BETAYou're using an early access version of Investhub
EN · DE
Tokenisation Regulation

The Issuer's Tokenisation Compliance Checklist

Raising capital through tokenisation opens powerful new doors—but only if you clear every regulatory gate first. This practical tokenisation compliance checklist walks issuers through each critical step before, during, and after launch.

Why a Tokenisation Compliance Checklist Matters

Tokenisation is not a regulatory shortcut. Issuing a digital token that represents equity, debt, or a real-asset claim triggers securities law in virtually every jurisdiction where investors reside. Regulators in the EU, UK, Switzerland, and beyond have made clear that the economic substance of an instrument—not its technical wrapper—determines how it is classified and supervised. Founders who skip structured compliance review risk asset freezes, investor claims, and reputational damage that can end a fundraise before it finds momentum. A disciplined checklist does two things: it forces you to answer hard questions early, when course-correction is cheap, and it signals seriousness to institutional investors and legal auditors alike. Think of it less as bureaucracy and more as the due-diligence infrastructure that makes your cap table defensible. Every item below maps to a real regulatory requirement you will face.

Step 1 – Legal Classification of Your Token

Before drafting any investment document, determine exactly what rights your token confers. Regulators distinguish broadly between security tokens (profit participation, voting rights, or debt claims), utility tokens (access to a product or service), and payment tokens (used as a medium of exchange). Hybrid structures are common but magnify regulatory complexity. In Liechtenstein, the Token and Trusted Technology Service Provider Act (TVTG) provides a clear legal container: the 'token' is a vessel that can carry virtually any right, and the law prescribes how that right is documented on a register. Under MiCA, which covers the EU from 2024, asset-referenced tokens and e-money tokens face the strictest regime. Misclassifying your token is one of the costliest errors an issuer can make, so obtain a formal legal opinion before proceeding to documentation. This single step can reframe your entire issuance structure.

Step 2 – Jurisdiction, Passporting and Exemptions

Once classification is confirmed, map where you intend to sell. Each jurisdiction carries its own prospectus threshold, investor-count limits, and marketing restrictions. Within the European Economic Area, a prospectus approved in one member state can be passported to others—but only if it meets the full Prospectus Regulation standard. Below the €8 million threshold (in most EEA states), an information memorandum or simplified disclosure document often suffices, though member-state rules vary. Liechtenstein's TVTG framework is particularly attractive for cross-border token issuances within the EEA because it combines a modern token-law basis with EEA single-market access. Outside the EEA—targeting US persons, for example—Regulation D or Regulation S exemptions under US securities law must be respected. Document every target jurisdiction explicitly and obtain counsel in each. Assumptions about equivalence between regimes have derailed more than one token offering.

Step 3 – KYC, AML and Investor Suitability

Anti-money-laundering obligations attach to token issuances that qualify as financial instruments or payment tokens in most jurisdictions. At a minimum, your process must include identity verification (government-issued ID plus liveness check), sanctions screening against current OFAC, EU, and UN lists, source-of-funds declarations for investments above defined thresholds, and ongoing transaction monitoring for secondary transfers. Investor suitability adds another layer: are you selling only to qualified or professional investors, or to the general retail public? Each category triggers different disclosure obligations and liability exposure. Automated KYC/AML workflows reduce friction without lowering standards—on-chain whitelisting can enforce investor eligibility at the smart-contract level, so transfers to non-verified wallets are blocked by design rather than by manual policing. Document your entire AML policy in a written programme and have it reviewed annually.

Step 4 – Offering Documents and Disclosure Standards

Depending on your classification and jurisdiction, you will need one or more of the following: a full prospectus approved by a competent authority, a key information document (KID) under PRIIPs, an information memorandum, or a token-specific white paper as required under MiCA. Regardless of the mandatory format, best practice demands that every offering document cover the issuer's legal structure and beneficial ownership, a clear description of the rights the token confers, use-of-proceeds breakdown, risk factors (including smart-contract risk, liquidity risk, and regulatory risk), conflict-of-interest disclosures, and a description of the secondary-market arrangements (or their absence). Vague, promotional language raises red flags with regulators and sophisticated investors alike. Write for the skeptical reader. Investhub's issuance workflow prompts structured disclosure at each stage, reducing the likelihood that a critical section is omitted under time pressure.

Step 5 – Smart-Contract Audit and Custody Arrangements

Compliance does not stop at the legal document layer. The code that governs your token must be audited by an independent third party before deployment. A formal smart-contract audit examines logic errors, access-control vulnerabilities, reentrancy risks, and the accuracy of on-chain business rules (such as transfer restrictions or distribution mechanics). Audit reports should be published and made available to investors as part of your disclosure package. Custody is equally critical: investors need to understand who holds private keys, whether tokens are held in self-custody, custodian-managed wallets, or exchange accounts, and what recovery procedures exist if keys are lost. Regulated custodians operating under MiCA or equivalent frameworks provide the clearest liability boundary. If you use a settlement layer denominated in stablecoins—as Investhub supports—verify that the stablecoin itself is either an e-money token regulated under MiCA or otherwise legally characterised in your jurisdiction.

