EST · MMXXVI
Home/Jurisdictions/Bermuda/Real-world asset tokenization in Bermuda
DeFi, Tokenization & Smart-Contract Law

Real-world asset tokenization in Bermuda

Real-world asset tokenization in Bermuda. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Real-world asset tokenization is one of the most technically demanding exercises in digital-asset law — and Bermuda has built one of the few regulatory regimes (a formal legal structure governing digital-asset activities) that can accommodate it end to end. For a business converting a bond, a real-estate interest, a fund unit or a trade-receivable into a blockchain-native instrument, the first question is not which platform to use. It is whether the resulting token is a security, what obligations attach to its issuance, and which jurisdiction's law governs the smart contract that represents it. Bermuda answers those questions with more precision than most.

This guide walks through the legal basis for real-world asset tokenization under Bermuda law, the step-by-step process for a compliant issuance, the cross-border tax and banking considerations that operators routinely underestimate, and the decision points that determine whether Bermuda is the right choice for a given structure. Every section opens with the direct answer. Figures and timelines are qualitative where the applicable threshold is set by regulation and subject to change.

The regulatory foundation: what Bermuda offers the tokenization operator

Bermuda's digital-asset regime is purpose-built for institutional-grade issuance, not retrofitted from securities law. The Digital Asset Business Act (DABA) and its subordinate regulations, administered by the Bermuda Monetary Authority (BMA), create a licensing and registration framework that explicitly contemplates the issuance of tokens representing rights in underlying real-world assets. That explicit scope matters. In many jurisdictions, a tokenized bond or real-estate interest falls into a gap between financial-markets law and technology law, forcing counsel to construct a compliance position from analogy. Under the BMA regime, the activity-based licensing structure maps more directly onto what tokenization platforms actually do.

The BMA distinguishes between digital asset businesses (entities conducting defined activities as a business) and issuers whose token constitutes a security under Bermuda law. A tokenized instrument that carries equity-like or debt-like rights will ordinarily engage the Companies Act 1981 and the Investment Business Act alongside DABA. The interaction between those regimes is where classification work becomes critical. A mis-classification — labeling a token representing a fractional bond interest as a utility token — does not make the securities requirements disappear. It makes them a latent enforcement risk.

The BMA has also introduced a sandbox pathway for novel structures. For a tokenization model that does not fit neatly into an existing licence class, the sandbox allows limited live operation while the regulatory position is clarified. In our practice, we have seen this pathway used effectively by issuers whose underlying asset class (infrastructure receivables, insurance-linked instruments) sat at the edge of the DABA activity definitions.

For the inbound operator, the practical advantage is this: Bermuda combines common-law contract enforceability, a credible AML/CFT regime aligned with FATF Recommendation 15, and a regulator that engages substantively on novel structures. That combination is rarer than the number of "crypto-friendly" jurisdictions suggests.

The BMA's activity-based licence categories under DABA include issuance services, exchange, custody and related functions — meaning a platform that both issues tokenized assets and holds them in custody will require a licence that spans multiple activity types. The licence scope must be correct before the platform goes live.

Step 1 – Classify the token before anything else

Token classification is the structural foundation of every tokenization project, and getting it wrong at the outset makes every subsequent step more expensive to correct. A token representing a fractional interest in a real-world asset will almost always carry one of three legal characters under Bermuda law: a security (if it confers ownership, profit-sharing or debt-repayment rights), a digital asset within the DABA definitions, or — in narrow cases — a payment instrument. These categories are not mutually exclusive. A token can engage multiple regimes simultaneously.

The classification analysis turns on substance, not label. The rights actually conferred by the token — as written in the smart contract and the underlying legal agreement — determine the category. A common assumption in the market is that placing a "utility" label on a whitepaper settles the legal classification. It does not. Regulators and courts look through the label to the economic reality of what the token holder receives. In our practice, we assess classification against the full rights architecture: governance rights, economic entitlements, redemption mechanics and the nature of the underlying asset.

The cross-border dimension compounds the analysis. A token issued under a Bermuda structure and sold to US persons may engage SEC jurisdiction regardless of the issuer's domicile. A token sold into the EU after MiCA's entry into force will be assessed against ESMA's classification guidance for asset-referenced tokens and "other crypto-assets." The classification work therefore needs to address the issuer's jurisdiction, the offering jurisdiction, and every material secondary-market jurisdiction where the token is expected to trade.

