Independent Tokenized Fund Blueprint and Vendor Scope Review
A tokenized fund is still an investment fund. Like other investment funds, it pools money under a defined strategy. The main difference is that a digital token represents a fund unit or share. The token may also be used to record ownership and control transfers.
This can make some processes faster or easier to automate. However, the technology must fit the fund’s legal structure and everyday operations. A working platform alone is not enough.
Gofaizen & Sherle can review a tokenized fund blueprint and competing proposals for fund tokenization services before the fund appoints providers or signs implementation contracts. The adviser works for the fund, not for a platform vendor. The review answers four practical questions:
- What does the project actually need?
- Who is responsible for each part?
- What is missing or covered by more than one provider?
- Which delivery model is the best fit for the fund manager?
This buyer-side review is not a generic list of the “best” tokenization providers.
Several specialist providers may be involved:
- A fund administrator calculates the fund’s value and supports its financial records.
- A transfer agent keeps investor records and processes purchases, sales and transfers of fund units.
- A custodian safeguards assets; separate custody arrangements may apply to digital tokens and to the investments owned by the fund.
- A distributor markets the fund to eligible investors.
When is an independent tokenized fund review useful?
The best time for a review is before contracts are signed and before the main build starts. At this stage, the fund can still change the project design without having to rebuild a live product.
A review may be useful when:
- a technology provider designed the first blueprint, but the legal documents and operating procedures have not been checked against it
- vendors disagree about who will handle investor onboarding, payments, wallet checks or the investor register
- the fund administrator, transfer agent, custodian and tokenization platform offer some of the same services
- the target investors, countries or distribution channels have changed
- several systems need to connect, but no one is responsible for testing the complete process
- vendor proposals use different assumptions, exclusions and pricing structures, which makes comparison difficult.
Each vendor can explain its own product. An independent review checks how all providers will work together.
What should the review test?
The review follows the complete investor journey. It starts with the legal rights attached to the token. It then checks how an investor joins the fund, pays, receives a token, gets reports, transfers the investment and finally withdraws money.
In fund language, buying units is a subscription and cashing them out through the fund is a redemption. Investor onboarding means checking whether a person or company may invest and completing identity and compliance checks.
In simple terms, it checks whether the legal, operational and technology parts describe the same product.
| Everyday question | What the review checks |
| What does the investor own? | Whether the token represents fund interests, fund shares or another right. It also identifies the chosen fund structure—for example, a tokenised share class or a digital ownership register. |
| Which legal and regulatory rules apply? | The relevant regulatory framework and regulatory considerations. These depend on the fund’s country, investors, sales route, token design and any plans for investors to trade with each other. |
| Which record proves ownership? | Whether the fund documents and procedures describe the same model. If a blockchain record and the administrator’s record disagree, the documents must say which one is official. |
| Who handles each investor step? | Who approves the investor, receives the money, issues the token, sends reports and processes transfers or redemptions. |
| How is the unit price managed? | Who calculates net asset value (NAV)—the value of the fund and its units. The review also covers cut-off times, fees and correction of errors. |
| Who safeguards the assets? | Who controls wallets and digital keys, and who holds the investments bought by the fund. These are separate custody questions. |
| When is a transaction complete? | How investors pay, when the payment and token transfer become final, and what happens if either one fails. |
| Who may offer or buy the fund? | The countries, sales channels and types of investors allowed. The review also checks how transfer restrictions are enforced. |
| What happens if systems disagree? | Which record takes priority and how providers exchange, compare and correct data. |
| What happens after a technology failure? | How smart contracts are tested, updated, paused and restored. A smart contract is code that carries out defined actions automatically. |
| Who gets the project ready for launch? | Who writes requirements, connects systems, tests the full process, trains staff, approves the launch and provides support afterwards. |
Fund tokenization is not one legal category with the same rules everywhere.
In April 2026, the FCA published UK-specific guidance on using distributed ledger technology (DLT) for authorised funds. DLT is the technology used to keep and share records across a network. The guidance includes the use of a DLT unitholder register. It is a useful reference, but it cannot be applied automatically to a fund in another country.
How does the review find vendor-scope gaps and overlaps?
The reviewer creates a single table for the entire project. It links every important requirement to:
- its legal or business reason
- the provider responsible for it
- any system or provider it depends on
- the evidence needed to show that it works
- the person responsible when something goes wrong.
This makes three common problems easier to see:
- A gap: no vendor is responsible for a required task, control or integration.
- An overlap: two service providers include the same task, but neither clearly owns the final result.
- A hand-off risk: every individual task is covered, but no one owns the connection between providers or systems.
For example, the platform may issue the token and the administrator may approve the investor. The project design must explain how the approval reaches the platform, what happens if the data does not match and who fixes the problem. Otherwise, an approved investor may still fail to receive the token.
