A token balance is only one layer of ownership
The blockchain is very good at proving certain facts.
It can tell you that an address holds a token. It can show transfers, supply changes and contract state. Depending on the implementation, it can also reveal administrator privileges, transfer restrictions, upgrade mechanisms, minting and burning authority, or whether a token can be frozen.
But none of that, by itself, tells you the complete legal meaning of the token.
A token may represent a fund share, a debt note, a beneficial interest, a certificate linked to another security, or another form of contractual claim. In some structures, the blockchain itself is not even the ultimate record of legal ownership.
BlackRock, for example, explains that for its tokenised money-market-fund model, an onchain token mirrors the fund holding while the transfer agent's shareholder register remains the “golden record.”
That is a crucial distinction. If you analyse only the wallet and contract, you may understand the token mechanics while still misunderstanding what the investor actually owns.
Identify the legal claim before analysing the wrapper
A familiar ticker can create a false sense of simplicity.
A token referring to a Treasury fund is not necessarily a Treasury security. A token referring to a public company's shares is not necessarily legally identical to a share held directly in a traditional brokerage account. A dollar-denominated yield token is not necessarily a stablecoin.
USDY is a useful example. Ondo describes USDY as a bearer note distributed to non-U.S. investors under Regulation S, rather than as a stablecoin. Its product documentation also makes clear that eligibility restrictions apply and that redemption is restricted to eligible non-U.S. persons.
The important diligence question is therefore not whether the asset has exposure to dollars or Treasuries. It is what instrument exists between the holder and those assets.
The same principle applies to tokenized equities. Coinbase describes its Tokenized Stocks as B20 tokens providing a beneficial claim on a real underlying share held in regulated custody, rather than simply presenting the token itself as interchangeable with every other form of share ownership.
Those details determine what rights survive if an intermediary fails, what records govern ownership, and how the holder can ultimately exit the position.
Find the actual issuer — not just the brand
RWA structures often involve several entities that are easy to collapse into one name.
There may be a consumer-facing platform, a legally distinct issuer, a fund or SPV, a broker, a custodian, a transfer agent and one or more service providers.
Those roles are not interchangeable.
If a website says that an asset is “issued by X,” diligence should establish the exact legal entity that owes the holder an obligation. If the asset is backed by securities, identify who owns those securities and where they are held. If a custodian or broker sits between the issuer and the underlying asset, determine what legal relationship connects them.
Brand recognition is useful context. It is not a substitute for mapping the actual structure.
This becomes particularly important in insolvency scenarios. “Backed by shares” and “the token holder has a direct bankruptcy-remote claim to those shares” are not equivalent statements.
Determine which record is authoritative
Crypto users are accustomed to thinking of blockchain state as final.
For many tokenized assets, the reality is more nuanced.
An onchain balance may be the operational representation of ownership while another register carries legal authority. In other structures, blockchain possession may play a stronger role.
The diligence question is simple:
If the blockchain record and the legally maintained ownership record diverge, which one controls?
BlackRock's description of the transfer agent's shareholder register as the golden record is one concrete example of why this matters.
A serious RWA review should therefore identify not just the token contract but the system of record behind it.
That might be a shareholder register, a transfer agent, a central securities depository, an issuer-maintained ledger or another legally recognized record.
Without that information, “self-custody” can be misunderstood. Holding your own private keys may eliminate one type of intermediary risk while leaving the underlying legal claim dependent on offchain records and institutions.
“Backed” is the beginning of the question, not the end
Backing is one of the most heavily marketed characteristics of tokenized assets.
But “backed 1:1” is not a complete diligence conclusion.
You still need to know what the backing consists of, who owns it, who holds it, how frequently its composition is disclosed, how it is valued, whether liabilities sit ahead of token holders, and what evidence supports each claim.
There is also a major difference between an issuer publishing a reserve statement and an independent party verifying it.
Both can be useful evidence. They are not the same type of evidence.
A good diligence process should preserve that distinction rather than reducing everything to a binary “verified” label.
The same applies to portfolio composition. A dated issuer disclosure can tell you what the issuer says was held at a given moment. It should not automatically be presented as continuous proof of reserves or as independent confirmation of the entire legal asset pool.
Precision matters more than confidence-sounding language.
Redemption rights can matter more than secondary-market liquidity
A token can trade actively without every holder having the same right to redeem it.
This is one of the easiest RWA risks to overlook.
Ondo, for example, states that people may be able to hold certain assets acquired through third-party venues while direct minting and redemption remain restricted to users who have completed onboarding and meet the relevant eligibility requirements.
USDY likewise has geographic and eligibility constraints around direct redemption.
That creates two different questions:
Can I sell this token to someone else?
And:
Can I exercise the underlying redemption right myself?
Those are not equivalent.
A diligence review should establish who can redeem, what KYC or eligibility rules apply, minimum amounts, settlement assets, expected timing, operating hours, relevant jurisdictions and whether redemption depends on an offchain process.
A token may have excellent secondary liquidity while its primary redemption path remains unavailable to a particular holder.
Inspect who can change, stop or reverse token behaviour
The legal structure tells you what the token represents.
The contract tells you what privileged actors can do to it.
Those control surfaces deserve their own analysis.
A token may support pausing, freezing, forced transfers, seizure, cancellation, minting or burning. It may be upgradeable. Transfers may require whitelisting or compliance checks. Administrator roles may be distributed across several addresses or concentrated behind a single authority.
None of these properties is automatically good or bad.
For regulated assets, transfer restrictions may be necessary to keep the instrument within its legal distribution framework.
