Workspace IndexDev Notes › The rule names an entity and the risk lives in the group

#115PoC

The rule names an entity and the risk lives in the group

A BIS brief points out that activity restrictions reach only the issuer, so a prohibited activity moves to a sister company and the restriction is satisfied while nothing about the risk changed. The asymmetry is sharper than it sounds: banks already carry group-wide supervision and non-banks do not, so the same rule binds hardest where it was least needed.

Not yet scoped, and the deliverable is a diagram of a group rather than a reading of a regime. For any stablecoin this project would accept or quote, list six functions and name the legal entity performing each: issuance, reserve management, custody of the reserve, the primary trading venue, the market maker quoting the pair, and the redemption desk. Then draw the ownership lines between them and mark which entities sit inside the stablecoin regime's perimeter. The number worth writing down is how many load-bearing functions are performed outside that perimeter by a related party — that is the figure the entity-level rule does not see. Do it for two issuers with different structures so the comparison has a control. Source: BIS FSI Briefs no. 33, "Regulating stablecoin issuance: permissible entities and activities", section 4, seen 2026-08-29 via a practitioner post. Read section 4 at source before quoting it; the passage circulating is one paragraph of a comparative brief.

Why

The sentence doing the work is an ordinary one about corporate structure, and it dissolves a whole class of rule. If a regime says an issuer may not do X, and X can be performed by a sister company owned by the same parent, then the restriction has been satisfied by a filing. Nothing about the exposure changed — the same balance sheet stands behind it, the same people decide, the same conflict exists — but the regulated entity is now clean. The rule was written against a box on an org chart, and org charts are cheap to redraw.

The asymmetry BIS names is the part that inverts the intent. Banks are already supervised on a consolidated basis: the group is the unit, so relocating an activity inside the group does not move it outside supervision. Non-banks are supervised entity by entity, so the same relocation works. That means an identical activity restriction binds the bank, which was already the safer case, and slides off the non-bank, which was the reason the restriction was written. A rule that is strictest where it is least needed is not merely ineffective; it is a subsidy to the structure it was aimed at, because the compliant path is available only to the party you were worried about.

This catalogue has a name for the move already, and it arrived from software. the-boundary-is-the-unit argues that the transferable question in security is never was this authorised but where is the boundary and what crosses it — and that the usual check fails because it returns yes at exactly the moment of the attack. This is the same failure in a regulatory register. The perimeter was drawn around the issuer. The group crosses it. And the compliance check returns yes, truthfully, at exactly the moment the risk is being held somewhere the check does not look. That the same shape shows up in vendor scripts, storage slots, model loading and now corporate structure is the strongest evidence available that the boundary framing generalises past code.

The concrete damage is specific, and it lands on two cards this catalogue already has. stablecoin-redemption-desk argues that what actually makes a stablecoin's denominator is the desk that redeems at par under stress, and arb-bots-are-the-peg argues that nobody operates the peg — competing bots are the mechanism. Both depend on independence. Under vertical integration the redemption desk can be the group's own trading arm and the arbitrageur can be the affiliate, so the two mechanisms that are supposed to hold the peg are being run by the party whose failure they are supposed to reveal. The peg is still maintained; it is just no longer evidence of anything. That is a more precise statement of the harm than "conflicts of interest", and it is checkable from an ownership diagram.

One correction to how the passage is being read. The natural instinct on seeing text that fits a local situation is to ask whether the authors meant it — and that instinct is backwards. A general principle that happens to fit is more useful than a targeted one, because it means the pattern recurs across jurisdictions and the remedies have been tried elsewhere. Reading local intent into an international comparative brief is the same error fork-date-provenance exists to prevent: a claim's usefulness comes from what it says and what it is based on, not from who you think it was aimed at.

How it works

The same restriction, two structures

Bank issuer Non-bank issuer
Unit of supervision The group (consolidated) The entity
Move activity X to a sister company Still supervised Now outside the regime
So the activity restriction Binds Slides off
Which was the case the rule was written for No Yes

The last two rows are the whole problem. A restriction that binds only the party it was not aimed at is worse than no restriction, because it also prices the compliant structure out of the market.

The six functions, and which ones the perimeter actually covers

Function Load-bearing because Commonly inside the issuer?
Issuance It is the regulated act Yes
Reserve management Decides what the claim is backed by Often a sister entity
Custody of the reserve Decides who can move it Often external, sometimes affiliated
Primary trading venue Where the price is observed Frequently affiliated
Market making the pair arb-bots-are-the-peg — this is the peg Frequently affiliated
Redemption desk stablecoin-redemption-desk — this is the denominator Frequently affiliated

Count the rows that are load-bearing and affiliated but outside the perimeter. That count is the card's number, and it is obtainable from public ownership records rather than from a regulator.

