Stablecoin payment orchestration layer: who holds the money in transit?

A payment orchestration platform for stablecoin payments, step by step: who holds the money at each stage, pre-funding or not, and 4 build paths.

Adrianna Szymańska-Krowiak
September 2026
Ask AI

Opens in a new tab with this page in the prompt

ChatGPTChatGPTGeminiGeminiPerplexityPerplexityCopilotCopilotClaudeClaudeGrokGrok

A payment orchestration platform is the software that sits between an institution's core systems and its payment providers and runs every payment as one controlled flow: which provider performs each step, in what order, under which controls, and how the result is reconciled. In stablecoin payments that flow crosses FIAT accounts, custody, compliance checks, an on-chain transfer and a payout, so the question that decides the architecture is simple: who holds the money, the keys and the client data while value moves.

NetiRails is software. The licence, the providers and the funds stay with the institution. This article shows what the platform does at each of seven steps, where the money sits, how the two liquidity models differ, and what you give up when the platform belongs to someone else.

What is a payment orchestration platform?

A payment orchestration platform coordinates several payment providers behind one control point, so the institution decides the route, the rules and the record of every payment instead of each provider deciding its own part. It holds the state of each payment from order to reconciliation and applies the same controls whatever provider sits underneath.

Solidgate describes the payment orchestration layer as "the software tier that sits above your PSPs and acquirers," written for e-commerce and subscription merchants. That definition holds, but the job changes when the providers are an on-ramp, a custodian, a KYT service and an off-ramp, and the operator is a licensed institution rather than a merchant.

Two layers make up stablecoin payment infrastructure:

  • Providers, each on the institution's own contract: KYC/KYT, custody, FX (the institution's dealing room or a provider), liquidity and on-ramp, and an off-ramp in the destination market.
  • The orchestration layer that connects them: control gates, a ledger, reconciliation and provider adapters.

NetiRails is a payment orchestration platform for licensed payment institutions, built from these components and deployed on the institution's own infrastructure. We described the engineering behind it in how a resilient orchestration architecture is built. A network such as Swift connects institutions to each other. NetiRails runs inside one of them, and we explain why that distinction matters in the next wave of stablecoins is the infrastructure around them. For the stablecoin-specific term, see stablecoin orchestration, defined.

Do you need a payment orchestration platform for stablecoin payments?

If you offer stablecoin payments to clients, yes: since stablecoin settlement moved into mainstream payment infrastructure in 2026, every institution that offers it manages more providers, more states per payment and more regulatory evidence than a single bank transfer ever required. Without one control point, each provider becomes its own silo with its own record.

Four moves in six months set the pace:

Your corporate clients will be offered these services this year, by someone. The open question is whose infrastructure they run on. For what the Swift ledger itself changes, see our breakdown of the new Swift blockchain ledger.

How does a payment orchestration platform run a stablecoin payment, step by step?

In seven steps, and at every one the platform records where the money is and who decided. We use a B2B payment to a supplier abroad as the worked example, because it touches every component.

  1. Order. The corporate client orders the payment in the institution's system. Money: on the client's account at the institution. Decides: the client.
  2. Controls. Sanctions screening, limits, operator approval and Travel Rule data run before value moves. Each step logs who, when, on what basis, with what result. Money: still at the institution. Decides: the institution, by its own thresholds.
  3. FX. Conversion in the institution's systems, on its credit lines, at its rates. Money: at the institution. Decides: the institution's dealing room.
  4. On-ramp. FIAT is converted to stablecoin at a provider the institution contracts directly. Money: with the institution's provider.
  5. Transfer. The stablecoin moves to the off-ramp provider in the destination market. Money: in transit, visible to the institution in real time.
  6. Off-ramp and payout. The stablecoin is converted to local currency at a provider the institution chose, then paid out by local transfer. Money: with the beneficiary.
  7. Reconciliation. Automatic matching in the institution's ledger, with reporting data in ISO 20022 fields. No new spreadsheet in the back office. Money: reconciled in the institution's ledger.

From step 4 onwards, the institution decides through its own contracts with on-ramp and off-ramp providers. Neti is not a party at any step. Keys sit in the institution's HSM, data stays in its infrastructure, and funds never touch Neti's accounts or balance sheet.

Reporting a stablecoin leg in ISO 20022 raises its own field-level questions. We mapped them event by event in ISO 20022 stablecoin payments, mapped.

What does the platform change for the institution?

