{
  "generatedFrom": "Payments Signal canonical architecture registry",
  "reviewDate": "2026-07-23",
  "blueprint": {
    "id": "architecture-emerging-value",
    "slug": "cbdc-stablecoin-tokenised-deposit-fx-pvp",
    "title": "CBDC, stablecoin, tokenised-deposit, FX, payment-versus-payment, CLS, trade-finance, and alternative cross-border architecture",
    "shortTitle": "Emerging value & FX",
    "family": "emerging-value",
    "summary": "Compare the claim, ledger, access, interoperability, foreign-exchange, delivery-versus-payment, and redemption boundaries before calling a token transfer settlement.",
    "audience": "Payment and digital-money architects, central-bank and commercial-bank teams, treasury, foreign-exchange, trade-finance, risk, legal, and business-analysis teams.",
    "reviewDate": "2026-07-23",
    "versionLabel": "Payments Signal reference architecture v1",
    "status": "current",
    "nodes": [
      {
        "id": "ev-user",
        "title": "Customer, institution, or market participant",
        "kind": "actor",
        "summary": "Holds a legal claim or authorised access and initiates payment, exchange, redemption, or trade settlement.",
        "responsibilities": [
          "Prove authority over the relevant account, wallet, asset, or obligation",
          "Understand which entity owes the claim"
        ],
        "owner": "Participating customer or institution",
        "inputs": [
          "Authorised business instruction and correlated state"
        ],
        "outputs": [
          "Versioned result, status, and audit evidence"
        ],
        "interfaceContracts": [
          "Versioned customer, institution, or market participant contract",
          "Stable identifier, state, error, and audit contract"
        ],
        "controls": [
          "Participant eligibility",
          "Identity and entitlement",
          "Jurisdiction and product rules"
        ],
        "failureModes": [
          "Wrong participant or wallet",
          "Unauthorised transfer",
          "Claim misunderstood"
        ],
        "recovery": [
          "Stop the instruction",
          "Restore authority and correct ownership records under the governing arrangement"
        ],
        "lenses": [
          "applications",
          "interfaces",
          "data",
          "controls",
          "operations",
          "resilience"
        ],
        "evidence": [
          {
            "ref": {
              "sourceId": "payments-signal-editorial",
              "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
              "label": "simplified-educational-illustration",
              "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "Payments Signal reference architecture v1"
          }
        ],
        "dataClassification": [
          "Payment, message, status, and operational metadata"
        ],
        "nonFunctionalRequirements": [
          "Durable correlation through stable business and technical identifiers",
          "Capacity and availability matched to the service-level objective",
          "Auditable state changes, configuration, and operator actions"
        ]
      },
      {
        "id": "ev-access",
        "title": "Access, wallet, custody, and participant gateway",
        "kind": "gateway",
        "summary": "Protects keys or account access, validates participant eligibility, and submits signed or authenticated instructions.",
        "responsibilities": [
          "Separate customer authority from operator authority",
          "Protect key, account, and transaction context"
        ],
        "owner": "Wallet, custodian, bank, or infrastructure participant",
        "inputs": [
          "Authorised business instruction and correlated state"
        ],
        "outputs": [
          "Versioned result, status, and audit evidence"
        ],
        "interfaceContracts": [
          "Versioned access, wallet, custody, and participant gateway contract",
          "Stable identifier, state, error, and audit contract"
        ],
        "controls": [
          "Identity and entitlement",
          "Key or credential lifecycle",
          "Transaction integrity",
          "Replay prevention"
        ],
        "failureModes": [
          "Lost key",
          "Custody outage",
          "Compromised participant"
        ],
        "recovery": [
          "Suspend access without destroying the underlying claim",
          "Recover through the arrangement's authorised process"
        ],
        "lenses": [
          "applications",
          "interfaces",
          "data",
          "controls",
          "operations",
          "resilience"
        ],
        "evidence": [
          {
            "ref": {
              "sourceId": "bis-cpmi-cyber-resilience",
              "locator": "Protection and recovery",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "CPMI-IOSCO cyber-resilience guidance"
          },
          {
            "ref": {
              "sourceId": "payments-signal-editorial",
              "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
              "label": "simplified-educational-illustration",
              "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "Payments Signal reference architecture v1"
          }
        ],
        "dataClassification": [
          "Payment, message, status, and operational metadata"
        ],
        "nonFunctionalRequirements": [
          "Durable correlation through stable business and technical identifiers",
          "Capacity and availability matched to the service-level objective",
          "Auditable state changes, configuration, and operator actions"
        ]
      },
      {
        "id": "ev-instrument",
        "title": "Money or settlement-asset issuer",
        "kind": "external-network",
        "summary": "Defines the claim, issuance, redemption, backing, liability, and holder rights for central-bank money, tokenised deposits, or stablecoins.",
        "responsibilities": [
          "Issue and redeem only under governing rules",
          "Keep liability, backing, and holder claim explicit"
        ],
        "owner": "Central bank, commercial bank, or arrangement issuer",
        "inputs": [
          "Authorised business instruction and correlated state"
        ],
        "outputs": [
          "Versioned result, status, and audit evidence"
        ],
        "interfaceContracts": [
          "Versioned money or settlement-asset issuer contract",
          "Stable identifier, state, error, and audit contract"
        ],
        "controls": [
          "Issuance authority",
          "Backing or reserve control",
          "Reconciliation and attestation",
          "Redemption terms"
        ],
        "failureModes": [
          "Unbacked issuance",
          "Redemption suspended",
          "Issuer and ledger records diverge"
        ],
        "recovery": [
          "Stop issuance",
          "Reconcile liabilities and backing",
          "Apply resolution and holder-protection arrangements"
        ],
        "lenses": [
          "applications",
          "interfaces",
          "data",
          "controls",
          "operations",
          "resilience"
        ],
        "evidence": [
          {
            "ref": {
              "sourceId": "bis-stablecoin-cross-border",
              "locator": "Governance, legal, settlement, and operational considerations",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "CPMI stablecoin cross-border report 2023"
          },
          {
            "ref": {
              "sourceId": "bis-tokenisation",
              "locator": "Token arrangements and settlement assets",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "CPMI tokenisation report 2024"
          }
        ],
        "dataClassification": [
          "Payment, message, status, and operational metadata"
        ],
        "nonFunctionalRequirements": [
          "Durable correlation through stable business and technical identifiers",
          "Capacity and availability matched to the service-level objective",
          "Auditable state changes, configuration, and operator actions"
        ]
      },
      {
        "id": "ev-ledger",
        "title": "Token, account, or settlement ledger",
        "kind": "ledger",
        "summary": "Records ownership or account balances and the state transition that the arrangement recognises.",
        "responsibilities": [
          "Apply an authorised state transition once",
          "Record ordering, finality condition, and reversal or correction authority"
        ],
        "owner": "Ledger or settlement-system operator",
        "inputs": [
          "Authorised business instruction and correlated state"
        ],
        "outputs": [
          "Versioned result, status, and audit evidence"
        ],
        "interfaceContracts": [
          "Versioned token, account, or settlement ledger contract",
          "Stable identifier, state, error, and audit contract"
        ],
        "controls": [
          "Consensus or central ordering",
          "No double spend",
          "Balance conservation",
          "Finality rule"
        ],
        "failureModes": [
          "Fork or inconsistent state",
          "Duplicate transfer",
          "Finality ambiguity"
