The short answer
What does this use case involve?
Investor wallet onboarding links an approved person or entity to a wallet and product-specific permissions. The address is not the identity record. Define who controls signing, custody, transfer policy and recovery, then reconcile wallet activity to the authoritative ownership register throughout the asset lifecycle.
Where the current process breaks down
Tokenized investment products must connect a verified investor to a wallet and keep that association current through transfers, device loss, credential compromise, organizational changes and provider migration. Useful for tokenized funds, digital securities, private-market platforms and issuer portals serving individuals, institutions and intermediaries through different wallet models.
From input to outcome
How does the workflow operate?
The following is an illustrative operating model, not a claim about a specific deployment. Ownership, approvals and exception handling should be agreed before implementation.
- 01
Approve identity and eligibility
Complete KYC or KYB, sanctions checks and product eligibility. Assign a stable investor identifier independent of any one wallet.
- 02
Create or connect the wallet
Use an approved embedded, institutional, self-managed or custodial model. Verify the association through a controlled process and record the custody configuration.
- 03
Apply transfer and signing policy
Enforce current investor status, asset rules, destinations, value limits and approval requirements before signing or allowing transfers.
- 04
Recover, change and reconcile
Handle lost devices, compromised credentials, organization changes and wallet replacement under separation of duties. Preserve historical ownership and reconcile every change.
Build the operating stack
Which infrastructure is needed?
These capabilities may sit inside an existing system, a specialist service or an integrated platform. Map each one to a responsible owner; do not assume a single vendor covers every function.
- Investor identity and eligibility
- Embedded or institutional wallet API
- Custody and signing model
- Transfer allowlists and policy
- Recovery and account changes
- Registry and transaction reconciliation
Evidence and context
NIST key management guidanceGeneral cryptographic key-management guidance. It does not determine whether a particular wallet arrangement is legally custodial or suitable for a tokenized investment.
Design for the exceptions
What can go wrong?
Wallet address treated as identity
Maintain a separate authoritative investor record and a controlled, versioned address association.
Recovery bypasses onboarding
Apply independent evidence, limited operator authority, notifications and risk-appropriate waiting periods.
MPC mistaken for complete governance
Map credentials, key shares, policy changes, recovery authority and provider dependencies, not only cryptography.
When this is not the right fit
Do not offer a wallet or custody model that the operating team cannot recover, reconcile or migrate. For some investors and products, a regulated custodian or traditional account model may be more suitable than embedded wallets.
A bounded first deployment
How should a team start?
Start with one workflow and named operational owners. A pilot should show that the process works through exceptions, not just that a transaction can succeed once.
- Select one investor type and one permitted asset workflow.
- Document legal custody, signing authority, identity association and recovery roles.
- Test a prohibited transfer, lost device, compromised credential and organization staff change.
- Export records and rehearse migration to a replacement wallet or custodian.
What should the pilot measure?
- Approved wallet onboarding completion
- Policy violations and unauthorized recovery attempts
- Wallet-versus-investor-register reconciliation breaks
Set a baseline and acceptance thresholds before choosing technology. Include support effort and failed cases in the comparison, and validate the result with the teams that will operate it.
Procurement questions
What should you ask vendors?
- Who can sign, change policy and recover access?
- How is current investor eligibility connected to the wallet?
- Can records and authority move if the provider becomes unavailable?
Request evidence from comparable workflows, a clear responsibility matrix, integration documentation and an export or exit plan. Confirm current capabilities directly rather than relying on a category listing.
Relevant vendor directories
Common questions
Does MPC make a wallet non-custodial?
No. Custody depends on legal agreements and practical control over authentication, policy, recovery and signing.
Can an investor use more than one wallet?
Potentially, if the product and operating model support multiple approved associations and can keep the authoritative record accurate.
Sources and further reading
Independent implementation guidance, not legal, investment or regulatory advice. Requirements depend on your product, jurisdiction and operating model.
Last updated