## wpiea2022217-print-pdf

## Source details

**Canonical URL:** [wpiea2022217-print-pdf](https://www.imf.org/-/media/files/publications/wp/2022/english/wpiea2022217-print-pdf.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/wp/2022/english/wpiea2022217-print-pdf.pdf.md)
- [Structured JSON version](/-/media/files/publications/wp/2022/english/wpiea2022217-print-pdf.pdf.json)

---

### 1. Introduction — systemic problems, objectives, and scope
- Cross-border payments are often slow, expensive, and risky; international level lacks coordination and public goods present domestically.
- G20 endorsed a Roadmap for Enhancing Cross-Border Payments in October 2020 comprising 19 Building Blocks to achieve faster, cheaper, more transparent, and more inclusive cross-border payment services.
- Twofold objectives:
  - Encourage discussion on multilateral platforms to enhance cross-border payments.
  - Stimulate provision of key international public goods and infrastructures.
- Proposed solution: a multilateral exchange and contracting platform (X-C) to:
  - Centralize payments and settlement and integrate cross-border functionality (streamline compliance, reduce FX conversion cost, better manage financial risks).
  - Leverage common ledgers with unique states, programmability/smart contracts, and encryption for privacy.
- Fundamental frictions addressed:
  - Asynchronous payment flows creating liquidity needs and buffer requirements.
  - Lack of trust/limited communication deterring truthful sharing of financial positions.
  - Separation of trade and settlement enabling reneging, requiring escrow/collateral.
  - Difficulty of systemic monitoring without a common reconciled ledger.
- International public-good gaps highlighted:
  - No common and widely available settlement asset.
  - Multiple currencies requiring FX transactions with high costs; illiquid FX markets increase spreads.
  - Compliance costs (KYC, AML/CFT) and uncertainty about foreign procedures that slow vetting.
- Innovations and context:
  - Builds on Building Block 17 and Building Block 19 of the Roadmap.
  - Extends initiatives with a centralized multi-currency FX trading environment and platform contracts/policies.
- Paper structure:
  - Section 2: X-C architecture and technological requirements.
  - Section 3: governance, compliance, privacy, and capital-flow management interplay.
  - Section 4: spot and derivative FX market organization.
  - Section 5: central bank backstops and platform policy tools.

### 2. X-C Architecture and Design — highlights and objectives
- X-C is a common financial infrastructure for exchange and for entering into and executing financial contracts.
- Key platform functions:
  - Provide an environment for digital monies issued by central banks (“Certificates of Escrow” or CEs) for programmable final settlement in participant countries’ currencies.
  - Shorten payment chains, reduce balance sheet interconnections, and make transactions faster, cheaper, and safer.
  - Open access to bank and non-bank financial entities to increase competition and liquidity in currency pairs.
- Technological features:
  - A single ledger recording participants’ accounts and contracts.
  - Programmability via smart contracts.
  - Encryption of accounts, contracts, and information flows.
- Settlement finality:
  - Settlement risk eliminated by immediate guaranteed settlement at a point in time or guaranteed contracted settlement at future designated dates and states.
  - Messaging, settlement, and committing contracts are linked so cross-border transactions are final and irrevocable.
- Participation and access:
  - Multilateral platform connecting intermediaries across jurisdictions; focuses on “back-end” services.
  - Access envisaged for banks and non-bank financial institutions including PSPs; each jurisdiction decides access.
  - In principle, all participating currencies would be available on the platform.
- Interfacing with domestic systems:
  - X-C complements existing domestic payment systems; central banks provide on-off ramps for funding and redemption of domestic currency.
  - Participants interact via APIs; 24x7 availability of a wholesale RTGS and CE conversion access is important.
  - Modularity allows central banks to pursue CBDC designs without interoperability constraints.

### Certificates of Escrow (CEs) — properties and constraints
- CEs are final settlement assets issued by each participating country’s central bank one-to-one against central bank reserves.
- CE characteristics:
  - Safe and homogenous; no intermediaries’ counterparty risk.
  - Native to the platform and only issued/exchanged within it, avoiding interoperability issues.
  - Can be committed under contracts and escrowed until released by specified contingencies.
- Convertibility and restrictions:
  - CEs are always convertible at par for entities regulated by the central bank and allowed to hold reserves.
  - CEs are not convertible to reserves for non-regulated entities (typically non-residents with platform access).
  - Parity with domestic fiat pinned by competition among regulated entities with reserve access and by central bank commitment to redeem CEs at par; for non-residents parity depends on expectation of counterpart acceptance.
- Deep currency exchange markets are key to ensuring counterparties and avoiding concentration.

### Governance, legal, and risks
- Platform requires common rules, governance, standards, and legal underpinnings across jurisdictions.
- Risks and implementation considerations include:
  - Financial integrity, operational and cybersecurity risks.
  - Financial stability and ecosystem sustainability risks, including adoption risk.
  - Costs, fees, and business-model cost-recovery considerations.
  - Legal uncertainties around smart contracts and cross-jurisdiction insolvency that may affect finality and irrevocability.
- Trade-offs in validation architecture:
  - Centralized ledger: efficiency gains, concentrated risks if attacked or corrupted.
  - Distributed computing: greater resilience; example referenced Project Hamilton’s multi-node deployment.

### Box 2.1 — CE comparisons and experiments (summary)
- CEs open access to central bank liabilities for a broader set of entities (NBFIs, PSPs, non-residents) and provide settlement finality similar to reserves, paper currency, and CBDC.
- Experiments linking instant payment systems and DLT:
  - "TIPS Hash-Link" and "TIPS-Algorand Just in Time Locking" cited as coordination mechanisms.
- Design priorities: fair participation, open access, governance to uphold competition, and public intervention early to avoid market-power extraction.

### 2.3 X-C as a Dynamic Ledger for Contracting — technical building blocks and uses
- Three key technological features:
  - (1) a common and unique ledger with participants’ accounts;
  - (2) programmability (smart contracts);
  - (3) encryption techniques.
- Unique ledger benefits:
  - Maintains mutually consistent shared state; records executed contracts and ownership.
  - Mitigates settlement risks and enables trustless exchanges and rehypothecation/commitments across contracts while enforcing consistency constraints.
- Programmability and smart contracts:
  - Reusable code snippets executed via transaction requests; can read and modify ledger data.
  - Enable PvP/DvP, escrow, atomic swaps, dynamic conditional swaps, auctions, and insurance/risk-sharing contracts without trusted third parties.
  - Atomic swap example: hash function H with secret s where H(s) = x, temporary keys, and short time windows to prevent unilateral reneging.
- Cryptography and privacy:
  - Public/private keys, digital signatures, cryptographic commitments, zero-knowledge proofs enable authorization and compliance checks without revealing sensitive data.
  - Advanced techniques allow computation on encrypted inputs and revelation of aggregates without revealing inputs.
- Contracts governance: “Supervised Open Contracting”
  - Pre-selected participants propose smart contracts; platform operator or governance validates and audits before deployment.
  - Start with templates (e.g., multi-currency auctions, forwards, risk-sharing contracts) and maintain a library of approved smart contracts.
  - Trade-off: openness versus standardization; layered architecture recommended.

### Representative mechanism-design applications
- Limited-commitment exchanges: smart contracts can ensure PvP/DvP with automatic settlement.
- Insurance and risk sharing: encrypted private shocks submitted to smart contracts that compute transfers without revealing private information.
- Auctions: smart-contract-based auctioneers can observe encrypted bids, rank them, and execute outcomes without a trusted third party.

### 3. Compliance, Data, and Privacy — privacy-preserving compliance and CFMs
- X-C leverages cryptography for privacy-preserving compliance, enabling regulators and compliance officers to conduct checks, monitor, and audit while preserving user privacy.
- Two sets of rules impacting cross-border payments:
  - Financial integrity (KYC/AML-CFT) requiring multilateral coordination to build trust in locally generated information.
  - Capital Flow Management Measures (CFMs), typically unilateral rules applied by jurisdictions to resident or non-resident agents.
- Key privacy-preserving design elements:
  - Credential providers issue anonymous credentials linked to off-ledger identity attestation or on-ledger transaction limits.
  - Transactions carry zero-knowledge proofs attesting compliance without revealing sender, recipient, amount, or metadata.
  - Separation of roles (credentialing vs transaction execution) maintains data sovereignty and minimizes exposure.
- Workflow example:
  - Step 1: compliance provider checks a non-encrypted transaction and issues a certificate validating compliance with rule XYZ.
  - Step 2: user submits encrypted transaction plus certificate; platform processes without learning private details.
- Shared on-ledger information and off-ledger bridging:
  - On-ledger CFMs: smart contracts can read and apply CFMs directly (e.g., non-resident tax obligations, required holding periods).
  - Off-ledger CFMs: bridging solutions and reconciliation required; manual administrative permits are harder to automate.