        ],
        "recovery": [
          "Pause unsafe finalisation",
          "Recover from an agreed checkpoint",
          "Reconcile participant and issuer records"
        ],
        "lenses": [
          "applications",
          "interfaces",
          "data",
          "controls",
          "operations",
          "resilience"
        ],
        "evidence": [
          {
            "ref": {
              "sourceId": "bis-cpmi-pfmi",
              "locator": "Principles 8, 9, 10 and 17",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "CPMI-IOSCO Principles for financial market infrastructures"
          },
          {
            "ref": {
              "sourceId": "payments-signal-editorial",
              "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
              "label": "simplified-educational-illustration",
              "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "Payments Signal reference architecture v1"
          }
        ],
        "dataClassification": [
          "Payment, message, status, and operational metadata"
        ],
        "nonFunctionalRequirements": [
          "Durable correlation through stable business and technical identifiers",
          "Capacity and availability matched to the service-level objective",
          "Auditable state changes, configuration, and operator actions"
        ]
      },
      {
        "id": "ev-interoperability",
        "title": "Interoperability and bridge boundary",
        "kind": "gateway",
        "summary": "Moves an instruction or representation between ledgers, account systems, jurisdictions, or technology stacks without pretending the two assets are the same.",
        "responsibilities": [
          "Name lock, burn, mint, escrow, prefunding, messaging, and legal mechanisms precisely",
          "Prevent value creation from inconsistent cross-system state"
        ],
        "owner": "Arrangement operators and participants",
        "inputs": [
          "Authorised business instruction and correlated state"
        ],
        "outputs": [
          "Versioned result, status, and audit evidence"
        ],
        "interfaceContracts": [
          "Versioned interoperability and bridge boundary contract",
          "Stable identifier, state, error, and audit contract"
        ],
        "controls": [
          "Two-sided state proof",
          "Supply conservation",
          "Timeout and rollback",
          "Operator and legal responsibility"
        ],
        "failureModes": [
          "Source locked but target not issued",
          "Bridge compromise",
          "Duplicate representation"
        ],
        "recovery": [
          "Stop bridge processing",
          "Prove both sides before release",
          "Use governed compensation or redemption"
        ],
        "lenses": [
          "applications",
          "interfaces",
          "data",
          "controls",
          "operations",
          "resilience"
        ],
        "evidence": [
          {
            "ref": {
              "sourceId": "bis-cbdc-interoperability",
              "locator": "Compatibility, interlinking, and common-platform options",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "BIS CBDC interoperability report 2022"
          },
          {
            "ref": {
              "sourceId": "bis-tokenisation",
              "locator": "Interoperability and risk",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "CPMI tokenisation report 2024"
          }
        ],
        "dataClassification": [
          "Payment, message, status, and operational metadata"
        ],
        "nonFunctionalRequirements": [
          "Durable correlation through stable business and technical identifiers",
          "Capacity and availability matched to the service-level objective",
          "Auditable state changes, configuration, and operator actions"
        ]
      },
      {
        "id": "ev-fx-pvp",
        "title": "Foreign-exchange matching and payment-versus-payment control",
        "kind": "control",
        "summary": "Links two currency legs so final transfer of one occurs only with final transfer of the other under the arrangement.",
        "responsibilities": [
          "Match both legs and participants",
          "Enforce payment-versus-payment rather than merely simultaneous message submission"
        ],
        "owner": "FX settlement system or linked operators",
        "inputs": [
          "Authorised business instruction and correlated state"
        ],
        "outputs": [
          "Versioned result, status, and audit evidence"
        ],
        "interfaceContracts": [
          "Versioned foreign-exchange matching and payment-versus-payment control contract",
          "Stable identifier, state, error, and audit contract"
        ],
        "controls": [
          "Trade and instruction match",
          "Currency-leg readiness",
          "Liquidity and cut-off",
          "Atomic or conditional finality"
        ],
        "failureModes": [
          "One leg ready and the other missing",
          "Liquidity shortfall",
          "Cut-off missed"
        ],
        "recovery": [
          "Keep both legs unsettled where the model permits",
          "Resolve liquidity or cancel under the governing rules"
        ],
        "lenses": [
          "applications",
          "interfaces",
          "data",
          "controls",
          "operations",
          "resilience"
        ],
        "evidence": [
          {
            "ref": {
              "sourceId": "cls-settlement",
              "locator": "Payment-versus-payment settlement",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "CLSSettlement public service description"
          },
          {
            "ref": {
              "sourceId": "payments-signal-editorial",
              "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
              "label": "simplified-educational-illustration",
              "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "Payments Signal reference architecture v1"
          }
        ],
        "dataClassification": [
          "Payment, message, status, and operational metadata"
        ],
        "nonFunctionalRequirements": [
          "Durable correlation through stable business and technical identifiers",
          "Capacity and availability matched to the service-level objective",
          "Auditable state changes, configuration, and operator actions"
        ]
      },
      {
        "id": "ev-asset-leg",
        "title": "Asset, document, or trade obligation",
        "kind": "ledger",
        "summary": "Represents the security, commodity, invoice, document, or trade obligation exchanged against payment.",
        "responsibilities": [
          "Prove entitlement and transfer conditions",
          "Link delivery state to the cash leg where delivery-versus-payment is intended"
        ],
        "owner": "Market infrastructure, custodian, registry, or trade platform",
        "inputs": [
          "Authorised business instruction and correlated state"
        ],
        "outputs": [
          "Versioned result, status, and audit evidence"
        ],
        "interfaceContracts": [
          "Versioned asset, document, or trade obligation contract",
          "Stable identifier, state, error, and audit contract"
        ],
        "controls": [
          "Asset authenticity",
          "Transfer restriction",
          "Delivery-versus-payment condition",
          "Document and title control"
        ],
        "failureModes": [
          "Asset unavailable",
          "Document discrepancy",
          "Cash and asset states diverge"
        ],
        "recovery": [
          "Hold both legs when possible",
          "Open an exception with legal and operational ownership"
        ],
        "lenses": [
          "applications",
          "interfaces",
          "data",
          "controls",
          "operations",
          "resilience"
        ],
        "evidence": [
          {
            "ref": {
              "sourceId": "payments-signal-editorial",
              "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
              "label": "simplified-educational-illustration",
              "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "Payments Signal reference architecture v1"
          }
        ],
        "dataClassification": [
          "Payment, message, status, and operational metadata"
        ],
        "nonFunctionalRequirements": [
          "Durable correlation through stable business and technical identifiers",
          "Capacity and availability matched to the service-level objective",
          "Auditable state changes, configuration, and operator actions"
        ]
      },
      {
        "id": "ev-compliance",
        "title": "Policy, compliance, risk, and privacy controls",
        "kind": "control",
        "summary": "Applies participation, financial-crime, data, monetary, prudential, consumer, and market rules appropriate to the arrangement.",
        "responsibilities": [
          "Apply controls to the actual parties, claims, assets, and jurisdictions",
          "Keep privacy and audit requirements compatible"
        ],
        "owner": "Issuer, participant, operator, compliance, legal, and risk owners",