The legal structure that holds the real-world asset and interfaces with the token is as important as the token itself. For most real-world asset tokenization projects, the structure requires at minimum: a special purpose vehicle (SPV) that legally holds the underlying asset, a subscription or participation agreement that creates the investor's rights in the underlying, and a smart contract that represents and transfers those rights on-chain.

Bermuda's company law is flexible on SPV formation. An exempted company or a limited-liability company under Bermuda law can serve as the issuer vehicle. Where the underlying asset is held in another jurisdiction — a real-estate portfolio in the UK, a loan book in Singapore — the structural chain needs to address both the Bermuda issuer layer and the local asset-holding layer. Allied counsel in the relevant jurisdiction will be needed for the local-law leg of that analysis.

For DAO-adjacent structures where governance is distributed among token holders, Bermuda does not yet have a dedicated DAO legislation equivalent to some US state regimes. The practical approach in our experience is to use a Bermuda exempted company with a governance agreement that maps token-weighted voting onto company-law decisions. This creates a legal wrapper that a court can recognize and enforce while preserving the on-chain governance mechanics. The alternative — launching a tokenized asset from a purely unincorporated on-chain structure — creates enforcement and liability exposure that most institutional counterparties will not accept.

CTA #1: The classification and structure steps above describe the standard analytical path. Your facts — the asset type, the investor base, the secondary-market plan — change the analysis in ways that a general framework cannot capture. For a scoped assessment of your tokenization structure, contact OBOLUS at info@oboluslaw.com. Or map your options with our team.

Step 3 – Apply for the BMA licence or registration

Most tokenization platforms operating from Bermuda will require a Class F or Class M licence under DABA, or a combination depending on the activities conducted. Class F covers issuance services as a principal activity; Class M covers a broader set of digital-asset business activities. The BMA also maintains a Class T (transitional) and sandbox track for novel models. Choosing the right class at the outset avoids the cost of a licence variation later.

The application itself requires: a detailed business plan, a description of the tokenized products and their legal classification, AML/CFT policies and procedures, a technology risk assessment, details of the applicant's key personnel and controllers, and evidence of adequate financial resources. The BMA's review is substantive — it is not a rubber-stamp process. Applicants should expect back-and-forth on the business plan and on the token classification analysis. In our experience, the quality of the upfront written submissions significantly affects the length of the review period. Applications that arrive with a clear classification rationale and a well-articulated risk framework move faster than those that defer the hard questions.

The timeline from a complete application to licence grant varies by complexity. Simple structures with clean classification profiles can resolve in a matter of months. Novel products — particularly those involving staking mechanics, DeFi integrations or secondary-market functionality — take longer. Applicants should factor the BMA review period into their go-to-market timeline and not pre-commit to product launch dates that depend on a specific approval date.

A note on capital adequacy: DABA sets financial-resource requirements by licence class. The applicable minimum varies and is subject to BMA discretion based on the specific risk profile of the business. These figures should be confirmed directly with the BMA or through counsel with current practice in the Bermuda market — they are not fixed numbers that remain constant across applicants.

A tokenized real-world asset depends on a smart contract that accurately reflects the legal rights it is supposed to represent. The technical implementation and the legal documentation must be consistent. Where they diverge — and they frequently do, particularly on redemption mechanics, transfer restrictions and event-of-default triggers — the legal documentation controls in most jurisdictions, but the smart contract controls in practice. That gap is a liability.

Under Bermuda law, a smart contract can constitute a binding legal agreement where the elements of contract formation are satisfied. The Electronic Transactions Act and the broader common-law framework support this. However, a smart contract that executes automatically and irreversibly creates particular challenges when the underlying legal obligation it represents is subject to conditions, disputes or regulatory restrictions. A legal override mechanism — a documented process by which the issuer or a court can halt or reverse on-chain transfers — should be built into the structure for any asset class that carries material regulatory or enforcement risk.

