Part 4 set out the rules that apply to stablecoin payments. Rules describe what a firm has to achieve. They do not, on their own, make it happen. Between the rule and the reality sits governance, which is how a firm organises its people, its decisions and its controls so that the rules are met every day and stay met.

This final part looks at how a firm actually runs stablecoin payments safely. It is the part that turns everything from the earlier parts into a working operation. In a business built on irreversibility, being genuinely in control before anything goes wrong is the whole point, because there is rarely a chance to fix things afterwards.

The three lines of defence

Most regulated financial firms organise their control of risk into three lines of defence, and it is a useful way to see how responsibility is shared.

The first line is the business itself, the people who run the day to day work and own the risk in what they do. The second line is the risk and compliance functions, who set the standards, watch over the first line and challenge it. The third line is internal audit, which checks independently that the whole arrangement actually works.

In stablecoin payments this structure matters even more than usual. When a single mistake with a key cannot be undone, a firm cannot depend on one person or one team getting everything right. The three lines make sure that risk is owned by the business, challenged by risk and compliance, and checked independently by audit.

The three lines of defence
1First lineThe business

The people who run the day to day work and own the risk in what they do.

2Second lineRisk & compliance

Sets the standards, watches over the first line and challenges it.

3Third lineInternal audit

Checks independently that the whole arrangement actually works.

No single person or team is relied on. Risk is owned by the business, challenged by risk and compliance, and checked independently by audit.

Risk ownership and risk appetite

A control that exists is not the same as a risk that is owned. Good governance gives every important risk a named owner who is accountable for managing it. When something goes wrong, there is then a clear line of responsibility and a clear person who was meant to be keeping it in check.

Alongside ownership sits risk appetite. A firm decides, on purpose and in advance, how much risk it is willing to accept and where its limits are. Decisions across the business then have to stay inside that appetite. This turns risk from something discussed after the fact into something chosen deliberately beforehand.

Key management governance

Because the private key is the money, the governance around keys is the most important control in the whole business. Part 3 explained the risk. This is how a firm holds it down in practice.

Keys are split so that no single person can move funds alone. Moving money requires several approvals from several people, so that no one individual holds that power by themselves. The person who requests a payment is kept separate from the person who approves it. Access to the keys is tightly limited and every use is logged. Each of these choices is made deliberately to match the irreversibility risk, so that neither a dishonest insider nor an attacker who takes over one account can move the money on their own.

Why this matters

The key is the money, so the controls around the key are the heart of the governance model. They are chosen to make sure no single person and no single failure can move funds that can never be recovered.

Third-party oversight under DORA

Much of the technology in this business is run by outside providers, from custody platforms to cloud services. DORA requires a firm to stay responsible for these providers even though the work is outsourced. In practice this means the firm has to know which providers support its important functions, assess them properly, keep the right to oversee them and to exit them if needed, and hold a clear register of these arrangements.

The principle underneath is simple and worth stating plainly. A firm can outsource the work to a provider, and it cannot outsource the responsibility. If a provider fails, the firm still answers for the service to its customers and to the regulator, so governance has to keep the firm in control of the providers it depends on.

Incident response and reporting

When something goes wrong, a firm needs a plan that is ready before the incident rather than written during it. The plan sets out who is called, what is contained first, how customers are protected, and how the event is reported to the regulator within the time the rules require.

In stablecoin payments this readiness matters more than in ordinary payments. Because value cannot be recovered once it moves, the speed and clarity of the response are often the only things that limit the damage. A firm that has rehearsed its response acts in minutes. A firm that has not loses time it does not have.

Board reporting and the tone from the top

The board and senior management are ultimately accountable for the business. For that accountability to mean anything, they have to understand the real risks, which means the reporting they receive has to be clear and honest. Good governance makes sure the board sees the true picture, including what is going wrong, rather than a comfortable version that hides the problems.

This is often described as the tone from the top. When senior leaders take risk seriously and ask for honest reporting, the rest of the firm follows. When they prefer reassurance, the controls weaken quietly over time. The behaviour at the top sets the standard for everyone below.

Pulling the model together

Governance is what separates a firm that happens to comply on paper from a firm that is genuinely in control. The rules from Part 4 set the destination. The three lines of defence, clear ownership and appetite, strong key controls, real oversight of providers, readiness for incidents, and honest reporting to the board are how a firm reaches that destination and stays there.

This is where the engineering and the governance meet. Understanding how the technology actually works, from the shared ledger to the keys, makes it possible to design controls that fit the real risk rather than controls that only look right on paper. In a business built on irreversibility, that fit is everything.

Governance elementWhat it doesThe risk it addresses
Three lines of defenceShares control across the business, risk and auditReliance on any single person or team
Risk ownership and appetiteNames an owner for each risk and sets limits in advanceRisks that no one is accountable for
Key management governanceSplits keys and approvals, separates and limits accessTheft or misuse of keys that cannot be reversed
Third-party oversightKeeps the firm responsible for its providersFailure of an outsourced provider
Incident responsePrepares a rehearsed plan before anything happensA slow or confused reaction to a live incident
Board reportingGives leaders an honest view of the real risksDecisions made on a false picture

The end of the series

That completes the series. We started with the technology, the shared ledger, the orchestration of value, and the movement between money and stablecoins. We saw why the market exists, by following one payment through SWIFT, SEPA Instant and a stablecoin. We looked at the new risks that appear once the middle is removed. We set out the rules that form the perimeter around the business. And we finished with the governance that turns those rules into something a firm can actually run.

The thread through all five parts is a single idea. Stablecoin payments remove the safety nets that ordinary payments were built around, and the work of this whole field is to rebuild those safety nets deliberately, through good technology, clear rules and strong governance.

Key takeaways

Governance turns rules into reality
The rules set the destination. Governance is how a firm reaches it and stays there.
Three lines, shared control
Risk is owned by the business, challenged by risk and compliance, and checked independently by audit.
The key is the money
Keys are split and approvals shared so that no single person and no single failure can move funds that cannot be recovered.
You cannot outsource responsibility
A firm can outsource the work to a provider, but it still answers for the service to its customers and its regulator.

A short glossary for this part

TermPlain meaning
Three lines of defenceA way of sharing control of risk across the business, the risk and compliance functions, and internal audit.
Risk appetiteHow much risk a firm decides in advance it is willing to take.
Segregation of dutiesKeeping the person who requests an action separate from the person who approves it.
Multi-party approvalRequiring several people to agree before money can move.
Register of informationA clear record of the outside providers a firm depends on.
Incident responseA prepared plan for acting quickly when something goes wrong.