        "inputs": [
          "Authorised business instruction and correlated state"
        ],
        "outputs": [
          "Versioned result, status, and audit evidence"
        ],
        "interfaceContracts": [
          "Versioned policy, compliance, risk, and privacy controls contract",
          "Stable identifier, state, error, and audit contract"
        ],
        "controls": [
          "Sanctions and anti-money-laundering",
          "Limits and eligibility",
          "Privacy and disclosure",
          "Governance and change"
        ],
        "failureModes": [
          "Pseudonym treated as anonymous",
          "Control absent at bridge",
          "Rule conflicts across jurisdictions"
        ],
        "recovery": [
          "Hold or reject under authority",
          "Escalate legal conflict",
          "Preserve evidence without unnecessary disclosure"
        ],
        "lenses": [
          "applications",
          "interfaces",
          "data",
          "controls",
          "operations",
          "resilience"
        ],
        "evidence": [
          {
            "ref": {
              "sourceId": "bis-stablecoin-cross-border",
              "locator": "Governance and cross-border considerations",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "CPMI stablecoin cross-border report 2023"
          },
          {
            "ref": {
              "sourceId": "payments-signal-editorial",
              "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
              "label": "simplified-educational-illustration",
              "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "Payments Signal reference architecture v1"
          }
        ],
        "dataClassification": [
          "Payment, message, status, and operational metadata"
        ],
        "nonFunctionalRequirements": [
          "Durable correlation through stable business and technical identifiers",
          "Capacity and availability matched to the service-level objective",
          "Auditable state changes, configuration, and operator actions"
        ]
      },
      {
        "id": "ev-ops",
        "title": "Liquidity, settlement, reconciliation, and incident operations",
        "kind": "operations",
        "summary": "Monitors positions, funding, ledger state, bridge state, redemption, both FX legs, asset delivery, and external account evidence.",
        "responsibilities": [
          "Identify the last confirmed state on every ledger and claim",
          "Reconcile issuance, backing, settlement, redemption, and external cash"
        ],
        "owner": "Arrangement and participant operations",
        "inputs": [
          "Authorised business instruction and correlated state"
        ],
        "outputs": [
          "Versioned result, status, and audit evidence"
        ],
        "interfaceContracts": [
          "Versioned liquidity, settlement, reconciliation, and incident operations contract",
          "Stable identifier, state, error, and audit contract"
        ],
        "controls": [
          "Multi-ledger reconciliation",
          "Liquidity thresholds",
          "Incident authority",
          "No unsupported replay"
        ],
        "failureModes": [
          "Token moves but bank cash does not",
          "Redemption queue ages",
          "One FX leg uncertain"
        ],
        "recovery": [
          "Freeze affected path",
          "Trace every claim and ledger",
          "Recover under the arrangement's legal and technical rules"
        ],
        "lenses": [
          "applications",
          "interfaces",
          "data",
          "controls",
          "operations",
          "resilience"
        ],
        "evidence": [
          {
            "ref": {
              "sourceId": "bis-cpmi-pfmi",
              "locator": "Principles 7, 8, 17, 23 and 24",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "CPMI-IOSCO Principles for financial market infrastructures"
          },
          {
            "ref": {
              "sourceId": "payments-signal-editorial",
              "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
              "label": "simplified-educational-illustration",
              "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "Payments Signal reference architecture v1"
          }
        ],
        "dataClassification": [
          "Payment, message, status, and operational metadata"
        ],
        "nonFunctionalRequirements": [
          "Durable correlation through stable business and technical identifiers",
          "Capacity and availability matched to the service-level objective",
          "Auditable state changes, configuration, and operator actions"
        ]
      }
    ],
    "interfaces": [
      {
        "id": "ev-e1",
        "from": "ev-user",
        "to": "ev-access",
        "title": "Authorised instruction",
        "kind": "api",
        "mode": "synchronous",
        "purpose": "Submit payment, exchange, delivery, redemption, or issuance intent.",
        "failureBehaviour": "Reject unclear authority or unsupported asset and jurisdiction.",
        "evidence": [
          {
            "ref": {
              "sourceId": "payments-signal-editorial",
              "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
              "label": "simplified-educational-illustration",
              "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "Payments Signal reference architecture v1"
          }
        ],
        "controls": [
          "Authentication and authorisation",
          "Integrity and replay protection",
          "Correlation and audit evidence"
        ],
        "lenses": [
          "interfaces",
          "data",
          "ledger",
          "controls",
          "operations",
          "resilience"
        ],
        "dataClassification": [
          "Payment instruction, status, and correlation metadata"
        ]
      },
      {
        "id": "ev-e2",
        "from": "ev-access",
        "to": "ev-compliance",
        "title": "Eligibility and control request",
        "kind": "control",
        "mode": "synchronous",
        "purpose": "Apply participant, transaction, asset, and jurisdiction controls.",
        "failureBehaviour": "Hold when required controls are unavailable or inconclusive.",
        "evidence": [
          {
            "ref": {
              "sourceId": "payments-signal-editorial",
              "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
              "label": "simplified-educational-illustration",
              "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "Payments Signal reference architecture v1"
          }
        ],
        "controls": [
          "Authentication and authorisation",
          "Integrity and replay protection",
          "Correlation and audit evidence"
        ],
        "lenses": [
          "interfaces",
          "data",
          "ledger",
          "controls",
          "operations",
          "resilience"
        ],
        "dataClassification": [
          "Payment instruction, status, and correlation metadata"
        ]
      },
      {
        "id": "ev-e3",
        "from": "ev-compliance",
        "to": "ev-ledger",
        "title": "Controlled ledger instruction",
        "kind": "control",
        "mode": "asynchronous",
        "purpose": "Release an authorised state transition.",
        "failureBehaviour": "Preserve rejected, held, and expired states.",
        "evidence": [
          {
            "ref": {
              "sourceId": "payments-signal-editorial",
              "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
              "label": "simplified-educational-illustration",
              "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "Payments Signal reference architecture v1"
          }
        ],
        "controls": [
          "Authentication and authorisation",
          "Integrity and replay protection",
          "Correlation and audit evidence"
        ],
        "lenses": [
          "interfaces",
          "data",
          "ledger",
          "controls",
          "operations",
          "resilience"
        ],
        "dataClassification": [
          "Payment instruction, status, and correlation metadata"
        ]
      },
      {
        "id": "ev-e4",
        "from": "ev-instrument",
        "to": "ev-ledger",
        "title": "Issuance and redemption authority",
        "kind": "posting",
        "mode": "synchronous",
        "purpose": "Change instrument supply or liability under governing rules.",
        "failureBehaviour": "Stop supply change when backing, authority, or reconciliation is uncertain.",
        "evidence": [
          {
            "ref": {
              "sourceId": "bis-stablecoin-cross-border",
              "locator": "Issuance, redemption, and settlement considerations",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "CPMI stablecoin cross-border report 2023"
          },
          {
            "ref": {
              "sourceId": "payments-signal-editorial",
              "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
              "label": "simplified-educational-illustration",
              "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "Payments Signal reference architecture v1"
