Module · Financial Systems Assurance

    The whole rail estate, legacy and digital, in one register.

    Institutions do not run a tokenisation programme and a payments programme. They run an estate of rails, some of them forty years old and some of them eighteen months old, and every one of them carries a supervisory obligation and a failure mode. This is that estate mapped: what each rail does, what obligation using it creates, where finality actually sits, and which control domains carry it.

    14 rail classes mappedLegacy · hybrid · digitalMapped to the control spine

    Finality is a legal question

    Operations teams treat a successful message as a completed payment. On most rails it is not. Where finality actually sits determines the exposure the institution is carrying, and half the rails in use have never had that question answered in writing.

    The new rails inherit the old failures

    Tokenised settlement removes principal risk only when both legs sit on the ledger. Where one leg settles conventionally, the atomicity claim collapses and the institution is back to the exposure the design was meant to remove.

    One control estate, every rail

    A reconciliation control is the same control whether it runs against a custodian statement or a chain extract. Modelling digital rails as a separate programme is how institutions end up with two standards and one exposure.

    The rail register

    Open a rail to see what it obliges you to hold

    Role in the estate

    Cross-border value movement through nostro and vostro relationships, still the default path where no direct scheme access exists.

    Obligation carried

    Respondent due diligence, nesting transparency, complete originator and beneficiary information, and sanctions screening on every leg.

    Where finality sits

    No single finality point — each leg settles on its own domestic rail, so exposure persists until the last leg completes.

    Failure that matters

    Nested relationships the institution never diligenced, and field stripping that removes the information screening depends on.

    Control domains carrying this rail

    C32 Correspondent and cross-border rails · C38 Sanctions and export control screening · C20 Concentration and dependency control

    Also carried by era and by the estate around it

    C09 Financial crime and sanctions · C13 AI governance · C14 Model risk management · C06 IT general controls · C33 Legacy core and end-of-life technology · C01 Governance and accountability · C02 Regulatory obligation management · C03 Policy lifecycle · C04 Risk and control self-assessment · C05 Reconciliation and financial integrity · C11 Third-party and outsourcing risk · C12 Operational resilience · C15 Data lineage and reporting integrity · C24 Evidence, audit and attestation

    Rail-specific domains set the settlement question. The domains beneath them are the ones a supervisor reaches for anyway: who owns it, what booked it, what reconciles it, who else touches it, and what evidence survives the examination.