Insights

Stablecoin payment infrastructure: what financial institutions actually need

Choosing a token and a chain is one layer of the stack. It is not the architecture.

Definition

Institutional stablecoin payment infrastructure is the full stack required to move regulated digital money in production: legal perimeter, issuer, custody, liquidity, FX, settlement ledger, controls, reconciliation, on/off-ramps and domestic payout. Choosing a token and a chain is one layer of that stack, not the architecture.

The Institutional Stablecoin Stack

The Institutional Stablecoin StackRegulation → money/issuer → liquidity → settlement → controls/reconciliation → payout.. Institutional & regulatory, Money / issuer, Funding & liquidity, Settlement, Controls & reconciliation, Local banking / payout.01Institutional & regulatoryLicensed institutions and the regulatory perimeteraround the flow.02Money / issuerRegulated digital money and the institution thatissues it.03Funding & liquidityPrefunding, FX and the liquidity that lets valuemove.04SettlementWhere value actually moves between institutions.05Controls & reconciliationIdentity and screening, custody and keys,reconciliation.06Local banking / payoutDomestic banking relationships and a working lastmile.
  1. Institutional & regulatory. Licensed institutions and the regulatory perimeter around the flow.
  2. Money / issuer. Regulated digital money and the institution that issues it.
  3. Funding & liquidity. Prefunding, FX and the liquidity that lets value move.
  4. Settlement. Where value actually moves between institutions.
  5. Controls & reconciliation. Identity and screening, custody and keys, reconciliation.
  6. Local banking / payout. Domestic banking relationships and a working last mile.
Regulation → money/issuer → liquidity → settlement → controls/reconciliation → payout.

Diagram (SVG)

Why picking a token and a chain is not an architecture

Most institutional stablecoin projects begin with two questions: which token, and which chain. Both are real decisions. Neither is the architecture. A production payment flow is a chain of licensed institutions, funded positions, conversion points and controls, and the token and ledger occupy exactly two layers of it. The other layers – who holds the licence, who funds the corridor, who converts the currency, who pays out the last mile, who reconciles the books – do not appear on a token comparison sheet, and they are where corridors succeed or fail.

The stack above is the shape of the work. Each layer is a set of named decisions with a named owner. An institution that can answer every layer has an architecture. An institution that has chosen a token and a chain has a procurement preference. The rest of this essay walks the stack from the legal perimeter down to the last mile, in the order the decisions actually constrain each other.

Money and issuer

The settlement asset is a liability of a specific institution. That institution – the issuer – determines what the asset legally is, what backs it, how it is issued and redeemed, and under whose supervision. Instrument choice therefore precedes chain choice: an institution should select the regulated money that matches its currency, its counterparties and its legal perimeter, and only then ask which ledgers that money can move on.

Issuer risk is counterparty risk and should be assessed the same way: reserve composition, redemption terms, supervision, concentration, and the issuer’s own operational controls, including its power to freeze or claw back balances. In the live Europe–Ethiopia corridor, regulated euro e-money is provided by Quantoz Payments, an electronic money institution supervised by De Nederlandsche Bank – a licensed issuer inside the perimeter, not an anonymous instrument bolted onto it.

Accounts, wallets and custody

On an account-based ledger, holding the settlement asset means controlling keys. The custody question is who controls which accounts, under what signing arrangements, with what procedures for compromise, loss and personnel change. It is a governance decision before it is a technology decision: single-signature operational accounts, multi-signature treasury accounts and delegated signing arrangements distribute both convenience and blast radius differently.

Custody is also a recurring operational cost, not a one-time setup. Key ceremonies, rotation, access reviews and recovery drills all have to be owned by someone with the institutional standing to be audited on them. If no participant is prepared to carry that burden, that is a finding about the corridor, not a detail to defer.

