25 min

Herstatt, the danger of paying first

A currency trade has two halves, and if you deliver yours before the other side fails to deliver theirs your loss is total; this settlement risk is named after a bank that died mid-trade in 1974.

Where you are. Nine lessons have priced the border crossing in fees, spread and days. A payment hops the correspondent relay, waits on cutoffs and compliance holds, draws on pre-funded nostros, pays a toll hidden inside the exchange rate, and the cost stack falls hardest on the smallest payments. All of that assumed everyone survives the trip. Module 2’s batch rail left a warning behind: between clearing and settlement, a payment is a promise, and promises can fail. Domestically that exposure was a footnote, softened by cutoffs, netting and a rulebook. This lesson carries it across the border, where the gap between a trade’s two halves is hours wide, no authority spans the two ledgers, and the cost of a failure in the gap is not a fee or a spread but everything. One bank’s death in 1974 gave that cost its name.

Mid-afternoon in Cologne

26 June 1974, mid-afternoon in Cologne. The German banking supervisor closes Bankhaus Herstatt, a mid-sized bank with an outsized appetite for currency trading. Banks fail; the system is built for that. What made this failure famous is the clock. Through that German morning, banks around the world had paid Deutsche Marks into Herstatt: their halves of that day’s currency trades, settled and final on the German books. Herstatt’s halves ran the other way, in dollars, and dollars settle in New York, hours behind. When the supervisor acted, the marks were long gone and the dollars had not yet moved. By New York’s morning, the world’s banks had all made the same discovery: the money they had paid was final, the money they were owed was never coming, and nothing in between had protected them. The risk was as old as time zones. Now it had a name.

the fatal gap: one leg settled, one leg due Frankfurt where the marks settle New York where the dollars settle DM leg settles morning, and it is final Herstatt closed mid-afternoon in Cologne, morning in New York dollar leg never paid due hours later, New York afternoon
The 1974 timeline: the Deutsche Mark leg settles in Frankfurt's morning, Herstatt is closed mid-afternoon, and the dollar leg due in New York is never paid; the shaded gap between the legs is the exposure

Wider than the screen; scroll it sideways.

The idea in one paragraph

An FX trade is two payments on two ledgers that share nothing. Each leg settles in its own currency’s world, on its own rail, in its own business day, and the business days of Frankfurt and New York, or New York and Tokyo, do not overlap, so one side always delivers first. From the moment your leg settles to the moment theirs does, you have made an unsecured loan to your counterparty, sized at the full principal, secured by nothing but their continued existence. Fail inside that window and the loss is not the profit on the trade; it is the trade’s entire value. This lesson’s exercise reproduces the exact shape on your own ledgers: the dollar leg settles, the failure is injected into the gap, the yen leg never comes, and the loss asserts equal to the full principal, to the digit.

One trade, two sovereign ledgers

The exercise restages 1974 with the module’s own cast. Alder, in New York, sells 1,000 dollars to Kiri, in Tokyo, for 150,000 yen: stylised numbers at a round rate of 150, so every diff reads at sight. Lesson 1 drew the map this trade must cross: two closed ledger worlds with no edge between them. The only bridges are lesson 4’s nostro accounts. Kiri keeps a dollar account at Alder; Alder keeps a yen account at Kiri. So “Alder pays dollars” is a posting entirely inside the dollar world, alder-fx-desk down 1,000 and kiri-nostro up 1,000, both deposits at Alder. And “Kiri pays yen” would be a posting entirely inside the yen world: kiri-fx-desk down 150,000, alder-nostro up 150,000.

Now the clock. The exercise pins the legs to minutes on New York’s wall: the dollar leg settles at minute 540, nine in the morning; the yen leg is due at minute 1140, seven in the evening, when Tokyo’s books open. Ten hours apart, chosen by no one. The gap is the geometry of the planet, and it means one side always pays first. Today it is Alder.

The gap is an unsecured loan

Between minute 540 and minute 1140, Alder holds nothing but Kiri’s word. You have met this exposure before: module 2’s batch rail held every bank cleared-but-not-settled until the batch landed. It is worth being precise about what crossing the border makes worse. Domestically, the gap was a design choice: a cutoff the rulebook sets, exposure sized at each bank’s net, and a clearing house able to pull a failed member’s payments and rerun the arithmetic, with the central bank standing at the end of the day. Across the border, every one of those softeners is missing. The gap is set by time zones, not by a timetable anyone can shorten. The exposure is gross: the full principal of everything paid and not yet paid back. And no authority spans the two ledgers; the central bank behind the dollars has no claim on Kiri, and the one behind the yen owes Alder nothing. When the promise breaks, there is no arithmetic to rerun. There is an estate, and a queue.

What the ledger sees, and what it cannot

The exercise’s failure is a line of nothing. At minute 700, Kiri is closed by its supervisor, and the honest way to put that on a ledger is to post nothing at all: failure is not an entry, it is the entry that never comes. The dollar world does not flinch. The 1,000 dollars sit exactly where settlement put them, in kiri-nostro at Alder, and that is the cruellest line in the exercise: the money never left the building. But lesson 4 taught you whose money a nostro is. That account is Kiri’s asset, so those dollars now belong to Kiri’s estate, and Alder queues behind every other creditor for whatever fraction crawls back, years from now. Lost does not mean vanished. It means no longer yours.

Then both worlds pass assert_world(). Sit with that for a moment. The dollar ledger balances; the yen ledger balances; every invariant module 1 built holds everywhere. The loss is real, and the harness measures it at the full principal, but it is a position of Alder’s, not an imbalance of any ledger. Double entry conserves each world’s internal truth, and settlement risk lives exactly where no invariant reaches: in the hours between two sovereign ledgers that share no books, no authority and no undo.

