## insea2026006

## Source details

**Canonical URL:** [insea2026006](https://www.imf.org/-/media/files/publications/imf-notes/2026/english/insea2026006.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/imf-notes/2026/english/insea2026006.pdf.md)
- [Structured JSON version](/-/media/files/publications/imf-notes/2026/english/insea2026006.pdf.json)

---

### Introduction — purpose, scope, and framework
- Purpose: identify emerging trends in tokenized finance and examine policy questions; "does not take a normative stance on policy choices" and "highlights implications and trade-offs to inform and guide policy dialogue and decision making."
- Focus: "frontier developments and novel questions affecting policy," with primary emphasis on money and other financial assets, including securities and derivatives.
- Three-part structure:
  - Part 1: infrastructure developments—governance models, interoperability, public sector role.
  - Part 2: innovations in financial assets—tokenized deposits, stablecoins, tokenized central bank reserves.
  - Part 3: possible evolution of financial market infrastructures drawing on earlier discussions.
- Three-layer analytical framework:
  - Infrastructure layer (bottom): rails and rules, databases, platforms, systems, operators, third-party service providers; tokenized example: the blockchain and rules for ownership and transaction validation.
  - Asset layer (middle): money and other financial assets associated with issuers and their balance sheets; tokenized examples: stablecoins, tokenized deposits, tokenized central bank reserves, tokenized securities, tokenized money market funds.
  - Services layer (top): asset management, fraud detection, customer due diligence, transaction monitoring; tokenized examples: wallets and exchanges.

### Definitions, technical features, and composability
- Tokenization: "the process of creating a digital token on a blockchain that represents an asset—either natively (the asset exists only on-chain) or as a representation of an off-chain asset."
- Core blockchain and smart contract features:
  - Blockchain as a shared ledger applying standardized transaction rules; can reduce reconciliation and reporting costs by synchronizing multiple copies of the ledger.
  - Smart contracts: code-based instructions stored on the blockchain executing predefined rules when triggered.
  - Composability: smart contracts can call each other; a single transaction can trigger sequential contract executions.
  - Atomicity: multi-step transactions are indivisible—either all state changes record successfully or the entire sequence reverts.
  - Governance: rules for transaction validation, protocol upgrades, and parameter adjustments; clear governance strengthens trust and operational resilience.

### Infrastructure layer — observed shifts, architectures, and public-sector options
- Observed market-structure shifts:
  - Decoupling of asset issuance from infrastructure operation: issuers need not build proprietary infrastructures; service providers can develop on shared infrastructure.
  - Example configuration: stablecoins issued by entities (asset layer), accessed via third-party wallets (services layer), settled on public permissionless infrastructures (infrastructure layer).
  - Potential benefit: reduced costs of proprietary systems and greater flexibility for layer-specific evolution.
- Trends and notable private-sector moves (preserve reported facts and dates):
  - Circle, Coinbase, and Stripe favor permissionless ledgers (Ethereum, Solana) while building proprietary ledgers or centralizing elements.
  - Banks historically favored permissioned ledgers; several have announced partial shifts to permissionless ledgers for issuance and transactions (JP Morgan (2026), UBS (FintechNewsCH 2025), Societe Generale (SG Forge 2026)).
  - JP Morgan Coin represents bank deposits and is deployed on Coinbase’s permissionless chain, Base.
  - UBS and others joined Tempo’s testnet to validate payments and explore settlement on a permissionless chain.
  - Société Générale issued EUR denominated stablecoin CoinVertible on Ethereum, Solana, Stellar, and the XRP Ledger.
  - Swift exploration: open-source, blockchain-based and EVM-compatible infrastructure to operate ledger, orchestrate transaction workflows, validate funding commitments, and coordinate interbank processes (Swift 2026).
  - Group of large US banks (including JPMorgan Chase, Bank of America, Citigroup, and Wells Fargo) announced a new network to clear tokenized deposits to be operated by The Clearing House (TCH); TCH currently clears nearly $2 trillion dollars per day; from early 2027 the new network will help banks clear tokenized deposits, with settlement taking place in central bank reserves.
- Technical and privacy developments:
  - Zero-knowledge proofs (such as zk-SNARKs) in early production use to verify compliance without revealing personal data.
  - Encryption methods under development to allow computations on encrypted data so transactions can be validated without exposing details.
  - Institutional-grade security via multi-signature governance and threshold cryptography.
- Layer distinctions and scaling:
  - Private vs public: who can access the blockchain; permissioned vs permissionless: who can validate transactions.
  - Layer 2 blockchains are scaling solutions operating off the main chain and rely on the base layer for security, settlement finality, data integrity, and dispute resolution.
- Architecture models for ledger relationships:
  - Single ledger model:
    - All owners access same ledger; enables natural interoperability and perfectly atomic transactions; creates single point of failure and concentration risks.
    - Closest practical examples: a central securities depository (CSD) subset; Circle’s Arc blockchain.
  - Compatible ledger model:
    - Assets on separate ledgers; owners have access to both; an orchestrating entity passes transfer instructions concurrently.
    - Examples: ECB’s T2S platform; Swift’s trial ledger; TCH’s ledger.
    - Does not fully support atomic settlement; increases operational risk for DvP and PvP but is easier to implement.
  - Common ledger model:
    - Owners access only their native ledger; assets moved to a ledger common to transacting parties; allows interoperability and atomicity via reissuance but introduces settlement and counterparty risk as the common ledger operator manages a balance sheet and holds assets in escrow.
    - Examples: central bank RTGS; correspondent bank arrangements; firms like Thunes.
- Public sector roles and options:
  - Operate key infrastructures when systemic with strong network effects.
  - License private operation within strict limits (current FMI practice: private ownership with licensing and intensive supervision).
  - Provide safe settlement assets (central banks provide ultimate settlement in central bank money) and operate infrastructure backbones.
  - Synchronize on-chain transactions with RTGS systems or directly operate blockchains to tokenize reserves.
  - Central banks may foster convergence and interoperability on minimal common technologies and rules (European Central Bank Pontes and Appia projects aim to enable settlement of tokenized asset transactions in central-bank money; European Central Bank 2026).
  - Consideration: convergence on compatible technology preferable to fragmentation; central bank provision of public infrastructure can alleviate coordination and fragmentation problems.

