Custodian Continuity Risk in Tokenized Assets
A tokenized interest settles in seconds. The legal chain behind it — investor to token, token to entity, entity to asset, asset to custodian — is paper, and paper does not re-paper itself when a service provider is acquired, restructured or wound down. Custody consolidates the way every infrastructure business consolidates: through acquisition. Institutions underwriting tokenized assets should therefore be able to answer a plain question before they subscribe, not after. If the custodian changes hands, does anything about your ownership change? For most well-built structures the answer is no. Knowing why is the work.
Failure surface one: keys and signing authority
The first surface is the one specific to digital instruments. Somewhere, key material controls the ability to mint, freeze, transfer or upgrade the token contract, and separate key material may control the wallet where assets or cash sit.
Corporate distress at a custodian is an operational event on this surface, not an ownership event — unless the keys were the ownership. The questions are mechanical. Is signing authority held by a multi-signature arrangement, and who are the signers by role: issuer, custodian, transfer agent, independent third party? What is the quorum, and can any single party act alone? Is there a documented key recovery and rotation procedure, and has it been tested rather than described? If the custodian is one signer of three, its disappearance is an inconvenience that triggers a rotation. If the custodian is the sole signer, its disappearance is a control failure, and every other protection in the structure is downstream of that fact.
The related question is upgrade authority. A contract that can be upgraded by a single administrative key is a contract whose terms can change without holder consent, and the identity and governance of that key should be as disclosed as the identity of the trustee in a bond indenture.
Failure surface two: the SPV-to-custodian chain
The second surface is older and better understood, which is precisely why it gets skipped.
In most institutional structures the asset is owned by a special purpose entity, and investors hold interests in that entity. The custodian is a service provider to the entity under a contract — it holds the bullion, the certificates, the cash account, the title documents. Ownership sits with the entity; the custodian holds. Where that separation is clean and the assets are segregated and identified as client property rather than commingled on the custodian's own balance sheet, a change of control at the custodian is a vendor transition. The entity terminates one agreement, appoints a successor, and moves the holdings.
Where it is not clean, the failure modes are familiar from every custody failure of the past forty years: assets held in an omnibus account with no client-level identification, rehypothecation permitted under a clause nobody priced, a sub-custodian in another jurisdiction whose insolvency law treats the relationship as a debt claim rather than a bailment, or a contract with no successor provision and a termination notice period measured in months. None of these are blockchain problems. They are the problems tokenization inherits from the asset side, and they are why the structure of the holding matters more than the sophistication of the ledger.
For vaulted commodities the diligence is concrete: allocated versus unallocated holding, bar or lot-level identification, the vault operator's identity, insurance, and the audit or attestation programme that ties the register to the physical inventory. The general mechanics of moving physical assets into a digital wrapper are set out in how tokenized commodities work. For real property, income-producing infrastructure or energy assets, the equivalent is title held at the entity level, with the custodian's role limited to cash, documents and collateral.
Failure surface three: the register of record
The third surface is the one institutions consistently underweight: if the custodian's systems are switched off, who can still say who owns what?
Every securities structure has a register of record. In a tokenized structure there are usually two artefacts that could serve — the on-chain ledger of token balances, and the transfer agent's or administrator's books that map those balances to identified, verified holders. Neither alone is sufficient. The ledger without the identity mapping is a list of addresses. The books without the ledger are a snapshot that stops updating. Continuity depends on both surviving independently of any single service provider.
The practical tests: is the register replicated outside the custodian's environment, and who holds the copy? If the administrator's systems went dark tomorrow, from what could the holder list be reconstructed, and how long would it take? Are holder identity records held by a party separate from the entity that holds the assets? Is there a defined successor transfer agent, or at least a contractual obligation to deliver records in a usable format on termination? A structure where the answer is "we would ask the vendor" has a single point of failure sitting underneath an instrument that was sold on transparency.
This is also where attestation discipline earns its cost. A reserve or holdings attestation that is independently signed, timestamped and published is a record that survives its issuer, and it gives a successor something to reconcile against on day one. What that layer should and should not be claimed to prove is worked through in what proof of reserve means for RWAs.
Two models, and where each one absorbs the shock
It is worth stating the two dominant designs plainly, because they distribute this risk differently.
In the qualified-custodian model, a regulated custodian holds the asset or the key material for the benefit of clients under a defined regulatory regime, with segregation requirements, examination and capital rules. The strength is supervision and a tested insolvency path; the exposure is concentration — the custodian is inside the ownership chain, and a transition is a regulated but real event.
In the entity-title model, legal title sits in the SPV, the token is the ledger entry evidencing an interest in that entity, and the custodian is a replaceable vendor holding assets that were never its own. The strength is that a custodian's corporate distress is an operational event rather than an ownership event. The exposure moves elsewhere: to the governance of the entity, the independence of its manager, and the quality of the register.
Neither model is inherently safer. Each has a place where the shock lands, and an allocator's job is to know which one they bought.
The checklist to send this week
Six questions, answerable by any issuer in a page. Who holds signing authority over the token contract and the asset wallets, at what quorum, and what is the rotation procedure? Are the underlying assets segregated and identified as client property, with rehypothecation expressly prohibited? Who is the custodian's regulator and what is its insolvency treatment in the governing jurisdiction? Is there a named successor custodian or a contractual delivery obligation on termination? Where is the register of record replicated, and how would the holder list be reconstructed if the administrator disappeared? And who signs the attestations — a party with independence from the entity that benefits from the number?
None of these is exotic, and none requires a technical audience. They are the questions a trustee, a fund board or a credit committee already asks about traditional structures, applied to a wrapper that settles faster. Commertize's position is that a structure should be able to answer all six before an investor is asked for a subscription, across every asset class on the platform — gold, carbon, energy, digital infrastructure and commercial real estate. How the pieces fit together is set out in how it works.
Have an asset you're thinking about? Register at commertize.com to see the platform — onboarding, KYC, holder dashboard and reporting. Or contact the team and tell us what the asset is; if it isn't a fit, that is a useful answer to get in one conversation rather than three.
Educational only — not legal, tax or investment advice, and not an offer of any security. Any securities offering is made by a sponsor, through documents prepared by the sponsor's counsel, under an exemption that counsel determines.
Have an asset you're evaluating for tokenization? Send the offering memo to deals@commertize.com or start at commertize.com/tokenize, and we will return a written tokenizability and capital-structure memo within 48 hours — free, no obligation.
Confidential review. No cost, no commitment, no calls unless it is a fit.