
Tokenization is often described as a change to the asset. The more accurate description is narrower and more useful: tokenization changes the record of who owns the asset, and the asset carries on being what it was.
That distinction determines almost everything an institution needs to know. A tokenized bond remains a bond, subject to the same securities law, the same disclosure obligations, and the same insolvency treatment as its paper equivalent. What changes is the ledger the ownership sits on, the speed at which it can move, the cost of maintaining the record, and the set of things the holder can do with the position.
This article covers each of those changes in turn. It separates the terms that get used interchangeably, explains the legal position after the regulatory clarifications of 2026, describes how transfer restrictions are enforced inside the token itself, quantifies the operational savings, and states the risks that tokenization leaves in place.
The Terms That Get Used Interchangeably
Search demand mixes several terms that describe overlapping things. The distinctions matter mainly because they signal how the instrument was created.
Term | Common meaning | Regulatory position |
|---|---|---|
Tokenized security | An existing security, such as a share, bond, or fund unit, represented by a token while the instrument itself continues to exist under conventional law | A security, treated according to the instrument it represents |
Security token | A token issued natively on-chain that carries the rights of a security from the outset, with the ledger acting as the primary register | A security, with the same treatment as any equivalent instrument |
Utility token | A token that provides access to a service or function within a network, with value tied to that use rather than to a claim on an enterprise | Assessed on economic substance. Under the 2026 US taxonomy this sits closest to the digital tools category |
Investment token, securitized tokens | Informal umbrella phrases used in marketing and search | No standing as legal categories. Read the offering document to establish what the instrument is |
The practical difference between the first two sits in the register. A tokenized security typically leaves a conventional register in place, with the token mirroring it. A natively issued security token makes the ledger the register, which is the model that allows an issuer to remove a layer of intermediation from primary issuance. Our guide to how tokenized stocks work covers how that difference plays out for equities specifically.
What Changes Legally
The legal position is settled in every major market, and it settled conservatively.
In the United States, the SEC issued a commission-level interpretive release on 17 March 2026, Release Nos. 33-11412 and 34-105020, joined by the CFTC. It set out a five-part taxonomy covering digital commodities, digital collectibles, digital tools, stablecoins, and digital securities, and it confirmed that digital securities are securities. A joint staff statement in January 2026 had already established the governing principle, which is that regulatory treatment follows economic substance rather than technical form. Existing securities law applies to tokenized instruments across the US, the EU, Singapore, the UAE, and Switzerland.
The practical consequences for institutional programmes all run in the direction of continuity. An offering of tokenized securities requires the same registration, or the same available exemption, that the underlying instrument would require, which means Regulation S, Regulation D, and their equivalents in other jurisdictions apply to the token exactly as they would to the share or the note behind it. Intermediary obligations survive the change of format, so broker-dealer registration, transfer agent registration, custody rules, and market structure rules continue to attach to whoever performs those functions, whatever the ledger records.
The token standard itself carries no independent legal weight in any of this. An instrument is defined by its offering document and its governing law, which is why reading the prospectus comes before any analysis of contract architecture.
How Permissioned Transfer Logic Works
The mechanism that reconciles a public blockchain with securities law sits inside the token contract. Virtually every institutional programme enforces restricted transferability through on-chain whitelisting, so only addresses that have passed identity checks and been approved can hold or receive the token.
Standards such as ERC-3643 encode that logic directly into the asset. A transfer call reaches the contract, the contract checks the identity status of both parties against an on-chain registry, and the transfer completes only when both sides satisfy the rules. Eligibility can be conditioned on jurisdiction, accreditation status, holding limits, or lockup periods, and the check happens before the transfer settles rather than afterwards in a compliance review.
That architecture concentrates real authority in whoever maintains the allow list, so the identity of that party, the governance covering changes to it, and the speed at which an address can be added or removed all belong in a diligence pack. The same design usually supports freeze and forced transfer functions, which exist to satisfy court orders, sanctions obligations, and error correction, and whose triggering circumstances and authorization path are worth documenting before allocating.
The allow list also decides what the asset can interact with, which is where a compliance decision becomes an economic one. A list admitting only investor wallets excludes smart contracts, so the token cannot enter a lending market or a vault. A list built to admit approved protocol addresses permits both. That single design choice governs how useful the token can be inside on-chain markets.
What Changes Operationally
The operational case is the most measurable part of tokenization, and the numbers come from the cost base it targets.
