Architecture overview
Seven layers, one enforceable CHF promise
A CHF stablecoin is not only a token contract. It is a connected operating system in which the legal claim, reserve assets, participant controls, ledger, banking rails, distribution network and daily assurance must agree at all times.
Issuer, legal claim & licence
Who owes the CHF, and under which authorisation?
Reserve, treasury & safeguarding
What backs one token, and where is that value held?
Identity, compliance & control
Who may hold and transfer the token?
Token, ledger & key management
Where does the token run, and who controls minting?
Mint, burn & banking rails
How does CHF enter and leave the token system?
Distribution, liquidity & settlement
How does the token reach users and remain usable at par?
Operations, data & assurance
How is the system proven correct every day?
Layer by layer
What each layer must deliver
Named organisations are illustrative examples of players with relevant capabilities. Their inclusion is not an endorsement or confirmation that they participate in a particular CHF stablecoin.
LAYER 1
Issuer, legal claim & licenceCreates the legal promise behind every token and identifies the supervised entity responsible for redemption at par.
Core participants
Issuing bank or non-bank · Legal counsel · FINMA · Auditor
Example players
- UBS
- Sygnum Bank
- PostFinance
- AllUnity
- Kellerhals Carrard
- PwC Switzerland
Required components
- Issuing entity and governance
- Token-holder claim and terms
- Bank, FinTech or other applicable authorisation
- Bankruptcy-remoteness and wind-down plan
Swiss regulatory anchor
The economic function matters more than the token label. Public deposits, interest, reserve investment and the redemption promise determine whether a banking or FinTech route is available.
What changes by business model
Closed group and institutional models can use narrower access. Retail and store-of-value models need the clearest holder protection and redemption framework.
LAYER 2
Reserve, treasury & safeguardingKeeps the circulating token supply fully funded and liquid enough to meet redemption requests in stressed conditions.
Core participants
Issuer treasury · Reserve bank · Custodian · Independent auditor
Example players
- UBS
- Zürcher Kantonalbank
- SIX SIS
- KPMG Switzerland
- EY Switzerland
Required components
- Segregated CHF accounts
- Eligible reserve assets and concentration limits
- Daily supply-to-reserve reconciliation
- Liquidity buffers and attestations
Swiss regulatory anchor
Reserve ownership, segregation, liquidity and the treatment of yield are central to FINMA's assessment and to the legal nature of the holder's claim.
What changes by business model
Trading and payments need high intraday liquidity. Store of value favours maximum reserve quality; treasury models can optimise around predictable corporate flows.
LAYER 3
Identity, compliance & controlDefines participant eligibility and continuously applies AML, sanctions, transaction-monitoring and operational controls.
Core participants
Compliance team · KYC/KYB provider · Blockchain analytics · Participants
Example players
- Swisscom Trust Services
- Signicat
- Chainalysis
- TRM Labs
- Sumsub
Required components
- Customer and business onboarding
- Wallet allowlists and transaction limits
- Sanctions screening and monitoring
- Freeze, investigation and reporting workflows
Swiss regulatory anchor
The issuer and financial intermediaries must allocate AML duties clearly. Permissionless settlement does not remove onboarding, monitoring or sanctions obligations.
What changes by business model
Institutional models use KYB and named wallets. Retail models require scalable customer controls, fraud handling and consumer-support processes.
LAYER 4
Token, ledger & key managementTurns the legal CHF claim into a secure digital instrument with controlled mint, burn, pause, recovery and upgrade functions.
Core participants
Protocol team · Key custodian · Smart-contract auditor · Node operators
Example players
- Taurus
- Fireblocks
- Metaco
- Utila
- Ethereum
- Canton Network
Required components
- Token contract and ledger selection
- HSM or MPC-controlled issuer keys
- Mint, burn, pause and recovery logic
- Security audits and change governance
Swiss regulatory anchor
Technology is assessed together with the legal claim and operating controls. The design must let the issuer enforce its obligations and evidence accurate ownership and supply.
