## wpiea2026136-source-pdf

## Source details

**Canonical URL:** [wpiea2026136-source-pdf](https://www.imf.org/-/media/files/publications/wp/2026/english/wpiea2026136-source-pdf.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/wp/2026/english/wpiea2026136-source-pdf.pdf.md)
- [Structured JSON version](/-/media/files/publications/wp/2026/english/wpiea2026136-source-pdf.pdf.json)

---

### How tokenization affects FMIs
- Smart contracts and distributed ledgers can perform a substantial share of the functions now carried out by central securities depositories (CSDs), securities settlement systems (SSSs), central counterparties (CCPs), and trade repositories (TRs), especially where processes are deterministic, rules-based, and data-driven.
- Record-keeping, settlement, collateral transfers and reporting can move on‑chain.
- Code cannot by itself provide legal certainty, bear accountability, or exercise discretion under stress.
- Tokenization does not imply disintermediation, but institutional redesign: the most plausible outcome is a hybrid FMI model, in which smart contracts perform a greater share of operational and transactional functions, while legal entities remain responsible for governance, compliance, risk management, and interventions to preserve business continuity.
- Hybrid arrangements are particularly likely where functions depend on:
  - off-chain inputs,
  - cross-ledger coordination,
  - supervisory access,
  - judgment in the calibration of margins,
  - management of defaults.

### Paper's approach and objective
- Examines shifts across issuance, clearing, settlement, and reporting:
  - asks which CSD, CCP and TR functions can migrate on‑chain, where the main limitations remain, and where hybrid arrangements are likely to emerge.
  - objective: clarify trade-offs and identify how responsibilities may be redistributed between technology and institutions in a tokenized financial system.
- Intended audience: policymakers, supervisors and market participants.
- Intended outcome: support a more systematic assessment of:
  - how existing infrastructures could adapt,
  - how trust and accountability are reallocated between institutions and technology,
  - how efficiency gains can be realized without undermining financial stability.
- Scope note:
  - does not focus on the evolution of payment systems in a tokenized economy but rather on FMIs that deal with securities and derivatives.
  - atomic settlement, asset locks, and prefunding could potentially have an impact on demand for central bank liquidity; exploring this topic is out of scope.

### Transaction lifecycle: issuance, trading, and post‑trading
- Issuance:
  - Creation of the security and its placement in the primary market.
  - Evolved from physical certificates to dematerialized processes where securities are transferred electronically via book‑entry accounts.
  - Process begins with opening an issuance account to record the number of assets created.
  - Accuracy of issuance records is essential to prevent unauthorized securities and to ensure transparency and credibility.
- Trading:
  - Agreement on terms to exchange assets (price, coupons, settlement dates), verification of transaction details, and written confirmations between parties.
  - Trading occurs through matching platforms that bring together buyers and sellers.
- Post‑trading (clearing, settlement, reporting):
  - Clearing:
    - Process of determining obligations of participants.
    - Clearing through a CCP involves novation: the CCP becomes the buyer and the seller of the transaction.
    - CCPs calculate net positions and ensure funds or securities are available to meet commitments.
    - CCPs use multilateral netting to consolidate obligations into a single position per participant, reducing risk.
  - Settlement:
    - Completes transfer of ownership by updating ownership records electronically at a CSD through book‑entry accounts.
    - During the time between trade and settlement (T and T+x), counterparties face risks such as asset destruction, failure to receive the asset, parties reneging on the trade, or delivering an asset without receiving anything in return.
    - To mitigate these risks, counterparties can either fully pre‑fund the assets to be delivered from the moment the trade is entered or use risk management techniques such as providing collateral.
  - Reporting:
    - Providing data on executed transactions to enhance transparency and ensure access for authorities.
    - Accuracy, completeness, and timeliness are essential for effective oversight.
- Coordination needs:
  - Settlement depends on the accuracy of ownership records at the CSD and coordination between intermediaries such as custodians and registrars.
  - Clear operational boundaries and robust reconciliation processes are essential.
  - Parties need to coordinate and reconcile across different IT systems, ledgers, and platforms operated in isolation by FMIs, participants, and intermediaries.

### Risks associated with the lifecycle of a transaction
- Legal risk:
  - Possibility that unexpected application of laws or regulations results in a loss.
  - Includes situations where legal uncertainty renders contracts illegal or unenforceable.
  - Particularly acute in cross‑border settings.
- Operational risk:
  - Deficiencies in information technology systems, human errors, management failures, or system disruptions that may delay, alter, or prevent execution and completion of transactions.
  - Cyber risk is a key subset of operational risk and includes prevention, recoverability, and coordinated crisis management.
- Custody risk:
  - Possibility of loss due to a custodian’s or sub‑custodian’s insolvency, negligence, fraud, poor administration, or inadequate recordkeeping.
- Settlement risk:
  - Possibility that settlement will not occur as expected (one counterparty delivers an asset but does not receive the corresponding payment).
  - Delivery versus Payment (DvP) is a core mechanism designed to mitigate settlement risk by ensuring simultaneous exchange of securities and cash.
  - DvP depends on coordinated processes and standardized messaging between relevant systems and agents.
  - Cash leg typically settled in central bank money or commercial bank money; central bank money generally considered safer due to absence of credit risk.
  - Historical note: Importance of DvP reinforced following the 1987 equity market crisis; the G‑30 recommended its implementation, with the G‑10 subsequently developing its framework (CPSS 1992). DvP is embedded in the CPMI‑IOSCO Principles for Financial Market Infrastructures (PFMIs).
- Credit and liquidity risks:
  - Credit risk: possibility that a counterparty is unable to meet financial obligations when due or at any point in the future.
  - Liquidity risk: when a counterparty fails to meet obligations on time, even if solvent.
  - Both are relevant during clearing and settlement phases when financial obligations crystallize.

### FMIs and how they mitigate risks
- FMIs’ roles:
  - Central to stability, efficiency, and resilience of financial markets.
  - Provide multilateral arrangements for clearing, settlement, and recording of financial transactions to reduce counterparty, settlement, and operational risks, limit contagion, and enhance transparency.
  - Centralization enables netting efficiencies, risk mutualization, and coordinated risk management across participants.
- Scope of FMIs:
  - Range of systems differing in scope, design, and risk‑management responsibilities.
  - Paper focuses primarily on CSDs, CCPs, SSSs, and TRs; payment systems are linked for the cash leg or payment.
- Value proposition:
  - FMIs manage risks across the transaction lifecycle and provide authorities with access to trading and ownership data.
  - Well‑managed FMIs are essential to financial stability.
- Analytical purpose:
  - Presents a benchmark for assessing how FMI functions and addressed risks may evolve in a tokenized environment.

