Digital Native vs Digital Twin: Which Tokenization Model?
Tokenized instruments are built on one of three models, distinguished by where the authoritative record of ownership sits. In the digital native model the issuer or its transfer agent agrees that distributed ledger technology is the authoritative books and records. In the digital twin model the authoritative record stays off-chain and the on-chain token mirrors it. In the custodial or intermediated model a bank, broker or securities intermediary custodies the shares and its own books reflect the arrangement. The choice is not a technical preference: it determines how a security interest is perfected, how settlement finality is analysed, what a counterparty must control to hold an enforceable claim, and who the holder has a claim against in a failure. This guide covers the three models, what each costs, and how to choose.
TL;DR — Key Takeaways
- ✓One Question, Three Answers: The models differ on where the authoritative record of ownership sits: on-chain, off-chain with an on-chain mirror, or on an intermediary's books.
- ✓Digital Native: The issuer or transfer agent agrees DLT is the source of truth. Cleanest settlement story; requires every downstream participant to accept the ledger as authoritative.
- ✓Digital Twin: Off-chain books govern; the chain mirrors them. Most compatible with existing infrastructure; on-chain settlement is provisional until the off-chain record agrees.
- ✓Custodial: The holder has a securities entitlement against an intermediary rather than the security directly. Changes who the claim runs against if the intermediary fails.
- ✓Why It Is Not Cosmetic: The model decides the perfection route, the settlement-finality analysis, and what a collateral taker must control. It is a legal choice wearing technical clothing.

One Question Underneath Three Models
Every tokenization model answers the same question differently: where does the authoritative record of ownership sit? On-chain, in the digital native model. Off-chain with an on-chain mirror, in the digital twin model. On an intermediary's books, in the custodial model. Everything else about a program's legal analysis follows from that answer.
The question is easy to skip because all three produce the same user experience — a balance in a wallet that moves when you transfer it. The difference only becomes visible under stress: when a transfer is disputed, when a lender wants a perfected interest, when a counterparty fails. At those moments the model determines which record a court consults and who the holder can sue, and no amount of interface polish substitutes for having chosen deliberately.
“Tokenizing assets on-chain does not recharacterize or alter the asset, it is merely a method of recording ownership.”
— GDF and ISDA, Unlocking Capital with U.S. Tokenized Money Market Funds for Collateral Mobility, July 2026
If tokenization is a method of recording ownership, then choosing a model is choosing a recording method — and the models differ in whether the on-chain record is the record or a copy of one. That distinction, not the choice of chain or standard, is the architectural decision with legal consequences.
The Three Models Side by Side
The first two models are fund-issuer sponsored: the issuer or its transfer agent decides how ownership is recorded. The third is third-party sponsored, where an intermediary interposes itself between the holder and the issuer. That structural difference — sponsored by whom — matters as much as the technical one.
| Digital native | Digital twin | Custodial | |
|---|---|---|---|
| Authoritative record | The chain | Off-chain books | Intermediary's books |
| Sponsored by | Fund issuer | Fund issuer | Third party |
| What the holder has | The security, recorded on-chain | The security, mirrored on-chain | A securities entitlement against the intermediary |
| On-chain transfer effect | Dispositive — it is the transfer | Provisional until the off-chain record agrees | Instruction to the intermediary |
| Counterparty must control | The on-chain position | The transfer agent's records | The intermediary relationship |
| Main failure exposure | Chain and key management | Reconciliation drift between the two records | Intermediary insolvency |
Key Insight
The row that gets misread most often is “on-chain transfer effect” in the twin column. Programs routinely describe a twin as though on-chain settlement were final, because that is how it looks and how the marketing reads. It is not: in a twin the off-chain record governs, so an on-chain transfer that the register does not reflect has not changed ownership, and a holder relying on the chain alone has relied on a copy. This is not a defect of the twin model — it is what the model is — but a twin operated as though it were native has taken on the risk of both without the benefits of either.
What Each Model Costs
No model is strictly better. Each buys a benefit with a specific liability, and the right choice depends on which liability an issuer is equipped to carry. Naming the cost honestly is the useful exercise, because every model is marketed on its benefit.
