This is an old revision of the document!
The Bank for International Settlements (BIS) has produced a paper on Central Bank Digital Currencies discussing the foundational principles and core features of a CBDC. The following is an excerpt from the Executive Summary:1)
The Federal Reserve has suggested “Desirements”2) in a White Paper named Money, and Payments: The U.S. Dollar in the Age of Digital Transformation. These “Desirements” were captured and summarized in a White Paper Analysis conducted by the Object Management Group . Ultimately, these “Desirements” need to be incorporated into a CBDC Data Strategy following the guidelines set by the U.S. government for government entities to develop a Federal Data Strategy.
The Federal Reserve has suggested a “Desirement” to have the CBDC used internationally and as a mechanism to transfer funds across borders. These “Desirements” need to be added to a Federal Reserve CBDC Data Strategy. For more information, the OMG DIDO-RA provides a discussion on Federal Data Strategy. The Federal Reserve and the implementation of the CBDC should formulate their own Federal Data Strategy. The Data Strategy should also address matters covered in Section 45_privacy.
Since the Federal Reserve is striving for a CBDC with international appeal, it also needs to develop a Data Strategy, covering Data Governance, Compliance and Regulation. Table 1 provides some insight into data governance the CBDC needs as part of a Data Strategy.
| Data Residency ‡ | Data Residency is the set of issues and practices related to the location of data and metadata, the movement of (meta)data across geographies and jurisdictions, and the protection of that (meta)data against unintended access and other location-related risks3) |
|---|---|
| Data Sovereignty | Data Sovereignty is the concept that information which has been converted and stored in binary digital form is subject to the laws of the country in which it is located. |
| Data Localization ‡ | Data Localization is the act of storing data on any device that is physically present within the borders of a specific country where the data was generated. |
The following “Desirements” are from the White Paper as identified by the Object Management Group's report called White Paper Analysis:
| Category | Desirements |
|---|---|
| Benefits | B0009, B0015, B0035, B0036, B0041, B0052 |
| Policies | P0004, P0005, P0006, P0012, P0023, P0024, P0028 |
| Risks | R0014 |
| Design | D0013, D0015, D0016, D0017 |
B = Benefit, P = Policy, R = Requirement, D = Design.| Statement No. | Statement | Comment | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| B0009 | Provide faster and cheaper payments (including cross-border payments) |
There is a lot of promise coming from the Blockchain world vis-a-vis decentralization and transactions per second, To a large extent this is driving the Stablecoin Desirements such as:
In addition to the speed issues, there are huge costs associated with consensus. See the OMG DIDO-RA discussion on Consensus Platforms.
|
||||||||||||||||||
| B0015 | Reduce cross-border costs to benefit:
| The U.S. Dollar is already an international global currency.
However, even though the U.S. Dollar is the de facto world currency, that it is partially because it is perceived as a neutral, unbiased, well-managed, and transparent commodity. If the CBDC were to change the rules to make it less well managed, neutral, unbiased, and transparent there will be serious challenges to the U.S. Dollar. Part of the explanation for Bitcoins' adoption was that transactions were perceived to be beyond the purview of the U.S. government, in specific, but other governments as well.
