Fault-Tolerant Architecture for Cross-Border Payment Systems Under Regulatory and Latency Constraints

Authors

  • Anath Bandhu Chatterjee Independent Researcher, India.

DOI:

https://doi.org/10.70917/ijcisim-2026-5717

Keywords:

Cross-border payments, fault tolerance, idempotency, at-most-once effect, saga, deterministic simulation testing, sanctions screening, DORA, distributed systems, formal verification

Abstract

Cross-border remittance systems operate across trust and legal boundaries in which no single control plane can commit an entire transaction atomically. One step, the disbursement to a receiver, is irreversible and takes place at a counterparty that cannot participate in a commit protocol. This paper contributes an architecture in which the payment intent is the durable append-only primitive, commit occurs before the irreversible act, and every recovery mechanism follows from that ordering. The paper's protocol contribution is the minting rule: a new external reference for a retry may be created only from a predecessor proven to be in a terminal-and-not-settled state; otherwise the retry must reuse the previous reference so that the partner's own deduplication converts at-least-once transport into at-most-once effect. Compliance is expressed as a state-transition precondition rather than as a middleware layer, so that no path to disbursement bypasses screening. Evidence for the architecture's guarantees is categorical, not statistical: three counts must be zero (duplicate settlements, releases without screening, payments without an intent record). The paper deliberately refuses production telemetry as the primary evidence base because rates cannot demonstrate absolutes. Correctness is established across three testing layers: exhaustive model checking of the specification, deterministic simulation of the implementation, and adversarial fault injection against per-capability-class partner simulators that include a partner that lies about settlement state. The paper argues that "at-most-once effect with eventual determination" is the strongest achievable guarantee at this boundary and should be adopted as the honest replacement for exactly-once framing that classical distributed-transaction literature carries into a setting where its assumptions do not hold

Downloads

Download data is not yet available.

Downloads

Published

2026-09-07

How to Cite

Anath Bandhu Chatterjee. (2026). Fault-Tolerant Architecture for Cross-Border Payment Systems Under Regulatory and Latency Constraints. International Journal of Computer Information Systems and Industrial Management Applications, 18(23s), 1625–1636. https://doi.org/10.70917/ijcisim-2026-5717

Issue

Section

Original Articles