What changes by business model
Treasury can run on a permissioned ledger. Broader payments and store of value benefit from public-chain reach, while regulated trading needs venue and custody interoperability.
LAYER 5
Mint, burn & banking railsConnects bank money to token supply so every issuance follows confirmed funding and every redemption permanently removes tokens.
Core participants
Subscriber · Issuer operations · Settlement bank · SIC and payment rails
Example players
- Swiss National Bank
- SIX Interbank Clearing
- UBS
- Zürcher Kantonalbank
- PostFinance
Required components
- Subscription and redemption instructions
- SIC or account-credit confirmation
- Supply controls and four-eyes approval
- Cut-offs, queues and exception handling
Swiss regulatory anchor
Minting should follow final receipt of funds; redemption needs a documented service level, reconciliation trail and clear treatment outside banking hours.
What changes by business model
Trading values rapid institutional minting. Point-of-sale needs batching and merchant settlement; store of value prioritises dependable par redemption over speed.
LAYER 6
Distribution, liquidity & settlementConnects the primary issuer to wallets, banks, venues, merchants and market makers while maintaining reliable secondary liquidity.
Core participants
Banks and PSPs · Wallets and venues · Market makers · Merchants or corporates
Example players
- SIX Digital Exchange
- BX Digital
- Taurus
- Talos
- Wyden
- Worldline
- Partior
Required components
- Primary distributor rules
- Wallet and platform integrations
- Market-making and FX corridors
- Settlement finality and interoperability
Swiss regulatory anchor
Each distributor's role must be classified separately. Custody, exchange, payment and trading-venue activities can create additional regulatory duties.
What changes by business model
Cross-border models depend on FX and payout partners. Trading needs atomic settlement; infrastructure succeeds through broad integrations and common standards.
LAYER 7
Operations, data & assuranceKeeps the legal claim, reserve balance, token supply and participant records aligned throughout the full lifecycle.
Core participants
Issuer operations · Risk and finance · External auditor · Regulators and partners
Example players
- SAP
- Oracle
- PwC Switzerland
- Deloitte Switzerland
- KPMG Switzerland
Required components
- Ledger and bank-account reconciliation
- Proof-of-reserves and financial reporting
- Incident response and continuity testing
- Participant, regulator and management reporting
Swiss regulatory anchor
The control framework must demonstrate sound organisation, operational resilience, traceable records and timely escalation of material incidents.
What changes by business model
High-volume retail needs automated exceptions. Institutional models need service-level evidence; infrastructure models require shared governance across operators.
End-to-end lifecycle
How the layers work together
Every business model uses the same controlled loop. What changes is who may enter it, where the token circulates and how settlement creates value.
- 01
Onboard
Verify participant and wallet eligibility.
- 02
Fund
Receive confirmed CHF on the issuer's banking rail.
- 03
Mint
Approve and create the matching number of tokens.
- 04
Circulate
Transfer under ledger and compliance controls.
- 05
Settle
Complete the business payment or asset exchange.
- 06
Reconcile
Match reserves, supply and participant records.
- 07
Redeem
Burn tokens and return CHF to the eligible holder.
Architecture matrix
How the eight models differ
The issuer foundation remains regulated, but the reserve velocity, ledger reach, participant access and settlement pattern change with the use case.