Kimberly Amadeo, Why the US Dollar Is the Global Currency, The Balance 16 March 2022, Accessed: 10 April 2022, https://www.thebalance.com/world-currency-3305931 )) Part of the reservation about the U.S. Dollar is also attributable to the Snowden revelation. See: Data Sovereignty and MacAskill and Dance.7) |
||||||||||||||||||
| B0035 | Streamline cross-border payments by using:
|
See |
||||||||||||||||||
| B0036 | Preserve the dominant international role of the U.S. dollar |
See |
||||||||||||||||||
| B0041 | Support streamlining cross-border payments | The Bank for International Settlements (BIS) has produced a paper for the G20 on Central bank digital currencies for cross-border payments8)
|
||||||||||||||||||
| B0042 | Preserve the dominant international role of the U.S. dollar |
See |
||||||||||||||||||
| B0052 | Prevent Financial money laundering crimes | There is already a rich legal framework in place to cope with Money Laundering within the U.S.; many of these can help prevent money laundering across U.S. borders. One example is the US Patriot Act, Title III: Anti-money-laundering to prevent terrorism of 2001, especially the
Also, 18 U.S. Code § 1956 - Laundering of monetary instruments has provisions for international situations:
|
||||||||||||||||||
| P0004 | Protect consumer privacy | Internationally, a major method of protecting consumer privacy is referred to as Data Localization. This section includes examples from Russia, China, India, European Union, and Brazil. Data Localization policies classification 9) is summarized below: Local-only Storing, Transmission, and Processing: This generally means an obligation to locally manage data or a prohibition of international data transfers. This is the strictest type of localization policy and is more likely to be descriptive of nations seeking broader control over citizen activities. Local Copy Required: Companies are required to keep a copy of data in local servers or data centers. This allows for easier access to this data for regulation and law enforcement purposes, i.e., it is generally easier for local law enforcement agencies to access data stored locally than it is for them to access data stored in another jurisdiction. Narrower, conditional restrictions: Transfers of data outside the country are only permitted if certain conditions are met by the transferee and/or by the recipient country. |
||||||||||||||||||
| P0005 | Protect against criminal activity | There is already a rich legal framework within the U.S. to protect against criminal activity, which includes international activities (see the Details of National Security Considerations). Many of these laws and regulations are already well established and operational on the international level. Some examples: Human Trafficking: Intelligence Reform and Terrorism Prevention Act of 2004 The Intelligence Reform and Terrorism Prevention Act, section 7202 established the Human Smuggling and Trafficking Center to achieve greater integration and overall effectiveness in the U.S. government's enforcement and other response efforts, and to work with foreign governments to address the separate but related issues of alien smuggling, trafficking in persons, and criminal support of clandestine terrorist travel. Drug Trafficking: 18 U.S. Code § 1952 - Interstate and foreign travel or transportation in aid of racketeering enterprises Five year maximum for traveling or using the mail or instruments of interstate commerce (telephone/internet) with intent to facilitate drug trafficking. Table 3: Summary of the number of laws and regulations covering National Security Considerations.
|
||||||||||||||||||
| P0006 | Garner broad support from key stakeholders | See 05_stakeholder. The primary international stakeholders in the CBDC effort are identified in non-U.S. Federal Government Oversight Authorities. This is a minimum set and could include more countries and specific agencies within these countries. |
||||||||||||||||||
| P0012 | The firms that operate interbank payment services are subject to federal supervision | This is highly dependent on the Currency Model or mix of currency models chosen to implement the U.S. CBDC. Existing intermediaries must already follow: As well as take steps to prevent Money Laundering, such as:
U.S. Federal law requires a person to report cash transactions of more than \$10,000 by filing IRS Form 8300 PDF, Report of Cash Payments Over \$10,000 received in a Trade or Business. 10)
|
||||||||||||||||||
| P0023 | CBDC would need to be readily transferable between customers of different intermediaries | This requires international agreement on the details of what constitutes a transfer, the rules of the transfers, limits or restrictions on the transfers, etc. Although there are already agreements using the existing systems, these are often too slow for modern expectations. Even though streamlining transfer processing using technologies such as Blockchain is promising (in order to reduce the time it takes to do a transfer) this should in no way mean that the rules can be ignored. |
||||||||||||||||||
| P0024 | CBDC would need to comply with the U.S. robust rules | Most of the international agrements have to do with detection and prevention of National Security which is a broad, extensive topic that requires an understanding of the U.S. Laws and Regulations, as well as, international treaties and agreements. Within the context of the CBDC, criminal activity can be one or more of the following: |
||||||||||||||||||
| P0028 | Require significant international coordination to address issues such as:
| 1. Common Standards: There are lots of “common standards” that apply to Blockchains and Blockchain technology. The following provides (and describes) standards or lists of standards that apply: Unfortunately, within the “blockchain” world, there is confusion about what constitutes a standard. Often, if something is Open Source, it is considered a standard. However, often these projects lack the rigor needed to be considered a “standard”. Also, see the discussion in the DIDO RA on Talk Openly Develop Openly (TODO). As a contrast, look at the DIDO RA definition of a Standards Developing Organization (SDO).