### FMIs relevant to this paper
- Central Securities Depositories (CSDs):
  - Responsible for safekeeping, maintenance, and transfer of securities.
  - Many CSDs act as securities registrars and provide ancillary services such as corporate action processing or securities’ lending.
  - International CSDs support cross‑border transactions by accommodating a range of globally traded instruments.
  - Issuance may occur at a CSD or via official registrar services depending on jurisdiction.
- Securities Settlement Systems (SSSs):
  - Facilitate transfer and settlement of securities by book entry, following predetermined multilateral rules.
  - When securities transactions involve a payment, SSSs ensure Delivery versus Payment (DvP).
  - In many jurisdictions, a CSD operates an SSS (e.g., in the European Union an SSS must be operated by a CSD).
- Central Counterparties (CCPs):
  - Interpose between counterparties, assuming counterparty risk of both sides and ensuring fulfillment of contractual obligations.
  - Reduce risks through multilateral netting and by imposing risk controls on participants.
  - Require collateral from participants and have mechanisms to mutualize losses in case of a participant’s default, thereby reducing systemic risk.
- Trade Repositories (TRs):
  - Provide centralized electronic repositories for transaction data and promote transparency.
  - Especially relevant in OTC derivatives markets where accurate and timely transaction data is vital for risk monitoring.
  - Aggregate and share information with regulators and market participants to reduce systemic risks and support operational efficiency.

*IMF WORKING PAPERS — Financial Market Infrastructures Evolution in a Tokenized Economy (Introduction).*

### Annex 1 — Legal and operational value propositions of FMIs
- FMIs operate under a clear and enforceable legal framework supported by a comprehensive rulebook that defines their rules and procedures, ensuring the validity and enforceability of transactions, reducing uncertainties related to contract execution, asset recovery, and potential disputes.
- In cross-border transactions, FMIs mitigate risks from conflicting legal regimes by adhering to harmonized international principles (PFMIs), establishing mechanisms to resolve jurisdictional conflicts, and ensuring that FMI rules are enforceable in all relevant jurisdictions.
- FMIs implement stringent operational risk management, including cyber risk preparedness, to ensure secure, reliable, and resilient systems with plans for timely recovery and service continuation during major disruptions.
- FMIs mitigate custody risk by:
  - Ensuring safekeeping of assets through robust custody arrangements, clear segregation of participant assets, comprehensive record-keeping, and due diligence on registrars and custodians.
  - CSDs safeguarding the integrity of securities via accurate securities accounts, end-to-end auditing, and rigorous reconciliation processes; verifying initial issuances and reconciling records with issuers, registrars, and agents.
- FMIs mitigate settlement risk through delivery-versus-payment (DvP) and by providing settlement finality that makes transactions irrevocable and unconditional at a legally defined point.
- FMIs prefer settlement in central bank money because it is free from credit and liquidity risks and increases stability relative to commercial bank money.
- FMIs mitigate credit and liquidity (counterparty) risk by:
  - Requiring participants to maintain adequate financial resources, collateral, and risk controls.
  - Conducting daily stress tests (CCPs) and applying loss mutualization via default funds and CCP "skin in the game".
  - Maintaining liquidity buffers such as central bank deposits, committed credit lines, and highly marketable collateral.
  - Using multilateral netting to consolidate bilateral obligations into a single net position per participant, reducing exposures and liquidity pressures; enforceability depends on a legally robust netting framework.

### Annex 1 — FMIs’ ecosystem and governance
- FMI operator responsibilities:
  - Manage operations, set participation rules (the FMI rulebook), and define risk management protocols.
  - Act as a legally accountable entity ensuring regulatory compliance.
- Participant access models:
  - Direct membership, indirect (through an FMI member), or agent frameworks under access criteria in rulebooks.
  - CSD ownership recording models: indirect holdings (CSD records custodian) and direct holdings (CSD registers beneficial owner).
- Roles of key entities:
  - Custodians: credit institutions or investment firms holding beneficial owner accounts; must comply with segregation requirements (omnibus and segregated accounts).
  - Clearing members: direct access to CCPs; contribute prefunded resources to default fund; may extend access to indirect members.
  - Settlement agents: facilitate money leg in DvP; can be central banks (settle in central bank money via RTGS) or commercial banks (settle in commercial bank money); support intraday liquidity via intraday credit operations.
  - Critical service providers: entities like SWIFT and outsourced providers delivering post-trade and optimisation functions.
- FMI rulebook scope:
  - Describes account types, settlement and clearing services, internal/external instructions, rules on investments, collateral management, margin calls, mutualization losses, and ancillary services such as financing.

### Annex 1 — Features of tokenized financial assets and blockchains
- Tokenization: creation of assets or representations of assets on a blockchain; benefits derive from blockchain properties (shared ledger, standardized execution rules, consensus protocols).
- Blockchain coordination mechanisms:
  - Execution rule standardization (smart contracts).
  - Consensus protocol standardization (e.g., proof-of-work, proof-of-stake, permissioned voting).
- Smart contracts:
  - Deterministic code-based instructions executed when transactions call contract functions.
  - Enable composability: smart contracts calling other contracts; atomicity: sequences executed as an indivisible unit (all succeed or all revert).
  - Token contracts maintain ownership records and enforce transfer logic; can include custom functions (blacklisting, automated payments, token-based voting).
  - Token security depends on both protocol and contract design; poor or malicious code can enable unauthorized freezes or arbitrary balance adjustments—thorough review and auditing are essential.
- Privacy and supervisory implications:
  - Shared ledgers could allow supervisors to verify data directly on-chain, improving consistency and reducing fraud opportunities.
  - Greater transparency raises privacy concerns; privacy-preserving technologies include ZkLedgers, privacy pools, or homomorphic encryption for tokens.
- Blockchain governance dimensions:
  1. Bookkeeping/consensus
  2. Transaction validation
  3. Access
  4. Upgrade policy
- Governance trade-offs:
  - Open validation and broad data access preserve trustless verification; restricting validation centralizes oversight and introduces single points of failure.
  - Upgrade policy is critical: changes can affect consensus, execution rules, security, and economic incentives.
  - Smart contract-level governance is subordinate to blockchain-level governance; blockchain-level sets the baseline.
  - Reverse dependencies: dominant assets or protocols can capture governance influence (e.g., dominant stablecoin issuer influencing upgrade policy).
- Scaling approaches:
  - Succinct validity proofs (zero-knowledge verification in the narrow sense of succinctness) allow small proofs to attest to correct state transitions without full re-execution.
  - Layer 2 mechanisms (linked state channels, optimistic rollups, zero-knowledge rollups) aggregate transactions and confirm aggregated state on base blockchain; base layer acts as settlement and dispute resolution.

### Annex 1 — Architecture models for tokenized systems
- Three architecture models (relationships between ledgers, assets, and owners):
  1. Single ledger model: all owners have access to the same ledger where assets are recorded; enables simplicity and atomicity but broad single-ledger examples are limited in practice.
  2. Compatible ledger model: assets recorded on separate ledgers but owners have access to both; an orchestrator passes instructions concurrently to ledgers (example: ECB’s T2S coordinating RTGS with CSD ledgers).
  3. Common ledger model: each owner accesses only the ledger where their asset is recorded; intermediaries (e.g., central bank or correspondent bank) receive assets, hold in escrow, and issue liabilities for settlement.
- Trust assumptions:
  - Single-ledger: trust in the ledger and token contracts.
  - Common-ledger: trust in native asset ledgers, the common ledger, and asset contracts.
  - Compatible-ledger: trust in native ledgers and orchestrating entities.
- Atomicity and reconciliation:
  - Strict atomicity only guaranteed on a unified ledger; cross-ledger transactions require intermediaries and additional assumptions (ledgers being live and immutable).
  - Reconciliation remains necessary when multiple ledgers register ownership; designating authoritative ledger is key (canonical chain designation in forks).

