Skip to content
How a Trade MovesPart 9 of 12

SWIFT and the Custodian: The Shipping Label and the Warehouse

A national moving-and-storage company doesn't own a single truck or warehouse in most of the cities it serves. What it actually sells is trust in a piece of paperwork: when a mover in one city writes "this box is now the responsibility of the depot in another," every depot in the network honors that handoff instantly, because they all trust the identical paperwork format — not because they share a boss. But the depot that actually receives the box — the one that stores it, dusts it, and calls you six months later about a manufacturer's recall — is a completely different kind of organization from whoever wrote the label.

Markets split the same two jobs across two systems, and mixing them up is one of the more common — and more expensive — mistakes a requirement can make.

Two jobs, cleanly split

SWIFT is the shipping label. It never touches a single share or rupee — it's a message network, nothing more, and its entire job is carrying a verified instruction from one bank to another: "move this." The custodian is the warehouse. It's the institution actually holding the asset once it lands, and its job keeps running long after the trade is finished — collecting dividends, processing stock splits, handling proxy votes, chasing tax reclaims across borders.

SWIFT was built in 1973 by 239 banks across 15 countries specifically to replace unstructured telex messages with a standardized format everyone could trust without a phone call to confirm it. Today it's a member-owned Belgian cooperative connecting more than 11,500 institutions across upward of 200 countries, carrying somewhere near 60 million messages a day — and it still doesn't hold a single asset. It only ever tells someone else what to do with one.

Example 1: SWIFT is rewriting its own label, mid-flight

For decades, SWIFT's instructions traveled as MT messages — fixed-width, telex-era formats like MT103 for a payment or MT101 to initiate one. SWIFT is in the middle of replacing that entire format with ISO 20022, a richer, structured standard (its messages are called MX) that carries far more data per instruction, including the kind of detail regulators now expect for sanctions screening and fraud checks. This isn't a minor version bump — it's the biggest rewrite of the network's own language in its history, and it's happening in stages with hard deadlines.

The first deadline already passed: the coexistence period between the old and new formats ended on November 22, 2025. Since that date, core institution-to-institution payment messages — MT103, MT102, MT201, MT203 — are no longer accepted on SWIFT's network at all; every one of them now has to arrive as MX. The second deadline lands in less than two months from when this is being written: on November 14, 2026, MT101 — the message a corporate client uses to initiate a payment through its bank — loses its own coexistence window too, and free-text postal addresses stop being valid anywhere in the process; every address has to arrive as structured data instead. The shipping label itself is being redesigned while the trucks are still running.

Example 2: India keeps the custodian on a separate leash entirely

India draws an even sharper line between the two roles than most markets do. A custodian, registered under the SEBI (Custodian) Regulations, 1996, is a distinct, separately licensed entity from a depository participant — the intermediary behind NSDL or CDSL that handles the demat holdings of ordinary retail trades. Only 17 custodians are registered with SEBI at all, and they mostly serve foreign portfolio investors, mutual funds, and other institutional money rather than the retail flow depositories handle. A business analyst who treats "custodian" and "depository participant" as interchangeable in an Indian context is already describing the wrong system.

SEBI moved on the custodian side too, and recently. After a consultation in late 2024, the regulator's 2025 amendment to the Custodian Regulations raised the minimum net worth a custodian must hold — from ₹50 crore to ₹75 crore — and, for the first time, wrote a formal requirement for business continuity and disaster recovery planning directly into the rules governing who's allowed to hold India's institutional securities.

What happens when the warehouse itself fails

That last requirement wasn't written in the abstract. In August 2015, a failed software upgrade at SunGard — the vendor running the fund-accounting system BNY Mellon, the world's largest custodian bank, relied on to calculate daily fund prices — crashed outright. For several days, BNY Mellon couldn't produce a valid net asset value for hundreds of the funds in its custody; Morningstar counted as many as 796 funds left without a price at all, and at least one fund manager reported NAV errors exceeding 1% on the numbers that did come through, in the middle of an unusually volatile week for markets. Nobody stole anything and no message went missing — SWIFT's side of the chain worked fine throughout. The failure sat entirely inside the custodian's own ability to do the second half of its job: not moving the asset, but correctly knowing and reporting what it was worth.

