Comprehensive Compliance Guide to Tokenized Funds Under the SFC Framework: Issuance Architecture, AML Screening, and Custody Requirements
Tokenized funds must operate within the SFC Type 9 (Asset Management) and Type 1/4 (Dealing in Securities / Advising on Securities) regulatory frameworks, with core focus placed on token legal classification, smart contract audits, and secondary market transfer restrictions. Following the Securities and Futures Commission (SFC) issuing two seminal regulatory circulars on November 2, 2023—namely the "Circular on Intermediaries Engaging in Tokenised Securities-Related Activities" and the "Circular on Tokenisation of SFC-Authorised Investment Products"—bringing Real-World Assets (RWA) and traditional fund shares on-chain has emerged as a major trend in the asset management industry. For licensed asset managers (Type 9), Web3 funds, and family offices, mastering the core rules of tokenized fund compliance not only leverages blockchain technology to enhance operational efficiency and fractional liquidity, but also ensures robust, legally compliant business operations within a strict regulatory framework.
I. Fund Tokenization Architecture & 5 Core Compliance Principles
When implementing a fund tokenization architecture in Hong Kong, fund managers and issuing entities must strictly adhere to five core compliance principles established by the SFC:
-
1. Smart Contract Audit & Technical Governance (Smart Contract Audit)
The issuance, dividend distribution, transfer, and burning of fund tokens rely entirely on underlying smart contract execution. Issuers must engage independent, professional third-party blockchain security firms to perform a thorough smart contract audit, verifying that the code is free of security vulnerabilities and resistant to cyberattacks. Furthermore, compliant smart contracts must incorporate proper administrative control mechanisms (Admin Keys)—enabling issuers to pause transactions, freeze illicit or law-enforcement-targeted tokens, or execute court-ordered forced transfers under extreme circumstances.
-
2. Primary & Secondary Market CDD / AML Screening (Primary & Secondary Market CDD)
Regardless of whether transactions occur during primary issuance or secondary trading, all fund token holders must pass rigorous Customer Due Diligence (CDD) and Anti-Money Laundering (AML) screening. Issuers must enforce chain-level transfer controls via whitelisting mechanisms, ensuring that fund tokens can only be held and traded by wallet addresses belonging to verified Professional Investors (PIs), while strictly abiding by the virtual asset "Travel Rule."
-
3. Custody Protocols for Virtual Assets and Tokenized Interests (Custody Protocols)
Fund managers must ensure absolute security over the custody of underlying assets and cryptographic private keys. If a fund involves virtual assets or tokenized securities, private keys must be held by SFC-licensed Virtual Asset Trading Platforms (VATPs) or compliant institutional custodians backed by sufficient capital and insurance coverage. Issuers must adopt Multi-Signature (Multi-Sig) or Multi-Party Computation (MPC) technologies to eliminate single points of failure or internal fraud risks.
-
4. Legal Classification & Product Due Diligence (Legal Classification & Due Diligence)
Issuers must obtain formal legal opinions assessing the classification of fund tokens under the Securities and Futures Ordinance (SFO)—which typically fall under the definition of "securities." Offering documents, such as Private Placement Memorandums (PPM), must comprehensively disclose the unique risks associated with tokenization, including blockchain network hard forks, smart contract bugs, loss of private keys, and secondary market illiquidity.
-
5. Permissioned Networks & Transfer Restrictions (Transfer Restrictions)
To satisfy supervisory requirements, an SFC Tokenized Fund generally utilizes a permissioned blockchain or deploys a permissioned smart contract layer on a public blockchain. Issuers must guarantee that unauthorized third parties cannot freely transfer tokens across public chains, restricting secondary market transfers exclusively to whitelisted, KYC-verified users or permitted trading venues.
II. Regulatory Notification and Operational Workflow for Transforming Traditional Private Funds into Tokenized Funds
When upgrading a traditional private fund into a tokenized fund, asset managers must re-evaluate their scope of business and contractual terms. The project team must address permission controls, select qualified service partners (blockchain developers, security auditors, qualified custodians), and submit formal regulatory notifications to the SFC to ensure a seamless bridge between traditional asset structures and on-chain operations.
III. Q&A: Comprehensive Analysis of Common Compliance Enquiries for Fund Managers
Q1: What are the specific SFC notification and approval procedures when transforming a traditional private fund into a tokenized fund?
A: Licensed asset managers (Type 9) planning to tokenize an existing private fund or launch a new tokenized fund structure must follow these notification and review steps:
-
Conduct Business Impact Assessment & Formal Notification: Pursuant to SFC notification requirements for licensed corporations, fund managers must submit a written advance notification to the SFC prior to effecting any material change in business operations (such as converting fund register management and share issuance into tokenized formats), detailing the tokenization design and governance framework.
-
Submit Technical and Legal Supporting Documentation: Provide the SFC with comprehensive compliance documentation, including legal opinions on token classification, independent smart contract audit reports, private key management and custody arrangements, AML/KYC whitelisting procedures, and updated fund offering documents (PPM).
-
Verify Scope of Licensing Conditions: Fund managers must ensure that their Type 9 license conditions permit the management of portfolios containing virtual assets or tokenized securities (and apply to modify or remove licensing conditions restricting operations to traditional assets where applicable).
Q2: Can an SFC Tokenized Fund be offered to retail investors?
A: Generally, unapproved private tokenized funds may only be offered exclusively to Professional Investors (PIs). If a fund is intended for public retail distribution, it must obtain formal SFC product authorization (Authorised Fund). In such cases, the issuer must demonstrate that the tokenization setup possesses exceptional operational resilience, robust investor protection mechanisms, and real-time Net Asset Value (NAV) disclosure capabilities.
Q3: What are the key advantages and operational challenges regarding Net Asset Value (NAV) calculation and auditing for tokenized funds?
A: The main advantage lies in leveraging blockchain oracles and transparent on-chain transaction data to achieve near real-time NAV calculations and auditability. The primary challenge rests on auditor capabilities in verifying on-chain data and auditing smart contract execution logic, as well as ensuring that off-chain underlying assets (such as real estate or private equity) are accurately and promptly valued and reflected in the tokenized fund's NAV.
Conclusion
As Hong Kong actively drives the digital transformation of its asset management industry, tokenized funds serve as a vital bridge connecting Web3 capital with traditional finance. Prospective fund managers and project sponsors should plan their compliance infrastructure early and engage experienced advisors. ComplianceOne Consulting Limited (“ComplianceOne”) provides end-to-end support covering structural design, smart contract compliance reviews, SFC regulatory filings, and custody integration.
