The quiet redistribution nobody sees
It is late afternoon in the back office of a mid-sized bank. You are watching a payment instruction sit unexecuted on a screen, the kind of screen nobody outside this building will ever see. The counterparty on the other end of that trade expected funds by end of day. They did not arrive. In a bilateral world, that is a clean, loud problem: two parties, one dispute, one phone call. But inside a wholesale interbank netting system, the geometry of who owes whom has already been collapsed into a single net figure for each participant. The failure does not announce itself the same way. It disperses.
That dispersal is the subject worth understanding. Not the failure itself. The architecture.
Specifically, the architecture that decides, silently and mechanically, which surviving banks absorb the shortfall and which ones never feel it at all.
What netting actually does to the web of obligations
Start with the basic mechanism. On any given settlement day, Bank A might owe Bank B $400 million across forty separate trades, while Bank B simultaneously owes Bank A $370 million across thirty-five others. Bilateral netting collapses that to a single $30 million obligation from A to B. Multilateral netting goes further: it pulls every participant's obligations together into a single net debit or net credit position against a central counterparty or settlement agent. A bank that owes $1.2 billion gross across dozens of counterparties might net down to a $90 million obligation. The compression is dramatic, sometimes exceeding 95% in high-volume systems like CLS (Continuous Linked Settlement), which handles foreign exchange settlement across major currencies.
That compression is the whole point. It reduces the liquidity each participant needs to post, reduces credit exposure, and reduces the operational burden of moving money. It works beautifully, like a suspension bridge that is elegant precisely because you cannot see the tension in the cables, until one participant cannot fund their net debit position.
What happens then depends entirely on the loss-sharing rules baked into the system's rulebook, and those rules are not uniform across systems.
The architecture of blame: survivors' funds and loss allocation waterfalls
Most central counterparty clearing systems (CCPs) and large-value netting systems maintain what is called a default waterfall: a ranked sequence of financial resources that absorb a defaulting member's shortfall before the loss reaches surviving participants. The defaulter's own posted margin or collateral goes first. Then a dedicated default fund, built from contributions by all members. Then, in some systems, the CCP's own capital. Only after those layers are exhausted does the loss reach surviving members through an assessment or loss-allocation mechanism.
But the geometry of multilateral netting means the loss is not distributed evenly across survivors. It flows toward whoever had the largest net credit position against the defaulter before netting was applied.
Consider a worked example with invented but realistic figures. Three banks: Northgate, Meridian, and Calloway, all members of a netting system. Gross obligations before netting run like this: Northgate owes Meridian $500 million, owes Calloway $200 million. Meridian owes Northgate $480 million, owes Calloway $150 million. Calloway owes Northgate $190 million, owes Meridian $130 million. After multilateral netting, Northgate's net position is roughly flat. Meridian ends up as a net creditor: it is owed more than it owes. Calloway is also a net creditor, but smaller. Now Northgate fails to fund its net debit. The system's default fund absorbs what it can. Whatever remains falls disproportionately on Meridian, because Meridian held the largest net claim that was dependent on Northgate's payment arriving. Calloway, whose gross exposure to Northgate was smaller and whose net position reflects that, takes a smaller hit. A fourth bank that happened to owe Northgate on a gross basis, and whose net position was already a debit, feels almost nothing.
This is the silent redistribution. No one chose it. It is the arithmetic consequence of netting combined with the default waterfall's exhaustion.
The difference between a debit cap and a credit cap, and why it matters more than most people realize
Systems protect themselves from this asymmetric exposure through position limits, and the design of those limits shapes the distribution of silent loss significantly.
A debit cap limits how large a net debit position any single participant can accumulate, capping the maximum loss a defaulter can impose on the system. CLS operates with short position limits on each currency leg, effectively constraining how much any member can owe at settlement time.
