Delivery-versus-payment (DvP) is the settlement principle that a securities transfer and its corresponding funds transfer are linked so that delivery occurs if and only if payment occurs. Neither leg is final unless the other is final. This linkage is the canonical way markets remove principal risk in securities settlement, as set out by the Bank for International Settlements’ Committee on Payment and Settlement Systems (CPSS) definition.
In tokenised markets, the same idea applies. Digital tokens representing assets and cash can settle under DvP rules, often through programmable mechanisms that commit both legs together. Tokenisation enables “atomic” DvP on a single platform, executing trades all-or-none. That can eliminate principal risk while changing liquidity and netting dynamics, as highlighted by the BIS/CPMI’s report to the G20 on tokenisation concepts and implications.
How DvP works in tokenised settlement
Tokenisation represents securities and money as digital tokens on programmable infrastructure. When both legs of a trade reside on the same platform, a single transaction can update the asset balance and the cash balance atomically. The trade either completes in full or not at all, removing principal risk and compressing operational steps. The BIS/CPMI describes this atomic DvP style and notes that it typically increases prefunding needs and can alter netting characteristics compared with traditional batch processes (BIS/CPMI 2024).
When the asset and cash exist on different systems, DvP requires a link. Central banks and market infrastructures have tested designs that coordinate between distributed ledger platforms and central bank payment rails. Examples include hashed timelock mechanisms, hash-link triggers from a DLT to a central bank system, and directly issuing cash tokens (eg tokenised central bank money) onto a DLT for on-ledger DvP. The European Central Bank’s exploratory work documents these approaches, including “Trigger Solution,” “Full DLT Interoperability,” and “TIPS Hash-Link” patterns (ECB Annex I).
The classic DvP models and what they imply
The CPSS identified three common ways to implement DvP in securities settlement systems. Each entails different credit, liquidity, and operational risk profiles (BIS/CPSS 1992):
Model Securities leg Funds leg Netting/timing Model 1 Gross settlement Gross settlement Real-time for both legs, trade by trade Model 2 Gross settlement Net settlement Securities real-time; funds settled on a net basis Model 3 Net settlement Net settlement Simultaneous net settlement of both legs
Tokenised settlement can mimic any of these patterns, from atomic gross DvP on one ledger to coordinated net settlements across linked systems. The choice affects how much liquidity must be prefunded, how benefits from netting accrue, and the operational processes around finality.
Participants and plumbing in tokenised DvP
Several roles interlock to make DvP work in practice:
- Asset issuers and custodians. Regulated entities may hold the legal title to assets while issuing tokenised representations for settlement. The Depository Trust & Clearing Corporation (DTCC) reported converting DTC-held securities into tokenised representations and processing production tokenised trades, including U.S. Treasury/repo DvP trades and equity DvP trades, in a multi-firm exercise (DTCC, July 15, 2026).
- Cash leg providers. Central bank systems and tokenised central bank money (CeBM) are prominent options in trials. The ECB’s annex illustrates conditional and atomic settlement designs where the cash leg is central bank money or tokenised CeBM (ECB Annex I).
- Settlement systems. Legacy infrastructures already implement DvP on-book. The Federal Reserve’s Fedwire Securities Service settles securities transfers on a gross, real-time basis and supports DvP by simultaneously updating securities and corresponding master (funds) accounts (Federal Reserve).
- Smart contracts and interoperability services. On-chain logic can enforce atomicity when both legs are tokenised. Interoperability services coordinate messages and proofs between DLT platforms and central bank rails using hash-link or trigger mechanisms (ECB Annex I).
Design patterns: atomic on one ledger vs cross-system links
Implementers typically choose among three patterns, each with distinct operational traits:
- Atomic DvP on a single platform. Both the security and cash tokens live on the same ledger. A single transaction transfers them all-or-none. This removes principal risk but often increases liquidity prefunding and may reduce netting benefits relative to batch cycles (BIS/CPMI 2024).
- Hash-locked or hash-link conditional settlement across systems. If the security and cash reside on different ledgers or on a DLT and a central bank RTGS, hashed timelock contracts or hash-linked triggers can coordinate conditional release, enabling DvP without co-locating assets (ECB Annex I).
- Cash tokens on DLT. Central bank or infrastructure-issued cash tokens on the asset’s ledger allow on-ledger DvP while keeping the cash leg in central bank money, as explored in Eurosystem experiments (ECB Annex I).
Step-by-step: an atomic DvP with cash tokens
The following simplified sequence illustrates atomic DvP when both legs are tokenised on one platform:
- Trade agreement. Buyer and seller agree on quantity and price.