### 3.1 Privacy: separation of roles and cryptographic schemes
- CBDC and payment-system privacy designs decouple controls/authorization from execution using cryptographic proofs.
- Two integrated components:
  - Anonymous credential providers for authorization while preserving identity privacy.
  - Digital signatures, cryptographic commitments, and zero-knowledge proofs to hide transaction details while proving compliance.
- Comparative note: CEs held by supervised domestic entities can be monitored akin to central bank reserves; CEs held by non-resident PSPs may resemble cash in holder anonymity but transactions must still carry compliance proofs.

### 3.2 Sharing identities and vetting across jurisdictions
- X-C can attach cryptographic proofs that participants were vetted (e.g., against sanctions lists) to transactions while keeping personal data local.
- Governance modules (e.g., Amplus) propose local providers onboarding customers overseen by local authority and supranational oversight.
- Incentive structures:
  - KYC providers could monetize onboarding by attaching fee instructions to transactions referencing the validating provider.
- Implementation requires updates to AML/CFT frameworks to cover multilateral platform use and address capacity/gaps.

### 3.3 Capital Flow Management Measures (CFMs)
- CFMs common in EMDEs; interaction with X-C depends on where CFMs apply:
  - On-ledger CFMs: programmable and automatable via smart contracts.
  - Off-ledger CFMs: require bridges to external records; reconciliation challenges may constrain automation.
  - Administrative unilateral CFMs (permits): manual processes limit automation benefits.

### 4. Markets and Contracts for FX — market failures and platform remedies
- FX spreads are a major component of cross-border payment fees; shallow wholesale FX markets drive higher spreads.
- Legacy FX dominated by oligopolistic intermediaries with large balance sheets, creating imperfect competition and price distortions.
- Centralization of information and exchange can:
  - Increase transparency on prices and volumes.
  - Eliminate settlement risk.
  - Improve competition and price discovery.
- X-C distinguishes itself by:
  - Organizing FX exchange in a multi-currency environment using market design theory.
  - Introducing multi-currency auctions and broker-dealer competition on a common platform.
  - Enabling on-platform FX forward and contingent contracts and risk-sharing contracts that exploit programmability and privacy.
- Dynamic ledger role:
  - Prevents double spending and double commitment of rights to future funds.
  - Enables rehypothecation and verification that deliverables will exist at settlement without full escrow.
  - Allows privacy-preserving monitoring of exposures.

### 4.1 Currency exchange illiquidity and hedging contracts
- For EMDEs, FX margins are a significant part of cross-border fees due to underdeveloped wholesale FX markets.
- Improving FX trading infrastructure, risk management, and policy predictability lowers market-making costs and spreads.
- Centralized trading increases transparency and supports market design to reduce market power.

### 4.2 Market design: centralized multi-currency market
- Problems with pairwise trading:
  - Absence of double coincidence of wants.
  - Coordination failures around vehicle currencies.
  - Information decentralization favouring large balance-sheet players.
- Naïve solutions (ample common currency, single large trader, pre-allocated credit) are costly or distortionary.
- Centralized approaches on X-C:
  - Dealer markets with free entry and hittable posted prices can approach competitive outcomes.
  - Centralized multi-currency auctions (agents submit net demand schedules or vectors of buy/sell orders) can generate competitive outcomes and avoid need for a single vehicle currency.
- Auctions with private information:
  - Smart-contract implementation can encrypt bids and compute rank-orders without revealing contents, supporting truthful revelation and mitigating frontrunning.
- Implementation choices:
  - Auction frequency trade-offs: more frequent auctions allow faster reallocation but reduce per-auction depth; seconds/minutes per auction can improve allocative efficiency for some assets.
  - Coordination on anchor contracts and sustainable business models needed for platform adoption.

### Box 4.1 — auctions, liquidity pricing, intertemporal and forward contracts
- RTGS/Liquidity savings: RTGS requires liquidity that LSMs and matching algorithms manage; liquidity can be priced via shadow prices per cluster.
- Intertemporal and forward markets:
  - X-C enables on-platform FX derivative markets and intertemporal markets for CEs.
  - Obstacles: limited commitment and private information; X-C addresses these via pre-programmed verifications and encryption to conceal prior contractual histories until settlement.
  - Dynamic atomic swaps and rehypothecation reduce need for ex-ante liquidity sequestration and allow just-in-time liquidity.
- Risk-sharing and hybrid contracts:
  - Encryption and smart contracts enable mutualization of idiosyncratic risks while preserving incentives for truthful reporting.
  - Hybrid borrowing/lending-insurance contracts combine escrowed maximum payouts, partial indemnities, and preserved incentives under private information.
- Financial stability and ledger consistency:
  - Dynamic ledger checks prevent double commitments and enable verification that deliverables exist at settlement without full escrow.
  - Commitment-of-a-commitment of CE in escrow reduces liquidity costs while guaranteeing settlement.
  - Privacy-preserving monitoring of exposures possible even for nondiversifiable risks.

### 5. Policy Design and Implementation in X-C — central bank tools and coordination
- X-C can implement policies via smart contracts and represent additional assets on the ledger to:
  - Implement domestic or multilateral safety nets.
  - Create FX intervention rules and automatically execute them.
  - Coordinate policies among central banks.
- Central bank roles:
  - Maintain escrow accounts on the platform and trade in spot auctions and other markets.
  - Enable regulated intermediaries to convert reserves to CEs and vice versa.
  - Use escrow and atomic intertemporal swaps for commitments and exchange of CE certificates.
- Issuance of CEs in foreign currencies:
  - A domestic central bank could escrow reserves in a major currency and issue that currency’s CEs on the platform when the issuer does not participate, subject to trust and audit requirements; this resembles a dollar stablecoin issued by a non-US central bank and carries convertibility and credibility risks requiring extreme care.
- Domestic liquidity windows on X-C:
  - Eligible collateral deposited at the central bank can generate on-platform certificates used by smart contracts to demonstrate eligibility to tap liquidity windows.
  - Contingent liquidity via such mechanisms could lower borrowing costs by signaling access to CEs.
- Cross-country liquidity and swap-like arrangements:
  - Smart contracts can operationalize liquidity bridges, swap-like arrangements, or regional financial arrangements with escrowed commitments and atomic swaps.
  - Hybrid borrowing/lending-insurance contracts can create contingent swap lines triggered in stress, requiring cryptographic methods to preserve privacy of positions/policies.
- FX intervention and volatility smoothing:
  - Central banks can submit private contingent bids and volatility-band preferences; smart contracts compute bands satisfying commitments and automatically intervene when limits are breached.
  - Offers an improvement over traditional swap lines and enhances coordination, credibility, and multilateral safety nets.
- Policy design caveats:
  - Requires governance agreements, aligned AML/CFT and legal frameworks, and operational stability planning given platform systemic nature.
  - Interoperability among regional platforms is important to counter geopolitical fragmentation.
  - Further work needed on public-sector vs private-sector roles, business models, and ensuring policy alignment (monetary sovereignty, financial stability).

*Source: wpiea2022217-print-pdf — Working Paper No. WP/2022/217*

### 1. Introduction ........................................................................................................

### 1. Introduction

### Scope and structure of the work
- The document is organized into numbered sections and supporting materials:
  - 1. Introduction ..................................................................................................................................................... 6
  - 2. X-C Architecture and Design ....................................................................................................................... 11
    - 2.1 General Description ........................................................................................................................ 12
    - 2.2 X-C’s Architecture ........................................................................................................................... 13
    - 2.3 X-C as a Dynamic Ledger for Contracting ...................................................................................... 21
    - 2.5. Contracts’ Governance: “Supervised Open Contracting” .............................................................. 27
  - 3. Compliance, Data, and Privacy .................................................................................................................... 28
    - Highlights .............................................................................................................................................. 28
    - 3.1. Privacy in Digital Payment Systems: Separation of Roles and Dedicated Cryptographic Schemes
      .............................................................................................................................................................. 30
    - 3.2: Sharing Identities and Information Across Jurisdictions ................................................................ 32
    - 3.3. Capital Flow Management Measures ............................................................................................ 34
  - 4. Markets and Contracts for FX ...................................................................................................................... 35
    - Highlights .............................................................................................................................................. 35
    - 4.1 Currency Exchange-Market Illiquidity and Hedging Contracts ....................................................... 36
    - 4.2 Market Design: a Centralized Multi-Currency Market .................................................................... 36
    - 4.3 Hedging Risks: Forward and Risk Sharing Contracts and Markets ............................................... 42
  - 5. Policy Design and Implementation in X-C .................................................................................................. 49
  - 6. Conclusions ................................................................................................................................................... 51
  - References ......................................................................................................................................................... 52