It removes intermediaries whose fees and delays nobody controlled, and it prices every remaining step from a contract the institution negotiated itself. Speed, cost certainty and visibility follow from that structure, not from the token.

In the worked example, the traditional route runs through one or two correspondent banks and settles T+1 or T+2. The institution cannot see funds in transit, quotes an estimate instead of a final amount, and needs a new correspondent and months of agreements for every new market. The Financial Stability Board's 2025 progress report states that "it is unlikely that satisfactory improvements at the global level will be achieved in line with the 2027 Roadmap timetable."

  • Speed. NetiRails is designed for T+0 settlement, with funds reaching the beneficiary within 15 minutes of the order. The payment-status calls stop.
  • A cost known before the transaction. Six cost components remain: on-ramp, off-ramp, KYT, liquidity, the local payout and the NetiRails fee. Each is a price from a contract the institution negotiated. Correspondent fees, lifting fees and intermediary deductions disappear, because there are no correspondents.
  • The FX margin stays home. NetiRails is FX-agnostic: conversion runs in your systems, at your rates, so no provider competes with your dealing room.
  • A new market in weeks. A new currency path means connecting another provider and configuring the flow. The bottleneck is the rules of the path, not the technology.

Who holds the money if you rent the platform?

The operator does. With stablecoin infrastructure as a service, funds pass through the operator's balance sheet and its chosen custody and liquidity providers; when the institution runs its own payment orchestration platform, funds stay with the institution or with providers it contracts directly.

That is the difference hidden behind the four paths institutions usually weigh:

PathThe appealWhat you will not read on their websiteChanging the process later
Build in-houseFull controlIn our estimate, 12 to 18 months of learning and risk, a new security review, and a new team competing with the mandatory regulatory backlogPossible, with a team that first has to exist
Stablecoin infrastructure as a service (API operator, BaaS)Easiest to buy, live in weeksFunds pass through the operator's balance sheet. A per-flow fee is rent on someone else's infrastructure. Client flow data sits with the operator. Custody, FX and liquidity providers are theirs, FX margin included. Hosting outside the institution is an entry in your DORA register of information, with an exit plan you cannot execute without rebuilding the flowA request for the operator's roadmap: months, or never
Integrator or consultancyThe brand, and "we will build anything"Built from scratch, expensive and slow, and the team leaves after acceptanceA new project, a new quote, a new team
Stay on existing railsNo projectT+2, opaque cost, and the networks above are launching an alternative for your clientsNone. The process stays as it is
NetiRailsControl and speedThe platform runs inside the institution, on its licence, with its providers and its FX. Neti is not in the flow of fundsThe institution decides; the team that built the framework executes, without a maintenance window

The DORA point deserves precision. Article 28(8) requires financial entities to be able to exit ICT contracts supporting critical or important functions "without disruption to their business activities." If the platform itself lives in a vendor's cloud, that exit is a rebuild.

Do stablecoin payments require pre-funding?

No. The institution decides whether a flow runs on capital held upfront or on liquidity bought per transaction, and the platform runs both models as a configuration.

In correspondent banking, pre-funding means balances parked in nostro accounts, sized for peak and idle the rest of the time. Stablecoin payments give two options instead:

  • With pre-funding. The institution keeps a balance with its on-ramp or off-ramp provider and settles from it. At high, steady volume this is often cheaper.
  • Without pre-funding. Liquidity is sourced per transaction from a provider the institution contracts directly. The cost becomes variable, paid for completed payments, with no frozen capital. FIAT in, stablecoin in the middle, FIAT out: the pattern is often called a stablecoin sandwich.

You can switch when volume changes. The no-pre-funding model pays off when the cost of capital sized for peak exceeds the sum of per-transaction liquidity fees at your real volume, which is a calculation to run with your own numbers. NetiRails does not provide liquidity and is not a party to it in either model.

How do banks ensure regulatory compliance for stablecoin payments?

With control gates in the platform that fire before value moves and record their own evidence. The control is executed, not recommended, and the proof exists at the moment of the event.

Without this, every requirement (sanctions screening, Travel Rule, limits, operator approval) is described in a procedure, performed by a person, and evidenced after the fact. A new channel usually also means a new spreadsheet in the back office and someone reconciling it with the ledger.

In NetiRails, the gates are screening, limits, operator approval, hold, and Travel Rule data. Limit policy stays in the institution's system; NetiRails asks for permission and respects the answer. Sender and recipient data is attached to the transfer and passed to the institution on the other side, as required under Regulation (EU) 2023/1113, with EBA Travel Rule Guidelines applicable from 30 December 2024. Every step is written to an immutable, auditable ledger. The report for your supervisor is built from data, not reconstruction.