          }
        ],
        "controls": [
          "Authentication and authorisation",
          "Integrity and replay protection",
          "Correlation and audit evidence"
        ],
        "lenses": [
          "interfaces",
          "data",
          "ledger",
          "controls",
          "operations",
          "resilience"
        ],
        "dataClassification": [
          "Payment instruction, status, and correlation metadata"
        ]
      },
      {
        "id": "ev-e5",
        "from": "ev-ledger",
        "to": "ev-interoperability",
        "title": "Source-ledger state proof",
        "kind": "event",
        "mode": "asynchronous",
        "purpose": "Prove lock, burn, final transfer, or other source condition.",
        "failureBehaviour": "Do not create target value from incomplete or unverified source state.",
        "evidence": [
          {
            "ref": {
              "sourceId": "bis-cbdc-interoperability",
              "locator": "Interlinking and common-platform options",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "BIS CBDC interoperability report 2022"
          }
        ],
        "controls": [
          "Authentication and authorisation",
          "Integrity and replay protection",
          "Correlation and audit evidence"
        ],
        "lenses": [
          "interfaces",
          "data",
          "ledger",
          "controls",
          "operations",
          "resilience"
        ],
        "dataClassification": [
          "Payment instruction, status, and correlation metadata"
        ]
      },
      {
        "id": "ev-e6",
        "from": "ev-interoperability",
        "to": "ev-ledger",
        "title": "Target-ledger action",
        "kind": "posting",
        "mode": "asynchronous",
        "purpose": "Complete the governed cross-system action without duplicating supply.",
        "failureBehaviour": "Use timeout and compensation rules for incomplete two-sided state.",
        "evidence": [
          {
            "ref": {
              "sourceId": "bis-tokenisation",
              "locator": "Interoperability and risk",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "CPMI tokenisation report 2024"
          }
        ],
        "controls": [
          "Authentication and authorisation",
          "Integrity and replay protection",
          "Correlation and audit evidence"
        ],
        "lenses": [
          "interfaces",
          "data",
          "ledger",
          "controls",
          "operations",
          "resilience"
        ],
        "dataClassification": [
          "Payment instruction, status, and correlation metadata"
        ]
      },
      {
        "id": "ev-e7",
        "from": "ev-ledger",
        "to": "ev-fx-pvp",
        "title": "Currency-leg readiness",
        "kind": "settlement",
        "mode": "asynchronous",
        "purpose": "Make each matched currency leg ready for conditional settlement.",
        "failureBehaviour": "Keep the pair unsettled when required readiness or liquidity is missing.",
        "evidence": [
          {
            "ref": {
              "sourceId": "cls-settlement",
              "locator": "Payment-versus-payment principle",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "CLSSettlement public service description"
          }
        ],
        "controls": [
          "Authentication and authorisation",
          "Integrity and replay protection",
          "Correlation and audit evidence"
        ],
        "lenses": [
          "interfaces",
          "data",
          "ledger",
          "controls",
          "operations",
          "resilience"
        ],
        "dataClassification": [
          "Payment instruction, status, and correlation metadata"
        ]
      },
      {
        "id": "ev-e8",
        "from": "ev-fx-pvp",
        "to": "ev-ledger",
        "title": "PvP settlement release",
        "kind": "settlement",
        "mode": "synchronous",
        "purpose": "Finalise both currency legs under the arrangement's PvP rule.",
        "failureBehaviour": "Record and resolve any residual uncertainty before participant credit.",
        "evidence": [
          {
            "ref": {
              "sourceId": "cls-settlement",
              "locator": "Payment-versus-payment settlement",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "CLSSettlement public service description"
          }
        ],
        "controls": [
          "Authentication and authorisation",
          "Integrity and replay protection",
          "Correlation and audit evidence"
        ],
        "lenses": [
          "interfaces",
          "data",
          "ledger",
          "controls",
          "operations",
          "resilience"
        ],
        "dataClassification": [
          "Payment instruction, status, and correlation metadata"
        ]
      },
      {
        "id": "ev-e9",
        "from": "ev-ledger",
        "to": "ev-asset-leg",
        "title": "Delivery-versus-payment condition",
        "kind": "settlement",
        "mode": "synchronous",
        "purpose": "Coordinate cash and asset delivery when the arrangement supports it.",
        "failureBehaviour": "Keep delivery and payment states visible if atomicity is unavailable.",
        "evidence": [
          {
            "ref": {
              "sourceId": "payments-signal-editorial",
              "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
              "label": "simplified-educational-illustration",
              "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "Payments Signal reference architecture v1"
          }
        ],
        "controls": [
          "Authentication and authorisation",
          "Integrity and replay protection",
          "Correlation and audit evidence"
        ],
        "lenses": [
          "interfaces",
          "data",
          "ledger",
          "controls",
          "operations",
          "resilience"
        ],
        "dataClassification": [
          "Payment instruction, status, and correlation metadata"
        ]
      },
      {
        "id": "ev-e10",
        "from": "ev-ledger",
        "to": "ev-ops",
        "title": "Ledger, liability, and settlement evidence",
        "kind": "event",
        "mode": "asynchronous",
        "purpose": "Reconcile instrument supply, claims, transactions, backing, and external settlement.",
        "failureBehaviour": "Stop reopening when ledgers or backing do not reconcile.",
        "evidence": [
          {
            "ref": {
              "sourceId": "bis-cpmi-pfmi",
              "locator": "Principles 17, 23 and 24",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "CPMI-IOSCO Principles for financial market infrastructures"
          },
          {
            "ref": {
              "sourceId": "payments-signal-editorial",
              "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
              "label": "simplified-educational-illustration",
              "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "Payments Signal reference architecture v1"
          }
        ],
        "controls": [
          "Authentication and authorisation",
          "Integrity and replay protection",
          "Correlation and audit evidence"
        ],
        "lenses": [
          "interfaces",
          "data",
          "ledger",
          "controls",
          "operations",
          "resilience"
        ],
        "dataClassification": [
          "Payment instruction, status, and correlation metadata"
        ]
      },
      {
        "id": "ev-e11",
        "from": "ev-interoperability",
        "to": "ev-ops",
        "title": "Cross-system exception",
        "kind": "event",
        "mode": "asynchronous",
        "purpose": "Open a case when two systems disagree or time out.",
        "failureBehaviour": "Keep both states and operator actions immutable.",
        "evidence": [
          {
            "ref": {
              "sourceId": "payments-signal-editorial",
              "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
              "label": "simplified-educational-illustration",
              "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "Payments Signal reference architecture v1"
          }
        ],
        "controls": [
          "Authentication and authorisation",
          "Integrity and replay protection",
          "Correlation and audit evidence"
        ],
        "lenses": [
          "interfaces",
          "data",
          "ledger",
          "controls",
          "operations",
          "resilience"
        ],
        "dataClassification": [
          "Payment instruction, status, and correlation metadata"
        ]
      }
    ],
    "views": [
      {
        "id": "context",
        "label": "Context",
        "plainPurpose": "Who depends on the architecture, which external service it reaches, and where value ultimately moves.",
        "nodeIds": [
          "ev-user",
          "ev-instrument",
          "ev-ledger",
          "ev-asset-leg"
        ],
        "interfaceIds": [
          "ev-e4",
          "ev-e9"
        ],
        "placements": {
          "ev-user": {
            "x": 80,
            "y": 100,
            "width": 244,
            "height": 126
          },
          "ev-instrument": {
