← Back to list
Management & Strategy
#CBDC#디지털화폐#분산원장#지급결제#통화주권
Last updated · 2026-09-30

Central Bank Digital Currency (CBDC)

1. Overview

A. Definition

A Central Bank Digital Currency (CBDC) is a digital form of legal tender issued directly by a central bank; like physical cash, it constitutes a direct claim on the central bank (a central bank liability) and is stored and transferred electronically.

To understand a CBDC precisely, one must start from the question "whose liability is it?". The account balances and card payments we use daily are mostly liabilities of commercial banks—that is, bank deposit money—and if a bank fails, amounts above the deposit insurance ceiling may be lost. Cash, by contrast, is a liability of the central bank and a final means of settlement free of credit risk. A CBDC extends this safety of cash into the digital domain, providing the attributes of central bank money—settlement finality and freedom from credit risk—in electronic form, which is what fundamentally distinguishes it from existing electronic payment instruments.

The Bank for International Settlements (BIS) defines a CBDC as "a digital form of central bank money that is different from balances in traditional reserve or settlement accounts," and sets out foundational principles for issuance: do no harm, support monetary and financial stability, and promote innovation and efficiency (BIS, Foundational principles and core features). What matters here is that a CBDC is not merely a new payment app but a new form of "money itself," forming the bedrock of the monetary system. Its design must therefore be approached, prior to any technology choice, as a problem of balancing public-policy objectives—monetary policy, financial stability, privacy, and inclusion—simultaneously.

In a professional-engineer answer, it is important not to confuse a CBDC with cryptocurrencies or stablecoins. A cryptocurrency such as Bitcoin has no issuer and is a private asset with fluctuating value, while a stablecoin is a liability of a private issuer that pegs value with reserve assets. A CBDC differs entirely in its source of trust in that it is legal tender whose value the state guarantees.

B. Background and Necessity

First, as cash use has declined sharply, the erosion of "access to public money" has emerged as a problem. In countries such as Sweden, where the share of cash payments has fallen to single digits, if private payment infrastructure fails or a particular operator suspends service, citizens risk losing access to a safe final means of settlement. A CBDC is an attempt to preserve a public means of payment available to everyone even in the digital age.

Second, concern has grown that the spread of private digital currencies could threaten monetary sovereignty. If global stablecoins issued by big tech firms come to be used widely across borders, the payment and unit-of-account functions of the domestic currency could be eroded and the transmission channels of monetary policy weakened. To counter this risk of "substitution by private money," central banks seek to secure a public digital foundation pre-emptively.

Third, there is demand to improve the efficiency and inclusiveness of payments. The expectation is that a CBDC can ease settlement delays in domestic retail payments, high cross-border remittance fees, and the problem of the unbanked among the financially excluded. In particular, cross-border payments pass through multiple banks and currencies, taking days and incurring high fees, and a multi-country CBDC platform has the potential to improve this into real-time, low-cost settlement.

C. Purpose and Scope

The policy purposes of introducing a CBDC are generally summarized in the following four points.

  1. Provide a safe public digital means of payment that complements cash (inclusion and resilience)
  2. Improve the efficiency of payments and settlement and enhance cross-border payments
  3. Maintain monetary sovereignty and foster a sound currency-competition environment
  4. Establish a public foundation for new financial-service innovation such as programmability

The scope divides broadly into retail CBDC, which the general public uses for retail payments, and wholesale CBDC, used for large-value settlement among financial institutions. The two types differ in purpose, users, and risk, and thus have different design requirements, so an answer must clearly distinguish which type it addresses. In general, the wholesale type is an extension of the existing reserve system and carries little risk, while the retail type has large spillovers such as deposit outflows and privacy, requiring careful design.

2. Types and Reference Architecture of CBDC

A. Design Axes and Type Classification

A CBDC is not a single fixed form but is determined by a combination of several design axes. Representative axes are the scope of use (retail/wholesale), the account structure (account-based/token-based), the ledger structure (centralized/distributed ledger), and who handles the user touchpoint (direct/indirect/hybrid). How these axes are combined greatly changes monetary-policy effects, the level of privacy, financial-stability risk, and implementation complexity.