Which services can run on the same platform?

Any payment service that reuses the same gates, ledger, reconciliation and provider adapters. The supplier payment above is one flow; the next one is a workflow configuration and perhaps a new provider, not a new system.

  • Mass payouts, one-to-many with a digital leg and a single reconciliation
  • Conditional payments and escrow, with funds released on a defined condition such as delivery confirmation
  • Moving the institution's own funds on weekends and at night, between accounts, entities and providers
  • FIAT-stablecoin conversion offered as a service to the institution's clients

Security review, integration and provider onboarding happen once. An institution that launches one flow this year can offer conditional settlement and 24/7 treasury to corporate clients next year, on what it already runs.

What does an institution need to launch its first flow?

A licence or a path to one, providers in the flow, and five decisions. The platform, the sandbox and the delivery team come from us.

Licence. A credit institution does not need a full CASP application. Article 60(1) of MiCA lets it provide crypto-asset services if it notifies its competent authority "at least 40 working days before providing those services for the first time." Separately, the EBA has advised that transferring e-money tokens on behalf of clients may qualify as a payment service under PSD2, with the transition period ending on 2 March 2026. An alternative is running the ramp through an external licensed CASP. The legal decision belongs to the institution.

Five decisions:

  1. The first flow and market
  2. The liquidity model, with or without pre-funding
  3. Limit and threshold policy
  4. The off-ramp entity
  5. The SLA level: 8/5 if you run your own NOC, 24/7 if you do not

What we bring. This is how we run the first engagement with an institution. A sandbox simulates provider messages, so your team runs the full path without real money or signed contracts. One flow in one market is deployed within three months. Your side needs five roles, none of them full-time. Responsibility is split up front: Neti owns the software; the institution owns licences, providers, configuration, gates and the regulatory outcome; providers own their own services. Delivery is by the same in-house team of around 40 engineers that built the framework, with no subcontractor in the chain.

What NetiRails does not do

We do not hold client funds, at any step. We do not provide liquidity, and we are not a party to the on-ramp or off-ramp contracts. We do not take an FX margin. We do not hold a licence on your behalf, and we do not make the legal call on MiCA or PSD2; your counsel does. The 15-minute delivery target also depends on the off-ramp's local payment system in the destination market. And we do not yet know your first flow, your volume or your liquidity model. That is what the first conversation is for.

Talk to us about your first flow

Book a 45-minute review with Sławomir Paśko or Artur Kania through netirails.com/contact. Bring three numbers for the flow you have in mind: monthly volume and transaction count, whether usage is flat or peaky, and how much capital sits under it today. You leave with a view on which flow to start with and which liquidity model fits your volume.

FAQs

A payment orchestration platform is the software that sits between an institution's core systems and its payment providers and runs every payment as one controlled flow. It decides which provider performs each step, applies the same controls regardless of provider, holds the state of each payment, and reconciles the result in one ledger.

A payment gateway connects a payment to one processing route. A payment orchestration platform coordinates several providers behind one control point, choosing the route, enforcing controls and reconciling the outcome across all of them. In stablecoin payments those providers include on-ramps, custodians, KYT services and off-ramps, not only card processors.

A stablecoin payment runs in seven steps: order, compliance controls, FX, on-ramp from FIAT to stablecoin, on-chain transfer, off-ramp and local payout, and reconciliation. When the bank runs the payment orchestration platform on its own infrastructure and licence, funds stay with the bank or its contracted providers at every step, and the bank can see money in transit in real time.

It depends on who runs the payment orchestration platform. With stablecoin infrastructure as a service, funds typically pass through the operator's balance sheet and its chosen custody and liquidity providers. When the institution runs its own payment orchestration platform, funds sit with the institution or with providers it contracts directly, and keys stay in its HSM.

No. An institution can pre-fund a balance with its on-ramp or off-ramp provider, which is often cheaper at high and steady volume, or source liquidity per transaction, which turns the fixed cost of capital parked in nostro-style balances into a variable cost for completed payments. The choice is a configuration that can change when volume changes.

Not a full one. Under Article 60(1) of MiCA, a credit institution may provide crypto-asset services after notifying its home competent authority at least 40 working days before starting. The EBA has also advised that transferring e-money tokens on behalf of clients may qualify as a payment service under PSD2. The alternative is to run the ramp through an external licensed CASP, and the legal choice belongs to the institution.