A credit cap is less common but more important. It limits how large a net credit position a participant can hold. This sounds counterintuitive: why would a system limit what you are owed? Because a very large net credit position means you are deeply dependent on the settlement of others' debits. Your liquidity plan for the afternoon assumes those payments arrive. If they do not, your own downstream obligations, payments to your own clients, repo settlements, bond purchases, are suddenly unfunded. You become a secondary failure. A system that omits the credit cap is choosing optimism over engineering, and that is a design decision with consequences that only become visible on the worst days.
Systems that use only debit caps protect against the size of any one default. Systems that pair them with credit caps protect against the concentration of exposure among survivors. The distinction matters enormously when a large member fails, because the post-default loss pool and the surviving members' dependency on incoming funds are two different risks, and they require different controls.
The role of settlement finality in deciding who can even complain
One underappreciated structural feature is the legal concept of settlement finality: the point at which a payment instruction becomes irrevocable. In systems with intraday finality, like Fedwire Funds in the United States or TARGET2 in the eurozone, each payment becomes final as it posts. There is no unwinding. If Bank A sends $200 million to Bank B at 10 a.m. and Bank A subsequently fails before end of day, Bank B keeps the $200 million. The loss falls on Bank A's creditors, not on Bank B.
In systems that batch net and settle at end of day, finality arrives later. If the failure occurs before settlement, the entire day's netting may be unwound, or "torn up," for the defaulting member, and surviving members' net positions are recalculated without the defaulter's trades. Call it loss allocation by position recalculation. It can dramatically shift who owes whom. A bank that thought it had a $50 million net credit, safely earned across a day's trading, suddenly discovers its recalculated position is a $30 million debit, because the trades with the defaulter have been stripped out. It now owes money it had not planned to pay.
This is the sharpest form of silent absorption. The bank did not fail. It followed every rule. And it still ends the day worse off than it started, through no action of its own, purely because of where it sat in the netting graph relative to the defaulter.
What people consistently misread about systemic contagion here
The standard narrative around bank failures and contagion focuses on direct credit exposure: Bank X lent money to Bank Y, Bank Y failed, Bank X has a hole. That story is real. But the netting-structure story is subtler and, in the judgment of anyone who has read the relevant Bank for International Settlements working papers carefully, considerably more dangerous, because it operates through operational dependency rather than credit exposure.
A bank might have zero direct credit exposure to a failing member. No loans, no bonds held, no derivatives. But if it was a net creditor in the netting cycle on the day of failure, it absorbs settlement loss regardless. And if that loss is large enough to impair its own liquidity position, it may delay or fail its own downstream payments, which impairs someone else's net credit position, which cascades. Stress tests conducted by central banks and regulators, documented in subsequent BIS working papers, consistently found that settlement interdependencies created contagion channels that pure balance-sheet analysis missed entirely. A bank that looked solvent on paper could become operationally impaired within hours, simply because the plumbing had seized.
Have you ever assumed that a bank's safety is purely a function of its own balance sheet? That assumption holds until the netting arithmetic turns against it on the wrong afternoon.
The real question is who designed the rulebook
Netting systems are not natural phenomena. Every feature of their architecture, the waterfall sequence, the debit and credit caps, the finality timing, the loss-allocation formula, reflects choices made by the system's governing body, often a consortium of the largest member banks themselves. Those members had interests when they wrote the rules. Large, systemically important participants tend to favor designs that limit their own assessment exposure in defaults. Smaller members, with less negotiating power, often absorb proportionally more through the loss-allocation formulas, even if their gross activity is modest. The history of financial infrastructure is, in no small part, a history of powerful incumbents encoding their preferences into the plumbing before anyone else arrived to object.
Regulators have pushed back on this through frameworks like the CPMI-IOSCO Principles for Financial Market Infrastructures, which set international standards for how default waterfalls should be sized and sequenced. But the fine-grained implementation remains largely in the hands of the systems themselves.
The quiet redistribution, then, is not purely mechanical. It is political. The architecture encodes decisions about whose exposure gets protected first, and those decisions were made in rooms that most of the banks affected by them never entered. Understanding that does not change the arithmetic on any given settlement day. What it does is explain why the arithmetic looks the way it does, and who, given a choice, made sure it looked that way.