Concept demos · Digital Money

Putting the tokenised payment side to work inside HSBC

The Tokenised Deposit Service already moves money 24/7. These two demos propose ways to make it more useful.

Left: what the client sees

A handful of plain milestones, a moving indicator and exactly where the money is at every moment — never a frozen screen.

Right: what the bank is doing

Every system touched, every stage that must pass before finality, and the audit trail being written as it happens.

Both driven by one engine

The two views read the same state, so they can never disagree. Use Pause to explain any stage mid-flight.

Demo 1 · Cash to asset

Keep the cash buffer invested, get it back at any hour

Money-market funds deal only on business days, so treasurers keep a precautionary buffer in plain deposits in case cash is needed when the fund is shut. Party A Holdings keeps its US$50m buffer in a tokenised share class instead. At 23:10 on a Sunday, Singapore's Monday payroll needs US$20m: the treasurer redeems units into tokenised deposits in seconds, as a single exchange of units for cash, and the rest stays invested.

≈ US$16kper weekend earned by keeping a US$50m buffer invested instead of idle, at a 4% yieldIllustrative: US$50,000,000 × 4% × 3 days (Fri–Mon) ÷ 365 = US$16,438, against a buffer earning close to nothing. Funds accrue interest on calendar days, so units already held at Friday's cut-off earn the weekend — round-the-clock redemption is what makes it safe to hold them. Subscribing at the weekend adds no yield: it starts on the next business day.

What the client sees

HSBCnet · Liquidity & Investments (mock)

Party A Holdings (HK)

Group treasury

Choose a scenario

Tokenised USD deposits

$12,400,000

USD money-market fund · tokenised units

50,000,000

What the bank is doing

Systems this touches · illustrative integration map

Client channel

HSBCnet / Treasury API

Where the treasurer or their ERP places the order

Client reporting & ERP feed

Contract note, API callback, statement

Controls

Entitlements & approvals

Who may deal, mandate limits, maker-checker

Financial crime screening

Sanctions, AML and PEP checks before value moves

HSBC Asset Management

Fund order management

Investor eligibility, dealing rules, concentration limits

Fund cash buffer

Tokenised deposits the fund holds to pay redemptions while markets are shut

NAV & pricing

Strikes the unit price the order settles at

HSBC Securities Services

Transfer agent & unit register

Issues, reserves and cancels fund units — the fund side

GPS · Digital Money

TDS ledger

Tokenised deposits: escrow and transfer — the payment side

Atomic settlement engine

Commits both sides together, or neither

Books of record

Core banking & general ledger

Deposit accounts and accounting entries

Reconciliation, audit & cases

Ledger, core and register must agree; exceptions get an owner

Stages before finality

  1. Choose a scenario to run.

Event log · immutable audit trail

  • Waiting for an instruction…

What HSBC already has

  • The Tokenised Deposit Service — a 24/7 tokenised payment side, live in six markets. HSBC
  • Tokenised fund infrastructure: HSBC is tokenisation agent, trustee and registrar for CSOP's tokenised HKD money-market ETF class (June 2026). Asia Asset Management
  • Its own money-market funds through HSBC Asset Management. HSBC AM
  • Market direction: the HKMA's EnsembleTX pilot made tokenised deposits settling tokenised money-market fund transactions its initial focus. HKMA

What is new

Joining the pieces. The payment side, the registrar capability and the funds exist separately; a treasurer on TDS cannot yet buy or sell an HSBC fund atomically, out of hours, with no settlement gap. This demo is that join — delivered entirely inside HSBC, with no external platform in the path.

It also rehearses the harder, larger prize: once the join works for HSBC's own funds, the same payment side can serve third-party funds on shared networks.

The hard parts

  • The fund, not the rail, sets the clock. Out-of-hours dealing needs a share class whose terms and pricing allow it, approved by the fund regulator.
  • The register must run 24/7 — transfer agency operations and exception handling included.
  • Legal finality of the exchange has to be confirmed per jurisdiction, not assumed from atomic settlement.
  • Who pays out while markets are shut. Weekend redemptions come from the fund's cash buffer, sized to expected demand. Beyond it, the realistic fallback is an HSBC loan to the investor secured on its units — many markets restrict a bank from propping up its own fund.
  • Fund liquidity rules — redemption limits, gates and fees — must be enforced in the flow, not after it.

Demo 2 · Cash to cash

Automated cash pooling on the 24/7 rail

At 02:15 on Monday, Singapore's payroll batch drops its balance below the floor the treasurer set. Nobody is awake, and nobody needs to be. The rule decides, the controls check, and the money moves — and when a top-up would breach the client's own daily cap, automation stops and a named person decides.

Why this is new: treasurers currently choose between automation and availability

Moves by rule?Moves any hour?What is missing
Conventional cash poolingYesNoSweeps run on scheduled cycles, usually end of day, bound by cut-offs and business days
Tokenised Deposit Service todayNoYesEvery movement still has to be spotted and instructed by a person or a client system
This proposalYesYesNothing on the rail — the new parts are the policy engine, the limits and the intercompany record

What the client sees

HSBCnet · Liquidity console (mock)

Party A Group · automated pooling

Floor $500,000 · top up to $2,000,000 · daily cap $3,000,000

Choose a scenario

Party A Holdings

Hong Kong · hub

$32,400,000

Party A Singapore

Singapore

$2,150,000

Party A UK

United Kingdom

$2,000,000

Automated sweeps today$0 / $3,000,000

What the bank is doing

Systems this touches · illustrative integration map

Client channel

HSBCnet liquidity console

Policy set-up, approvals and alerts

Client TMS / ERP

Receives positions and sweep events by API

GPS · Digital Money

Policy & mandate engine

Floors, targets, caps — decides when to move

TDS ledger

Reserve and atomic transfer between entity wallets

GPS · Liquidity Management

Real-time position service

Live balance per entity from TDS ledger and core

Pooling & interest allocation

Tracks intercompany positions and allocates interest

Controls

Entitlements & corridor register

Approved entities; corridors with legal sign-off

Limits & exposure service

Per-transfer limit, daily group cap, hub reserve

Financial crime screening

Intra-group flows are still screened

Books of record

Core banking & general ledger

Deposit accounts and accounting entries

Case management & audit

Owns anything held; immutable decision trail

Stages before finality

  1. Choose a scenario to run.

Event log · immutable audit trail

  • Waiting for an instruction…

What is new

  • A policy engine that turns balance events into funding decisions, so the trigger is a rule rather than a person.
  • Client-owned limits — per-transfer, daily group cap and hub reserve — enforced before anything is reserved.
  • An intercompany record for every sweep, so interest allocation and group accounting keep up with money that now moves at 2am.
  • A human exception path: the cap stops automation and routes a decision to a named checker, on the audit trail.

The hard parts

  • Tax and intercompany rules. Cross-border sweeps create intercompany loans; transfer pricing, and in some markets currency or pooling restrictions, decide which corridors are possible.
  • Legal finality per corridor — an unapproved corridor should be refused by the engine, not discovered later.
  • A misconfigured policy could drain the hub — hence the client cap, the reserved hub minimum and suspension after repeated triggers.
  • Always-on is a real operating cost — someone owns a held sweep at 5am.