### Asset layer — tokenized deposits, stablecoins, and tokenized central bank reserves
- Tokenized deposits — three theoretical distribution models and regulatory determinants:
  - Definition: bank liabilities held, recorded, and transacted on a blockchain or other DLT.
  - Model A (retail direct): direct claim on the bank; bank performs due diligence; asset may be recorded on blockchain and accessed through bank-provided wallet.
  - Model B (wholesale distribution): wallet provider or exchange distributes deposit tokens issued by the bank; wallet provider may warehouse tokens or distribute just-in-time; bank may not have direct relationship with end user; wallet provider performs due diligence and transaction monitoring while end user holds a claim on the bank.
  - Model C (tiered distribution): wallet provider acquires a claim on bank liabilities and issues its own token backed by that claim; end user holds a claim only on the wallet provider; wallet provider responsible for due diligence and transaction monitoring.
  - Regulatory determinant: which model prevails depends largely on whether the issuer (the bank) is required to know the holders of its liabilities.
  - If issuers must know holders:
    - Case A allowed (tokens transferable only among bank clients).
    - Case B likely ruled out.
    - Case C possible (tokens circulate among known clients and the token is not strictly a deposit).
  - If banks in Case A have access to a central bank ledger through a bridge or compatible infrastructure, clients of two banks could pay each other with sender’s token extinguished and recipient’s token created, while banks settle claims on central bank infrastructure.
- Stablecoins — distribution, risks, interest policy, and central bank interaction models:
  - Distribution patterns:
    - Stablecoins generally follow Model B (wholesale distribution) or Model C (tiered distribution).
    - "around 25 percent of outstanding USDC stablecoins are distributed by Coinbase and held in wallets of the same firm." (As of March 31, 2025 and 2024, the percentage was approximately 25 percent and 17 percent, respectively.)
    - Stablecoins can be transferred among end users who are not direct clients of the issuer.
  - Legal/regulatory distinctions:
    - In some jurisdictions (including the EU and the UK) all stablecoin holders are expressly granted a legal redemption claim against the issuer.
    - Major jurisdictions seem to converge on banning interest accrual for stablecoin holders (EU under MiCA; US under the GENIUS and CLARITY Acts), though other jurisdictions remain silent and the Financial Stability Board has not taken a formal position.
  - Economic characteristics and money test:
    - Stablecoins resemble securities distribution more than traditional money because of transferability without issuer knowledge.
    - Stablecoins introduce counterparty risk if issuers take excessive risks.
    - Stablecoins do not necessarily pay interest; if they did, prices would fluctuate with demand and interest rates, distancing them from money.
    - The key test of money: whether it can retain its nominal value in all states of the world (redeemable into sovereign currency at face value or broadly accepted "no questions asked").
  - Loss absorption and moral hazard mitigation:
    - Stablecoins would need significant loss-absorption capacity to be considered money; policy inspiration could come from default funds and loss-mutualization funds (prefunded resources in addition to backing assets and equity capital).
    - Alternatives: government backstops such as an investor compensation fund, access to safe central bank reserves, or access to emergency liquidity—trade-offs must be carefully weighed.
  - Four models of central bank involvement (access dimensions: overnight reserves to back issuance; intraday reserves to make payments; emergency reserves for liquidity support):
    - Full service model:
      - Stablecoins fully backed with central bank reserves.
      - Issuer has access to central bank’s payment system, enabling interoperability between issuers.
      - Closest to narrow banking and "synthetic CBDC."
    - Partial service model:
      - Issuers hold a fraction of assets as central bank reserves, with access to central bank payment system and emergency liquidity.
      - Similar to the Bank of England’s recent proposal for stablecoin regulation.
    - Light service model:
      - Issuers only access the central bank’s payment system (interoperability) but cannot hold overnight central bank reserves to back issuance.
      - Similar to the concept of a skinny payment account explored by the Board of Governors of the Federal Reserve System (2025).
    - Self-service model:
      - Issuers have no access to any form of central bank reserves (the prevalent case to date).
  - Additional design points:
    - Each model implies different operational and reputational risks for central banks.
    - Models could be combined with a clearinghouse for stablecoin issuers to guarantee emergency liquidity if an issuer defaults.
    - The full service model could be extended by having the stablecoin issuer distribute CBDC instead of private liabilities, eliminating exposure to private issuer balance sheet risk while preserving issuer roles in technology and services.
  - Open banking and competition at services level:
    - Open banking can inject competition at the services level without creating private money; examples of rapid inclusion gains:
      - India: UPI increased financial inclusion from about 20 percent in 2016 to 75 percent in 2021.
      - Brazil: 67 percent of adults had signed up in a little over a year since Pix launch.
      - Kyrgyz Republic: account ownership grew by 70 percent between 2011 and 2024, with 67 percent of the population making or receiving a digital payment in 2024, and 72 percent having a bank account.
    - Caveat: open banking does not change competition at settlement or money issuance level.
- Tokenized central bank reserves:
  - Central bank money remains the only settlement asset free of private credit risk as a direct liability of the sovereign issuer.
  - If the public sector does not provide an on-chain settlement asset, private alternatives may expand to fill that role carrying credit, market, and operational risk.
  - Central banks exploring making reserves available on-chain to support atomic settlement of tokenized assets, programmability, and interoperability with private ledgers.
  - Tokenized reserves may not change who has access to central bank money, but they would change how that money is held and transferred, preserving central bank money’s role as ultimate settlement asset while allowing wholesale system efficiency gains.