            "x": 444,
            "y": 100,
            "width": 244,
            "height": 126
          },
          "ev-ledger": {
            "x": 808,
            "y": 100,
            "width": 244,
            "height": 126
          },
          "ev-asset-leg": {
            "x": 80,
            "y": 326,
            "width": 244,
            "height": 126
          }
        },
        "boundaries": [
          {
            "id": "context-bank-boundary",
            "label": "Institution-controlled boundary",
            "nodeIds": [
              "ev-user",
              "ev-ledger",
              "ev-asset-leg"
            ],
            "kind": "ownership"
          }
        ]
      },
      {
        "id": "container",
        "label": "Container",
        "plainPurpose": "The major applications, stores, gateways, controls, and operational ownership boundaries.",
        "nodeIds": [
          "ev-access",
          "ev-instrument",
          "ev-ledger",
          "ev-interoperability",
          "ev-fx-pvp",
          "ev-asset-leg",
          "ev-compliance",
          "ev-ops"
        ],
        "interfaceIds": [
          "ev-e2",
          "ev-e3",
          "ev-e4",
          "ev-e5",
          "ev-e6",
          "ev-e7",
          "ev-e8",
          "ev-e9",
          "ev-e10",
          "ev-e11"
        ],
        "placements": {
          "ev-access": {
            "x": 80,
            "y": 100,
            "width": 196,
            "height": 126
          },
          "ev-instrument": {
            "x": 376,
            "y": 100,
            "width": 196,
            "height": 126
          },
          "ev-ledger": {
            "x": 672,
            "y": 100,
            "width": 196,
            "height": 126
          },
          "ev-interoperability": {
            "x": 968,
            "y": 100,
            "width": 196,
            "height": 126
          },
          "ev-fx-pvp": {
            "x": 80,
            "y": 326,
            "width": 196,
            "height": 126
          },
          "ev-asset-leg": {
            "x": 376,
            "y": 326,
            "width": 196,
            "height": 126
          },
          "ev-compliance": {
            "x": 672,
            "y": 326,
            "width": 196,
            "height": 126
          },
          "ev-ops": {
            "x": 968,
            "y": 326,
            "width": 196,
            "height": 126
          }
        },
        "boundaries": [
          {
            "id": "container-bank-boundary",
            "label": "Institution-controlled boundary",
            "nodeIds": [
              "ev-access",
              "ev-ledger",
              "ev-interoperability",
              "ev-fx-pvp",
              "ev-asset-leg",
              "ev-compliance",
              "ev-ops"
            ],
            "kind": "ownership"
          }
        ]
      },
      {
        "id": "component",
        "label": "Component",
        "plainPurpose": "The processing responsibilities and interface contracts that must cooperate for one payment.",
        "nodeIds": [
          "ev-user",
          "ev-access",
          "ev-instrument",
          "ev-ledger",
          "ev-interoperability",
          "ev-fx-pvp",
          "ev-asset-leg",
          "ev-compliance",
          "ev-ops"
        ],
        "interfaceIds": [
          "ev-e1",
          "ev-e2",
          "ev-e3",
          "ev-e4",
          "ev-e5",
          "ev-e6",
          "ev-e7",
          "ev-e8",
          "ev-e9",
          "ev-e10",
          "ev-e11"
        ],
        "placements": {
          "ev-user": {
            "x": 80,
            "y": 100,
            "width": 196,
            "height": 126
          },
          "ev-access": {
            "x": 376,
            "y": 100,
            "width": 196,
            "height": 126
          },
          "ev-instrument": {
            "x": 672,
            "y": 100,
            "width": 196,
            "height": 126
          },
          "ev-ledger": {
            "x": 968,
            "y": 100,
            "width": 196,
            "height": 126
          },
          "ev-interoperability": {
            "x": 80,
            "y": 326,
            "width": 196,
            "height": 126
          },
          "ev-fx-pvp": {
            "x": 376,
            "y": 326,
            "width": 196,
            "height": 126
          },
          "ev-asset-leg": {
            "x": 672,
            "y": 326,
            "width": 196,
            "height": 126
          },
          "ev-compliance": {
            "x": 968,
            "y": 326,
            "width": 196,
            "height": 126
          },
          "ev-ops": {
            "x": 80,
            "y": 552,
            "width": 196,
            "height": 126
          }
        },
        "boundaries": [
          {
            "id": "component-bank-boundary",
            "label": "Institution-controlled boundary",
            "nodeIds": [
              "ev-user",
              "ev-access",
              "ev-ledger",
              "ev-interoperability",
              "ev-fx-pvp",
              "ev-asset-leg",
              "ev-compliance",
              "ev-ops"
            ],
            "kind": "ownership"
          }
        ]
      },
      {
        "id": "deployment",
        "label": "Deployment",
        "plainPurpose": "The trust zones, runtime dependencies, external connections, and recovery boundaries.",
        "nodeIds": [
          "ev-access",
          "ev-instrument",
          "ev-ledger",
          "ev-interoperability",
          "ev-asset-leg"
        ],
        "interfaceIds": [
          "ev-e4",
          "ev-e5",
          "ev-e6",
          "ev-e9"
        ],
        "placements": {
          "ev-access": {
            "x": 80,
            "y": 100,
            "width": 244,
            "height": 126
          },
          "ev-instrument": {
            "x": 444,
            "y": 100,
            "width": 244,
            "height": 126
          },
          "ev-ledger": {
            "x": 808,
            "y": 100,
            "width": 244,
            "height": 126
          },
          "ev-interoperability": {
            "x": 80,
            "y": 326,
            "width": 244,
            "height": 126
          },
          "ev-asset-leg": {
            "x": 444,
            "y": 326,
            "width": 244,
            "height": 126
          }
        },
        "boundaries": [
          {
            "id": "deployment-bank-boundary",
            "label": "Institution-controlled boundary",
            "nodeIds": [
              "ev-access",
              "ev-ledger",
              "ev-interoperability",
              "ev-asset-leg"
            ],
            "kind": "ownership"
          }
        ]
      }
    ],
    "traces": [
      {
        "id": "ev-pvp-exchange",
        "label": "Two-leg payment-versus-payment exchange",
        "summary": "Follow two currency claims from authorised access to matched, conditional final settlement and reconciliation.",
        "viewId": "component",
        "steps": [
          {
            "id": "ev-pvp-exchange-step-1",
            "title": "Submit the exchange",
            "nodeId": "ev-user",
            "interfaceId": "ev-e1",
            "plainExplanation": "The participant identifies both currency claims, parties, amounts, and settlement conditions.",
            "businessState": "Two-leg intent created"
          },
          {
            "id": "ev-pvp-exchange-step-2",
            "title": "Prove authority",
            "nodeId": "ev-access",
            "interfaceId": "ev-e2",
            "plainExplanation": "The access layer proves who may move each claim.",
            "businessState": "Participant and instruction authenticated"
          },
          {
            "id": "ev-pvp-exchange-step-3",
            "title": "Apply controls",
            "nodeId": "ev-compliance",
            "interfaceId": "ev-e3",
            "plainExplanation": "Policy and compliance controls apply to parties, claims, jurisdictions, and arrangement.",
            "businessState": "Instruction eligible"
          },
          {
            "id": "ev-pvp-exchange-step-4",
            "title": "Make both legs ready",
            "nodeId": "ev-ledger",
            "interfaceId": "ev-e7",
            "plainExplanation": "Each ledger or account system records readiness without finalising only one side.",
            "businessState": "Currency legs matched and funded"
          },
          {
            "id": "ev-pvp-exchange-step-5",
            "title": "Settle payment versus payment",
            "nodeId": "ev-fx-pvp",
            "interfaceId": "ev-e8",
            "plainExplanation": "The control releases one currency leg only with the other.",
            "businessState": "Both legs final under the arrangement"
          },
          {
            "id": "ev-pvp-exchange-step-6",
            "title": "Record final ownership",
            "nodeId": "ev-ledger",
            "interfaceId": "ev-e10",
            "plainExplanation": "Both settlement records and participant positions now reflect the exchange.",
            "businessState": "Ledger states final",
            "ledgerEffect": "Two linked currency-leg debits and credits recorded."