### Supporting boxes, figures, and tables enumerated in the Introduction
- Boxes:
  - Box 2.1 How do CEs compare with other payment instruments? ....................................................................... 19
  - Box 4.1. Auctions, smart contracts, and pricing liquidity needs .......................................................................... 42
  - Box 4.2. A Hybrid Model with borrowing, lending, ex-ante insurance, and private information .......................... 46
  - Box 4.3. Concealing histories .............................................................................................................................. 47
- Figures:
  - Figure 2.1. CE issuance and cross-border .......................................................................................................... 15
  - Figure 2.2. Cross-border payment using X-C. .................................................................................................... 16
  - Figure 2.3 Cross-border payments using correspondent banking. ..................................................................... 17
  - Figure 2.4. Hash Time Lock and Commitment, guaranteed instantaneous trade and settlement ...................... 25
  - Figure 2.5. Smart contracts, cryptography, and mechanism design. .................................................................. 26
  - Figure 2.6. X-C as a protocol stack ..................................................................................................................... 28
  - Figure 3.1: Delegating verification using zero-knowledge proofs ........................................................................ 31
  - Figure 3.2: Extending Amplus’ Identification Scheme with Encrypted Certificates ............................................. 34
  - Figure 4.1. Pairwise trade ................................................................................................................................... 37
- Tables:
  - Table 2.1. Alternative types of monies as payment instruments ......................................................................... 19

### Emphasis in the Introduction (as reflected by section headings)
- The Introduction signals the document will cover:
  - Technical architecture and design of X-C, including general description, detailed architecture, and its role as a dynamic ledger for contracting.
  - Governance of contracts under a “Supervised Open Contracting” approach.
  - Compliance, data, and privacy themes with dedicated subsections on privacy, cross-jurisdiction information sharing, and capital flow management measures.
  - Market design for foreign exchange (FX), liquidity and hedging instruments, and centralized multi-currency market structures.
  - Policy design and implementation considerations for X-C, followed by conclusions and references.

*Source: wpiea2022217-print-pdf - 1. Introduction (table of contents and listed boxes/figures/tables).*

### 1.    Introduction

### 1.    Introduction

### Cross-border payments: systemic problems and drivers
- Cross-border payments are often slow, expensive, and risky, exposed to fundamental obstacles to trade.
- Domestic environments benefit from infrastructures and governance that provide payment and financial services; international level lacks coordination, producing insufficient public goods and inefficient arrangements.
- New technologies that may allow transactions to circumvent borders and regulations, and fears of fragmentation from ongoing geopolitical conflicts, compound these issues.
- The international community has long recognized the need for better cross-border payments; in October 2020, G20 Finance Ministers and Central Bank Governors endorsed a Roadmap for Enhancing Cross-Border Payments comprising 19 Building Blocks to achieve faster, cheaper, more transparent, and more inclusive cross-border payment services.

### Objectives of the paper
- Twofold objectives:
  - Encourage further discussion on how multilateral platforms could enhance cross-border payments.
  - Stimulate the provision of key international public goods and infrastructures.
- Present a specific vision for a multilateral exchange and contracting platform (X-C platform) to improve cross-border transactions by:
  - Centralizing payments and settlement and integrating functionality needed for cross-border transactions (streamline compliance, reduce FX conversion cost, better manage financial risks).
  - Leveraging new technologies (common ledgers with unique states, programmability/smart contracts, and encryption for privacy) to organize payments and associated financial markets.

### Fundamental frictions and contractual problems addressed
- Asynchronous payment flows at the agent level create liquidity needs: agents accumulate liquidity buffers, borrow, or enter insurance schemes to withstand net outflows.
- Sharing financial positions is hampered by lack of trust and “limited communication,” deterring truthful information sharing and undermining contracting.
- Trade and settlement are typically separated in time, producing limited commitment and opportunities to renege on pre-entered trades; mitigation requires escrow, collateral, monitoring and audits.
- Bilateral reneging can create contagion and, without a common reconciled ledger, systemic monitoring is difficult.

### Public goods that alleviate frictions domestically (and their absence internationally)
- Domestic public goods and institutions that reduce frictions:
  - Payments and financial market infrastructures.
  - Central bank money as a common settlement asset and potential central bank backstops.
  - Regulation that delineates rules and responsibilities to create trust in intermediaries (including due diligence frameworks and customer standards).
  - Payment infrastructures (e.g., RTGS) that aggregate and clear payment requests; financial markets that allow futures and derivative contracts to manage risks.
- Internationally:
  - No common and widely available settlement asset; banks rely on nostro/vostro accounts or establish regulated branches to access foreign central bank reserves.
  - Multiple currencies require FX transactions, introducing risks and high costs; FX costs are a main driver of cross-border transaction costs.
  - Illiquid FX markets increase spreads charged by intermediaries due to inventory and FX risk; lack of forward swaps and FX derivatives markets exacerbates costs and market power concentration.
  - Compliance costs (KYC, AML/CFT) and uncertainty about foreign institutions’ procedures make cross-border vetting expensive and slow; compliance with CFMs slows transaction processing and complicates legacy-system solutions.
- These three frictions (absence of common settlement asset, FX market frictions, compliance/governance heterogeneity) foster specialization and networks of bilateral correspondent banking, international banking, and closed-loop solutions (e.g., Wise, MoneyGram) with high fixed costs, economies of scale, and concentrated market structures.

### Innovations and related initiatives
- Past and ongoing public and private innovations:
  - Standardized messaging (e.g., Swift) sped up and improved safety of correspondent banking.
  - Netting and settlement improvements for some currencies (e.g., CLS operating in 18 currencies).
  - Regional payment platforms and experimentation interlinking domestic payment systems (examples cited).
  - Fast retail payment systems from private bank clearing associations and central banks; fintechs building credit and insurance on digital payment functions.
  - Wholesale initiatives: large intermediaries developing blockchain-based solutions for instantaneous digital transfers.
  - Solutions leveraging stablecoins and DLT projects using tokens representing national monies; some central bank consortia projects and BIS Innovation Hub collaborations.
  - Projects that focus on tokenized regulated liabilities and AMM approaches to FX markets (examples cited).
- The paper builds on Building Block 17 and Building Block 19 of the Roadmap and extends existing initiatives with a centralized multi-currency FX trading environment and contracts/policies to manage FX risks on the platform.

### X-C platform: two key design aspects
- Aspect 1 — Provide key public goods via platform architecture:
  - A common infrastructure with rules and governance to shorten transaction chains and provide legal certainty.
  - Common settlement assets to reduce settlement risk.
  - A trading environment to trade different settlement assets on the platform.
- Aspect 2 — Combine technological features to address market failures:
  - Three technological features emphasized: (1) one common ledger, (2) programmability (smart contracts), and (3) cryptography (privacy-preserving).
  - Uses:
    - Common ledger to build markets and keep track of ownership of transactions.
    - Smart contracts to read, execute, and modify ledger entries and automatize financial contracts.
    - Cryptography to allow execution without revealing information to irrelevant parties.
  - Applications of these features to address frictions:
    - Limited commitment/reneging: cryptographic commitments, atomic swaps, and automatic transfers.
    - Untrusted messages: domestic certification combined with cryptography to preserve data sovereignty and privacy.
    - Unobserved states generating financial risks: aggregation of information from privacy-preserving messages.
    - Unobserved actions (e.g., front-running): contracts executed by programmed rules.

### Economic and market-design grounding
- The design is anchored on contract theory and market design: define how agents should interact, what they should trade, and market organization to overcome market failures.
- Current landscape: large institutions act as dealers, covering currency inventory costs and markups for FX and counterparty risk; market concentration increases markups.
- X-C aims to:
  - Increase competition.
  - Lower spreads.
  - Reduce risks by providing infrastructure, contracts, and markets for just-in-time liquidity transfers, a centralized multi-currency market, and instruments/markets for hedging risks.

### Scope and structure of the paper
- The paper starts with the barebones design of X-C and iteratively adds features to improve cross-border transactions:
  - Section 2: architecture of the platform and key technological requirements.
  - Section 3: how technology can complement governance arrangements and enable more efficient customer due diligence and capital management.
  - Section 4: organization of spot and derivative FX markets to improve market liquidity and risk management.
  - Section 5: application of the same tools for Central Bank backstops and operations on the platform.