Digital native — buys settlement clarity
The chain is the register, so an on-chain transfer is the transfer and there is no second record to reconcile against. The cost: the transfer agent must agree to treat DLT as authoritative books and records, and every downstream participant — custodians, lenders, administrators — has to accept that too. One holdout who insists on an off-chain confirmation reintroduces the dual-record problem the model was chosen to avoid.
Digital twin — buys compatibility
The authoritative record stays in a system that is already examined, integrated and understood, so nothing downstream has to change its assumptions. The cost: two records that can drift, a reconciliation obligation that never ends, and an on-chain settlement that is provisional. The efficiency case is genuinely weaker, and programs that claim otherwise are describing a native model.
Custodial — buys familiarity
Institutions that already hold through intermediaries keep doing so, and the tokenization sits inside an existing relationship with known documentation. The cost: the holder has an entitlement against the intermediary rather than the security itself, which concentrates exposure on that intermediary's solvency and segregation practices.
The native model's cost is the one most often underestimated, because it is organisational rather than technical. Getting a transfer agent to treat a ledger as its master securityholder file is permitted — SEC staff has confirmed it — but it requires that agent to accept examination against the recordkeeping rules on that basis, which is a commercial negotiation as much as an engineering one. What the rules demand of them is set out in who is the transfer agent for a tokenized security.
What the Choice Determines Downstream
The model propagates into every subsequent legal question. The GDF and ISDA working group assessed all three models separately across ten legal and regulatory dimensions rather than assessing tokenized funds as one category, because the answers differ by model — and a counterparty that does not know which model it is dealing with cannot complete its own analysis.
| Downstream question | How the model changes the answer |
|---|---|
| Perfecting a security interest | Control of the on-chain position, of the register, or of the intermediary relationship — three different undertakings |
| Settlement finality | Analysed through both legal and operational lenses, and differs by model rather than by chain |
| Who the holder sues | The issuer directly, or the intermediary in the custodial model |
| What a corporate action reads from | The chain, or the off-chain register the chain mirrors |
| What a dispute is resolved against | Whichever record the model designates as authoritative |
The perfection row connects directly to the priority regime, where control is a senior method that beats a filing made first — covered in why control beats filing for tokenized collateral. A lender cannot establish control without first knowing what it needs to control, which is a question only the model answers.
How to Choose, and When Each Breaks
Choose by asking which participant is least able to change. If the transfer agent will not treat a ledger as authoritative, the native model is unavailable regardless of its merits. If the target investors hold everything through a custodian, the custodial model is the path of least resistance. If neither constraint binds, the choice is between settlement clarity and infrastructure compatibility.
Choose native when
- The transfer agent will accept DLT as authoritative
- On-chain settlement finality is the point of the program
- Counterparties can control on-chain positions
- You want one record rather than a reconciliation
Choose twin when
- Existing systems must stay authoritative
- Distribution reach matters more than settlement speed
- Counterparties are not ready to rely on a chain
- You accept a permanent reconciliation obligation
Choose custodial when
- Investors already hold through intermediaries
- The intermediary relationship is the distribution channel
- Entitlement-based holding is acceptable to holders
- Intermediary segregation practice is verifiable
Each breaks in its own way. Native breaks when one participant refuses the ledger and a shadow record appears. Twin breaks when the two records drift and nobody notices until a corporate action pays the wrong holders. Custodial breaks when the intermediary fails and holders discover their claim runs against a failed entity rather than against the asset — which is where the bankruptcy-remoteness analysis in what makes a tokenized RWA SPV bankruptcy remote becomes the operative question.
How Blockmaze Handles Model Declaration
Because every downstream legal question depends on the model, the model itself should be a recorded property of the instrument rather than institutional knowledge held by whoever set the program up. A counterparty asking which record governs should be able to get the answer from the instrument.
Model Recorded per Instrument
Whether an instrument is digital native, digital twin or intermediated is declared against it, so perfection and finality analysis starts from a stated fact rather than an inference.
