Back to Blog
RWA by Priya Chandrasekaran

RWA Tokenization and the Compliance Gaps Nobody Is Talking About

On-chain ownership records and off-chain custodian records do not automatically agree. The compliance gap between them is where the real reconciliation work happens, and most tokenization projects skip it entirely.

RWA Tokenization and the Compliance Gaps Nobody Is Talking About

The tokenization of real-world assets has moved faster than the back-office infrastructure required to support it compliantly. Issuance platforms have gotten good at creating token representations of real estate, private credit, infrastructure, and other illiquid assets. The on-chain mechanics work. What has not kept pace is the reconciliation and compliance layer that connects on-chain ownership records to the off-chain systems where regulatory reporting, tax accounting, and fiduciary oversight actually happen.

This gap is not theoretical. It is a practical problem for any institutional back-office team that holds tokenized positions. The gap manifests in specific, concrete ways that this post will describe in detail. We are not arguing that tokenization is wrong for institutional portfolios. We are pointing to the compliance infrastructure work that the tokenization conversations tend to skip over.

The On-Chain / Off-Chain Record Divergence Problem

A tokenized real estate position held by an institutional investor exists in two record systems simultaneously. On chain, the token represents ownership and the blockchain maintains a ledger of token holders and transfers. Off chain, the traditional custody and fund administration infrastructure maintains its own ownership record based on DTC settlement, fund register entries, or custody agreements depending on the structure.

These two records do not automatically agree, and when they disagree, neither system automatically knows it. The on-chain record reflects what the blockchain has confirmed. The off-chain record reflects what the custodian or fund administrator has processed. A token transfer that occurs on chain does not trigger an update to the custodian's off-chain record until a reconciliation process explicitly compares the two and reconciles any differences.

For traditional securities, this gap is closed by the DTC settlement process, which serves as the authoritative reconciliation mechanism between broker records and custody records. For tokenized assets settled directly on chain with no DTC involvement, no equivalent central reconciliation mechanism exists. The reconciliation responsibility falls to the institutional holder, who must operate a process that continuously compares on-chain state to off-chain records and resolves any divergences.

Most institutional holders of tokenized positions do not have this process. They have custody statements for their traditional holdings and a separate, largely manual process for tracking their token positions. These two streams are not reconciled against each other in any systematic way at the positions level.

The Regulatory Reporting Exposure

The regulatory reporting implications of the on-chain / off-chain gap are significant. SEC ownership reporting requirements, including Schedule 13D and 13G, attach to beneficial ownership based on the total economic interest in an issuer. If a beneficial owner holds both traditional securities and tokenized interests in the same underlying issuer, the reporting threshold applies to the combined position. If the combined position is tracked in two separate record systems that are not reconciled, the threshold calculation may be wrong.

Under Rule 17a-4, required record-keeping for broker-dealers includes records of securities positions, which the SEC has interpreted to include tokenized securities positions held on behalf of customers. A broker-dealer that holds tokenized positions for institutional clients and relies only on blockchain state as the ownership record, without maintaining a separate off-chain record that meets the rule's format and retention requirements, has a compliance gap with direct enforcement risk.

CFTC reporting for derivatives linked to tokenized assets creates a parallel issue. If the reporting basis is the on-chain token ownership and the on-chain record does not match the off-chain derivatives position records, the reported data may not be internally consistent. CFTC examination of derivatives reporting has historically focused on exactly this type of internal consistency failure.

Corporate Actions on Tokenized Assets: The Infrastructure Is Not Ready

Corporate action processing is where the compliance gap in tokenized asset infrastructure is sharpest and least discussed. For traditional securities, corporate action events are managed by custodians through a well-established process: the issuer notifies DTC, DTC distributes to custodians, custodians notify and process for their clients. The process is slow and expensive, but it is systematic and its outcomes are reconcilable.

For tokenized assets, there is no equivalent systematic process. When a tokenized real estate fund makes a distribution, the mechanism for ensuring that every token holder's off-chain custody record is updated to reflect the distribution depends on the specific platform, the custody arrangement, and whatever bespoke process was set up at issuance. In many cases, the process is: the issuer notifies holders via email, holders update their internal records manually, and the on-chain distribution event is never formally reconciled against the off-chain distribution records.

This is a problem that token issuance platforms have largely not solved. They have built the issuance and transfer mechanics. They have not built the corporate action notification infrastructure, the custodian notification protocols, or the reconciliation tools that institutional compliance requires for these events. The institutions that hold tokenized positions have inherited the work of building those processes themselves.

The Missing AML / KYC Layer at Transfer

For traditional securities transfers, broker-dealers and custodians maintain AML and KYC records on counterparties as a standard operating procedure embedded in the settlement infrastructure. For peer-to-peer token transfers executed on chain, the settlement infrastructure does not include those controls. The transfer completes on chain without any AML screening or KYC verification at the point of transfer.

Institutional holders who receive token transfers on chain without applying off-chain AML / KYC screening to the transferring party may find themselves holding a position transferred from a counterparty that would not have passed a standard screening. The fact that the transfer was facilitated by a smart contract rather than a broker does not change the underlying compliance obligation for the receiving institution.

This is not a hypothetical risk. It is a specific operational gap in how tokenized asset transfers are processed at most institutions, and it is one that requires explicit attention during the custody and compliance workflow design phase of any tokenized asset program.

What Compliant Tokenized Asset Infrastructure Actually Requires

We are not saying that tokenized assets cannot be held compliantly. They can. But doing it correctly requires specific infrastructure that most tokenization platforms do not provide and most institutional holders have not built.

At minimum, a compliant institutional tokenized asset program requires: a systematic on-chain / off-chain reconciliation process that runs continuously, not just at month end; a custody arrangement that maintains off-chain records in a format satisfying applicable retention and format requirements; a corporate action notification process that translates on-chain events into off-chain record updates for all holders; and AML / KYC screening applied at every transfer event, on chain or off chain.

The challenge is that each of these requirements involves work that sits outside the scope of what most token issuance platforms deliver. The institution ends up building the reconciliation, custody interface, corporate action, and AML layers independently. That is not necessarily wrong. But it needs to be done explicitly, not assumed away on the grounds that the token platform handles it.

How to Evaluate a Tokenized Asset Program for Compliance Readiness

For compliance teams evaluating whether their institution's tokenized asset holdings are in defensible shape, the checklist questions are straightforward. Does the institution maintain an off-chain position record for every tokenized holding that satisfies the applicable format and retention requirements? Is there a documented reconciliation process that compares on-chain and off-chain records on a defined schedule? How are corporate action events on tokenized assets captured and processed into off-chain records? Is AML / KYC screening applied at the point of transfer, and is the screening documented?

If the answers to any of these are unclear or rely on processes that exist as informal practices rather than documented procedures, the program has compliance exposure that needs to be addressed before the portfolio grows. The infrastructure gaps described here tend to become more consequential, not less, as the scale of tokenized holdings increases.

See OpenAssets in practice

Request early access to see how the platform handles your specific custody structure and reconciliation workflow.

Request Early Access

More from the OpenAssets Blog