Three regimes govern a tokenized fund unit. The Alternative Investment Fund Managers Directive (2011/61/EU, as amended by Directive (EU) 2024/927 — "AIFMD II"), the UCITS Directive (2009/65/EC), and the European Long-Term Investment Fund Regulation ((EU) 2015/760, as amended — "ELTIF 2.0"). They read as three rulebooks. On-chain they are one layer, because they all do the same thin, set a ratio, and re-check it when capital moves.
This is a deep-dive on that layer. The architecture around it — the transfer gate, identity, documents — is in the EU-Compliant Tokenized Securities: Smart Contract Architecture pillar. Six modules carry this layer: EltifConcentration, UcitsFiveTenForty, NavBorrowingCap, LmtGate, HoldingPeriodLock, and the feed they all divide by, ValuationOracle.
Two things to hold before reading any of it. AIFMD and UCITS are Directives. Nothing below is directly binding on a manager; each Member State transposes it, on its own date, sometimes more strictly. ELTIF is a Regulation and applies directly. And no manager owes all of this. Each section opens with the fact that triggers it.
1. Two gates before any of it
Applies to every reader. Answer both before a single fund module is scoped.
Is it a fund at all?
If each investor holds a direct, individual fractional share of one asset, with no pooling and no manager exercising discretion, AIFMD does not attach and this layer deploys nothing. A tokenized building sold as co-ownership is not a fund. The same building wrapped in a vehicle that a manager runs is.
Is the manager sub-threshold?
Below €100 million of assets under management for a leveraged fund, or €500 million for an unleveraged, closed-ended one, AIFMD Article 3(2) applies a lighter regime: registration with the home authority under Article 3(3), not full authorization, and no EU marketing passport. Article 3(4) allows a voluntary opt-in to full authorization to obtain the passport.
That is a commercial decision that changes the build. The module set below is sized for a fully authorized manager. A sub-threshold registered manager needs the eligibility gate and the holding-period logic and not the full concentration, borrowing and liquidity-tool stack on day one. Decide it on the passport, not on the engineering.
One consequence rides on the same decision and is easy to miss. The Digital Operational Resilience Act's entity list has no plain-issuer category, and Article 2(3) of that Regulation expressly excludes sub-threshold managers. A fully authorized manager is inside it. Opting up for the passport therefore also opts into the resilience regime, a separate obligation set that this article does not cover.
2. Every fund limit is a ratio, and the contract owns one side
Applies to every module in this layer. This is the design rule the rest of the article depends on.
A platform that issues fund units does not acquire the fund's assets, originate its loans, or decide its portfolio. That is the manager's side, off-platform. But a fund limit is a ratio, and the platform owns one side of it. Every ELTIF concentration limit is denominated in the fund's capital; the borrowing limits in net asset value. Both move when units are minted on subscription and burned on redemption, the platform's own operations, which the manager's systems cannot block.
So the split is by layer, not by module:
| Layer | What it is | Who owns it |
|---|---|---|
| Numerator | What the fund holds — which assets, which counterparties, at what valuation | The manager, off-platform. Fed to the contract as a number |
| Denominator, timers and breach state | Capital and NAV at the mint and burn boundary; the suspension and ramp-up windows; the active/passive breach flag; the warning alert | The platform, at the subscription and redemption boundary |
We build each limit module thinned to that second row. EltifConcentration takes onMint() and onBurn() in cash amounts from the subscription agent, and takes per-asset exposure through recordAssetTrade() and syncAssetValuation() as fed inputs. It compares a fed ratio against a ceiling. It never decides what counts as an eligible long-term asset, a qualifying portfolio undertaking, or a same-group borrower. Those are eligibility determinations, not balances, and no contract evaluates them.
Four obligations have no contract surface at all
And the audit map must name the manager against them rather than a module: the prohibited-borrower list (AIFMD II Article 15(4e)), same-group borrower aggregation (Article 15(4a)), borrower solvency assessment before origination (the Article 15(4c)–(4i) block), and the ELTIF related-party acquisition restriction (Article 12(1)–(2)). Each bites on the acquisition or origination path, which does not exist on the platform. An unmapped Article reads to a regulator as an unenforced one; a module named against an obligation nobody built is worse.