Funding and liquidity

Value does not move because a ledger exists; it moves because someone funded a position. Every corridor has a funding model: who acquires the settlement asset, in what size, ahead of or at the moment of payment, and who carries the inventory risk while holding it. Faster settlement can shrink the window that capital sits idle, and a common settlement asset can replace several prepaid currencies with one position.

The honest formulation is that prefunding often moves rather than disappears. Someone still holds the sending currency today to pay out the local currency tomorrow; the question is who, in what instrument, and for how long. Partners in the Ethiopia corridor have said publicly – the Quantoz CEO, in the Cooperative Bank of Oromia announcement – that a regulated digital euro can reduce the need for costly pre-funding. Assess that potential benefit against the positions and funding responsibilities of the proposed corridor.

FX

A stablecoin is denominated in one currency. If the payment starts or ends in another, conversion still happens, and someone still holds the FX exposure and earns or pays the spread. The architectural question is where conversion sits: at the on-ramp, at the off-ramp, or inside the receiving institution – and who is licensed and capitalised to hold the position at that point.

Moving settlement onto a ledger does not create an FX market where none exists. In corridors with managed or thin currency markets, the FX leg is often the binding constraint, and it deserves the same design attention as the settlement leg. A corridor diagram that shows an arrow labelled “FX” with no named counterparty behind it is not finished.

Settlement ledger

The ledger’s job is narrow and valuable: to be the shared, deterministic record of the transfer between institutions. Done well, it contributes settlement outside conventional banking windows, unambiguous state while a payment is in flight, issued-currency semantics that match how regulated money actually behaves, and programmable controls at the account where policy is needed.

Chain choice follows the flow’s requirements – control model, operating characteristics, counterparty acceptance – not the reverse. INFTF contributes to Xahau infrastructure and brings experience with its account-based financial model. Xahau is the settlement layer in the live Ethiopia corridor. For another flow, asset availability, liquidity, custody support and counterparties may point to a different rail.

Controls

A settlement flow needs a control model covering screening, monitoring, authorisation and limits, together with any freeze or clawback powers under the asset model. Establish which controls are required, where each executes and which institution owns its outcome.

Some controls can move onto the ledger itself: account-level authorisation, transfer limits, allow-lists enforced at the settlement account rather than reconstructed in surrounding systems. That is genuinely useful where policy must travel with the payment. But a control nobody has rehearsed is a diagram, not a control. Freeze rules, escalation paths and the order of operations under an alert belong in the corridor design, with named responsibility, before the first live payment.

On-ramps and off-ramps

Fiat enters and leaves the flow through licensed institutions: an on-ramp converts fiat into the settlement asset, an off-ramp converts it back. These are regulated conversion points with their own counterparty risk, capacity limits, operating hours and fee structures – and a corridor is only as strong as its weakest ramp. Fast ledger settlement is worth little if the off-ramp batches redemptions overnight.

Ramps are where the elegant middle of the architecture meets the constraints of real banking relationships. Assess them the way a treasurer would: throughput, cut-offs, concentration, and what happens when the ramp is unavailable for a day.

Reconciliation

Reconciliation does not disappear because the ledger is shared. Each institution still reconciles the ledger record against its own books, its payment messages, its FX positions and its payout confirmations. What changes is the quality of one input: the settlement leg stops being inferred from messages and statements and becomes a fact both sides can read from the same record.

That is a real operational gain – less ambiguity, fewer breaks, faster investigation – but it has to be engineered, not assumed. The mapping between ledger transactions and internal references, the treatment of partial failures, and the ownership of unmatched items are design work. “The blockchain is the source of truth” is a slogan; a reconciliation procedure is a document with an owner.

Domestic payout

The last mile is domestic, licensed and non-negotiable. A recipient is paid in local currency, into an account or over a rail they already use, by an institution permitted to do so. In the Ethiopia corridor that institution is Cooperative Bank of Oromia, and the design point generalises: the recipient never needs to hold, see or understand the settlement asset. The customer experience remains a bank payment.

