Open Financial Infrastructure: From Labels to Outcomes
How prudential supervisors should evaluate emerging financial infrastructure built on open blockchain networks, drawn from a submission to the Monetary Authority of Singapore.Why this consultation matters
When the Monetary Authority of Singapore opened its consultation on the prudential treatment of cryptoassets that settle on permissionless blockchains, much of the response treated it as a technical clarification: a question of which paragraphs to disapply, which annexes to refine, which thresholds to set. That reading is too small.
What MAS has done is among the first serious attempts anywhere to operationalise a prudential framework for infrastructure that no single, regulated entity operates. The proposal asks whether a banking system built on identified validators and a defined network perimeter can extend its assumptions to systems that have neither. That is not a narrow drafting matter. It is a test of whether financial regulation can develop alongside the technology it governs, rather than freezing the technology to fit the rules.
Singapore is well suited to run that test. It combines regulatory credibility with a willingness to experiment thoughtfully, and its approach to digital finance is often studied by policymakers seeking a balance between innovation and trust. What it concludes here will be read in other jurisdictions as a reference point. The stakes, in other words, sit well above cryptoassets.
Separating asset risk from infrastructure risk
The most useful idea in this debate is also the simplest: the asset and the network it runs on are different things, and they carry different risks.
Consider a bank holding a tokenised bond on a permissionless chain. It is exposed to two distinct sources of loss. The first is the claim itself: the credit standing of the issuer, the movement of the market, the reliability of the counterparty. The second is the rails: whether the network settles with finality, whether it stays operational, whether its validators behave. The first set is asset-layer risk. The second is infrastructure-layer risk.
Conflating the two weakens analysis on both sides. A pristine bond settling on a fragile network is not safe, and a robust network carrying a poor-quality asset does not redeem the asset. MAS's structure already gestures at this distinction: classification conditions one and two speak to the asset, while the principle-based requirements in Annex C speak to the network. Making that separation explicit in supervisory guidance would help banks apply the framework consistently across very different instruments, and would let supervisors reason about each layer on its own terms. A prudential framework becomes stronger, not more permissive, when it evaluates each layer independently.
Technology neutrality in practice
Technology neutrality is often invoked but rarely defined. It does not require regulators to ignore architectural differences, nor does it imply a lighter touch for newer technologies.
In practice, neutrality means something more demanding. The prudential outcomes the original rules sought, operational integrity, transferability, settlement finality, traceability, remain non-negotiable. What neutrality concedes is that those outcomes can be reached by more than one route. A permissioned ledger may achieve them through identified, regulated operators. A permissionless network may achieve equivalent outcomes through a combination of architectural design, economic incentives, and entity-level safeguards where identifiable entities exist.
Seen this way, entity-level regulation is one mechanism for delivering prudential outcomes rather than a precondition for them. Where regulated entities exist within an arrangement, their presence sharpens supervisory clarity and should be welcomed. Where they do not, the relevant question is not who is accountable in the familiar sense, but whether the system can evidence the same outcomes through other means. Neutrality, properly understood, holds every architecture to the same outcomes and lets them compete on how convincingly they meet them.
Anti-money-laundering controls offer the clearest illustration. The current drafting leans on a model in which a cryptoasset issuer can permission or whitelist holders. That fits a stablecoin issued by a regulated entity onto an open chain, where an identifiable issuer holds the relevant controls. It fits far less well a protocol-native asset, which has no issuer in the regulatory sense and whose money-laundering risk is managed at the points of entry and exit, through regulated intermediaries and transaction-level monitoring, rather than at the protocol layer. The prudential concern is whether the bank's exposure to that risk is adequately contained, not the precise point at which the control sits. A tiered expectation follows naturally: where an issuer with permissioning capability exists, the existing approach applies; where it does not, banks can evidence mitigation through transaction analytics, counterparty screening at custody and transfer, and controls at their own perimeter. The outcome MAS is seeking is preserved. The framework simply meets each system where it actually operates.
Governance is becoming a prudential question
For most of its history, prudential supervision has treated governance as a matter of corporate conduct: boards, committees, lines of accountability. In open networks, governance becomes something closer to an operational property of the system itself, and it starts to behave like a source of financial risk.
The original classification conditions assume an identified set of validators and a clear network boundary. That assumption maps cleanly onto permissioned systems and breaks down in permissionless ones, where the relationship between functions and identifiable entities is rarely tidy. A wallet provider may be a recognisable team that nonetheless functions only as an interface, performing no custody. Transfer and settlement may be carried out by protocol logic rather than by any operator. The administrator of a stabilisation mechanism may, in practice, be a set of governance processes rather than a single accountable party.
This is why governance deserves scrutiny comparable to operational risk. How a network is upgraded, who holds privileged keys, how contested changes have been resolved in the past: these are not abstractions. They determine whether a system can be changed under pressure, by whom, and with what notice. Where a function once performed by a regulated entity is now performed by audited on-chain logic, supervisors and banks would benefit from explicit guidance on how to treat it. Without that, the framework risks screening out the very arrangements its principle-based design was meant to accommodate.
Measuring decentralisation without false precision
If governance and validator structure matter, supervisors will want to measure them. The instinct is right; the danger is in pretending the measurement is more precise than it is.
Validator diversification, the single most important infrastructure safeguard in a permissionless system, is not one quantity but several. Stake can be widely distributed while operational control is not: two nominally independent validators run by the same staking pool are not independent for the purposes of liveness or censorship resistance. Validators can be numerous yet clustered in a handful of jurisdictions, creating a correlated exposure to political or regulatory interference. A network can run almost entirely on a single client implementation, so that one software defect halts it. And a chain that looks decentralised today may concentrate over time if the cost of running a validator is high.
Indicators such as Nakamoto coefficients, measured by stake and by operator, can offer a useful reference point across these dimensions. The mistake would be to convert them into rigid thresholds and treat a number as a verdict. There is a related trap worth naming. Open networks are transparent by design, but transparency is not the same as interpretability. The raw data is observable, but turning it into a supervisory signal takes analytical tooling. The signals that matter include how often the chain rewrites its recent history, how long transactions take to become final, how many validators are actively participating, and whether the network depends on a single software client. Building or sourcing that capability is itself a supervisory choice.
Decentralisation is a spectrum and a moving one. The stronger approach names the dimensions supervisors should weigh, asks banks to assess them, and retains judgement on where any given network sits, rather than reducing a living system to a single pass-or-fail score.
Beyond cryptoassets: why these questions will matter more
It would be a mistake to file this consultation under crypto. The questions it raises are about infrastructure, and infrastructure does not stay in one asset class.
The same analysis, asset versus network, outcomes versus labels, governance as prudential risk, will apply with growing force to tokenised deposits, tokenised securities, on-chain money market instruments, derivatives infrastructure, and cross-border settlement systems. As more financial functions move onto programmable networks, supervisors will repeatedly face the question MAS is confronting now: when an established function is performed by code and shared infrastructure rather than by a named intermediary, what does prudential assurance look like?
In answering today's narrow question, regulators are quietly drafting the evaluation framework for tomorrow's financial architecture. That is reason to get the principles right rather than the thresholds precise.
An illustrative case: blockchain-native market infrastructure
A useful way to see why this matters is to look at venues where execution, liquidity, and settlement are converging inside a single blockchain-native environment. Hyperliquid is one current example: a setting in which functions that traditional markets distribute across exchanges, clearing, and settlement systems are performed together on-chain.
The point is not that such a venue represents the future of finance, nor that activity will inevitably migrate on-chain, nor that established institutions are becoming obsolete. Whether any particular venue succeeds is beside the point. What matters is that increasingly sophisticated financial functions are already being conducted in environments that do not fit existing supervisory categories. An arrangement that combines trading, liquidity provision, and settlement does not resolve neatly into exchange or clearing house, and the prudential tools built for those categories do not transfer cleanly.
Examples of this kind demonstrate, concretely, why a framework that assesses outcomes rather than labels is worth building now. The categories will keep blurring. The outcomes society expects of critical financial infrastructure will not.
Where Singapore can lead
This is where Singapore's particular standing becomes valuable. Few jurisdictions combine the regulatory credibility to be taken seriously with the willingness to test frameworks against real systems. Singapore does, and its conclusions travel.
The contribution it can make is not a ruling on whether open infrastructure should exist. It is a demonstration that prudential safeguards and technological development can hold together: that a supervisor can take governance, validator concentration, and operational resilience seriously without retreating into a blanket prohibition, and can do so in language other regulators are able to adopt. Standards developed here, grounded in implementation realities rather than in posture, stand a real chance of shaping international practice.
That credibility shows up in small design choices as much as in stated principles. Interim exposure and issuance caps, for instance, are a reasonable response to a framework whose principle-based assessments have not yet been tested at scale. The more interesting question is how they are lifted. Tying any review to observable indicators, the depth of secondary markets, accumulated supervisory experience, the consistency of industry practice on validator diversification and governance disclosure, rather than to a procedural date alone, lets calibration track the maturity of the market. It is a modest example of the same principle that runs through the whole framework: judge the system by what it can demonstrate, not by the calendar or the label.
Conclusion
The framing question was never whether permissionless infrastructure should be allowed to exist. It exists. The more useful question, and the one this consultation begins to answer, is narrower and harder: under what conditions can an emerging infrastructure demonstrate that it is capable of supporting regulated activity safely and responsibly?
The strongest frameworks will not try to pick technological winners. They will state, clearly and durably, the outcomes society expects from critical financial infrastructure, governance that can be examined, resilience that can be tested, transparency that can be interpreted, safeguards that can be evidenced, and then allow different architectures to compete in meeting them. That is a higher standard than choosing a side, and a more honest one. It keeps the human purpose of the system in view: not the elegance of any particular technology, but the safety of the people and institutions that depend on it.
Written by: Katherine, Founder and Managing Partner of Katashe Solutions