### Annex 1 — FMI functions in a tokenized world: lifecycle stages and implementation notes
- Tokenized asset lifecycle broadly mirrors traditional lifecycle: issuance, trading, clearing, settlement, reporting.
- Issuance:
  - Single-ledger: native token issuance via token smart contracts; issuance and record-keeping unified.
  - Common-ledger: assets remain on native ledgers and are mirrored or re-issued on common ledger; requires strong technical and legal enforceability.
  - Compatible-ledger: issuance occurs independently on distinct asset ledgers; coordination arrangements required.
  - Standardized token interfaces (e.g., ERC-20) provide consistent log data; token contracts can require additional information for regulatory granularity.
- Trading:
  - On-chain or off-chain trading feasible across models.
  - Single-ledger allows native on-chain trading (e.g., AMMs) enabling atomicity through the same execution environment.
  - Common-ledger allows on-chain trading where assets are mirrored on the common ledger.
  - Compatible-ledger weakens atomicity; off-chain trading forgoes strict atomicity across all models.
- Clearing:
  - Deterministic functions (e.g., novation) more easily automated on-chain; discretionary processes (e.g., margin model adjustments) may require off-chain discretion.
  - Risk model computations and sensitive market price data are likely processed off-chain; resulting margin outputs can be recorded on-chain.
  - Smart contracts can act as counterparties analogous to CCPs; full atomicity for novation and margin pulls feasible in single-ledger, partially feasible in common-ledger, minimal in compatible-ledger.
  - Netting and loss mutualization can be automated on-chain; design and location of prefunded default contributions determine complexity.
- Settlement:
  - Single-ledger: atomic settlement via smart contracts achievable.
  - Common-ledger: atomic settlement within common ledger; cross-ledger relies on bridges or messaging with weaker atomicity.
  - Compatible-ledger: requires trusted third party and prefunding for DvP, DvD, PvP; lacks composability and strict atomicity.
  - Atomicity between netting and settlement reduces exposures and prefunding needs but is limited to single and common ledgers.
  - Settlement finality depends on blockchain consensus rules; probabilistic finality versus stronger finality through thresholds and checkpoints (e.g., contexts like proof-of-work vs fixed consensus resources).
- Reporting:
  - Blockchains can centralize transaction data, enabling direct supervisory access and reducing discrepancies.
  - Token standards (e.g., ERC-20) facilitate standardized events and consistent log data; on-chain recording can reduce reporting obligations.
  - Data distribution varies by model: single-ledger as primary source; common-ledger supplemented by native asset ledgers; compatible-ledger requires aggregation from multiple ledgers and off-chain sources.
  - Public mempool visibility offers supervisory monitoring potential but may be limited by private routing and raises privacy concerns.

### Annex 1 — Risks introduced or altered by tokenization and mitigation options
- General observation:
  - Risks exist at each lifecycle stage (issuance, trading, clearing, settlement, reporting); many are mitigable by architecture choices, privacy-enhancing technologies, legislation, regulation, and accountable legal entities.
- Issuance risks and mitigations:
  - Risks:
    - Weak minting governance enabling unauthorized/excessive issuance.
    - Custody risks for off-chain backed tokens lacking clear legal links to underlying assets.
    - Token contract design flaws or malicious code as attack vectors.
    - Forks creating competing ledger versions and legal uncertainty over canonical chain for redemptions.
    - Reverse dependencies where dominant assets/protocols capture governance.
  - Mitigations:
    - Minting controls: multisig schemes (example thresholds: 2-of-3 or 4-of-7), timelocks, tiered approval requirements.
    - Dedicated custody entities and regulatory/platform rulebook-specified legal links between token and underlying asset.
    - Smart contract audits focusing on governance, restricted functions, and upgradability.
    - Governance and legal frameworks specifying canonical chain choice and fork handling.
- Trading and clearing risks and mitigations:
  - Risks:
    - Concentration and contagion when multiple functions combine on one platform.
    - Liquidity fragmentation across closed-loop platforms and mixed traditional/blockchain markets.
    - Limited atomicity for clearing operations, especially in compatible-ledger models.
    - Operationally undesirable automatic enforcement of margin calls during stressed conditions.
    - Privacy trade-offs: enhanced transparency vs exposure of holdings and mempool visibility facilitating rent extraction via transaction reordering.
    - Oracle dependence with trade-offs in timeliness versus manipulation resistance.
    - Conflicts of law across jurisdictions impacting collateral enforceability.
    - Scalability constraints in single-ledger models and vulnerabilities of bridges/bridging mechanisms.
    - Cyber and market manipulation risks specific to composable smart contract environments.
  - Mitigations:
    - Platform design to isolate operationally different functions and limit contagion.
    - Regulation to address liquidity fragmentation and establish transaction precedence across ledgers and traditional exchanges.
    - Leverage atomic execution where feasible (single and common ledger models) to reduce counterparty and operational risks.
    - Earmarking of funds and programmable asset pools to improve collateral management efficiency (technological guarantees strongest in single-ledger).
    - Privacy-enhancing technologies (zero-knowledge proofs, confidential transactions) to balance verifiability and confidentiality.
    - Oracle architecture choices: regulated single oracle entity or decentralized oracle networks with collateral/stake and penalties for misreporting; endogenous alternatives like TWAP are vulnerable to manipulation.
    - Platform rulebooks to address conflicts of law and assign responsibility for off-chain inputs.
    - Scaling via Layer 2s or succinct validity-proof-based block validation to preserve trust while increasing throughput.
    - Retain accountable legal entities for CCP-like functions, risk models, and discretion during crises; smart contracts can automate many functions but legal entities remain essential for compliance and recovery.
- Settlement risks and mitigations:
  - Risks:
    - Atomicity depends on architecture; compatible-ledger models face heightened settlement challenges and prefunding requirements.
    - Settlement finality varies by consensus mechanism; probabilistic finality in some systems may be acceptable depending on application.
    - Lack of legal recognition of blockchain settlement in many jurisdictions creates mismatch with existing SSS/CSD frameworks.
  - Mitigations:
    - Use HTLCs and bridges in compatible-ledger models for cross-ledger settlement; bridges may require a legal entity for accountability.
    - Blockchain can offer stronger immutability of settled transactions than conventional IT systems where operators hold unilateral admin rights.
    - Designate authoritative ledger to provide legal certainty (native asset ledgers generally prevail in common-ledger; orchestrator may be assigned authority in compatible-ledger).
    - Integrate blockchain platforms with existing market infrastructure and CSD ownership records until legal recognition evolves.
    - In single and common ledger models, some CSD functions may be executed via smart contracts and distributed consensus, but responsible entities remain necessary where securities are issued off-chain.
- Reporting risks and mitigations:
  - Risks:
    - Reconciliation risks when information is fragmented across ledgers; greatest in compatible-ledger models.
    - Misreporting risk persists despite immutable audit trails; centralized validation introduces risk where validators can alter records.
  - Mitigations:
    - Robust consensus mechanisms in single-ledger models to prevent unilateral modification; decentralized governance to limit change by any one party.
    - Regulated entities required to perform reconciliation and audits in common and compatible ledger models to ensure data integrity and enforce reporting compliance.
    - Privacy-enhancing cryptography (homomorphic encryption, zk-SNARKs) to allow computable verification while protecting sensitive information, expanding trade repository capabilities.

