CHF issuance · architecture

Architecture for issuing a CHF stablecoin

One regulated issuance foundation, adapted to eight different business models. The layers below show what must be built, who participates, and which design decisions change with each use case.

Architecture overview

Seven layers, one enforceable CHF promise

A CHF stablecoin is not only a token contract. It is a connected operating system in which the legal claim, reserve assets, participant controls, ledger, banking rails, distribution network and daily assurance must agree at all times.

1

Issuer, legal claim & licence

Who owes the CHF, and under which authorisation?

2

Reserve, treasury & safeguarding

What backs one token, and where is that value held?

3

Identity, compliance & control

Who may hold and transfer the token?

4

Token, ledger & key management

Where does the token run, and who controls minting?

5

Mint, burn & banking rails

How does CHF enter and leave the token system?

6

Distribution, liquidity & settlement

How does the token reach users and remain usable at par?

7

Operations, data & assurance

How is the system proven correct every day?

Layer by layer

What each layer must deliver

Named organisations are illustrative examples of players with relevant capabilities. Their inclusion is not an endorsement or confirmation that they participate in a particular CHF stablecoin.

  1. LAYER 1

    Issuer, legal claim & licence

    Creates the legal promise behind every token and identifies the supervised entity responsible for redemption at par.

    Core participants

    Issuing bank or non-bank · Legal counsel · FINMA · Auditor

    Example players

    • UBS
    • Sygnum Bank
    • PostFinance
    • AllUnity
    • Kellerhals Carrard
    • PwC Switzerland

    Required components

    • Issuing entity and governance
    • Token-holder claim and terms
    • Bank, FinTech or other applicable authorisation
    • Bankruptcy-remoteness and wind-down plan

    Swiss regulatory anchor

    The economic function matters more than the token label. Public deposits, interest, reserve investment and the redemption promise determine whether a banking or FinTech route is available.

    What changes by business model

    Closed group and institutional models can use narrower access. Retail and store-of-value models need the clearest holder protection and redemption framework.

  2. LAYER 2

    Reserve, treasury & safeguarding

    Keeps the circulating token supply fully funded and liquid enough to meet redemption requests in stressed conditions.

    Core participants

    Issuer treasury · Reserve bank · Custodian · Independent auditor

    Example players

    • UBS
    • Zürcher Kantonalbank
    • SIX SIS
    • KPMG Switzerland
    • EY Switzerland

    Required components

    • Segregated CHF accounts
    • Eligible reserve assets and concentration limits
    • Daily supply-to-reserve reconciliation
    • Liquidity buffers and attestations

    Swiss regulatory anchor

    Reserve ownership, segregation, liquidity and the treatment of yield are central to FINMA's assessment and to the legal nature of the holder's claim.

    What changes by business model

    Trading and payments need high intraday liquidity. Store of value favours maximum reserve quality; treasury models can optimise around predictable corporate flows.

  3. LAYER 3

    Identity, compliance & control

    Defines participant eligibility and continuously applies AML, sanctions, transaction-monitoring and operational controls.

    Core participants

    Compliance team · KYC/KYB provider · Blockchain analytics · Participants

    Example players

    • Swisscom Trust Services
    • Signicat
    • Chainalysis
    • TRM Labs
    • Sumsub

    Required components

    • Customer and business onboarding
    • Wallet allowlists and transaction limits
    • Sanctions screening and monitoring
    • Freeze, investigation and reporting workflows

    Swiss regulatory anchor

    The issuer and financial intermediaries must allocate AML duties clearly. Permissionless settlement does not remove onboarding, monitoring or sanctions obligations.

    What changes by business model

    Institutional models use KYB and named wallets. Retail models require scalable customer controls, fraud handling and consumer-support processes.

  4. LAYER 4

    Token, ledger & key management

    Turns the legal CHF claim into a secure digital instrument with controlled mint, burn, pause, recovery and upgrade functions.

    Core participants

    Protocol team · Key custodian · Smart-contract auditor · Node operators

    Example players

    • Taurus
    • Fireblocks
    • Metaco
    • Utila
    • Ethereum
    • Canton Network

    Required components

    • Token contract and ledger selection
    • HSM or MPC-controlled issuer keys
    • Mint, burn, pause and recovery logic
    • Security audits and change governance

    Swiss regulatory anchor

    Technology is assessed together with the legal claim and operating controls. The design must let the issuer enforce its obligations and evidence accurate ownership and supply.