Review

One trade, two sovereign ledgers

A currency trade is two payments on two ledgers that share nothing. Each leg settles in its own currency’s world, on its own rail, in its own business day, and the business days of Frankfurt and New York, or New York and Tokyo, do not overlap. So one side always delivers first, and which side that is was chosen by no one. In the worked example the dollar leg settles at nine in the morning on New York’s clock and the yen leg is not due until seven in the evening, when Tokyo’s books open. Ten hours apart. The gap is the geometry of the planet, not a defect in anybody’s system, and no amount of care inside either ledger closes it.

The gap is an unsecured loan

From the moment your leg settles to the moment theirs does, you have made an unsecured loan to your counterparty, sized at the full principal, secured by nothing but their continued existence. Fail inside that window and the loss is not the profit on the trade. It is the trade’s entire value. That is what makes this different from ordinary credit risk: you are not exposed to the difference between what you expected and what you got, you are exposed to everything you sent. The exercise reproduces the exact shape on your own ledgers, injecting the failure into the gap, and the loss asserts equal to the full principal, to the digit.

Check yourself

1. The failure is injected as the absence of a posting. Why is that the honest model?

Because on a ledger, a failure is not an event you record; it is a scheduled posting that never happens. Kiri’s supervisor stops the bank, and the yen world simply never sees the payment: no submit, no settle, nothing. Meanwhile the dollar leg is final, and module 1 was firm that finality has no undo button, so neither world contains any entry that could mean “give it back”. Death is silence, and the silence is the loss.

2. The loss asserts to 1,000 dollars, the full principal. What would Alder have lost if Kiri had failed at minute 500, before the dollar leg?

Only the trade, not the money. Alder re-deals with another bank at the current rate, and the loss is the price move since the original deal: a spread-sized number, possibly even a gain. Principal risk exists only inside the window that opens when you pay and closes when you are paid. Before the window, a counterparty failure is market risk; inside it, the entire notional is on the table.

3. Alder’s 1,000 dollars still exist, sitting in kiri-nostro at Alder itself. The money never left the building, so why is it lost?

Because the account is Kiri’s, not Alder’s. Lesson 4 defined the nostro from the holder’s side: it is the holder’s asset, wherever it is kept. The balance is Kiri’s property and passes to Kiri’s estate, and Alder becomes one unsecured creditor among many, waiting years for a fraction. Lost means no longer yours, not vanished; the ledger location of the money is irrelevant to who owns the claim.

4. Both assert_world() calls pass at the end of the run. What does that tell you about where settlement risk lives?

That it lives between the ledgers, not inside either one. Each world’s double entry balances perfectly through the whole episode, because the loss is a position of Alder’s, not a bookkeeping error. No invariant spans the two worlds, and no single authority does either. That is why the cure cannot be a better ledger on either side; it has to be a mechanism that binds the two legs together, which is the next lesson’s subject.

5. Module 2’s batch rail also carried exposure until the batch landed. Name two ways the FX gap is worse.

The size and the backstop. Domestic netting sized each bank’s exposure at its net difference; the FX gap is gross, the full principal of every paid leg. And the domestic batch ran under one rulebook with one central bank behind it, able to pull a failed member’s payments and rerun the netting; between currency worlds no shared authority exists, so a failure leaves an estate and a creditors’ queue instead of a rerun. The gap is also structural, set by time zones rather than by a cutoff anyone could move.

Do this

Fifteen minutes, from module-03-across-borders. Open code/herstatt.py. build_zones is written: two closed worlds bridged only by nostro deposits, each desk endowed with twice the principal so nothing today fails for want of funds. Your work is the failure injection in run_timeline, three scheduled moments in the TODO(you). At minute 540, settle the dollar leg: submit and settle 1,000 dollars from alder-fx-desk to kiri-nostro, both at Alder, in the usd world, and record the event. At minute 700, record that Kiri fails, and post nothing, because on a ledger death is silence. At minute 1140, record that the yen leg never settles, touching the jpy world not at all. Return the three events in minute order and let the harness do the measuring.

python3 code/herstatt.py

Green is exactly this, ending with the final line verbatim:

FX trade: Alder sells 1000 dollars to Kiri for 150000 yen
minute  540  dollar leg settles: 1000 dollars into kiri-nostro at Alder
minute  700  KIRI FAILS - closed by its supervisor, mid-trade  <-- the failure
minute 1140  yen leg due: NEVER SETTLES - alder-nostro at Kiri stays at zero
loss to Alder: 1000 dollars of 1000 principal
pay first across a border and a failure between the legs costs the full principal - not a margin, the whole payment

If the yen assert fires with alder-nostro above zero, you posted into the yen world: you resurrected Kiri to pay a debt its estate owes, and the temptation to record the failure as an entry is exactly the instinct this lesson exists to correct. If dollars_paid comes up zero, you submitted without settling; module 1’s two-phase discipline again, and the dollar leg must be final for the loss to be real. The completed version is solutions/herstatt.py; compare after you are green.

What you can now do. You can reproduce the failure that named a risk: two ledgers, one trade, one death in the gap, and a loss you measured rather than imagined - the full principal, with both worlds in perfect balance while it happens. You can say precisely where the risk lives, in the hours between two sovereign ledgers that no invariant and no authority spans, and why the paid leg’s finality is what makes the loss total. What you cannot yet do is prevent it. The only promise that removes the risk is binding the two legs together, both or neither, and nothing you have built can make that promise. The next lesson names the family of constructs that do, and lesson 12 visits the machine the industry built to keep the promise at planetary scale.

What you can now do

You can reproduce the 1974 failure that named cross-currency settlement risk and measure the loss precisely.