Tokenization Economics Lab
Make the economics of tokenization defensible.
The technical question is largely answered. The economic one is not: where value is created, what it costs to get there, how much of it the ledger is actually responsible for, and which participant ends up keeping it.
The Lab is a shared vocabulary for those questions and a disciplined way to build one institution’s case with it — against a real baseline, with the evidence attached, and with a result a board can interrogate line by line rather than take on trust.
The method
Four columns, one boundary, and the honest question in the middle.
A case holds the same initiative four ways. The columns share one system boundary and one cast of participants, so a benefit cannot appear because somebody moved the line.
How it works today
The current process, measured or reconstructed from actuals. The starting point, and deliberately not the benchmark.
Best conventional alternative
What the same outcome would cost with an API, a workflow redesign and better data. This is the column that decides whether tokenization earned its place, and it is the one almost every business case leaves out.
Tokenized, as planned
The design at its intended operating point. A plan, and labelled as one — a target cannot carry a realised claim however confident it is.
Tokenized, as measured
What it actually does once it runs. The only column that can support a realised number, and the one that usually arrives smaller than the plan.
Discipline
The useful part is what it will not let you say.
A fee is not value created
Every economic flow has a payer and a recipient. A fee between two parties inside the boundary cancels — one party's revenue is the other's cost, and the system as a whole is no better off. The consolidated result is calculated twice by independent routes, and the two must agree before anything is shown.
A benefit with no bearer cannot be entered
Not validated afterwards — inexpressible. There are exactly two things you can record: a transfer, which always has both ends, and a resource effect, which always has exactly one bearer. There is no third shape for a benefit that nobody pays for.
You cannot promote your own baseline
The baseline class is assigned from what the case can actually evidence: measured side by side, your own history adjusted, a validated process model, or a general estimate. It is not a setting, and a class D baseline never reaches a peer comparison at any sample size.
Faster settlement costs you netting
Released prefunding and destroyed netting happen together, so they are one calculation. A liquidity benefit reported without the netting it gave up is half an answer, and the engine says so on the figure rather than in a footnote.
One exposure cannot fund three benefits
The same reduction in settlement exposure can plausibly be told as a capital benefit, a liquidity benefit and a fall in expected loss. Each is defensible alone; together they triple-count one fact. The case has to declare whether they share an underlying exposure.
Weak evidence does not move the number
It changes what the number may be used for. Pulling an uncertain figure toward a neutral middle would make a bad case look average, which is the opposite of the point. Quality sits beside the economics and governs use, never value.
Attribution
How much of it was the ledger?
Almost every tokenization programme also digitises something, redesigns a workflow, standardises a data format and changes its volume mix — all at once. Each of those would have produced some of the same improvement on its own.
So the observed difference is allocated across eight mutually exclusive drivers that must sum to a hundred, and the result is reported three ways: everything that changed, what the transformation caused by any route, and what needed the ledger. The third is nearly always the smallest, and publishing it honestly is the most useful thing this exercise does. Anything nobody can allocate is carried as unallocated rather than scaled away — a case that has attributed sixty percent should look like one.
The eight drivers
The ledger itself
Effects that need a shared ledger or programmability and could not be obtained any other way.
Ordinary digitisation
Replacing paper and manual keying. Real, valuable, and available without any of this.
Redesigning the process
Removing steps and approvals. Often the largest single driver, and frequently credited to technology that merely provided the occasion.
Standardising data
A common format or message. Most of the interoperability benefit usually lives here rather than in the ledger.
A change in the rules
A regulation moved, and would have had this effect regardless of the platform.
Volume, product or client mix
You are doing more, or a different mix. Unit economics move without anything improving.
Rates and the wider economy
Liquidity and funding benefits are especially sensitive to this.
Something else, named
Naming it is the point. 'Other' with no explanation is not an allocation.
The dictionary
14 domains, 47 metrics, 23 of them required.
Open in full, free, no account.
Anything expressed per unit of something carries its denominator, because “cost per transaction” is not a number until it says whether it counts transactions initiated, accepted or actually settled. Two institutions using different answers cannot be compared, and usually do not notice.
