EST · MMXXVI
Home/Insights/Tax/Real-world asset tokenization: A Cross-jurisdiction Comparison
DeFi, Tokenization & Smart-Contract Law

Real-world asset tokenization: A Cross-jurisdiction Comparison

Real-world asset tokenization: A Cross-jurisdiction Comparison. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Tal

Real-world asset tokenization – the process of issuing a blockchain-based token that represents ownership rights, economic interests or claims over a tangible or financial asset – sits at the intersection of securities law, property law, tax regulation and the emerging VASP (virtual asset service provider) licensing regimes that now govern digital-asset markets across the major financial centers. The legal risk is concrete: a token issued without proper classification analysis can convert what was intended as a product launch into an unregistered securities offering, with consequences that reach across every jurisdiction where the token is marketed or traded. This page provides a cross-jurisdiction comparison of the key legal questions that arise when a business tokenizes a real-world asset, drawing on the regulatory regimes that matter most to operators building at scale.

The central classification question – whether a real-world asset token is a security, an asset-referenced token, a utility instrument or something else entirely – is answered differently in every major jurisdiction. No single legal label travels cleanly across borders. The token that qualifies as a utility instrument under one regime may constitute a regulated security under another and trigger e-money authorization requirements under a third. For any cross-border issuance, the analysis must be run in parallel, not sequentially.

What Is Real-World Asset Tokenization and Why Does Classification Matter?

Real-world asset tokenization is the technical and legal process of anchoring a digital token on a blockchain to a right, claim or economic interest in an underlying asset – real estate, private credit, commodities, fund units, receivables or intellectual property among others. The token is not the asset itself; it is a contractual or property-law instrument that represents a defined relationship to that asset. Classification determines the entire regulatory pathway: which license the issuer needs, which disclosures it must make, which investors may hold the token, and which transfer restrictions apply.

The classification exercise is substance-driven, not label-driven. A common and costly assumption is that placing a utility label on a whitepaper settles the legal question. It does not. Every major regulator – ESMA under MiCA, the SEC under its existing securities laws, the SFC in Hong Kong, MAS in Singapore – looks to the economic substance of the rights the token confers. If those rights include profit participation, a claim on the issuer's assets or exposure to the issuer's business risk, the token is likely to be analyzed as a security regardless of what the whitepaper calls it. In our practice, we assess classification against the substance of rights at the instrument-design stage, before any whitepaper is published.

The cross-border dimension compounds the risk. A tokenization project headquartered in Switzerland may issue tokens to investors in the EU, trade them on an exchange licensed in Dubai, hold the underlying asset in a Cayman special-purpose vehicle and use a Singapore entity as the distribution agent. Each leg of that structure attracts a different regulatory regime. The issuer's liability in each jurisdiction depends on what the token looks like to that jurisdiction's regulator – not what it looks like to the issuer.

CTA #1: The classification analysis shapes every decision that follows – structuring, licensing, disclosures, transfer restrictions. If you are at the instrument-design stage, the cost of an early legal assessment is a fraction of the cost of restructuring after a regulatory inquiry. To map the classification, licensing and structuring questions for your tokenization project, contact OBOLUS at info@oboluslaw.com.

How Does MiCA Treat Real-World Asset Tokens in the EU?

Under the EU's MiCA (Markets in Crypto-Assets Regulation), a real-world asset token that references the value of one or more assets – fiat currencies, commodities, other crypto-assets, or a basket – falls within the definition of an asset-referenced token (ART), triggering an issuer authorization requirement overseen by ESMA and the relevant national competent authority. If the token references only a single fiat currency and is used as a means of payment, it is classified as an e-money token (EMT), pulling in e-money authorization requirements. Tokens that do not meet either definition may qualify as "other crypto-assets" subject to a whitepaper notification regime.

The ART authorization path is the most demanding in the MiCA structure. The issuer must be a legal entity authorized in a member state, publish a detailed whitepaper approved by the national competent authority, maintain reserve assets backing the outstanding token supply, comply with redemption rights obligations and meet governance and capital requirements set by the applicable regime. Passporting then allows the authorized issuer to offer the ART across the EU and EEA without separate authorization in each member state – a significant structural advantage over the patchwork that preceded MiCA.

