Ripple Systems Payments Infrastructure Engineering
Position paper

The messaging layer always ships. The settlement layer is what doesn't.

Ripple Systems · Payments infrastructure engineering · Figures cited from Swift, the World Bank and the Financial Stability Board

The shape is recognisable

If you have been near a payments programme in the last decade, you can predict the sequence before it runs.

A programme is announced with a named executive sponsor and a two-year horizon. A pilot is stood up quickly — faster than anyone expected, which is taken as evidence that the hard part is behind them. A corridor is chosen: one currency pair, one counterparty, a handful of transactions a day, business hours only. It works. There is an internal demonstration and a slide showing settlement time falling from days to seconds.

Then the programme goes quiet. Not cancelled — cancelled would be a decision, and there is no decision on the table. It is rescoped to a narrower corridor. The sponsor moves to another division. The two-year horizon becomes three, and then stops being quoted. Eighteen months later the organisation is still, technically, live: the same daily volume it had at the end of the pilot, moved by the same four people, described in the annual report as a capability rather than as a business.

Nobody records this as a failure, because at no point did anything fail.

Three waves, one stall

The first wave was a messaging upgrade. Richer payment data, end-to-end tracking, harmonised formats. It has now largely happened: coexistence between the old and new formats for cross-border instructions ended in November 2025, with adoption reported at around 97% of in-scope traffic. That is a genuine achievement and it changed almost nothing about how money settles. The industry acquired better visibility into a process it had not altered.

The second wave was a distributed-ledger payments network, and it remains the most instructive case available. Several hundred financial institutions signed on. Most of them adopted only the messaging layer — addressing, tracking, status — and never adopted the settlement layer. The settlement layer was the part that required touching the core, the liquidity model and the reconciliation process. A large number of institutions signed a contract. A much smaller number changed how money moved.

The third wave is the one in front of you: settlement on public ledgers, tokenized deposits, and payment stablecoins that finalise in seconds at any hour. The technology is not in question this time. The XRP Ledger has been settling transactions continuously for over a decade at costs that make the correspondent chain look expensive. The question is the same question as the previous two waves — whether the settlement layer gets adopted, or only the part that is easy to bolt on.

A large number of institutions signed a contract. A much smaller number changed how money moved.

Where they actually stop

In every case the programme stops at the same boundary, and it is not a technical boundary. It is the transition from a corridor operated by people to a system operated by systems.

A pilot is a corridor operated by people. Somebody watches it. Somebody reconciles it at the end of the day, by hand or nearly by hand. Somebody is reachable when it breaks, and the volume is low enough that they can resolve a break by looking at it. This is not a small version of production. It is a different activity that produces a similar-looking result, and it succeeds for reasons that do not scale.

Production means the core posts without an operator. It means reconciliation runs on a schedule, and that when ledger state and core state disagree there is a documented path that resolves the break rather than a person who knows what to do. It means the system is available on Sunday at 2am, during the maintenance window, and during the week of the core upgrade. It means an end-to-end time with a measured worst case across every leg, including the legs owned by a correspondent and by a vendor.

Nobody stops a programme at that boundary. What happens instead is that the organisation discovers, one capability at a time, that crossing it requires work nobody costed — and each piece of that work joins a queue behind everything else already committed. The programme does not fail. It waits.

What is genuinely different this cycle

Two things, and they matter.

The first is that the deadlines are now external. The messaging migration was mandatory and it completed. The structured-address mandate follows in November 2026, and it is the more awkward of the two: it requires address data in a shape that most originating systems have never been asked to produce, which makes it an estate problem rather than a messaging problem. An organisation that treats it as a formatting exercise discovers the difference late.

The second is that the official sector has stopped being optimistic. The Financial Stability Board's five-year review of the G20 cross-border payments roadmap concluded that its targets are unlikely to be met by 2027, and named slow infrastructure upgrades and continued reliance on correspondent banking among the reasons. The global average cost of sending $200 across a border remains around 6%, against a target of 3%. The diagnosis is not that the technology is missing.

What is worse

The estates. The same batch posting, the same overnight cycle, the same Sunday maintenance window, the same end-of-day reconciliation that is a person rather than a process. The obligations are new. The systems being asked to carry them are the ones that were there for the previous two waves, plus a decade of accumulated integration around the edges.

And there is a function nobody has staffed. A ledger integration comes with an operations discipline attached to it: node topology and peering, storage growth, amendment tracking and testing, failover, an on-call rota, and instrumentation good enough to produce a timestamped account of an incident afterwards. None of that is difficult. All of it is unfamiliar, and it is routinely discovered after go-live rather than costed before it.

The part nobody costs

Ask a programme what it has budgeted for exception handling and the answer is usually a shrug. Returns, reversals, partial legs and stuck payments carry no volume at all until the day they carry everything, and an exception path that has never been used in anger is an assumption rather than a control.

The same is true of reconciliation. Every programme has one. Very few can describe, without a meeting, what happens on the morning ledger state and core state disagree — who is told, on what frequency the comparison runs, and which of the two is treated as authoritative while the break is open. At pilot volume the answer is a person, and the person is competent, so nothing goes wrong. That arrangement has a capacity limit and nobody knows what it is.

The recommendation is two questions

Before commissioning anything — from us or from anyone — ask these internally and pay attention to how the answers arrive.

Where does a ledger transaction enter your payment estate today, and who owns that interface? If the answer is a point-to-point integration somebody stood up for the pilot, the production question is already open, whoever ends up doing the work.

If ledger state and core state disagree tomorrow morning, who reconciles them, on what frequency, and what is the documented path for resolving the break? Most institutions find the answer is a person rather than a process. That holds at pilot volumes and stops holding shortly afterwards.

Neither question is about the ledger. Both are about everything the ledger has to be joined to. That is the whole argument, and it is why we build on that side of the boundary.

Where this leads

The twelve capabilities are the practical version of this paper: six of connecting a ledger to a payment estate, six of operating the result. They can be measured before anything is committed, built once the answer is known, or operated afterwards.

The twelve capabilities

Migration and adoption figures are Swift's, reported for the November 2025 CBPR+ cutover and the November 2026 structured-address mandate. Remittance cost figures are the World Bank's Remittance Prices Worldwide series. The roadmap assessment is the Financial Stability Board's consolidated progress report of October 2025. Confirm the current quarter's remittance figure before circulating this paper.