47 of 47
Completed transactions
TE.VOL.TXN.COUNTTransactions that finished successfully in the period, on the stated denominator basis.
The denominator for most unit economics. Whether it counts what was attempted or what actually settled changes every per-unit figure downstream.
RequiredDepends on the caseper transaction settled
Transaction notional
TE.VOL.NOTIONALTotal value transacted in the period.
Scales fee income and settlement exposure. Rising notional is not adoption if it rose because prices did.
RequiredDepends on the case
Assets outstanding
TE.VOL.ASSETS_OUTSTANDINGValue held on the platform at the measurement date.
The base most servicing and custody fees are charged on.
RequiredHigher is better
Active clients
TE.VOL.ACTIVE_CLIENTSClients meeting a stated minimum activity in the period. The threshold is part of the number, not a note beside it.
Onboarded is not active. Most disappointing adoption figures are the gap between the two, and the gap is the finding.
RequiredHigher is betterper active client
Repeat transaction rate
TE.VOL.REPEAT_RATEShare of active clients who transacted more than once in the period.
The cheapest test of whether the thing works. One transaction can be a favour; the second is a decision.
Higher is better
Secondary turnover
TE.VOL.SECONDARY_TURNOVERSecondary volume as a share of assets outstanding, per period.
Where the liquidity claim is tested. Primary issuance efficiency implies nothing at all about this.
Higher is better
Incremental revenue
TE.REV.TOTAL_INCREMENTALRevenue that would not have been earned without this initiative.
The only revenue that belongs in the business case. Revenue that moved across from the legacy product belongs in the line below.
RequiredHigher is better
Cannibalised revenue
TE.REV.CANNIBALIZEDExisting revenue lost or displaced because this initiative exists.
Subtracted, always. A case that reports incremental revenue without it is reporting gross where it means net.
RequiredLower is better
Fee yield
TE.REV.FEE_YIELDFees earned divided by the relevant notional or assets outstanding.
Makes fee levels comparable across very different sizes. Retrospective only, and never shared identifiably.
Calculated, never typedDepends on the caseper million of notionalper million of AUM
TE.REV.TOTAL_INCREMENTAL / TE.VOL.NOTIONAL * 10000
Contribution margin
TE.REV.CONTRIBUTION_MARGINNet revenue less the variable cost of producing it.
The numerator of breakeven. Without it, the volume threshold cannot be calculated at all.
RequiredCalculated, never typedHigher is better
(TE.REV.TOTAL_INCREMENTAL - TE.REV.CANNIBALIZED) - TE.COST.RECURRING.TOTAL
One-off implementation cost
TE.COST.FIXED.INITIALEverything spent to reach production: build, integration, legal, licensing, assurance, change.
The number payback is measured against, and the one most often quoted before integration is finished.
RequiredLower is betterOne-off, not recurring
Legacy coexistence cost
TE.COST.FIXED.DUAL_RUNThe cost of running the old process alongside the new one, per period, until the old one is switched off.
Frequently the largest number in the model and the one most often missing. A saving that depends on decommissioning is not a saving until decommissioning is funded and scheduled.
RequiredLower is better
Recurring operating cost
TE.COST.RECURRING.TOTALEverything it costs to keep running for a period: people, technology, vendors, network, compliance, support.
The run rate. Pilots understate it whenever exceptional manual support is doing part of the work.
RequiredLower is better
Cost per completed transaction
TE.COST.UNIT.TRANSACTIONRecurring operating cost divided by transactions on the declared denominator basis.
Meaningless without the denominator and without utilisation beside it: a low unit cost at 10 percent of capacity is an artefact of the divisor.
RequiredCalculated, never typedLower is betterper transaction settledper transaction acceptedper transaction initiated
TE.COST.RECURRING.TOTAL / TE.VOL.TXN.COUNT
Cost per active client
TE.COST.UNIT.CLIENTRecurring operating cost divided by active clients on the declared activity threshold.
The right denominator when the business is a relationship rather than a flow.
