Core Focus: The compliance challenges of offline CBDC payments, including double-spending risk, the loss of real-time traceability, and the design options for balancing privacy and AML/CFT.
In-Depth Notes:
Offline functionality is a key feature of many CBDC designs, reflecting the desire to provide cash-like resilience and privacy. However, offline payments present significant compliance challenges that must be carefully addressed.
The Privacy Promise of Offline Payments:
Offline payments are generally believed to provide additional degrees of freedom for user privacy, as the lack of direct involvement of third parties in these offline transfers interferes with key regulatory requirements that need to be accommodated in the financial space . Offline transactions would settle directly between users, meaning neither the central bank nor payment service providers would have access to data related to offline transactions.
The Compliance Challenge:
The lack of direct involvement of third parties in offline transfers interferes with key regulatory requirements that need to be accommodated in the financial space . A compliance-by-design approach is needed to evaluate technologies that can balance privacy with AML/CFT measures. The literature classifies privacy design options and corresponding technical building blocks for offline CBDCs, along with their impact on AML/CFT measures .
The IMF’s Guidance on Offline Payments:
The IMF has provided specific guidance on offline functionality . Offline functionality should be carefully limited and coupled with measures to preserve traceability where necessary for AML/CFT purposes . Privacy-preserving options should be combined with regulatory safeguards so that user protection does not become a loophole for illicit flows . This reflects a recognition that while privacy is important, it cannot come at the expense of financial integrity.
Technical Design Options:
The Bank of England’s CBDC Technology Forum explored a hybrid account-token model which aimed to ensure protection of user balances, support for offline payments and improved user privacy. CBDC accounts can be represented by a set of public and private key pairs, which could be renewed regularly while the wallet is online to prevent user tracking and profiling when making different payments. CBDC transactions would include a chain of payer and payee signatures and the offline transaction history to ensure that the core ledger balances could be updated when the wallets went back online.