Core Focus: The fundamental trade-off central banks face in designing retail CBDCs: the inability to simultaneously maximise privacy, financial stability, and regulatory compliance.

In-Depth Notes:
A systematic review of the CBDC literature has identified a fundamental design trilemma: central banks cannot simultaneously maximise privacy, financial stability, and regulatory compliance when designing retail CBDCs . This trilemma is not merely a theoretical abstraction but a practical constraint that shapes every major design decision in CBDC development. Evidence synthesised across 140 peer-reviewed articles supports all three pairwise tensions: privacy-enhancing designs weaken AML/CFT enforcement, anonymous holdings amplify bank-run risk, and stringent prudential safeguards constrain transaction monitoring .

The Three Tensions of the Trilemma:
The trilemma consists of three distinct but interconnected tensions. The first is the privacy-compliance tension. Privacy-enhancing designs, such as offline functionality or token-based systems, make it more difficult to monitor transactions for illicit activity. Conversely, designs that prioritise full traceability for AML/CFT purposes compromise user privacy. This tension is at the heart of many CBDC design debates. The second tension is privacy-financial stability. Anonymous holdings can amplify bank-run risk by making it easier for depositors to shift funds from commercial banks to the central bank during times of stress. The third tension is compliance-financial stability. Stringent prudential safeguards and regulatory requirements can constrain transaction monitoring and impede the operational efficiency of the payment system.

The “Zone of Feasible Design”:
The literature converges on two-tier, hybrid architectures with tiered privacy as the dominant compromise—a “zone of feasible design” that sacrifices full optimality on each vertex of the trilemma . This means that central banks must make deliberate trade-offs, accepting that no single design can fully satisfy all three objectives simultaneously. The two-tier hybrid model, where intermediaries handle customer-facing functions while the central bank maintains oversight, has emerged as the preferred approach for balancing the tensions of the trilemma. This model allows for tiered privacy (anonymity for small-value transactions, traceability for high-value ones) while preserving financial stability through holding limits and preserving regulatory compliance through intermediary oversight.

Implications for Policymakers:
The trilemma framework offers policymakers a structured lens for evaluating retail CBDC design trade-offs and provides researchers with a testable proposition for future empirical work . It underscores that CBDC design is not about finding a perfect solution but about making informed trade-offs based on a jurisdiction’s specific priorities and risk tolerance. For example, jurisdictions with strong privacy norms may prioritise privacy even if it means some reduction in AML/CFT efficiency, while jurisdictions with significant illicit finance concerns may prioritise traceability even if it means some reduction in user privacy.