And none of this sits on the transfer hook
The reasons are in the transfer restrictions article, but the short version.
a peer-to-peer transfer moves neither the capital nor the NAV denominator, and a mint raises the denominator, so vetoing subscriptions during a breach would block the remedy. The fund modules are gated by their own reverting mint, burn and position-recording functions. Do not let an adapter be written to bridge them onto the gate.
3. Concentration — ELTIF
Applies if the vehicle is authorized as a European long-term investment fund. A closed-ended AIF that is not an ELTIF skips this section entirely.
ELTIF Article 13 sets the portfolio composition limits, and they are more numerous than the headline figure suggests:
| Article | Limit | What the contract holds |
|---|---|---|
| 13(1) | At least 55% of capital in eligible long-term assets | A floor over the capital denominator |
| 13(2) | 20% of capital per qualifying portfolio undertaking, real asset, or other fund | A per-asset ceiling — the asset's classification is fed |
| 13(3) | 20% of capital in aggregate across STS securitizations | A separate bucket ceiling — the classification marking a holding as an STS securitization is fed |
| 13(4) | 10% of capital in aggregate across OTC derivative, repo and reverse-repo counterparty exposure | An aggregate ceiling, not a per-counterparty one — a per-counterparty counter permits any number of counterparties at 10% each |
| 15(1) | 30% of the units or shares of any single ELTIF, EuVECA, EuSEF, UCITS or EU AIF | A different Article and a different counter from the 20% per-fund cap of Article 13(2)(c). The two are routinely collapsed |
| 15(2) | The liquid-asset bucket under Article 9(1)(b) carries the UCITS Article 56(2) concentration limits | Nothing — not modelled. See below |
Six rows built, three gaps named on purpose — never left silently unmapped.
EltifConcentration holds the first six rows.
- The eligible-asset floor,
- the 20% per-asset ceiling with its 10% variant for a liquid-asset issuer,
- the STS bucket,
- the OTC and repo aggregate, and
- the cross-holding cap.
The Article 15(2) row is not built, and the reason is a missing input rather than a missing counter: its denominator is the issuer's outstanding securities, not this fund's capital, and no feed in the architecture supplies that. Two further things are unmodelled and named in the same place — the Article 13(7) professional-only relief, and the Article 13(6) group look-through, where the asset identifier is whatever consolidation level the manager keys on. A limit named in an audit map against a counter nobody built is worse than an unmapped one.
Two exemptions, and they do not cover the same ground. Article 13(7) exempts a professional-only ELTIF from the limits in Article 13(2)(a)–(d) and Article 13(3)–(4). It does not reach the 30% cross-holding cap. Article 15(1) carries its own professional-only carve-out, and a separate one for a feeder ELTIF investing in its master. A deployment that reads Article 13(7) as a blanket concentration exemption leaves the 30% counter wrongly disabled, or wrongly enabled.
The timers matter as much as the ratios, and the relief they give is narrower than it reads
Article 17(1)(c) suspends the 55% floor for up to 12 months during a capital raise or reduction, and Article 17(1)(a) starts that floor from a date in the fund rules. Both relieve the floor and nothing else. The 20%, 10% and 30% ceilings have no start date and no capital-raise suspension anywhere in the Regulation, so the ceiling checks never consult either — applying the relief across every bucket, which is the natural way to write it, switches off concentration limits the raise never touched.
Two further properties
The ramp-up start date is a fed input from the fund rules rather than the deployment date, and the twelve months are a lifetime budget — lifting and reactivating banks the seconds used and does not restart the clock, or the relief is an indefinite escape hatch with a twelve-month label.
4. Concentration — UCITS
Applies if the vehicle is a UCITS. All UCITS are open-ended by definition, so every one of them is also inside section 7.
UCITS Article 52 is remembered as "5/10/40" — 5% of NAV per issuer, up to 10% where the aggregate of positions above 5% stays under 40%. That is one counter of several:
| Article | Limit | Note |
|---|---|---|
| 52 | 5% per issuer; 10% if positions over 5% total ≤ 40% | The main basket |
| 52(1), second and third subparagraphs | 20% of NAV in deposits with one credit institution; 5% OTC derivative counterparty exposure, 10% where the counterparty is a credit institution | Two further counters, routinely missed. Which limb applies depends on a fed fact: is the counterparty a bank |
| 52(4) | 20% combined exposure to one entity across securities, money-market instruments, deposits and OTC derivatives | The grouping that combines four legs is an entity question, not an address question — fed |
| 55 | 10% per single UCITS or eligible fund; per single non-UCITS fund read as either 10% or 20%; 30% aggregate in non-UCITS funds | A third counter set. The non-UCITS per-fund figure is a configured parameter, not a constant — see below |
| 51(3) | Global derivative exposure not to exceed NAV | Ceiling only — the exposure figure is computed off-chain by the commitment approach or value-at-risk and fed |
Open to anyone for the number, never for the label
UcitsFiveTenForty holds all of those against a NAV denominator, taking each exposure leg through recordHoldingUpdate() and revaluing through syncLegValuation(). The issuer identity behind each leg, the credit-institution status of a counterparty, and the entity grouping under Article 52(4) are not derivable from a token balance. They arrive as inputs and they are persisted at the manager-gated trade call, never re-supplied at revaluation.