          },
          {
            "id": "ev-pvp-exchange-step-7",
            "title": "Reconcile claims and settlement",
            "nodeId": "ev-ops",
            "plainExplanation": "Participants reconcile matched instructions, both ledger outcomes, fees, liquidity, and external evidence.",
            "businessState": "Exchange reconciled"
          }
        ],
        "evidence": [
          {
            "ref": {
              "sourceId": "cls-settlement",
              "locator": "Payment-versus-payment principle",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "CLSSettlement public service description"
          },
          {
            "ref": {
              "sourceId": "payments-signal-editorial",
              "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
              "label": "simplified-educational-illustration",
              "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "Payments Signal reference architecture v1"
          }
        ]
      }
    ],
    "stressCases": [
      {
        "id": "ev-stress-one-leg",
        "label": "Only one FX leg is ready",
        "trigger": "One currency leg lacks liquidity or valid settlement authority.",
        "divergesAfterStepId": "ev-pvp-exchange-step-4",
        "traceId": "ev-pvp-exchange",
        "affectedNodeIds": [
          "ev-ledger",
          "ev-fx-pvp",
          "ev-ops"
        ],
        "affectedInterfaceIds": [
          "ev-e7",
          "ev-e8"
        ],
        "lastConfirmedState": "The pair is matched; only one leg is ready.",
        "settlementState": "Payment-versus-payment settlement has not completed.",
        "fundsState": "Neither leg should be treated as final under the illustrated PvP control.",
        "owner": "FX settlement operations",
        "safeAction": "Keep the pair unsettled, resolve liquidity or eligibility, and apply cut-off or cancellation rules.",
        "requiredEvidence": [
          "Matched instruction",
          "Both ledger states",
          "Liquidity position",
          "Cut-off and rule"
        ],
        "recoverySteps": [
          "Fund or correct the missing leg",
          "Settle both or expire/cancel under rules",
          "Reconcile positions"
        ],
        "evidence": [
          {
            "ref": {
              "sourceId": "cls-settlement",
              "locator": "Payment-versus-payment settlement",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "CLSSettlement public service description"
          }
        ]
      },
      {
        "id": "ev-stress-bridge",
        "label": "Cross-ledger bridge stops halfway",
        "trigger": "Source value is locked or burned but the target action is not confirmed.",
        "divergesAfterStepId": "ev-pvp-exchange-step-5",
        "traceId": "ev-pvp-exchange",
        "affectedNodeIds": [
          "ev-ledger",
          "ev-interoperability",
          "ev-ops"
        ],
        "affectedInterfaceIds": [
          "ev-e5",
          "ev-e6",
          "ev-e11"
        ],
        "lastConfirmedState": "The source-side condition is recorded; target-side state is uncertain.",
        "settlementState": "Cross-system settlement is incomplete.",
        "fundsState": "The user's usable value may be unavailable on both sides until recovery.",
        "owner": "Interoperability incident command",
        "safeAction": "Freeze the affected path and prove both ledger states before compensation, mint, unlock, or refund.",
        "requiredEvidence": [
          "Source proof",
          "Target proof",
          "Bridge event sequence",
          "Operator authority"
        ],
        "recoverySteps": [
          "Recover target or apply governed compensation",
          "Reconcile supply and liabilities",
          "Reopen only after two-sided proof"
        ],
        "evidence": [
          {
            "ref": {
              "sourceId": "bis-cbdc-interoperability",
              "locator": "Interlinking risks and design options",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "BIS CBDC interoperability report 2022"
          },
          {
            "ref": {
              "sourceId": "payments-signal-editorial",
              "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
              "label": "simplified-educational-illustration",
              "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "Payments Signal reference architecture v1"
          }
        ]
      },
      {
        "id": "ev-stress-redemption",
        "label": "Redemption cannot complete",
        "trigger": "The token is surrendered but external bank-money payment is delayed or rejected.",
        "divergesAfterStepId": "ev-pvp-exchange-step-6",
        "traceId": "ev-pvp-exchange",
        "affectedNodeIds": [
          "ev-instrument",
          "ev-ledger",
          "ev-ops"
        ],
        "affectedInterfaceIds": [
          "ev-e4",
          "ev-e10"
        ],
        "lastConfirmedState": "Redemption request and token state are recorded.",
        "settlementState": "External cash settlement is not confirmed.",
        "fundsState": "The holder's token and issuer liability treatment depends on the governing arrangement.",
        "owner": "Issuer treasury and redemption operations",
        "safeAction": "Do not mark redemption paid; preserve the claim and apply documented retry, reinstatement, or refund treatment.",
        "requiredEvidence": [
          "Redemption ID",
          "Token burn or lock state",
          "Bank payment status",
          "Backing and liability records"
        ],
        "recoverySteps": [
          "Resolve external payment",
          "Restore or reissue claim if rules require",
          "Reconcile supply, backing, and holder record"
        ],
        "evidence": [
          {
            "ref": {
              "sourceId": "bis-stablecoin-cross-border",
              "locator": "Redemption and settlement considerations",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "CPMI stablecoin cross-border report 2023"
          },
          {
            "ref": {
              "sourceId": "payments-signal-editorial",
              "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
              "label": "simplified-educational-illustration",
              "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "Payments Signal reference architecture v1"
          }
        ]
      }
    ],
    "overlays": [
      {
        "id": "ev-overlay-cls",
        "label": "CLS payment-versus-payment",
        "summary": "Show matched foreign-exchange instructions, both currency legs, liquidity, PvP release, and reconciliation.",
        "nodeIds": [
          "ev-user",
          "ev-access",
          "ev-compliance",
          "ev-ledger",
          "ev-fx-pvp",
          "ev-ops"
        ],
        "interfaceIds": [
          "ev-e1",
          "ev-e2",
          "ev-e3",
          "ev-e7",
          "ev-e8",
          "ev-e10"
        ],
        "relatedFlowIds": [
          "flow-cls-pvp"
        ],
        "evidence": [
          {
            "ref": {
              "sourceId": "cls-settlement",
              "locator": "Payment-versus-payment settlement",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "CLSSettlement public service description"
          }
        ],
        "coverageGap": "Detailed participant interfaces, currencies, schedules, funding, and failure procedures require current CLS service documentation."
      },
      {
        "id": "ev-overlay-wholesale-cbdc",
        "label": "Wholesale CBDC experiment",
        "summary": "Show participant access, central-bank liability, ledger finality, interoperability, controls, and operations without assuming production deployment.",
        "nodeIds": [
          "ev-user",
          "ev-access",
          "ev-instrument",
          "ev-ledger",
          "ev-interoperability",
          "ev-compliance",
          "ev-ops"
        ],
        "interfaceIds": [
          "ev-e1",
          "ev-e2",
          "ev-e3",
          "ev-e4",
          "ev-e5",
          "ev-e6",
          "ev-e10",
          "ev-e11"
        ],
        "relatedFlowIds": [
          "flow-wholesale-cbdc"
        ],
        "evidence": [
          {
            "ref": {
              "sourceId": "bis-cbdc-interoperability",
              "locator": "CBDC access and interoperability design options",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "BIS CBDC interoperability report 2022"
          }
        ],
        "coverageGap": "The flow is synthetic and does not represent a live central-bank digital-currency scheme."
      },
      {
        "id": "ev-overlay-trade",
        "label": "Trade-finance and delivery-versus-payment pattern",
        "summary": "Separate documentary or asset obligations from cash, control discrepancies, and coordinate delivery against payment only where supported.",
        "nodeIds": [
          "ev-user",
          "ev-access",
          "ev-compliance",
          "ev-ledger",
          "ev-asset-leg",
          "ev-ops"
        ],
        "interfaceIds": [
          "ev-e1",
          "ev-e2",
          "ev-e3",
          "ev-e9",
          "ev-e10"
        ],
        "relatedFlowIds": [
          "flow-letter-of-credit"
        ],
        "evidence": [
          {
            "ref": {
              "sourceId": "payments-signal-editorial",
              "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
              "label": "simplified-educational-illustration",
              "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "Payments Signal reference architecture v1"
          }
        ],
        "coverageGap": "Documentary-credit law, rules, bank undertakings, document examination, title, and settlement vary; this overlay shows responsibility boundaries only."