Authoritative Record Named
For a twin, the off-chain register that governs is identified, so holders know the on-chain balance is a mirror rather than assuming it is the record.
Reconciliation State Visible
Where two records exist, whether they currently agree is observable, so drift surfaces as a condition rather than as a surprise during a corporate action.
Intermediary Chain Disclosed
In custodial structures, the entity the holder's entitlement runs against is named, since that is the exposure the holder actually carries.
The recurring theme is that the model is a fact about the instrument with legal consequences, and facts with legal consequences belong in records rather than in assumptions. A program that cannot state its own model in a form a counterparty can rely on has left the most consequential question about its instruments unanswered.
Choosing a Tokenization Model?
Blockmaze provides the compliance layer that declares the tokenization model against each instrument, names the authoritative record, and makes reconciliation state observable.
Frequently Asked Questions
What is the difference between digital native and digital twin tokenization?
In the digital native model, the security issuer or its transfer agent agrees to use distributed ledger technology as the authoritative books and records — the source of truth for recording ownership. In the digital twin model, the issuer or transfer agent maintains off-chain books and records as the authoritative record, while the on-chain token mirrors that record. Both are fund-issuer sponsored. The difference is which record governs when the two disagree: in the native model the chain is the register, and in the twin model the chain is a reflection of a register kept elsewhere.
What is the third, custodial model?
The third-party sponsored or intermediated model, in which a bank, broker or other securities intermediary agrees to custody the shares for clients, with its books and records reflecting that custodial arrangement — either maintained on distributed ledger technology or updated based on it. The holder's legal position differs meaningfully here: rather than holding the security directly, the holder has a securities entitlement against the intermediary. That changes who the holder has a claim against, which becomes the decisive question if the intermediary fails.
Why does the choice of model matter beyond architecture?
Because it determines what a counterparty must control to have an enforceable interest, and how settlement finality is analysed. A collateral taker needs to know whether to control the chain, the transfer agent's records, or an intermediary's books — three different operational undertakings producing three different sets of documentation. The GDF and ISDA working group assessed all three models separately across ten legal and regulatory dimensions precisely because the answers vary by model. “We tokenized the fund” is not a specification a counterparty can act on.
Does the digital twin model defeat the purpose of tokenization?
No, though it does bound the benefits. The twin keeps the authoritative record in a system that is already understood, examined and integrated, which lowers legal and operational risk at the cost of the on-chain record being derivative rather than dispositive. The benefits that survive are real: faster distribution, programmable transfer logic, and a shared view across participants. What does not survive is the claim that the chain settles ownership — in a twin, on-chain settlement is provisional until the off-chain record agrees, and any design treating it otherwise has misread its own model.
Which model should an institutional issuer choose?
It depends on which risk the issuer would rather carry. Digital native offers the cleanest on-chain settlement story and the strongest efficiency case, at the cost of requiring the transfer agent and every downstream participant to accept the ledger as authoritative. Digital twin is the most conservative and the most compatible with existing infrastructure, at the cost of dual records and reconciliation. Custodial fits institutions that already hold through intermediaries and want tokenization without changing that relationship, at the cost of the holder's claim being against the intermediary rather than the issuer.
Can a program change models later?
It can, but the change is a migration rather than a configuration switch, because the authoritative record is moving. Converting a twin into a native design means the off-chain register stops governing and the chain starts — which requires the transfer agent's agreement, updated documentation for every counterparty relying on the old arrangement, and a defined cutover at which the answer to “which record governs” changes. The cost of getting the model right at the outset is much lower than the cost of moving it, which is the main argument for deciding deliberately rather than by default.
Related Articles
Can Tokenized Money Market Funds Be Used as Margin Collateral?
The GDF/ISDA assessment that tested all three models across ten legal dimensions.
Who Is the Transfer Agent for a Tokenized Security?
Who maintains the authoritative register, and what the rules require of them.
What Are the Four SEC Tokenization Models?
The SEC staff structures, including the issuer-sponsored model these three sit within.
RWA Token Standards Guide
The token standards that carry each model, and what they enforce on transfer.