    What changes by business model

    Treasury can run on a permissioned ledger. Broader payments and store of value benefit from public-chain reach, while regulated trading needs venue and custody interoperability.

  5. LAYER 5

    Mint, burn & banking rails

    Connects bank money to token supply so every issuance follows confirmed funding and every redemption permanently removes tokens.

    Core participants

    Subscriber · Issuer operations · Settlement bank · SIC and payment rails

    Example players

    • Swiss National Bank
    • SIX Interbank Clearing
    • UBS
    • Zürcher Kantonalbank
    • PostFinance

    Required components

    • Subscription and redemption instructions
    • SIC or account-credit confirmation
    • Supply controls and four-eyes approval
    • Cut-offs, queues and exception handling

    Swiss regulatory anchor

    Minting should follow final receipt of funds; redemption needs a documented service level, reconciliation trail and clear treatment outside banking hours.

    What changes by business model

    Trading values rapid institutional minting. Point-of-sale needs batching and merchant settlement; store of value prioritises dependable par redemption over speed.

  6. LAYER 6

    Distribution, liquidity & settlement

    Connects the primary issuer to wallets, banks, venues, merchants and market makers while maintaining reliable secondary liquidity.

    Core participants

    Banks and PSPs · Wallets and venues · Market makers · Merchants or corporates

    Example players

    • SIX Digital Exchange
    • BX Digital
    • Taurus
    • Talos
    • Wyden
    • Worldline
    • Partior

    Required components

    • Primary distributor rules
    • Wallet and platform integrations
    • Market-making and FX corridors
    • Settlement finality and interoperability

    Swiss regulatory anchor

    Each distributor's role must be classified separately. Custody, exchange, payment and trading-venue activities can create additional regulatory duties.

    What changes by business model

    Cross-border models depend on FX and payout partners. Trading needs atomic settlement; infrastructure succeeds through broad integrations and common standards.

  7. LAYER 7

    Operations, data & assurance

    Keeps the legal claim, reserve balance, token supply and participant records aligned throughout the full lifecycle.

    Core participants

    Issuer operations · Risk and finance · External auditor · Regulators and partners

    Example players

    • SAP
    • Oracle
    • PwC Switzerland
    • Deloitte Switzerland
    • KPMG Switzerland

    Required components

    • Ledger and bank-account reconciliation
    • Proof-of-reserves and financial reporting
    • Incident response and continuity testing
    • Participant, regulator and management reporting

    Swiss regulatory anchor

    The control framework must demonstrate sound organisation, operational resilience, traceable records and timely escalation of material incidents.

    What changes by business model

    High-volume retail needs automated exceptions. Institutional models need service-level evidence; infrastructure models require shared governance across operators.

End-to-end lifecycle

How the layers work together

Every business model uses the same controlled loop. What changes is who may enter it, where the token circulates and how settlement creates value.

  1. 01

    Onboard

    Verify participant and wallet eligibility.

  2. 02

    Fund

    Receive confirmed CHF on the issuer's banking rail.

  3. 03

    Mint

    Approve and create the matching number of tokens.

  4. 04

    Circulate

    Transfer under ledger and compliance controls.

  5. 05

    Settle

    Complete the business payment or asset exchange.

  6. 06

    Reconcile

    Match reserves, supply and participant records.

  7. 07

    Redeem

    Burn tokens and return CHF to the eligible holder.

Architecture matrix

How the eight models differ

The issuer foundation remains regulated, but the reserve velocity, ledger reach, participant access and settlement pattern change with the use case.

CHF business modelIssuerReserveLedgerAccessSettlement
01Treasury Management — Intercompany TransferGroup's relationship bankBank balance / segregated CHFPermissioned enterprise ledgerWhitelisted group entitiesInternal 24/7 transfer; bank redemption
02Cross-border payments — B2BBank or bank consortiumSegregated CHF with intraday bufferInteroperable institutional networkKYB corporates, banks and FX partnersToken transfer plus FX and local payout
03Cross-border payments — B2CBank or licensed fintech structureFully backed liquid CHFPublic or widely connected networkVerified senders, wallets and payout partnersRetail transfer, FX conversion and payout
04Digital-asset trading — B2BRegulated bank issuerHigh-liquidity institutional reserveVenue-compatible DLT railsRegulated venues and professional firmsAtomic delivery-versus-payment
05Digital-asset trading — B2CBank or guaranteed issuerLiquid CHF reserveExchange and wallet networksOnboarded retail investorsExchange cash leg and account redemption
06CHF stablecoin as payment infrastructureMulti-bank consortium or neutral operatorShared, governed reserve structureCommon interoperable CHF railBanks, PSPs and approved platformsAlways-on shared settlement asset
07B2C payments at the point of sale — with supplementary servicesBank or licensed / guaranteed issuerFully backed operating reserveLow-cost payment networkConsumer wallets, acquirers and merchantsInstant payment; batched merchant payout
08Store of valueSupervised bank-led structureHighest-quality CHF / central-bank accessPublic reach with controlled issuanceVerified holders and whitelisted walletsMint, hold and redeem at par

