Custody, permissions and regimes

Somebody has to be allowed

Every function in the chain — holding the asset, keeping the register, introducing buyers, taking the money — is something a named party is authorised to do in a named place. Technology changes how these are performed. It does not change that they must be performed by someone permitted to perform them.

Custody

The question is always: whose is it if the firm fails?

Custody is the clearest dividing line in the whole field, and the test is simple. If a firm can move an asset without the owner’s signature, it has custody of that asset, whatever the product calls itself. If it cannot — because the only key that authorises a movement is held by the owner — it does not.

Where a firm does have custody, three obligations follow almost everywhere: the assets are held separately from the firm’s own, they are recorded so that each client’s share is identifiable, and there is a plan for returning them if the firm becomes insolvent. Meeting these is what a custody licence attests to.

This is why the custodial and non-custodial parts of a product should never be blurred on the same screen. A user who cannot tell which of their holdings someone else can move has not been given the information that matters most.

Non-custodial
The key stays with the holder

No licence is needed to publish software that lets someone hold their own asset, because nothing is being held for them. The trade-off is real: lose the key, lose the asset, and no operator can reverse it.

Custodial
The firm can move it

Convenient, recoverable, and regulated. Client assets segregated, reconciled and protected on insolvency. This is a licensed activity in essentially every serious jurisdiction.

The hybrid
Two wallets, clearly labelled

A common and workable design: the holder keeps their own keys for the asset, and a regulated partner holds the money. It only works if the boundary is visible in the interface.

The roles

Six permissions, rarely held by one firm.

Names and boundaries differ between jurisdictions, but the functions are consistent. A tokenized offering that reaches the public usually needs most of this list, assembled from several firms.

01CustodianHolds the underlying asset, or the keys to it, for someone else. For fund and securities structures this is often a specifically recognised category with capital and segregation requirements attached.
02Transfer agent or registrarMaintains the authoritative register of holders for a registered security, processes transfers, and answers the question of who held what on a given date. Where a ledger is to be the register, this is the role that has to be permitted to use it.
03Dealer, broker or placement agentIntroduces the offering to investors, takes orders, and is remunerated for it. Arranging deals in securities is a licensed activity in its own right, distinct from issuing them.
04Fund or scheme operatorWhere the vehicle pools money from multiple investors and manages it, the management function is itself authorised, and the vehicle may be a regulated scheme with its own rulebook.
05Payment or e-money institutionHolds and moves fiat for customers, issues accounts, and safeguards client funds. This is the permission behind every account that receives a domestic transfer.
06Crypto-asset service providerExchanges between crypto-assets and currency, operates custody of crypto-assets, or runs a trading venue. The European regime names these services explicitly and authorises firms against them.
Jurisdiction

A licence is a permission from a place, for people that place recognises.

There is no global authorisation. A firm permitted to provide custody in one country is, by default, not permitted to provide it in another, and serving a customer resident elsewhere may require a permission in that customer’s country rather than the firm’s own.

The result is that cross-border products are assembled from locally licensed parties, connected by contract. Most of the engineering difficulty in this field is the connecting, and most of the legal difficulty is deciding which party is responsible at each hand-off.

The vehicle
Where it is formed

Sets company law, insolvency treatment, whether the ledger can be the register, and what must be filed publicly.

The investor
Where they live

Sets whether they may be offered the interest at all, what must be disclosed to them, and which regulator hears their complaint.

The institution
Where it is authorised

Sets what it may do and for whom. A partner’s licence is not a licence you hold; it is a licence you are relying on, and the scope of that reliance is worth writing down.

The practical reading

Technology providers are in the chain, not above it.

A software layer can build the contracts, keep the record, enforce the restrictions and present all of it through one interface. It can shorten a process from months to days. It cannot hold client assets without a custody permission, cannot be the register where that role is reserved, cannot introduce an offering without the relevant authorisation, and cannot make an investor eligible who is not.

That is not a limitation to be worked around. It is the shape of the field, and designs that acknowledge it early tend to reach production; designs that discover it late tend to be rebuilt.

The honest summary for anyone planning an issuance: assemble counsel in the vehicle’s jurisdiction, a custodian, a registrar or transfer agent, a licensed distributor if the offering reaches beyond people you already know, and a payment institution for the money leg. Then choose the technology.