Home > Tokenised Securities in the UK: Law, Ledgers and Legal Lag
|
There’s a corner of finance that’s quietly trying to drag centuries-old law into the digital age.
It’s called tokenisation, and depending on who you ask, it’s either the future of capital markets or a very clever way to make record-keeping sound exciting.
In simple terms, it means putting traditional securities – shares, bonds and other investments – on a blockchain. The promise? Faster settlement, fewer middlemen, and transparency so dazzling you might need your sunnies.
At the heart of it all sits something called distributed ledger technology – basically a fancy way of saying that, instead of one central database keeping score, lots of computers (known as ‘nodes’) share and update the same record simultaneously.
There’s just one snag: UK law wasn’t exactly built with that kind of system in mind. Our legal system still prefers a single registrar, a named custodian, and one person to blame – not a global chorus of computers all trying to agree who owns what.
So, what happens when modern tech collides with centuries-old legal plumbing? Let’s find out.
The first question is simple enough: when you put a share or a bond on a blockchain, does it magically become something else?
Short answer: not really.
Under the Financial Services and Markets Act 2000 (FSMA) and its trusty companion, the Regulated Activities Order (RAO), the UK sets out what counts as a “specified investment” – things like shares, bonds, fund units and derivatives.
If a token represents equity in a company, it’s still a share. If it represents a debt instrument, it’s still a debt instrument. The FCA has been clear that regulation is “technology-neutral”: what matters is the right you hold, not where it’s written down.
Back in 2019, the FCA set out its classification of cryptoassets – a sort of Harry Potter-style Sorting Hat moment, dividing the token world into three neat houses.
So far, so logical. But property law is where things get a little foggy. A share isn’t a paper certificate; it’s a chose in action – a fancy way of saying “a right you can enforce”. English courts (for example, AA v Persons Unknown [2019]) have recognised that digital assets can count as property, but Parliament hasn’t yet given them an official legal pigeonhole.
For now, a blockchain record is useful evidence of ownership – but not the final word. Let’s call it the world’s most sophisticated spreadsheet: impressive, efficient, but still waiting for the law to catch up.
If you’re planning to issue digital securities, brace yourself: the rules haven’t changed just because the tech has. The FCA still wants its forms filled, its boxes ticked, and its prospectuses written in something more formal than code.
As of October 2025, the UK Prospectus Regulation remains firmly in place. Unless you can rely on one of the usual exemptions – such as offers to qualified investors only, fewer than 150 people, or raising less than €8 million – you’ll need an FCA-approved prospectus before going public. Blockchain or not, the regulator still expects a paper trail.
And from January 2026, things get an update under the Public Offers and Admissions to Trading Regulations (POATRs). These will introduce a £5 million threshold for public offers and create new ways to raise capital through public offer platforms and so-called “primary” multilateral trading facilities (MTFs). If your deal straddles that date, you’ll need a careful bit of transitional planning.
Then there’s section 21 of FSMA, the rule that haunts every marketing department. It says you can’t make or approve an investment invitation unless you’re FCA-authorised or exempt. In other words: whether your pitch lives in a glossy PDF, a tweet, or a smart contract, the same law applies.
If your tokenised securities are being traded on a platform, it helps to know what kind of platform it is. The London Stock Exchange is a regulated market – the traditional heavyweight. Then there are multilateral trading facilities, digital marketplaces matching multiple buyers and sellers, and organised trading facilities, designed mainly for bonds and derivatives. All three are regulated under the UK’s MiFID II framework, the rulebook that governs how trading venues behave.
So yes, tokenisation might sound cutting-edge. But when it comes to issuing and offering, the paperwork remains reassuringly familiar.
This is where the legal theory meets the messy reality. How do digital versions of securities actually get issued, traded and settled in practice?
Off-chain issuance with an on-chain twin
Most UK projects today take the cautious middle ground – half digital, half traditional. The real security is still issued and recorded the old-fashioned way: shares on a company’s register, or debt instruments through CREST, the UK’s central settlement system run by Euroclear. Alongside that, a digital “token” is created on a blockchain – a parallel record designed to move faster than the law that governs it.
That token looks impressive – it moves faster, updates automatically and never takes a lunch break – but it isn’t the legal record. Under the Uncertificated Securities Regulations (USRs), the official proof of ownership sits in the system operator’s register (in practice, CREST). The blockchain copy might help with efficiency and tracking, but the law still takes its orders from the traditional register. For now, the blockchain is the understudy – useful to have on standby, but not yet the star.
The full on-chain dream (and why it doesn’t quite work)
A fully on-chain system – where the blockchain itself is the legal record – sounds cutting-edge, but it doesn’t fit within current UK legislation. Both the USRs and the Central Securities Depositories Regulation (CSDR) assume there’s one single identifiable operator responsible for maintaining the record. A decentralised network of computers, each holding its own copy, doesn’t quite meet that job description.
The UK Settlement Finality Regulations pose a similar problem. They’re designed to guarantee when a transaction becomes final – easy enough in systems like CREST, where one operator can say “done”. But on a blockchain, transactions are confirmed only when lots of computers agree they’ve happened. There’s no single authority pressing the “final” button, and the law doesn’t yet recognise that kind of digital decision-making.
In short, the UK’s legal plumbing was built for single operators, not swarms of machines. Until that changes, a fully on-chain issuance isn’t legally possible.
Hybrid for now
That’s why almost every real-world tokenisation project in the UK uses a hybrid approach. The legal record stays in CREST or on the company register, while the blockchain handles the day-to-day legwork. It’s faster, cleaner and a good way to show regulators what’s possible. But until Parliament updates the rulebook, the blockchain remains the capable assistant, not the boss.
Once your freshly created digital securities are out in the wild, someone has to look after them, and that’s where things get interesting.
Under the FCA’s Client Assets Sourcebook (CASS), the rules sound simple enough: keep client assets separate, keep the records spotless, and be ready to hand everything back if the firm goes under. It’s all very proper – until you throw blockchains into the mix.
Tokenised securities don’t live in a friendly central system like CREST. They live in digital wallets protected by private keys – long, complex codes that act like passwords, except if you lose them, it’s game over. There’s no helpline, no “forgot your password?” button, no second chances. Lose the key, lose the asset. Forever.
To keep regulators calm and investors reassured, most firms now use institutional-grade custody setups: multi-signature wallets (where several approvals are needed before anything moves) or specialist digital custodians who treat private keys like the crown jewels. It’s safer, but still not foolproof.
The FCA has made clear that “just trust us” won’t cut it. Firms must tell clients exactly what could go wrong, explain how those keys are protected, and prove they’ve thought about what happens if something does.
Custody still rests on the same core principles – segregation, good records, and accountability – but the stakes are higher. And if a firm does lose a private key, “the blockchain ate it” won’t sound nearly as funny when the FCA asks for an explanation.
If you’re dealing in digitised financial instruments, the FCA will almost certainly want to know about it. The technology might be new, but the regulator’s favourite question hasn’t changed: are you authorised to do that?
Under the Financial Services and Markets Act 2000 (FSMA), several activities fall firmly inside the regulatory fence. If you’re issuing or offering tokenised securities, arranging deals, running a trading platform, or holding assets on behalf of clients, you’re squarely within the FCA’s territory. That means authorisation, compliance, and plenty of paperwork.
Even giving investment advice on these instruments counts as a regulated activity. In other words, if you’re doing anything that feels even vaguely like financial business, assume the FCA has you on its radar.
If your tokens are traded on a regulated market or a multilateral trading facility, you’ll also fall under the UK Market Abuse Regulation (UK MAR). The same rules apply as for traditional securities: disclose inside information promptly, avoid manipulation, and don’t trade on secrets. The blockchain might be transparent, but the regulator still expects honesty.
Bottom line: the FCA doesn’t care how futuristic your technology sounds. Whether your securities live on paper, in CREST, or across a blockchain, the same principles apply: fairness, transparency and a healthy respect for the rulebook.
For all the legal friction, the UK isn’t standing still. Policymakers have realised that if they don’t modernise the rules, the market will eventually do it for them.
The Digital Securities Sandbox, launched under the Financial Services and Markets Act 2023, is the big experiment. It allows market infrastructures to test tokenised issuance and settlement models under a slightly relaxed rulebook, supervised by the Bank of England and the FCA. In theory, it’s a safe space for firms to play with new structures without breaking any laws – but with two regulators standing over it, it feels more like a controlled experiment than playtime.
Meanwhile, the Law Commission wants digital assets to have clear legal status and says company and securities law will need a few tweaks to work properly with fully digital ownership records. The Treasury is also looking at pulling more crypto activity inside the regulatory fence, including stablecoins and other tokens that currently sit in the grey zone.
Over in Europe, the EU’s Markets in Crypto-Assets Regulation (MiCA) has already arrived. It sets rules for most cryptoassets but leaves security tokens under existing securities law – much the same as the UK’s position.
Progress isn’t flashy, but it’s moving in the right direction. Each change brings the UK a little closer to a market where digital systems aren’t just experiments, but part of everyday financial life.
Tokenisation might seem innovative, but the legal questions it raises are distinctly familiar. For firms thinking of testing the waters, a few basic rules still go a long way:
For all the hype, tokenisation isn’t rewriting finance – it’s translating it. The principles are the same: ownership, custody, trust. The difference is how they’re recorded.
Law will always trail innovation, but it catches up eventually. When it does, today’s experiments will look less like novelty and more like normal practice.
Because, that’s how change really happens in finance – gradually, deliberately, and safely inside the rulebook.
Stay updated with the latest insights and articles delivered to your inbox weekly.
Stay Informed with Our Updates
Subscribe to our newsletter for the latest insights and expert advice
on funding structures.