What Happened
The Bank for International Settlements processed $1 million in tokenized cross-border payments through Project Agorá, settling 30 transactions in about 80 seconds across six currencies. Twenty-eight major banks participated, including JPMorgan, Citi, Deutsche Bank, and Standard Chartered. The platform integrated tokenized commercial bank deposits with central bank reserves, executing foreign exchange and payment settlement simultaneously on a unified ledger.
This was a live transaction test running on real banking infrastructure, not just a proof-of-concept.
Timeline
The BIS hasn't disclosed detailed timestamps for each phase, but the operational sequence is clear:
- Pre-transaction: Banks tokenized commercial deposits and central bank reserves on the platform.
- Execution window: 30 cross-border payments spanning USD, EUR, GBP, JPY, and two additional currencies.
- Settlement: Approximately 80 seconds per transaction, with full transparency from initiation to finality.
- Foreign exchange: Conversion and settlement occurred simultaneously, with no lag between FX execution and payment finalization.
The 80-second settlement window includes the entire lifecycle: authorization, FX conversion, cross-border routing, and final settlement. Compare that to correspondent banking, where T+2 or T+3 settlement is standard and each intermediary adds opacity.
Compliance Challenges
This trial wasn't a failure, but it exposes gaps in how your AML/KYC compliance team should prepare for tokenized payment rails.
Regulatory ambiguity on tokenized deposit classification: Your KYC obligations under the Bank Secrecy Act assume discrete account structures. Tokenized deposits blur the line between account balances and bearer instruments. If a tokenized deposit moves across borders in 80 seconds, when does your transaction monitoring system trigger? At tokenization? At transfer? At redemption?
Sanctions screening latency: FATF Recommendations require real-time screening against watchlists. Your current sanctions engine likely runs batch checks or near-real-time queries with sub-second latency. Can it screen a tokenized payment that settles in 80 seconds across multiple jurisdictions with different sanctions regimes? If the payment crosses six currencies, which jurisdiction's sanctions list applies at each hop?
Audit trail fragmentation: The BIS noted full transparency from start to finish. But transparency to whom? If the ledger is shared across 28 banks and multiple central banks, who owns the audit trail for Suspicious Activity Report (SAR) filing purposes? Under BSA regulations, you must retain records for five years and produce them on demand. Tokenized rails need clear data custody rules.
Stablecoin substitution risk: The BIS framed this project as an alternative to privately issued stablecoins like Tether and Circle's USDC. Your compliance program likely treats stablecoins as higher-risk counterparties due to limited regulatory oversight. But what happens when a tokenized bank deposit offers the same speed and cost profile? You'll need to reassess your risk-based approach to digital asset transactions.
Relevant Standards
Bank Secrecy Act (BSA): You must implement a risk-based Customer Identification Program (CIP) and file SARs for transactions that meet the reporting threshold or exhibit red flags. For cross-border payments, this includes identifying the originator, beneficiary, and any intermediaries. Tokenized payments that settle in 80 seconds compress your decision window. If your current SAR review process takes 24-48 hours, you're filing after the fact.
FATF Recommendations: Recommendation 16 (the "Travel Rule") requires you to include originator and beneficiary information in cross-border wire transfers. For transactions above USD/EUR 1,000, you must transmit full KYC data with the payment. Tokenized rails must support this data payload without degrading settlement speed. The BIS trial processed payments across six currencies, each subject to local Travel Rule thresholds. Your compliance engine needs to parse jurisdiction-specific rules in real time.
Wolfsberg Principles: The Wolfsberg Group's guidance on correspondent banking due diligence applies here. Even though Project Agorá eliminates traditional correspondent banks, you're still moving money across borders through a network of institutions. Wolfsberg Principle 3 requires you to understand the risk profile of each participating bank. In a tokenized system with 28 banks, that's 28 risk assessments, and the network will grow.
PCI DSS: If tokenized payments intersect with card-based transactions (for example, a cardholder initiating a cross-border payment via tokenized deposit), PCI DSS Requirement 3.4 applies: you must render Primary Account Numbers (PANs) unreadable wherever stored. Tokenization of deposits is separate from payment tokenization under the EMV Payment Tokenisation Framework, but your teams need to distinguish which tokenization standard applies to which data flow.
Action Items for Your Team
Build sanctions screening for sub-minute settlement: Your current batch screening model won't work. Evaluate real-time screening APIs that can query OFAC, EU, and UN sanctions lists with sub-second latency. Test them against a simulated 80-second settlement window. If you can't screen and block within that window, you're approving first and reviewing later, which is a compliance failure.
Map your SAR decision tree to tokenized payment attributes: SARs rely on pattern recognition, structuring, unusual cross-border activity, Politically Exposed Person (PEP) involvement. Tokenized payments may not fit your existing typologies. A $50,000 payment that settles in 80 seconds might be legitimate treasury management or it might be rapid-fire structuring. Update your transaction monitoring rules to account for settlement speed as a risk factor.
Clarify audit trail ownership with your banking partners: If you participate in a tokenized payment network, negotiate data retention and access rights upfront. Who maintains the authoritative record? Who can query the ledger for compliance purposes? Who responds to regulatory subpoenas? The BIS noted transparency, but transparency without clear data governance creates compliance risk.
Distinguish tokenized deposits from stablecoins in your risk taxonomy: Stablecoins issued by private companies carry different risks than tokenized bank deposits backed by central bank reserves. Update your risk-based approach to reflect this distinction. A payment settled via tokenized deposits on a BIS-led platform is not equivalent to a USDC transfer on a public blockchain, even if both settle in under two minutes.
Pressure-test your Travel Rule data flow: The FATF Travel Rule requires KYC data to move with the payment. In correspondent banking, you attach that data to SWIFT messages. In a tokenized system, you need a different transport mechanism. Work with your payment operations team to confirm that originator and beneficiary data is embedded in the tokenized transaction payload and that downstream institutions can parse it.
The BIS trial shows that tokenized cross-border payments can work at scale within a regulated framework. Your compliance program needs to catch up before this moves from trial to production.