This type of risk is not theoretical. ESMA’s report of 25 June 2025 on the functioning and review of the DLT Pilot Regime, prepared under Article 14 of Regulation (EU) 2022/858, is a case in point. Uptake stayed limited, with only three authorised DLT market infrastructures and minimal live trading, and among the obstacles ESMA identified were the lack of interoperability with traditional financial infrastructure, restricted access to central bank money, and legal difficulties in structuring tokenised instruments under national law. The report concerns EU market infrastructure rather than all tokenized funds. Even so, it shows why system connections and record ownership must be tested.
The review should also check the evidence behind vendor claims. Relevant evidence may include licences or permissions, system diagrams, audit reports and smart-contract reviews. It may also include promised service standards, security controls and lists of subcontractors. Finally, the vendor should explain how it will keep the service running after an incident and how the fund can move to another provider.
Which delivery model should the sponsor select?
There is no delivery model that is best for every fund. The sponsor—the organisation leading the project—should choose based on its asset management team, the number of providers, integration complexity and the need to remain independent from one platform. These are practical as well as regulatory considerations.
| Delivery model | What it means | Main point to check |
| One main contractor | One provider coordinates most of the project and may use subcontractors | Check whether the main contractor accepts responsibility for the work of subcontractors and for gaps between them. |
| Several specialist providers | The fund selects separate experts for technology, fund administration, custody or distribution | The fund needs strong project management, shared requirements and one end-to-end testing plan. |
| Fund-led delivery | The asset manager coordinates the project with its own legal, operations and technology teams | Confirm that the internal team has enough time and expertise and that specialist or regulated work has an owner. |
| Hybrid model | The fund keeps control of the overall design but delegates clearly defined work packages | Separate the roles of design, independent oversight and implementation. |
The recommendation should explain the benefits, limits and extra controls required for each realistic option. The Financial Stability Board’s toolkit on enhancing third-party risk management and oversight, published on 4 December 2023, takes the same view: critical third-party services should be managed across the whole lifecycle of the relationship, not only at selection.
What information does the reviewer need?
The documents do not need to be final, but the reviewer needs enough information to understand the product and compare vendor responsibilities.
Useful inputs include:
- the current tokenization blueprint and system diagrams
- the fund’s country, legal form, manager and target investor markets
- the proposed token model and official ownership register
- the fund documents and planned amendments
- the investor journey from onboarding and subscription to transfer and redemption
- vendor proposals, fees, assumptions and exclusions
- the list of proposed providers and subcontractors
- the custody model and controls over wallets and digital keys
- data flows and system connections
- security and testing documents, plans for keeping the service running after an incident and a plan for changing providers
- the implementation plan, decision-making structure and launch conditions.
The review should separate acceptable open questions from important tasks that have no owner.
What should the independent adviser deliver?
Depending on the agreed scope, Gofaizen & Sherle can prepare:
- a clear red-flag report covering legal, operational, custody, distribution, security, technology and implementation issues
- a matrix showing which vendor covers each requirement and where gaps or overlaps remain
- a map of responsibilities between the fund, manager, administrator, transfer agent, custodian, distributors, technology providers and advisers
- a comparison of realistic delivery models
- vendor selection criteria based on the actual fund model rather than a generic feature list
- questions and negotiation points for proposals, contracts and promised service standards
- a prioritised action plan for the period before contract signing, build, testing or launch.
The scope should also state what is not included. For example, a blueprint review is not automatically a legal opinion for a specific country, a regulatory application, a smart contract audit, a technical security test or a check of a vendor’s financial health. These services must be added separately if required.
How can the fund check that the adviser is independent?
The adviser should disclose any relationship that could affect the recommendation. This includes:
- referral fees
- reseller agreements
- investments
- preferred-provider arrangements and a possible role in the later implementation.
Providers should be compared using stated criteria and similar evidence. The engagement terms and disclosures must support the claim of independence.
The review team should understand more than one area. Legal advice alone may miss a system problem. A technology review alone may miss a rule in the fund documents. The team must be able to identify problems that sit between these areas.
Request an independent blueprint and vendor-scope review
Send Gofaizen & Sherle the current blueprint, fund structure, target investors, vendor proposals and relevant countries. The team can define the review scope, identify any specialist input required and agree on the practical outputs needed for the vendor decision.
Frequently asked questions
Does every tokenized fund need a cryptoasset custodian?
No. The answer depends on what is being held, who controls the wallets or keys, how the token is legally classified and which custody rules apply. Custody of the token and custody of the fund’s underlying assets are separate questions.
Can a DLT unitholder register replace a traditional register?
Sometimes, but not in every country or fund structure. The fund must first confirm that local law allows the DLT register to be the official record. The fund documents, operating procedures and service-provider roles must then support the same model.
Should the review be repeated?
Yes, if the fund model, investor markets, providers, technology or implementation scope changes materially. The new review can focus only on the parts affected by the change.

