Mid-Year Savings Are Live | Flat 25% OFF | Code: GROWTH
Blockchain Council
digital assets9 min read

Direct vs Indirect CBDC Models: How Central Banks Distribute Digital Currency

Suyash RaizadaSuyash Raizada
Direct vs Indirect CBDC Models: How Central Banks Distribute Digital Currency

Direct vs Indirect CBDC Models define one of the most important design choices in central bank digital currency: should the central bank serve every retail user directly, or should banks and payment firms distribute digital money through a two-tier system? The answer shapes privacy, bank funding, resilience, compliance, and how quickly a CBDC can move from pilot to production.

Retail CBDC is digital central bank money available to households and businesses. That makes it different from wholesale CBDC, which is built mainly for settlement among banks and financial institutions. The distribution model decides who holds the customer relationship, who runs the ledger, and where the legal claim sits.

Certified Artificial Intelligence Expert Ad Strip

What Are Direct vs Indirect CBDC Models?

CBDC architecture is not just a technical diagram. It is a decision about institutional responsibility. The Bank for International Settlements, Payments Canada, the World Bank, and the ITU Digital Currency Global Initiative all frame CBDC distribution around single-tier and multi-tier models.

Direct CBDC model

In a direct CBDC model, the central bank issues CBDC and manages retail accounts or wallets for the public. Every user holds a direct claim on the central bank, similar in legal quality to cash. The central bank also operates the core retail ledger and processes payments.

Private firms may still provide wallet apps or front-end services, but the central bank remains the main account operator. Think of it as a national payment wallet where the central bank controls the balance sheet and the core payment rails.

Indirect CBDC model

In an indirect CBDC model, commercial banks, payment service providers, or licensed intermediaries serve end users. The central bank maintains wholesale accounts for those intermediaries, while the intermediaries maintain retail ledgers and customer wallets.

Here, the user usually has a claim on the intermediary, and that liability is fully backed by central bank money. This keeps the structure close to existing banking, where the central bank deals with regulated institutions and those institutions deal with the public.

How a Direct CBDC Works

A direct CBDC is the cleanest model on paper. The central bank issues the digital currency, opens accounts or wallets for citizens and businesses, updates balances, and settles transactions in real time or near real time.

The main features are:

  • Legal claim: Users hold a direct claim on the central bank.
  • Ledger control: The central bank runs the retail ledger.
  • Payments: The central bank processes transfers between end users.
  • Intermediary role: Banks and fintech firms may provide apps, but not the core ledger.

This model gives the central bank maximum control. It can define settlement rules, apply limits, set remuneration, and preserve access to risk-free public money in a digital economy.

Benefits of a direct CBDC

  • Safety of money: A direct claim on the central bank removes commercial bank credit risk for CBDC balances.
  • Policy control: Interest, holding limits, tiered remuneration, and emergency transfers can be applied without routing through banks.
  • System clarity: One operator means fewer parties in the core settlement chain.
  • Crisis utility: In a banking stress event, the central bank could deliver payments directly to the public.

That sounds attractive. Still, direct CBDC is the hardest model to operate at national scale.

Risks of a direct CBDC

The first problem is operational. Central banks are built for monetary policy, reserves, settlement systems, supervision, and financial stability. They are not usually built to run call centers for forgotten passwords, disputed merchant payments, wallet recovery, phishing complaints, or retail onboarding.

Anyone who has worked on payment ledgers knows the ugly details arrive fast. A timeout at the wallet layer can cause a client to retry the same payment instruction. If the ledger does not enforce an idempotency key, the transfer may post twice. That is not a theoretical issue. It is one of the first bugs you test for in any real payment sandbox.

Then comes privacy. The European Data Protection Supervisor has warned that direct architectures can concentrate detailed payment data at the central bank. Even if a democratic central bank has no intent to surveil users, the design can create a tempting database for future governments, law enforcement overreach, or attackers.

There is also the banking impact. If users can move large deposits into risk-free CBDC instantly, banks may lose a stable funding base. That can affect lending, liquidity management, and financial stability. Holding limits can reduce the risk, but they add design complexity.

How an Indirect CBDC Works

An indirect CBDC keeps the familiar two-tier model. The central bank issues and settles at the wholesale layer. Regulated intermediaries distribute CBDC or CBDC-backed balances to the public.

The setup usually looks like this:

  • Central bank layer: Issues CBDC or reserve-backed settlement balances to intermediaries.
  • Intermediary layer: Handles wallets, onboarding, KYC, AML checks, user support, and transaction interfaces.
  • Retail user layer: Individuals and firms transact through banks, fintech apps, or payment providers.

Payments Canada describes this as a model where intermediaries run the retail ledger while the central bank maintains a wholesale ledger. The ITU reference architecture also distinguishes multi-tier models where intermediaries perform core lifecycle functions for general-purpose CBDC.

Benefits of an indirect CBDC

  • Scalability: Banks and payment providers already handle millions of retail customers.
  • Continuity: The model preserves the role of commercial banks in financial intermediation.
  • Privacy by design: The central bank does not need to see every retail transaction.
  • Competition: Different providers can compete on wallet design, merchant tools, analytics, and accessibility.
  • Compliance fit: KYC, AML, fraud monitoring, and customer due diligence stay with regulated entities that already perform them.

For large economies, this is the practical choice. To be blunt, a pure direct CBDC may be elegant in a policy paper, but an indirect CBDC is much closer to how national payment systems actually work.

Risks of an indirect CBDC

The weakness is that users depend on intermediaries. If a wallet provider fails, mishandles funds, or suffers a cyberattack, users can face disruption. Full backing with central bank money helps, but legal segregation, supervision, operational resilience, and recovery planning still matter.

Another issue is fragmentation. If each bank or payment provider builds its own wallet standard, payments can become messy. Interoperability has to be specified early. This includes message formats, identity checks, offline payment rules, fraud reporting, and settlement finality. ISO 20022 messaging may help at the payment layer, but it does not solve wallet governance by itself.

Hybrid CBDC: The Middle Path

A hybrid CBDC combines both models. Intermediaries manage customers and process most payments, while the central bank maintains a backup record of balances or has a clear legal and technical path to step in if an intermediary fails.

This model tries to answer a hard question: how do you keep private-sector distribution without letting a failed intermediary break public confidence in CBDC?

Hybrid architecture can support:

  • Payment continuity if a provider exits the market.
  • Limited central bank visibility into balances without full transaction surveillance.
  • Clearer recovery procedures during outages.
  • A stronger public guarantee than a fully indirect model.

Many current policy discussions lean toward indirect or hybrid CBDC because they preserve the two-tier banking system while giving the central bank more control than ordinary private payment instruments.

Synthetic CBDC and Stablecoin Links

Synthetic CBDC is often discussed alongside indirect models, but it is not always treated as true CBDC. In this setup, a private issuer offers a stablecoin or payment token fully backed by central bank reserves or similar high-quality assets. Users hold a claim on the issuer, not directly on the central bank.

This can support private innovation while anchoring value in central bank money. It also raises familiar stablecoin questions: who supervises the issuer, where are reserves held, how are customer assets segregated, and what happens during redemption stress?

As stablecoin regulation matures, synthetic CBDC may become an important bridge between private digital money and public money. But it should not be confused with a direct retail CBDC.

Direct vs Indirect CBDC Models: Side-by-Side Comparison

DimensionDirect CBDCIndirect CBDC
Legal claimUser has a direct claim on the central bankUser usually has a claim on an intermediary backed by central bank money
LedgerCentral bank operates the retail ledgerIntermediaries operate retail ledgers, central bank runs wholesale ledger
Bank roleLimited or optionalCore role in distribution and customer service
Operational burdenHigh for the central bankShared across regulated intermediaries
PrivacyHigher risk of central data concentrationBetter scope for data minimization
Financial stabilityGreater disintermediation riskDesigned to preserve bank intermediation

What Are Central Banks Choosing?

The direction is clear. Most major retail CBDC work favors indirect or hybrid distribution. The euro area, the United Kingdom, India, and Canada have all explored models where private intermediaries play a meaningful front-end role. BIS research also notes that CBDC design choices are being shaped by financial stability, payment resilience, and the need to preserve the two-tier system.

Direct CBDC remains useful as a reference design. It may suit smaller jurisdictions, narrow public payment use cases, emergency disbursement systems, or environments with weak payment infrastructure. For a large advanced economy, though, the operational and political cost is hard to justify.

Privacy, Cross-Border Access, and Future Design

Privacy will decide much of the architecture. A CBDC that gives the state full retail transaction visibility will face public resistance, even if the technology works. Indirect and hybrid CBDC models allow stronger data minimization because intermediaries can perform compliance checks without sending every detail to the central bank.

Cross-border CBDC adds another layer. Foreign users or foreign payment providers may access CBDC directly, or they may be routed through domestic intermediaries. BIS and IMF work on cross-border CBDC points to the same trade-off seen domestically: direct access can improve reach, while indirect access helps manage compliance, foreign exchange, and jurisdictional risk.

Programmability matters too. Conditional payments, wallet limits, merchant restrictions, and offline transactions all depend on who controls execution rules. If you are designing CBDC systems, keep policy logic separate from wallet interface code. Hard-coding policy into client apps is a mistake you will regret at the first rule change.

Which CBDC Model Is the Better Choice?

For most central banks, indirect or hybrid CBDC is the better default. It fits existing financial infrastructure, protects the role of banks, reduces central bank operational load, and leaves more room for privacy-preserving design.

Direct CBDC is not useless. It offers the strongest public-money claim and the clearest central bank control. But it turns the central bank into a retail payments operator, with all the support, cybersecurity, privacy, and political risks that come with that job.

If you work in policy, payments, or digital assets, build your CBDC knowledge around architecture, legal claims, ledger design, interoperability, and privacy engineering. For structured learning, look at Blockchain Council's Certified Blockchain Expert™, Certified Blockchain Developer™, and Certified Cryptocurrency Expert™ programs. Then map one CBDC use case yourself: define the claim, choose the ledger model, set privacy boundaries, and test what happens when an intermediary fails.

Related Articles

View All

Trending Articles

View All