*Source: wpiea2026136-source-pdf - Annex 1 outlines the FMIs’ value propositions and functions*

### Conclusion — Key findings and implications
- Key findings:
  - Tokenization has the potential to reshape Financial Market Infrastructures more profoundly than any technological shift since securities dematerialization.
  - The lifecycle of a financial transaction—issuance, clearing, settlement, custody, and reporting—remains relevant in a tokenized environment, as do many of the risks FMIs were designed to manage.
  - Tokenization is more likely to reconfigure FMIs than to make them disappear; what changes is the way in which FMI functions are delivered.
  - Smart contracts and distributed ledgers can perform a substantial share of FMI functions, particularly where processes are deterministic, rules-based, and data-driven.
- Technological implications:
  - Blockchain-based systems can replicate many FMI functions directly in code, including record-keeping, reconciliations, delivery-versus-payment, and collateral movements.
  - Embedding these functions in smart contracts can reduce operational frictions and, under some architectures, mitigate counterparty and settlement risk.
  - Where assets, cash, and collateral exist in a shared programmable environment, lifecycle steps can be compressed and more tightly coordinated, opening scope for:
    - more efficient collateral use,
    - lower reconciliation needs, and
    - greater composability across financial functions.
- Institutional limits and non-codeable functions:
  - Not all FMI functions can be reduced to code; some remain inherently institutional because they depend on:
    - legal certainty,
    - accountable governance,
    - supervisory access, and
    - discretion under stress.
  - This is especially true for risk model governance, margin calibration, default management, loss mutualization, business continuity, and handling off-chain dependencies such as oracle inputs and legal claims on real-world assets.
  - Even where smart contracts can perform a function technically, legal entities remain necessary where responsibility must be assigned, judgments must be exercised, or intervention may be required.
- Emergence of hybrid FMIs and persistence of institutions:
  - Most plausible outcome: hybrid FMIs where smart contracts perform a greater share of operational/transactional functions while legal entities remain responsible for governance, compliance, accountability, and intervention.
  - Hybrid model likely to persist where:
    - blockchain settlement lacks legal recognition,
    - ownership claims depend on off-chain enforceability, or
    - transactions span multiple ledgers and require coordination beyond what code alone can securely provide.
- Evolving risk landscape and policy boundary:
  - Tokenization reshapes the risk landscape by introducing new vulnerabilities even as some frictions are reduced. New risks include:
    - smart contract vulnerabilities,
    - governance concentration,
    - oracle dependence,
    - privacy trade-offs, and
    - cross-platform fragmentation.
  - Policy challenge: determine the boundary between what can be reliably executed in code and what must remain anchored in accountable institutions.
  - Future of FMIs is not full disintermediation, but institutional redesign.

*From: wpiea2026136-source-pdf — Conclusion*

### Annex 1 — Consolidated value propositions and functions (table summary preserved in text)
- Liquidity saving
  - Multilateral netting
    - CCP: X
    - CSD/SSS: (blank)
    - TR: (blank)
- Lower counterparty and credit risk
  - Interposing between parties; Requiring margin; Mutualizing losses; Network incentives for adequate risk behavior; High entry cost is a deterrent for less solid entities
    - CCP: X
    - CSD/SSS: X (SSSs)
    - TR: (blank)
- Lower custody risk
  - Centralizing records of securities; Acting as a trusted register of ownership
    - CCP: (blank)
    - CSD/SSS: X
    - TR: (blank)
- Lower settlement risk
  - Ensuring finality (irrevocability); Reducing settlement cycles
    - CCP: X
    - CSD/SSS: X
    - TR: (blank)
- Ensure integrity of securities
  - Reconciling initial issuance with secondary market records
    - CCP: (blank)
    - CSD/SSS: X
    - TR: (blank)
- Centralize transaction records in one imperfect ledger
  - Acting as the register of transactions
    - CCP: X
    - CSD/SSS: X
    - TR: (blank)
- Facilitate monitoring systemic risk building in the market
  - Doing accuracy checks on data reported; Providing access to authorities
    - CCP: (blank)
    - CSD/SSS: X
    - TR: (blank)
- Lower operational risks
  - Creating a hub-network, continuity plans, cyber resilience
    - CCP: X
    - CSD/SSS: X
    - TR: X
- Regulatory, liquidity, and legal value propositions (selected)
  - Highly regulated and supervised environment; Onboarding processes with strict risk requirements
    - CCP: X
    - CSD/SSS: X
    - TR: X
  - Prevents moral hazard; Risk takers and their peers bear the consequences of irresponsible behavior (no public money bail-out)
    - CCP: X
    - CSD/SSS: X
    - TR: (blank)
  - Lower liquidity risk through collateralization and DvP
    - CCP: X
    - CSD/SSS: X
    - TR: (blank)
  - Lower money settlement risk: FMIs preferably settle in central bank money, risk-free
    - CCP: X
    - CSD/SSS: X
    - TR: (blank)
  - Lower investment and general business risks: investments limited to highly liquid assets
    - CCP: X
    - CSD/SSS: X
    - TR: X
  - Minimize legal risk: FMIs are recognized by the laws of the jurisdiction they operate in; rulebook determines rules and procedures
    - CCP: X
    - CSD/SSS: X
    - TR: X

- Footnotes and explanatory notes (verbatim):
  - 41 A CCP often bilaterally nets its obligations vis-a-vis its participants, which achieves multilateral netting of each participants’ obligations vis-a-vis all of the other participants. This can reduce substantially the potential losses in the event of the default of a participant, both on trades that have not reached settlement (replacement cost exposures) and on trades in the process of settlement (principal exposures).
  - 42 Netting requires strong legal basis. Netting must be enforceable against the participants in bankruptcy. Without such legal underpinnings, net obligations may be challenged in judicial or administrative insolvency proceedings.
  - 43 The failure of a CCP would almost certainly have serious systemic consequences, especially where multiple markets are served by one CCP or where the same CCP members are present in different CCPs. Consequently, a CCP’s ability to monitor and control the credit, liquidity, legal and operational risks it incurs, and to absorb losses, is essential, to the sound functioning of the markets it serves. A CCP must be able to withstand severe shocks, including defaults by at least the two members with largest exposures one or more of its participants, and its financial support arrangements should be evaluated in this context.

*IMF Working Papers — Financial Market Infrastructures Evolution in a Tokenized Economy (wpiea2026136-source-pdf).*

### Introduction ...........................................................................................................