Revaluation is deliberately permissionless, because the figure it applies is already guarded by the valuation feed and a role check would hand whoever held it the power to suppress a breach by not calling. That argument covers the figure and never the classification. A revaluation that accepted a caller's flags would let anyone re-label an asset on a price fall and hide the breach the sync was supposed to surface.
The Article 55 non-UCITS per-fund cap is a parameter, and the article you are reading cannot settle it.
The 10% per-UCITS limb is not in doubt. Whether a single non-UCITS collective investment undertaking sits at 10% or 20% is read differently, so the module carries it as a governance-set figure bounded to that range. Defaulted to 20%, settable to 10% where counsel reads it that way rather than as a constant one reading has to be wrong about. The 30% aggregate across non-UCITS funds is fixed.
Two whole alternative limit sets exist, and they are selected at fund level, not at runtime.
An index-replicating UCITS runs on Article 53's 20% per issuer, or 35% for one unduly large constituent, and not on 5/10/40 at all. A UCITS holding sovereign paper may use Article 54's 35% per single public issuer, or up to 100% across six or more issuers with each issue at or below 30% of NAV — conditioned on the fund rules permitting it, prospectus disclosure, and, for the 35% limb, "exceptional market circumstances." That last condition is a judgment no contract can evaluate. We model both as a configured limit set plus, for Article 54, a governance flag carrying an off-chain justification. Never an automatic branch.
5. Borrowing and leverage
Applies if the fund borrows, uses derivatives, or originates loans. A cash-only closed-ended vehicle touches none of it.
Three regimes cap borrowing, each on its own base:
- ELTIF Article 16(1)(a) — 50% of NAV for a fund marketed to retail, 100% for professional-only. Three further conditions the ratio does not cover, a purpose test (Article 16(1)(b)), currency matching to the assets acquired (16(1)(c)), and loan maturity within the fund's life (16(1)(d)). The cap is on-chain; the three conditions are borrowing policy. Article 16(3)–(4) suspends the cap during a capital raise or reduction, on the same suspension pattern as section 3.
- UCITS Article 83 — 10% temporary borrowing for liquidity. A separate 10% for immovable property essential to the business (investment-company structures only), and a combined cap of 15%, not 20% (Article 83(3)). Back-to-back currency transactions are excluded from the definition (Article 83(4)).
- AIFMD II Article 15(4b) — leverage caps for a loan-originating fund of 175% open-ended and 300% closed-ended, with a carve-out for shareholder loans up to 150% of the fund's capital. This is a Directive limb: the figures bind through national transposition, and the per-borrower limit in Article 15(4a) is measured against committed capital, not NAV unless the transposing law says otherwise.
NavBorrowingCap holds each as a distinct bucket
recordEltifBorrowing(), recordUcitsBorrowing() with its two sub-buckets, recordDerivativeExposure(), recordLofBorrowing() — against one NAV denominator. Each bucket is a ceiling check; what was actually borrowed, and for what purpose, is the manager's figure.
One denominator, and the limb that needs a different one is not built
Every ratio in the module divides by NAV, the shareholder-loan carve-out included. A committed-capital denominator does not exist in the architecture, it is not derived and it is not fed. So the Article 15(4a) per-borrower limit, which is measured against commitments rather than NAV, has no counter here. It belongs with the four obligations in section 2 that the audit map names the manager against. Running it against NAV instead would be worse than leaving it out: it would produce a number that passes.
And the relief in the ELTIF sections above does not travel with the bucket structure
Article 16(4) suspends the ELTIF borrowing limit during a capital raise or reduction. It says nothing about the UCITS Article 83 limits or the loan-origination caps. So the suspension applies to the ELTIF borrowing bucket alone and the module refuses to activate it on a non-ELTIF instance at all. Its twelve months are a lifetime budget, banked on each lift, not a window that restarts.