Fund operating costs stood at 0.74% of assets under management for the average fund as of 2024, according to Calastone research based on a survey of 26 asset managers, with those costs concentrated in the back office. The back office accounts for 64% of fund operating costs, and fund accounting alone represents almost 24% of the total. Fund accounting, corporate actions, and reconciliations rank among the four most expensive line items in the whole operating base. Respondents expected processing costs to rise by roughly a third over three years, with transfer agent services among the fastest-rising components.
Against that baseline, the same research put achievable savings from tokenization and distributed ledger deployment at 23% of operating costs, equivalent to 0.13% of AUM.
Reconciliation absorbs most of that saving. A single transaction currently appears in the systems of a fund administrator, a custodian, a transfer agent, and a broker, each with its own timestamp and its own version of the record. A shared ledger reduces the number of independent records that have to agree, which cuts both the frequency of breaks and the manual work of clearing them, and it gives near real-time visibility into where holdings sit and whether they are encumbered. Asset servicing follows the same logic once the register lives on the ledger, with subscription and redemption processing, income distribution, and corporate action handling moving into the contract layer and the register updating as transfers settle.
Settlement finality adds a further saving, since delivery against payment can execute atomically and remove the counterparty exposure that exists during a conventional settlement window. Evidence from bond markets suggests the gain reaches pricing as well as processing, because the Hong Kong Monetary Authority's review of tokenized bond issuances documented lower underwriting costs and tighter bid-ask spreads compared with equivalent conventional bonds.
What Changes Economically
Atomic settlement changes the shape of liquidity risk, and this is the part of the analysis that vendor material tends to skip.
The IMF set out the mechanics in an April 2026 note on tokenized finance. Conventional markets run on end-of-day settlement, batch processing, and delayed reconciliation. Those frictions are costly, and they also create temporal buffers that allow exposures to be netted, liquidity to be mobilized, and authorities to intervene before settlement becomes final. Tokenized systems compress those buffers. Settlement becomes continuous, margining becomes automated, and liquidity demands arrive in real time rather than at discrete points in the day.
The net effect redistributes risk rather than removing it. Credit exposure between counterparties falls because settlement finality arrives immediately, while intraday liquidity requirements rise because gross flows are no longer netted down before settlement, and the residual risk shifts away from intermediaries and toward infrastructure and code.
For a treasury team, the consequence is practical. Tokenized holdings reduce the capital tied up waiting for settlement, and they require a funding plan that accounts for continuous rather than end-of-day liquidity demands.
The Residual Risks of Tokenization
Smart contract risk arrives with the format. The token contract, the identity registry, and any bridge the asset crosses are software, and software carries defects, which makes audit history, upgrade authority, and the process for pausing a contract during an incident the relevant diligence items. This exposure has no equivalent in conventional securities processing, so it belongs on the risk register as an addition rather than as a substitution for something tokenization removed.
Custodian and infrastructure concentration is the exposure most often underweighted. A large share of tokenized fund assets sits with a small number of qualified custodians and transfer agents, so a failure at one provider could freeze redemptions across several products at once. Map that exposure the way you would map any concentrated counterparty, working from the identity and charter of the custodian rather than from the brand of the issuer.
Secondary Market Depth
Thin secondary markets are the constraint that most limits what tokenization currently delivers. Institutional capacity is arriving through venue and depository infrastructure, and for most tokenized instruments issued today the working exit remains redemption or over-the-counter dealing rather than an order book. Most tokenized bonds are still held to maturity. Structures that isolate the asset from the issuer's balance sheet have attracted the deepest markets, because counterparties commit sustained volume only when they trust that their claim survives an issuer default.
Secondary depth is also the reason collateral utility matters more than trading volume at this stage of the market. When a holder can borrow against a position, hedge it, or deploy it inside on-chain credit, the asset becomes useful without waiting for an order book to form.
Sentora Co-founder Jesus Rodriguez, joined by Katya Ternopolska, VP of Sales and Partnerships, and Lucas Outumuro, VP of Institutional DeFi, takes this up in Beyond the Wrapper: What Tokenized Assets Do Next. They discuss what it takes for equities to function as productive collateral for borrowing, hedging, and yield. The session also covers how liquidation, oracle, and liquidity risk are solved at scale, and where the tokenised asset market is heading across Treasuries, credit, and gold.
What This Means for an Institutional Programme
Tokenizing a security changes the record, the speed, the cost, and the range of things a holder can do with the position. It leaves the legal character of the instrument, the obligations of the intermediaries, and the credit risk of the underlying asset exactly where they were.
That combination is why the interesting questions have moved past whether tokenized securities are permissible. They are permissible, the operational case is measurable, and the remaining work sits in market structure: building the secondary depth, the collateral integrations, and the risk controls that let a tokenized instrument do something a conventional one cannot.