Calculated, never typedLower is betterper active client
TE.COST.RECURRING.TOTAL / TE.VOL.ACTIVE_CLIENTS
End-to-end cycle time
TE.OPS.END_TO_END_TIMEElapsed time from trigger to completion, across the whole in-scope process.
Only becomes economic once it changes funding, exposure or headcount. Speed on its own is a fact, not a benefit.
RequiredLower is better
Straight-through-processing rate
TE.OPS.STP_RATEShare of items completing with no manual intervention.
The cleanest predictor of unit cost, and the number a well-automated legacy process already scores well on.
RequiredHigher is better
Manual touches
TE.OPS.MANUAL_TOUCHESHuman interventions per transaction.
Where pilot economics quietly diverge from production economics.
Lower is betterper transaction settled
Exception rate
TE.OPS.EXCEPTION_RATEShare of items requiring investigation or repair.
Exceptions cost far more per item than the happy path, and they rarely disappear on a new rail.
RequiredLower is better
Failed settlement or process rate
TE.OPS.FAIL_RATEShare of items that did not complete.
Drives both cost and counterparty exposure, and is the number counterparties ask for first.
Lower is better
Mean recovery time
TE.OPS.RECOVERY_TIMEAverage time to restore normal service after a failure.
What a resilience claim means in practice, and what a client actually experiences.
Lower is better
Required prefunding
TE.LIQ.PREFUNDINGCash that must be in place before the process can run.
The headline liquidity benefit — and the one that must always be reported alongside the netting it gave up.
RequiredLower is better
Peak intraday liquidity
TE.LIQ.INTRADAY_PEAKThe largest funded balance required at any point in the day.
What the treasury actually has to provide for. Averages hide the constraint that binds.
Lower is better
Average idle balance
TE.LIQ.IDLE_BALANCECash sitting available but unused across the period.
Carries an opportunity cost every day it sits there.
Lower is better
Liquidity funding cost
TE.LIQ.FUNDING_COSTThe cost of funding the balances the in-scope process requires, over the period.
Converts a balance into a number the business case can use. Rate-sensitive, so the basis must be stated.
RequiredLower is better
Value of netting gained or lost
TE.LIQ.NETTING_CHANGEThe change in netting benefit, signed: positive when netting improves, negative when it is given up.
Gross settlement releases prefunding and destroys netting. A liquidity benefit reported without this line is half an answer, and the engine treats it as one.
RequiredHigher is better
Risk-weighted-asset change
TE.CAP.RWA_CHANGEChange in risk-weighted assets attributable to the in-scope process.
Real, and dependent on a supervisory view somebody has to actually hold. Store it as modelled until they do.
Lower is better
Capital charge
TE.CAP.CAPITAL_CHARGECost of the capital the in-scope process consumes, per period.
Must not double count against liquidity or expected loss — the engine checks the overlap explicitly.
RequiredLower is better
Collateral posted
TE.COL.POSTEDValue of collateral posted against in-scope obligations.
Encumbered assets are unavailable for anything else, which is a cost even when it is not a charge.
Depends on the case
Effective haircut
TE.COL.HAIRCUTAverage discount applied to posted collateral.
Decides how much has to be posted for a given exposure.
Lower is better
Time to mobilise collateral
TE.COL.MOBILIZATION_TIMEElapsed time from decision to collateral being usable where it is needed.
One of the few places a shared ledger can pay for itself outright, because the delay is the entire product.
Lower is better
Eligible collateral reuse rate
TE.COL.REUSE_RATEShare of eligible collateral reused within permitted limits.
Higher is better only inside the controls. Outside them it is leverage wearing an efficiency label.
Higher is better
Expected loss
TE.RISK.EXPECTED_LOSSProbability-weighted loss from in-scope operational, settlement and technology risk, per period.
Enters the risk-adjusted result exactly once. Where there is no loss history, use a transparent range and accept the lower evidence grade rather than inventing a point.
RequiredLower is better
Service downtime
TE.RISK.DOWNTIMETime the service was unavailable during the period.