### Financial market infrastructures (FMIs), automation trade-offs, and collateral innovations
- FMIs and blockchain:
  - Blockchain can replicate FMI functions: maintain records of ownership (CSD role), act as trade repository, clear and net exposures like a CCP.
  - Trading, clearing, settlement, and reporting could in principle occur on a single shared infrastructure.
  - Full on-chain automation may be undesirable: risk-model calibration, business continuity, and human judgment require accountable legal entities.
  - Existing standards often require critical infrastructures to restore operations within a short time frame, often within two hours; lack of a responsible entity overseeing a blockchain-based infrastructure complicates compliance and recovery.
- Trade-offs between liquidity and instant settlement:
  - Shorter settlement cycles reduce counterparty and settlement risks, but instant settlement may reduce market liquidity because participants rely on short settlement windows to source assets or funding.
  - Instant and atomic settlement eliminates settlement and counterparty risk; any delay reintroduces these risks and requires mitigation such as prefunding, which imposes liquidity costs.
- FMIs as catalysts and collateral management innovations:
  - Common ledgers connecting multiple custodians and FMIs enable rapid reallocation of collateral, reducing delays and reconciliation needs.
  - CCPs accepting tokenized money or assets as eligible collateral could accelerate adoption, conditional on regulatory frameworks evolving in tandem.

### Key policy questions and conclusions (infrastructure and asset layers)
- Selected infrastructure-level policy questions:
  - Which architectures (permissionless, permissioned, or hybrid) will predominate for different market uses, and how should oversight and regulation be tailored?
  - Do existing legal frameworks recognize infrastructures, smart contracts, and tokens, and do they support settlement finality and enforceable outcomes across architectures?
  - How can governance and accountability be made clear when there is no single operator? How to apply AML/CFT, investor protection, and access eligibility on permissionless infrastructures?
  - What technical capabilities (scalability, privacy, predictable fees, deterministic settlement) are needed for adoption at scale?
  - What standards or governance arrangements ensure interoperability across ledgers and infrastructures?
  - How should operators of common ledgers that intermediate transactions or hold assets in escrow be regulated?
  - Should authorities promote convergence on common technologies, smart contract standards, or legal frameworks to avoid fragmentation?
  - Should central banks continue to operate settlement backbones in central bank money, including in tokenized environments? Should central banks participate in blockchains they do not operate?
  - Under what conditions should private blockchain infrastructures performing systemic functions be licensed and subject to oversight similar to FMIs today?
  - How should authorities address concentration risks and network effects arising in blockchain infrastructures?
- Selected asset-layer policy questions:
  - Can tokenized deposits change the bank–end user relationship, and to what extent must banks maintain direct relationships with deposit token holders?
  - Can distribution models for tokenized deposits and stablecoins be the same?
  - What safeguards ensure stablecoin issuers can absorb losses, maintain stable value, and limit moral hazard?
  - Under which central bank access models (full, partial, light, or none) might it be appropriate for stablecoin issuers to access central bank reserves or payment infrastructure?
  - What role might central banks play in supporting interoperability and stability where private stablecoins circulate widely?
  - What are implications of not providing tokenized reserves for private settlement assets in wholesale markets?
- Conclusions and policy implications:
  - Hybrid solutions between permissionless and permissioned models are emerging; public networks may support connectivity and innovation while governance, validation, and access controls provide predictability for institutional users.
  - Tokenization loosens the link between issuing an asset and operating the infrastructure; private assets may circulate on public infrastructures while public money may interact more closely with private platforms.
  - Single-ledger architectures enable atomic settlement but raise governance, resilience, and contestability concerns; compatible-ledger architectures are more practical near term; common-ledger models introduce counterparty and concentration risks requiring careful backing and safeguards.
  - Public authorities will continue to anchor the system: central banks likely to operate settlement backbones in central bank money, foster convergence toward compatible technologies and legal frameworks, and consider licensing/supervision for private infrastructures taking on systemic functions.
  - For tokenized deposits and stablecoins, multiple distribution and design models are possible, but regulatory choices will be decisive in determining risks, responsibilities, and the extent to which private instruments function as money.

*Source: insea2026006 (IMF Note).*

### Introduction ...........................................................................................................

### Introduction

### Overview and purpose
- Tokenization is defined as "the process of issuing and transferring assets on blockchain-based infrastructures" and is "gaining momentum in financial markets" with significant implications for market structure, risk management, and financial stability.
- The Note aims to identify emerging trends in tokenized finance and to examine policy questions they raise; it "does not take a normative stance on policy choices" and instead "highlights implications and trade-offs to inform and guide policy dialogue and decision making."
- The Note is divided into three parts:
  - First: surveys recent developments in infrastructure with emphasis on governance models, interoperability, and the role of the public sector.
  - Second: surveys innovations in financial assets (tokenized deposits, stablecoins, tokenized central bank reserves).
  - Third: considers possible evolution of financial market infrastructures drawing on earlier discussions.
- Focus: "frontier developments and novel questions affecting policy," with primary emphasis on money and other financial assets, including securities and derivatives.

### Key definitions and scope
- Tokenization (footnote 3): "the process of creating a digital token on a blockchain that represents an asset—either natively (the asset exists only on-chain) or as a representation of an off-chain asset."
  - Potential benefits: streamlining settlement, enabling programmable asset management, facilitating atomic cross-asset transactions.
  - Key risk: legal link between token and underlying asset.
- Blockchain is cited as an example of a "public permissionless distributed ledger technology (DLT)" where many relevant market use cases are developing; the Note also incorporates messages relevant to "non-blockchain DLT, that is, private permissioned networks" (relevant to tokenized deposit liabilities).