Why vertical integration is the specific harm

Two mechanisms in this catalogue are supposed to keep a stablecoin honest, and both are independence arguments:

  1. The redemption desk makes the denominator real by paying par under stress.
  2. Competing arbitrageurs make the peg real because no single party operates it.

Under one group both can be the same party. The peg still holds and stops being evidence — which is worse than a visibly broken peg, because a broken peg is information and a manufactured one is not.

The same shape, four domains

Where The perimeter drawn What crossed it
Frontend (third-party-blast-radius) "our site" An authorised vendor's script
Contract (storage-collision-admin-takeover) "each module owns its state" A shared storage slot
Model loading (huggingface-is-a-package-manager) "loading weights" Repo code, executed
Regulation (here) "the issuer" The group

the-boundary-is-the-unit claimed the boundary question transfers. This is the test of that claim outside software, and it passes.

← All Dev Notes · Workspace Index · Top ↑

규칙은 법인을 지목하고, 위험은 그룹에 산다

BIS 브리프가 짚습니다 — 활동 규제는 발행자에게만 닿으므로, 금지된 활동을 자매회사로 옮기면 규제는 충족되고 위험은 그대로입니다. 비대칭은 들리는 것보다 날카롭습니다: 은행은 이미 그룹 단위 감독을 받고 비은행은 아니어서, 같은 규칙이 가장 덜 필요한 곳에서 가장 세게 묶입니다.

아직 범위 미정이고, 결과물은 규제 해설이 아니라 그룹 구조도입니다. 이 프로젝트가 받거나 호가할 스테이블코인 하나에 대해 기능 여섯을 적고 각각을 수행하는 법인의 이름을 씁니다: 발행, 준비금 운용, 준비금 수탁, 주 거래장, 그 페어를 호가하는 마켓메이커, 그리고 환매 데스크. 그다음 그들 사이의 지분 관계를 선으로 긋고, 어느 법인이 스테이블코인 규제의 경계 안에 있는지 표시합니다. 적어둘 값어치가 있는 숫자는, 하중을 받는 기능 중 몇 개가 그 경계 밖에서 특수관계인에 의해 수행되는가입니다 — 법인 단위 규칙이 보지 못하는 숫자가 그것입니다. 구조가 다른 발행자 둘에 대해 해서 비교에 대조군을 두십시오. 출처: BIS FSI Briefs no. 33, "Regulating stablecoin issuance: permissible entities and activities" 4장. 2026-08-29 실무자 게시물로 확인. 인용 전에 4장을 원문에서 읽을 것 — 도는 것은 비교 브리프의 한 문단입니다.

하중을 받는 문장은 기업 구조에 관한 평범한 문장이고, 그 한 문장이 규칙 한 부류를 통째로 녹입니다. 어떤 규제가 발행자는 X 를 하면 안 된다고 하는데 같은 모회사를 둔 자매회사가 X 를 할 수 있다면, 그 규제는 서류 한 장으로 충족됩니다. 익스포저는 아무것도 안 바뀌었습니다 — 같은 대차대조표가 뒤에 있고, 같은 사람들이 결정하고, 같은 이해상충이 있습니다 — 다만 규제 대상 법인만 깨끗해졌습니다. 규칙은 조직도의 네모 하나를 겨냥해 쓰였고, 조직도는 다시 그리는 비용이 쌉니다.

BIS 가 지목한 비대칭이 의도를 뒤집는 지점입니다. 은행은 이미 연결 기준으로 감독받습니다 — 그룹이 단위이므로 활동을 그룹 안에서 옮겨도 감독 밖으로 나가지 않습니다. 비은행은 법인별로 감독되므로 같은 이전이 통합니다.동일한 활동 규제가 이미 더 안전했던 은행은 묶고, 그 규제를 쓰게 만든 이유였던 비은행에서는 미끄러집니다. 가장 덜 필요한 곳에서 가장 엄격한 규칙은 단지 무효한 게 아니라, 겨냥한 구조에 대한 보조금입니다 — 준수 경로가 걱정하던 쪽에게만 열려 있으니까요.

이 목록에는 이미 그 수의 이름이 있고, 그건 소프트웨어에서 왔습니다. the-boundary-is-the-unit 은 보안에서 이전되는 질문이 인가됐는가가 아니라 경계가 어디이고 무엇이 넘는가이며, 통상의 검사는 공격이 일어나는 바로 그 순간에 예 라고 답하기 때문에 실패한다고 주장합니다. 이건 같은 실패의 규제 버전입니다. 경계는 발행자 둘레에 그어졌고, 그룹이 그것을 넘습니다. 그리고 컴플라이언스 검사는 정직하게 예 라고 답합니다위험이 검사가 보지 않는 곳에 놓이는 바로 그 순간에. 같은 모양이 협력사 스크립트에서, 스토리지 슬롯에서, 모델 로딩에서, 이제 기업 구조에서 나타난다는 것경계 프레이밍이 코드 밖으로 일반화된다는 가장 강한 증거입니다.