The classification boundary between an ART and a security token under existing EU financial instruments law (MiFID II) is not always clean. A token that references a commodity but also confers profit rights or voting rights over the issuing entity may be caught by MiFID II as a transferable security rather than by MiCA as an ART. MiCA expressly carves out instruments that qualify as financial instruments under MiFID II. Operators who designed their token as an ART to avoid securities regulation may find, on analysis, that the instrument's rights push it across the MiFID II boundary. We see this issue regularly in inbound EU structuring mandates.

For operators outside the EU who issue tokens to EU investors or list on EU-accessible platforms, the MiCA regime may still apply on a jurisdictional reach basis. The analysis turns on where the offer is directed and where the token is traded – not merely where the issuer is incorporated.

Does a Real-World Asset Token Constitute a Security Under US Law?

In the United States, a real-world asset token is likely to be analyzed as a security by the SEC if it involves an investment of money in a common enterprise with an expectation of profit derived from the efforts of others – the classic Howey test framework applied to digital instruments. No formal SEC rule classifies token types; the analysis is fact-specific and applied token by token. The practical consequence is significant: an issuer who cannot confidently conclude that its RWA token falls outside the securities definition must either register the offering or identify a valid exemption, and must ensure that any trading venue where the token appears is registered as a national securities exchange or operating under a valid broker-dealer or alternative trading system framework.

The CFTC's jurisdiction is also relevant where the underlying asset is a commodity – including certain crypto-assets and precious metals. A token that references the price of a commodity without transferring title to that commodity may attract CFTC oversight as a derivative. The parallel jurisdiction between the SEC and CFTC over digital-asset instruments has not been resolved by statute as of the current regulatory environment, creating a layer of genuine structural uncertainty for issuers.

State-level money-transmitter licensing, administered in the leading financial states by regulators including the NYDFS (which operates the BitLicense framework for digital-asset businesses), adds a further dimension. A token that functions as a payment instrument or stablecoin in New York may require NYDFS authorization independent of any federal securities determination. Operators distributing RWA tokens to US persons must account for all three layers – federal securities, federal commodities, and state money-transmission – in any US-facing structure.

How Do Singapore and Hong Kong Regulate Real-World Asset Tokenization?

Both Singapore and Hong Kong have developed active RWA tokenization markets supported by regulatory guidance, but the licensing pathways differ in structure and the classification analyses diverge at key points.

In Singapore, the MAS (Monetary Authority of Singapore) applies its securities laws to determine whether a token constitutes a capital markets product – including a share, debenture, unit in a collective investment scheme or a derivative. A real estate token that confers fractional ownership rights over an asset or a pass-through economic interest in rental income is likely to be analyzed as a collective investment scheme interest or a debenture, requiring the issuer to either register a prospectus or rely on an exemption under the applicable legislation. The MAS has published guidance on digital token offerings that addresses the classification question directly, and the Payment Services Act governs DPT (digital payment token) services separately from capital-markets activities. For most RWA tokens, the capital-markets analysis is the primary regulatory constraint; the DPT framework governs trading infrastructure.

In Hong Kong, the SFC (Securities and Futures Commission) has taken a comparably assertive position on tokenized securities. The SFC's position is that a token representing rights in an underlying investment asset – whether real estate, a fund or a structured product – is a security and must be issued and traded in accordance with Hong Kong securities laws. The SFC's VASP licensing regime for virtual-asset trading platforms adds a second layer: any exchange that lists security tokens must be properly licensed. The SFC has published a series of circulars addressing tokenized investment products, reflecting active regulatory engagement with the RWA market.

For an operator choosing between Singapore and Hong Kong as an Asian hub for an RWA tokenization program, the comparison turns on several axes: the depth of the existing investor base, the tax treatment of the underlying asset and the token distribution, the licensing costs and timelines, and the availability of banking for the issuing entity. Both jurisdictions offer sophisticated legal infrastructure and English-language courts. In our cross-border practice, we see operators choosing Singapore for its well-developed fintech sandbox environment and Hong Kong for its proximity to mainland Chinese capital flows – though both remain attractive and neither is categorically superior for all RWA profiles.

What Is the Position Under VARA and the ADGM Regime in the UAE?

The UAE offers two distinct regulatory regimes for RWA tokenization: the VARA framework in mainland Dubai and the FSRA framework within the ADGM free zone in Abu Dhabi, each with its own activity-based license structure and token classification approach.