The problem is not that controls exist.
The problem is buying an asset without knowing that they exist, who controls them, and under what circumstances they can be exercised.
Do not assume every onchain asset behaves like a conventional ERC-20
Familiar interfaces can hide very different implementations.
A token may use a proxy architecture. It may implement a permissioned token standard. Some functions may depend on external registries or compliance modules. Other assets may use chain-specific or native mechanisms that do not behave like ordinary deployed smart contracts.
This is why generic contract scanners can produce misleading conclusions when applied blindly to tokenized assets.
The right question is not:
Does this look like the ERC-20 pattern I already know?
It is:
What implementation actually governs this asset, and what assumptions does my analysis make about that implementation?
That distinction becomes increasingly important as traditional assets move onto infrastructure designed specifically for regulated financial instruments.
Treat “regulated” as a precise statement, not a quality badge
“Regulated” is one of the least useful words in RWA analysis when it appears without an object.
What exactly is regulated?
The issuer? The custodian? The broker? The fund? The offering? The venue?
Under what jurisdiction and framework?
Coinbase's current Tokenized Stocks, for example, are described as being available in eligible jurisdictions outside the United States, with the product structured around regulated custody and Regulation S distribution.
That information is meaningful.
It still should not be rewritten into a generic claim that the token is “government approved” or universally available.
The same discipline should apply to fund registration, securities exemptions and regulatory licences.
A regulatory fact should remain exactly what the underlying source establishes.
Separate observation, claim and proof
One of the most useful habits in RWA diligence is to label the provenance of each conclusion.
An onchain observation is different from an issuer statement. An issuer statement is different from a governing legal document. A governing legal document is different from a regulatory record. And all of them are different from an independent third-party attestation.
Combining them into a single confidence score may look convenient, but it hides the most important part of the analysis: why you believe a particular fact.
Consider the statement:
The token is backed by underlying securities.
Depending on the evidence, that might mean:
- the issuer says it is backed;
- the legal documents create a claim to those securities;
- a custodian confirms holdings;
- an independent report verifies a balance;
- or some combination of those.
Those conclusions should not be silently treated as equivalent.
“Unknown” is sometimes the correct answer
Risk analysis becomes dangerous when missing evidence is automatically translated into a positive conclusion.
If you cannot establish that a contract can freeze tokens, that does not necessarily prove freezing is impossible.
If you cannot find a redemption restriction, that does not prove redemption is unrestricted.
If the documentation does not clearly establish who has priority over backing assets in an insolvency, “safe” is not an acceptable substitute.
For RWA analysis, uncertainty is information.
A disciplined report should distinguish between:
- facts that have been established;
- claims made by an issuer or other party;
- and questions that remain unresolved.
That may be less satisfying than a green checkmark, but it is considerably more useful.
A better way to think about RWA due diligence
A tokenized asset sits at the intersection of several systems.
There is the blockchain implementation.
There is the legal instrument.
There is the issuer and intermediary structure.
There is the backing or underlying asset.
There is the redemption and eligibility framework.
And there is the evidence used to establish each of those facts.
The mistake is evaluating only one layer and assuming it describes the others.
A token contract can be technically sound while the legal claim is weak or poorly understood. A strong legal structure can still contain meaningful transfer controls. High-quality backing does not guarantee that every holder can redeem. Self-custody does not necessarily make an offchain ownership register irrelevant.
The token is important.
It just is not the entire asset.
Why this analysis is difficult to do manually
None of these checks is impossible on its own.
The difficulty is that the evidence is fragmented.
Smart-contract behaviour lives onchain. Legal rights live in offering documents, prospectuses and agreements. Backing information may be published separately. Eligibility and redemption terms can change over time. The issuer, custodian and platform may be different legal entities. Regulatory records can add another layer of context.
A useful analysis therefore has to reconcile those sources without collapsing their provenance.
That is one of the problems we are working on at OnChainRisk: building structured, evidence-backed analysis of tokenized assets while keeping onchain observations, issuer claims, legal evidence and unresolved questions clearly separated.
Because in RWA markets, knowing that a token exists is easy.
Knowing exactly what you own is the harder problem.
RWA Due-Diligence Checklist
A compact synthesis of the questions above. Establish each for any tokenized asset — and record what remains unknown rather than assuming a positive answer.
- Legal claim — what the holder actually owns (fund share, note, beneficial interest, certificate), not just what the token tracks.
- Issuer & entities — the exact legal entity that owes the obligation; map platform vs issuer vs fund/SPV vs broker vs custodian vs transfer agent.
- Authoritative record — which record controls if the onchain balance and the legally maintained ownership register diverge.
- Backing evidence — what the backing is, who owns and holds it, how often its composition is disclosed, how it is valued, and whether liabilities sit ahead of holders.
- Redemption rights & eligibility — who can actually redeem, KYC/eligibility rules, jurisdictions, minimums, settlement asset and timing — separate from secondary-market liquidity.
- Token controls — pausing, freezing, forced transfers, seizure, minting/burning, upgradeability or whitelisting; who holds those roles and under what circumstances.
- Implementation — the mechanism that actually governs the asset (proxy, permissioned standard, compliance module, or native), not an assumed ERC-20.
- “Regulated” — in what sense — exactly what is regulated (issuer, custodian, fund, offering or venue), under which jurisdiction and framework.
- Provenance of each fact — label every conclusion: onchain observation, issuer claim, governing legal document, regulatory record, or independent attestation.
- Unknowns — record unresolved questions explicitly; missing evidence is not proof of a positive answer.