Tokenisation (RWA)
Custody and settlement of tokenised assets
Tokenisation promises faster settlement, but who safeguards ownership and how money and securities change hands simultaneously remains just as important as in traditional securities markets. Custody and settlement are the two building blocks that determine whether a tokenised security is in practice as safe as a classic one.
Custody: who holds the private key
With a tokenised security, custody shifts from a bookkeeping entry at a bank to managing a cryptographic key that grants access to the token. An investor could manage that key themselves, but in practice almost every regulated issuance uses an external custodian who manages the keys on the client's behalf, comparable to a traditional securities custodian.
Regulated custodians must meet strict requirements around segregating client assets, internal controls and insurance against theft or loss of keys. That is a deliberate choice: self-custody of a private key is irreversible upon loss, whereas a classic securities account can be restored through the bank or notary.
Some structures use multi-signature setups where several parties must jointly approve a transaction, reducing the risk of a single compromise while slightly slowing settlement.
- Custody shifts from bookkeeping to key management
- Regulated custodians must segregate and insure client assets
- Multi-signature lowers risk but slightly slows settlement
Delivery versus payment on the blockchain
The classic principle of delivery-versus-payment (DvP), where a security only changes hands once payment happens simultaneously, remains the starting point with tokenisation too. On a blockchain this can be enforced via an atomic swap: a smart contract executes the transfer of the security token and the payment token within the same transaction, so neither party can end up without the other.
This works most convincingly when both the security and the money live on the same blockchain, for example when a bank uses its own tokenised deposit or a digital central bank currency for the cash leg. When payment still runs through a classic banking system while the security sits on the blockchain, true atomic DvP is not possible and an intermediary must bridge the time gap, reintroducing part of the classic counterparty risk.
- Atomic swaps link security and payment in one irreversible transaction
- Works best when money and security sit on the same infrastructure
- Mixed setups with classic money reintroduce some counterparty risk
The role of central securities depositories (CSDs)
In the classic securities chain, a central securities depository (CSD) records who ultimately owns which security and handles settlement between banks and brokers. With tokenisation, some CSDs try to keep that role by offering a blockchain infrastructure themselves, keeping the official ownership register digital while staying compatible with existing law.
Other initiatives let the blockchain itself act as the ownership register, outside the classic CSD structure. That can be faster but requires an explicit legal basis to count as a valid ownership register. Within the DLT Pilot Regime this is one of the core questions: how far can a market infrastructure deviate from the classic CSD role.
- Classic CSDs can add a blockchain layer to their existing role
- Alternative models let the blockchain act as the primary ownership register
- A legal basis is required to recognise a blockchain register as official
Why banks remain an intermediate link
Even in a fully tokenised chain, banks remain relevant, partly because they handle the fiat leg of transactions, identify clients under anti-money-laundering rules and often act as custodian for institutional clients themselves. A number of large banks are building their own tokenised deposit systems precisely to deliver on the DvP promise without depending on an external stablecoin issuer.
For investors this means 'blockchain' does not automatically remove intermediaries; it mainly changes which intermediaries are needed and how fast settlement happens after a transaction.
- Banks remain responsible for fiat settlement and identification
- Own tokenised deposits let banks offer atomic DvP themselves
- Tokenisation more often replaces intermediaries than eliminates them
Frequently asked questions
Who holds my tokenised security if I don't self-custody?
With a regulated issuance this is usually an external custodian who manages the private keys on your behalf, under rules comparable to a traditional securities custodian.
What is delivery versus payment and why does it matter?
It is the principle that a security only changes hands once payment happens simultaneously. On the blockchain this can be enforced via an atomic swap, reducing the risk of one party paying without receiving the security or vice versa.
Does the blockchain replace the central securities depository?
Not necessarily. Some CSDs build their own blockchain layer, while other initiatives use the blockchain as a separate ownership register. Both forms exist alongside each other.
Does tokenisation fully remove counterparty risk?
No. Only when money and the security live on the same infrastructure can an atomic swap truly remove counterparty risk. With a mixed setup involving classic bank money, some of that risk remains.
Read next
Tokenisation and the EU legal framework
When does a token fall under MiCA versus MiFID, what does the DLT Pilot Regime do, and when does a token qualify as a security?
Tokenisation in Belgium and the Netherlands
How do the FSMA and AFM approach tokenisation, what tax points matter, and how far has the market progressed in Belgium and the Netherlands?
Tokenised treasuries and money market funds
How tokenised treasuries and money market funds work, how the yield is generated and which risks remain despite the blockchain layer.