Switzerland · DLT Act · Registerwertrechte

Technology for ledger-based securities under Art. 973d CO

Since the DLT Act took effect in 2021, a Swiss share, bond or other transferable right can exist as a ledger-based security: entered in a securities ledger, and exercised and transferred only through it. Article 973d of the Code of Obligations sets four requirements that ledger must meet, and the issuer answers for them. This page maps each one to what Tokenistry Core does — and says where it does not do it yet.

The law is technology-neutral. It describes what the securities ledger (Wertrechteregister) must achieve, and leaves the parties' registration agreement (Registrierungsvereinbarung) to say how. Two provisions put the weight on the issuer: it must ensure the ledger is organised for its purpose (Art. 973d para. 3), and it must inform acquirers how the ledger works, with liability for inaccurate information that it cannot exclude (Art. 973i).

So the technology underneath a ledger-based security is part of the issuer's own liability. That is the reason to read the gaps below as carefully as the fits.

First: which record is the title

The ledger is the title — Art. 973d

A ledger-based security moves on the ledger, so the register of holders follows the chain, not the other way round. This is how the Ownership Engine works: positions are derived from chain state, lot by lot, rather than asserted by the application that issued them.

The register is the title — Art. 973c and 686

Simple uncertificated securities, transferred by written assignment, or registered shares, where the issuer's register stays authoritative and a token represents it. Tokenistry Backoffice, as built, runs this model: the register is the record, and token operations follow its entries.

These are different instruments with different transfer rules, not two settings of one product. The terms of the issue and counsel decide which one it is; the technology has to match. The rest of this page is about the first.

Art. 973d CO, requirement by requirement

Paraphrased rather than quoted, and not legal advice. The notes follow the Swiss Blockchain Federation's Circular 2021/01, the practitioner reading most counsel start from. Whether a given configuration forms a securities ledger is counsel's call, not ours.

RequirementWhat it asks forWhat Core does
Power of disposal
para. 2 no. 1
Holders, not the issuer, control their securities by technical means. Custody may be delegated, even to the issuer, but the holder must be able to take direct control. Holders sign their own transfers, from their own wallets or through a custodian. The token has no pause function, which the circular advises against because a paused ledger stops being a securities ledger.
Rights of intervention
para. 2 no. 1
Freezing, allow-listing and token recovery are compatible only with governance that prevents misuse: described in the registration agreement, freezing usually only on an order from a competent authority, and safeguards such as a key held by an independent party. Recovery the issuer alone can exercise is the most problematic. Freeze, forced transfer, burn and eligibility administration are separate roles, so each can be granted to a different address, including one held by an independent party. There is no holder opt-out from forced transfer today.
Allow-listing Permissible, and comparable to agreed transfer restrictions, with the consent of the first takers. For registered shares, transfers that meet the restrictions must be allowed. The token checks the Eligibility Engine registry inside every transfer, with separate send and receive permissions, and moves nothing when no list is attached. Keeping eligible addresses current is the issuer's operation.
Integrity
para. 2 no. 2
Adequate technical and organisational measures protect the ledger from unauthorised change, such as joint management by several independent participants. The ledger is the chain you deploy to: EVM, public or permissioned. A public network supplies independent participants; on a permissioned network, their number and independence is an assessment to make before issuing.
Content and registration agreement
para. 2 no. 3
The content of the rights, how the ledger works and the registration agreement are recorded in the ledger or in linked accompanying data. In practice: a link to the terms, ideally with a hash, that holders can find from the ledger. Not met by the contract alone today. The token has no terms field, so the link has to run from the registration agreement to the contract addresses. An on-chain terms link is the gap to close before a ledger-based issuance.
Inspection and verification
para. 2 no. 4
Holders can view their entries and verify their integrity without anyone's cooperation. A third-party token audit does not replace that; the source should be published and checkable against the deployed bytecode. Holders verify against the chain, not against our API. Contract source can be published and verified against the deployed bytecode. The Indexing and Ownership Engines serve the issuer's operations; they are not the holder's verification path.
Organisation and information
para. 3, Art. 973i
The issuer ensures the ledger is organised for its purpose, and tells acquirers how it works and how its integrity is protected. Liability for inaccurate or misleading information cannot be excluded. We document how the contracts, roles and eligibility rules work, as input to the information you owe acquirers. The duty and the liability stay with the issuer.
Cancellation
Art. 973h
A court can cancel a ledger-based security whose holder has lost control of it; the entitled person can then ask for a replacement. The cancelled position can be burned and a replacement minted to the entitled holder. Both are role-gated functions and both leave an on-chain record.

Sources: Swiss Code of Obligations, Art. 973d–973i; Swiss Blockchain Federation, Circular 2021/01, Ledger-based Securities.

