What Does Atomic Settlement Actually Change?
Atomic delivery-versus-payment is a settlement arrangement in which the security and the payment transfer together, so delivery occurs if and only if payment occurs and neither leg finalises unless both do. It eliminates principal risk — the Herstatt exposure where one party performs and the counterparty fails before performing — structurally rather than by mitigation. The BIS/CPMI classifies it as Model 1, atomic gross settlement, against Model 3 where both legs net before settling. The trade is explicit: atomic DvP typically increases prefunding needs and alters netting characteristics, because offsetting trades no longer reduce the cash a participant must have available. This guide covers what the mechanism removes, what it demands in exchange, whether netting can be rebuilt on tokenized rails, and where production deployments have reached.
TL;DR — Key Takeaways
- ✓The Mechanism: Delivery occurs if and only if payment occurs. Neither leg finalises unless both do — BIS/CPMI Model 1, atomic gross settlement.
- ✓What It Removes: Principal risk, the Herstatt exposure where one party performs and the counterparty fails before performing. Eliminated structurally, not mitigated.
- ✓What It Costs: Multilateral netting. Offsetting trades no longer reduce the requirement, so each trade must be funded gross rather than net.
- ✓The Net Effect: Credit exposure falls, intraday liquidity demand rises. Risk moves from intermediaries toward infrastructure, code and treasury funding.
- ✓The Fix Is Not Free: Netting can be recreated through orchestration layers or liquidity-saving mechanisms — but it has to be engineered rather than inherited.

Two Things Happen at Once, and Only One Is Advertised
Atomic delivery-versus-payment links the security and payment legs so that delivery occurs if and only if payment occurs. It eliminates principal risk outright. It also eliminates multilateral netting, and the second consequence arrives with the first whether or not anyone planned for it.
This is the most consequential mechanical fact about tokenized settlement and the one most often presented as pure upside. Atomic settlement is genuinely better on the dimension it addresses — principal risk is a real exposure that has caused real failures, and removing it structurally is a meaningful improvement over managing it. The question is what a market pays for that, and the answer is measured in prefunded cash.
Eliminating settlement lags and end-of-day netting shifts liquidity demands from discrete points to continuous real time: credit exposures decline but intraday liquidity needs increase, redistributing risk from intermediaries toward infrastructure and code.
— Analysis of atomic settlement in tokenized markets, 2026
“Redistributing risk” rather than removing it is the accurate framing, and it is the same conclusion the IMF reaches at the system level in its note on tokenized finance.
Three Settlement Models, One Trade-Off
The BIS/CPMI framework distinguishes three DvP models by what settles gross and what settles net. All three eliminate principal risk — that is what makes them DvP — and they differ in how much liquidity a participant must have available to achieve it.
| Model | How it settles | Liquidity requirement |
|---|---|---|
| Model 1 — atomic gross | Both legs settle in real time, trade by trade, all-or-none | Highest — every trade funded separately |
| Model 2 | Securities settle gross; funds net | Intermediate — cash benefits from netting |
| Model 3 — netted | Both legs net before settling simultaneously | Lowest — only net differences funded |
Key Insight
Existing markets did not choose Model 3 out of technological limitation. They chose it because funding every trade gross is expensive, and netting was the mechanism that made high-volume securities markets affordable to operate. Tokenization does not make Model 1 newly possible so much as newly convenient — atomic settlement on a shared ledger is the path of least resistance when both legs live in the same system. A market that adopts it by default rather than by decision has selected the most liquidity-intensive of three options without pricing the difference.
Principal Risk, and Why Removing It Matters
Principal risk is the exposure to losing the full value of a transaction rather than a movement in its price. It arises whenever one party performs before the other: the seller delivers securities, the buyer fails before paying, and the seller has lost the asset entirely rather than suffering a mark-to-market loss.
It is named Herstatt risk after the 1974 failure of Bankhaus Herstatt, which was closed by German regulators partway through a settlement day having received Deutsche Marks from counterparties who had not yet received their dollars. Decades of settlement infrastructure — DvP mechanisms, payment-versus-payment systems, central counterparties — exist substantially to prevent that scenario recurring.
