Tokenization Services
Last Update:
Asset Tokenization Services

Investor Onboarding and Operating Infrastructure

Gofaizen & Sherle can design the legal, regulatory, corporate and compliance architecture that connects investor onboarding with wallets, custody, payments, distributions, property reporting, transfers and ongoing controls. The mandate allocates each function to a provider that is permitted and equipped to perform it. G&S should not be treated as the wallet operator, custodian, payment processor or token platform unless a separately verified scope says so.

This model suits teams with a defined commercial, residential or agricultural asset and a proposed token-holder right. It supports fractional real estate tokenization across jurisdictions where the challenge is controlling how investors, money, data and ownership records move through the system.

A real estate tokenization platform cannot determine the compliance model from the asset label. The token may represent an SPV share, note, fund interest or contractual entitlement. Its rights and offering route determine who may onboard investors, hold assets or funds, approve transfers and maintain records.

United Kingdom

Tokens carrying ownership, repayment or profit rights may enter the regulated security-token perimeter. The analysis is fact-specific under the FCA’s cryptoasset guidance, and financial-promotion controls can apply before KYC.

European Union

MiCA excludes financial instruments. ESMA’s qualification guidelines apply a technology-neutral MiFID assessment. The project needs the appropriate MiCA or securities-law route and relevant Member State rules, not a blended EU workflow.

United States

Tokenization does not decide securities status. The SEC requires analysis under the applicable securities category and economic characteristics in its March 2026 Commission interpretation. Federal and relevant state questions then shape the workflow.

This page does not select a universal SPV or provide a full securities-classification opinion. Those decisions are inputs to the operating design.

Designing the investor journey

AML/KYC compliance should be built as a controlled investor-onboarding sequence, not a widget added shortly before launch:

  1. Set acquisition and eligibility rules. Define where the offer may be promoted, which investors qualify and what evidence supports a decision.
  2. Identify the customer and responsible entity. Allocate identity, beneficial-owner, sanctions, PEP, source-of-funds and risk-rating checks to the regulated or otherwise responsible participant.
  3. Manage exceptions. State who reviews a mismatch, requests more evidence, rejects an applicant or escalates a suspicious case. An identity vendor can support the process without becoming the accountable decision-maker.
  4. Connect approval to access. Approval should control subscription acceptance, wallet allowlisting and issuance. Later sanctions or eligibility changes should trigger review.
  5. Preserve evidence. Record the rule, documents, reviewer, decision, refresh trigger and retention owner.

Onboarding, wallets, custody and payments

The wallet design begins with a legal question: which record establishes the investor’s entitlement? A wallet address, blockchain ledger, custodian account, transfer-agent record and statutory company register can show different parts of the same position. The workflow must say which is authoritative and how discrepancies are resolved.

Investors may use managed wallets, permitted self-hosted wallets or both. The design should identify who controls keys, how address control is verified and how lost keys, compromised addresses, freezes and replacements are handled.

Custody and payments need equally clear boundaries. An appropriately authorised custodian or other valid structure may control the tokens or keys. A permitted provider receives funds according to the route. The map should cover account ownership, segregation where required, settlement finality, refunds and unmatched or rejected subscriptions. Tokens should be minted or the ownership record updated only after approval and funding conditions are met.

Income distribution and property reporting

Onchain holdings do not calculate rental income by themselves. A controlled cycle starts with property-manager and accounting data, then applies approved expenses, reserves, tax or withholding inputs and the record-date ownership position. The responsible body approves the entitlement file before payment instructions are released.

Investor reporting should link each amount to the relevant period, asset data, expense allocation and ownership record. It also needs procedures for stale bank or wallet details, failed payments, withheld amounts and corrected statements. The final reconciliation should connect the property account, approved distribution file, payment outcome, investor register and blockchain record without treating transaction history as a substitute for accounts or a property report.

Transfers, exceptions and reconciliation

A token can be transferred technically without creating a lawful resale route or market liquidity. Before a transfer, the workflow may need to test:

  • investor status
  • jurisdiction
  • holding period
  • sanctions results
  • offering restrictions
  • venue requirements
  • the issuer’s own documents.

Smart-contract restrictions can stop an unapproved address or enforce a lockup, but they cannot decide every legal exception. Lost-key recovery, inheritance, court orders, forced transfers and incorrect ledger entries need a documented human approval path. Every completed, rejected or reversed transfer should leave an evidence trail and update the authoritative holder record.

Ongoing compliance needs named owners and tested controls

An operating model continues after issuance. Each control needs an accountable owner, an evidence source and an escalation route. The project should allocate:

  • KYC refreshes
  • sanctions rescreening
  • investor and provider reviews
  • access control
  • incident response
  • disclosure updates
  • reconciliations
  • regulatory change management.

Provider contracts also need practical governance. The Financial Stability Board third-party risk toolkit supports a lifecycle approach covering due diligence, contracts, monitoring, incidents and exit planning. For tokenized real estate, this means checking permissions where relevant, data access, audit rights, subcontractors, service levels, continuity and migration support.

Testing should cover successful transactions and failure states. Useful scenarios include duplicate subscriptions, payment-provider outage, KYC false positives, missing transfer data, lost keys, failed distributions and a mismatch between the blockchain and legal register. Launch approval should record who tested each interface, the reconciliation tolerance, unresolved exceptions and the rollback route.

Commission an operating-model design

A useful brief identifies:

  • the asset
  • asset jurisdiction
  • proposed token-holder rights
  • entity and SPV position
  • target investor countries and categories
  • offering route
  • preferred payment rails
  • current provider shortlist
  • budget stage
  • desired launch timing.

It should also state whether transfers or a secondary-market route are planned.

Within an agreed mandate, Gofaizen & Sherle can turn those inputs into a jurisdiction and responsibility matrix, an end-to-end workflow, a provider-permissions map, a control and evidence schedule, exception rules, reconciliation points and implementation test requirements. The scope can also identify questions that need local property, tax, corporate or securities advice. Cost and timing remain project-specific and should be set only after the facts and provider architecture are reviewed.

Frequently Asked Questions

Can one provider operate every tokenization workflow?

Not necessarily. A platform may combine technical functions, while custody, payments, transfer agency or market operation may require different permissions and accountable entities. The designer coordinates the stack and identifies gaps.

Does every investor need a managed wallet?

Not always. It depends on classification, custody model, network, investor profile and applicable transfer rules. Managed and self-hosted routes both need recovery, sanctions, recordkeeping and exception procedures.

Can a smart contract enforce all transfer restrictions?

No. Code can enforce objective rules such as allowlists or lockups. Offchain facts and approvals still govern issues such as investor status, resale exemptions, inheritance and authoritative ownership records.

What information is needed for a proposal?

Provide the asset and jurisdiction, proposed investor right, SPV or entities, target markets and investors, provider shortlist, payment rails, custody preference, transfer plans, budget stage and desired launch timing.

Mihhail Sherle
Mihhail Sherle
Senior Partner, Head of Legal
Robert Pekin
Robert Pekin
Assocaite, Head of Tokenization
Get in touch
Phone *
Estonia +372 Estonia

    Connect with our experts

    Our experts will tell you how to do it as quickly and easily as possible.

    Estonia

      By clicking the button, I confirm that I have read the privacy policy and consent to the collection and processing of my personal data in accordance with the GDPR rules.

      Thank you

      Thank you for reaching us. Our team is working on your request, and we will contact you soon.

      Message not sent