Transfer restrictions are a specific concern for tokenized securities. If the underlying asset is a security under Bermuda law, the token representing it will carry transfer restrictions tied to securities law: no transfers to persons in jurisdictions where the token is not registered, no transfers in violation of lock-up provisions, no transfers that breach OFAC or equivalent sanctions. These restrictions must be encoded into the smart contract, documented in the legal agreements, and monitored operationally. A smart contract that permits unrestricted transfers of a tokenized security is not a compliance feature — it is an enforcement problem.

Step 5 – Address the cross-border tax and banking stack

Bermuda imposes no corporate income tax, capital gains tax or withholding tax on Bermuda entities in the ordinary case — a structural advantage that makes it a natural domicile for the issuer SPV in a multi-jurisdictional tokenization structure. That advantage is real but frequently overstated in its simplicity. The tax position of the token holders, the asset-holding entity in the underlying asset's jurisdiction, and any distribution or dividend flows are all governed by the laws of their respective jurisdictions, not by Bermuda's tax neutrality.

A real-estate tokenization project, for example, might have a Bermuda issuer SPV, a UK property-holding company and EU-domiciled token holders. The Bermuda layer faces no local tax on its income. The UK property company faces UK corporation tax on rental income and UK SDLT on acquisition. The EU token holders face their home jurisdiction's treatment of digital-asset income — which under MiCA and the DAC8 directive (requiring crypto-asset reporting by EU service providers) is increasingly visible to local tax authorities. The Bermuda structure does not insulate the other layers.

Banking is a parallel challenge. Bermuda-domiciled tokenization entities can access banking services locally, but the number of Bermuda banks with appetite for digital-asset business is limited. Most operators maintain the Bermuda issuer SPV with Bermuda banking for local operational needs while routing substantive treasury through allied banking relationships in other jurisdictions. Establishing those relationships before the licence is granted — not after — is the practical discipline we advise. Banks in the major hubs that serve digital-asset businesses conduct their own diligence on the issuer's regulatory status, and a licence in hand from a credible regulator like the BMA materially improves the conversation.

CTA #2: If a prior banking application for a tokenization structure stalled, or a cross-border tax analysis produced unexpected exposure, a structural review can often surface the issue and the route to resolution. To map the licence, banking and tax stack for your build, write to info@oboluslaw.com or message us via t.me/oboluslaw. You can also map your options directly.

Step 6 – Build and operate the AML/CFT and Travel Rule framework

Bermuda's AML/CFT obligations for digital-asset businesses are aligned with FATF Recommendation 15, which requires that VASPs implement customer due-diligence, transaction monitoring and suspicious-activity reporting obligations equivalent to those of traditional financial institutions. For a tokenization platform, the practical implementation involves: identifying token holders at subscription, applying enhanced due diligence for high-risk profiles, monitoring on-chain transfers for unusual patterns, and reporting to the Financial Intelligence Agency (FIA) where required.

The Travel Rule (the FATF obligation to pass originator and beneficiary identification data with a virtual-asset transfer) applies to transfers above the applicable threshold. For a tokenized-asset platform that processes secondary-market transfers, the operational implication is significant: every transfer of the tokenized instrument between wallets must be screened for Travel Rule applicability, the counterparty VASP must be identified, and the required data must be transmitted. In practice, this requires integration with one of the available Travel Rule data-transmission solutions and a compliance workflow that operates in near real time.

Sanctions screening applies on an ongoing basis, not only at onboarding. A token holder who was clean at subscription may subsequently appear on an OFAC or UK/EU sanctions list. The platform's compliance framework must include a periodic screening refresh and a documented process for responding to a match — including, where applicable, seeking guidance from the BMA and the relevant sanctions authority before taking any action that could itself constitute a sanctions violation.

A recent matter and the decision point for incoming operators

In a recent tokenization matter, a structured-finance operator sought to issue tokenized trade receivables from a Bermuda SPV to a pool of institutional investors across three jurisdictions. The token was initially drafted as a utility instrument. On analysis, the rights conferred — a pro-rata interest in receivable proceeds, with no active participation required — engaged the securities analysis under Bermuda law and the equivalent analysis in two of the three investor jurisdictions. We advised on re-characterizing the legal documentation, restructuring the transfer restrictions in the smart contract, and sequencing the BMA application to lead with a complete classification memorandum. The issuer obtained its licence and launched its first offering to the institutional market within the planned timeline.

The decision point for an inbound operator comes down to three questions. First, does the underlying asset class fit within the BMA's activity definitions, or does it require a sandbox engagement? Second, is the investor base primarily institutional — in which case Bermuda's credibility with institutional counterparties is a direct commercial advantage — or does it include retail participants in jurisdictions with their own offering restrictions? Third, does the operator have or can it build the operational infrastructure for BMA-standard AML/CFT compliance, or would a lighter-touch registration regime in another jurisdiction better match its current compliance maturity?

Bermuda is not the cheapest or the fastest tokenization jurisdiction. It is, however, one of the few that provides genuine regulatory certainty for institutional-grade issuance alongside common-law enforceability, FATF-compliant AML and a credible appellate court system. For an operator whose product will be sold to regulated institutions, pension funds or sophisticated family offices, that combination frequently justifies the investment in the BMA process.

What goes wrong: the five most common mistakes in Bermuda tokenization projects

Misclassification at the design stage is the most consequential error — and the most common. A project that begins with a utility-token assumption and builds its smart contract, investor documentation and marketing materials on that assumption faces a full rebuild if the classification changes during BMA review. The classification analysis should be the first deliverable, not an afterthought.

The second mistake is treating the Bermuda licence as a global passport. A BMA licence authorizes activity under Bermuda law. It does not authorize the offer or sale of tokenized securities in the US, EU or any other jurisdiction. Secondary-market trading by persons in regulated jurisdictions engages the laws of those jurisdictions. The offering memorandum and the smart-contract transfer restrictions must together enforce the geographic limits of the offering.

Third, many operators underestimate the operational cost of Travel Rule compliance for secondary-market transfers. Building the technical integration after the platform is live is significantly more expensive than designing for it from the outset. The compliance architecture should be scoped as part of the initial technology design, not as a post-launch addition.

Fourth, the relationship between the legal documentation and the smart contract is frequently under-specified. The two instruments must be consistent. Where the smart contract is intended to be the authoritative instrument for transfer, the legal documentation must say so explicitly and address what happens when on-chain execution is technically impossible or legally prohibited. Where the legal documentation controls, the smart contract must not be capable of executing transfers that the legal documentation prohibits.

Fifth, banking is left to the end of the process. Establishing banking relationships for a Bermuda tokenization entity is a structured process that takes time. Starting that process at the time of the BMA application — not after the licence is granted — avoids the operational gap between regulatory approval and commercial launch.

Related at OBOLUS

FAQ

Can a DeFi protocol be regulated?

Yes — and increasingly it is. The legal analysis turns on whether the protocol has identifiable operators, developers or governance participants who exercise control over the system. Where human actors make material decisions about the protocol — even through on-chain governance — regulators in the major hubs treat those actors as potentially subject to licensing and AML obligations. Bermuda's DABA regime, like MiCA in the EU, is activity-based: what matters is what the protocol does and who controls it, not how it is labeled.

What legal wrapper suits a DAO?

No single wrapper is universally correct. Bermuda offers the exempted company structure, which can accommodate token-weighted governance through a bespoke governance agreement. The US Marshall Islands DAO LLC and Wyoming DAO LLC are alternatives with different trade-offs on liability insulation and regulatory recognition. The right choice depends on the DAO's asset base, its investor profile, whether it needs to enter contracts with regulated institutions, and which jurisdictions its members are in. We advise on the full menu before recommending a specific structure.

Who is liable when a smart contract fails?

Liability in a smart-contract failure is determined by the legal documentation governing the instrument, the applicable law of the issuing entity's jurisdiction, and the specific cause of the failure. Developers may face liability in tort if the failure resulted from negligence. Issuers may face liability in contract if the smart contract was the agreed mechanism for performing a contractual obligation. Bermuda common law applies general principles of contract and tort; a well-drafted legal agreement will address the allocation of technical risk explicitly, including which party bears the cost of a remediation or reissuance process.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights conferred, not the marketing label — a discipline that has protected clients from unregistered-offering exposure at the design stage. We work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where recovery is at issue. To discuss your tokenization structure or a live compliance question, contact info@oboluslaw.com.

By Roman Levitt, Technology & DeFi Counsel — specializing in smart-contract legal architecture, token classification and DeFi regulatory analysis for digital-asset issuers and protocol operators.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours