Putting a real-world asset onchain is easy if the token is only a technical demonstration. Putting it into production means making eight systems agree: the law, the ownership record, investor eligibility, money, custody, asset servicing, trading and exit.

That distinction matters because a token can move perfectly while the legal asset does not. It can settle in seconds while the cash arrives two days later. It can trade around the clock while the transfer agent, paying agent or fund administrator still works to a business-day cut-off. Production begins when the whole operating chain works, including its exceptions.

Proof of Talk Paris 2026 placed this question on the agenda through The Tokenisation of Everything: RWAs, Institutions, and the Next Market Structure. The published record says that Julien Clausse, John Nahas, Joseph Bruzzesi and Nenter Chow joined moderator Yana Prikhodchenko on day two, 3 June 2026. It does not provide a transcript or recording. Nothing in this article is attributed to what they said on stage. The session establishes what Paris scheduled; the evidence below comes from dated filings, regulators and official product documentation.

This is also deliberately different from our broader analysis of the institutional tokenisation debate in 2026. The question here is narrower: what has to be built, contracted and operated before an RWA token can survive production?

Start with the claim, not the chain

The first design decision is not Ethereum versus a private ledger. It is what the holder owns and which record a court will treat as authoritative.

A token can be the security itself, an entry in the issuer's official register, an entitlement to an asset held through an intermediary, or a separate instrument that merely tracks another asset. Those structures are not interchangeable. In a 28 January 2026 staff statement, three US Securities and Exchange Commission divisions distinguished issuer-sponsored tokenised securities from third-party custodial and synthetic models. The staff warned that a third-party token may confer no rights against the issuer of the referenced security and may add exposure to the third party's bankruptcy. The statement itself says it has no legal force, so it is a useful taxonomy, not permission to launch.

Before code is commissioned, counsel and the product owner should produce a rights map answering:

  • Who is the issuer, special-purpose vehicle, trustee or fund?
  • Does the token represent direct ownership, a security entitlement, a beneficial interest, debt, a fund share or contractual exposure?
  • Which document creates that right, and under which governing law?
  • Which record is authoritative if the blockchain, transfer agent and custodian disagree?
  • Are assets segregated from the issuer, platform and custodian on insolvency?
  • Who can correct the register after fraud, a court order or a lost key?

The cleanest production examples state the answer explicitly. The Franklin OnChain U.S. Government Money Fund prospectus dated 1 August 2026 says its transfer agent maintains the official record of share ownership through a blockchain-integrated system. It also says the transfer agent retains full control, can limit transfers and can correct erroneous or unauthorised transactions by appending a correcting instruction. The legal product remains a registered government money market fund. The blockchain is part of its recordkeeping machinery, not a substitute for the fund, its board or the Investment Company Act.

1. Engineer issuance around the authoritative register

Once the claim is fixed, issuance becomes a controlled state transition: subscription accepted, cash confirmed, units calculated, official register updated and tokens minted or allocated. Every step needs an owner, a timestamp and a reversal procedure.

The issuance policy should specify maximum supply, denomination, mint authority, approval thresholds, permitted networks, contract upgrade rights and reconciliation frequency. It should also define what happens if the chain reorganises, fees spike, an oracle fails or minting succeeds while the registrar update fails. A mint transaction hash is evidence of a technical event. It is not, by itself, evidence that legally valid issuance occurred.

Franklin's prospectus offers a practical control pattern. Its transfer agent creates or approves investor wallets, maintains the official ownership record and uses a fee model under which the investment manager or its affiliates pay network fees for transactions made through the app or institutional portal, while investors pay fees for transactions signed directly from investor-managed wallets. The filing says Stellar is the primary network, while Polygon, Aptos, Avalanche, Arbitrum, Ethereum, Solana and Base may be available to certain accounts subject to eligibility and approval. That is multichain distribution under one administrative authority, not independent supplies on eight chains.

Production teams therefore need a daily, and preferably event-driven, reconciliation among:

  1. issued legal units or principal amount;
  2. the registrar or transfer agent's master record;
  3. tokens outstanding on every supported network;
  4. positions reported by custodians and distributors; and
  5. cash and asset balances supporting creation and redemption.

Any unexplained difference should stop minting, transfers between networks or redemptions according to a documented severity matrix. Immutability does not remove reconciliation. It makes discrepancies easier to preserve.

2. Bind identity to eligibility, then keep checking it

Institutional onboarding is more than knowing a wallet's owner. Eligibility can depend on legal form, domicile, sanctions status, investor category, distribution jurisdiction, concentration limit, tax documentation and the authority of the person instructing the trade.

The production pattern is to keep personal and commercial data offchain, bind an approved identity to one or more wallet addresses, and expose only the minimum credential or status needed for a transfer decision. The status must be revocable. A wallet approved yesterday may be ineligible today because a document expired, control changed or sanctions screening produced a match.

Open standards show how the pieces can connect. GLEIF says the verifiable Legal Entity Identifier, standardised in ISO 17442-3 in 2024, can cryptographically connect an entity's LEI, an individual's identity and that person's official organisational role. ERC-3643 defines a permissioned token interface in which each transfer checks an identity registry and compliance rules before execution, with functions for freezing, pausing, recovery, minting and burning. Neither standard performs customer due diligence by itself. They provide credentials and enforcement interfaces; a regulated firm remains responsible for onboarding and monitoring.

Franklin's filing makes the restriction concrete: only wallets created or approved by the transfer agent may purchase, hold, receive, transfer or redeem fund shares. Both parties to a peer-to-peer transfer must have active, permissioned wallets. That turns compliance from a front-door form into a lifecycle control.

3. Design the cash leg as part of the asset

An asset token without an integrated payment process is half a settlement system. The operator must decide what money the buyer delivers, where it is held, when it becomes final and whether delivery of the asset is conditional on receipt of cash.

The main choices are commercial bank money through existing payment rails, tokenised deposits, regulated stablecoins and wholesale central bank money where available. Each brings a different issuer, redemption promise, operating window and credit exposure. The correct choice follows the asset, jurisdiction and investor mandate, not the fashionable rail.

Delivery versus payment is the control objective: either both legs become final or neither does. If the asset moves onchain but money moves through a separate bank process, an orchestration layer must reserve the asset, confirm funds, release both legs and manage timeouts. Legal settlement finality must match the technical sequence.

A dated production example shows the difference. On 3 September 2024 Siemens issued a €300 million, one-year digital bond under Germany's Electronic Securities Act. DekaBank acted as registrar, five German banks invested, the security settled on SWIAT's private permissioned blockchain, and Deutsche Bank handled Siemens' central-bank-money settlement through the Bundesbank Trigger Solution. Siemens said the process completed within minutes; its first €60 million blockchain bond in 2023 had required two-day settlement.

That transaction was real, but it was also part of Eurosystem trials. The wider Eurosystem exercise concluded on 4 December 2024 after more than 200 transactions worth €1.59 billion, involving 64 participants. Some were trials with actual central bank money and others were experiments using mock settlement. A production claim should preserve that distinction.

4. Separate custody of the token from custody of the asset

Custody has at least three layers: control of private keys, safekeeping of the legal asset or collateral, and maintenance of the ownership record. One firm may perform all three, but the contracts should never assume that it does.

For a tokenised fund share, the wallet custodian protects signing keys while the fund custodian safeguards portfolio assets and the transfer agent determines registered ownership. For tokenised real estate, a wallet key does not hold the building; the property-owning vehicle, land register, bank accounts and corporate records still matter. For a custodial wrapper, the holder also depends on the intermediary that owns or controls the underlying asset.

The custody design should document key generation, hardware and software boundaries, signing quorums, transaction policies, address allowlists, recovery, segregation, sub-custodians, insurance scope and insolvency treatment. It should identify who can freeze or force-transfer a position and under what legal authority.

Franklin permits both transfer-agent-hosted wallets and, for eligible institutional investors, approved investor-managed wallets. In the former, the transfer agent holds the key. In the latter, the investor or its third-party wallet custodian does. Yet the transfer agent says it can correct the ownership record in either case. That is a useful reminder: control of a key and final legal authority over a fund register are different powers.

5. Build servicing before launch day

The token must survive the asset's lifecycle, not just its initial sale. Bonds need interest calculation, payment dates, record dates, tax handling, notices, amendments, defaults and principal repayment. Funds need valuation, subscriptions, redemptions, income allocation, fee accruals and reporting. Private credit needs covenant monitoring, payment waterfalls, waivers and workouts. Real estate needs rent collection, expenses, valuations and corporate governance.

For every event, define the source of truth, calculation agent, cut-off, instruction path, onchain action, cash action and correction route. Smart contracts may automate a calculation or distribution, but an authorised party still has to approve inputs and handle exceptions. Oracle governance is therefore service-provider governance: who publishes a rate or valuation, what happens when it is late, and which value wins after a correction?

The Franklin prospectus illustrates how detailed servicing becomes. It states that after a peer-to-peer transfer, the transfer agent allocates intraday income between transferor and transferee according to how long each held the shares during that net asset value cycle. That is not decorative programmability. It is the operating rule that prevents a continuously transferable income-bearing instrument from allocating the whole day's dividend to the wrong holder.

6. Treat secondary liquidity as a separate product

Transferability is not liquidity. A token may be technically transferable yet have no venue, market maker, price formation, settlement access or eligible counterparty ready to buy it.

Franklin permits transfers between active, permissioned wallets at any time, but its August 2026 prospectus is explicit that these transfers do not constitute a public trading market. The filing says no current agreement exists to make shares available for trading in a secondary market, a feature that may never become available. That is controlled mobility, not exchange liquidity.

A production plan for secondary trading must answer who operates the venue, which licence covers it, who may participate, how orders are matched, whether the asset and cash settle atomically, how market abuse is monitored and how the official register receives final positions. In the EU, the ESMA list of authorised DLT market infrastructures is the relevant starting point, not a platform's marketing page. The DLT Pilot Regime has applied since 23 March 2023 and permits authorised DLT multilateral trading facilities, settlement systems, and combined trading and settlement systems within defined conditions and thresholds.

The US route can preserve familiar market structure. On 18 March 2026 the SEC approved Nasdaq's rule change allowing eligible securities to trade in tokenised form during DTC's pilot. The order describes trading through Nasdaq and post-trade processing through DTC for eligible participants and securities. It is an integration path, not evidence that every RWA token can list on Nasdaq.

7. Make redemption the primary acceptance test

Redemption proves whether the token connects back to the legal asset and cash. It should be tested before issuance, then rehearsed under normal, stressed and failed conditions.

The procedure must state who can redeem, minimum amounts, cut-offs, valuation point, fees, required notices, wallet destination, bank-account controls and when tokens are burned or blocked. It must prevent double use while a redemption is pending. If underlying assets must be sold, the liquidity terms offered to token holders cannot be faster than the portfolio can support without a committed facility or someone taking principal risk.

Test at least five failure cases: a lost key, a sanctioned holder, a closed bank account, a chain outage and a discrepancy between token supply and the register. Add death, insolvency, court order and mistaken transfer where the investor base makes them relevant. The runbook should identify the human decision-maker, not merely return an error code.

A production token is redeemable under law, operations and stress. A pilot token is merely movable when everything works.

The minimum production dossier

Before approving launch, an investment committee, issuer board or regulated operator should be able to inspect one dossier containing:

  • a legal opinion and rights map for each jurisdiction;
  • the authoritative-register policy and supply reconciliation controls;
  • investor eligibility rules, wallet binding and revocation procedures;
  • the cash-leg design and evidence of settlement finality;
  • custody, key recovery, segregation and insolvency analysis;
  • a lifecycle-event calendar with named service providers and fallbacks;
  • venue, market-making and surveillance arrangements, or a clear statement that no secondary market exists;
  • the redemption procedure and completed failure simulations;
  • network governance, smart-contract audits, upgrade controls and incident response; and
  • regulatory permissions mapped to each activity, entity and territory.

The sign-off should be conditional on end-to-end tests that cross organisational boundaries. A successful smart-contract audit cannot prove that bank cash arrived, a transfer agent updated its master file or a custodian segregated assets. The hardest defects sit between firms.

What changed between pilot and production

The technology did not suddenly become capable in 2026. The shift is that official records increasingly expose the operating model. Franklin's prospectus identifies who controls the register, who approves wallets, how transfers work and how income is divided. Siemens' bond identifies the registrar, investors, network, cash bank and central bank settlement bridge. ESMA publishes the infrastructures that actually hold DLT permissions. The SEC's Nasdaq order defines a route into an existing order book and DTC process.

Those examples do not converge on one architecture. One uses public networks under transfer-agent control. One uses a private permissioned ledger and the Bundesbank Trigger Solution to produce final central-bank-money bookings in TARGET. One keeps familiar exchange and depository infrastructure while adding a tokenised form. That diversity is the point. Institutional tokenisation is not a chain selection exercise. It is the deliberate construction of a legally coherent operating chain.

The Paris 2026 agenda correctly framed tokenisation as a question of institutions and market structure. The production test is more exacting: can the holder prove the claim, pay, take custody, receive income, transfer only when eligible, find liquidity where promised and redeem when the system is under pressure? Until every answer is documented and tested, the project has not left the pilot.