Skip to main content
Category: Virtual Assets and Technology

Central Bank Digital Currency (CBDC)

Also known as: CBDC, central bank digital currency, digital fiat currency
Simply put

A Central Bank Digital Currency (CBDC) is a digital version of a country's official currency that is created and issued by its central bank, rather than by a private company. Like physical cash, it is a direct claim on, and liability of, the central bank that backs it. Holders can generally use a CBDC to store value and make payments digitally, and it can typically be transferred across networks and accounts.

Formal definition

A CBDC is a digital form of a nation's sovereign fiat currency that constitutes a liability of, and a claim on, the issuing central bank, distinguishing it from privately issued digital money or commercial bank deposits. In this respect it carries the same central-bank backing that physical currency does, and is generally described as a risk-free form of digital money issued and controlled by the central bank. CBDCs are designed to allow holders to store value and make payments digitally, with the capacity to be transferred across networks and bank accounts. Design characteristics, issuance status, and legal treatment vary by jurisdiction; many CBDCs remain at the research, pilot, or discussion-paper stage rather than being fully deployed, and specific attributes should be confirmed against the framework of the issuing central bank.

Why it matters

For financial crime professionals, CBDCs represent a potential structural shift in how sovereign money is issued, held, and moved, and this shift carries implications that are still being worked out across jurisdictions. Because a CBDC is a direct liability of the central bank rather than of a commercial intermediary, it could alter the traditional model in which obliged entities such as banks sit between the currency issuer and the end user and perform customer due diligence, transaction monitoring, and reporting. How AML/CFT obligations would attach to CBDC transactions, and which parties would bear them, depends heavily on the design choices of each issuing central bank and the surrounding legal framework, and these questions remain largely open.

The compliance significance of a CBDC therefore cannot be assessed in the abstract. Design characteristics such as whether holdings are account-based or token-based, the degree of transaction visibility to the central bank or intermediaries, and any transfer or balance limits would each shape the money laundering and terrorist financing risk profile differently. Some designs could enhance the traceability of payments relative to physical cash, while others could raise data-protection or intermediation concerns; none should be assumed to eliminate financial crime risk. As with any payment instrument, controls around a CBDC would function to detect, deter, and mitigate risk rather than to guarantee prevention.

Because many CBDCs remain at the research, pilot, or discussion-paper stage rather than being fully deployed, practitioners should treat the field as evolving. Specific attributes, legal treatment, and any AML/CFT requirements should be confirmed against the framework of the relevant issuing central bank rather than assumed to follow a single global model.

Who it's relevant to

Compliance officers at banks and payment firms
Where a CBDC is issued in a jurisdiction in which they operate, compliance teams may need to understand how the instrument affects their institution's role as an intermediary and how customer due diligence, monitoring, and reporting obligations would apply to CBDC activity. Because the extent of these obligations depends on the central bank's design choices and the applicable legal framework, they should be confirmed against the specific regime rather than assumed.
Financial intelligence and transaction monitoring analysts
Analysts should recognize that a CBDC's traceability and monitoring characteristics depend entirely on how it is designed and whether transactions are visible to the central bank or intermediaries. This affects how, and whether, CBDC flows can be surfaced and analyzed for suspicious activity, and analysts should not assume that a CBDC behaves like either physical cash or existing digital payment rails.
Policy, regulatory affairs, and legal professionals
Given that many CBDCs remain at the research, pilot, or discussion-paper stage, professionals tracking regulatory developments have an interest in how issuance status, legal treatment, and any AML/CFT expectations evolve across jurisdictions. Because approaches differ by central bank and no single global rule exists, these developments should be monitored on a jurisdiction-by-jurisdiction basis.
Risk and product teams evaluating digital currency exposure
Teams assessing exposure to digital forms of money should distinguish a CBDC, as a central-bank liability, from privately issued digital money and commercial bank deposits. Understanding this distinction supports more accurate risk assessment, while recognizing that specific attributes must be verified against the issuing central bank's framework.

Inside CBDC

Central Bank Issuance
A CBDC is a digital form of a jurisdiction's sovereign currency issued and backed directly by its central bank, representing a direct liability of that central bank. This distinguishes it from commercial bank deposits (a liability of a private bank) and from privately issued stablecoins or cryptoassets.
Retail vs. Wholesale Models
CBDC designs are generally categorized as retail (available to the general public for everyday payments) or wholesale (restricted to financial institutions for interbank settlement). The AML/CFT risk profile and applicable obligations may differ significantly between these models, and specifics vary by jurisdiction.
Account-Based vs. Token-Based Architecture
CBDCs may be structured around identified accounts (where access depends on verifying identity) or tokens (where validity of the instrument itself is verified). The chosen architecture influences how customer due diligence and transaction monitoring can be applied.
Intermediated Distribution
Many proposed CBDC frameworks contemplate a two-tier model in which the central bank issues the currency but private-sector intermediaries (such as banks or payment providers) handle distribution, customer onboarding, and related compliance functions. Where this applies, those intermediaries may be the obliged entities carrying AML/CFT responsibilities.
Privacy and Traceability Design Choices
CBDC designs involve trade-offs between user privacy and transaction traceability. The degree of anonymity or auditability designed into a CBDC affects the extent to which controls such as monitoring, screening, and record-keeping can be operationalized.
AML/CFT Regulatory Status
The application of AML/CFT obligations to CBDCs depends on how each jurisdiction classifies and legislates for them; frameworks are still developing in many places, and it should not be assumed that existing obligations for other instruments map identically onto CBDCs.