Under the VARA (Virtual Assets Regulatory Authority) regime, virtual assets are defined broadly, and VARA's activity-based licensing structure covers advisory, broker-dealer, custody, exchange, lending, management and transfer/settlement services involving virtual assets. A real-world asset token that functions as an investment product – conferring economic rights in underlying real estate, commodities or credit – is likely to require the issuer and any intermediary to hold the relevant VARA activity licenses. VARA has issued detailed rulebooks governing each licensed activity, and the regime applies to mainland Dubai operations, excluding the DIFC financial free zone.

The FSRA within the ADGM operates a separate recognized virtual asset framework. The FSRA maintains a list of recognized virtual assets, and activities involving those assets require authorization. The ADGM is a common-law jurisdiction with English-language courts – the ADGM Courts – and its legal infrastructure is designed to support complex cross-border transactions. For RWA issuers seeking a hub that combines regulatory clarity, tax neutrality and strong dispute-resolution infrastructure, the ADGM offers a compelling combination.

A practical note on the cross-border structure: many RWA tokenization programs use a UAE entity as the issuer or distribution vehicle while holding the underlying asset in a Cayman or BVI special-purpose vehicle and listing the token on exchanges licensed in Singapore or Europe. Each leg of that structure must be analyzed for regulatory compliance in its own jurisdiction. The UAE entity's VARA or FSRA authorization covers its activities in the UAE; it does not create a passport into other jurisdictions.

How Do Offshore Structures – BVI and Cayman – Interact With RWA Tokenization?

The BVI and Cayman Islands remain heavily used as SPV jurisdictions for RWA tokenization programs, primarily for their tax-neutral treatment of capital flows, their flexible corporate law and their well-established relationships with institutional investors – but both jurisdictions now operate active VASP registration regimes that issuers must account for.

Under the BVI FSC's regime, entities carrying on VASP activities from within the BVI – including the issuance of virtual assets – are required to register under the VASP Act 2022. A Cayman SPV that issues tokens and conducts relevant activities may similarly fall within the CIMA (Cayman Islands Monetary Authority) registration or licensing requirements under the Virtual Asset (Service Providers) Act. The common assumption that an offshore SPV used solely to hold an underlying asset and issue tokens against it escapes VASP regulation is not reliable without a specific legal analysis of the activities conducted from within the jurisdiction.

The more common and defensible structure is to use the BVI or Cayman entity as a pure asset-holding vehicle, with the token issuance and distribution activity conducted by a separately incorporated and licensed entity in a regulated jurisdiction such as Singapore, the ADGM or the EU. This separation of the asset-holding and distribution functions allows each entity to be analyzed within its own regulatory perimeter – a cleaner structure that is easier to defend on examination.

Tax treatment of the offshore structure requires separate analysis in each relevant jurisdiction. The token holder's jurisdiction taxes the economic income from the token; the issuer's jurisdiction taxes the entity's activities; the underlying asset's jurisdiction may impose withholding on distributions or capital gains on disposal. No universal answer exists, and the interaction of these layers is one of the more technically demanding aspects of cross-border RWA structuring.

In a recent structuring matter, a fund manager seeking to tokenize a portfolio of private credit assets used a Cayman holding vehicle for the underlying loan book and a Singapore-incorporated issuer for the token distribution. We advised on the token classification under the MAS framework, the interaction between the Cayman VASP Act and the SPV's activities, and the withholding tax implications for token holders in three jurisdictions. The structure reached first close within a timeframe consistent with a well-prepared application, and the token was listed on a regulated platform in Asia.

A smart contract (self-executing code deployed on a blockchain that automatically performs defined actions when specified conditions are met) can produce legally binding obligations in most major common-law and civil-law jurisdictions, but its legal effect is determined by the governing law of the underlying transaction – not by the code itself.

The key legal questions are: which jurisdiction's law governs the contract embedded in or implemented by the smart contract code; whether the parties have validly consented to that governing law; and whether the automatic execution of the code satisfies the jurisdiction's requirements for offer, acceptance, consideration and certainty of terms. In England and Wales, Singapore and the DIFC Courts, courts have confirmed that digital assets can constitute property and that on-chain transactions can create enforceable rights. The legal infrastructure in those forums is the most developed for resolving disputes involving smart-contract-based instruments.