*Source: wpiea2022217-print-pdf - 1.    Introduction*

### 2. X-C    Architecture and Design

### 2. X-C    Architecture and Design

### Highlights
- X-C is a common financial infrastructure for exchange and for entering into and executing financial contracts.
- X-C provides an environment for digital monies issued by Central Banks (“Certificates of Escrow” or CEs) for programmable final settlement in participant countries’ currencies.
- CEs shorten payment chains, reduce balance sheet interconnections, and make transactions faster, cheaper, and safer than bilateral private claims.
- X-C opens access to bank and non-bank financial entities, enabling agents from participating countries to transact using all available CEs to increase competition and liquidity in currency pairs.
- Technological features include:
  - a single ledger where participants’ accounts and contracts are recorded;
  - programmability via smart contracts;
  - encryption of accounts, contracts, and information that flows in the platform.
- Settlement risk is eliminated by immediate guaranteed settlement at a point in time or guaranteed contracted settlement at future designated dates and states. Messaging, settlement, and committing contracts become linked so cross-border transactions using X-C are final and irrevocable.

### Key Technological Features
- Unique state of the common ledger:
  - Mitigates settlement risks by recording executed trade contracts or transfers and ownership.
  - Ensures all participants retrieve the same information and trust consistency across observers.
- Programmability:
  - Smart contract code executes via a transaction request to its address.
  - Contracts execute arrangements without a trusted third party; rules for market exchange, contracts, and mechanisms can encode ex ante contingent actions and automate execution.
- Cryptography:
  - Encryption protects message content and authenticity and provides guarantees on authenticity, commitments, and enforcement of contracts.
  - Allows participants to share private information with smart contracts without revealing it to other parties.

### Applications and Contracting Capabilities
- Smart contracts address limited commitment in exchanges and can ensure Payment-versus-Payment (PvP) and/or Delivery-versus-Payment (DvP) without fails.
- Dynamic future and conditional smart contracts:
  - Platform ability to check that a contract has an underlying asset enables rehypothecation and interlinking contracts, saving collateral and conserving liquidity.
- Insurance and risk-sharing agreements can be developed using smart contracts that observe outcomes and agents’ messages while preserving privacy.
- Auctions implemented via smart contracts:
  - Preserve agents’ bids privacy by observing encrypted bids, ranking them, and determining outcomes without a trusted third party.
- Hash-time locked contracts are an example of smart contracts used to eliminate risks in CE exchanges.

### General Description and Objectives
- X-C proposes a multilateral platform to deploy tools for cross-border payments, specifying participation, access, and available assets.
- The platform leverages digital monies issued by central banks to shorten transaction chains and reduce counterparty and settlement risk.
- X-C provides programmable and final settlement in participant countries’ currencies.
- Design aims to increase competition in cross-border payments, enable smaller intermediaries to enter market making and hedging, and better manage risks while addressing central bank concerns over non-resident unsupervised institutions holding fiat.

### Participation, Access, and Currencies
- X-C is a multilateral platform (financial market infrastructure) for cross-border transactions requiring common rules, governance, standards, and technology.
- Focus on “back-end” services: financial intermediaries provide services to final users; platform connects intermediaries across jurisdictions.
- Centralized model with multiple currencies:
  - Participants from different jurisdictions have accounts in the multilateral platform.
  - Platform does not require modifying domestic systems.
  - In principle, all participating jurisdictions’ currencies would be available on the platform.
- Access:
  - Design envisages access by banks and non-bank financial institutions including payment service providers (PSPs).
  - Each jurisdiction decides the entities it gives access to X-C.

### Certificates of Escrow (CEs)
- CEs are final settlement assets for each participating country issued by its central bank and issued one-to-one against central bank reserves.
- Characteristics of CEs:
  - Safe and homogenous; do not carry intermediaries’ risk.
  - Native to the platform and only issued and exchanged within it, avoiding interoperability issues.
  - Can be committed under contracts and escrowed until released by specified contingencies.
- Settlement on platform:
  - Done by transferring value on the platform’s ledger via moving CEs between agents’ accounts.
  - When exchanging different CEs, agents can use smart contracts to eliminate transaction risks.
- Convertibility and restrictions:
  - CEs are always convertible at par for entities regulated by the central bank and allowed to hold reserves.
  - CEs are not convertible to reserves for non-regulated entities (typically non-residents with platform access), reflecting limits on central bank money use for cross-border settlement.
  - Parity of each CE with domestic fiat is pinned by competition among regulated entities with reserve access and by central bank commitment to redeem CEs at par; market differences would be arbitraged by domestic entities.
  - For non-residents, parity depends on expectation of finding counterparts that accept domestic CEs at the same rate as fiat outside the platform.
- Deep currency exchange markets are key for an efficient platform to ensure counterparties and avoid concentration.

### Clearing, Settlement, and Finality
- Platform provides PvP and DvP so messaging and settlement (or messaging and committed contracts) are linked rather than separated in time.
- Settlement risk eliminated by:
  - immediate guaranteed settlement at a point in time; or
  - guaranteed contracted settlement at future designated dates and states.
- Cross-border transactions using X-C are final and irrevocable.
- Example process (high level):
  - Intermediaries fund accounts with CEs using reserves (central banks reflect changes in liabilities).
  - Intermediaries exchange CEs at an agreed FX rate via oracles, bilateral OTC agreements, or centralized trading environments.
  - Residents can instruct PSPs to convert and send foreign CEs to counterparty banks, which credit deposits and cancel IOUs.

### Interfacing with Domestic Systems and Operational Design
- X-C complements existing domestic payment systems and does not require harmonization of infrastructures beyond connection to the platform.
- Central banks provide on-off ramps for funding and redemption of domestic currency.
- Participants retrieve information and send instructions (including contracts) to the platform via APIs.
- Important operational features:
  - 24x7 availability of a wholesale RTGS and access to central bank reserves to CE conversion as the bridge between traditional rails and the platform.
- Modularity:
  - Central banks can develop domestic solutions (including CBDCs) without being constrained by interoperability requirements.
  - Having CEs as a dedicated digital liability for cross-border transactions allows central banks to pursue CBDC designs focused on domestic policy goals.

*Source: wpiea2022217-print-pdf - 2. X-C    Architecture and Design*

### Box 2.1 compares CEs to

### Box 2.1 How do CEs compare with other payment instruments?

### Comparison with other monies
- CEs allow more agents access to central bank reserves, opening access to non-bank financial institutions, NBFIs, and payment-system providers, PSPs, and to non-residents.
- While non-residents may have access to paper currency, in practice this is not useful for high value cross-border transactions or wholesale payments in general.
- Compared with commercial bank deposits and stablecoins:
  - Each country’s CE provides settlement finality.
  - As a central bank liability, a CE is homogeneous and has no counterparty risk, the same as paper currency, reserves, and CBDC.
  - CEs share programmability with stablecoins (see section 1.2).
- Key comparison with CBDCs:
  - Access to CBDCs may vary by country and could potentially be used by non-residents (and thus be useful for cross-border payments).
  - CBDCs may be designed for specific country circumstances and are not expected to be coordinated internationally to be on the same ledger.
  - While CBDCs may be programmable for their users, cross-border transfers are sometimes an afterthought.
  - CEs directly address the need for a multi-currency platform.

### Technology and interoperability (examples and experiments)
- Two experiments linking an instant payment system (TIPS) and DLT-based solutions:
  - "TIPS Hash-Link"
    - Lightweight, API-based and DLT agnostic protocol enabling loosely coupled integration of the market infrastructure with the majority of DLT platforms.
    - Inspired by Hash-Time Locked Contracts (HTLC) but tailored to overcome some HTLC failure scenarios.
    - Leverages TIPS as a trusted escrow for funds and a smart contract to coordinate DvP operations on the DLT in a safe and consistent manner.
  - "TIPS-Algorand Just in Time Locking"
    - Leverages a native feature of Algorand that simplifies DvP transactions guaranteeing atomicity.
    - Requires the two systems to be directly connected to interact with each other.
- Platform automation:
  - Platform actions can be executed by computer code (smart contracts) stored and executed in the platform’s ledger.
  - Financial transactions like cross-border payments, FX conversion, or hedging/risk sharing agreements can be written and enforced as smart contracts.
- Validation architecture choices:
  - Transactions and account changes can be validated by a central authority (“single node”) or by more than one (“multiple nodes”).
  - Example: Project Hamilton deploys 4 nodes.
  - Trade-offs:
    - Centralized ledger: efficiency gains, concentrated risks if attacked or corrupted, concentrated control mechanisms and tools to detect misbehavior.
    - Distributed computing: greater physical infrastructure resilience; Project Hamilton’s phase 1 used DLT to continue access and prevent data loss even with multiple data center failures.
- Platform infrastructure requirements:
  - Platforms must have common rules, governance, and standards, and a technology to reduce risks and costs of exchange (referred to as “infrastructure”).
  - Common infrastructure contributes to increasing transparency in cross-border payments through clearly specified, enforceable procedures.

### Governance, legal, and participation
- New multilateral platforms such as X-C could be operated under different structures with different public/private roles (CPMI-IMF-WB 2022).
- Design priorities:
  - Fair participation requirements, pricing, open access, and governance arrangements that uphold competition and interoperability.
  - Ensuring broad representation in decision making to mitigate challenges from large stakeholders.
- Public sector role:
  - Public intervention from an early stage may be required to allow the development of a platform to progress.
  - If a platform’s uptake is high, the public sector should ensure the platform does not use market power to extract excessive rents from participants (see CPMI, IMF, WB (2022)).
  - Existing global governance structures like the one supporting Legal Entity Identifier (LEI) could be used as a guide (see FSB (2022)).
- Legal and cross-jurisdictional considerations:
  - CEs will require a sound legal underpinning; legal soundness may require arrangements involving multiple legal jurisdictions (see CPMI 2019).
  - Design should consider minimizing the need to harmonize legislation relative to data, digital ID, commercial and financial transactions, insolvency, and central banking and payments.
  - If inconsistencies between national insolvency regimes are not addressed, finality and irrevocability of payments may not be achieved.
  - Governance and contractual agreements between participating countries might require legal reform.
  - Smart contracts still suffer legal uncertainties in many jurisdictions, implying legal risks especially for application of commercial and financial law.

### Risks, costs, and implementation considerations
- Risk management must be incorporated from early stages; risks arise from:
  - Financial integrity, operational and cybersecurity risks.
  - Financial stability, sustainability of the ecosystem around the platforms, and implementation risks (for instance, failing to develop sufficient overall adoption or adoption in targeted participants).
- Costs and fees:
  - Costs associated with establishing and sustaining a multilateral platform should be considered.
  - Fees, prices, and business model should include cost-recovery considerations.
- Design tailoring and interoperability:
  - Specific design could be tailored to the scope of a platform (regional differences).
  - Sufficient compatibility across potential X-C regional platforms is desirable to allow interoperability among them.
- Technical choice trade-offs:
  - Choice between DLT or centralized databases should be weighed against cyber-security, resiliency, and governance differences.
  - A centralized ledger can concentrate data useful for algorithms that automatically detect suspicious activities (e.g., siphoning of funds), but also concentrates systemic risk.

*Source: Box 2.1 and surrounding text from wpiea2022217-print-pdf*

### 2.3 X-C as a Dynamic Ledger for Contracting

### 2.3 X-C as a Dynamic Ledger for Contracting

### Key technological features
- X-C’s three key technological features are:
  - (1) a common and unique ledger with participants’ accounts;
  - (2) programmability; and
  - (3) encryption techniques.53
- These components can be recombined or unbundled depending on the use case to satisfy technological requirements.
- The features are often bundled in blockchain ledgers, but the paper treats them separately and is agnostic about validation procedures (proof of work, proof of stake, or permissioned blockchains).53

### Unique state of the common ledger (feature 1)
- The ledger maintains a unique state of shared information so participants’ accounts are always mutually consistent.
- When a transaction or contract is signed or executed, it causes a state change in the database and updates information retrievable by agents.
- Benefits:
  - Mitigates settlement risks: once a trade contract or transfer is operated on the ledger, agreement and ownership are definitely recorded and verifiable by all in the encrypted ledgers.
  - Enables “trustless” exchanges or transactions.
  - Allows participants to pledge assets they do not have yet but have committed to buy (for instance through rehypothecation of smart contracts).54
- X-C generalizes domestic and cross-border schemes by creating appropriate escrow accounts on a multilateral contracting platform rather than centering around one private balance sheet or a limited function or use case.55,56
- Consistency constraint: because the ledger is common and a unique state is ensured, commitments of assets in one program must be non-conflicting with commitments of the same assets in another program.59

### Programmability and smart contracts (feature 2)
- Smart contracts are reusable snippets of code published into the shared unique ledger; code can be executed via a transaction request to its address.57,58
- Smart contracts can read and potentially modify data recorded in the platform’s ledger.
- Implications:
  - Smart contracts execute contractual arrangements that maximize participants’ outcomes without the need for a trusted third party.62
  - Commitment of assets and non-conflicting executions across smart contract programs are fundamental for safety (important for rehypothecation; revisited in section 4).59
- Applications enabled by programmability:
  - Addressing limited commitment in exchanges to reduce trade failure and counterparty risk.
  - Enabling PvP and/or DvP with no reneging via code-enforced settlement (linked to “instant settlement”).63
  - Supporting escrow accounts and atomic swaps to ensure simultaneous exchange or committed handshake exchanges.
- Atomic swap mechanics (example):
  - Two agents lock CE funds in escrow managed by a smart contract that unlocks only when participants provide temporary key(s) and “shake hands”.64,65
  - The smart contract uses a hash function H with secret s so H(s) = x, enabling the unlocking protocol and preventing unilateral reneging.65
  - Contracts are symmetric (both agents have temporary keys) and incorporate short time windows; funds return to agents if keys are not provided in time.

### Cryptography and privacy (feature 3)
- Encryption protects message content and authenticity, enables controlled revelation to maintain market depth, and secures identities and privacy.
- Key mechanics:
  - Public key encrypts messages; private key decrypts. Private key generates digital signatures verifiable by those knowing the public key.
  - Properties include authenticity verification, non-repudiation, and infeasibility of deciphering without the private key.
- Advanced privacy-preserving cryptography:
  - Enables intermediate states of information (neither fully public nor fully private).
  - Allows computation on encrypted inputs and revelation of aggregate results without revealing initial inputs.61
- Encryption advantages:
  - Solves communication and commitment problems.
  - Makes information flows a design variable in contract design and expands feasible outcomes closer to those without information frictions.60

### Representative applications and mechanism-design uses
- Limited-commitment exchanges:
  - Smart contracts ensure PvP/DvP and eliminate settlement uncertainty from counterparty risk by automating delivery and transfer on commitment.
  - Escrow or rehypothecated commitments can be used; full collateralization is not required for all contracts because penalties and exclusion from future trades can sustain off-escrow arrangements.66
- Atomic swaps and dynamic conditional swaps:
  - Atomic swaps commit agents to simultaneous exchange via hash time lock and temporary keys; dynamic versions can require evidence the seller will possess the asset at delivery, allowing rehypothecation and collateral saving.
- Insurance contracts:
  - Two parties place maximum possible premium in escrow; private shocks are announced encrypted to the smart contract, which computes transfers (indemnities/premiums) without revealing private information to other parties (example in Townsend and Zhang (2020)).
- Auctions:
  - Smart contracts can act as the auctioneer: observe encrypted bids, rank them, determine winner and price, and execute outcomes without a trusted third party. Buyers can audit code to ensure correct mechanism (Vickrey-type incentives referenced).67

### Contracts governance: “Supervised Open Contracting”
- X-C aims to reproduce the Internet’s open, layered, and upgradable architecture in an economically safe and regulatory-compliant fashion.
- Governance model elements:
  - Pre-selected participants could propose smart contracts for deployment.
  - Platform operator or oversight/governance bodies validate proposed smart contracts before integration.
  - X-C would start with “templates” (e.g., centralized multi-currency auctions, forwards, risk sharing contracts) that can be proposed, audited, and adopted.
  - Open contracting and a library of approved smart contracts aim to foster competition and let users design contracts tailored to needs, subject to security and regulatory audits and approval.
- Trade-offs:
  - Openness versus standardization (open-source smart contracts easier to standardize; open standards like ISO20022 require more coordination and governance).
  - A layered architecture and leveraging existing protocols are advised to avoid replacing successful existing standards.

*Source: wpiea2022217-print-pdf - 2.3 X-C as a Dynamic Ledger for Contracting*

### 3. Compliance, Data, and Privacy

### 3. Compliance, Data, and Privacy

### Highlights
- X-C can deal with data, retain privacy, and comply with domestic and international regulations. X-C leverages cryptography to enable regulators and compliance officers to conduct checks, monitor and audit in a privacy-preserving fashion.
- Financial integrity checks and capital flow management measures (CFMs) encompass two sets of rules and regulations that can make cross-border payments slower, riskier, and more expensive.
- In the case of financial integrity, a major challenge is the required harmonization of KYC frameworks which requires multilateral coordination to ensure that the information generated in each country is trusted by others. CFMs are unilateral rules imposed by each country on resident or non-resident agents, so there is no need for inter-jurisdictional agreements.
- Strong privacy can be retained while preventing untraceable transactions by leveraging “credential providers” and control agencies together with cryptographic proofs and checks. This allows decoupling controls and user authorization from transaction submission and execution.
- “Credential providers” issue anonymous credentials, which ensure that only authorized persons can use the system while simultaneously protecting their identities. These credentials can be associated with actions that are outside the system (“off-ledger”) such as identity or with actions inside the system (“on-ledger”) such as limits to certain transactions amounts.
- X-C functionalities allow efficient, privacy-preserving management of locally generated information to identify and vet individuals or firms X-C participants may want to serve (for example, attaching a cryptographic proof that transaction participants were vetted and are compliant with AML-CFT rules).
- When CFMs are applied to holdings within the platform’s common ledger, programmability can greatly simplify transactions involving CFMs. When CFMs involve information generated outside the platform this requires a “bridge” so smart contracts can read that information. CFMs applied by administrative decisions are unlikely to allow for more efficiency.

*This section explains how X-C can deal with data, retain privacy, and comply with regulations. X-C leverages cryptography to enable regulators and compliance officers to conduct checks, monitor and audit in a privacy-preserving fashion. 68 Financial integrity checks and capital flow management encompass two sets of rules and regulations that can make cross-border payments slower, riskier, and more expensive.*

### 3.1 Privacy in Digital Payment Systems: Separation of Roles and Dedicated Cryptographic Schemes
- Current CBDC designs that promote strong privacy while preventing large-scale flows of untraceable money do so by decoupling controls and user authorization from transaction submission and execution, leveraging existing controls agencies and using cryptographic proofs and checks. 70
- Separation of controls from transactions can hide sender, recipient, and amount from intermediaries while providing cryptographic proof that users and transactions are compliant with rules; transactions without a valid proof can be automatically rejected.
- Two cryptographic components are typically integrated:
  - Credential providers issue anonymous credentials that allow only authorized persons to use the system while protecting identities; credentials can be associated with off-ledger actions (attestation by credential providers, e.g., identity) or on-ledger actions (system checks, e.g., transaction limits). 71,72
  - Transactions are authorized using digital signatures and details hidden using cryptographic commitments; transactions carry zero-knowledge proofs that attest compliance without revealing underlying sensitive information. 73,74,75
- Example workflow (illustrated in Figure 3.1 as described):
  - Step 1: a compliance provider checks a non-encrypted transaction against an encrypted version and issues a certificate validating compliance with rule XYZ.
  - Step 2: the user submits the encrypted transaction plus the certificate; the platform processes it without learning private information (sender ID, recipient ID, amount, metadata).
- Trust-minimized separation of components ensures compromise of a single component does not break overall privacy; data sovereignty can be maintained since identity and user information need not leave the country while transactions carry cryptographic proof of authorization.
- Comparative privacy note: A central bank’s CEs held by supervised domestic entities could be monitored akin to central bank reserves, but CEs held by a non-resident PSP could resemble cash—issuer knows issuance but may not see holder identity—while transactions still must carry cryptographic proof of compliance. 76
- Encrypted and confidential data stored across entities can still permit privacy-preserving computations (e.g., smart contracts with proper permission interacting with encrypted data).

### 3.2 Sharing Identities and Information Across Jurisdictions
- Preserving financial integrity imposes costs and frictions in cross-border payments: domestic KYC/AML-CFT compliance creates client data retained by institutions; international vetting lacks common governance and trusted procedures across jurisdictions, and lack of common digital ID standards creates hurdles. 77,78,79
- X-C can manage locally generated information in a privacy-preserving way and attach cryptographic proofs (for instance, a proof that participants were vetted against a sanctioned individuals list) to transactions.
- On-ledger functionality depends on trustworthiness of off-ledger information; provision of identification and vetting services requires governance to ensure trust in information backing transaction proofs.
- G20 and related workstreams emphasize international identification frameworks to enhance cross-border payments. 80
- Governance options and incentive structures:
  - Amplus (2020) governance module: local providers (financial institutions, mobile operators) identify and onboard customers overseen by a local authority; local arrangements overseen by a supranational entity. 81,82
  - KYC providers could monetize onboarding: once a KYC provider on-boards a customer and adds her to a KYC list, transactions on X-C could carry encrypted information of the validating provider and an instruction to add a fee to the transaction paying that provider. This could create markets and incentives for validation services while keeping KYC checks within national borders.
- Implementation considerations:
  - Platform requires close coordination and cooperation to ensure ongoing due diligence and transaction scrutiny across the relationship lifecycle (including KYC, business profile, risk, and source of funds). 83
  - AML/CFT frameworks may need updating to cover multilateral platform use, ensure all relevant actors and activities are subject to regulation and supervision in line with FATF standards, and address capacity and governance gaps.

### 3.3 Capital Flow Management Measures (CFMs)
- CFMs are common, especially among EMDEs, and can be an important barrier to multilateral platform development and cross-border payment improvements. 84,85
- CFMs interact with platform capabilities depending on where and how they are applied:
  - CFMs on the platform’s common ledger:
    - When CFMs apply to holdings within the platform’s common ledger, programmability can greatly simplify compliance: all required information is recorded on-ledger and smart contracts can read and apply CFMs (examples: non-resident tax obligations, required holding periods for CEs).
  - CFMs off the platform’s common ledger:
    - When CFMs apply to holdings that include off-chain balances, bridging solutions are needed so smart contracts can access external information (e.g., commercial bank reporting systems). Reconciliation between on-chain and off-chain records is required; this may create hurdles for some platform propositions (example: Inthanon-LionRock enabling Thailand to enforce non-resident deposit limits).
  - Administrative decisions:
    - CFMs implemented via ad-hoc administrative permits are harder to automate. Manual issuance of permits or human intervention for authorization limits gains from programmability and automation.

*Italic: Source: wpiea2022217-print-pdf - 3. Compliance, Data, and Privacy*

### 4. Markets and Contracts for FX

### 4. Markets and Contracts for FX

### Highlights
- FX spreads play a large role in the fees for cross-border payments and are usually a result of wholesale market underdevelopment. A better trading infrastructure, better risk management, and a more predictable policy environment can contribute to lower FX trading risks and better-functioning for FX markets.
- Currently, FX trade is mostly done through a set of oligopolistic intermediaries who carry different currency inventories. This requires large balance sheets, resulting in imperfect competition and in price distortions. When markets are decentralized or shallower, market power and distortions are usually larger.
- The centralization of information and exchange of FX trading can contribute to improving markets by increasing transparency and by creating incentives to increase competition. It allows for visibility on prices and quantities that are being actively traded. It also allows elimination of settlement risk from transactions.
- X-C is distinguished from other proposals by organizing FX exchange in a multi-currency environment that utilizes market design theory. Intermediaries act as broker dealers and compete to attract trade from clients. Also, multi-currency auctions are introduced as a robust solution that generates competitive outcomes and can be implemented entirely through smart contracts where no third-party auctioneer is needed.
- X-C is also distinguished by enabling participants to hedge FX risks via forward or contingent contracts, allowing on-platform FX derivative contracts and markets for those. Agents can also enter contracts that mutualize idiosyncratic risks though contingent on aggregate shocks. Smart contracts take as inputs the messages of all the agents with private shocks and implements a cross agent allocation.
- X-C’s dynamic ledger can help control and manage financial stability risks from these derivative contracts without requiring full escrow or collateral. The dynamic ledger goes beyond preventing double spending of funds and avoids the double commitment of the rights to future funds that have been contracted with others. As smart contracts are part of the ledger, these can be made to be consistent with each other.
- When there is risk that cannot be diversified, the dynamic ledger can still allow for privacy preserving monitoring of exposures.

### 4.1 Currency Exchange‑Market Illiquidity and Hedging Contracts
- For EMDEs, FX margins play a large role in the fees for cross-border payments (Feyen et al. 2021). This is usually a result of wholesale market underdevelopment: transactions in shallow and illiquid domestic wholesale FX markets are more expensive, and that pricing spills over to retail FX markets. 86
- Where FX markets do not function well, inter-dealer FX market trades are irregular, insignificant, and shallow, and so de facto complementary markets FX hedging instruments do not exist. As a result, FX exchange can be costly for more illiquid currency pairs, and, in certain circumstances, it can reinforce existing players’ market power in cross-border payments.
- A key for well-functioning for FX markets is to reduce FX trading risks. This can be done by providing a better trading infrastructure, better risk management, and a more predictable policy environment. This can result in lower costs and risks of market making, so that this activity can be profitable at smaller spreads. 87
- The centralization of currency trading can contribute to this, as it increases market transparency for participants. Trading rules and mechanisms within centralized structures are also important as these create incentives for a more competitive environment.
- The next subsections present solutions for (1) organizing FX exchange in a multi-currency environment that utilizes market design theory, and for (2) designing hedging contracts to manage risks that utilize contract theory. These solutions distinguish X-C from existing proposals that use new forms of digital money for cross-border payments; these typically take market structure as given and do not discuss how programmability can be applied to improve contracts and markets functioning. 88

*Source: 4. Markets and Contracts for FX — wpiea2022217-print-pdf*

### 4.2 Market Design: A Centralized Multi-C urrency Market

### 4.2 Market Design: A Centralized Multi-C urrency Market

### Problem: pairwise trading, market power, and information decentralization
- FX trade is mostly done through a set of oligopolistic intermediaries who carry different currencies inventories, requiring large balance sheets and resulting in imperfect competition and price distortions.
- Pairwise trading (one currency trades against another as if in a bilateral market or a series of bilateral markets) contributes to the inefficiency of legacy systems and can lead to autarky in simple settings where decentralized pairwise exchanges fail to match demands.
- Where markets are shallower, market power and distortions are usually larger.
- Three conceptual issues clarified by market design considerations:
  - Absence of double coincidence of wants: in segregated bilateral exchanges, low volumes can result because mutually beneficial bilateral exchange may not exist (example drawn from Wicksell (2013) with three traders where centralized exchange enables trade).
  - Coordination failure around a unit-of-account/vehicle currency: even designating a dominant means of payment can produce multiple equilibria and self-fulfilling illiquidity, enabling market power and discouraging participation.
  - Information decentralization: lack of centralized visibility on prices and volumes prevents competitive outcomes; agents with larger balance sheets engage in more trades and can profit from superior knowledge, producing coordination problems, inefficient outcomes, and financial instability.

### Limitations of naïve solutions
- Providing all participants with ample amounts of a common currency would require very large and costly liquidity buffers.
- A common large trader with sufficient inventory creates excessive market power and requires large inventories.
- Pre-allocated credit for currency trade creates exposure to credit risk (example: risks incurred by central clearing counterparties (CCPs)).
- These options are costly or create other distortions.

### Benefits of centralizing information and exchange
- Centralization allows visibility on prices and quantities actively traded, elimination of settlement risk (traders’ financial position can be checked), and recording trades as references for future exchange.
- Centralization supports contracts (see Section 4.3) and can improve price discovery and market depth for illiquid currency pairs, mitigating market power and facilitating cross-border transactions.

### Centralized dealers’ markets: conditions for competitive outcomes
- X-C platform offers two organized approaches: intermediaries (broker dealers) competing on the same platform, and multi-currency auctions.
- Dealer exchanges on a centralized order book can generate competitive outcomes under two conditions:
  - Free entry into market making: all participants can act as dealers and offer terms of trade to attract buyers and sellers, preventing capture of clients and allowing arbitrage.
  - Posted prices must be hard commitments: orders must be honored and dealers not allowed to stock out or renege—posted prices should be “hittable”.
- With multiple active intermediaries offering differing terms, clients arbitrage differences; in a frictionless environment terms should be identical across dealers, leading to Walrasian competitive equilibrium.
- Practical limitation: dealers cannot commit to terms for any possible trade size; hittable quotes are limited to transactions easily fulfilled, leaving room for market power in large trades.

### Centralized multi-currency auctions as a robust solution
- Centralized multi-currency auctions connect trades in all assets simultaneously via preferences and budget constraints, enabling substitution across assets and consistent bidding with budget constraints.
- Different auction designs can generate competitive outcomes:
  - Agents submitting net demand schedules for each currency (Dubey and Sonderman (2009)) guarantees competitive outcomes.
  - Multi-product limit order auctions where participants submit a vector of buy and sell orders for all currencies simultaneously (Dubey (1982)) also generate competitive outcomes.
- Centralized auctions avoid the need for a common currency as the unit of account for pricing is only used to reconstruct relative prices; any currency can be the “numeraire” and pricing is distinct from a role as “vehicle” currency.
- Under competitive allocation in the auction, no arbitrage across currency pairs is possible; with n fiat monies, there are n(n-1)/2 pairs priced in these auctions.

### Multi-currency auctions and private information
- Auctions can be implemented in contexts with private information; mechanisms can be designed to allow price discovery while selecting what information is kept private or made public.
- Mechanism design can provide incentives for truthful revelation and address information rent extraction via pre-coded auction rules.
- The “private-but-contributing-state-of-information” concept handles how private information that is revealed by agents is treated by the mechanism; privacy matters because traders may withhold private valuations if they fear exploitation.
- X-C enables auctions implemented via smart contracts so no third-party auctioneer can see bids of others; bids are encrypted and can be rank-ordered without revealing content (e.g., using FHE methods), inducing truthful bids while preserving privacy and mitigating rent extraction and frontrunning.

### Box 4.1. Auctions, smart contracts, and pricing liquidity needs

### Box 4.1. Auctions, smart contracts, and pricing liquidity needs

### Auctions, liquidity pricing, and RTGS frictions
- Markets can be put in place to manage high frequency liquidity problems (Garratt (2022)).
- End-of-day settlement which separates trade from settlement runs the risk of default.
- Real time gross settlement, RTGS, would require in principle every entity to have sufficiently secured balances to honor all payment requests from others instantly when submitted.
- In practice, liquidity savings mechanisms, LSMs, are adopted in conjunction with RTGS, with computer algorithms to determine who should pay whom and when, once a batch of payment orders are submitted.
- Algorithms used by Central Banks suffer from logjams due to queuing and occasionally fail to find solutions (see Leinonen 2005).
- Liquidity provision can be priced in a market (Garratt (2022)); sophisticated matching and assignment algorithms can be used to optimize who is executing payments with whom and potentially vary composition of subclusters over time.
- Townsend (2022) uses linear programs to solve for efficient market structure and deliver type specific shadow prices for each potential cluster, where the cluster uses internal clearing for its membership.
- Conceptual design: cluster run by a broker dealer with its order book; entry price into a group if the participant is benefiting (paying for liquidity) or a price received if a participant is helping others by providing liquidity.
- Shadow prices are type-specific prices in a price-taking competitive equilibrium that, by design, achieves an efficient outcome.

### Intertemporal and forward contracts on X-C
- Efficient FX forward and risk management is fundamental for achieving low FX transaction costs.
- Jurisdictions with shallow financial markets may have limited availability of forward and risk management products; banks may not offer regular derivative transactions due to perceived scarce market demand and regulatory uncertainty.
- X-C features enable participants to hedge FX risks via forward or contingent contracts by allowing on-platform FX derivative contracts and markets.
- This contributes to a more competitive market structure for cross-border transactions and reduces the determinism of balance sheet size on participants' ability to manage risks.
- Strong complementarity between derivative and spot markets: agents need both an active, liquid, and well-functioning spot FX market, and to be able to price intertemporal trades in their own currency.
- Proposed option: an “on-platform” intertemporal market for domestic currency CE as well as a derivative market for exchanging CEs denominated in different currencies (FX).
- Intertemporal uses:
  - Agents may experience a deficit in a specific currency and want to borrow with promise to repay same currency at a future date; need counterparty lender in that currency.
  - Forward contracts and dynamic currency swaps allow traders to manage future needs and swap two currencies with exchange reversed at a designated future date.
- Two obstacles to currency swaps and lending:
  - Limited commitment: risk of the payer reneging can be solved in the X-C Platform via pre-programmed code that prevents reneging. The contract verifies that the party promising to deliver will have the assets in the portfolio or has contracted to get it. (See Lee, Martin, Townsend (2022a, 2022b).)
  - Private information: supplier must prove she will be in possession of the asset at the future time; information revelation at trade entry can create hold-up problems (see Lee, Martin and Townsend (2022a)).
- Solution to information revelation problem: leverage encryption and the common unique state of the ledger to conceal whether a party has entered a prior agreement, keeping matched partners’ histories secret at time of trade and revealing them only in settlement period.
- X-C eliminates trade failures and reduces need for liquidity buffers:
  - Dynamic atomic swaps allow trade and movement of an asset to be separated in time while maintaining certainty of settlement.
  - Liquidity does not have to be sequestered in advance; no need to store ex-ante liquidity, employ liquidity savings mechanisms, nor rely exclusively on broker dealers.
  - X-C allows just-in-time contracted liquidity management.
- Price discovery and allocation of forward contracts can be implemented with multi-currencies-multi-forward auctions; dimensionality increases with delivery times and auction frequency matters for generating depth and competitive outcomes.