Atomic settlement addresses it more completely than any of them, because it removes the interval rather than shortening it or insuring against it. There is no window during which one party has performed and the other has not, so the exposure has no moment in which to exist. That is a genuine structural improvement and the reason atomic DvP is worth the funding cost in the contexts where it is worth it.
The Netting Problem, Concretely
The BIS/CPMI observes that atomic DvP typically increases prefunding needs and alters netting characteristics compared with traditional batch processes. Under netted settlement, offsetting trades cancel before cash moves; under atomic gross settlement, they do not cancel at all.
Consider a dealer who buys 100 units of a security in the morning and sells 100 units in the afternoon. Under Model 3 the two obligations net, and the dealer funds approximately the price difference. Under Model 1 the dealer funds the full purchase when it settles and receives the full sale proceeds when that settles — two gross movements rather than one net one, with the cash tied up in between. Multiply that across a trading book and the intraday funding requirement is a different order of magnitude from the net exposure it supports.
| Consequence | What it means operationally |
|---|---|
| Prefunding rises | Cash must be in place before each trade settles, not at a day-end cut-off |
| Offsets stop helping | Buying and selling the same instrument funds twice rather than netting to zero |
| Timing becomes binding | A late incoming payment blocks an outgoing trade that would otherwise have netted |
| Treasury runs continuously | Intraday liquidity management becomes a real-time function, not a daily one |
| Fails fall | The genuine benefit — fewer settlement failures, because unfunded trades simply do not settle |
The last row is worth keeping in view. Fewer settlement fails is not a small benefit, and a trade that does not settle because it was unfunded is a cleaner outcome than one that half-settles and requires unwinding. The point is not that atomic settlement is worse but that its costs and benefits land on different desks — the risk function gains, the treasury function pays.
Rebuilding Netting on Tokenized Rails
Netting is not incompatible with tokenized settlement; it simply has to be constructed. If a market wants liquidity efficiency, it must recreate netting explicitly through orchestration layers, liquidity-saving mechanisms or pricing models — otherwise it gets fewer settlement fails alongside higher liquidity needs and more complex liquidity management.
Orchestration layers
A coordinating layer that batches and offsets obligations before submitting them for atomic settlement, reconstructing Model 3 economics on Model 1 infrastructure at the cost of reintroducing a coordinator.
Liquidity-saving mechanisms
Queuing and offsetting logic borrowed from real-time gross settlement payment systems, which faced this exact problem when they replaced netted payment systems decades ago.
Pricing the difference
Charging participants for the liquidity their settlement pattern consumes, so the choice between gross and netted settlement is made on economics rather than by default.
Hybrid models
Model 2 exists precisely because netting the cash leg while settling securities gross captures much of the liquidity benefit without recreating the full batch cycle.
The first option carries an irony worth noticing. An orchestration layer that batches and offsets obligations before settlement is, functionally, a clearing house — the intermediary tokenization was supposed to remove, reintroduced because the function it performed turned out to be load-bearing.
Where This Stands in Production, and When to Use It
On 15 July 2026 the DTCC reported converting DTC-held securities into tokenised representations and processing production tokenised trades — US Treasury and repo DvP trades, and equity DvP trades — in a multi-firm exercise. Central counterparties, depositories, payment systems and cross-border platforms are increasingly experimenting with tokenization to achieve atomic settlement and continuous processing.
Atomic DvP fits
- Large-value, low-frequency transactions
- Cross-border trades where principal risk is acute
- Bilateral settlement without a shared CCP
- Collateral movements needing immediate finality
Netting still wins
- High-frequency trading books with heavy offsets
- Markets where funding cost dominates
- Flows already covered by a CCP
- Anywhere intraday liquidity is scarce
Where it breaks
- Treasury funded for net, not gross exposure
- Cash leg on a different ledger from the asset
- Prefunding assumed rather than arranged
- Settlement asset unavailable out of hours
The second item in the third column is the practical failure mode. Atomicity only holds if both legs sit where a single transaction can bind them; a cash leg on another system reintroduces the gap the design was meant to close, and the arrangement becomes conventional DvP with extra steps. That is also why the US approach kept T+1 settlement through DTC rather than pursuing atomic settlement, as covered in how tokenized stocks trade on Nasdaq.