Step 6 – Ongoing Obligations After Token Launch

Compliance is not a one-time gate; it is a continuous programme. Post-launch obligations typically include periodic financial reporting to token holders (quarterly or annual, depending on the instrument), material-event notifications (change of control, insolvency risk, amendment of token terms), ongoing AML transaction monitoring, annual review of your AML/KYC programme, regulatory reporting to the supervising authority, and maintenance of the token register. In Liechtenstein under TVTG, the Token Issuer must maintain an up-to-date register of token rights and ensure that any transfer of those rights is recorded. Secondary-market liquidity, even on a regulated bulletin board, triggers best-execution and market-integrity considerations. Build a compliance calendar from day one. Issuers who treat post-launch obligations as an afterthought typically face the heaviest enforcement costs. Investhub's platform is designed to automate much of this reporting infrastructure so that your team focuses on building the underlying business.

Key Takeaways

  • Classify your token correctly under applicable securities law before drafting any offering document—misclassification is the single costliest early error.
  • Map every target jurisdiction individually; prospectus thresholds, investor-count limits, and marketing rules differ materially across the EEA and beyond.
  • KYC/AML obligations are non-negotiable and should be enforced at the smart-contract level through on-chain whitelisting wherever possible.
  • Compliance continues after launch: token issuers carry ongoing reporting, register-maintenance, and AML monitoring obligations that must be calendared from day one.

FAQ

What is a tokenisation compliance checklist?

A tokenisation compliance checklist is a structured list of legal, regulatory, and operational steps an issuer must complete before, during, and after a token offering. It typically covers token classification, jurisdiction mapping, KYC/AML setup, offering-document preparation, smart-contract audit, and post-launch reporting obligations. Working through such a checklist systematically reduces the risk of regulatory enforcement, investor claims, and offering delays.

Is token issuance regulated in Europe?

Yes. Token issuances in Europe are regulated under a combination of existing securities law (Prospectus Regulation, MiFID II), national legislation such as Liechtenstein's TVTG, and the new EU Markets in Crypto-Assets Regulation (MiCA), which has applied in full since December 2024. The specific regime depends on how the token is classified—as a security, utility, or payment token—and where investors are located.

What is the TVTG and why does it matter for token issuers?

The TVTG (Token and Trusted Technology Service Provider Act) is Liechtenstein's token-specific law, in force since 2020. It defines the token as a legal vessel that can represent virtually any right—equity, debt, real-estate claim, or otherwise—and provides a clear framework for registration and transfer of those rights. Because Liechtenstein is an EEA member, TVTG-compliant issuances benefit from EEA single-market access, making it a practical choice for pan-European token offerings.

Do I need a prospectus for a token offering?

It depends on the size of the offering, the type of investors targeted, and the jurisdiction. Within the EEA, offerings above €8 million to retail investors generally require a full prospectus approved by a national regulator. Below that threshold, an information memorandum or simplified document often suffices, but member-state-specific rules apply. Offerings restricted to professional or qualified investors benefit from lighter disclosure requirements. Always obtain legal advice for your specific structure.

What ongoing compliance obligations does a token issuer have?

After launch, a token issuer typically must maintain the token register, provide periodic financial reporting to holders, notify investors of material events, conduct ongoing AML/KYC monitoring, and report to the relevant supervisory authority. Under MiCA, crypto-asset service providers operating secondary markets face additional market-integrity and best-execution obligations. The exact obligations depend on the legal classification of the token and the jurisdictions in which investors reside.

How can Investhub help with tokenisation compliance?

Investhub operates a regulated token issuance infrastructure anchored in Liechtenstein's TVTG framework, with EEA single-market reach. The platform automates KYC/AML onboarding, enforces investor whitelisting at the smart-contract level, supports stablecoin-based settlement, and provides a secondary bulletin board for token liquidity. Issuers benefit from a structured onboarding workflow that prompts compliant disclosure at each stage, reducing the manual compliance burden on founders and CFOs.

Navigating tokenisation compliance is complex, but it is entirely manageable when you work through each requirement methodically and build the right infrastructure from the start. The checklist above covers the essentials—classification, jurisdiction, KYC/AML, disclosure, smart-contract audit, and ongoing obligations—but every issuance has nuances that demand tailored legal and operational advice. Investhub is built specifically to take the compliance weight off the issuer's shoulders: from TVTG-anchored token issuance and automated KYC to stablecoin settlement and a regulated secondary bulletin board. If you are ready to explore what a compliant token offering looks like for your business, start your onboarding with Investhub today.