구체적 피해는 특정적이고, 이 목록의 카드 두 장에 그대로 떨어집니다. stablecoin-redemption-desk스테이블코인의 분모를 실제로 만드는 것은 스트레스 상황에서 액면가로 환매하는 데스크라고 하고, arb-bots-are-the-peg아무도 페그를 운영하지 않으며 경쟁하는 봇들이 곧 메커니즘이라고 합니다. 둘 다 독립성에 의존합니다. 수직 계열화 아래서는 환매 데스크가 그룹 자체의 트레이딩 부문일 수 있고 차익거래자가 계열사일 수 있습니다. 그러면 페그를 붙들기로 되어 있는 두 메커니즘을, 그 실패를 드러내야 할 바로 그 당사자가 돌리고 있는 것입니다. 페그는 여전히 유지됩니다 — 다만 더 이상 아무것의 증거도 아닙니다. "이해상충"보다 정확한 피해 진술이고, 지분 구조도만으로 확인 가능합니다.

그 문단을 읽는 방식에 대한 정정 하나. 우리 상황에 들어맞는 문장을 보면 저자가 의도한 것인지 묻고 싶어지는데, 그 직감은 거꾸로입니다. 우연히 들어맞는 일반 원리가 겨냥된 원리보다 더 쓸모 있습니다패턴이 여러 법역에서 반복된다는 뜻이고, 처방이 다른 곳에서 이미 시도됐다는 뜻이니까요. 국제 비교 브리프에서 국내적 의도를 읽어내는 것fork-date-provenance 가 막으려는 것과 같은 오류입니다: 주장의 쓸모는 그것이 무엇을 말하고 무엇에 근거하는가에서 오지, 누구를 겨눴다고 내가 생각하는가에서 오지 않습니다.

동작 방식

같은 규제, 두 구조

은행 발행자 비은행 발행자
감독의 단위 그룹(연결) 법인
활동 X 를 자매회사로 이전 여전히 감독 대상 규제 밖으로 나감
그래서 활동 규제는 묶음 미끄러짐
규칙이 겨냥한 대상이었나 아니오

마지막 두 줄이 문제의 전부입니다. 겨냥하지 않은 쪽만 묶는 규제는 규제가 없는 것보다 나쁩니다준수하는 구조를 시장에서 가격으로 밀어내기까지 하니까요.

기능 여섯, 그리고 경계가 실제로 덮는 것

기능 왜 하중을 받나 보통 발행자 안에 있나
발행 규제되는 행위 그 자체
준비금 운용 청구권이 무엇으로 뒷받침되는지 결정 자주 자매회사
준비금 수탁 누가 그것을 움직일 수 있는지 결정 외부, 때로 계열
주 거래장 가격이 관측되는 곳 자주 계열
해당 페어 마켓메이킹 arb-bots-are-the-peg — 이것이 곧 페그 자주 계열
환매 데스크 stablecoin-redemption-desk — 이것이 곧 분모 자주 계열

하중을 받고, 계열이며, 경계 밖인 줄을 셉니다. 그 개수가 이 카드의 숫자이고, 규제기관이 아니라 공개된 지분 기록으로 구할 수 있습니다.

왜 수직 계열화가 구체적 피해인가

이 목록에서 스테이블코인을 정직하게 유지한다고 보는 메커니즘 둘은 모두 독립성 논증입니다:

  1. 환매 데스크 — 스트레스 상황에서 액면가를 지급해 분모를 실재하게
  2. 경쟁하는 차익거래자아무도 혼자 운영하지 않으므로 페그가 실재

한 그룹 아래서는 둘이 같은 당사자일 수 있습니다. 페그는 여전히 유지되고, 증거이기를 멈춥니다눈에 보이게 깨진 페그보다 나쁩니다. 깨진 페그는 정보이고, 만들어진 페그는 아니기 때문입니다.

같은 모양, 네 도메인

어디서 그어진 경계 무엇이 넘었나
프론트엔드 (third-party-blast-radius) "우리 사이트" 인가된 협력사의 스크립트
컨트랙트 (storage-collision-admin-takeover) "각 모듈이 자기 상태 소유" 공유된 스토리지 슬롯
모델 로딩 (huggingface-is-a-package-manager) "가중치를 불러온다" 실행되는 저장소 코드
규제 (여기) "발행자" 그룹

the-boundary-is-the-unit경계 질문이 이전된다고 주장했습니다. 이것이 소프트웨어 밖에서의 그 시험이고, 통과합니다.

← 전체 개발 노트 · 워크스페이스 인덱스 · 맨 위 ↑