation; intermediaries covered by FATF standards would need to be regulated and supervised for AML/CFT purposes.
- Complexity factors:
  - Retail and cross-border CBDC ecosystems are more complex than wholesale or domestic settings; introduction of new intermediaries or service changes can create novel compliance complexities.
  - Many-to-one mappings of CBDC service providers to end users (e.g., Project Sela) can add complexity and require further research.
  - CBDC does not solve uneven application of AML/CFT rules across jurisdictions; counterparties may refuse to service jurisdictions with weak AML/CFT implementation.
  - Reductions in the number of intermediaries could decrease some compliance burdens if transaction chains shorten.
- Anonymity and privacy:
  - Some central banks consider limited anonymous low-value domestic CBDC transactions; such models remain vulnerable to misuse and must comply with FATF standards.
  - Cross-border arrangements raise challenges if jurisdictions differ on anonymity or privacy levels; privacy-enhancing technologies (Project Aurora and Project Aurum 2.0) may help.
- Capital Flow Management Measures (CFMs):
  - CFMs include authorizations, taxes, fees, or quantity limits and traditionally rely on intermediaries collecting transaction and beneficiary information.
  - “Smart CFMs” can be coded as algorithms within CBDC systems; rule-based CFMs may be preferable to discretionary ones to enable digital automation.
  - Smart CFMs can be implemented on three levels:
    1. User technical interface
    2. Core CBDC system operated by the central bank
    3. Multilateral platform coordination among central banks
  - User-interface CFMs suit simple, infrequently updated rules; central-bank-implemented CFMs offer higher effectiveness and access to required information.
  - Governance and legal constraints may limit CFMs on multilateral platforms; modular approaches (e.g., Lego-Bricks in project mBridge) can allow flexible combinations of payment, FX, capital management, and AML/CFT modules for participating jurisdictions.
- Key design considerations for compliance:
  - Roles and responsibilities in the ecosystem
  - Anonymity and privacy measures
  - Smart CFMs

### Settlement
- Core issues: cross-currency payments require settlement of both currency legs; settlement finality (irrevocable and unconditional transfer) is central to reducing settlement risk.
- Two design levers to reduce settlement risk:
  1. 24/7 availability and instant settlement to remove timing and operating-hour mismatch risk.
  2. Payment versus Payment (PvP) settlement functions to reduce counterparty (principal/Herstatt) risk.
- Instant settlement:
  - Processed and settled individually and continuously; participants must maintain adequate balances at any time.
  - Instant settlement implies foreign exchange providers must hold liquidity in the target currency at trade moment or have instant funding mechanisms such as intraday credit or instant CBDC issuance.
  - Central banks considering 24/7 CBDC designs must evaluate liquidity management implications for foreign exchange providers and intermediaries.
  - Challenges include real-time liquidity management, 24/7 operational and cybersecurity resilience, and difficulty in recalling payments to prevent fraud.
- PvP forms and implementation:
  - Two PvP classifications:
    - Traditional PvP: two actors exchange currencies directly (two-way).
    - Coordinated (one-directional) PvP: involves an intermediary between payer and payee.
  - Retail CBDC cross-border arrangements are likely to require intermediaries, implying coordinated PvP (aligned with case 3 in Figure 3); case 1 aligns with traditional PvP, case 2 could have both.
  - PvP implementation approaches:
    - Third-party-based: trusted third party or central counterparty (CCP) verifies receipts and releases assets, mitigating counterparty risk.
    - Peer-to-peer: technical escrow or smart contracts (technical locks with conditional release), oracles that countersign transactions, or atomic swaps/HTLC.
      - HTLC: payer locks payment with hash of secret, payee mirrors, payer reveals secret to unlock payee’s payment initiating chained releases; used in Project Icebreaker for coordinated PvP (see Annex IV). HTLC and similar protocols often require synchronous communication and can present non-atomicity risk due to operational events.
  - Trust trade-offs: third-party arrangements rely on trust in the entity, peer-to-peer relies on trust in technology implementation.
  - Ledger technology considerations: smart contract–capable ledgers can facilitate peer-to-peer protocols, but similar outcomes can be achieved via less advanced technologies using trusted third parties.
- Key design considerations for settlement:
  - Instant settlement
  - 24/7 availability
  - Programmability

*International Monetary Fund — ftnea2024002 (Annex IV excerpt as supplied).*

### 4.    Conclusions

### 4.    Conclusions

### Cross-border implications in retail CBDC design
- When designing retail CBDC systems, it is beneficial to factor in cross-border implications from the start.
- Even if cross-border payments are not considered to be available at the initial launch, avoiding unintended barriers for potential later stages is important.
- The G20 Roadmap recognizes this importance: Building block 19 considers “Factoring an international dimension into CBDC design” (BIS, IMF, World Bank 2021 and 2022).
- This paper assists central bank in their efforts to factoring in an international dimension in their CBDC exploration.