That is precisely the category of risk SEBI's 2025 rule is aimed at closing before it happens in India, rather than after.

Reality check: one layer is being modernized, the other can't be

It's worth being precise about what each of these developments actually changes. ISO 20022 makes the shipping label richer and more standardized — it doesn't touch who's allowed to write one, or what happens after a box arrives. SEBI's higher net-worth bar and disaster-recovery mandate make an Indian custodian failure less likely — they don't, and can't, eliminate the deeper asymmetry: SWIFT is a pure messaging network and, structurally, cannot suffer a BNY-Mellon-style failure, because it never holds anything to get wrong in the first place. A custodian can, because holding and servicing the actual asset is the entire point of the job. Better paperwork and stronger balance sheets both help. Neither one turns a warehouse into something that, definitionally, cannot break.

Why this matters for a Business Analyst

Back to the shipping label and the warehouse

A reconciliation break between a firm's own trade records and a custodian statement is a shipping-label-versus-warehouse problem before it's anything else. If the mismatch traces back to an instruction that never fully processed, that's a SWIFT-layer question — a message that failed, was rejected, or arrived malformed. If it traces back to a dividend, split, or corporate action the trade system never captured, that's purely a custodian-layer question — nothing ever went wrong with a message, because no message was ever supposed to carry that information in the first place. A ticket that says "investigate the reconciliation break" without first asking which of those two layers is actually implicated sends whoever picks it up looking for a lost package in a warehouse that never lost anything — or vice versa.

Lighthouse Insight

Right now, two systems that most people have never had to tell apart are both mid-rewrite at once, on opposite sides of the world, for opposite reasons. SWIFT is redesigning the shipping label itself, with its next deadline weeks away. India's regulator just made the warehouse itself sturdier, in direct response to a warehouse that once failed on the other side of the planet. Neither rewrite changes the one fact underneath both of them: the label and the warehouse were never the same thing, and never will be.

Reference anchors

Continue the system

A curated path through the next concept, so one essay becomes a map.

Related essays

Capital Markets

Market Data: The Broadcast Delay Nobody Else Can See

The price on a retail screen and the price a trading firm's algorithm sees aren't the same feed arriving at the same time — they never have been.

The price on a retail screen and the price a trading firm's algorithm sees aren't the same feed arriving at the same time — they never have been. The SIP versus proprietary direct feeds, the SEC's still-unfinished 2020 rewrite of who gets to run the tape, NSE's colocation-only tick data and the Supreme Court settlement that only closed the book on its own version of the gap two weeks before this was written, and the 38 miles of coiled fiber IEX built to blunt it.

Surya · 7 min read

Capital Markets

The Matching Engine: The Algorithm That Turns Two Orders Into a Trade

Every 'trade executed' notification is one sentence of code deciding whose order counted first.

Every 'trade executed' notification is one sentence of code deciding whose order counted first. Price-time priority versus CME's pro-rata futures algorithms, NSE's pre-open equilibrium auction versus NYSE's human-assisted open, and what a 2015 NYSE halt and a 2021 NSE outage reveal about the systems the matching engine can't run without.

Surya · 8 min read

Capital Markets

OMS vs. EMS: The Permission Layer and the Tactics Layer

An Order Management System asks whether a trade is allowed to exist at all.

An Order Management System asks whether a trade is allowed to exist at all. An Execution Management System asks how to fill it without wrecking the price. Two systems, two clocks, two legal histories — from the 2010 Flash Crash to the SEC's 2026 proposal to tear up the rule that built the modern smart order router.

Surya · 7 min read