How Blockmaze Fits Atomic Settlement
Atomic settlement raises a compliance problem alongside the funding one. If both legs settle in a single indivisible transaction, every eligibility and restriction check has to complete before that transaction executes — there is no post-settlement window in which to detect a problem and unwind it.
Checks Complete Pre-Execution
Eligibility and transfer restrictions resolve before the atomic transaction executes, so a non-compliant transfer never settles rather than settling and requiring reversal.
Encumbrance Checked at the Leg
Whether a position is already pledged is evaluated as part of the settlement decision, so the same asset cannot be delivered into two atomic transactions.
Settlement Asset Recorded
Which instrument formed the cash leg is retained against the transaction, so exposure to a settlement asset is measurable rather than an operational assumption.
Finality Basis Retained
What established finality for a given settlement is recorded, since atomic execution answers the operational question and not the legal one.
The last point is the boundary. Atomic execution guarantees that both legs moved together; it does not establish that the recipient holds an enforceable right, which depends on the authoritative record rather than the transaction — the distinction developed in when a tokenized transfer is actually final.
Designing for Atomic Settlement?
Blockmaze provides the compliance layer that completes eligibility and encumbrance checks before an atomic transaction executes, and records the settlement asset and finality basis against every trade.
Frequently Asked Questions
What is atomic delivery-versus-payment?
A settlement arrangement in which the security and the payment transfer together, so that delivery occurs if and only if payment occurs — neither leg finalises unless both do. The BIS/CPMI framework calls this Model 1, atomic gross settlement, where both legs settle in real time, trade by trade, on an all-or-none basis. Tokenization makes it straightforward when both the asset and the cash leg exist on a single platform, because the transfer of both can be conditioned on the same transaction succeeding.
What risk does it eliminate?
Principal risk, also called Herstatt risk after the 1974 failure of a German bank mid-settlement. It is the exposure where one party delivers and the counterparty fails before delivering the other leg, leaving the first party out the full value rather than merely a market movement. Atomic DvP eliminates it structurally rather than mitigating it: if the transaction cannot complete both legs, it completes neither, so there is no interval during which one party has performed and the other has not.
What does atomic settlement cost?
Netting. The BIS/CPMI notes that atomic DvP typically increases prefunding needs and alters netting characteristics compared with traditional batch processes. Under Model 3, both legs net before settling, so a firm with offsetting trades funds only the net difference. Under atomic gross settlement each trade executes independently, so offsetting positions do not reduce the requirement — a firm buying and selling the same security in a day must fund both sides separately rather than netting to approximately nothing.
How large is the netting effect?
Large enough that it is the reason netted settlement exists. Multilateral netting in conventional securities markets reduces gross obligations to a small fraction of their face value, which is precisely why central counterparties and batch cycles were built. Removing it does not increase the total value transacted; it increases the cash that must be available at the moment of each transaction. The result, as one analysis puts it, is fewer settlement fails but higher liquidity needs and more complex liquidity management.
Can netting be recreated on tokenized rails?
Yes, but it has to be built deliberately. If a market wants liquidity efficiency it must recreate netting explicitly through orchestration layers, liquidity-saving mechanisms or pricing models. That means the choice is not between atomic settlement and netted settlement so much as between netting that comes free with the legacy infrastructure and netting that must be engineered on top of a tokenized platform. Programmes that adopt atomic DvP without addressing this discover the funding requirement in production.
Has atomic DvP been done at production scale?
It is starting to be. On 15 July 2026 the DTCC reported converting DTC-held securities into tokenised representations and processing production tokenised trades, including US Treasury and repo DvP trades and equity DvP trades, in a multi-firm exercise. Central counterparties, central securities depositories, payment systems and cross-border settlement platforms are increasingly experimenting with tokenization to achieve atomic settlement and continuous processing — which is a different maturity level from the pilots of previous years.
Related Articles
What Does the IMF Say About Tokenized Finance Risk?
The macro version of the same trade-off — continuous settlement and the liquidity frameworks built for discrete cycles.
When Is a Tokenized Transfer Actually Final?
Why operational finality and legal finality resolve at different moments.
How Does the DTCC Tokenization Pilot Work?
The depository-anchored model behind the production tokenized DvP trades.
How Do Tokenized Stocks Trade on Nasdaq?
An approval that deliberately kept T+1 settlement rather than pursuing atomic DvP.