A 24/7 promise is a 24/7 cost. This is where the difference shows.
Lower is better
Key-control coverage
TE.RISK.CONTROL_COVERAGEShare of identified key controls that are implemented and tested.
Risk that moved to a bridge, an oracle or a key is not risk removed. This is where the relocation becomes visible.
Higher is better
Client onboarding time
TE.CLIENT.ONBOARD_TIMEElapsed time from first contact to a client able to transact.
The friction that decides how many of the eligible ever become active.
Lower is better
Minimum economical ticket
TE.CLIENT.MIN_TICKETThe smallest transaction that is worth processing.
Where an access claim is settled. If this does not fall, nothing was opened to anybody new.
Lower is better
Service availability window
TE.CLIENT.AVAILABILITYHours per week the service can actually be used.
Extending it is a genuine client benefit and a genuine staffing, liquidity and incident-response cost.
Higher is better
Bid-ask spread
TE.MKT.SPREADAverage quoted spread on the in-scope instrument.
Test whether it survives without a subsidised market maker before treating it as a durable improvement.
Lower is better
Concentration index
TE.MKT.CONCENTRATIONHow concentrated activity is among participants.
High concentration flatters volume figures and is a fragility. It also blocks a peer result from being published.
Depends on the case
Point-to-point integrations
TE.INT.INTEGRATIONSNumber of bespoke integrations required for the stated coverage.
Usually the largest single driver of the fixed cost, and it scales with the network rather than with volume.
RequiredLower is better
Reused integration components
TE.INT.REUSE_RATEShare of integration work reused from earlier initiatives.
Decides whether the second use case is cheap or costs the same as the first. Claimed often, measured rarely.
Higher is better
Time to launch or replicate
TE.STR.TIME_TO_MARKETElapsed time to bring this, or the next one like it, to market.
The clearest measure of the option a platform actually bought.
Lower is better
Critical partner concentration
TE.STR.PARTNER_DEPENDENCYHow concentrated the initiative is on partners it cannot replace.
A dependency is a price you have not been quoted yet.
Lower is better
Required-field coverage
TE.EVD.COVERAGEShare of the required metrics that carry a value or a reasoned exclusion.
A case can be precise and incomplete. This is the number that says which, and it is derived so it cannot be talked up.
RequiredCalculated, never typedHigher is better
answered_required / total_required * 100
Evidence quality
TE.EVD.QUALITYWeighted score across evidence reliability, comparability, completeness, reproducibility, reconciliation, recency and independence.
Governs whether an observation can ever enter a peer distribution. It never changes the economic value itself — a weak case must look weak, not average.
RequiredCalculated, never typedHigher is better
see quality.ts — weighted components with hard caps
Result confidence
TE.EVD.CONFIDENCEHow much weight the calculated result can bear, from 0 to 1.
Reported beside the result, never folded into it. A result can be economically precise and poorly comparable, or comparable and internally uncertain; those are two different problems.
RequiredCalculated, never typedHigher is better
f(TE.EVD.COVERAGE, TE.EVD.QUALITY, dispersion)
Taxonomy version 1.0.0. Every calculated result is stamped with the version that produced it, so a figure signed off today can be re-derived under the rules that produced it rather than under a later set.
Scope
What this is not.
Not a benchmark, yet
Confidential peer comparison is coming, and it is the reason the evidence discipline is built the way it is. For now the Lab is worth using with nobody else on it: the case you build is for your own decision, and nothing you enter is pooled, compared or published.
Not a vendor comparison
It measures what an initiative does economically, not which platform is best. Vendor estimates enter as class D evidence — usable for orienting a discussion, never as the basis for a decision.
Not advice
Nothing produced here is legal, regulatory, accounting or investment advice. It is an instrument for making an internal argument legible to the people who have to approve it.
Build your own
One institution, one initiative, one case a board can argue with.
The workspace is part of the Institute’s member programme. Your organisation gets a private workspace, seats for the people who have to fill it in, a review step so nobody approves their own numbers, and an export that carries its working. Nothing you enter is pooled, compared or published — there is nothing to pool it into.