Why
The sentence doing the work is an ordinary one about corporate structure, and it dissolves a whole class of rule. If a regime says an issuer may not do X, and X can be performed by a sister company owned by the same parent, then the restriction has been satisfied by a filing. Nothing about the exposure changed — the same balance sheet stands behind it, the same people decide, the same conflict exists — but the regulated entity is now clean. The rule was written against a box on an org chart, and org charts are cheap to redraw.
The asymmetry BIS names is the part that inverts the intent. Banks are already supervised on a consolidated basis: the group is the unit, so relocating an activity inside the group does not move it outside supervision. Non-banks are supervised entity by entity, so the same relocation works. That means an identical activity restriction binds the bank, which was already the safer case, and slides off the non-bank, which was the reason the restriction was written. A rule that is strictest where it is least needed is not merely ineffective; it is a subsidy to the structure it was aimed at, because the compliant path is available only to the party you were worried about.
This catalogue has a name for the move already, and it arrived from software. the-boundary-is-the-unit argues that the transferable question in security is never was this authorised but where is the boundary and what crosses it — and that the usual check fails because it returns yes at exactly the moment of the attack. This is the same failure in a regulatory register. The perimeter was drawn around the issuer. The group crosses it. And the compliance check returns yes, truthfully, at exactly the moment the risk is being held somewhere the check does not look. That the same shape shows up in vendor scripts, storage slots, model loading and now corporate structure is the strongest evidence available that the boundary framing generalises past code.
The concrete damage is specific, and it lands on two cards this catalogue already has. stablecoin-redemption-desk argues that what actually makes a stablecoin's denominator is the desk that redeems at par under stress, and arb-bots-are-the-peg argues that nobody operates the peg — competing bots are the mechanism. Both depend on independence. Under vertical integration the redemption desk can be the group's own trading arm and the arbitrageur can be the affiliate, so the two mechanisms that are supposed to hold the peg are being run by the party whose failure they are supposed to reveal. The peg is still maintained; it is just no longer evidence of anything. That is a more precise statement of the harm than "conflicts of interest", and it is checkable from an ownership diagram.
One correction to how the passage is being read. The natural instinct on seeing text that fits a local situation is to ask whether the authors meant it — and that instinct is backwards. A general principle that happens to fit is more useful than a targeted one, because it means the pattern recurs across jurisdictions and the remedies have been tried elsewhere. Reading local intent into an international comparative brief is the same error fork-date-provenance exists to prevent: a claim's usefulness comes from what it says and what it is based on, not from who you think it was aimed at.
How it works
The same restriction, two structures
| Bank issuer | Non-bank issuer | |
|---|---|---|
| Unit of supervision | The group (consolidated) | The entity |
| Move activity X to a sister company | Still supervised | Now outside the regime |
| So the activity restriction | Binds | Slides off |
| Which was the case the rule was written for | No | Yes |
The last two rows are the whole problem. A restriction that binds only the party it was not aimed at is worse than no restriction, because it also prices the compliant structure out of the market.
The six functions, and which ones the perimeter actually covers
| Function | Load-bearing because | Commonly inside the issuer? |
|---|---|---|
| Issuance | It is the regulated act | Yes |
| Reserve management | Decides what the claim is backed by | Often a sister entity |
| Custody of the reserve | Decides who can move it | Often external, sometimes affiliated |
| Primary trading venue | Where the price is observed | Frequently affiliated |
| Market making the pair | arb-bots-are-the-peg — this is the peg |
Frequently affiliated |
| Redemption desk | stablecoin-redemption-desk — this is the denominator |
Frequently affiliated |
Count the rows that are load-bearing and affiliated but outside the perimeter. That count is the card's number, and it is obtainable from public ownership records rather than from a regulator.
Why vertical integration is the specific harm
Two mechanisms in this catalogue are supposed to keep a stablecoin honest, and both are independence arguments:
- The redemption desk makes the denominator real by paying par under stress.
- Competing arbitrageurs make the peg real because no single party operates it.
Under one group both can be the same party. The peg still holds and stops being evidence — which is worse than a visibly broken peg, because a broken peg is information and a manufactured one is not.
The same shape, four domains
| Where | The perimeter drawn | What crossed it |
|---|---|---|
Frontend (third-party-blast-radius) |
"our site" | An authorised vendor's script |
Contract (storage-collision-admin-takeover) |
"each module owns its state" | A shared storage slot |
Model loading (huggingface-is-a-package-manager) |
"loading weights" | Repo code, executed |
| Regulation (here) | "the issuer" | The group |
the-boundary-is-the-unit claimed the boundary question transfers. This is the test of that claim outside software, and it passes.