      },
      {
        "id": "ev-overlay-regional",
        "label": "Alternative cross-border infrastructure",
        "summary": "Show participant access, multi-currency or regional routing, settlement asset, compliance, liquidity, and reconciliation without inferring unpublished operating rules.",
        "nodeIds": [
          "ev-user",
          "ev-access",
          "ev-instrument",
          "ev-ledger",
          "ev-interoperability",
          "ev-compliance",
          "ev-ops"
        ],
        "interfaceIds": [
          "ev-e1",
          "ev-e2",
          "ev-e3",
          "ev-e4",
          "ev-e5",
          "ev-e6",
          "ev-e10"
        ],
        "relatedFlowIds": [
          "flow-cips",
          "flow-papss",
          "flow-buna"
        ],
        "evidence": [
          {
            "ref": {
              "sourceId": "payments-signal-editorial",
              "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
              "label": "simplified-educational-illustration",
              "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "Payments Signal reference architecture v1"
          }
        ],
        "coverageGap": "CIPS, PAPSS, and Buna have distinct participation, clearing, settlement, currency, and compliance arrangements. Use each operator's current official material for implementation."
      }
    ],
    "decisions": [
      {
        "id": "ev-decision-claim",
        "question": "What exactly does the holder own or claim?",
        "options": [
          {
            "label": "Explicit issuer liability",
            "consequence": "Makes redemption, insolvency, backing, and reporting questions visible."
          },
          {
            "label": "Technology-only token label",
            "consequence": "Hides the legal and financial meaning behind a ledger object."
          }
        ],
        "guidance": "Name issuer, holder claim, settlement asset, governing law, redemption right, backing, and finality before choosing technology.",
        "evidence": [
          {
            "ref": {
              "sourceId": "bis-tokenisation",
              "locator": "Token arrangements and underlying claims",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "CPMI tokenisation report 2024"
          },
          {
            "ref": {
              "sourceId": "payments-signal-editorial",
              "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
              "label": "simplified-educational-illustration",
              "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "Payments Signal reference architecture v1"
          }
        ]
      },
      {
        "id": "ev-decision-interoperability",
        "question": "How should two systems coordinate value?",
        "options": [
          {
            "label": "Governed interlink or common platform",
            "consequence": "Can make two-sided state explicit but concentrates operational, legal, and security dependencies."
          },
          {
            "label": "Uncontrolled representation or bridge",
            "consequence": "May appear simple but can create duplicate supply and unresolved claims."
          }
        ],
        "guidance": "Document source and target state, supply conservation, operator authority, timeout, compensation, finality, and incident ownership.",
        "evidence": [
          {
            "ref": {
              "sourceId": "bis-cbdc-interoperability",
              "locator": "Compatibility, interlinking, and common-platform models",
              "label": "official-requirement"
            },
            "verifiedDate": "2026-07-23",
            "versionContext": "BIS CBDC interoperability report 2022"
          }
        ]
      }
    ],
    "targets": [
      {
        "type": "flow",
        "id": "flow-cls-pvp"
      },
      {
        "type": "flow",
        "id": "flow-wholesale-cbdc"
      },
      {
        "type": "flow",
        "id": "flow-letter-of-credit"
      },
      {
        "type": "flow",
        "id": "flow-cips"
      },
      {
        "type": "flow",
        "id": "flow-papss"
      },
      {
        "type": "flow",
        "id": "flow-buna"
      }
    ],
    "glossaryTermIds": [
      "central-bank-digital-currency",
      "delivery-versus-payment",
      "foreign-exchange-settlement-risk",
      "payment-versus-payment",
      "stablecoin",
      "tokenised-deposit",
      "tokenisation",
      "wholesale-cbdc"
    ],
    "evidence": [
      {
        "ref": {
          "sourceId": "cls-settlement",
          "locator": "Payment-versus-payment settlement",
          "label": "official-requirement"
        },
        "verifiedDate": "2026-07-23",
        "versionContext": "CLSSettlement public service description"
      },
      {
        "ref": {
          "sourceId": "bis-stablecoin-cross-border",
          "locator": "Cross-border stablecoin considerations",
          "label": "official-requirement"
        },
        "verifiedDate": "2026-07-23",
        "versionContext": "CPMI stablecoin cross-border report 2023"
      },
      {
        "ref": {
          "sourceId": "bis-tokenisation",
          "locator": "Token arrangements and risks",
          "label": "official-requirement"
        },
        "verifiedDate": "2026-07-23",
        "versionContext": "CPMI tokenisation report 2024"
      },
      {
        "ref": {
          "sourceId": "bis-cbdc-interoperability",
          "locator": "Access and interoperability models",
          "label": "official-requirement"
        },
        "verifiedDate": "2026-07-23",
        "versionContext": "BIS CBDC interoperability report 2022"
      },
      {
        "ref": {
          "sourceId": "payments-signal-editorial",
          "locator": "Tokenised money, foreign exchange, and alternative cross-border patterns",
          "label": "simplified-educational-illustration",
          "simplifications": "These patterns have different legal claims, issuers, operators, settlement assets, redemption rights, governance, interoperability, access, privacy, and finality. A shared diagram must not imply that they are interchangeable or production-ready."
        },
        "verifiedDate": "2026-07-23",
        "versionContext": "Payments Signal reference architecture v1"
      }
    ],
    "simplifies": "This blueprint compares architectural questions across foreign-exchange settlement, central-bank digital currency, tokenised deposits, stablecoins, tokenised assets, and trade obligations. It does not say these instruments are equivalent, authorised, interoperable, final, backed, redeemable, or suitable for production."
  },
  "sources": [
    {
      "id": "cls-settlement",
      "publisher": "CLS Group",
      "title": "CLSSettlement",
      "sourceType": "official-standard",
      "accessedDate": "2026-07-23",
      "url": "https://www.cls-group.com/products/settlement/clssettlement/",
      "applicability": "Explains payment-versus-payment settlement for eligible foreign-exchange instructions, in which the two currency legs settle together to mitigate foreign-exchange settlement risk.",
      "notes": "The public page supports the payment-versus-payment principle and service role. Participant interfaces, schedules, currencies, and detailed operating rules require current official service documentation."
    },
    {
      "id": "bis-stablecoin-cross-border",
      "publisher": "Committee on Payments and Market Infrastructures",
      "title": "Considerations for the use of stablecoin arrangements in cross-border payments",
      "sourceType": "regulatory-guidance",
      "publicationDate": "2023-10-31",
      "accessedDate": "2026-07-23",
      "url": "https://www.bis.org/cpmi/publ/d220.htm",
      "applicability": "Examines possible benefits, risks, governance, legal, settlement, interoperability, and operational considerations when stablecoin arrangements are used for cross-border payments.",
      "notes": "The report is analytical guidance, not an endorsement of a stablecoin arrangement or evidence that a token transfer constitutes final settlement in a particular jurisdiction."
    },
    {
      "id": "bis-tokenisation",
      "publisher": "Committee on Payments and Market Infrastructures",
      "title": "Tokenisation in the context of money and other assets",
      "sourceType": "regulatory-guidance",
      "publicationDate": "2024-10-21",
      "accessedDate": "2026-07-23",
      "url": "https://www.bis.org/cpmi/publ/d225.htm",
      "applicability": "Explains token arrangements, governance, settlement assets, interoperability, risks, and design choices for tokenised money and assets.",
      "notes": "The report supports architecture questions and risk boundaries; it does not make a tokenised deposit, security, or settlement arrangement compliant by design."
    },
    {
      "id": "bis-cbdc-interoperability",
      "publisher": "Bank for International Settlements",
      "title": "Options for access to and interoperability of CBDCs for cross-border payments",
      "sourceType": "regulatory-guidance",
      "publicationDate": "2022-07-11",
      "accessedDate": "2026-07-23",
      "url": "https://www.bis.org/publ/othp52.htm",
      "applicability": "Examines access, compatibility, interlinking, and common-platform options for central bank digital currencies in cross-border payments.",
      "notes": "The report describes design options rather than a production central-bank digital-currency scheme."
