The flow

Who signs what

A freeze takes effect at the venue at once, before Tx 1: every order, redemption, admission and distribution of the investor is refused, with the freeze’s reason. Tx 1 is the register keeper’s own act, on its own node: it lists each investor the venue freezes on every asset, and takes it off once the venue lifts the freeze (Register keeper). Tx 1 stops even a transfer between two custodians that NodeAsset never sees. Tx 2 to 5 happen once. Afterwards a move (Tx 6) needs only the venue’s own four eyes, because the registrar and the investor authorized it in advance. One act of the registrar ends the agreement and every move under it.

Worked example

From the demo (chapter 9):
  1. The venue freezes Investor B for sanctions. Its next subscription is refused, in the freeze’s words: “holder ’…’ is frozen on FUND (restriction …, sanctions): it takes no subscription”.
  2. The registrar’s block list names Investor B (Tx 1), so its transfer to another investor is refused on the registry too: “Sender must not be blocklisted”.
  3. The venue asks for the lift; two approvers sign it, and the registrar takes Investor B off its block list.

Controls

  • A freeze stops one investor, entirely or except to leave (“liquidate only”); a hold stops an asset’s distributions, redemptions and new orders, and a backed instrument’s new mints; a pause is a hold placed by hand.
  • A freeze takes one call by compliance or risk, and a pause one call by risk, each effective at once.
  • Lifting a freeze or releasing a hold takes two approvers besides the maker, never an auditor. Lifting names the one restriction it lifts, so lifting a lapsed-KYC limit never lifts a sanctions freeze.
  • A backed instrument’s mints and redemptions stop on the ledger only under its register keeper’s supply terms: liquidate-only, or redemptions paused (Backed issuance).
  • Reasons come from a closed list (sanctions, court order, regulator order, lapsed KYC, investigation, key loss, …); a court or regulator order must be cited, with the document’s hash.
  • A forced transfer or a recovery covers only an investor that consented; it cites the order or the evidence, takes two approvers, and goes only to a receiver that is eligible and holds its own credential. Reconciliation matches every move to the operation that approved it, and GET /v1/forced-moves lists every move made, with the order cited and its approvers.
  • An investor sees no restriction record: it learns of one from the refusal’s reason. The record (rationale, cited order) stays with your staff in NodeAsset.

Do it

See KYC and screening. Related: Reconciliation · Onboard investors · Four-eyes approvals