Model profiles

The decisive layers for each model

01
Treasury Management — Intercompany Transfer

Programmable CHF liquidity transfers between group companies for cash concentration, funding and settlement.

The architecture is deliberately closed: one bank, known group companies, controlled wallets and direct integration with the treasury-management system.

Decisive architecture layers

1 · Issuer, legal claim & licence3 · Identity, compliance & control4 · Token, ledger & key management

Issuer: Group's relationship bank

Settlement: Internal 24/7 transfer; bank redemption

02
Cross-border payments — B2B

24/7 CHF settlement leg for corporate and interbank cross-border flows.

The difficult layer is not token creation but corridor liquidity: the design must coordinate CHF funding, FX conversion and final credit to the foreign beneficiary.

Decisive architecture layers

2 · Reserve, treasury & safeguarding5 · Mint, burn & banking rails6 · Distribution, liquidity & settlement

Issuer: Bank or bank consortium

Settlement: Token transfer plus FX and local payout

03
Cross-border payments — B2C

Remittances and consumer transfers with a CHF leg at retail scale.

Consumer scale moves the architecture toward automated onboarding, fraud monitoring, wallet recovery and many local payout integrations.

Decisive architecture layers

3 · Identity, compliance & control6 · Distribution, liquidity & settlement7 · Operations, data & assurance

Issuer: Bank or licensed fintech structure

Settlement: Retail transfer, FX conversion and payout

04
Digital-asset trading — B2B

CHF cash leg for institutional trading, settlement and collateral.

The CHF token acts as the cash leg of a securities trade, so ledger compatibility, custody controls and atomic finality dominate the design.

Decisive architecture layers

4 · Token, ledger & key management5 · Mint, burn & banking rails6 · Distribution, liquidity & settlement

Issuer: Regulated bank issuer

Settlement: Atomic delivery-versus-payment

05
Digital-asset trading — B2C

CHF on/off-ramp and quote currency for retail crypto investors.

It combines institutional settlement with retail safeguards: suitability, fraud controls, wallet support and reliable off-ramping must work together.

Decisive architecture layers

3 · Identity, compliance & control6 · Distribution, liquidity & settlement7 · Operations, data & assurance

Issuer: Bank or guaranteed issuer

Settlement: Exchange cash leg and account redemption

06
CHF stablecoin as payment infrastructure

A neutral settlement asset that other providers build payment products on.

The key architecture problem is governance: participants need common technical standards, liability rules, operating controls and a neutral change process.

Decisive architecture layers

1 · Issuer, legal claim & licence4 · Token, ledger & key management7 · Operations, data & assurance

Issuer: Multi-bank consortium or neutral operator

Settlement: Always-on shared settlement asset

07
B2C payments at the point of sale — with supplementary services

Everyday CHF spending at merchants, monetised through value-added services.

The architecture must hide blockchain complexity at checkout and deliver low fees, fast confirmation, refunds and predictable merchant settlement.

Decisive architecture layers

3 · Identity, compliance & control5 · Mint, burn & banking rails6 · Distribution, liquidity & settlement

Issuer: Bank or licensed / guaranteed issuer

Settlement: Instant payment; batched merchant payout

08
Store of value

A programmable Swiss-franc safety asset held for value preservation, not for spending.

Trust is the product. Reserve quality, legal segregation, transparent assurance and dependable redemption matter more than transaction throughput.

Decisive architecture layers

1 · Issuer, legal claim & licence2 · Reserve, treasury & safeguarding7 · Operations, data & assurance

Issuer: Supervised bank-led structure

Settlement: Mint, hold and redeem at par

Continue with the business logic

Review the participants, data and value flows, business canvas and scoring for every model.

Eight CHF business models

Confirm the legal route

Compare when a bank licence is likely and where a non-bank structure may be available.

CHF token licensing map

This is a high-level architecture and regulatory research framework, not legal advice. The final design requires project-specific legal, risk, accounting, technology and supervisory review.