For RWA tokens specifically, the smart contract governs core economic functions: distribution of income, enforcement of transfer restrictions, execution of redemption rights and, potentially, governance votes over the underlying asset. Each of those functions is legally significant. If the smart contract contains an error – a bug that causes incorrect distribution, a vulnerability that allows unauthorized transfer, or a governance mechanism that can be manipulated – the question of who bears the legal liability for that error is not answered by the code. It is answered by the governing law of the instrument, the terms disclosed in the whitepaper or token agreement, and the general law of negligence, contract and (where applicable) securities regulation in the relevant forum.

In our technology and DeFi practice, we routinely review smart contract documentation and token agreement terms to identify mismatches between the code's behavior and the legal obligations the issuer has assumed in its disclosure documents. That gap is where liability concentrates.

Which Jurisdiction and Structure Fits Which RWA Profile?

The right structuring choice for an RWA tokenization program depends on the nature of the underlying asset, the investor base, the issuer's existing regulatory footprint and the desired secondary-market liquidity – and no single jurisdiction is optimal for all profiles.

Profile A – Real estate tokenization targeting EU retail investors. The issuer should expect ART or MiFID II security analysis under the MiCA regime, requiring either CASP authorization or a full prospectus depending on the rights conferred. Lithuania or Malta offer relatively accessible EU authorization pathways under MiCA's transitional provisions. The timeline from complete application to authorization varies by category and competent authority; operators should plan for a process measured in months rather than weeks. Key risk: the ART reserve and redemption requirements add operational cost and complexity.

Profile B – Private credit tokenization for institutional investors in Asia-Pacific. Singapore under the MAS Payment Services Act and capital-markets framework is the natural hub. The token is likely classified as a capital-markets product; a prospectus exemption for institutional and accredited investors may be available. Timeline to MAS authorization is typically a matter of months for a well-prepared application. Key risk: the MAS has been selective in granting capital-markets service licenses for novel instruments; the application requires detailed disclosure of the token mechanics and the underlying asset structure.

Profile C – Commodity-backed token for global distribution, issuer based in the UAE. VARA or ADGM/FSRA authorization is the primary licensing path. The token's classification under the applicable VARA rulebook determines which activity licenses apply. Secondary markets in Singapore and the EU require separate analysis. Key risk: the multi-jurisdictional distribution requires parallel regulatory clearance in each target market; the UAE authorization does not substitute for authorization elsewhere.

Profile D – Fund unit tokenization using an offshore holding structure. A Cayman or BVI SPV holding the fund assets, with a separately incorporated and licensed distribution entity in Singapore, Hong Kong or the EU, is the most defensible structure. The offshore SPV's activities must be analyzed for local VASP registration requirements. Key risk: the interaction of the offshore holding structure with the investors' home-jurisdiction tax treatment can erode the economic case for tokenization if not addressed at the design stage.

CTA #2: If a prior tokenization structure was challenged or a proposed design has drawn regulator questions, a second structural review can identify the gap and map a remediation path. We have seen structures that were well-designed on the surface but exposed on the asset-holding or distribution leg. Write to info@oboluslaw.com to arrange a scoped review.

What Are the Most Common Legal Mistakes in RWA Tokenization Programs?

The most frequently recurring legal error in RWA tokenization programs is treating the token classification as a marketing decision rather than a legal one – designing the instrument around a preferred label and then seeking legal confirmation, rather than beginning with the rights analysis and designing the instrument to fit the target classification.

A second error is failing to analyze the full chain of regulated activities. Token issuance may itself require authorization, but so may secondary trading, custody, lending against the token, and the management of the underlying asset vehicle. An issuer who obtains authorization for the issuance activity but neglects the custody or trading activities may find that every exchange where the token lists independently needs to be licensed in jurisdictions where the token is accessible.

A third error is the assumption that a DAO structure removes regulatory accountability. Where a decentralized autonomous organization controls the management of an underlying asset pool or governs the distribution of token proceeds, regulators in the leading jurisdictions have increasingly taken the position that the DAO's governance participants – or the promoters who established the DAO – bear regulatory responsibility for the activities the DAO conducts. Wrapping a DAO in an appropriate legal structure is a substantive requirement, not a formality. We address this directly in our comparative analysis of DAO legal wrappers.