In particular, the distinction between account-based and token-based comes from a difference in the method of verification. The account-based approach transfers a balance by verifying "who you are" (identity-based), so it resembles a bank account and makes AML/CFT controls easy but full anonymity difficult. The token-based approach verifies "what you know" (the key or token that can transfer value), so it is closer to cash and relatively easy for offline transfer, but preventing double spending and handling loss or theft become challenges. In actual designs the two approaches are often mixed.

flowchart TB
  CBDC["Central Bank Digital Currency (CBDC)"] --> USE["Scope of use"]
  CBDC --> ACC["Account structure"]
  CBDC --> LED["Ledger structure"]
  CBDC --> DIST["Issuance/distribution model"]
  USE --> R["Retail"]
  USE --> W["Wholesale"]
  ACC --> AB["Account-based (identity verification)"]
  ACC --> TB["Token-based (key/token verification)"]
  LED --> CEN["Centralized ledger"]
  LED --> DLT["Distributed ledger (DLT)"]
  DIST --> D1["Direct (central bank alone)"]
  DIST --> D2["Indirect/hybrid (two-tier)"]
  D2 --> RES["Balance of financial stability and innovation"]
  R --> RES
  TB --> RES

B. Two-tier Operating Architecture

The model most countries intend to adopt is a two-tier hybrid structure in which the central bank issues and redeems the CBDC while intermediaries such as banks and electronic-finance operators handle the actual user touchpoint (wallet opening, identity verification, customer support). The reason is clear. If the central bank directly operated the personal accounts of tens of millions of people, it would bring enormous operational burden, a concentration of personal data, and a weakening of the intermediation function of existing banks (disintermediation). The two-tier structure is a compromise that preserves the safety of central bank money while leveraging the innovation and operational capacity of the private sector.

The core of the hybrid type is that even if an intermediary fails, the user's CBDC claim remains directly with the central bank. That is, the intermediary provides the wallet and services but the CBDC itself is not the intermediary's liability, and the central bank holds a backup ledger (or a means of recovery) of individual balances so that they can be transferred to another institution if an intermediary fails. This is the mechanism that guarantees, at the implementation level, why a CBDC—unlike a deposit—is free of credit risk.

sequenceDiagram
  participant U as "User (wallet)"
  participant I as "Intermediary (bank/EFP)"
  participant CB as "Central bank (issuance/ledger)"
  participant M as "Merchant (payee)"
  CB->>I: Issue CBDC (in exchange for deposits)
  U->>I: Open wallet and verify identity (KYC)
  U->>I: Request deposit -> CBDC conversion
  I->>CB: Request conversion and balance update
  CB-->>I: Confirm issuance and record (finality)
  U->>M: Pay CBDC (including offline)
  M->>I: Confirm receipt and settle
  I->>CB: Final settlement and ledger update

C. Core Components

A CBDC system comprises the central bank core ledger responsible for issuance and redemption, the payment and settlement engine that processes user balances and transactions, the standard API gateway that intermediaries connect to, the intermediary layer that performs wallets, identity verification, and limit management, and the governance and security layer responsible for privacy protection, fraud detection, and audit. Each component is required to have the scalability to process tens of thousands of transactions per second without delay, 24-hour uninterrupted availability, and cyber resilience at the level of national critical infrastructure.

3. Key Design Issues

The success or failure of a CBDC depends on how conflicting requirements are balanced, and the following four are the key points of contention.

Design issue Core tension Representative response
Privacy Anonymity ↔ AML/CFT, anti-money laundering Tiered anonymity (small-value anonymous, large-value identified), data separation
Financial stability Convenience of use ↔ deposit outflow (disintermediation) Holding/transaction limits, zero interest or tiered rates
Offline payment Access and resilience ↔ double-spending risk Local settlement based on secure element (SE), synchronization limits
Programmability Innovation ↔ infringing the singleness of money and freedom Smart logic in an upper layer separated from the money core

First, the balance between privacy and anti-money laundering is the most acute. Citizens expect cash-level anonymity, but complete anonymity can be abused for money laundering, terrorist financing, and tax evasion. Many designs adopt a tiered approach that grants strong privacy for small-value payments and strengthens identity verification as the amount grows. Furthermore, they seek to separate data so that no single party can, on its own, know "who bought what": the intermediary sees the transaction record but not the user's identity, while the central bank sees only the ledger without identity. The European Central Bank (ECB) has stated that it will guarantee cash-equivalent privacy for offline payments in the digital euro.

Second is the problem of financial stability and bank disintermediation. If a CBDC is too attractive, deposits could shift rapidly to CBDC in a crisis (a digital bank run), shaking the funding base of banks. To prevent this, designs are considered that set per-person holding limits (e.g., in the ECB discussion, a level of several thousand euros per person), position it as a means of payment rather than a store of value by paying no interest, and automatically route amounts above the limit back into a linked bank deposit (a waterfall).

Third, offline payment arises from the resilience requirement that payment must be possible even during communication or power outages. Value is stored in a smartphone's secure element or a dedicated card and transferred by short-range communication between two devices, but is settled upon returning online, and an offline transfer limit is set to restrict double-spending risk.

Fourth, programmability enables innovations such as conditional automatic payment (e.g., restricting the place and period of use of disaster-relief funds, or automatic settlement when a condition is met), but placing usage restrictions on money can infringe on the "singleness of money" and individuals' economic freedom. Accordingly, many central banks take the cautious stance of leaving the money core unrestricted and confining programmable functions to "programmable payments" that the private sector provides in an upper layer.

4. Comparison and Cases

A. Comparison with Similar Digital Means of Payment

Comparing a CBDC with stablecoins, cryptocurrencies, and existing electronic payment instruments reveals differences in the source of trust and the risk structure. The table below should be read not as a mere list but together with "why those differences arise."

Category CBDC Stablecoin Cryptocurrency (Bitcoin, etc.) Bank deposit/easy payment
Issuer Central bank (public) Private issuer None (decentralized) Commercial bank/PG
Credit risk None (final money) Issuer/reserve-asset risk Market-price fluctuation Bank-failure risk (insurance limit)
Value stability Legal tender = 1:1 Depends on reserve assets Very large Fixed at face value
Finality Immediate and definitive Depends on issuer/chain Probabilistic finality Settlement delay exists

The key difference is that only a CBDC provides, as central bank money, the final settlement quality free of credit risk. A stablecoin carries the risk of de-pegging (departure of value) if its reserve assets deteriorate, and in fact the 2022 collapse of Terra/UST exposed the vulnerability of algorithmic stablecoins. That event became an occasion for countries to accelerate their discussion of public digital currency.

B. Cases by Country

The Bahamas' Sand Dollar (2020) was the world's first officially issued retail CBDC, aiming at financial inclusion given the geographic feature of being dispersed across islands. Nigeria's eNaira (2021) was also an early adopter but left the challenge of low usage, offering the lesson that "designing incentives to use" rather than "issuance" determines success or failure.

China's digital yuan (e-CNY) has greatly expanded its cumulative transaction volume through large-scale pilots, and is characterized by a two-tier structure, offline payment, and managed anonymity. In the digital euro project, the European Union concluded in October 2025 the preparation phase begun in November 2023 and moved to the next stage, presenting a pilot in 2027 and the possibility of a first issuance around 2029 if related legislation is in place during 2026 (ECB, Digital euro).

Korea's Bank of Korea, after a simulation experiment in 2021–2022, carried out "Project Hangang," a real-transaction pilot based on deposit tokens, from April to June 2025. Seven commercial banks—KB, Shinhan, Hana, Woori, Nonghyup, IBK, and Busan—participated, targeting the general public, with about 80,000 electronic wallets opened and about 110,000 transactions carried out. That said, this had the character of an experiment in tokenized deposits, tokenizing bank deposits, rather than a pure CBDC, and the subsequent second test was tentatively suspended, showing a trend of re-examining the strategy toward an institutional, wholesale focus. In the cross-border payment domain, cases such as the BIS-led Project mBridge are underway, experimenting with real-time cross-border settlement using multi-country wholesale CBDC.

5. In Depth: Recent Trends and Expected Exam Directions

A. Recent Trends

The recent trend can be summarized as "cautious on retail, accelerating on wholesale." The retail type is being paced down owing to privacy controversy, resistance from the banking sector, and the absence of clear benefits, whereas experiments in wholesale types among financial institutions and in deposit tokens and institutional tokenized money are spreading because of the clear benefit of interbank settlement efficiency. The BIS has presented a "unified ledger" concept that places wholesale CBDC, tokenized deposits, and securities on a single programmable platform. Another trend worth noting is that national policy lines are clearly diverging, with the United States taking a negative stance on retail CBDC and orienting toward regulating private stablecoins.

B. Expected Exam Directions and Answer Strategy

In the professional-engineer exam, a CBDC is likely to appear not only as a standalone new-technology question but also linked to security (privacy and anonymity design), architecture (the two-tier structure and whether to apply DLT), financial stability (disintermediation and holding limits), and cross-border payment (multi-country CBDC). When writing an answer, it is effective to structure it as: (1) first distinguish retail/wholesale, (2) develop the architecture along design axes such as account-based/token-based and the two-tier structure, (3) describe the conflicts of privacy, financial stability, offline, and programmability as trade-offs, and (4) draw implications from domestic (Project Hangang) and overseas (digital euro, e-CNY) cases.

6. Considerations and Implications

Introducing a CBDC is not the building of technology but the redesign of the monetary and financial system, so from a professional-engineer perspective the following should be considered comprehensively.

  • Strategy to ensure alignment between policy goals and design: A CBDC fails if "why it is needed" is unclear. One must clarify the priority among financial inclusion, payment efficiency, and monetary sovereignty, and design retail/wholesale, limits, and the level of privacy in reverse to fit that goal. Technology adoption without a goal ends in low usage (the lesson of eNaira).

  • Trade-off between financial stability and the banking ecosystem: Deposit outflow should be curbed by design of holding limits, zero interest, and waterfall, yet excessive restriction removes the incentive to use and undermines policy effectiveness. Limit policy based on stress scenarios should be designed in advance so as not to amplify a digital bank run in a crisis.

  • Balance between privacy and fears of a surveillance society: Tiered anonymity, data separation (separation of roles between intermediary and central bank), and minimal collection of personal data should be enforced at the architecture level (privacy by design). The loss of trust that "the state sees every transaction" is a political and social risk that can wreck adoption itself.

  • Resilience/security and the outlook for interoperability: As national critical infrastructure, one must secure uninterrupted availability, preparation for post-quantum cryptography (PQC), and offline-payment resilience, and secure standards-based interoperability (linked technologies: DLT, ISO 20022, API gateway) with existing payment networks and other countries' CBDCs. In particular, cross-border payment—multi-country CBDC platforms and the linkage of tokenized assets—will be a key direction of future development.

References

  1. BIS, "Central bank digital currencies: foundational principles and core features" — https://www.bis.org/publ/othp33.htm
  2. BIS, "Central bank digital currencies (CBDC)" topic page — https://www.bis.org/topic/fintech/cbdc.htm
  3. European Central Bank, "A digital euro" — https://www.ecb.europa.eu/euro/digital_euro/html/index.en.html
  4. IMF, "Central Bank Digital Currency" — https://www.imf.org/en/Topics/fintech/central-bank-digital-currency
  5. Atlantic Council, "Central Bank Digital Currency Tracker" — https://www.atlanticcouncil.org/cbdctracker/

In one line: A CBDC is a credit-risk-free digital legal tender issued by a central bank; on the design axes of retail/wholesale and account-based/token-based/two-tier structure, it is a problem of redesigning the monetary system by balancing the trade-offs of privacy, financial stability, offline, and programmability.