Skip to content
Skip article header Engineering

Institutional RWA Platform Requirements: What Allocators Demand

What institutions actually check before allocating to an institutional RWA platform, covering qualified custody, SOC 2 Type II, smart contract audits, transfer agent and fund administration integration and the BUIDL/BENJI reference bar.

12 min read 21 views
Skip key takeaways

Key takeaways: institutional RWA platform requirements 5

The requirements checklist institutions actually run against a tokenization platform before allocating, from qualified custody and attestations through fund plumbing to the BUIDL/BENJI reference bar.

See our tokenization and RWA development services

When a fund manager or a bank starts evaluating an institutional RWA platform, the first meeting rarely touches the token standard or the chain. It is about custody, attestations and who is registered to do what. Vendor pitch decks tend to lead with throughput and chain coverage; the institutions writing the allocation check lead with a due-diligence checklist that a platform either answers point by point or does not, and a platform that cannot answer it does not get a second meeting. This guide walks through that checklist as institutions actually run it, drawn from the same regulatory and infrastructure landscape covered in our tokenization and RWA development practice.

In short: institutions allocating to a tokenized fund or platform are not buying token technology, they are buying controls. The checklist that actually decides an allocation runs through qualified custody, SOC 2 Type II attestation, third-party smart contract audits, transfer agent and fund administration integration and ongoing operational reporting, in roughly that order of scrutiny. BlackRock's BUIDL and Franklin Templeton's BENJI are the two deployments institutions point to when they describe what "institutional-grade" looks like in practice, and this guide uses them as a reference bar rather than a case study.

What institutional due diligence actually checks

Strip away the pitch language and an institutional due-diligence review reduces to a small number of concrete questions, each with a specific document or arrangement that answers it. The table below is the checklist an allocator's operations and compliance team actually works through before a term sheet gets signed.

Requirement What the institution asks for Typical evidence
Qualified custody Who legally holds the underlying assets, and under what regulatory status A named qualified-custodian relationship (bank, broker-dealer, trust company), not a self-custody wallet
SOC 2 Type II Evidence that security and operational controls worked over a period of time, not just on paper A SOC 2 Type II report, reviewed under NDA, covering period, scope, subservice organizations and exceptions
Smart contract audits Independent review of the token and compliance contracts moving the asset A named audit firm's report, covering the exact contract version deployed in production
Proof of reserves Confirmation that claimed holdings actually exist and match the token supply A periodic independent attestation, increasingly paired with an on-chain proof-of-reserve feed
Transfer agent and fund administration Who maintains the official investor register and calculates NAV An SEC-registered transfer agent named for US offerings, plus a fund administrator engagement
NAV oracle integrity How a NAV figure gets from the fund's books onto the chain without going stale or forgeable A documented oracle architecture with update cadence and a named source for each price
Ongoing operational reporting Investor reporting cadence, audited financials and incident notification, not a one-time compliance sign-off A sample monthly or quarterly investor report pack

None of these seven sit in isolation. Custody determines who an institution's lawyers actually have recourse against if something goes wrong; SOC 2 and audits determine whether anyone independent has checked the controls and the code; transfer agent, administration and NAV integration determine whether the platform can plug into a fund's existing operational plumbing instead of asking the institution to build a workaround. The sections below take each in turn.

Ongoing operational reporting is the piece easiest to skip in an early pitch and hardest to skip once capital is actually allocated. Institutions expect a defined investor reporting cadence, audited financials on a regular schedule and a documented incident-notification process, not a one-time compliance sign-off. A sample monthly or quarterly report pack, even from a comparable prior deal, is usually enough to show the cadence is real.

Qualified custody

The current US custody landscape

Under the RIA Custody Rule (Advisers Act Rule 206(4)-2), a registered investment adviser holding client crypto assets in custody has to use a qualified custodian: a bank, a broker-dealer, a futures commission merchant, certain foreign financial institutions or a qualifying state trust company. That single requirement is why "who custodies the assets" is the first question on almost every institutional RWA platform due-diligence call, ahead of chain choice or token standard.

The custody picture moved twice in late 2025. On September 30, 2025, the SEC's Division of Investment Management issued a no-action letter allowing state-chartered trust companies to act as qualified custodians of crypto assets for RIAs and registered funds, a position Commissioner Hester Peirce supported and Commissioner Caroline Crenshaw dissented from. On December 17, 2025, the SEC's Division of Trading and Markets went further for broker-dealers, stating that staff would not object to a broker-dealer deeming itself to have "physical possession" of a crypto asset security under Exchange Act Rule 15c3-3(b)(1) in a set of specified circumstances, including demonstrated access, transfer capability on the underlying blockchain and a documented distributed-ledger risk assessment. That followed the May 2025 withdrawal of the SEC's 2019 joint statement on broker-dealer custody and the publication of updated crypto FAQs. The same day, Commissioner Peirce issued a request for information on ATS and exchange trading of crypto assets, a further signal that the custody and trading rulebook is still being actively rewritten rather than settled.

Named custodians and what they solve

In practice, institutions ask an institutional RWA platform to name its custody partner rather than describe custody in the abstract. Anchorage Digital is frequently cited as the clearest qualified-custodian story in the US market because it operates under a federal bank charter. BitGo is SOC 2 Type II certified and offers trust-company custody. Fireblocks' core platform is MPC infrastructure rather than a custodian, though it now also operates Fireblocks Trust Company, an NYDFS-chartered limited-purpose trust offering qualified custody; platforms using only the technology platform still pair it with a named custodian. Custody-modernization rulemaking sits on the SEC's 2026 agenda with proposals targeted for mid-2026, not yet issued as of this writing.

Attestations and audits

SOC 2 Type II

SOC 2 Type II has become the baseline document institutional due-diligence teams request first when evaluating a custody or platform relationship. The distinction from a SOC 2 Type I report matters: Type I verifies that controls are designed correctly at a single point in time, Type II verifies that those controls actually operated effectively over a period. A vendor's claim to be "SOC 2 compliant" should be treated as marketing language until the actual report, including its stated period, scope, subservice organizations and any noted exceptions, has been reviewed under NDA.

Proof of reserves

Proof of reserves is the second attestation institutions expect: a periodic independent confirmation that the assets backing a token actually exist and match the reported supply. Some providers have moved toward automated on-chain variants, Chainlink's Proof of Reserve product connects smart contracts to custodial or bank account data so reserve figures can be checked continuously rather than only at audit time. Regulators have also started floating formal proof-of-reserve audit requirements, an approach that appeared in a Monetary Authority of Singapore consultation annex, a sign the practice is moving from a voluntary trust signal toward an expected control.

Smart contract audits

Third-party security audits of the token and compliance contracts are a standard line item in institutional due diligence for any platform using ERC-3643, ERC-1400 or a comparable standard; all of the major security-token standards actively advertise third-party audit coverage as part of their pitch to issuers. What institutions actually check is narrower than "was it audited": which firm performed the review, whether the audited contract version matches what is deployed in production, and whether findings were remediated before launch rather than accepted as known risk. For the specific mapping from a regulatory duty, such as jurisdiction restrictions or investor caps, to the on-chain control enforcing it, see our RWA compliance controls guide.

Fund plumbing: transfer agent, administration and NAV

Transfer agents

A transfer agent's core obligation is reconciling the official share register against the on-chain token balances, keeping the legal record of ownership and the ledger from drifting apart as tokens change hands. Rulemaking on this front is still catching up: SEC staff have flagged transfer agent modernization as a work item, and industry participants have pushed to update rules written well before tokenized assets existed. Securitize is the name most institutional allocators already recognize here, it is the SEC-registered transfer agent behind BlackRock's BUIDL.

Securitize has also moved into fund administration directly, launching Securitize Fund Services after its cumulative on-chain issuance crossed a reported milestone, then acquiring MG Stover's fund administration business in April 2025, a deal reported to make it one of the largest digital-asset fund administrators by assets under administration. For an institutional RWA platform still early in its build, the practical takeaway is less about any single vendor and more about the pattern it sets: transfer agent and fund administration functions are expected to be either directly integrated or handled by a named, recognizable partner, not built in-house as a side feature of the tokenization contract.

Net asset value is the number institutions actually trade against, and getting it on-chain without it going stale or becoming manipulable is its own integration problem. Securitize and RedStone published a "Trusted Single Source Oracle" whitepaper in July 2025 describing a cryptographically chained approach to NAV updates for tokenized private funds, an architecture aimed specifically at giving institutions a verifiable, tamper-evident price feed rather than a manually updated number. Specialist fund administrators have also started marketing dedicated digital transfer agent services for tokenized RWA funds as a named product line, a sign that NAV and transfer-agent integration for tokenized structures is becoming its own vendor category rather than a one-off build.

The reference bar: BUIDL and BENJI

When institutions describe what an "institutional-grade" RWA platform looks like, two deployments come up more than any others: BlackRock's BUIDL and Franklin Templeton's BENJI. Neither is cited here for its assets under management, a figure that moves too quickly and is reported too inconsistently across sources to use responsibly in a checklist article. What both funds normalized is the structure around the token, not the token itself.

BlackRock's BUIDL

BlackRock's USD Institutional Digital Liquidity Fund (BUIDL) launched in March 2024 as a British Virgin Islands private fund restricted to qualified purchasers, with a $5 million minimum subscription, Securitize as its SEC-registered transfer agent and its underlying assets, treasury bills, repo and cash, held with BNY Mellon. It distributes yield monthly and has expanded to six or more blockchains since launch. Every piece of that structure, the qualified-purchaser gate, the named transfer agent, the named custodian for the underlying assets, is exactly what institutional due diligence checks for, which is why BUIDL functions as a reference point rather than just one more fund among many.

Franklin Templeton's BENJI

Franklin Templeton's BENJI, the Franklin OnChain U.S. Government Money Fund, took a different structural path to a similar credibility outcome. Launched in April 2021 on the Stellar network, it was the first US-registered mutual fund under the Investment Company Act of 1940 to use a public blockchain for share recording, and it has since expanded to eight chains. It carries a 0.15% management fee and, unlike BUIDL's institutional minimum, is retail-accessible from roughly $20 through the Benji app with daily rebasing yield. That contrast shows the same regulatory and operational rigor, registered fund status, blockchain-recorded shares, an established transfer agent relationship, can support both an institutional-minimum private fund and a retail-accessible registered fund on the same underlying compliance model.

The lesson for a platform team is not to copy either fund's specific chain choice or distribution model. It is that both funds cleared the checklist above before institutions treated them as reference points: a registered fund wrapper, a named qualified custodian for underlying assets, an SEC-registered transfer agent and a distribution model matched to investor type. A platform that can give equivalent answers on each of those points is already speaking the language institutional allocators trust.

Sequencing the requirements

Not every item on the checklist has to be in place before the first institutional conversation, but the order matters. Before approaching an institutional allocator, a platform needs a named custody relationship with a qualified custodian (or a state trust company relying on the 2025 no-action relief), at minimum a SOC 2 Type I report with Type II in progress and a completed third-party audit of the live smart contracts. Those three answer the questions that end a conversation quickly if left blank: who holds the assets, has anyone independently verified the controls and has anyone independently verified the code.

Transfer agent and fund administration integration, proof-of-reserve automation and a documented NAV oracle architecture can reasonably follow once a specific institutional relationship is close to committing capital, since those pieces are easier to scope against a real fund structure and a real counterparty than in the abstract. This article deliberately stays at the requirements-checklist level. For the platform architecture, token-standard decision and build cost and timeline behind an institutional RWA platform, see our RWA tokenization platform development roadmap. For the build-vs-license decision matrix and the market-level data on where institutional issuance is actually concentrated, see our state of RWA tokenization 2026 report; this guide does not repeat that ground.

How Pharos Production helps

Meeting an institutional checklist is a platform-architecture decision as much as a compliance one: custody integration, transfer agent connectivity and an auditable NAV pipeline all have to be designed into the token and compliance layer from the start, not retrofitted after an allocator asks the question. Our tokenization and RWA development team builds that stack compliance-first, and our digital assets and trading platforms practice covers the surrounding custody, settlement and market infrastructure an institutional counterparty expects to see named and working before it allocates.

Sources: SEC Division of Investment Management and Division of Trading and Markets no-action and staff statements (2025-2026); public disclosures from Securitize, BlackRock and Franklin Templeton; vendor-attributed custody and attestation practice descriptions. Specific assets-under-management figures for BUIDL and BENJI are omitted here because publicly reported figures conflict across sources; check a live dashboard such as rwa.xyz for a current number.

FAQ

Last updated:

Quick answers to common questions about custom software development, pricing, process and technology.

  • Copy link Copies a direct link to this answer to your clipboard.

    An institutional due-diligence review checks seven things in roughly this order: who legally holds the underlying assets (qualified custody), whether security and operational controls have been independently verified over time (SOC 2 Type II), whether the token and compliance contracts have been audited by a named firm, whether reserves are periodically attested, who runs the official investor register and NAV calculation (transfer agent and fund administration), how NAV data reaches the chain without going stale or forgeable and whether investor reporting, audited financials and incident notification happen on a defined ongoing cadence.

  • Copy link Copies a direct link to this answer to your clipboard.

    Under the RIA Custody Rule (Advisers Act Rule 206(4)-2), a qualified custodian is one of a short, defined list of regulated entities: banks, broker-dealers, FCMs, certain foreign financial institutions and qualifying state trust companies. The SEC expanded that picture in late 2025: a September 30, 2025 no-action letter allowed state-chartered trust companies to act as qualified custodians for RIAs and registered funds, and a December 17, 2025 staff statement addressed when a broker-dealer can treat itself as having "physical possession" of a crypto asset security.

  • Copy link Copies a direct link to this answer to your clipboard.

    SOC 2 Type II verifies that security and operational controls actually operated effectively over a period of time, not just that they were designed correctly at a single point in time, which is what a SOC 2 Type I report shows. Institutions treat a vendor's "SOC 2 compliant" claim as unverified until the report itself, its period, scope, subservice organizations and any exceptions, has been reviewed under NDA, which is why it is typically the first document requested in due diligence.

  • Copy link Copies a direct link to this answer to your clipboard.

    A transfer agent maintains the official record of who owns what, and for a tokenized fund that record has to reconcile with the on-chain token balances. In current institutional practice the role runs through an SEC-registered transfer agent, Securitize holds that role for BlackRock's BUIDL fund, and the SEC's own regulatory agenda lists transfer agent rules among its planned crypto-related rulemakings, since existing rules predate digital-native assets.

  • Copy link Copies a direct link to this answer to your clipboard.

    Institutions most often point to BlackRock's BUIDL and Franklin Templeton's BENJI as the reference deployments, not for their size but for their structure. BUIDL pairs a BVI private fund restricted to qualified purchasers with a named SEC-registered transfer agent (Securitize) and a named custodian for its underlying treasury bills, repo and cash (BNY Mellon).

    BENJI pairs the first US-registered (1940 Act) mutual fund to use a public blockchain for share recording with the same category of transfer agent relationship, at a retail-accessible minimum instead of an institutional one. Both show that the checklist, not the chain or the distribution model, is what makes a platform look institutional-grade.

I work with startup founders who need a dedicated software development team but don’t want to gamble on hiring, random outsourcing, or opaque delivery.
Most founders face the same problem sooner or later.
Early technical and team decisions lock the product into tech debt, slow delivery, missed milestones and constant re-hiring. By the time this becomes visible, fixing it is already expensive.

As a CTO and software architect, I help founders design, build and run dedicated development teams that work as a true extension of the startup. Not as a black-box vendor.

My focus is on complex products where mistakes are costly:

  • Web3 and blockchain platforms
  • FinTech and regulated products
  • High-load startup systems
  • MVP → scale transitions

We don’t do body-shopping.
We don’t sell generic outsourcing.

Instead, we help founders:

  • build the right team structure from day one
  • keep technical ownership and transparency
  • scale delivery without losing control
  • avoid vendor lock-in and hidden risks

Teams are aligned with the product roadmap, business goals and long-term architecture. Not just short-term velocity.

Dmytro Nasyrov, Founder and CTO at Pharos Production
Dmytro Nasyrov Founder & CTO Let's work together!

Your business results matter

Achieve them with minimized risk through our bespoke innovation capabilities

Your contact details
Please enter your name
Please enter a valid email address
Please enter your message
* required

We typically reply within 4 hours. Prefer email? [email protected]

What happens next?

  1. Contact us

    Contact us today to discuss your project. We're ready to review your request promptly and guide you on the best next steps for collaboration

    Same day
  2. NDA

    We're committed to keeping your information confidential, so we'll sign a Non-Disclosure Agreement

    1 day
  3. Plan the Goals

    After we chat about your goals and needs, we'll craft a comprehensive proposal detailing the project scope, team, timeline and budget

    3-5 days
  4. Finalize the Details

    Let's connect on Google Meet to go through the proposal and confirm all the details together!

    1-2 days
  5. Sign the Contract

    As soon as the contract is signed, our dedicated team will jump into action on your project!

    Same day