The Swiss issuing duties beside the ledger

A securities ledger is one obligation among several. The first jurisdiction pack in Tokenistry Backoffice is Swiss, and it carries the issuer-side duties that sit next to the register:

  • prospectus requirement & FinSA Art. 36 exemptions
  • 35% withholding tax on interest, deducted by the issuer
  • issuance stamp duty: none on bonds, 1% on equity above CHF 1m
  • turnover duty exemption on issuance
  • FinSA client segmentation
  • Swiss business days for coupon & redemption dates

It runs the register-as-title model described above. The control mapping is engineering, not legal advice, and needs sign-off from your compliance officer and audit firm before it goes live.

Who this is for

FirmTypical starting pointWhat matters most
Issuing houses Repeat bond or note issuance for several issuers The second issue as configuration; withholding and stamp duty handled per series
Legal & structuring advisers A client mandate for a bond or DLT shares Contract functions that match the registration agreement they draft, gaps stated up front
Private-markets & asset managers Private credit, real estate or fund interests with restricted transfers Eligibility that fails closed, lot-level lineage for redemptions
Banks & securities firms Ledger-based securities for clients, on infrastructure they run Single-tenant in their own cloud account, in a Swiss region, with their own keys

Outside Tokenistry, plainly

  • registration agreement & terms of issue
  • articles of association & board resolutions
  • licensing questions & FINMA
  • custody of investors' tokens
  • KYC & AML
  • secondary trading venues

Tokenistry is a software supplier, not a FINMA-licensed firm. Where keeping a register, placing securities or holding client assets is a licensed activity, that role stays with the licensed firm and Tokenistry supplies the technology beneath it.

How it is delivered

Operated, for issuers

We run the stack; you hold the authority key in your own custody workspace. See for issuers.

Licensed, for institutions

Single-tenant in your own cloud account and a Swiss region, with your database and your keys. See for institutions.

Questions

What is a ledger-based security (Registerwertrecht)?

A right that, under the parties' registration agreement, is entered in a securities ledger meeting the requirements of Art. 973d CO, and can be exercised and transferred only through that ledger. Shares, bonds and other transferable rights can take this form. Because the ledger is the title, a transfer needs no written assignment.

What is the difference between uncertificated securities and ledger-based securities?

Simple uncertificated securities (Art. 973c CO) are kept in the issuer's book and transferred by written assignment. Ledger-based securities (Art. 973d CO) are transferred on the securities ledger itself. Tokenistry Backoffice, as built, keeps the register as the record of title for the first; for the second, Core derives the register from the chain.

Can the issuer freeze or force-transfer a ledger-based security?

Technically, if the token has those functions, and ours does. Legally, the Swiss Blockchain Federation's circular treats them as compatible only with governance that prevents misuse: described in the registration agreement, freezing usually only on an order from a competent authority, and safeguards such as an independent key holder. Each function is a separate role in our contracts, there is no pause function, and there is no holder opt-out from forced transfer. Whether that configuration fits is for counsel.

Does a ledger-based security need a public blockchain?

No. The law is technology-neutral and asks for integrity through adequate measures, such as several independent participants. A public network supplies those. On a permissioned network the participants have to be genuinely independent, and the circular notes that tolerating the failure of one takes at least three.

How is the registration agreement linked to the ledger?

The law allows it to sit in linked accompanying data rather than on chain. The circular suggests a link with a hash of the document, and considers a one-way link sufficient as long as holders can find the agreement from the ledger. Our token has no terms field today, so the link runs from the agreement to the contract addresses; an on-chain terms link is the open gap.

Does the token follow the CMTA standard (CMTAT)?

No. It implements ERC-7943, with freezing, forced transfer, burn and allow-listing. CMTA's own FAQ says a tokenizer may build on its reference implementation or implement its own token. The difference that matters most under Art. 973d is the terms field: CMTAT carries one, and ours does not yet.

Are the smart contracts audited?

Not yet by an external firm. The circular notes that a token audit does not replace a holder's own ability to verify the ledger, but an issuer's diligence will still want one, so ask where ours stands before relying on the contracts.

Who is liable if the ledger does not work as described?

The issuer. Art. 973i CO requires it to inform acquirers about how the ledger works and how its integrity is protected, and makes it liable for inaccurate or misleading information, a liability it cannot exclude. Tokenistry supplies the software and its documentation under a separate written agreement.

Is Tokenistry a FINMA-licensed firm?

No. Tokenistry supplies software and its implementation. Where keeping a register, placing securities or holding client assets requires a licence, that role stays with the licensed firm.

What happens when a holder loses their private key?

Art. 973h CO lets a court cancel the security, after which the entitled person can ask for a replacement. Technically that is a burn of the lost position and a mint to the entitled holder, both role-gated. Because court cancellation is slow, the circular suggests the terms of issue also set out a recovery process with precisely defined prerequisites.

Related

Issuing a ledger-based security?

Tell us the instrument, the chain and who keeps the register today. We will map it against Article 973d and say which parts Core covers, and which stay with the issuer and counsel.

Discuss an issuance