CBDC Distribution & Bank Operating Models

Retail, wholesale, intermediated and direct models and their bank impact

First separate the money from the service

A central bank digital currency (CBDC) is digital central bank money. In the retail designs discussed here, the holder's claim is on the central bank, even when a commercial bank or payment provider supplies the wallet and customer service. This is the essential distinction from a commercial bank deposit or a privately issued stablecoin. A design choice about who runs an app does not, by itself, change who owes the money.

CBDC proposals and implementations vary by jurisdiction. This chapter compares operating models; it does not assume that a retail or wholesale CBDC exists in a particular market or that one design has been selected. A bank working on a real programme must use the issuing central bank's current rulebook, legal framework and technical specifications.

Retail and wholesale purposes

Retail CBDC is intended for use by the public. Design questions include who can hold it, how customers open and recover wallets, how it exchanges with deposits and cash, how privacy and financial-crime controls coexist, whether offline payments are possible, and who resolves errors or complaints.

Wholesale CBDC or tokenised central bank money is aimed at eligible financial institutions and settlement arrangements. It may support transfers between participants or settlement of tokenised assets. Eligibility, operating hours, finality and access to central bank accounts are programme-specific. A wholesale experiment does not imply that the public can hold that instrument.

The BIS Financial Stability Institute describes these forms and the trade-offs among retail architectures. The BIS and participating central banks also identify privacy, cyber security, offline function and point-of-sale acceptance as system-design issues, not optional user-interface details.

Who keeps the ledger and who serves the user?

ModelCentral bank roleIntermediary roleBank question
Direct retailCentral bank carries most retail account and payment functionsLimited or optional service roleHow will customer service and distribution be organised?
Intermediated retailCentral bank maintains the central-bank liability and wholesale position; detailed retail processing is largely with intermediariesOnboarding, wallet, payments and servicingHow are retail records, central-bank positions and customer balances reconciled?
Hybrid retailCentral bank keeps more retail information to support continuity, while intermediaries handle customer-facing servicesOnboarding, payments and supportCan service continue or be transferred if an intermediary fails?
WholesaleCentral bank supplies settlement money or infrastructure to eligible participantsBanks and other eligible firms initiate and service underlying transactionsWhich asset leg, cash leg and finality rule meet the business need?

These are simplified analytical models. Real programmes can combine features, and the legal definition matters more than a label. The “indirect CBDC” term is also used in some literature for a claim on an intermediary rather than a direct claim on the central bank; a bank should state the legal claim explicitly instead of relying on the architecture name.

CBDC liability and service roles in direct, intermediated and hybrid retail models.

The bank's operating work

A bank asked to distribute retail CBDC would need to map a complete customer journey. Depending on the programme, this can include eligibility and identity checks, wallet provisioning, conversion between a deposit and CBDC, payment initiation and authentication, transaction status, account recovery, dispute handling, customer support, reconciliation and reporting. These are responsibilities to allocate, not universal legal obligations imposed identically on every bank.

The conversion step is especially important. If a customer moves value from a bank deposit to CBDC, the bank's deposit liability changes while the customer's central-bank-money holding changes. Treasury and finance must know the funding and balance-sheet effect, including stressed flows. App teams must not describe that as a transfer between two identical bank accounts. The BIS notes that a large shift from deposits to CBDC could affect bank intermediation; the scale depends on design and adoption.

Privacy and access also belong in the operating model. A bank needs a clear answer about which transaction data it can see, which data the central bank or another intermediary can see, what customers can control, and how lawful access works. Offline use creates additional issues: device loss, double spending, delayed reconciliation and limits on what can be promised when connectivity returns. Those trade-offs must be tested with the central bank's actual design.

Worked example: deposit to CBDC and back

Assume an eligible customer converts 200 units of a bank deposit into a retail CBDC through the bank's app. The bank authenticates the request and applies the programme's rules. Its deposit book debits the customer, the CBDC system records the customer's new holding, and the bank reconciles the conversion against its central-bank position. The customer should not see “available CBDC” until the rules make that state true.

Later the customer pays a merchant that accepts CBDC. The wallet and CBDC system record the payment according to the programme's finality rule. If the merchant converts the proceeds into a bank deposit, that is another event with its own bank posting. The bank must be able to trace conversion, CBDC payment and later deposit credit separately. The example is simplified; a real system may involve more intermediaries and different ledger mechanics.

If the bank's wallet service fails after the customer sends the payment, operations needs enough retained identifiers to determine whether the CBDC moved, whether the merchant was credited, and what the customer should see. The incident response cannot assume that retrying a request is harmless. Recovery, idempotency, dispute rights and the responsible service provider must follow the issuing programme's rules.

Wholesale settlement example

A bank buying a tokenised security may want the asset and the payment leg to complete together. A wholesale CBDC or tokenised central bank money arrangement may provide the payment asset for such a design. Product teams should confirm participant eligibility, access to the settlement venue, legal finality, liquidity needs and the fallback if one leg does not complete. “Atomic” in a technical demonstration is not sufficient evidence that every legal and accounting obligation has settled.

Questions for a bank decision record

  1. Who is the legal issuer of the money, and who owes customer service, error correction and redress?
  2. Which party maintains each authoritative record: wallet, retail transaction, central-bank position and bank book?
  3. How do conversion, payment and recovery states reach the customer without showing premature success?
  4. Which data are visible to each party, and how are privacy and financial-crime requirements met?
  5. What happens to the bank's funding and liquidity if customers convert deposits at scale or under stress?
  6. Can the service continue if an intermediary or device fails, and how are offline transactions reconciled?
  7. What rule gives settlement finality, and what fallback applies when an asset or cash leg fails?

A bank can measure readiness through reconciliation breaks, failed conversions, dispute resolution, wallet recovery and stress-test results. Adoption or wallet downloads alone cannot answer whether the operating model works.

Takeaway

CBDC changes the form of the monetary claim; distribution determines who builds and runs the customer service around it. A bank should assess the issuer, ledger, customer-service role and funding effect together. The answer is specific to the issuing central bank's chosen design and rules.

Sources and review scope

These sources describe models and design questions. They are not a substitute for the rules of an issuing central bank or the law of a particular jurisdiction.