### Three-layer analytical framework
- The Note uses a three-layer framework applicable to both traditional and tokenized financial architectures:
  - Infrastructure layer (bottom): "transactions are settled"; includes rails and rules, databases, platforms, systems, operators, third-party service providers. Traditional examples: Swift, TARGET2. Tokenized example: the blockchain and rules for ownership and transaction validation.
  - Asset layer (middle): "the value held by end users—money and other financial assets associated with issuers and their balance sheets." Tokenized assets include stablecoins, tokenized deposits, central bank digital currency (CBDC), tokenized securities, tokenized money market funds.
  - Services layer (top): functions such as asset management, fraud detection, customer due diligence, transaction monitoring; tokenized examples include wallets and exchanges.

### Observed shifts in market structure and business models
- Traditional vertically integrated model:
  - Money issuance and wholesale payments provided through vertically integrated models spanning layers: commercial banks issued deposits and offered services while running much of settlement infrastructure; central banks provided final settlement infrastructure.
- New configurations enabled by tokenization:
  - Decoupling of asset issuance from infrastructure operation—issuers need not build proprietary infrastructures; service providers can develop applications independently on shared infrastructure.
  - Example: stablecoins accessed via third-party wallets (services layer), issued by entities responsible for backing (asset layer), and settled on public permissionless infrastructures operated by many participants (infrastructure layer).
  - Potential benefit: reduced costs of building and maintaining proprietary systems and greater flexibility for each layer to evolve compared with traditional vertically integrated models.

### Emphases for policymakers
- Rapid technological change, broad experimentation, and frequent product announcements make it difficult to identify durable developments and where policy attention should focus.
- The Note extracts and explains emerging trends most relevant for policymakers and highlights policy-relevant questions rather than definitive answers.

### Structure and references in the Note
- Background materials and concise overviews (e.g., Box 1) provide core features of tokenization and technological and governance characteristics underpinning tokenized systems.
- Citations and referenced materials appearing in the Introduction include Agur and others 2025; Aldasoro and others 2023; Cabedo and others (2026); BIS-CPMI (2024); Schär (2021); Duarte et al (2022); BCB (2025); Eroglu et al (2026).
- Figure 1 compares traditional commercial bank money models and the tokenization stack (infrastructure, asset, services layers).

_The Rise of Tokenization, Tobias Adrian, Yaiza Cabedo, and Tommaso Mancini-Griffoli (Introduction section)._

### Box 1. Features of Tokenization

### Box 1. Features of Tokenization

### Definitions and core features
- Tokenization involves issuing assets, or representations of assets, on a blockchain.
- Benefits derive from core features of blockchain technology and smart contracts.
- Blockchain:
  - Functions as a shared ledger that applies standardized transaction rules.
  - Can provide a transparent and consistent record compared with conventional databases.
  - By synchronizing multiple copies of the ledger to maintain a single state of transactions, can reduce reconciliation and reporting costs.
- Smart contracts:
  - Code-based instructions stored on the blockchain that execute predefined rules automatically when a transaction triggers them by calling the smart contract function.
- Composability: smart contracts can interact with and call functions of other smart contracts, so a single transaction can trigger a chain of sequential contract executions.
- Atomicity: when a transaction triggers multiple smart contract calls, the protocol treats them as a single indivisible unit; all resulting state changes are recorded only if every step executes successfully; if any step fails, it reverts the entire sequence, leaving no partial execution.
- Blockchain governance: defines how participants validate transactions, upgrade protocols, and adjust system parameters; clear and pre-agreed governance rules strengthen trust through transparency, while distributed validation and oversight enhance operational resilience by reducing single points of failure.

### Trends in the infrastructure layer
- Three essential questions for the infrastructure layer:
  - Will operation and governance be open to the public (anyone can validate) or closely permissioned?
  - What architecture will allow interoperability of assets across chains?
  - What role could the public sector play?
- Market participants oscillate between permissionless and permissioned architectures.
- Notable private-sector moves:
  - Circle, Coinbase, and Stripe began favoring permissionless ledgers (Ethereum, Solana) but are building proprietary ledgers or centralizing elements to optimize costs, speed, and privacy.
  - Banks have traditionally favored permissioned ledgers for privacy, scalability, accountability, and predictable costs; several have announced partial shifts to permissionless ledgers for issuance and transactions (JP Morgan (2026), UBS (FintechNewsCH 2025), Societe Generale (SG Forge 2026)).
  - JP Morgan Coin represents bank deposits and is deployed on Coinbase’s permissionless chain, Base.
  - UBS and others joined Tempo’s testnet to validate payments and explore settlement on a permissionless chain.
  - Société Générale issued EUR denominated stablecoin CoinVertible on Ethereum, Solana, Stellar, and the XRP Ledger.
- Centralized and hybrid governance models:
  - Regulated financial institutions leverage permissionless networks while incorporating permission controls such as whitelisting to govern who can hold and transact tokens, creating hybrid governance models.
- New infrastructure entrants:
  - Swift is exploring an open-source, blockchain-based and Ethereum Virtual Machine (EVM)–compatible infrastructure; Swift will operate the ledger, orchestrate transaction workflows, validate funding commitments, and coordinate interbank processes, supporting programmable corporate payment flows, foreign exchange Payment versus Payment (PvP), and cash movements for securities transactions (Swift 2026).
  - A group of large US banks (including JPMorgan Chase, Bank of America, Citigroup, and Wells Fargo) announced a new network to clear tokenized deposits to be operated by The Clearing House (TCH); TCH currently clears nearly $2 trillion dollars per day; from early 2027, the new network will help banks clear tokenized deposits, with settlement taking place in central bank reserves.
- Technical and privacy developments:
  - Techniques like zero-knowledge proofs (such as zk-SNARKs) allow users to verify compliance (e.g., not being on a sanctions list) without revealing personal data; these systems are now in early production use.
  - Projects are developing encryption methods that allow computations on encrypted data so transactions can be validated without exposing details.
  - Institutional-grade security is being strengthened through shared control mechanisms like multi-signature governance and threshold cryptography requiring multiple parties to approve a transaction.
- Layer distinctions:
  - For the purpose of this Note, private versus public chains refer to who can access the blockchain, whereas permissioned versus permissionless refers to who can participate in validating transactions.
  - Layer 2 blockchains are scaling solutions that operate off the main chain and rely on the base layer for security, settlement finality, data integrity, and dispute resolution.

### Technology, governance, and infrastructure design choices
- Permissionless vs permissioned trade-offs:
  - Permissionless base layers allow restrictions at higher layers (Layer 2s, smart contracts); fewer constraints at the outset and wide inclusion, with constraints implementable via smart contracts.
  - Permissioned infrastructures parse users at the outset, potentially enabling more scalable settlement and trusted counterparties.
- Examples of permissioned and hybrid designs:
  - Circle’s Arc: a permissioned Layer 1 blockchain operated by approved validators; built-in foreign exchange engine, mechanisms to protect sensitive payment data, PvP settlement; transaction fees paid in USDC.
  - Stripe’s Tempo: Layer 1 blockchain designed for payments at scale; aspires to evolve toward a public permissionless model; fees paid in US$-denominated stablecoins.
  - Coinbase’s Base: an Ethereum Layer 2 blockchain that remains public and permissionless at the base layer while introducing centralized transaction sequencing and validation by Coinbase before transactions are settled in batches on Ethereum.
  - All three are EVM compatible.
- Developer and issuer incentives:
  - Developers favor infrastructures with a large user base and coverage of assets.
  - Issuers prefer infrastructures supported by large and active developer communities.
  - This tends to favor network effects of public permissionless models or convergence toward EVM-compatible infrastructures.

### Architecture design and interoperability models
- Three architecture models for relationships between ledgers, assets, and owners:
  - Single ledger model:
    - All owners have access to the same ledger on which assets are recorded.
    - Enables natural interoperability and perfectly atomic transactions, eliminating settlement risk and reducing counterparty risk.
    - Creates single point of failure and concentration risks; complicates governance as participants must accept the same rulebook.
    - Closest practical examples: a central securities depository (CSD) for securities subset; Circle’s Arc blockchain.
  - Compatible ledger model:
    - Assets recorded on separate ledgers, owners have access to both ledgers.
    - An orchestrating entity passes transfer instructions to both ledgers concurrently so the bond is received only if the payment is made.
    - Examples: ECB’s T2S platform; Swift’s trial ledger; TCH’s ledger.
    - Does not fully support atomic settlement; increases operational risk for Delivery versus Payment and PvP but imposes less centralization and is easier to implement with agreed orchestration and compatibility.
  - Common ledger model:
    - Each owner can only access the ledger on which their asset is recorded; assets are moved to a ledger common to both transacting parties.
    - Allows interoperability and atomicity by reissuing assets on the common ledger but introduces settlement and counterparty risk because the common ledger operator manages a balance sheet and holds assets in escrow; custody becomes central to risk management.
    - Examples: central bank RTGS providing settlement in central bank reserves; correspondent bank arrangements; firms like Thunes offering global services by receiving and paying in any country and settling on the firm’s common ledger in the middle (connects payments across more than 130 countries and in more than 80 currencies).

### Role of the public sector
- Public sector interventions can address coordination failures, network effects leading to concentration/path dependence, and unpriced negative externalities from systemic infrastructure failures.
- Options for public sector involvement:
  - Operate key infrastructures when they are systemic and involve strong network effects.
  - License private operation within strict limits (current practice for FMIs: private ownership with licensing and intensive supervision).
  - Provide safe settlement assets (central banks provide ultimate settlement in central bank money) and operation of infrastructure backbones for payment systems.
  - Synchronize on-chain transactions with RTGS systems or directly operate blockchains on which central banks tokenize reserves.
- Central bank roles and examples:
  - Central banks may foster convergence and interoperability on a minimal common set of technologies and rules while leaving the private sector room to innovate.
  - European Central Bank Pontes and Appia projects aim to provide interoperability between market DLT platforms and Eurosystem settlement infrastructure, enabling settlement of tokenized asset transactions in central-bank money (European Central Bank 2026).
- Considerations:
  - It may not be necessary or possible for central banks to pick an optimal technology; convergence on compatible technology is preferable to fragmentation.
  - Central bank provision of public infrastructure can alleviate coordination and fragmentation problems because private sector participants will seek compatibility with central bank money and infrastructure.

*Source: IMF Note — Box 1. Features of Tokenization*

### Box 2. Key Policy Questions for Trends on the Infrastructure Layer

### Box 2. Key Policy Questions for Trends on the Infrastructure Layer

### Key policy questions (infrastructure layer)
- Which infrastructure architectures (permissionless, permissioned, or hybrid) will predominate for different market uses, and how should oversight and regulation be tailored to the specific risks?
- Do existing legal frameworks recognize the infrastructure, smart contracts and their effects, or the nature of the tokens, and do they support settlement finality and enforceable outcomes across different architectures?
- How can governance and accountability be made clear when there is no single operator? How can anti-money laundering/combating the financing of terrorism, investor protection, and access eligibility rules be applied effectively on permissionless infrastructures?
- What technical capabilities (for example, scalability, privacy, predictable fees, deterministic settlement) are needed for tokenization’s adoption at scale?
- What standards or governance arrangements are needed to ensure interoperability across ledgers and infrastructures?
- How should operators of common ledgers that intermediate transactions or hold assets in escrow be regulated?
- Should authorities actively promote convergence on common technologies, smart contract standards, or legal frameworks to ensure interoperability and avoid fragmentation across private blockchain infrastructures?
- Should central banks continue to operate settlement backbones in central bank money, including in tokenized environments? Should central banks participate in blockchains they do not operate?
- Under what conditions should private blockchain infrastructures performing systemic functions be licensed and subject to oversight, similar to financial market infrastructures today?
- How should authorities address concentration risks and network effects that may arise in blockchain infrastructures?

### Trends in the asset layer — overview
- The asset layer enables assets to be created, destroyed, and recorded as tokens; the most common financial asset used today is money.
- Retail money primarily exists as commercial bank deposits; wholesale transactions ultimately settle in central bank money (reserves) whenever possible.
- This section considers tokenized deposits, stablecoins, and tokenized reserves.

### Tokenized deposits — models and regulatory implications
- Definition: Tokenized deposits are bank liabilities held, recorded, and transacted on a blockchain or other DLT.
- Observations:
  - Technology should not necessarily change the bank–client relationship, but new technology can prompt evolution in relationships and processes for efficiency and risk reduction.
  - The key question: what will tokenized deposits represent and how will they affect the relationship between banks and end users?
- Three theoretical distribution models (as illustrated in the source):
  - Model A (retail direct): replicates traditional bank–retail client relationship. User A holds a direct claim on the bank; bank performs due diligence; the asset may be recorded on a blockchain and accessed through a wallet provided by the bank. Nothing else changes.
  - Model B (wholesale distribution): a wallet provider or exchange distributes deposit tokens issued by the bank. The wallet provider can warehouse tokens or distribute them just in time; the bank may not have a direct relationship with User B. The wallet provider performs due diligence and transaction monitoring, while User B still holds a claim on the bank.
  - Model C (tiered distribution): a wallet provider acquires a claim on the bank’s liabilities and issues its own token backed by that claim. The end user holds a claim only on the wallet provider (not the bank); the wallet provider bears full responsibility for customer due diligence and transaction monitoring.
- Regulatory determinants:
  - Which model prevails will be dictated largely by regulation, especially by whether the issuer (the bank) is required to know the holders of its liabilities.
  - If issuers must know holders: Case A allowed (tokens transferable only among bank clients); Case B likely ruled out (intermediary undertakes due diligence); Case C possible (tokens circulate among known clients and the token is not strictly a deposit).
  - If banks in Case A have access to a central bank ledger through a bridge or compatible infrastructure (or access to tokenized central bank reserves), clients of two banks could pay each other with sender’s token extinguished and recipient’s token created, while banks settle claims on central bank infrastructure.

### Stablecoins — distribution patterns, risks, and central bank interaction models
- Distribution models:
  - Stablecoins generally follow either the wholesale distribution model (B) or the tiered distribution model (C).
  - Example data point: "around 25 percent of outstanding USDC stablecoins are distributed by Coinbase and held in wallets of the same firm." (As of March 31, 2025 and 2024, the percentage of USDC in circulation held on Coinbase’s platform was approximately 25 percent and 17 percent, respectively.)
  - In many cases, stablecoins can be transferred among end users who are not direct clients of the issuer, allowing global hold and transfer.
  - Whether end users hold a direct claim on the issuer (Model B) or on the intermediary (Model C) depends on regulation; in some jurisdictions (including the EU and the UK) all stablecoin holders are expressly granted a legal redemption claim against the issuer.
- Economic and legal distinctions vs. tokenized treasury bills and deposits:
  - Stablecoins resemble securities distribution more than traditional money in terms of transferability without issuer knowledge.
  - Stablecoins introduce counterparty risk: if issuers take excessive risks, end users may not recoup full value of backing assets.
  - Stablecoins do not necessarily pay interest, unlike a treasury bill; major jurisdictions seem to converge on banning interest accrual for stablecoin holders (EU under MiCA; US under the GENIUS and CLARITY Acts), though other jurisdictions remain silent and the Financial Stability Board has not taken a formal position.
  - If stablecoins paid interest, their prices would fluctuate with demand and interest rate conditions, further distancing them from the concept of money.
  - The key test of an asset being money: whether it can retain its nominal value in all states of the world (i.e., redeemable into sovereign currency at face value or broadly accepted "no questions asked").
- Loss absorption and moral hazard mitigation:
  - Stablecoins would need significant loss-absorption capacity to be considered money; policy inspiration could come from default funds and loss-mutualization funds (prefunded resources in addition to backing assets and equity capital).
  - Market-based mechanisms to channel liquidity to issuers without public backstops merit consideration.
  - Alternatives for loss absorption include government backstops such as an investor compensation fund, access to safe central bank reserves, or access to emergency liquidity; trade-offs must be carefully weighed.
- Possible models of central bank involvement in stablecoins (four models, defined by access dimensions: (1) access to overnight central bank reserves to back issuance, (2) access to intraday central bank reserves to make payments, (3) access to emergency central bank reserves for liquidity support):
  - Full service model:
    - Stablecoins are fully backed with central bank reserves.
    - Issuer has access to the central bank’s payment system, enabling interoperability between different stablecoin issuers.
    - Closest to narrow banking and "synthetic CBDC."
  - Partial service model:
    - Issuers hold a fraction of assets as central bank reserves, with access to the central bank’s payment system and emergency liquidity.
    - Similar to the Bank of England’s recent proposal for stablecoin regulation.
  - Light service model:
    - Issuers only access the central bank’s payment system (interoperability) but cannot hold overnight central bank reserves to back issuance.
    - Similar to the concept of a skinny payment account explored by the Board of Governors of the Federal Reserve System (2025).
  - Self-service model:
    - Issuers have no access to any form of central bank reserves (the prevalent case to date).
- Additional design and policy points:
  - Each service model has different implications for the operational and reputational risk of the central bank.
  - Except for the partial model (where emergency liquidity is backstopped by the central bank), models could be combined with a clearinghouse for stablecoin issuers to guarantee emergency liquidity if an issuer defaults.
  - The full service model is closest to retail CBDC; it could be extended by having the stablecoin issuer distribute CBDC instead of private liabilities, eliminating exposure to private issuer balance sheet risk while preserving issuer roles in technology, client relationships, and services.
  - Open banking can inject competition at the services level without creating private money; examples of rapid inclusion gains where fast payment systems and third-party wallets expanded access:
    - India: UPI increased financial inclusion from about 20 percent in 2016 to 75 percent in 2021.
    - Brazil: 67 percent of adults had signed up in a little over a year since Pix launch.
    - Kyrgyz Republic: account ownership grew by 70 percent between 2011 and 2024, with 67 percent of the population making or receiving a digital payment in 2024, and 72 percent having a bank account.
  - Caveat: open banking does not change competition at the level of settlement or money issuance; if the banking sector is uncompetitive, open banking may not reduce costs to end users unless it addresses fees. In such cases, e-money or well-regulated stablecoins that ensure redemption in any state of the world may be more attractive.

### Tokenized central bank reserves — role and implications
- Central bank money remains the only settlement asset free of private credit risk as a direct liability of the sovereign issuer.
- If the public sector does not provide an on-chain settlement asset, private alternatives (tokenized deposits, stablecoins, or other instruments) may expand to fill that role, carrying varying degrees of credit, market, and operational risk.
- Central banks’ choices about tokenized reserves (whether to issue them, use cases, and infrastructure) will have significant implications for the architecture and resilience of the tokenized financial system.
- At the wholesale layer, central banks are exploring making reserves available on-chain to support atomic settlement of tokenized assets, programmability, and interoperability with private ledgers.
- Tokenized reserves may not change who has access to central bank money, but they would change how that money is held and transferred, preserving central bank money’s role as the ultimate settlement asset while allowing the wholesale system to capture blockchain-based efficiency gains.

*Source: insea2026006 - Box 2. Key Policy Questions for Trends on the Infrastructure Layer (IMF Note).*

### Box 3. Key Policy Questions for Trends on the Asset Layer

### Box 3. Key Policy Questions for Trends on the Asset Layer

### Key policy questions (asset layer)
- Can tokenized deposits change the relationship between banks and end users, and how?
- To what extent do banks need to maintain a direct relationship with deposit token holders, versus allowing distribution through intermediaries?
- Can the same models of distribution apply to tokenized deposits and stablecoins?
- What safeguards could help ensure that stablecoin issuers can absorb losses, maintain a stable value of their liabilities, and limit moral hazard?
- To what extent, and under which models (full, partial, light, or none), might it be appropriate for stablecoin issuers to access central bank reserves or payment infrastructure?
- What role might central banks play in supporting interoperability and stability in systems where private stablecoins circulate widely?
- What are the implications of not providing tokenized reserves for the role of private settlement assets, including stablecoins and tokenized deposits, in wholesale markets?

### Implications of tokenized architecture for financial market infrastructures (FMIs)
- Choices over blockchain architecture will shape how functions currently performed by FMIs evolve in tokenized environments.
- A central question is how much of the processes of issuance, clearing, settlement, and reporting can be automated through technology, and which functions will continue to require accountable legal entities capable of bearing responsibility, exercising discretion, and adapting to stress.
- Blockchain technology can replicate several functions that FMIs perform today and, in doing so, blur some of the distinctions between them:
  - A blockchain can maintain records of ownership, similar to the role of CSDs.
  - A blockchain can function as a repository of transaction data akin to trade repositories.
  - A blockchain can clear and net participants’ exposures like a central counterparty.
  - In principle, trading, clearing, settlement, and reporting could occur on a single shared infrastructure.
- Full on-chain automation of some FMI functions may not be desirable because key activities such as risk-model calibration or business continuity require human judgment and accountable institutions capable of intervening when conditions change or systems fail.
- Existing standards typically require critical infrastructures to restore operations within a short time frame, often within two hours; without a responsible entity overseeing a blockchain-based infrastructure, ensuring compliance with such business continuity requirements or managing orderly recovery and wind-down processes would be difficult.

### Trade-offs between liquidity and instant settlement
- Shorter settlement cycles can reduce counterparty and settlement risks, but instant settlement may not be optimal for all market participants.
- Many market participants sell assets before they are available for delivery and rely on short settlement cycles to source the necessary assets or funding; this flexibility supports liquidity and market functioning.
- Instant and atomic settlement eliminates settlement and counterparty risk by ensuring that trading and settlement occur simultaneously.
- Once any delay is introduced between trading and settlement, settlement and counterparty risks re-emerge and must be mitigated through mechanisms such as prefunding.
- Prefunding can impose liquidity costs and constrain trading activity.

### FMIs as catalysts and collateral management innovations
- The use of blockchain is likely to transform how markets operate today, but the functions performed by FMIs will remain relevant.
- Innovation is emerging in collateral management: new solutions allow market participants to allocate collateral more efficiently to meet margin calls and to move assets more rapidly across jurisdictions.
- Common ledgers connecting multiple custodians and FMIs allow participants to interact seamlessly, facilitating rapid reallocation of collateral across institutions and markets, reducing delays, reconciliation needs, and operational frictions, as all participants share visibility over transactions recorded on the common ledger.
- FMIs are well placed to act as catalysts for change:
  - CSDs provide authoritative records of securities ownership.
  - CCPs bring together virtually all major market participants and set common risk-management and collateral standards.
  - Changes adopted by CCPs—such as accepting tokenized money (including stablecoins, tokenized deposits, and tokenized central bank reserves) or tokenized assets (for example, tokenized treasury bills) as eligible collateral—could materially accelerate and broaden the adoption of tokenization across markets, provided that regulatory frameworks evolve in tandem.

### Conclusions: public sector role, architectures, and asset-layer implications
- The emergence of blockchain technology raises fundamental questions about infrastructures underpinning finance, the nature of assets held and transacted, and the role of the public sector in shaping this evolution.
- Infrastructure layer trends:
  - The contrast between public permissionless and private permissioned blockchains is increasingly giving way to hybrid solutions.
  - Fintech firms that initially favored fully public systems are introducing centralized components to enhance speed, privacy, governance, and cost predictability.
  - Banks that historically relied on private infrastructures are beginning to issue and transact assets on public blockchains.
  - The emerging pattern points toward infrastructures in which public networks support connectivity and innovation, while governance, validation, and access controls provide predictability required by institutional users.
  - For tokenization to scale, infrastructures must also deliver operational reliability and predictable transaction costs.
- Governance and legal questions:
  - In environments without a single operator, accountability is likely to shift away from the operators of infrastructure.
  - Regulatory frameworks are evolving with greater focus on issuers, exchanges, and service providers operating on blockchain networks.
  - Compliance requirements—including anti-money laundering/combating the financing of terrorism controls, investor protection, and eligibility restrictions—can increasingly be embedded through smart contracts or layered technical solutions.
  - Tokenization is loosening the traditional link between issuing an asset and operating the infrastructure on which it circulates; private assets may increasingly circulate on public infrastructures, whereas public money may interact more closely with private platforms.
- Interoperability architectures and trade-offs:
  - Single-ledger architectures offer significant functionality, enabling atomic settlement and eliminating settlement risk, but concentrate activity on a single infrastructure, raising concerns about governance, resilience, and market contestability.
  - Compatible-ledger architectures, in which assets remain on separate ledgers but transactions are coordinated across them, appear more practical in the near term as they impose fewer governance constraints.
  - Common-ledger models facilitate interoperability through an intermediary ledger but introduce counterparty and concentration risks that must be carefully managed; it is critical in this case to ensure that assets issued on the intermediary ledger remain fully backed by assets held in their native systems.
- Public sector role at the system anchor:
  - Public authorities will continue to play a central role.
  - Central banks are likely to continue operating settlement backbones in central bank money, providing safety, liquidity, and a trusted anchor.
  - Public institutions can foster convergence toward compatible technologies, messaging standards, and legal frameworks, reducing fragmentation while preserving scope for private innovation.
  - Private infrastructures taking on systemic functions may increasingly resemble traditional FMIs and warrant licensing, supervision, and oversight comparable to that applied today to entities such as CSDs and CCPs.
- Asset-layer implications (tokenized deposits and stablecoins):
  - Multiple distribution and design models are possible, but regulatory choices will be decisive.
  - For tokenized deposits, direct issuance by banks to their clients remains closest to the existing institutional framework and is likely to remain the default outcome if regulation remains broadly unchanged.
  - Wholesale distribution through wallet providers could expand reach and innovation at the services layer, provided intermediaries are allowed to take responsibility for customer due diligence and transaction monitoring.
  - Tiered distribution models, in which intermediaries issue their own liabilities backed by bank deposits, may support further market development but introduce additional counterparty risks and would likely require stronger safeguards to protect end users and ensure full backing.
- Stablecoin-specific conclusions and open policy questions:
  - Stablecoins raise distinct policy challenges; they do not necessarily fully meet the traditional criteria of money, particularly when redemption cannot be guaranteed under all circumstances.
  - Issuing stablecoins requires funding with existing money, whereas deposits can be created elastically by banks (the same is true of reserves for central banks).
  - Stablecoins lack the elasticity that characterizes the traditional monetary system.
  - Stablecoins can be transferred peer to peer between end users who do not necessarily have a direct contractual relationship with the issuer, nor are known to it; as such, stablecoins do not appear to be money.
  - The key question is why certain securities, like the treasury bills that back stablecoins, are not themselves able to be transferred as seamlessly including across borders as stablecoins.
  - Maintaining stable value requires credible loss-absorption mechanisms:
    - Current models rely mainly on reserve asset requirements and issuer capital buffers.
    - Complementary arrangements may be considered, such as mutualized risk-management mechanisms for stablecoin issuers, akin to clearinghouse arrangements in derivatives markets, to distribute losses across participants while reinforcing market discipline.
  - Public backstops—such as access to central bank liquidity or insurance mechanisms—may be considered to varying degrees, subject to careful calibration to limit moral hazard.
  - A central policy question concerns the extent to which stablecoin issuers should have access to central bank reserves and payment infrastructures; possible models range from full reserve backing with access to central bank settlement systems—approaching synthetic CBDC—to lighter arrangements that grant access to payment infrastructures without reserve backing.
  - At present, most stablecoins operate under a self-service model with no direct central bank access; emerging regulatory proposals are exploring options.

*Source: insea2026006 - Box 3. Key Policy Questions for Trends on the Asset Layer*

---


_Source: https://www.imf.org/-/media/files/publications/imf-notes/2026/english/insea2026006.pdf_