### Introduction

### How tokenization affects FMIs
- Smart contracts and distributed ledgers can perform a substantial share of the functions now carried out by central securities depositories (CSDs), securities settlement systems (SSSs), central counterparties (CCPs), and trade repositories (TRs), especially where processes are deterministic, rules-based, and data-driven.
- Record-keeping, settlement, collateral transfers and reporting can move on‑chain.
- Code cannot by itself provide legal certainty, bear accountability, or exercise discretion under stress.
- Tokenization does not imply disintermediation, but institutional redesign: the most plausible outcome is a hybrid FMI model, in which smart contracts perform a greater share of operational and transactional functions, while legal entities remain responsible for governance, compliance, risk management, and interventions to preserve business continuity.
- Hybrid arrangements are particularly likely where functions depend on:
  - off-chain inputs,
  - cross-ledger coordination,
  - supervisory access,
  - judgment in the calibration of margins,
  - management of defaults.

### Paper's approach and objective
- The paper examines shifts across issuance, clearing, settlement, and reporting:
  - It asks which CSD, CCP and TR functions can migrate on‑chain, where the main limitations remain, and where hybrid arrangements are likely to emerge.
  - The objective is not to predict a single end‑state, but to clarify trade-offs and identify how responsibilities may be redistributed between technology and institutions in a tokenized financial system.
- Intended audience: policymakers, supervisors and market participants.
- Intended outcome: support a more systematic assessment of:
  - how existing infrastructures could adapt,
  - how trust and accountability are reallocated between institutions and technology,
  - how efficiency gains can be realized without undermining financial stability.
- Scope note:
  - The paper does not focus on the evolution of payment systems in a tokenized economy but rather on FMIs that deal with securities and derivatives.
  - Atomic settlement, asset locks, and prefunding could potentially have an impact on demand for central bank liquidity; exploring this topic is out of scope.

### Transaction lifecycle: issuance, trading, and post‑trading
- Issuance:
  - Creation of the security and its placement in the primary market.
  - Evolved from physical certificates to dematerialized processes where securities are transferred electronically via book‑entry accounts.
  - Process begins with opening an issuance account to record the number of assets created.
  - Accuracy of issuance records is essential to prevent unauthorized securities and to ensure transparency and credibility.
- Trading:
  - Agreement on terms to exchange assets (price, coupons, settlement dates), verification of transaction details, and written confirmations between parties.
  - Trading occurs through matching platforms that bring together buyers and sellers.
- Post‑trading (clearing, settlement, reporting):
  - Clearing:
    - Process of determining obligations of participants.
    - Clearing through a CCP involves novation: the CCP becomes the buyer and the seller of the transaction.
    - CCPs calculate net positions and ensure funds or securities are available to meet commitments.
    - CCPs use multilateral netting to consolidate obligations into a single position per participant, reducing risk.
  - Settlement:
    - Completes transfer of ownership by updating ownership records electronically at a CSD through book‑entry accounts.
    - During the time between trade and settlement (T and T+x), counterparties face risks such as asset destruction, failure to receive the asset, parties reneging on the trade, or delivering an asset without receiving anything in return.
    - To mitigate these risks, counterparties can either fully pre‑fund the assets to be delivered from the moment the trade is entered or use risk management techniques such as providing collateral.
  - Reporting:
    - Providing data on executed transactions to enhance transparency and ensure access for authorities.
    - Accuracy, completeness, and timeliness are essential for effective oversight.
- Coordination needs:
  - Settlement depends on the accuracy of ownership records at the CSD and coordination between intermediaries such as custodians and registrars.
  - Clear operational boundaries and robust reconciliation processes are essential.
  - Parties need to coordinate and reconcile across different IT systems, ledgers, and platforms operated in isolation by FMIs, participants, and intermediaries.

### Risks associated with the lifecycle of a transaction
- Legal risk:
  - Possibility that unexpected application of laws or regulations results in a loss.
  - Includes situations where legal uncertainty renders contracts illegal or unenforceable.
  - Particularly acute in cross‑border settings.
- Operational risk:
  - Deficiencies in information technology systems, human errors, management failures, or system disruptions that may delay, alter, or prevent execution and completion of transactions.
  - Cyber risk is a key subset of operational risk and includes prevention, recoverability, and coordinated crisis management.
- Custody risk:
  - Possibility of loss due to a custodian’s or sub‑custodian’s insolvency, negligence, fraud, poor administration, or inadequate recordkeeping.
- Settlement risk:
  - Possibility that settlement will not occur as expected (one counterparty delivers an asset but does not receive the corresponding payment).
  - Delivery versus Payment (DvP) is a core mechanism designed to mitigate settlement risk by ensuring simultaneous exchange of securities and cash.
  - DvP depends on coordinated processes and standardized messaging between relevant systems and agents.
  - Cash leg typically settled in central bank money or commercial bank money; central bank money generally considered safer due to absence of credit risk.
  - Historical note: Importance of DvP reinforced following the 1987 equity market crisis; the G‑30 recommended its implementation, with the G‑10 subsequently developing its framework (CPSS 1992). DvP is embedded in the CPMI‑IOSCO Principles for Financial Market Infrastructures (PFMIs).
- Credit and liquidity risks:
  - Credit risk: possibility that a counterparty is unable to meet financial obligations when due or at any point in the future.
  - Liquidity risk: when a counterparty fails to meet obligations on time, even if solvent.
  - Both are relevant during clearing and settlement phases when financial obligations crystallize.

### FMIs and how they mitigate risks
- FMIs’ roles:
  - Central to stability, efficiency, and resilience of financial markets.
  - Provide multilateral arrangements for clearing, settlement, and recording of financial transactions to reduce counterparty, settlement, and operational risks, limit contagion, and enhance transparency.
  - Centralization enables netting efficiencies, risk mutualization, and coordinated risk management across participants.
- Scope of FMIs:
  - Range of systems differing in scope, design, and risk‑management responsibilities.
  - Paper focuses primarily on CSDs, CCPs, SSSs, and TRs; payment systems are linked for the cash leg or payment.
- Value proposition:
  - FMIs manage risks across the transaction lifecycle and provide authorities with access to trading and ownership data.
  - Well‑managed FMIs are essential to financial stability.
- Analytical purpose:
  - Presents a benchmark for assessing how FMI functions and addressed risks may evolve in a tokenized environment.

### FMIs relevant to this paper (Box 1)
- Central Securities Depositories (CSDs):
  - Responsible for safekeeping, maintenance, and transfer of securities.
  - Many CSDs act as securities registrars and provide ancillary services such as corporate action processing or securities’ lending.
  - International CSDs support cross‑border transactions by accommodating a range of globally traded instruments.
  - Issuance may occur at a CSD or via official registrar services depending on jurisdiction.
- Securities Settlement Systems (SSSs):
  - Facilitate transfer and settlement of securities by book entry, following predetermined multilateral rules.
  - When securities transactions involve a payment, SSSs ensure Delivery versus Payment (DvP).
  - In many jurisdictions, a CSD operates an SSS (e.g., in the European Union an SSS must be operated by a CSD).
- Central Counterparties (CCPs):
  - Interpose between counterparties, assuming counterparty risk of both sides and ensuring fulfillment of contractual obligations.
  - Reduce risks through multilateral netting and by imposing risk controls on participants.
  - Require collateral from participants and have mechanisms to mutualize losses in case of a participant’s default, thereby reducing systemic risk.
- Trade Repositories (TRs):
  - Provide centralized electronic repositories for transaction data and promote transparency.
  - Especially relevant in OTC derivatives markets where accurate and timely transaction data is vital for risk monitoring.
  - Aggregate and share information with regulators and market participants to reduce systemic risks and support operational efficiency.