    },
    {
      "id": "payments-signal-editorial",
      "publisher": "Payments Signal",
      "title": "Payments Signal editorial teaching models",
      "sourceType": "educational-simplification",
      "accessedDate": "2026-07-12",
      "applicability": "This site's own simplified teaching models.",
      "notes": "Used wherever diagrams, scenarios, figures, or example values are didactic constructions rather than sourced facts; every such use carries a simplifications disclosure. All people, companies, banks, and list entries in examples are fictional."
    },
    {
      "id": "bis-cpmi-cyber-resilience",
      "publisher": "Committee on Payments and Market Infrastructures / IOSCO",
      "title": "Guidance on cyber resilience for financial market infrastructures",
      "sourceType": "regulatory-guidance",
      "accessedDate": "2026-07-23",
      "url": "https://www.bis.org/cpmi/publ/d146.htm",
      "applicability": "Sets expectations for governance, identification, protection, detection, response, recovery, testing, situational awareness, and learning at financial market infrastructures.",
      "notes": "The guidance applies to financial market infrastructures. A bank or payment-service provider should translate the control outcomes into its own regulatory, risk, and operating context."
    },
    {
      "id": "bis-cpmi-pfmi",
      "publisher": "CPMI and IOSCO (Bank for International Settlements)",
      "title": "Principles for financial market infrastructures",
      "sourceType": "industry-paper",
      "publicationDate": "2012-04-16",
      "accessedDate": "2026-07-12",
      "url": "https://www.bis.org/cpmi/publ/d101.htm",
      "applicability": "International risk-management standards for systemically important payment systems and other financial market infrastructures.",
      "notes": "Published by the CPSS (now CPMI) and IOSCO; contains 24 principles plus responsibilities for authorities. This site uses it only for high-level concepts such as settlement finality."
    }
  ],
  "relatedContent": [
    {
      "type": "article",
      "label": "Central bank digital currency, explained",
      "href": "/2026/07/18/central-bank-digital-currency-explained",
      "coverage": "derived"
    },
    {
      "type": "article",
      "label": "Central versus commercial bank money",
      "href": "/2026/07/18/central-versus-commercial-bank-money",
      "coverage": "derived"
    },
    {
      "type": "article",
      "label": "Letters of credit and documentary trade",
      "href": "/2026/07/18/letters-of-credit-and-documentary-trade",
      "coverage": "derived"
    },
    {
      "type": "article",
      "label": "Stablecoins as a settlement asset",
      "href": "/2026/07/18/stablecoins-as-a-settlement-asset",
      "coverage": "derived"
    },
    {
      "type": "article",
      "label": "The MT7xx trade finance message family",
      "href": "/2026/07/18/the-mt7xx-trade-finance-message-family",
      "coverage": "derived"
    },
    {
      "type": "article",
      "label": "Tokenized deposits and the unit of account",
      "href": "/2026/07/18/tokenized-deposits-and-the-unit-of-account",
      "coverage": "derived"
    },
    {
      "type": "flow",
      "label": "A Buna cross-border payment (Arab region RTGS)",
      "href": "/explore/buna",
      "coverage": "direct"
    },
    {
      "type": "flow",
      "label": "CIPS cross-border RMB payment",
      "href": "/explore/cips",
      "coverage": "direct"
    },
    {
      "type": "flow",
      "label": "CLS: payment-versus-payment FX settlement",
      "href": "/explore/cls-pvp",
      "coverage": "direct"
    },
    {
      "type": "flow",
      "label": "Letter of credit settlement",
      "href": "/explore/letter-of-credit",
      "coverage": "direct"
    },
    {
      "type": "flow",
      "label": "PAPSS — Pan-African Payment and Settlement System",
      "href": "/explore/papss",
      "coverage": "direct"
    },
    {
      "type": "flow",
      "label": "Wholesale CBDC interbank settlement (illustrative)",
      "href": "/explore/wholesale-cbdc",
      "coverage": "direct"
    },
    {
      "type": "glossary",
      "label": "Account-based CBDC",
      "href": "/glossary#account-based-cbdc",
      "coverage": "derived"
    },
    {
      "type": "glossary",
      "label": "Advising bank",
      "href": "/glossary#advising-bank",
      "coverage": "derived"
    },
    {
      "type": "glossary",
      "label": "Atomic settlement",
      "href": "/glossary#atomic-settlement",
      "coverage": "derived"
    },
    {
      "type": "glossary",
      "label": "Bill of lading",
      "href": "/glossary#bill-of-lading",
      "coverage": "derived"
    },
    {
      "type": "glossary",
      "label": "Discrepant documents",
      "href": "/glossary#discrepant-documents",
      "coverage": "derived"
    },
    {
      "type": "glossary",
      "label": "Documentary collection",
      "href": "/glossary#documentary-collection",
      "coverage": "derived"
    },
    {
      "type": "glossary",
      "label": "Fiat-backed stablecoin",
      "href": "/glossary#fiat-backed-stablecoin",
      "coverage": "derived"
    },
    {
      "type": "glossary",
      "label": "Issuing bank",
      "href": "/glossary#issuing-bank",
      "coverage": "derived"
    },
    {
      "type": "glossary",
      "label": "Letter of credit",
      "href": "/glossary#letter-of-credit",
      "coverage": "derived"
    },
    {
      "type": "glossary",
      "label": "MT700",
      "href": "/glossary#mt700",
      "coverage": "derived"
    },
    {
      "type": "glossary",
      "label": "Nominated bank",
      "href": "/glossary#nominated-bank",
      "coverage": "derived"
    },
    {
      "type": "glossary",
      "label": "Programmable payment",
      "href": "/glossary#programmable-payment",
      "coverage": "derived"
    },
    {
      "type": "glossary",
      "label": "Retail CBDC",
      "href": "/glossary#retail-cbdc",
      "coverage": "derived"
    },
    {
      "type": "glossary",
      "label": "Settlement asset",
      "href": "/glossary#settlement-asset",
      "coverage": "derived"
    },
    {
      "type": "glossary",
      "label": "Singleness of money",
      "href": "/glossary#singleness-of-money",
      "coverage": "derived"
    },
    {
      "type": "glossary",
      "label": "Token-based CBDC",
      "href": "/glossary#token-based-cbdc",
      "coverage": "derived"
    },
    {
      "type": "glossary",
      "label": "Tokenized deposit",
      "href": "/glossary#tokenized-deposit",
      "coverage": "derived"
    },
    {
      "type": "glossary",
      "label": "Tokenized settlement",
      "href": "/glossary#tokenized-settlement",
      "coverage": "derived"
    },
    {
      "type": "glossary",
      "label": "Unified ledger",
      "href": "/glossary#unified-ledger",
      "coverage": "derived"
    },
    {
      "type": "glossary",
      "label": "Wholesale CBDC",
      "href": "/glossary#wholesale-cbdc",
      "coverage": "derived"
    },
    {
      "type": "topic",
      "label": "Central bank digital currency (CBDC)",
      "href": "/learn/digital-money/central-bank-digital-currency",
      "coverage": "derived"
    },
    {
      "type": "topic",
      "label": "Forms of money: central vs commercial bank money",
      "href": "/learn/digital-money/forms-of-money-central-vs-commercial",
      "coverage": "derived"
    },
    {
      "type": "topic",
      "label": "Stablecoins and tokenized deposits",
      "href": "/learn/digital-money/stablecoins-and-tokenized-deposits",
      "coverage": "derived"
    },
    {
      "type": "topic",
      "label": "Trade finance payments",
      "href": "/learn/digital-money/trade-finance-payments",
      "coverage": "derived"
    }
  ]
}
