2026 GuideHow to tokenize an asset in Spain, reviewed by three law firms. Download it

KYC and AML in security tokens: complying on-chain

KYC and AML in security tokens: how to comply on-chain with wallet whitelists, transfer restrictions, and freezing. Who is the obligated subject.

· 8 min read

KYC and AML in security tokens: complying on-chain

When a security token circulates on the blockchain, investor identification and anti-money laundering obligations do not disappear: they shift to controlling who can receive the token. In practice, this is solved by restricting transfers to pre-verified wallets, so that the contract itself prevents a transfer to an unidentified third party.

You are going to issue a security token and you stop at the same question: when the token circulates on the blockchain, how do you comply with KYC and AML obligations? In the banking world you have a counter and a form. Here the asset moves by itself, from wallet to wallet, without anyone raising a hand. If you don't control who receives the token, compliance escapes you in the first transfer.

The good news: you don't need to monitor every transaction by hand. The obligations are transferred to the token's own technical layer. This guide explains what the law requires, how it is applied on-chain, and who is responsible for each thing.

Short answer

KYC and AML do not disappear on-chain: they are programmed. You identify and verify each investor (KYC, know your customer), you add their wallet to a whitelist and configure the token so that it only moves between authorized addresses. If something fails, you freeze. The obliged entity remains the regulated entity that markets the issuance, not the software. HokenFi gives you the technical layer to apply those controls; it does not provide regulated services or act as an obliged entity.

What KYC and AML require of you

The reference rule in Spain is Ley 10/2010 on prevention of money laundering and terrorist financing (AML/PBC, anti-money laundering). It obliges you to know who you do business with and to monitor what happens afterwards.

KYC: know your customer

KYC means identifying and verifying who is going to be the holder of the security. You collect their identity, check that it is real, and understand the origin of the funds. It is not enough to write down a name. You verify the document and the person behind it. Without that step, no wallet should touch the token.

AML: monitor and report

AML comes after onboarding. You monitor operations, detect what doesn't fit, and report to the authorities when appropriate. It is a continuous duty, not an entry procedure. Identification opens the door; monitoring maintains control while the security is still alive (Ley 10/2010).

What it means for you: before a single investor receives tokens, you need a closed verification process and a monitoring mechanism that keeps working when the asset is already circulating.

How on-chain compliance is applied

In a security token, control is not a department that reviews papers: they are rules written in the token contract. Three mechanisms do almost all the work.

Whitelist of verified wallets

Each investor who passes KYC enters a whitelist. Their wallet is marked as authorized. The token recognizes those addresses and rejects the rest. A wallet that has not passed verification simply cannot appear as a holder. The ERIR, the digital notary of the registry, records ownership with legal effects (art. 8 LMVSI; RD 814/2023). As of 2026, the first authorized ERIR in Spain is Ursus-3 Capital.

Transfer restrictions

The token has a condition written into it: it only moves between whitelist addresses. If someone tries to send it to an unverified wallet, the network itself rejects the operation. No one needs to intervene. The rule acts on its own, on every transfer, without exceptions slipping through.

Freezing and forced execution

Sometimes you have to stop. A court order, a KYC data point that expires, a founded suspicion. The contract allows freezing the balance of a specific address or forcing a movement by mandate. It is the on-chain equivalent of blocking an account. The capability exists from the design, it is not improvised later.

What it means for you: compliance stops depending on the good will of each investor. If you configure it well at issuance, the token enforces the rules for you on every transaction.

Who is the obliged entity

The obliged entity is the regulated party that markets or manages the issuance, such as the investment firm or the distributing entity, not the blockchain or the software that executes the rules. The obligation falls on a person or entity, not on the code.

It is worth being clear about this because it sets out responsibilities. The obliged entity is responsible for KYC, AML monitoring and reporting. The software is the tool through which it applies those controls. Confusing the two levels leaves you exposed: you assume the system complies on its own, and no one takes on the legal duty.

The same applies to industry terminology: each actor has a defined role. The ESI provides the investment service. The ERIR registers. The software provider supplies the infrastructure. Knowing who does what is the first compliance control.