*IMF WORKING PAPERS — Financial Market Infrastructures Evolution in a Tokenized Economy (Introduction).*

### Annex 1 outlines the FMIs’ value propositions and functions.

### wpiea2026136-source-pdf - Annex 1 outlines the FMIs’ value propositions and functions

### Legal and operational value propositions of FMIs
- FMIs operate under a clear and enforceable legal framework supported by a comprehensive rulebook that defines their rules and procedures, ensuring the validity and enforceability of transactions, reducing uncertainties related to contract execution, asset recovery, and potential disputes.
- In cross-border transactions, FMIs mitigate risks from conflicting legal regimes by adhering to harmonized international principles (PFMIs), establishing mechanisms to resolve jurisdictional conflicts, and ensuring that FMI rules are enforceable in all relevant jurisdictions.
- FMIs implement stringent operational risk management, including cyber risk preparedness, to ensure secure, reliable, and resilient systems with plans for timely recovery and service continuation during major disruptions.
- FMIs mitigate custody risk by:
  - Ensuring safekeeping of assets through robust custody arrangements, clear segregation of participant assets, comprehensive record-keeping, and due diligence on registrars and custodians.
  - CSDs safeguarding the integrity of securities via accurate securities accounts, end-to-end auditing, and rigorous reconciliation processes; verifying initial issuances and reconciling records with issuers, registrars, and agents.
- FMIs mitigate settlement risk through delivery-versus-payment (DvP) and by providing settlement finality that makes transactions irrevocable and unconditional at a legally defined point.
- FMIs prefer settlement in central bank money because it is free from credit and liquidity risks and increases stability relative to commercial bank money.
- FMIs mitigate credit and liquidity (counterparty) risk by:
  - Requiring participants to maintain adequate financial resources, collateral, and risk controls.
  - Conducting daily stress tests (CCPs) and applying loss mutualization via default funds and CCP "skin in the game".
  - Maintaining liquidity buffers such as central bank deposits, committed credit lines, and highly marketable collateral.
  - Using multilateral netting to consolidate bilateral obligations into a single net position per participant, reducing exposures and liquidity pressures; enforceability depends on a legally robust netting framework.

### FMIs’ ecosystem and governance
- FMI operator responsibilities:
  - Manage operations, set participation rules (the FMI rulebook), and define risk management protocols.
  - Act as a legally accountable entity ensuring regulatory compliance.
- Participant access models:
  - Direct membership, indirect (through an FMI member), or agent frameworks under access criteria in rulebooks.
  - CSD ownership recording models: indirect holdings (CSD records custodian) and direct holdings (CSD registers beneficial owner).
- Roles of key entities:
  - Custodians: credit institutions or investment firms holding beneficial owner accounts; must comply with segregation requirements (omnibus and segregated accounts).
  - Clearing members: direct access to CCPs; contribute prefunded resources to default fund; may extend access to indirect members.
  - Settlement agents: facilitate money leg in DvP; can be central banks (settle in central bank money via RTGS) or commercial banks (settle in commercial bank money); support intraday liquidity via intraday credit operations.
  - Critical service providers: entities like SWIFT and outsourced providers delivering post-trade and optimisation functions.
- FMI rulebook scope:
  - Describes account types, settlement and clearing services, internal/external instructions, rules on investments, collateral management, margin calls, mutualization losses, and ancillary services such as financing.

### Features of tokenized financial assets and blockchains
- Tokenization: creation of assets or representations of assets on a blockchain; benefits derive from blockchain properties (shared ledger, standardized execution rules, consensus protocols).
- Blockchain coordination mechanisms:
  - Execution rule standardization (smart contracts).
  - Consensus protocol standardization (e.g., proof-of-work, proof-of-stake, permissioned voting).
- Smart contracts:
  - Deterministic code-based instructions executed when transactions call contract functions.
  - Enable composability: smart contracts calling other contracts; atomicity: sequences executed as an indivisible unit (all succeed or all revert).
  - Token contracts maintain ownership records and enforce transfer logic; can include custom functions (blacklisting, automated payments, token-based voting).
  - Token security depends on both protocol and contract design; poor or malicious code can enable unauthorized freezes or arbitrary balance adjustments—thorough review and auditing are essential.
- Privacy and supervisory implications:
  - Shared ledgers could allow supervisors to verify data directly on-chain, improving consistency and reducing fraud opportunities.
  - Greater transparency raises privacy concerns; privacy-preserving technologies include ZkLedgers, privacy pools, or homomorphic encryption for tokens.
- Blockchain governance dimensions:
  1. Bookkeeping/consensus
  2. Transaction validation
  3. Access
  4. Upgrade policy
- Governance trade-offs:
  - Open validation and broad data access preserve trustless verification; restricting validation centralizes oversight and introduces single points of failure.
  - Upgrade policy is critical: changes can affect consensus, execution rules, security, and economic incentives.
  - Smart contract-level governance is subordinate to blockchain-level governance; blockchain-level sets the baseline.
  - Reverse dependencies: dominant assets or protocols can capture governance influence (e.g., dominant stablecoin issuer influencing upgrade policy).
- Scaling approaches:
  - Succinct validity proofs (zero-knowledge verification in the narrow sense of succinctness) allow small proofs to attest to correct state transitions without full re-execution.
  - Layer 2 mechanisms (linked state channels, optimistic rollups, zero-knowledge rollups) aggregate transactions and confirm aggregated state on base blockchain; base layer acts as settlement and dispute resolution.

### Architecture models for tokenized systems
- Three architecture models (relationships between ledgers, assets, and owners):
  1. Single ledger model: all owners have access to the same ledger where assets are recorded; enables simplicity and atomicity but broad single-ledger examples are limited in practice.
  2. Compatible ledger model: assets recorded on separate ledgers but owners have access to both; an orchestrator passes instructions concurrently to ledgers (example: ECB’s T2S coordinating RTGS with CSD ledgers).
  3. Common ledger model: each owner accesses only the ledger where their asset is recorded; intermediaries (e.g., central bank or correspondent bank) receive assets, hold in escrow, and issue liabilities for settlement.
- Trust assumptions:
  - Single-ledger: trust in the ledger and token contracts.
  - Common-ledger: trust in native asset ledgers, the common ledger, and asset contracts.
  - Compatible-ledger: trust in native ledgers and orchestrating entities.
- Atomicity and reconciliation:
  - Strict atomicity only guaranteed on a unified ledger; cross-ledger transactions require intermediaries and additional assumptions (ledgers being live and immutable).
  - Reconciliation remains necessary when multiple ledgers register ownership; designating authoritative ledger is key (canonical chain designation in forks).