2. Infrastructure: The CBDC Infrastructure needs to be considered Mission Critical since any loss of functionality could be considered a threat to survival. This is why the Desirements: 3. Types of Intermediaries able to access any new infrastructure:
4. Legal Frameworks: There are already legal frameworks in place to handle: Although these frameworks were developed without a CBDC, they already “comply with the United States are subject to robust rules” and are continuously being reviewed, updated, and amended based on new information obtained from the field. As part of this process, these frameworks need to add to the existing frameworks rather than creating new frameworks. 5. Preventing Illicit Transactions: There are two areas within the existing legal frameworks covering Illicit transactions: Although these frameworks were developed without a CBDC, they already “comply with the United States are subject to robust rules” and are continuously being reviewed, updated, and amended based on new information obtained from the field. As part of this process, these frameworks need to add to the existing frameworks rather than create new frameworks.
6. Cost and Timing of Implementation: The CBDC is a complex issue that, once released, could have a life expectancy of many, many years. Only through extensive Systems Analysis, Engineering, Design, and Testing will CBDC have the stability it needs to instill confidence in the public ( |
||||||||||||||||||
| R0014 | Risk of not achieving an appropriate balance between safeguarding the privacy rights of consumers and affording the transparency necessary to deter criminal activity | This has to be accomplished understanding international treaties, laws and regulations on |
||||||||||||||||||
| D0002 | Design should allow the central bank to limit the amount of CBDC an end user could hold | The U.S. CBDC would need to work within the confines of the individual country's laws and regulations on: |
||||||||||||||||||
| D0003 | Design should allow a limit on the amount of CBDC an end user could accumulate over short periods | See: q16 The U.S. CBDC would need to work within the confines of the individual country's laws and regulations on: |
||||||||||||||||||
| D0002 | Design should allow the central bank to limit the amount of CBDC an end user could hold | The U.S. CBDC would need to work within the confines of the individual country's laws and regulations on: |
||||||||||||||||||
| D0009 | Design should allow for significant foreign demand for CBDC, furthering complicate monetary policy implementation | This depends on the Currency Model used for the CBDC. For |
||||||||||||||||||
| D0013 | Design should facilitate compliance with a robust set of rules already intended to combat
| Criminal Activity is a broad, extensive topic that requires an understanding of the U.S. Laws and Regulations as well as international treaties and agreements. Within the context of the CBDC, criminal activity can be one more of the following: Customer due diligence and record keeping need to take into account: |
||||||||||||||||||
| D0015 | Design should include any dedicated infrastructure required to provide resilience to threats such as operational disruptions and cybersecurity risks | Often, threats and operational disruptions are not limited to the geographic location of a particular country or jurisdiction. Some recent international attacks on communications 11) listed below: March 2022: An attack on a satellite broadband service run by the American company Viasat disrupted internet services across Europe, including Ukrainian military communications at the start of the Russian invasion. The attackers hacked satellite modems belonging to thousands of Europeans to disrupt the company’s service. March 2022: Hackers penetrated the websites belonging to multiple Russian agencies including the Energy Ministry, the Federal State Statistics Service, the Federal Penitentiary Service, and the Federal Bailiff Service. The websites displayed several anti-government and anti-invasion images and messages before the agencies were able to expel the attackers. March 2022: Hackers linked to the Chinese government penetrated the networks belonging to government agencies of at least 6 different U.S. states in an espionage operation. Hackers took advantage of the Log4j vulnerability to access the networks, in addition to several other vulnerable internet-facing web applications. February 2022: Researchers identified campaigns by two North Korean government-backed groups targeting employees across numerous media, fintech, and software companies. The hackers used phishing emails advertising fake job opportunities and exploited a vulnerability in Google Chrome to compromise the companies’ websites and spread malware. February 2022: A Beijing-based cybersecurity company accused the U.S. National Security Agency of engineering a backdoor to monitor companies and governments in over 45 countries around the world. A Foreign Ministry spokesman said that operations like this may threaten the security of China’s critical infrastructure and compromise trade secrets. |
||||||||||||||||||
| D0016 | Design should include offline capabilities to help with the operational resilience of the payment system |
See: |
||||||||||||||||||
| D0017 | Design should include digital payments in areas suffering from large disruption, such as natural disasters |
See: |
||||||||||||||||||
B = Benefit Considerations |
||||||||||||||||||||
P = Policy Considerations |
||||||||||||||||||||
R = Risk Considerations |
||||||||||||||||||||
D = Design Considerations |
||||||||||||||||||||