Common questions

Answers to the questions practitioners most commonly ask about CBDC.

Is a CBDC just another form of cryptocurrency?
No. Although both are digital, a CBDC is a direct liability of a central bank and represents central bank money, whereas most cryptocurrencies are decentralized assets with no central issuer or sovereign backing. Conflating the two can lead to misapplied controls: the money laundering and terrorist financing risk profile, governance model, and legal status of a central-bank-issued CBDC generally differ from those of decentralized virtual assets. The specific design features, and therefore the applicable regulatory treatment, vary by jurisdiction and should be confirmed against the relevant central bank framework.
Does the introduction of a CBDC automatically eliminate money laundering risk because transactions can be traced?
No. Greater traceability may support detection and monitoring, but it does not guarantee prevention of financial crime. The degree of transparency depends heavily on design choices, such as whether the CBDC is account-based or token-based, the level of any privacy or offline functionality, and the intermediary model. Layering and integration typologies may still be attempted, and controls should be understood as measures to detect, deter, and mitigate risk rather than as a guarantee. Residual risk and its treatment depend on the specific CBDC architecture adopted in a given jurisdiction.
Which entity typically performs customer due diligence for a CBDC, and does it change existing obligations?
This depends on the distribution model chosen by the issuing central bank. In many proposed designs that use an intermediated or two-tier model, regulated intermediaries such as banks or payment service providers would generally continue to perform customer due diligence on their users, consistent with their existing obligations as obliged entities under the applicable AML regime. Direct-issuance models could shift some responsibilities. Because approaches differ, firms should confirm the allocation of CDD responsibilities against the specific CBDC framework and any implementing guidance in their jurisdiction.
How might transaction monitoring differ for a CBDC compared with existing payment rails?
Transaction monitoring approaches would depend on the CBDC's technical design and the data available to the monitoring entity. Some designs may provide different data granularity, settlement finality characteristics, or offline transaction capabilities than existing rails, which could affect how alerts are generated and investigated. Firms typically need to assess whether existing monitoring rules, thresholds, and typologies remain appropriate or require recalibration. Any operational assumptions should be validated against the technical specifications published for the relevant CBDC.
What sanctions screening considerations may apply to CBDC transactions?
Sanctions screening obligations would generally continue to apply to obliged entities handling CBDC transactions, though the practical implementation depends on the design and on which party has visibility of the relevant party data. Screening for sanctions is a distinct process from PEP screening and from customer due diligence, and each may need to be re-examined in light of the CBDC's identity and data model. Firms should confirm how screening responsibilities and data access are allocated within the specific CBDC framework and their applicable legal requirements.
How should a compliance function begin preparing for a potential CBDC rollout?
Preparation typically starts with monitoring the design and consultation materials published by the relevant central bank, since obligations flow from the specific framework and its implementing rules rather than from a single global standard. Firms may wish to assess how a CBDC would map to their existing risk assessment, CDD, monitoring, and screening controls, and to identify where recalibration might be needed depending on the distribution model. Because CBDC design and regulatory treatment remain jurisdiction-specific and evolving, planning assumptions should be revisited as authoritative details are confirmed.

Common misconceptions

A CBDC is essentially the same thing as a cryptocurrency or stablecoin.
A CBDC is a direct liability of a central bank and represents sovereign currency, whereas cryptocurrencies are typically decentralized and not backed by a central authority, and stablecoins are privately issued instruments referencing an asset. The issuer, backing, and legal status differ materially, and these distinctions affect the applicable regulatory treatment.
Because a CBDC is digital and traceable, it inherently prevents money laundering and terrorist financing.
Design features that enable traceability may help detect, deter, or mitigate certain risks, but no instrument eliminates financial crime risk. Effectiveness depends on the specific design choices, the controls applied by obliged entities, and the surrounding regulatory framework, all of which vary and remain under development in many jurisdictions.
AML/CFT obligations for CBDCs are already settled and uniform across regimes.
Regulatory frameworks for CBDCs are generally still evolving. How obligations apply depends on each jurisdiction's classification and legislation, and it should not be assumed that a single global rule exists or that requirements for other instruments transfer directly. Exact requirements should be confirmed against the applicable regulation.

Best practices

Determine which entity in the CBDC value chain qualifies as the obliged entity for AML/CFT purposes in the relevant jurisdiction, as intermediated distribution models may place customer due diligence and monitoring responsibilities on distributing intermediaries rather than the central bank.
Assess whether a given CBDC follows a retail or wholesale, and account-based or token-based, model, since these design characteristics shape how customer due diligence, transaction monitoring, and record-keeping can be operationally applied.
Confirm the applicable AML/CFT obligations against the specific regulations of each relevant jurisdiction rather than assuming that requirements for cryptoassets, stablecoins, or commercial bank money map directly onto CBDCs.
Evaluate the privacy-versus-traceability design trade-offs of a CBDC to understand the practical limits and possibilities for detecting and mitigating financial crime risk within that design.
Treat CBDC controls as measures to detect, deter, and manage risk rather than as guarantees, and integrate them within a broader risk-based AML/CFT program.
Monitor the evolving regulatory landscape for CBDCs, given that frameworks in many jurisdictions remain under development, and update policies and procedures as classifications and obligations are clarified.