### Retail versus wholesale CBDC considerations
- While this paper has focused on retail CBDC, many of the lessons apply also to wholesale CBDC and other forms of money.
- A retail CBDC is intended to be available for household, providing them with direct access to central bank money.
- A wholesale CBDC is typically intended to only be available to banks and financial institutions.
- With a retail CBDC, households within a country transact directly and thus need fewer financial intermediaries.
- Intermediaries are likely to be needed in a cross-border payment to convert currencies and expand access to foreign market.
- Using a retail CBDC for cross-border payments can reduce the total number of intermediaries needed, and can lower credit and settlement risks for users.
- If a retail CBDC is not available for cross-border payments, retail users could still benefit from cross-border wholesale CBDC arrangements that deliver more efficient interbank cross-border payments, which would ideally trickle down to faster and cheaper payments for end users.

### Flexible, modular system design
- Given that the future cross-border payments landscape is still unfolding and potentially fragmented, central banks should ensure their retail CBDC systems are able to “plug in” to different forms of arrangements.
- Flexible or modular design: systems built using components that can be easily modified, replaced, or extended without requiring significant changes to the overall architecture.

### International collaboration and coordination
- A strong focus on international collaboration with other central banks is important.
- Establishing agreements, collaborations, and mechanisms to facilitate information sharing and policy coordination is paramount to the viability of cross-border arrangements and their ability to facilitate and enhance cross-border payments.
- International organizations such as the International Monetary Fund, the World Bank, and the Bank for International Settlements play a significant role in fostering cooperation and providing capacity development and guidance.
- International cooperation can be more impactful if achieved at a global level to avoid fragmentation and walled gardens.
- The priority actions agreed under the G20 Roadmap in the coming years will be important.

### Operational recommendation: cross-border workstream
- To factor in cross-border implications right from the start is not a trivial task.
- Central banks can establish a cross-border workstream in their CBDC exploration to consider cross-border implications.
- This paper views cross-border payments through the lens of five elements, identifying core design and policy options central banks need to view from a cross-border perspective.
- The analysis is not comprehensive; technical and policy design considerations during the CBDC exploration should be viewed through the lens of cross-border payments.
- The questions listed in Box 3 provide additional guidance.

### Box 3. Guiding Baseline Questions When Factoring in Cross-Border Implications in the CBDC Design
- General
  1. What are the cross-border-related objectives?
  2. What role should the central bank play in facilitating cross-border payments?
- Access
  3. Do non-residents have access to the CBDC, and what are the rules and criteria for that access?
  4. What are the rules and access criteria for financial intermediaries and foreign exchange providers?
- Communication
  5. What data and messaging standard(s) do the system support?
  6. Are we following the guidance from CPMI on ISO 20022 implementation?
  7. What standards are used for payment initiation (for example, proxies, QR code, NFC)?
  8. What digital ID framework is necessary to ensure smooth and efficient cross-border transactions?
  9. Is the system or the wallet providers responsible for identifying that it is a cross-border payment?
  10. Should there be a national gateway for any formal interlinking with other systems?
- Currency conversion
  11. Who is providing foreign exchange and how are end users matched with the foreign exchange provider?
  12. What is the role of the central bank in facilitating foreign exchange transactions and liquidity?
- Compliance
  13. How will international AML/CFT standards be incorporated into the system's compliance framework?
  14. Who is responsible for AML/CFT compliance checks (including KYC)?
  15. Who is responsible for CFM compliance checks?
  16. Should AML/CFT compliance checks (including KYC) be automated and/or centralized?
  17. Should “smart CFMs” be implemented, and at what level?
- Settlement
  18. Should the system offer programmability options, for example, smart contracts, to facilitate PvP?
  19. Should a centralized trusted oracle/CCP be part of the baseline CBDC ecosystem?

### Annex insights: traditional arrangements and design implications
- Annex I (Traditional Arrangements through the Lens of the Five Elements) maps correspondent, closed loop, and aggregator models across Access, Communication, Currency conversion, Compliance, and Settlement (detailed table in the source).
- Annex II (eNaira as a Payment Option for Inbound Remittances) summarizes the Central Bank of Nigeria operational framework for IMTOs and eNaira, including the stepwise procedure for IMTOs to prefund CBN accounts and receive eNaira equivalent. Key procedural steps:
  1. IMTOs are to apply for a one-time “No Objection” to pay out in eNaira from the CBN.
  2. The CBN shall provide account details where foreign currency from the IMTOs shall be received.
  3. IMTOs are required to open Merchant Wallets through the CBN.
  4. IMTOs are to prefund the CBN account mentioned in (2) above with foreign currency.
  5. The CBN will subsequently fund the IMTO Merchant Wallet with eNaira equivalent of the foreign currency earlier prefunded by the IMTO.
  6. Payment procedure shall be as follows:
     a. Sender initiates diaspora transfer with IMTO of choice overseas providing details of beneficiary’s wallet,
     b. IMTO logs into the eNaira web wallet portal, debits its eNaira Merchant wallet, and credits beneficiary with eNaira equivalent of foreign currency sent at origin using I&E window rate, or
     c. Alternatively, IMTO integrates with the eNaira portal from its platform via API provided by CBN and initiates transfer of eNaira equivalent of foreign currency sent at origin at the I&E window rate.
- Annex III (Foreign Exchange Provider Restrictions) outlines possible transaction or holding limits, potential use of a “waterfall model” for handling limits, alternatives including central bank active participation (redeem and issue CBDCs), overnight sweeping of accounts, and special rules granting foreign exchange wallets the same status as wholesale CBDC or reserves.
- Annex IV (Design Implications of the Icebreaker Protocol) describes the Icebreaker payment process in eight phases:
  Phase 1: Payer enters currency and amount, and the payer wallet sends a quote request to the hub.
  Phase 2: The hub retrieves the best available quote from its foreign exchange database and responds with the best quote and the identity of the associated foreign exchange provider.
  Phase 3: If the payer accepts the quote, she proceeds by entering the payee’s payment address/alias and the payer wallet sends a payment request to the payee wallet.
  Phase 4: The payee wallet validates its wallet address and generates a secret and sends the verification results and returns a hash value of the secret to the payer wallet.
  Phase 5: The payer wallet creates a locked payment to the foreign exchange provider’s payer-currency wallet.
  Phase 6: The foreign exchange provider’s payer-currency wallet sends the payment information and the hash value to the foreign exchange provider’s payee-currency wallet where it creates a locked payment in the payee currency to the payee wallet.
  Phase 7: The payee wallet recognizes there is a locked incoming payment and presents the secret (generated in phase 4) to the smart contract locking the incoming payment, and the funds are released to the payee wallet only if the calculated hash value of the presented secret matches the hash value used to lock the payment.
  Phase 8: The secret is now revealed to the foreign exchange provider’s payee-currency wallet and the secret is sent to the foreign exchange provider’s payer-currency wallet where it presents the secret to the smart contract to unlock the incoming payer currency payment.
- Icebreaker design implications and considerations:
  - Payment initiation: compatibility of QR codes, NFC messages, and aliases with foreign systems; whether wallet providers or systems must identify cross-border payments.
  - Connectivity: whether wallets/PSPs communicate via a hub or through national gateways; different jurisdictions may adopt gateways, PSP nodes, or direct wallet connections.
  - HTLC-based conditional settlement: each CBDC system must be able to implement HTLC-based conditional settlement; HTLC functionality can be implemented in different ways depending on underlying technology.
  - Smart contracts versus trusted escrow agents: DLT systems may use smart contracts as “technical escrow”; non-DLT systems may require a trusted escrow agent to emulate HTLC behavior.
  - Liquidity reservation: production systems might reserve liquidity between quote request and locking phases; design must address potential spamming of quote requests.
  - Approval timing and spamming: three potential places for payer approval (before phase 1, in phase 3, or before phase 5) each have trade-offs between information availability and spamming risk; balancing approval processes and misbehavior rules is necessary.