What this means for you: identify from the outset which regulated entity acts as the obliged entity in your issuance. That entity needs its own AML procedures, and the software connects to them.

What the software does and does not do

HokenFi is non-custodial software. It facilitates the technical application of controls (whitelist, transfer rules, freezing), but it does not custody your assets, it is not an obliged entity and it does not provide regulated services.

The distinction matters. The software gives you the mechanisms for the obliged entity to meet its duties effectively. It translates a legal obligation into an executable rule. But the decision to accept or reject an investor, to report a transaction or to freeze a balance belongs to the regulated party. The software executes; the entity decides and is accountable.

There is also the Travel Rule, set out in Regulation (EU) 2023/1113, which requires crypto-asset transfers to be accompanied by origin and destination information. It applies to crypto-asset transfers and is worth keeping on your radar when designing the flow. Check its specific scope for your case (Regulation (EU) 2023/1113).

What does it mean to you: the software does not exempt you from anything. It equips you. The responsibility to comply remains with the regulated entity behind the issuance.

This table connects each technical mechanism with the obligation it satisfies. Use it as a checklist when configuring your issuance.

On-chain controlLegal obligation it covers
KYC verification before admitting the walletIdentify and verify the customer (Ley 10/2010)
Whitelist of verified walletsOperate only with identified holders (Ley 10/2010)
Transfer restriction to authorized addressesPrevent the security from reaching unverified parties (Ley 10/2010)
Freezing and forced execution by orderBlocking and measures under legal mandate or suspicion (Ley 10/2010)
Ownership registration in the ERIRRegistration of the security with legal effects (art. 8 LMVSI; RD 814/2023)
Origin and destination information in transfersCrypto-asset Travel Rule (Regulation (EU) 2023/1113)

What to do now

Get compliance in order before issuing, not after. Take these steps.

  • Define which regulated entity acts as the obliged entity in your issuance and review its AML procedures.
  • Design the KYC flow: what data you collect, how you verify it and when each wallet enters the whitelist.
  • Configure the transfer rules and freezing capability from the token contract. Review how to issue a security token in Spain to fit these controls into the complete process.
  • If you are starting from scratch, place KYC/AML on the overall map with the asset tokenization guide for companies.

Frequently asked questions

Is HokenFi the obliged entity for KYC and AML?

No. HokenFi is non-custodial software. The obliged entity is the regulated entity that markets or manages the issuance. The software provides the technical layer to apply the controls.

Can I issue a security token without KYC?

No. Customer identification is an obligation under Ley 10/2010 that falls on the obliged entity. On-chain, this means that only verified wallets enter the whitelist and can be holders.

How is the token prevented from reaching an unverified wallet?

With transfer rules written into the token contract. They only allow the security to be moved between whitelist addresses. The network rejects any transfer to an unverified wallet.

Can a security token be frozen?

Yes. The contract allows freezing the balance of an address or forcing a transfer by order. It is the on-chain equivalent of blocking an account when required by a legal mandate or a reasonable suspicion.

What is the Travel Rule and does it affect me?

It is the obligation to accompany crypto-asset transfers with origin and destination information, set out in Regulation (EU) 2023/1113. It applies to crypto-asset transfers. Check its specific scope for your issuance.

What role does the ERIR play in compliance?

The ERIR is the digital notary of the registry: it records ownership of the security with legal effects (art. 8 LMVSI; RD 814/2023). As of 2026, the first ERIR authorized in Spain is Ursus-3 Capital.

Notice

Informational content. It does not constitute legal, tax or investment advice. HokenFi is a software and infrastructure provider; it does not provide regulated services. Check the current version of the rules cited in the BOE and EUR-Lex.

Cited regulations

  • Ley 10/2010, of 28 April, on the prevention of money laundering and terrorist financing.
  • Ley 6/2023, de 17 de marzo, de los Mercados de Valores y de los Servicios de Inversión (LMVSI), Art. 8.
  • Real Decreto 814/2023, de 8 de noviembre.
  • Regulation (EU) 2023/1113 of the European Parliament and of the Council (Travel Rule for crypto-assets).
Get started

Do you have an asset to finance? Request your first offers.

Create your account, activate access and you will receive offers from law firms.