Tokenised Finance Is Missing an Identity Layer
Financial institutions are rapidly expanding experiments with tokenised funds, bonds, deposits and other assets. Their infrastructure can increasingly issue an asset, move it across a blockchain and settle transactions through programmable money.
The system still struggles to answer a basic institutional question: who is permitted to own and transfer the asset?
Traditional capital markets rely on brokers, custodians, transfer agents, banks and central securities depositories to identify participants and enforce eligibility. Public blockchain addresses do not provide the same information. They show where an asset sits, but not necessarily who controls it, which legal entity it represents or whether that holder remains compliant.
Tokenised finance cannot scale through settlement technology alone. It needs an identity and permissions layer that works across institutions and networks.
Institutional Assets Are Conditional
Many financial assets cannot circulate freely among anonymous holders.
A fund may accept only professional or accredited investors. A security may be restricted by jurisdiction. Banks must screen customers and monitor transactions. Issuers may need to prevent sanctioned entities from receiving an asset. Tax rules, suitability requirements and ownership limits can also affect who may hold it.
Placing the asset on a blockchain does not remove these conditions.
A token can include transfer restrictions directly within its smart contract, but the contract needs reliable information on which wallets satisfy the requirements. Without a portable identity framework, every platform must maintain its own list of approved addresses.
That approach reproduces the fragmentation that tokenisation is supposed to reduce.
Wallet Addresses Are Poor Institutional Identities
A wallet address works well as a technical destination. It works poorly as a complete identity.
One company may control several wallets. Several individuals may approve transactions from one institutional wallet. Control can change after credentials are compromised or employees leave. A regulated institution also needs to connect the address to a legal entity, compliance status and authorised representatives.
Simply publishing that connection on a public blockchain creates another problem. Commercial relationships, holdings and transaction patterns could become easier to observe.
Institutional identity must therefore support verification without requiring permanent disclosure of every underlying detail.
Digital credentials can allow a wallet to prove specific facts. A participant may demonstrate that it has passed a know-your-customer process, belongs to an eligible investor class or operates within an approved jurisdiction. The recipient verifies the credential rather than collecting the complete identity file again.
The underlying information can remain with a regulated identity provider.
Credentials Need to Travel
A tokenised market loses much of its value when every venue requires a participant to repeat the same onboarding process.
Portable credentials could allow an institution to complete verification once and present trusted evidence across several compatible platforms. The receiving platform would decide which credential issuers it accepts and which attributes it requires.
This does not mean that every institution must trust every identity provider. A bank may recognise credentials from a defined group of regulated entities. A fund administrator may require additional evidence for a particular product.
The important shift lies in separating the credential from the platform.
The United Kingdom’s digital-identity sector continued expanding in 2026, with government analysis identifying 275 firms providing relevant products and services at the beginning of the year. The growth reflects wider demand for reusable digital verification across financial and commercial services.
Tokenised markets could become an important application, provided standards and liability arrangements develop with the technology.
Privacy Must Be Designed Into Compliance
Institutional adoption does not require every transaction to become publicly attributable.
Zero-knowledge proofs and selective-disclosure credentials can allow a participant to prove that a condition is true without revealing all supporting information. A wallet may prove that its owner passed a sanctions check or belongs to an eligible investor category without publishing a name, passport or complete corporate structure.
This distinction matters because financial privacy is not inherently suspicious. Asset managers, companies and family offices have legitimate reasons to protect positions, counterparties and commercial activity.
A system that forces participants to choose between compliance and confidentiality will push institutional transactions back toward closed databases.
The stronger model allows regulators and authorised intermediaries to access the information they lawfully require while preventing unnecessary exposure to every network participant.
Revocation Is as Important as Issuance
Identity credentials cannot remain valid indefinitely.
A customer’s risk classification may change. A corporate authorisation may expire. A wallet may be compromised. A sanctioned entity may appear in an ownership chain. The system needs to revoke or suspend credentials quickly enough to prevent further transactions.
This requirement creates a governance challenge. Participants must know who can revoke a credential, how the change propagates across networks and what happens to assets already held by a wallet that becomes ineligible.
A token may freeze transfers while preserving ownership. Another system may require the asset to move to a compliant custodian. The correct response depends on the product, law and contractual framework.
The identity layer therefore cannot operate as a simple digital passport. It must support continuing status and defined intervention.
Identity Providers Become Critical Infrastructure
Once tokenised markets rely on digital credentials, identity providers acquire considerable power.
An error could prevent a legitimate investor from trading. A security breach could compromise many platforms at once. An overly concentrated system could give one provider influence across a large part of the market.
Institutions need standards that allow credentials from several trusted providers to work together. They also need clear liability when a credential is wrong, outdated or fraudulently obtained.
This resembles other parts of financial-market infrastructure. Efficiency often increases when participants share a common layer, but dependence on that layer creates operational and governance risks.
The design question is therefore not whether tokenised finance needs trusted intermediaries. It is how to prevent those intermediaries from becoming opaque single points of failure.
Interoperability Begins With Knowing the Counterparty
Tokenised assets are beginning to move across several public and private networks. Financial institutions are investing in different platforms, settlement systems and forms of digital money.
Technical bridges can connect networks. They cannot determine whether the participant on the other side of the transaction is eligible.
Interoperability requires compatible rules for identity, permissions and credentials. Otherwise, an asset may travel between blockchains while its compliance status remains trapped inside the platform that issued it.
The next phase of tokenisation will therefore depend on infrastructure that is less visible than the token itself.
The market already knows how to create a digital representation of an asset. It now needs a reliable way to represent the legal and institutional authority of the person or organisation controlling it.