This layer is why domestic banking reach remains essential to every stablecoin corridor. A settlement asset with no payout partner reaches an account balance, not a person. Institutions evaluating a corridor should weigh the payout leg – coverage, capacity, local compliance – as heavily as any property of the ledger.

Monitoring and reporting

A production corridor is observed in three directions at once. Operationally: is the flow healthy – ramps up, liquidity sufficient, settlement confirming, payout completing. For compliance: screening hits, unusual patterns, threshold reports, each feeding the institution’s existing frameworks rather than a parallel one. And for regulators: the reporting each supervisor expects, in the form it expects, produced on time.

The ledger helps here more than it is usually credited for: a deterministic shared record is a strong substrate for monitoring. But substrate is not system. Alerting, dashboards, audit trails and regulatory returns are built, owned and staffed – and they should exist before volume does.

Failure paths

Every layer of the stack has a failure mode, and the corridor design should name each one with its response. The issuer freezes an account or suspends redemption. An on-ramp or off-ramp loses capacity. Liquidity runs short mid-day. A key is compromised. The ledger or a participant’s infrastructure is degraded. A partner exits the corridor. Each requires an agreed response and a responsible participant.

The test of an architecture is not whether these events occur but whether the response is designed: who is notified, what halts, what falls back to an alternative rail, how customers are made whole, and in what order service resumes. Fallback and recovery are the final item in the corridor checklist and need to be designed alongside the normal payment flow.

Responsibility matrix

Map the required functions to the institutions responsible for them. The illustrative allocation below is a starting point for that discussion; custody, funding and conversion roles depend on the agreed model. INFTF contributes architecture, prototypes, blockchain integration support and coordination. The business parties manage issuance, compliance checks and production operations.

Illustrative allocation of responsibilities, to be agreed for each flow.

FunctionIssuerPSP / networkDomestic bankLedgerINFTF
Licence & perimeterLicensed to issue the settlement assetLicensed for cross-border payment servicesLicensed for domestic accounts and payoutNone – a ledger holds no licenceMaps the perimeter; holds no licence
Issuance & redemptionIssues and redeems against reservesAcquires and redeems as a counterparty–Records issued balances–
Onboarding & screeningScreens its institutional counterpartiesKYC on senders; screening in flightKYC on recipients; local compliance––
Custody & keysControls issuing accountsCustody of its settlement balancesCustody of its settlement balancesEnforces signatures; holds no keysAdvises on the key model
Liquidity & FXManages reservesFunds the corridor; carries FX exposure where agreedLocal-currency liquidity for payout––
Settlement recordReconciles to itReconciles to itReconciles to itThe shared, deterministic record–
Domestic payout–Delivers instruction to the payout institutionPays out in local currency––
Architecture & coordinationOwns issuer-side designOwns network-side designOwns payout-side design–Contributes architecture; connects the parties

A practical readiness checklist

These fifteen decisions provide a starting point for assessing readiness. Work through each with the participating institutions, identify an owner and record what needs to be resolved before implementation.

  1. Origin jurisdictions – regulators and licences on the sending leg, named
  2. Destination jurisdictions – the receiving perimeter, confirmed in writing
  3. Asset / currency – the settlement instrument and its legal classification
  4. Issuer – regulated, supervised, with assessed redemption terms
  5. On-ramp – a licensed conversion point with known capacity and cut-offs
  6. Ledger – chosen for the flow’s control and operating requirements
  7. Custody / key model – account control, signing and recovery, owned
  8. Liquidity – the funding model and who carries the position
  9. FX – where conversion happens and who holds the exposure
  10. Receiving institution – licensed, capable, contractually committed
  11. Payout rails – the domestic last mile, tested end to end
  12. Controls / screening – each control placed, owned and rehearsed
  13. Reconciliation – ledger-to-books mapping and break ownership
  14. Reporting – regulatory and operational reporting, built before volume
  15. Fallback / recovery – what halts, what falls back, who decides