Positioning · 2026

    Six obligations the rail cannot discharge.

    When systemic tokenisation infrastructure begins production trades in mid-2026, every participating institution inherits a governance obligation that the rail itself cannot answer. Tokenisation networks, global CSD rails, and Big Four advisory each own part of the stack. Cabier operates the layer above — the governance, control and assurance plane every participating institution owns.

    The Stack

    Five layers. The top one belongs to the institution.

    L1 through L4 are operated inside the rail. L5 sits above it — and no rail operator's home authorisation can answer for it on behalf of a participating bank, asset manager, custodian or pension scheme.

    The tokenisation stack — both rails
    L5
    Governance, Control & Assurance
    Cabier — TCOS, Cabier Protocol, AI Assurance OS

    Above both rails — tokenised securities and tokenised deposits. Cross-framework ORS, effectiveness-graded controls, immutable calculation lineage, six-obligation coverage, human-led assurance across 6+ jurisdictions.

    Above the rail
    L4
    Network & Consortia
    Tokenisation networks · permissioned-ledger frameworks

    Membership rules, validator coordination, network-level operating standards inside a single rail.

    L3
    Smart-Contract Runtime
    Ledger runtimes · DLT platforms

    Asset-level lifecycle primitives: mint, burn, freeze, unfreeze, force transfer, clawback, pause.

    L2
    CSD, Custody & Transfer Agency
    Global CSD rails · licensed custodians

    Securities-account bookkeeping, settlement participant authorisation, custody segregation under a single home regulator.

    L1
    Settlement Finality & Cash Leg
    Securities rails — CSDs · central-bank money · wholesale CBDC

    Atomic DvP, finality, and the cash leg of securities settlement. Cohort A.

    L1-D
    Deposit-Rail Settlement (Cohort B)
    The Clearing House · BNY · Cari Network · DBS / Kinexys

    Bank-issued deposit tokens settled 24/7 inside the regulated, insured banking system. Operator-utility neutrality — no participant bank can own governance over a shared rail.

    L1–L4 are operated by the rail itself. L5 is the institution's own obligation — it cannot be discharged by any rail operator's home authorisation.

    The six obligations

    What every participating institution still owns.

    Each of these must be answered to the institution's own board, internal audit, and home regulator — independent of any authorisation held by the rail operator.

    Basel III RWA
    Capital treatment of tokenised assets on the participating institution's own balance sheet.
    DORA ICT mapping
    Article 28 third-party register, exit strategy, and concentration testing where the rail is a critical ICT provider.
    MiCA Title III / IV
    EU asset-referenced and e-money token obligations independent of the rail's home authorisation.
    MAS / FCA / SEC
    Local custody, AML, transaction-reporting, and conduct duties in every market the institution operates.
    Travel Rule (FATF R.16)
    Cross-chain and unhosted-wallet originator/beneficiary data once the asset leaves the rail.
    Model risk (SR 11-7 / EU AI Act)
    Governance of any AI inside tokenised workflows — owned by the institution, not the rail.
    Capability matrix

    Where governance belongs to whom.

    Categories — not individual vendors. Tokenisation networks operate L3–L4; global CSD rails operate L1–L2; Big Four advisory provides programmatic assurance. None of them sits in L5 as a deployed control plane.

    CapabilityTokenisation networksGlobal CSD railsBig Four advisoryCabier TCOS
    Continuous Control Monitoring
    Always-on monitoring across 8 control domains, not point-in-time audit.
    Effectiveness-graded controls
    Controls graded on operating effectiveness — not pass/fail evidence collection.
    Cross-framework ORS
    Single resilience score mapped to DORA, NIS2, SR 11-7, OSFI E-23, SMCR, BCBS 239, FFIEC CAT, MiCA.
    Six-obligation coverage
    Issuer, custodian, transfer agent, settlement participant, oracle/data provider, governance authority — mapped in one plane.
    Cross-jurisdiction breadth
    JFSA, OSFI, FCA, SEC, MAS, FINMA, MiCA, EU AI Act in a single control surface.
    Immutable calculation lineage
    Every ORS movement traced to the underlying signal, evidence, and method — regulator-ready.
    AI assurance for tokenised workflows
    EU AI Act classifier, SR 11-7 model risk, continuous bias and drift across models embedded in token operations.
    Cross-chain Travel Rule envelope
    Originator/beneficiary data once the asset leaves the rail (FATF R.16, IVMS101).
    Human-led senior assurance
    Named senior consultants attached to every deployment — not a self-serve SaaS.
    Engagement Intelligence Vault
    Confidential per-engagement evidence vault; never co-mingled.
    Deployment velocity
    Weeks, not multi-year programmes.
    Covered as a deployed control Partial — programmatic or scoped Not in scope

    A named-stack comparison is available under NDA.

    For institutional sponsors, rail operators, and regulator participants, Cabier publishes a private working brief that maps the governance layer onto specific tokenisation networks, CSD rails, and advisory programmes. Distribution is by invitation.