### Risk-sharing contracts and insurance on X-C
- Agents on X-C can be exposed to shocks (including valuation effects from FX rate movements) that call for insurance contracts.
- Under full insurance with full information on shocks and no other obstacles, risk can be mutualized; idiosyncratic shocks can be pooled, aggregate shocks cannot be avoided and more risk-tolerant agents should bear more.
- Risk sharing contracts should be entered into before any information about shocks is realized.
- In realistic environments with private-information shocks:
  - Messages about shocks need to be communicated and incentives must exist for honest disclosure.
  - Encryption allows safe sharing of private-shock information to smart contracts so others do not see the messages, enabling schemes that reduce individual risk exposures.
  - Revealing shocks too quickly can damage insurance possibilities by washing out insurers’ incentives to enter contracts.
- X-C enables:
  - Contracts that mutualize idiosyncratic risks contingent on aggregate shocks.
  - Securitization of risk pools to cater to different investor risk profiles despite limited information.
  - Smart contracts that take as inputs messages of all agents with private shocks and compute cross-agent allocations while ensuring agents retain some risk to induce truthful revelation.
  - Incorporation of information from observable aggregate shocks (e.g., movements in FX rates) to index the pool outcomes.

### Hybrid contracting: borrowing, lending, and ex-ante insurance (Box 4.2)
- Environment: potential borrower with stochastic needs at borrowing time and a lender with varying needs at repayment time; agents agree ex-ante on contingent borrowing and repayment amounts.
- Private shocks make pure borrowing/lending insufficient and full ex-ante risk sharing infeasible.
- Optimal arrangement under information constraints is a hybrid between borrowing/lending and insurance (Townsend (1982 JPE); Townsend (1988)).
- Key features of hybrid contracts:
  - Parties commit resources and can put maximum payout in escrow in advance.
  - Borrower announces shock into code; borrower receives payment from lender’s escrow that includes indemnity for bad shock but is below full insurance to preserve truth-telling incentives.
  - If first party wishes to lend, counterparty puts sufficient income into escrow to repay; interest rate is lower than market borrowing/lending rate, reflecting movement toward more insurance.
  - Hybrid contracts act as flexible risk-sharing arrangements under private information.

### Concealing histories and privacy-preserving allocation (Box 4.3)
- Privacy via encryption and multi-party computation can hide whether borrower is in high or low liquidity need by adding a layer of scrambling in allocation so lender cannot infer borrower’s state.
- Each agent sees outcomes and allocations pertinent to them but not others’ messages; messages are encrypted and code can randomize “as if'' a trusted third party.
- Challenges:
  - Harder to conceal agents' “bids” than in typical auctions because auction outcomes here allocate to all agents over time and parts of outcomes are observable by all.
  - Information carried over to subsequent periods impacts incentives; allocation mechanism must encrypt messages and make inference difficult as allocations are realized.
- Smart contracts must:
  - Implement randomization without knowing underlying states.
  - Ensure no conflicting intertemporal contracts have been entered that undercut the hybrid contract.
- Goal: maximize ex-ante insurance across dynamic paths while mitigating strategic behavior from announcements of private information.

### Financial stability, ledger consistency, and smart contracts
- Market deepening and hedging markets can increase efficiency but unchecked derivatives can create financial stability risks; high interconnectedness or large exposures can be systemic.
- Legacy markets manage such risks with ex-ante prudential regulation; unregulated markets (e.g., shadow banks) can generate contagion risks; DeFi manages risk with high collateral requirements.
- X-C’s dynamic ledger can help manage risks without requiring full escrow or collateral:
  - Single-state ledger prevents double spending and prevents double commitment of rights to future funds contracted with others.
  - Smart contracts as part of the ledger can be made consistent with each other.
  - Platform can require proof that an agent committing to deliver will have the deliverable at expiration date without requiring escrow liquidity; other forward contracts can serve as valid collateral.
  - An original CE put in escrow can be rehypothecated without generating risks.
- For complex hybrid risk-sharing schemes, the dynamic ledger can check that payments will be delivered in different contingencies; the limit to consistency checks links back to the structure of the shared, common ledger.
- Core mechanism for guaranteeing contracts:
  - Record commitments to future resources on shared unique ledger; prevent double commitment (analogous to double spend).
  - Verify that one CE is escrowed at start of a chain of contracts; verification can be automated to check whether any party committing has in his possession the commitment of a CE escrowed somewhere on the platform already.
  - Commitment of a commitment of a CE in escrow (instead of commitment of a CE in escrow) reduces liquidity cost while still guaranteeing settlement.
- Dynamic ledger also allows privacy-preserving monitoring of exposures even when risks are nondiversifiable.

*Source: Box 4.1, Box 4.2, and Box 4.3 from the provided IMF content unit.*

### 5.    Policy Design and Implementation in X-C

### 5.    Policy Design and Implementation in X-C

### Overview
- X-C can be used to implement policies using smart contracts and to represent additional assets on the platform’s ledger, enabling:
  - implementing domestic or multilateral safety nets,
  - creating FX intervention rules and implementing them on the platform,
  - coordinating policies among different central banks.

### Central bank roles on X-C
- Central banks are entities with escrow accounts on the platform and can trade in spot auctions and other markets.
- Special capabilities:
  - Allow regulated intermediaries to convert reserves to CEs (and CEs to reserves).
  - Expand their balance sheet directly by trade on the platform.
- Escrow accounts and atomic intertemporal swaps can be used for central bank commitments and exchange of CE certificates.

### Issuance of CEs in foreign currencies
- X-C is designed to foster trade and settlement in posted CE representation of domestic currencies by domestic central banks.
- Use case: a domestic central bank could escrow reserves denominated in dollars and issue dollar CEs on the platform when a major-currency issuer (e.g., the U.S.) does not participate.132
- Risks and requirements:
  - Requires trust and/or external audits to ensure redeemability of the underlying currency off-platform.
  - This would be equivalent to a dollar stablecoin issued by a non-US central bank native to the platform.
  - Highlights risk of reneging on convertibility to a currency that the issuing central bank cannot itself issue; explore only with extreme care and when mitigations exist.

### Domestic liquidity windows implemented on X-C
- Typical domestic liquidity provision is collateralized; eligible collateral is pledged and liquidity in the form of central bank reserves is provided at a cost.133 134
- Implementation on X-C:
  - Eligible domestic collateral would be deposited at the central bank in advance and a certificate of this security would be issued on the platform.135
  - The certificate need not be tradable; it can serve as an input for smart contracts to demonstrate eligibility to tap liquidity windows.136
  - Contingent liquidity via such mechanisms could lower borrowing costs by signaling access to CEs issued by the central bank.

### Cross-country liquidity, swap-like arrangements, and risk sharing
- Smart contracts can deploy cross-country liquidity via committed borrowing and lending arrangements among participating central banks:
  - Could operate as liquidity bridges137 (if routine),
  - As currency swaps (if exceptional),
  - Or as regional financial arrangements.138
- Implementation mechanics:
  - Central banks can commit via escrow accounts and atomic intertemporal swaps to exchange CE certificates, analogous to credit lines and asset swaps but at an enhanced level.
- Contingency and insurance features:
  - Hybrid borrowing/lending-insurance contracts can act like swap lines called only in times of stress, where the lender does not seek to gain from FX movements—thus providing a subsidy during stress.
  - Cryptography (e.g., homomorphic encryption, MPC) is needed to allow tailoring of swap line contracts while keeping FX positions, policy, and reserve goals private.139

### FX intervention rules and multilateral volatility smoothing
- FX intervention intentions and bids can be aggregated in a privacy-preserving fashion on X-C.140
- Functionality:
  - Each central bank can communicate preferences for volatility bands for FX rates reflecting policy choices, risk aversion, and reserve commitments.
  - Central banks can input contingent bids in auctions; parameters remain private, but smart contracts can compute bands that satisfy all central banks and their reserve commitments and automatically intervene when volatility limits are reached.
- Benefits:
  - Improves on current use of swap lines.141
  - Provides coordination tools and trust building among central banks, expanding access to international financial safety nets.
  - Strengthens central bank credibility by enabling commitments on X-C that imply losses when FX rates move outside agreed bands.142
- Multilateral volatility-smoothing rules can complement risk sharing mechanisms linked to FX volatility.

### Policy design and coordination implications
- X-C enables automated, privacy-preserving coordination of central bank policies but requires:
  - governance agreements,
  - aligned AML/CFT, legal, and regulatory frameworks,
  - reflections on operational stability given platform systemic nature,
  - interoperability of regional platforms to counter geopolitical fragmentation.
- Role considerations:
  - Further work needed on the role of public sector and international organizations in operating/developing platforms.
  - The private sector’s role in ensuring adoption and sustainable business models should be explored.
- Caution:
  - Private solutions are being explored and deployed but may not align with policy objectives such as monetary sovereignty and financial stability, and may create excessive market power or regulatory evasion.
  - The paper offers a public-sector-leveraged technological solution for public policy objectives.

*Source: A Multi-Currency Exchange and Contracting Platform, Working Paper No. WP/2022/217*

---


_Source: https://www.imf.org/-/media/files/publications/wp/2022/english/wpiea2022217-print-pdf.pdf_