A fourth error is cross-border distribution without jurisdiction-by-jurisdiction analysis. The issuer's home-jurisdiction authorization does not create a passport into markets where the token is accessible. Each jurisdiction where the token is offered to, or traded by, residents requires its own analysis. Geo-blocking that is technically easily circumvented does not satisfy this requirement in most regulatory environments.

How Do AML and the Travel Rule Apply to RWA Token Transfers?

Real-world asset tokens transferred on public or permissioned blockchains are subject to the Travel Rule (the FATF Recommendation 15 obligation requiring VASPs to pass originator and beneficiary identification data with virtual asset transfers above the applicable threshold) in every jurisdiction that has implemented FATF's virtual asset guidance.

Under MiCA and the EU's Transfer of Funds Regulation as extended to crypto-assets, transfers of RWA tokens between VASPs must be accompanied by the required originator and beneficiary data. The threshold for Travel Rule compliance and the technical implementation standards vary by jurisdiction; the de minimis figure is set in the applicable local implementing measures rather than by FATF directly. Singapore under the MAS framework, Hong Kong under the SFC and Anti-Money Laundering ordinance requirements, and the UAE under VARA's AML rulebook all impose parallel Travel Rule obligations.

For RWA tokens that are designed to be transferred peer-to-peer without VASP intermediaries, the AML compliance picture is more complex. Most regulators take the position that the issuer of the token bears responsibility for implementing controls that prevent the token from being used to evade AML requirements, even where direct VASP involvement in individual transfers is absent. This is an area where the regulatory position is still developing across the leading hubs, and issuers should take a conservative approach.

The practical implication for token design is significant. An RWA token that is intended to trade freely on decentralized exchanges without intermediary oversight may face regulatory challenges in every jurisdiction with an active VASP regime. Permissioned transfer mechanisms – whitelisted wallets, on-chain KYC attestations, transfer restrictions enforced at the smart-contract level – are increasingly used to address this constraint, though their legal sufficiency varies by jurisdiction and is not yet definitively settled in most forums.

Related at OBOLUS

FAQ

Can a DeFi protocol be regulated?

A DeFi protocol can fall within the regulatory perimeter of one or more jurisdictions depending on the activities it facilitates – trading, lending, custody, asset management – and the degree to which identifiable persons or entities control, promote or profit from those activities. Regulators in the EU under MiCA, Singapore under MAS, and the UAE under VARA have all signaled that the absence of a central operator does not, by itself, place a protocol outside the regulated perimeter. The relevant analysis turns on who exercises control, who earns fees and who benefits from the protocol's operation, not on the technical architecture.

What legal wrapper suits a DAO?

The appropriate legal wrapper for a DAO depends on the DAO's purpose, the jurisdiction of its principal operations and the regulatory activities it conducts. The most commonly used structures include a Cayman Foundation Company, a Marshall Islands DAO LLC, a Swiss association or a BVI company. Each offers different liability protection, governance flexibility and regulatory treatment. A foundation is frequently used where the DAO manages an asset pool or issues tokens, because it can hold assets, enter contracts and limit member liability without requiring a shareholder structure. The choice has direct implications for tax, AML obligations and the regulators that will assert jurisdiction.

Who is liable when a smart contract fails?

Liability for a smart-contract failure depends on the governing law of the instrument, the terms of the token agreement or whitepaper, the nature of the failure and the parties involved. Where the failure results from a coding error, liability may attach to the developer under contract or tort law. Where it results from a design decision disclosed in the documentation, the issuer's liability may be limited by the terms of the disclosure. Regulators increasingly expect issuers to audit smart-contract code before deployment and to maintain incident-response procedures. In disputes forums including England and Wales and the DIFC Courts, claimants have successfully pursued recovery in on-chain matters by identifying the legally responsible party behind the protocol.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label – the analytical discipline that matters most in RWA structuring. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when transactions go wrong. To discuss your situation, contact info@oboluslaw.com.

CTA #3: To map the licence, banking and tax stack for your RWA tokenization build – or to pressure-test a structure before you commit – message us via t.me/oboluslaw or write to info@oboluslaw.com.

By Lydia Brennan, Tax & Structuring Analyst – specializing in cross-border token structuring, the tax treatment of digital-asset instruments and the interaction between offshore holding structures and onshore regulatory regimes across the EU, Asia-Pacific and the Gulf.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours