Row of austere bank vault doors slightly ajar in a marble corridor — symbolic of deposit tokens crossing institutional boundaries on a shared rail
    Flagship · Cohort B · June 2026 · Pre-publication

    The deposit-rail governance vacancy

    Bank-issued deposit tokens settle 24/7 on a shared rail across competing institutions. The L5 governance obligation is structurally wider than Cohort A — and structurally not the rail's.

    Pre-publication · noindex · 9 min read · Cabier Intelligence

    Contents
    1. 01Executive summary
    2. 02What the deposit rail is
    3. 03Why it is not Cohort A
    4. 04Why the L5 vacancy is structurally wider
    5. 05Seven build deltas
    6. 06Cabier capabilities — Cohort B mapping
    7. 07What we will not publish
    8. 08What this is not
    9. 09Frequently asked questions
    10. 10Glossary

    Executive summary

    Bank-issued deposit tokens settled on shared 24/7 rails across competing institutions are emerging on a parallel timeline to systemic tokenised securities infrastructure. They are not stablecoins, not cryptocurrencies, and not securities. They are bank money on a new substrate.

    The L5 governance obligation above this rail has the same shape as Cohort A and is structurally wider. Operator-utility neutrality is sharper — a consortium utility cannot govern over itself. The regulatory perimeter is wider — BSA/AML, OFAC, FDIC characterisation, Reg HH and the PFMI principles, plus the April 2026 NPRMs. The cadence does not match any batch process the institution already runs.

    This brief states the category map, the seven build deltas Cabier is putting against it, and the capabilities that operate above the rail. It deliberately withholds the ORS weights, the effectiveness-grade rubric, the Trust Gate definitions, the dependency-graph internals, and the control library specifics — those are released only under signed terms at /platform/cohort-b-deposit-tokens.

    What the deposit rail is

    A shared ledger, operated by or on behalf of a consortium of regulated banks, on which each participating bank can mint a token against a customer deposit, transfer it 24/7 to another participating bank's customer, and burn it on receipt. The token is a liability of the issuing bank, characterised — where the rule set so permits — as a deposit and therefore within scope of deposit insurance.

    Operationally, the rail offers a finite control set inside the substrate, the same shape as a securities rail. Governance, accountability, exception handling, reconciliation, supervisory evidence, and AI assurance sit above and across the consortium boundary.

    Why it is not Cohort A

    Different law. Securities law does not govern deposit issuance. BSA/AML, OFAC, FDIC, Reg HH and the PFMI principles do. The April 2026 NPRMs add a banking-supervisory layer specific to shared deposit rails.

    Different cadence. A 24/7 rail with continuous mint and burn cannot be reconciled against a deposit ledger on a T+1 batch. Continuous Control Monitoring must run at the rail's cadence, not the bank's overnight cycle.

    Different topology. Cohort A is one rail under one home regulator. Cohort B is one rail across competing institutions, each with its own home regulator. The participants cannot reasonably govern each other.

    Why the L5 vacancy is structurally wider

    In Cohort A, the rail operator is a known entity under a known supervisor. The L5 obligation is the institution's, but the perimeter is relatively clean.

    In Cohort B, three things widen at once. First, the supervisory perimeter — banking law, payments law, AML law, and securities-adjacent characterisation rules layer on top of one another. Second, the operator question — a consortium utility cannot supervise itself, and no participant can credibly supervise the rail it competes on. Third, the cadence — every control, every reconciliation, every supervisory answer must hold at 24/7 cadence across the boundary.

    The vacancy is not theoretical. It is the difference between a control framework written for T+1 securities settlement and a control framework that holds when a transfer crosses the consortium boundary at 03:14 UTC on a Sunday and a regulator asks for the lineage on Monday.

    Seven build deltas

    The Cohort B build is not a new platform. It is a set of seven deltas against the existing Cabier substrate. Δ2 and Δ5 are front-loaded; Δ3, Δ6 and Δ7 are extensions; Δ1 and Δ4 are parallel content work.

    Δ1Deposit-token control set

    Banking-supervisory control library — BSA/AML, OFAC, FDIC characterisation, Reg HH and the PFMI principles, plus the April 2026 NPRMs. Parallel content effort; reuses the institutional control library substrate.

    Δ2Network-level consortium governance

    Multi-party accountability matrix, per-participant confidentiality, network exception governance, multi-tenant topology. Differentiated build; critical path for Δ3, Δ6 and Δ7. A consortium utility cannot govern over itself — this is structurally L5.

    Δ3Continuous 24/7 assurance and mint/burn ↔ deposit-ledger reconciliation

    Extends Continuous Control Monitoring to a 24/7 cadence and reconciles every mint and burn against the issuing bank's deposit ledger in near-real time.

    Δ4Characterisation and classification engine

    FDIC look-through, FATF Recommendation 16 / IVMS101 over the deposit rail via CTRE. Parallel content effort; reuses the Cabier Protocol substrate.

    Δ5Regulator and supervisor interface

    Built ahead of the rule set. Reuses the OSFI, SR 11-7 and NIS2 supervisor patterns; seeds a Cabier Protocol module for shared-rail supervision. Front-loaded.

    Δ6AI Assurance OS over deposit-rail monitoring

    Validation, drift, bias, explainability, and evidence over any model used in surveillance, screening, liquidity or pricing on the rail. Extension of the existing AI-RFOS infrastructure.

    Δ7Liquidity and intraday-risk telemetry (proposed)

    Extends the Liquidity Resilience Engine with intraday metrics across consortium participants. Depends on Δ2 and Δ3. Proposed scope, flagged for verification.

    Cabier capabilities — Cohort B mapping

    TCOSTokenization Control OS — deposit profile

    Three-lines-of-defence evidence engine reweighted for banking-supervisory law. Continuous Control Monitoring runs at 24/7 cadence; effectiveness grading replaces pass/fail attestation.

    PROTOCOLCabier Protocol — CTRE over the deposit rail

    FATF R.16 / IVMS101 envelope carried across the consortium boundary. Per-participant confidentiality preserved by design.

    AI-RFOSAI Assurance OS

    Model risk governance over any AI embedded in surveillance, screening, liquidity, or pricing decisions on the deposit rail. EU AI Act and SR 11-7 mapped.

    ORSOperational Resilience Score — deposit weighting

    Nine-dimension composite recalibrated for the deposit cohort: liquidity, BSA/AML, third-party concentration, and ICT resilience carry distinct weights from Cohort A.

    LRELiquidity Resilience Engine — intraday extension

    Basel III LCR and NSFR machinery extended with intraday telemetry across consortium participants. Proposed scope (Δ7); depends on Δ2 and Δ3.

    VAULTSingle evidence vault

    One immutable substrate behind every supervisory question — across deposit issuance, reconciliation, liquidity, AML alerts, and AI model events.

    What we will not publish

    • ORS weights. The nine-dimension composition is described publicly; the weights are not.
    • Effectiveness-grade rubric. The grade scale is described publicly; the rubric is not.
    • Trust Gate definitions. The seven gates exist; the definitions are released only under signed terms.
    • Dependency-graph internals. The graph exists; the schema and edge rules are not public.
    • Control library specifics. The categories are described publicly; the institutional control set itself is not.

    Qualified institutional readers are directed to the private brief at /platform/cohort-b-deposit-tokens, by invitation only.

    What this is not

    • Not custody. Cabier does not hold deposit tokens.
    • Not settlement. The rail settles; Cabier governs.
    • Not issuance. The bank issues; Cabier evidences.
    • Not autonomous execution. The platform is human-led; senior consultants operate it alongside the institution.
    • Not a public price. Every engagement is custom-quoted under signed terms.
    • Not a model vendor. The AI Assurance OS wraps any model in scope; Cabier does not train foundation models.

    Frequently asked questions

    What is a tokenised deposit?

    A liability of a regulated, insured bank, represented as a token on a shared ledger so that interbank transfers settle 24/7 inside the regulated banking system. It is not a stablecoin and not a cryptocurrency; it is bank money on a new substrate.

    Why is this a different cohort from tokenised securities?

    Different law (banking-supervisory and payment-system rather than securities), different cadence (24/7 mint and burn rather than T+1 settlement), different topology (shared consortium rail across competing institutions rather than a single rail under one home regulator).

    Why can't the consortium govern itself?

    Because a participant bank cannot meaningfully supervise a shared rail it co-owns and competes on. Network-level consortium governance is structurally L5 — it sits above the rail and above any single participant.

    Why is the L5 vacancy wider than Cohort A?

    Because the operator-utility-neutrality requirement is sharper, the regulatory perimeter is wider (BSA/AML, OFAC, FDIC characterisation, Reg HH, PFMI, plus the April 2026 NPRMs), and the 24/7 reconciliation requirement cannot be satisfied by batch processes the institution already runs.

    Does Cabier replace the rail's controls?

    No. The rail's controls are essential. The L5 substrate sits above them — accountability matrix, exception governance, reconciliation evidence, supervisory interface, and the AI assurance plane.

    What are the April 2026 NPRMs?

    Proposed banking-supervisory rulemakings published in April 2026 covering deposit tokens, custody, and operational resilience for shared rails. Final form pending; Cabier maps both the proposed and final text once each rulemaking concludes.

    Is FDIC insurance preserved?

    Where the token is characterised as a deposit, the underlying deposit is insured to the standard limits. Look-through characterisation, evidence of segregation, and supervisory attestation are the institution's obligation; Cabier carries the evidence.

    How does this map to BSA/AML and OFAC?

    Every transfer on the rail carries an originator/beneficiary envelope and is screened in near-real time. Cabier instruments the controls, captures the evidence, and surfaces effectiveness grading rather than pass/fail compliance.

    What about Reg HH and the PFMI principles?

    Where the shared rail is a designated financial market utility or analogous payment system, Reg HH and the PFMI principles apply. Cabier produces the operational, risk-management, and resilience evidence on the institution's behalf.

    Does this work for non-US deposit rails?

    Yes. The same substrate maps to UK FCA, EU DORA, MAS Singapore, JFSA Japan, and OSFI Canada. Sovereign deployments and on-shore residency are supported.

    How fast is mint/burn reconciliation?

    Near-real time, against the issuing bank's deposit ledger. The cadence is set by the rail; Cabier matches it.

    Is Cabier endorsed by any rail operator?

    Endorsement and reference-implementation arrangements are handled privately. The companion private brief at /platform/cohort-b-deposit-tokens covers the partnership and verification status.

    What does the regulator-facing interface expose?

    ORS lineage, control effectiveness grades, reconciliation evidence, model-risk artefacts, and incident reports — at the depth the supervisor specifies, scoped to the participating institution.

    Is this in production?

    No. The deposit-rail cohort targets H1 2027. Cabier's substrate exists in production for Cohort A and adjacent banking workstreams; the Cohort B build is the deltas described above.

    Is there a public price list?

    No. Every engagement is custom-quoted under signed terms. Public price cards distort institutional procurement and we refuse to publish them.

    Can a participating bank stand up its own L5 internally?

    It can attempt to. The question is whether the network-level consortium governance, the 24/7 reconciliation, and the regulator-facing interface can be built credibly inside any single participant — and whether the other participants will accept that bank's instrumentation as neutral.

    What is Cabier withholding from this article?

    ORS weights, the effectiveness-grade rubric, the Trust Gate definitions, the dependency-graph internals, and the institutional control library specifics. The category map is published; the operating disclosure is released only under signed terms.

    Where is the named competitor comparison?

    Under non-disclosure at /insights/tokenization-named-comparison. The matrix carries a TCH column for Cohort B alongside the Cohort A entries.

    Glossary

    Cohort B
    Tokenised deposits — bank-issued money on shared 24/7 rails, governed by banking-supervisory and payment-system law. Targeting H1 2027.
    Deposit token
    A token representing a liability of a regulated, insured bank, transferable on a shared ledger.
    Consortium utility
    A shared rail operated collectively by participating banks; cannot govern over itself by design.
    L5 — Governance, Control & Assurance
    The institutional governance layer above the tokenisation stack. Structurally wider for Cohort B than Cohort A.
    Operator-utility neutrality
    The structural requirement that L5 governance be operated by a neutral party, not a participating bank.
    BSA/AML
    US Bank Secrecy Act and Anti-Money Laundering framework; primary AML perimeter for US deposit rails.
    OFAC
    US Office of Foreign Assets Control sanctions screening; screens every transfer in near-real time.
    FDIC characterisation
    The look-through analysis determining whether the token carries deposit insurance and the evidence sustaining that characterisation.
    Reg HH
    Federal Reserve regulation governing designated financial market utilities — relevant where a shared rail is so designated.
    PFMI
    CPMI–IOSCO Principles for Financial Market Infrastructures; the international baseline for systemically important payment systems.
    April 2026 NPRMs
    Proposed banking-supervisory rulemakings published April 2026 covering deposit tokens, custody, and shared-rail operational resilience.
    Mint/burn reconciliation
    Continuous matching of token mint and burn events on the rail against the issuing bank's deposit ledger.
    24/7 cadence
    Continuous operation of the rail; controls and reconciliation must match the cadence.
    FATF Recommendation 16
    Travel Rule — originator/beneficiary data for value transfers; applies across the deposit rail.
    IVMS101
    The InterVASP messaging standard for originator/beneficiary data; carried in Cabier's CTRE envelope.
    CTRE
    Cabier Protocol's cross-rail Travel Rule envelope. Used here to carry IVMS101 over the deposit rail.
    TCOS
    Tokenization Control OS — three-lines-of-defence evidence engine. Deposit profile reweights for banking-supervisory law.
    AI Assurance OS
    Model risk governance over any AI embedded in surveillance, screening, liquidity, or pricing on the rail.
    ORS
    Operational Resilience Score — nine-dimension composite; deposit weighting differs from Cohort A.
    LRE
    Liquidity Resilience Engine — Basel III LCR and NSFR calculators; proposed intraday extension under Δ7.
    Evidence vault
    Single immutable substrate behind every supervisory question.
    Calculation tree
    Reproducible lineage of any score, grade, or attestation.
    Cohort A
    Tokenised securities — addressed in the companion brief.
    Above the rail
    Cabier's positioning. The rail settles; Cabier governs.
    Custom quote
    No engagement is publicly priced; every scope is sized and quoted under signed terms.

    Continue reading

    The companion flagship covers Cohort A — the L5 obligation above the mid-2026 securities rail.

    References and citations

    Primary sources. Positions change; verify at source before relying on any figure or determination.

    1. 1Bank for International Settlements, Annual Economic Report — unified ledgers and tokenised depositsThe conceptual architecture for tokenised commercial bank money.Source
    2. 2Basel Committee on Banking Supervision, Prudential treatment of cryptoasset exposures (SCO60)Capital treatment of tokenised exposures.Source
    3. 3Regulation (EU) 2023/1114 (MiCA)EU treatment of e-money tokens versus deposits.Source
    4. 4Committee on Payments and Market Infrastructures and IOSCO, Principles for Financial Market InfrastructuresSettlement finality and operational risk principles.Source