One cap a regulator can move after deployment
AIFMD Article 25 lets the competent authority impose leverage limits where it judges the level to pose systemic risk. So the module takes an externally settable ceiling through setRegulatorCeiling(), held by a regulator-designated key and only ever able to tighten. An imposed limit must not be a redeploy event.
6. A breach is not always a transaction to revert
Applies to every ratio above. This is the section a first implementation gets wrong in the most harmful direction.
UCITS Article 49(2) says that where an investment limit is exceeded because of market movements or the exercise of subscription rights. The manager must make it a priority to remedy the situation within a reasonable period, taking account of the best interests of unitholders. It is a duty to remedy, not a prohibited act. A module that reverts on any state where the limit is exceeded gets this wrong twice. The breach was caused by a price change, not the transaction in front of it, and blocking transactions is precisely what stops the manager unwinding into compliance.
Three behaviors, coded separately.
- Active breach — the transaction itself would push the fund over the limit. Revert.
- Passive breach — valuation movement has already put the fund over. Do not revert. Emit, and record when the breach began. What exists is a start timestamp, not a running deadline. Nothing on-chain counts down to a due date, because "a reasonable period, in the best interests of unitholders" is not a number and inventing one would be stating an engineering choice as a legal requirement. The timestamp is what makes the period measurable after the fact; the judgement about it stays with the manager and the supervisor.
- Ramp-up — Article 56 permits a newly authorized UCITS to exceed Articles 52–54 for six months from authorization. A window with a hard expiry, not a permanent bypass and it runs from the authorization date, fed in, never from deployment. Deriving it from the deployment block gives a fund that tokenizes two years after authorization a fresh six months of relief it is not owed. And one deployed before authorization a window that has already partly run.
Nothing in Article 49(2) says anything per transaction. We build one step further, and it is an implementation choice: while a passive breach is open, the module permits excess-reducing position updates and refuses excess-increasing ones. That is one defensible way to discharge "make it a priority to remedy," and it should be put to counsel as such rather than cited to the Article. The same split applies to the ELTIF and borrowing modules nothing about it is UCITS-specific; that is only where the text states it.
We also alert at 90% of every threshold. No Article says so. It is market practice, and on-chain it is an event at the warning level, not only at the breach.
7. Liquidity tools, and the redemption cap you cannot compute from balances
Applies to every UCITS and to every open-ended AIF. A closed-ended AIF needs no liquidity-tool module at all, which is the cheapest way to delete this entire surface.
AIFMD II requires the manager of an open-ended AIF to select at least two liquidity management tools from the list in Annex V of AIFMD, proportionate to the fund's liquidity profile. For a UCITS the equivalent is Article 18a and Annex IIA of the UCITS Directive, inserted by the same amending Directive Annex V is the AIFMD annex and does not apply to a UCITS.
Three selection constraints bind either way: the two tools come from points 2 to 8. The selection may not consist only of points 5 and 6; and suspension must remain available as a backstop whatever was chosen.
The lock does the enforcing: two constraints by construction, one structurally
LmtGate takes the selection through setTool() and locks it before the fund accepts a redemption request at all, because selection happens at authorization and not mid-crisis. Two of the three constraints are enforced at the lock and the third is structural. The count is taken over points 2 to 8 only — side pockets and suspension do not count toward it. So a deployment cannot reach two by nominating the backstop it already has. And a locked selection of exactly swing pricing and dual pricing is refused outright, since two pricing adjustments are not a redemption-management toolkit.
Suspension cannot be compiled out of a deployment, which is the third constraint holding by construction rather than by check. activateSuspension() must not depend on a prior notification step completing. An emergency suspension is the one case where investors may be told afterwards. forceEnableTool() is held by a regulator-designated key, for the same reason as the leverage ceiling above.
What the gate does with a request, because "at least two tools" says nothing about fairness
Requests accumulate into an open dealing window. Closing the window sizes the cap off redeemable net asset value at that moment and fixes one pro-rata ratio for everyone in it. Each request then pays its share of the cap and the unpaid remainder carries into the next window at full value.
First-come-first-paid is the failure this replaces: It turns a liquidity constraint into a race, and paying early redeemers in full out of value belonging to those behind them is the dilution the tool catalogue exists to prevent.