*FINTECH NOTES  Cross-Border Payments with Retail CBDC: Design and Policy Considerations — INTERNATIONAL MONETARY FUND*

### References

### References

### IMF Fintech Notes, IMF Working Papers, and IMF Policy Papers
- Adrian, Tobias, and Tommaso Mancini-Griffoli. 2023. “The Rise of Payment and Contracting Platforms.” IMF Fintech Note 2023/005, International Monetary Fund, Washington, DC.  
- Adrian, Tobias, Federico Grinberg, Tommaso Mancini-Griffoli, Robert M. Townsend, and Nicolas Zhang. 2022. “A Multi-Currency Exchange and Contracting Platform.” IMF Working Paper 22/217, International Monetary Fund, Washington, DC.  
- Das, Mitali, Tommaso Mancini Griffoli, Fumitaka Nakamura, Julia Otten, Gabriel Soderberg, Juan Sole, and Brandon Tan. 2023. “Implications of Central Bank Digital Currencies for Monetary Policy Transmission.” IMF Fintech Note 2023/010, International Monetary Fund, Washington, DC.  
- He, Dong, Annamaria Kokenyne, Tommaso Mancini Griffoli, Marcello Miccoli, Thorvardur Tjoervi Olafsson, Gabriel Soderberg, and Herve Tourpe. 2023. “Capital Flow Management Measures in the Digital Age (2): Design Choices for Central Bank Digital Currency.” IMF Fintech Note 2023/009, International Monetary Fund, Washington, DC.  
- International Monetary Fund (IMF). 2017. “Recent Trends in Correspondent Banking Relationships: Further Considerations.” Policy Paper, International Monetary Fund, Washington, DC.  
- International Monetary Fund (IMF). 2020. “Digital Money across borders: macro-financial implications.” Policy Paper, International Monetary Fund, Washington, DC.  
- International Monetary Fund (IMF). 2022. “Review of the institutional view on the liberalization and management of capital flows.” Policy Paper, International Monetary Fund, Washington, DC.  
- Lannquist, Ashley, and Brandon Tan. 2023. “Central Bank Digital Currency’s Role in Promoting Financial Inclusion.” IMF Fintech Note 2023/011, International Monetary Fund, Washington, DC.  
- Soderberg, Gabriel, John Kiff, Herve Tourpe, Marianne Bechara, Stephanie Forte, Kathleen Kao, Ashley Lannquist, Tao Sun, and Akihiro Yoshinaga. 2023. “How Should Central Banks Explore Central Bank Digital Currency? A Dynamic Decision-Making Framework.” IMF Fintech Note 2023/008, International Monetary Fund, Washington, DC.  
- Tan, Brandon. 2023. “Central Bank Digital Currency Adoption: A Two-Sided Model”, IMF Working paper 2023/127, International Monetary Fund, Washington, DC.  
- Tourpe, Herve, Ashley Lannquist, and Gabriel Soderberg. 2023. “A Guide to Central Bank Digital Currency Product Development 5P Methodology and Research and Development.” IMF Fintech Note 2023/007, International Monetary Fund, Washington, DC.  