### FMI functions in a tokenized world: lifecycle stages and implementation notes
- Tokenized asset lifecycle broadly mirrors traditional lifecycle: issuance, trading, clearing, settlement, reporting.
- Issuance:
  - Single-ledger: native token issuance via token smart contracts; issuance and record-keeping unified.
  - Common-ledger: assets remain on native ledgers and are mirrored or re-issued on common ledger; requires strong technical and legal enforceability.
  - Compatible-ledger: issuance occurs independently on distinct asset ledgers; coordination arrangements required.
  - Standardized token interfaces (e.g., ERC-20) provide consistent log data; token contracts can require additional information for regulatory granularity.
- Trading:
  - On-chain or off-chain trading feasible across models.
  - Single-ledger allows native on-chain trading (e.g., AMMs) enabling atomicity through the same execution environment.
  - Common-ledger allows on-chain trading where assets are mirrored on the common ledger.
  - Compatible-ledger weakens atomicity; off-chain trading forgoes strict atomicity across all models.
- Clearing:
  - Deterministic functions (e.g., novation) more easily automated on-chain; discretionary processes (e.g., margin model adjustments) may require off-chain discretion.
  - Risk model computations and sensitive market price data are likely processed off-chain; resulting margin outputs can be recorded on-chain.
  - Smart contracts can act as counterparties analogous to CCPs; full atomicity for novation and margin pulls feasible in single-ledger, partially feasible in common-ledger, minimal in compatible-ledger.
  - Netting and loss mutualization can be automated on-chain; design and location of prefunded default contributions determine complexity.
- Settlement:
  - Single-ledger: atomic settlement via smart contracts achievable.
  - Common-ledger: atomic settlement within common ledger; cross-ledger relies on bridges or messaging with weaker atomicity.
  - Compatible-ledger: requires trusted third party and prefunding for DvP, DvD, PvP; lacks composability and strict atomicity.
  - Atomicity between netting and settlement reduces exposures and prefunding needs but is limited to single and common ledgers.
  - Settlement finality depends on blockchain consensus rules; probabilistic finality versus stronger finality through thresholds and checkpoints (e.g., contexts like proof-of-work vs fixed consensus resources).
- Reporting:
  - Blockchains can centralize transaction data, enabling direct supervisory access and reducing discrepancies.
  - Token standards (e.g., ERC-20) facilitate standardized events and consistent log data; on-chain recording can reduce reporting obligations.
  - Data distribution varies by model: single-ledger as primary source; common-ledger supplemented by native asset ledgers; compatible-ledger requires aggregation from multiple ledgers and off-chain sources.
  - Public mempool visibility offers supervisory monitoring potential but may be limited by private routing and raises privacy concerns.

### Risks introduced or altered by tokenization and mitigation options
- General observation:
  - Risks exist at each lifecycle stage (issuance, trading, clearing, settlement, reporting); many are mitigable by architecture choices, privacy-enhancing technologies, legislation, regulation, and accountable legal entities.
- Issuance risks and mitigations:
  - Risks:
    - Weak minting governance enabling unauthorized/excessive issuance.
    - Custody risks for off-chain backed tokens lacking clear legal links to underlying assets.
    - Token contract design flaws or malicious code as attack vectors.
    - Forks creating competing ledger versions and legal uncertainty over canonical chain for redemptions.
    - Reverse dependencies where dominant assets/protocols capture governance.
  - Mitigations:
    - Minting controls: multisig schemes (example thresholds: 2-of-3 or 4-of-7), timelocks, tiered approval requirements.
    - Dedicated custody entities and regulatory/platform rulebook-specified legal links between token and underlying asset.
    - Smart contract audits focusing on governance, restricted functions, and upgradability.
    - Governance and legal frameworks specifying canonical chain choice and fork handling.
- Trading and clearing risks and mitigations:
  - Risks:
    - Concentration and contagion when multiple functions combine on one platform.
    - Liquidity fragmentation across closed-loop platforms and mixed traditional/blockchain markets.
    - Limited atomicity for clearing operations, especially in compatible-ledger models.
    - Operationally undesirable automatic enforcement of margin calls during stressed conditions.
    - Privacy trade-offs: enhanced transparency vs exposure of holdings and mempool visibility facilitating rent extraction via transaction reordering.
    - Oracle dependence with trade-offs in timeliness versus manipulation resistance.
    - Conflicts of law across jurisdictions impacting collateral enforceability.
    - Scalability constraints in single-ledger models and vulnerabilities of bridges/bridging mechanisms.
    - Cyber and market manipulation risks specific to composable smart contract environments.
  - Mitigations:
    - Platform design to isolate operationally different functions and limit contagion.
    - Regulation to address liquidity fragmentation and establish transaction precedence across ledgers and traditional exchanges.
    - Leverage atomic execution where feasible (single and common ledger models) to reduce counterparty and operational risks.
    - Earmarking of funds and programmable asset pools to improve collateral management efficiency (technological guarantees strongest in single-ledger).
    - Privacy-enhancing technologies (zero-knowledge proofs, confidential transactions) to balance verifiability and confidentiality.
    - Oracle architecture choices: regulated single oracle entity or decentralized oracle networks with collateral/stake and penalties for misreporting; endogenous alternatives like TWAP are vulnerable to manipulation.
    - Platform rulebooks to address conflicts of law and assign responsibility for off-chain inputs.
    - Scaling via Layer 2s or succinct validity-proof-based block validation to preserve trust while increasing throughput.
    - Retain accountable legal entities for CCP-like functions, risk models, and discretion during crises; smart contracts can automate many functions but legal entities remain essential for compliance and recovery.
- Settlement risks and mitigations:
  - Risks:
    - Atomicity depends on architecture; compatible-ledger models face heightened settlement challenges and prefunding requirements.
    - Settlement finality varies by consensus mechanism; probabilistic finality in some systems may be acceptable depending on application.
    - Lack of legal recognition of blockchain settlement in many jurisdictions creates mismatch with existing SSS/CSD frameworks.
  - Mitigations:
    - Use HTLCs and bridges in compatible-ledger models for cross-ledger settlement; bridges may require a legal entity for accountability.
    - Blockchain can offer stronger immutability of settled transactions than conventional IT systems where operators hold unilateral admin rights.
    - Designate authoritative ledger to provide legal certainty (native asset ledgers generally prevail in common-ledger; orchestrator may be assigned authority in compatible-ledger).
    - Integrate blockchain platforms with existing market infrastructure and CSD ownership records until legal recognition evolves.
    - In single and common ledger models, some CSD functions may be executed via smart contracts and distributed consensus, but responsible entities remain necessary where securities are issued off-chain.
- Reporting risks and mitigations:
  - Risks:
    - Reconciliation risks when information is fragmented across ledgers; greatest in compatible-ledger models.
    - Misreporting risk persists despite immutable audit trails; centralized validation introduces risk where validators can alter records.
  - Mitigations:
    - Robust consensus mechanisms in single-ledger models to prevent unilateral modification; decentralized governance to limit change by any one party.
    - Regulated entities required to perform reconciliation and audits in common and compatible ledger models to ensure data integrity and enforce reporting compliance.
    - Privacy-enhancing cryptography (homomorphic encryption, zk-SNARKs) to allow computable verification while protecting sensitive information, expanding trade repository capabilities.