Two supporting rules follow
- A window cannot be closed before a minimum duration has elapsed, or the manager can re-size after every payout and reconstruct the race.
- And a cost-based tool — swing, dual pricing, a redemption fee — haircuts the cash value once, when the request is priced; a carried remainder is already net and is never haircut again.
Activating a tool is a regulatory notification event, and the contract is where it becomes observable
Where any tool other than a redemption fee or anti-dilution levy is activated, the home authority is to be notified without undue delay. The transaction confirming is the moment the clock starts. Wire the event so operations cannot miss it. The selected tool set, its activation thresholds, and investors' rights during activation are disclosed in the fund rules and offering documents and for a UCITS in the key information document as well. A threshold that lives only as a constructor argument is undisclosed by construction.
The ELTIF redemption cap is a formula, not a percentage of net asset value and this module does not implement it
The delegated regulation supplementing ELTIF (Article 5(5)–(6)) sets the maximum redeemable amount at a dealing date as a percentage multiplied by the sum of the Article 9(1)(b) liquid-asset bucket. And the cash flow prudently forecast over the next 12 months, with that forecast excluding proceeds from new subscriptions and from selling long-term assets. The percentage comes from one of two grids in the delegated regulation's Annexes, a notice-period grid or a minimum-liquid-assets grid and the fund picks which at authorization.
Read against that, the gate above is the AIFMD toolkit and not the ELTIF cap
It caps on redeemable net asset value; it holds no liquid-asset bucket, no forecast input and neither grid. That is a correct implementation of the Annex V liquidity-management surface and an incorrect one of Article 5(5)–(6), and the two are easy to confuse because both produce a percentage cap on a dealing date.
Three things the difference decides:
- the base includes a forward-looking figure, so it is not computable from balances at any point in time;
- incoming subscription money cannot fund redemptions and be counted toward the capacity to meet them;
- and the base is the liquid sleeve, not the long-term assets the fund mostly holds. So a cap taken off total net asset value is larger than the one the Regulation sets — the error runs in the permissive direction.
So an ELTIF deployment owes two further fed inputs before this row is closed. The liquid bucket and the twelve-month forecast, under the same staleness discipline as the valuation feed plus the grid choice as configuration. Until they exist, do not present this module against Article 5(5)–(6) in an audit map.
The redemption parameters are under regulatory change control, not governance control
Under Article 4(2) of the same delegated regulation, changing the redemption frequency or notice period, the tool set, or the percentage approach requires written notice to the competent authority at least one month in advance, deemed agreed if the authority does not react within 20 calendar days.
A notice period under three months needs written justification (Article 5(8)). Also a redemption frequency more frequent than quarterly needs one too (Article 5(4)). These look like governance variables in the contract and are not. Nothing reverts on them, the notice artefact travels as the salt on the timelocked parameter change, and an off-chain reconciliation job with a named owner joins the two. The one-month lead time is a runbook constraint, not a require.
Holding periods are the one fund control that genuinely sits on the transfer hook
A minimum holding period restricts exiting, so HoldingPeriodLock binds the sender only and skips mint; recordSubscription() starts the clock at the subscription boundary. It reaches the gate through a thin adapter, and it is the only module in this article that does.
Transposition dates, and the caveat that goes with them. The AIFMD II transposition deadline was 16 April 2026, with Member States permitted to apply national measures from 16 October 2026. Both are per-jurisdiction parameters. Confirm the effective date of the national law in the home Member State before treating any liquidity-tool item as binding.
8. Valuation — the number every limit divides by
Applies to every fund. This is the largest engineering risk in the layer, because a wrong figure silently passes a breach check.
AIFMD Article 19 requires proper and independent valuation of the fund's assets, a documented methodology reviewed at least annually, and the limb that bites the oracle design. Article 19(5) keeps the manager liable to the fund and its investors for correct valuation even where an external valuer is used. Outsourcing the valuation to a data provider does not outsource the liability. UCITS Article 85 requires NAV at least fortnightly, independent verification by the depositary. And an error-correction procedure with materiality thresholds and investor compensation.
Neither prescribes a method, a source count, or a freshness window. Those are ours:
We build ValuationOracle to accept absolute figures only. Never deltas, a design that takes a delta from a privileged valuator self-heals on the next post when a figure is stale. But a missed delta never does, and the book stays permanently wrong with nothing on-chain able to detect it. Registered sources call postValuation(); a value is accepted as the median of fresh posts at quorum, not the mean. Because the failure being guarded against is one source going wrong and a mean lets a single absurd figure drag the result.
The deviation guard halts rather than publishes
On an out-of-band move the feed declines the figure and stops advancing its own timestamp, so freshness decays and every fail-closed consumer stops on schedule. Publishing the suspicious number propagates a bad valuation into a breach check; freezing the old one as though it were current is the stale-limit failure this section exists to prevent. Clearing a halt is clearHalt() with a justification reference, it re-attests a figure, and who holds that authority is a per-fund decision.
Two reads, on purpose. value() reverts when the feed is stale or halted, and is what anything that mints, redeems or admits reads. peek() never reverts and returns the last accepted figure flagged as not fresh, for passive rechecks and dashboards. No fail-closed consumer may ever read the second.
The source count is a per-fund parameter with a floor, not a constant
"Multi-source" is not a cited requirement anywhere in the fund regimes — a single-administrator fund legitimately runs one source. The deviation band is then the only remaining defense, so the one configuration the contract refuses outright is a single source with the band disabled. Do not present dual sourcing to a regulator as an obligation.
Error correction has no natural home in atomic settlement
Subscriptions and redemptions already settled at a wrong NAV must be capable of being made good under Article 85. Build the correction ledger and the top-up or claw-back path before the first material error, not after — the only remedy available otherwise is a forced transfer.
The depositary is a party to the architecture
Every UCITS has a single depositary, and its duties land on surfaces this stack already builds: cash monitoring of subscription proceeds is the subscription escrow seen from the other side, and oversight covers the NAV calculation process. UCITS Article 24(1) makes the depositary strictly liable for loss of instruments held in custody. Discharged only by an external event beyond reasonable control with unavoidable consequences. Which entity will accept that liability over the chain you chose is a real question, and its answer constrains the chain choice.
9. Retail investors, and a regime that is not a fund regime
Applies where any investor in the distribution chain is retail. Professional-only distribution removes all of it.
PRIIPs (Regulation (EU) 1286/2014) is a product regime, not a fund regime. It attaches where the product is packaged, the amount repayable fluctuates because of exposure to assets the investor does not directly purchase. And at least one investor is retail. A fund unit is packaged by definition. So a closed-ended tokenized AIF sold to one retail investor owes a key information document even though it is neither a UCITS nor an ELTIF, and a prospectus exemption is not a PRIIPs exemption the two regimes have independent triggers. Only the professional-only route removes both at once.
The build surface is two contracts covered elsewhere
The document registry anchors each KID version and its review cadence (the document-anchoring article). The delivery acknowledgement is a covenant bound to that version, checked on the subscription path and never on the transfer hook (the investor-covenants article). The retail/professional line it turns on is the same investor-classification claim the identity layer already maintains — do not build a second one.
Two ELTIF-specific limbs ride on the same tier claim. Article 18(3) requires, for a retail fund with a life over ten years, a written warning that the product may not suit investors unable to sustain such a commitment. A covenant gated at mint, on a one-dimensional predicate: retail.
⚠️ The fund-life limb is not a predicate dimension and is not checked on-chain. The covenant store is deployed per asset, so the fund's life is a fixed number known when its covenants are configured. The limb is therefore a configuration decision, recorded in the deployment checklist and signed off by a second person, not a comparison the contract runs.
The consequence to carry
A fund over ten years whose covenant was never configured will not block anything. So this is a control that lives in your deployment process rather than in the gate. Article 26 requires suitability verifying the retail investor can bear total loss and hold for the full fund life. The determination is off-chain, and the outcome is the tier claim the subscription gate reads. The €10,000 minimum ticket and 10%-of-portfolio limit of the previous ELTIF text are removed.
10. What stays a person's job
Applies to every fund. Stated so the coverage above is not read as an estimate of the build.
- Fee disclosure. AIFMD Article 23(1)(c) requires disclosure of fees and charges to investors. On-chain deduction is evidence that the disclosed fee was what was charged; it is not the disclosure.
- Reporting. AIFMD Article 24 reporting to the authority is an extraction layer over the modules, kept schema-agnostic until the harmonized templates land. For a loan-originating fund, the loan record has to carry borrower sector, geography and maturity at origination or the report cannot come from chain data at all.
- Loan origination. Retention, borrower solvency and the prohibited-borrower list sit on the origination and disposal side, outside the fund wrapper this article builds. Where a client separately mandates the platform to issue loan participations as their own product, that is a second security and a separate scoping exercise.
- Is a third-party contract operator a delegate?. Where the keys that set fund-limit parameters sit with a technology provider, AIFMD's delegation notification and letterbox tests are at least engaged. The rules do not address smart-contract operation as a delegated function, so this is a question for counsel rather than an answer. The build that survives either reading keeps parameter-setting authority with the manager's own governance and treats the provider as infrastructure.
If you're evaluating a AIFMD, UCITS, ELTIF architecture like this one for a live issuance, that's the kind of build an RWA tokenization development company like ours takes on end-to-end.
At a glance
| Article | On-chain | Partial | Off-chain |
|---|---|---|---|
| AIFMD Art 3(2)–(4) — sub-threshold | Decides whether this layer is built at all | — | Passport decision, before Phase 1 |
| ELTIF Art 13(1)–(4), 15(1) | EltifConcentration — capital denominator; the eligible-asset floor plus the per-asset, liquid-issuer, STS, OTC/repo and cross-holding ceilings; relief scoped to the floor alone, on a 12-month lifetime budget | Per-asset exposure, and classification persisted at the trade | Which exemption reaches which counter |
| ELTIF Art 15(2), 13(6), 13(7) | Nothing — not modelled. 15(2)'s denominator is the issuer's outstanding securities, which no feed supplies | — | Name the manager in the audit map |
| UCITS Art 52, 52(1), 52(4), 55, 51(3) | UcitsFiveTenForty — NAV denominator, four counter sets, six-month ramp-up from the fed authorization date; the non-UCITS per-fund cap is a bounded parameter | Exposure legs, issuer identity, entity grouping, global exposure | Art 53 / Art 54 limit-set selection; which reading of the Art 55 non-UCITS figure |
| ELTIF Art 16, UCITS Art 83, AIFMD II Art 15(4b), AIFMD Art 25 | NavBorrowingCap — per-bucket ceilings all divided by NAV, regulator-settable ceiling that only tightens, ELTIF-only suspension scoped to the borrowing bucket | Amounts borrowed, purpose classification | Purpose, currency and maturity conditions |
| AIFMD II Art 15(4a) — per borrower, on committed capital | No counter. The commitment denominator is neither derived nor fed | — | Name the manager. Running it against NAV would produce a number that passes |
| UCITS Art 49(2), 56 | Active breach reverts; passive breach emits and records a start timestamp, not a deadline; ramp-up window with hard expiry. Permit-reducing/block-increasing is our choice, not the Article | Valuation input distinguishing price-driven from trade-driven | What period is reasonable, and to whom it is owed |
| AIFMD Art 16 + Annex V; UCITS Art 18a + Annex IIA | LmtGate — ≥2 tools counted over points 2–8, swing-plus-dual-alone refused, suspension backstop, regulator-forced tool; pro-rata allocation on a minimum-length dealing window | — | Tool set in fund rules and KID; authority notified on activation |
| ELTIF delegated regulation Art 5(5)–(6) | Not implemented. No liquid-asset bucket, no forecast, neither Annex grid — the gate caps on redeemable NAV, which is the AIFMD toolkit and not this cap | Owed: liquid bucket and 12-month forecast as fed inputs; grid choice as configuration | Do not present the module against this Article until both inputs exist |
| ELTIF delegated regulation Art 4(2) | Nothing reverts on a parameter change — the notice artefact rides as the timelock salt | — | One-month notice; 20-day deemed agreement; reconciliation owner |
| AIFMD Art 19, 19(5); UCITS Art 85 | ValuationOracle — absolute values, median at quorum, deviation halt, fail-closed and never-reverts reads | The valuation itself, under the documented method | Methodology and annual review; error-correction procedure |
| PRIIPs; ELTIF Art 18(3), 26 | Tier claim on the subscription gate; KID anchored; covenants at mint | Suitability outcome | KID drafting; annual and material-change review |
| AIFMD II Art 15(4a), (4e), (4c)–(4i); ELTIF Art 12 | No contract — name the manager in the audit map | — | Acquisition and origination-path duties |
This is engineering commentary on regulatory requirements, not legal advice. AIFMD and UCITS bind through national transposition, and whether and how any of this applies to a specific fund structure needs sign-off from counsel.