### BIS, BIS Innovation Hub (BISIH), CPMI, and Related Projects
- Bank of Canada and Monetary Authority of Singapore. 2019. “Jasper-Ubin design paper: enabling cross-border high value transfer using distributed ledger technologies.” Accenture, New York.  
- BIS Innovation Hub (BISIH). 2021. “Nexus: a blueprint for instant cross-border payments.” Bank for International Settlements, Basel, Switzerland.  
- BIS Innovation Hub (BISIH). 2023a. “Project Aurora: The power of data, technology and collaboration to combat money laundering across institutions and border.” Bank for International Settlements, Basel, Switzerland.  
- BIS Innovation Hub (BISIH). 2023b. “Project mBridge Update Experimenting with a multi-CBDC platform for cross-border payments.” Bank for International Settlements, Basel, Switzerland.  
- BIS Innovation Hub (BISIH), Bank of France, and Swiss National Bank. 2021. “Project Jura – Cross-border settlement using wholesale CBDC.” Bank for International Settlements, Basel, Switzerland.  
- BIS Innovation Hub (BISIH), Bank of France, Monetary Authority of Singapore, and Swiss National Bank. 2023a. “Project Mariana: Cross-border exchange of wholesale CBDCs using automated market-makers.” Interim Report, Bank for International Settlements, Basel, Switzerland.  
- BIS Innovation Hub (BISIH), Bank of Israel, and Hong Kong Monetary Authority. 2023b. “Project Sela – An accessible and secure retail CBDC ecosystem.” Bank for International Settlements, Basel, Switzerland.  
- BIS Innovation Hub (BISIH), Bank of Israel, Norges Bank, and Sveriges Riksbank. 2023c. “Project Icebreaker: breaking new paths in cross-border retail CBDC payments.” Bank for International Settlements, Basel, Switzerland.  
- BIS Innovation Hub (BISIH), Hong Kong Monetary Authority, Bank of Thailand, the Digital Currency Institute of the People's Bank of China and the Central Bank of the United Arab Emirates. 2022a. “Project mBridge: Connecting economies through CBDC.” Bank for International Settlements, Basel, Switzerland.  
- BIS Innovation Hub (BISIH), Reserve Bank of Australia, Central Bank of Malaysia, Monetary Authority of Singapore, and South African Reserve Bank. 2022b. “Project Dunbar – International settlements using multi-CBDCs.” Bank for International Settlements, Basel, Switzerland.  
- Committee on Payments and Market Infrastructures (CPMI). 2018 “Cross-border retail payments.” Bank for International Settlements, Basel, Switzerland.  
- Committee on Payments and Market Infrastructures (CPMI). 2020. “Enhancing cross-border payments: building blocks of a global roadmap.” Stage 2 Report to the G20, Bank for International Settlements, Basel, Switzerland.  
- Committee on Payments and Market Infrastructures (CPMI). 2022a. “Facilitating increased adoption of payment versus payment (PvP).” Consultative Report, Bank for International Settlements, Basel, Switzerland.  
- Committee on Payments and Market Infrastructures (CPMI). 2022b. “Interlinking payment systems and the role of application programming interfaces: a framework for cross-border payments.” Report to the G20, Bank for International Settlements, Basel, Switzerland.  
- Committee on Payments and Market Infrastructures (CPMI). 2022c. “Liquidity bridges across central banks for cross-border payment.” Analysis and Framework, Bank for International Settlements, Basel, Switzerland.  
- Committee on Payments and Market Infrastructures (CPMI). 2022d. “Improving access to payment systems for cross-border payments: best practices for self-assessments.” Bank for International Settlements, Basel, Switzerland.  
- Committee on Payments and Market Infrastructures (CPMI). 2023. “ISO 20022 harmonisation requirements for enhancing cross-border payments.” Consultative Report, Bank for International Settlements, Basel, Switzerland.  
- Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO). 2022. “Application of the Principles for Financial Market Infrastructures to stablecoin arrangements.” Bank for International Settlements, Basel, Switzerland.  
- Committee on Payments and Market Infrastructures and BIS Innovation Hub (BIS), International Monetary Fund (IMF), and World Bank. 2021. “Central bank digital currencies for cross-border payments.” Report to the G20, Bank for International Settlements, Basel, Switzerland.  
- Committee on Payments and Market Infrastructures and BIS Innovation Hub (BIS), International Monetary Fund (IMF), and World Bank. 2022. “Options for access to and interoperability of CBDCs for cross-border payments.” Report to the G20, Bank for International Settlements, Basel, Switzerland.  
- Society for Worldwide Interbank Financial Telecommunication (SWIFT). 2022. “Connecting digital islands: CBDCs.” Results Report: Phase 2 Experiments, Society for Worldwide Interbank Financial Telecommunication, La Hulpe, Belgium.  

### Financial Stability Board, G7, and Central Bank Publications
- Financial Stability Board (FSB). 2020a. “Enhancing Cross-border Payments—Stage 1 Report to the G20.” Financial Stability Board, Basel, Switzerland.  
- Financial Stability Board (FSB). 2020b. “Enhancing Cross-border Payments—Stage 1 report to the G20: Technical Background Report.” Financial Stability Board, Basel, Switzerland.  
- Financial Stability Board (FSB). 2023. “G20 Roadmap for Enhancing Cross-border Payments: Priority actions for achieving the G20 targets.” Financial Stability Board, Basel, Switzerland.  
- G7. 2021. “Public Policy Principles for Retail Central Bank Digital Currencies (CBDCs).” HM Treasury, London.  
- Bank of England and HM Treasury. 2023. “The digital pound: A new form of money for households and businesses.” Consultation Paper, Bank of England, London.  
- European Central Bank (ECB). 2024. “Sweden joins TIPS – Eurosystem instant payments platform also settles in kronor.” MIP News, February 27.  

### Books and Academic Articles
- Foucault, Thierry, Marco Pagano, and Ailsa Röell. 2013. Market Liquidity: Theory, Evidence, and Policy. New York: Oxford University Press.  
- Mu, Changchun. 2023. "Theories and practice of exploring China's e-CNY." In Data, Digitalization, Decentialized Finance and Central Bank Digital Currencies: The Future of Banking and Money, edited by A. Dombret and P.S. Kenadjian. Boston: De Gruyter, 179–190.  

*Cross-border Payments with Retail CBDC: Design and Policy Considerations NOTE/2024/002*

---


_Source: https://www.imf.org/-/media/files/publications/ftn063/2024/english/ftnea2024002.pdf_