*Source: wpiea2026136-source-pdf - Annex 1 outlines the FMIs’ value propositions and functions*

### Conclusion

### Conclusion

### Key findings
- Tokenization has the potential to reshape Financial Market Infrastructures more profoundly than any technological shift since securities dematerialization.
- The lifecycle of a financial transaction—issuance, clearing, settlement, custody, and reporting—remains relevant in a tokenized environment, as do many of the risks FMIs were designed to manage.
- Tokenization is more likely to reconfigure FMIs than to make them disappear; what changes is the way in which FMI functions are delivered.
- Smart contracts and distributed ledgers can perform a substantial share of FMI functions, particularly where processes are deterministic, rules-based, and data-driven.

### Technological implications
- Blockchain-based systems can replicate many FMI functions directly in code, including record-keeping, reconciliations, delivery-versus-payment, and collateral movements.
- Embedding these functions in smart contracts can reduce operational frictions and, under some architectures, mitigate counterparty and settlement risk.
- Where assets, cash, and collateral exist in a shared programmable environment, lifecycle steps can be compressed and more tightly coordinated, opening scope for:
  - more efficient collateral use,
  - lower reconciliation needs, and
  - greater composability across financial functions.

### Institutional limits and functions that remain non-codeable
- Not all FMI functions can be reduced to code; some remain inherently institutional because they depend on:
  - legal certainty,
  - accountable governance,
  - supervisory access, and
  - discretion under stress.
- This is especially true for risk model governance, margin calibration, default management, loss mutualization, business continuity, and handling off-chain dependencies such as oracle inputs and legal claims on real-world assets.
- Even where smart contracts can perform a function technically, legal entities remain necessary where responsibility must be assigned, judgments must be exercised, or intervention may be required.

### Emergence of hybrid FMIs and persistence of institutions
- The most plausible outcome is the emergence of hybrid FMIs:
  - smart contracts perform a greater share of operational and transactional functions, and
  - legal entities remain responsible for governance, compliance, accountability, and intervention in a market event.
- The hybrid model is likely to persist where:
  - blockchain settlement lacks legal recognition,
  - ownership claims depend on off-chain enforceability, or
  - transactions span multiple ledgers and require coordination beyond what code alone can securely provide.

### Evolving risk landscape and policy boundary
- Tokenization reshapes the risk landscape by introducing new vulnerabilities even as some frictions are reduced. New risks include:
  - smart contract vulnerabilities,
  - governance concentration,
  - oracle dependence,
  - privacy trade-offs, and
  - cross-platform fragmentation.
- The policy challenge is how FMIs will evolve; the key boundary is between what can be reliably executed in code and what must remain anchored in accountable institutions.
- The future of FMIs is not full disintermediation, but institutional redesign.

*From: wpiea2026136-source-pdf — Conclusion*

### Annex 1. FMIs’ value propositions and functions

### Annex 1. FMIs’ value propositions and functions

### Value propositions and associated functions
- Liquidity saving
  - Multilateral netting
    - CCP: X
    - CSD/SSS: (blank)
    - TR: (blank)
- Lower counterparty and credit risk
  - Interposing between parties
  - Requiring margin
  - Mutualizing losses
  - Network incentives for adequate risk behavior
  - High entry cost is a deterrent for less solid entities
    - CCP: X
    - CSD/SSS: X (SSSs)
    - TR: (blank)
- Lower custody risk
  - Centralizing records of securities
  - Acting as a trusted register of ownership
    - CCP: (blank)
    - CSD/SSS: X
    - TR: (blank)
- Lower settlement risk
  - Ensuring finality (irrevocability)
  - Reducing settlement cycles
    - CCP: X
    - CSD/SSS: X
    - TR: (blank)
- Ensure integrity of securities
  - Reconciling initial issuance with secondary market records
    - CCP: (blank)
    - CSD/SSS: X
    - TR: (blank)
- Centralize transaction records in one imperfect ledger
  - Acting as the register of transactions
    - CCP: X
    - CSD/SSS: X
    - TR: (blank)
- Facilitate monitoring systemic risk building in the market
  - Doing accuracy checks on data reported
  - Providing access to authorities
    - CCP: (blank)
    - CSD/SSS: X
    - TR: (blank)
- Lower operational risks
  - Creating a hub-network, where all counterparties trust the system used by the FMI
  - Continuity plans
  - Cyber resilience
    - CCP: X
    - CSD/SSS: X
    - TR: X

### Regulatory, liquidity, and legal value propositions
- Highly regulated and supervised environment
  - Onboarding processes with strict risk requirements
  - Multiple controls on the risk model applied by FMIs, especially CCPs.
    - CCP: X
    - CSD/SSS: X
    - TR: X
- Prevents moral hazard
  - Risk takers and their peers bear the consequences of irresponsible behavior (no public money bail-out)
    - CCP: X
    - CSD/SSS: X
    - TR: (blank)
- Lower liquidity risk
  - Through collateralization of transactions and DvP mechanisms
    - CCP: X
    - CSD/SSS: X
    - TR: (blank)
- Lower money settlement risk
  - FMIs preferably settle in central bank money, risk-free
    - CCP: X
    - CSD/SSS: X
    - TR: (blank)
- Lower investment and general business risks
  - FMIs are strictly regulated and monitored in their activity
  - investments are limited to highly liquid assets
    - CCP: X
    - CSD/SSS: X
    - TR: X
- Minimize legal risk
  - FMIs are recognized by the laws of the jurisdiction they operate in
  - The rulebook determines the rules and procedures an FMI follows
  - FMIs need to address any potential conflict of laws impacting their operations
    - CCP: X
    - CSD/SSS: X
    - TR: X

### Footnotes and explanatory notes (preserve original wording)
- 41 A CCP often bilaterally nets its obligations vis-a-vis its participants, which achieves multilateral netting of each participants’ obligations vis-a-vis all of the other participants. This can reduce substantially the potential losses in the event of the default of a participant, both on trades that have not reached settlement (replacement cost exposures) and on trades in the process of settlement (principal exposures).
- 42 Netting requires strong legal basis. Netting must be enforceable against the participants in bankruptcy. Without such legal underpinnings, net obligations may be challenged in judicial or administrative insolvency proceedings.
- 43 The failure of a CCP would almost certainly have serious systemic consequences, especially where multiple markets are served by one CCP or where the same CCP members are present in different CCPs. Consequently, a CCP’s ability to monitor and control the credit, liquidity, legal and operational risks it incurs, and to absorb losses, is essential, to the sound functioning of the markets it serves. A CCP must be able to withstand severe shocks, including defaults by at least the two members with largest exposures one or more of its participants, and its financial support arrangements should be evaluated in this context.

*IMF Working Papers — Annex 1. FMIs’ value propositions and functions*

---


_Source: https://www.imf.org/-/media/files/publications/wp/2026/english/wpiea2026136-source-pdf.pdf_