| CHF business model | Issuer | Reserve | Ledger | Access | Settlement |
|---|---|---|---|---|---|
| 01Treasury Management — Intercompany Transfer | Group's relationship bank | Bank balance / segregated CHF | Permissioned enterprise ledger | Whitelisted group entities | Internal 24/7 transfer; bank redemption |
| 02Cross-border payments — B2B | Bank or bank consortium | Segregated CHF with intraday buffer | Interoperable institutional network | KYB corporates, banks and FX partners | Token transfer plus FX and local payout |
| 03Cross-border payments — B2C | Bank or licensed fintech structure | Fully backed liquid CHF | Public or widely connected network | Verified senders, wallets and payout partners | Retail transfer, FX conversion and payout |
| 04Digital-asset trading — B2B | Regulated bank issuer | High-liquidity institutional reserve | Venue-compatible DLT rails | Regulated venues and professional firms | Atomic delivery-versus-payment |
| 05Digital-asset trading — B2C | Bank or guaranteed issuer | Liquid CHF reserve | Exchange and wallet networks | Onboarded retail investors | Exchange cash leg and account redemption |
| 06CHF stablecoin as payment infrastructure | Multi-bank consortium or neutral operator | Shared, governed reserve structure | Common interoperable CHF rail | Banks, PSPs and approved platforms | Always-on shared settlement asset |
| 07B2C payments at the point of sale — with supplementary services | Bank or licensed / guaranteed issuer | Fully backed operating reserve | Low-cost payment network | Consumer wallets, acquirers and merchants | Instant payment; batched merchant payout |
| 08Store of value | Supervised bank-led structure | Highest-quality CHF / central-bank access | Public reach with controlled issuance | Verified holders and whitelisted wallets | Mint, hold and redeem at par |
Model profiles
The decisive layers for each model
Programmable CHF liquidity transfers between group companies for cash concentration, funding and settlement.
The architecture is deliberately closed: one bank, known group companies, controlled wallets and direct integration with the treasury-management system.
Decisive architecture layers
Issuer: Group's relationship bank
Settlement: Internal 24/7 transfer; bank redemption
24/7 CHF settlement leg for corporate and interbank cross-border flows.
The difficult layer is not token creation but corridor liquidity: the design must coordinate CHF funding, FX conversion and final credit to the foreign beneficiary.
Decisive architecture layers
Issuer: Bank or bank consortium
Settlement: Token transfer plus FX and local payout
Remittances and consumer transfers with a CHF leg at retail scale.
Consumer scale moves the architecture toward automated onboarding, fraud monitoring, wallet recovery and many local payout integrations.
Decisive architecture layers
Issuer: Bank or licensed fintech structure
Settlement: Retail transfer, FX conversion and payout
CHF cash leg for institutional trading, settlement and collateral.
The CHF token acts as the cash leg of a securities trade, so ledger compatibility, custody controls and atomic finality dominate the design.
Decisive architecture layers
Issuer: Regulated bank issuer
Settlement: Atomic delivery-versus-payment
CHF on/off-ramp and quote currency for retail crypto investors.
It combines institutional settlement with retail safeguards: suitability, fraud controls, wallet support and reliable off-ramping must work together.
Decisive architecture layers
Issuer: Bank or guaranteed issuer
Settlement: Exchange cash leg and account redemption
A neutral settlement asset that other providers build payment products on.
The key architecture problem is governance: participants need common technical standards, liability rules, operating controls and a neutral change process.
Decisive architecture layers
Issuer: Multi-bank consortium or neutral operator
Settlement: Always-on shared settlement asset
Everyday CHF spending at merchants, monetised through value-added services.
The architecture must hide blockchain complexity at checkout and deliver low fees, fast confirmation, refunds and predictable merchant settlement.
Decisive architecture layers
Issuer: Bank or licensed / guaranteed issuer
Settlement: Instant payment; batched merchant payout
A programmable Swiss-franc safety asset held for value preservation, not for spending.
Trust is the product. Reserve quality, legal segregation, transparent assurance and dependable redemption matter more than transaction throughput.
Decisive architecture layers
Issuer: Supervised bank-led structure
Settlement: Mint, hold and redeem at par
Continue with the business logic
Review the participants, data and value flows, business canvas and scoring for every model.
Eight CHF business modelsConfirm the legal route
Compare when a bank licence is likely and where a non-bank structure may be available.
CHF token licensing mapThis is a high-level architecture and regulatory research framework, not legal advice. The final design requires project-specific legal, risk, accounting, technology and supervisory review.