- Lock both legs. A smart contract escrows the seller’s tokenised security and the buyer’s tokenised cash (eg CeBM or a cash token) under the same condition.
- Check and commit. When predefined conditions are met, the contract simultaneously transfers the security to the buyer and the cash to the seller; otherwise, nothing moves.
- Finality. The ledger records both transfers atomically. If conditions expire unmet, both side’s escrows are returned. This “all-or-none” execution removes principal risk (BIS/CPMI 2024).
Real-world implementations to date
Legacy DvP is well-established. The Fedwire Securities Service performs on-book DvP by synchronising gross, real-time securities transfers with updates to funds accounts in the same infrastructure (Federal Reserve).
Bridging to tokenisation, DTCC reported converting DTC-held securities into tokenised representations and processing production tokenised trades, including U.S. Treasury/repo DvP trades and equity DvP trades, in a multi-firm exercise. The demonstration shows how regulated custody can interoperate with tokenised DvP workflows (DTCC, July 15, 2026).
At the central bank layer, the Eurosystem’s exploratory work documents several DvP designs across DLT and central bank infrastructures, including hash-link triggers and cash tokens for atomic or conditional settlement in central bank money (ECB Annex I).
Limitations, risks, edge cases and misconceptions
Atomic DvP changes risk, it does not erase it. By construction it removes principal risk, but the liquidity required to prefund gross, instant settlement can rise and netting benefits can diminish relative to batch processes. Policy and supervisory analyses emphasise these trade-offs in tokenised DvP (BIS/CPMI 2024) and in market overviews (OECD 2021).
- Legal and custody questions. Who holds title to the underlying asset, how are client assets segregated, and how is key custody managed? These issues remain central in tokenised settings, alongside enforceability and finality across jurisdictions (OECD 2021).
- Nature of money. Some designs use central bank money or tokenised central bank money; others might rely on private stablecoins. The choice affects credit risk, settlement finality, and oversight frameworks (OECD 2021).
- Operational coordination. Cross-system DvP via hash-links or triggers depends on reliable messaging, timeouts, and liveness. Edge cases like time expiry in hashed timelock flows can unwind a trade safely but still create delays and operational workload (ECB Annex I).
- Model selection. Different DvP models entail different credit, liquidity and operational profiles. Choosing between gross atomic settlement and netted approaches is a market design decision, not a one-way upgrade (BIS/CPSS 1992).
A common misconception is that atomic DvP makes settlement “risk-free.” It removes principal risk by definition, but legal, governance, operational, and liquidity risks persist and must be managed.
Where you will encounter or use DvP
You encounter DvP whenever a securities trade settles with cash in a system that links both legs. In traditional markets, that includes central bank and CSD platforms that synchronise securities and funds, such as Fedwire Securities for eligible instruments (Federal Reserve).
In tokenised markets, you will see DvP when a platform settles tokenised securities against tokenised cash atomically, or when an interoperability service triggers payment in a central bank system upon asset delivery. Real-world exercises, such as DTCC’s tokenisation of DTC-held securities and processing of U.S. Treasury/repo and equity DvP trades, show how regulated infrastructures can bridge to these workflows (DTCC), while the Eurosystem’s work outlines technical paths for central bank money settlement on or linked to DLT (ECB Annex I).
Frequently Asked Questions
What problem does DvP solve?
DvP removes principal risk by ensuring the security and the payment finalize together. If either leg fails, neither settles. This is the CPSS standard for safe securities settlement (BIS/CPSS 1992).
Is atomic DvP always preferable to net settlement?
No. Atomic, gross settlement removes principal risk but typically increases liquidity prefunding and can reduce netting benefits. Markets weigh these trade-offs when choosing a model (BIS/CPMI 2024).
Do tokenised DvP systems need central bank money?
They can, but do not have to. Designs include using central bank money or tokenised central bank money, as well as private money arrangements. The choice has legal and risk implications (ECB Annex I) (OECD 2021).
How is DvP different from PvP?
PvP, or payment-versus-payment, applies to settling one currency against another in foreign exchange, linking both payments. DvP links a security and a cash payment for that security.
Can DvP work across different blockchains or systems?
Yes, with conditional designs such as hashed timelocks or hash-link triggers that coordinate releases across platforms. Central bank and market-infrastructure trials document these patterns (ECB Annex I).
Where does DvP operate in traditional markets today?
The Fedwire Securities Service is an example. It settles securities transfers on a gross, real-time basis and supports DvP by simultaneously updating securities and funds accounts (Federal Reserve).
Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

2 hours ago
13









English (US) ·