Why
The sentence doing the work is an ordinary one about corporate structure, and it dissolves a whole class of rule. If a regime says an issuer may not do X, and X can be performed by a sister company owned by the same parent, then the restriction has been satisfied by a filing. Nothing about the exposure changed — the same balance sheet stands behind it, the same people decide, the same conflict exists — but the regulated entity is now clean. The rule was written against a box on an org chart, and org charts are cheap to redraw.
The asymmetry BIS names is the part that inverts the intent. Banks are already supervised on a consolidated basis: the group is the unit, so relocating an activity inside the group does not move it outside supervision. Non-banks are supervised entity by entity, so the same relocation works. That means an identical activity restriction binds the bank, which was already the safer case, and slides off the non-bank, which was the reason the restriction was written. A rule that is strictest where it is least needed is not merely ineffective; it is a subsidy to the structure it was aimed at, because the compliant path is available only to the party you were worried about.
This catalogue has a name for the move already, and it arrived from software. the-boundary-is-the-unit argues that the transferable question in security is never was this authorised but where is the boundary and what crosses it — and that the usual check fails because it returns yes at exactly the moment of the attack. This is the same failure in a regulatory register. The perimeter was drawn around the issuer. The group crosses it. And the compliance check returns yes, truthfully, at exactly the moment the risk is being held somewhere the check does not look. That the same shape shows up in vendor scripts, storage slots, model loading and now corporate structure is the strongest evidence available that the boundary framing generalises past code.
The concrete damage is specific, and it lands on two cards this catalogue already has. stablecoin-redemption-desk argues that what actually makes a stablecoin's denominator is the desk that redeems at par under stress, and arb-bots-are-the-peg argues that nobody operates the peg — competing bots are the mechanism. Both depend on independence. Under vertical integration the redemption desk can be the group's own trading arm and the arbitrageur can be the affiliate, so the two mechanisms that are supposed to hold the peg are being run by the party whose failure they are supposed to reveal. The peg is still maintained; it is just no longer evidence of anything. That is a more precise statement of the harm than "conflicts of interest", and it is checkable from an ownership diagram.
One correction to how the passage is being read. The natural instinct on seeing text that fits a local situation is to ask whether the authors meant it — and that instinct is backwards. A general principle that happens to fit is more useful than a targeted one, because it means the pattern recurs across jurisdictions and the remedies have been tried elsewhere. Reading local intent into an international comparative brief is the same error fork-date-provenance exists to prevent: a claim's usefulness comes from what it says and what it is based on, not from who you think it was aimed at.
How it works
The same restriction, two structures
| Bank issuer | Non-bank issuer | |
|---|---|---|
| Unit of supervision | The group (consolidated) | The entity |
| Move activity X to a sister company | Still supervised | Now outside the regime |
| So the activity restriction | Binds | Slides off |
| Which was the case the rule was written for | No | Yes |
The last two rows are the whole problem. A restriction that binds only the party it was not aimed at is worse than no restriction, because it also prices the compliant structure out of the market.
The six functions, and which ones the perimeter actually covers
| Function | Load-bearing because | Commonly inside the issuer? |
|---|---|---|
| Issuance | It is the regulated act | Yes |
| Reserve management | Decides what the claim is backed by | Often a sister entity |
| Custody of the reserve | Decides who can move it | Often external, sometimes affiliated |
| Primary trading venue | Where the price is observed | Frequently affiliated |
| Market making the pair | arb-bots-are-the-peg — this is the peg |
Frequently affiliated |
| Redemption desk | stablecoin-redemption-desk — this is the denominator |
Frequently affiliated |
Count the rows that are load-bearing and affiliated but outside the perimeter. That count is the card's number, and it is obtainable from public ownership records rather than from a regulator.
Why vertical integration is the specific harm
Two mechanisms in this catalogue are supposed to keep a stablecoin honest, and both are independence arguments:
- The redemption desk makes the denominator real by paying par under stress.
- Competing arbitrageurs make the peg real because no single party operates it.
Under one group both can be the same party. The peg still holds and stops being evidence — which is worse than a visibly broken peg, because a broken peg is information and a manufactured one is not.
The same shape, four domains
| Where | The perimeter drawn | What crossed it |
|---|---|---|
Frontend (third-party-blast-radius) |
"our site" | An authorised vendor's script |
Contract (storage-collision-admin-takeover) |
"each module owns its state" | A shared storage slot |
Model loading (huggingface-is-a-package-manager) |
"loading weights" | Repo code, executed |
| Regulation (here) | "the issuer" | The group |
the-boundary-is-the-unit claimed the boundary question transfers. This is the test of that claim outside software, and it passes.
Where it lands in Jayverse
- Verex: name the entity behind each function before trusting it. For any integration where a partner touches issuance, custody, market-making or redemption-like flows, list which legal or operational entity performs each function, and flag when the same party sits on both sides of a check meant to be independent.
- Token/Bridge: don't let the mint authority and the relayer be the same key held by the same party silently. The six-function test in this PoC applies to JYVE's bridge and market maker too — write down who controls minting, who provides liquidity, and whether they overlap.
- Auditor: draw the ownership diagram before publishing methodology. Before the Auditor row certifies a feed or a counterparty as independent, require a one-page ownership diagram showing which functions are affiliated, per this PoC's six-function table.
Key expressions
| Expression | 뜻 · 쓰이는 자리 |
|---|---|
| satisfied by a filing | 서류 제출만으로 충족되다 · 형식적 절차만으로 규정을 지킨 것처럼 되는 상황. "the restriction has been satisfied by a filing" |
| on a consolidated basis | 연결 기준으로 · 그룹 전체를 하나의 단위로 감독할 때. "supervised on a consolidated basis" |
| slide off | 슬쩍 벗어나다, 빠져나가다 · 규제 적용에서 은근슬쩍 제외될 때. "slides off the non-bank" |
| a subsidy to | ~에 대한 (의도치 않은) 혜택 · 규제가 특정 대상을 유리하게 만들 때. "a subsidy to the structure it was aimed at" |
| load-bearing | 핵심을 떠받치는, 없으면 무너지는 · 기능·논거가 전체 구조의 핵심일 때. "how many load-bearing functions are performed outside" |
| price out of the market | 비용 때문에 시장에서 밀려나게 하다 · 규제 비용이 특정 구조를 못 쓰게 만들 때. "it also prices the compliant structure out of the market" |
| that instinct is backwards | 그 직감은 거꾸로 된 것이다 · 흔한 직관이 사실은 틀렸을 때. "that instinct is backwards" |
| generalise past | ~을 넘어 일반화되다 · 어떤 원리가 원래 분야 밖에서도 성립할 때. "generalises past code" |
| checkable from | ~로부터 검증 가능한 · 공개 자료만으로 주장을 확인할 수 있을 때. "checkable from an ownership diagram" |
| vertical integration | 수직 계열화 · 한 그룹이 공급망의 여러 단계를 함께 소유할 때. "Why vertical integration is the specific harm" |
| BIS | 국제결제은행(Bank for International Settlements) · 은행 규제·감독 리서치를 내는 국제기구, 이 카드의 출처. "A BIS brief points out that activity restrictions reach" |
| FSI | 금융안정연구원(Financial Stability Institute) · BIS 산하 조직, 출처 문서를 발행한 곳. "Source: BIS FSI Briefs no. 33" |
| perimeter | 규제 경계(관할 범위) · 특정 규제 체계가 적용되는 범위의 경계선을 가리킬 때. "mark which entities sit inside the stablecoin regime's perimeter" |