Research story · Law, securities & governance
What a securities register
must survive.
A securities register has to keep ownership usable when a key is lost, a provider disappears or a lawful correction changes a position. Those events reveal whether the technology and the institutions around it work together.
Consider a registered shareholder who loses the signing credential used by her wallet. The company still exists. Its register records her position. A dividend is approaching, and she may need to transfer her shares. The immediate technical problem is a missing secret. The wider problem is how the arrangement will establish her authority, restore the permitted means of acting and preserve the rights attached to the position.
That is a central question in my Comment on Transfer Agent Rules: Legal, Technical, and Governance Analysis, dated 7 October 2026 and now available in the SEC’s public comment record. The response addresses all 175 numbered questions in the Commission’s proposed transfer-agent rules. My recommendation is to assess recording technologies through the legal and operational functions they can actually perform, including tested recovery when ordinary operation fails.
Begin with the right being recorded
A share carries a relationship with an issuer and the rights attached to the instrument. Replacing a paper certificate or a conventional database entry with a token can change how that relationship is recorded and administered. Where the same security and rights are maintained, the change in recording technology preserves the underlying obligation.
The legal foundation already accommodates electronic records. Delaware’s corporate-records provisions permit distributed electronic networks, while retaining requirements concerning legibility, stockholder lists, specified information and transfers. This directs attention to what a register makes possible: identifying holders, producing usable records and supporting the exercise of rights.
The instrument still needs careful classification. An issuer’s registered share, a securities entitlement held through an intermediary and a third party’s linked product can give their holders different claims. A token label cannot settle those differences. The analysis begins with the obligor, the interest acquired and the mechanism through which a transfer becomes legally effective.
Keep ownership, authority and control distinct
A cryptographic signature can establish a mathematical relationship between a message, a signature value and a public key. Determining the legal effect of the instruction also requires the relevant attribution and authority. A stolen credential may produce a signature that verifies. A representative may possess a valid credential whose mandate has expired or whose scope excludes the proposed transfer.
I therefore distinguish the holder’s legal position, the authority to act and the technical means of exercising that authority. The system needs evidence connecting each instruction to the relevant person or representative, the permission relied upon and the record adopted. A wallet can include several credentials and approval arrangements; counting its keys cannot establish the number of holders.
Attribution can also be private. A maintained identity record can connect operational credentials to the holder without publishing a readable map of that person’s addresses and documents. Authorised examiners need a reliable way to resolve the relationship and inspect the necessary evidence. Ordinary observers need not receive the same information. Privacy and accountability depend on specifying those different access rights and preserving the records that support them.
Recover the complete position
Return to the shareholder with the lost key. Under the arrangement I propose, replacing an operational credential should preserve her position, restrictions, applicable limits, pending instructions and record-date entitlements. It should also retire the old instruction powers and retain the evidence needed to explain the replacement.
Replacing an identity anchor presents a further problem. Establishing a new credential does not mathematically reconstruct a lost encryption secret. Historical documents and privately derived indexes require their own continuity arrangements, such as protected recovery copies, independently controlled recovery keys or retained originals. The test should be run with the original secret and the original provider unavailable.
The same discipline applies when recovery uses replacement securities or migration. The old representation must be cancelled, immobilised or consistently recognised as superseded across the relevant arrangement. If a wallet displays the replacement while another interface continues accepting the old representation, the recovery has left a duplicate-recognition problem. The register, settlement interfaces and systems administering distributions must reach a coherent result.
Give correction a lawful scope
Recovery authority creates a powerful capability. Its design must constrain misuse as carefully as it enables legitimate correction. A court-directed operation begins with the actual order, the parties it binds, its effective scope and any stay or recognition requirement. An allegation, an authentic-looking document or a broad administrator permission cannot supply the missing authority.
Third-party interests matter too. Under Delaware UCC section 8-303, a purchaser satisfying the protected-purchaser conditions acquires its interest free of an adverse claim. Technical power to move a balance cannot by itself override that protection. The appropriate remedy requires legal analysis and may involve replacement, compensation or other relief rather than reversal against a subsequent holder.
A well-governed correction can preserve the original event and append the authorised event that changes its operative effect. The resulting evidence should show who decided, what they were entitled to do, which positions were affected and how the outcome was reconciled. Preserving history and correcting the current register can serve the same accountability objective.
Test the failure, including the recovery power
The practical standard in my comment is demonstrated effectiveness across the complete arrangement. A successful server restart leaves further questions: can valid holders establish their positions, exercise the relevant rights and use the restored service? Can a successor agent obtain the records and associations it needs without depending on the failed provider?
The comment develops those questions into failure scenarios and, in Appendix D, proposed acceptance cases. They include lost credentials, compromised identity roots, unavailable private records, stale copies of the register, concurrent transfers and interruption after only one component has updated. The recovery process itself must face tests involving false claimants, compromised recovery credentials, colluding approvers and forged or stayed orders.
The evidence should establish that an authorised correction completes once, an unauthorised correction fails, and interrupted execution can be reconciled without creating duplicate positions. These are requirements I recommend. The comment does not report that a particular deployed platform has passed them.
Implementation can take several forms: a governed registry function, an asset-layer control, authorised migration or a protocol change with the adoption needed to make it effective. The responsible agent must demonstrate the route it relies upon. Developers can implement the mechanism, but effectiveness also depends on decisions, deployment, operational participation and verification of the resulting register.
Measure the work that automation removes
There is a substantial role for automation within this framework. One structured event record can support transfer processing, reconciliation, communications and reporting. It can reduce repeated entry and make a reported figure traceable to the events and calculation rules behind it. Responsibility for the underlying function remains identifiable.
The economic case needs equally careful boundaries. Network throughput alone does not measure the time from receipt of an instruction to lawful registration and completion. Faster gross settlement may require prefunding and give up benefits obtained through netting. Setup, continuing operation, independent assurance and migration costs also belong in the comparison.
My response proposes collecting comparable operational evidence. It does not invent a national savings percentage or carry payment-fee estimates into a different securities-market setting. A conventional database and a distributed ledger should be assessed against the same required outcomes and the costs of achieving them.
The opportunity is to make ownership easier to administer, with less duplicated work and better evidence. The decisive demonstration comes when something goes wrong: the holder, the issuer, the agent and an authorised examiner should still be able to establish the operative position, explain the action taken and make the relevant rights usable.