Transfer agents keep the official record of who owns what share of what company — the boring, load-bearing job that makes "shareholder" mean something. On September 1, the SEC proposed the first real rewrite of that job's rulebook to account for electronic systems and blockchain-based share records, per [The Defiant](https://thedefiant.io/converge/regulation/sec-proposes-transfer-agent-rules-for-blockchain-based-share-records). The rules being amended date to an era when "electronic" meant a mainframe, not a distributed ledger. Tokenized equity has been running ahead of the paperwork; this is the paperwork catching up.
What's actually in the proposal
Five rules move, each doing a specific job:
- ▸Rules 17ad-6 and 17ad-7 collapse the current patchwork into a single retention period for most transfer agent records, and modernize how electronic systems and third-party recordkeepers are treated.
- ▸Rules 17ad-1 and 17ad-9 update terminology so "recordkeeping" and "communications" actually cover electronic and blockchain-based methods, not just paper and telex-era assumptions.
- ▸Rule 17ad-12, rewritten, requires transfer agents to hold written policies for safeguarding securities and funds, identify and mitigate material operational risk, maintain business continuity plans, and keep client funds in separate bank accounts.
- ▸Rule 17ad-30 is new: it requires written compliance policies and procedures, full stop — something the existing rules apparently didn't spell out.
Read together, the theme is less "blockchain is now allowed" and more "if you're going to run a shareholder registry on infrastructure that can silently fork, go down, or get operated by a third party, here's the minimum you now have to prove you're doing about it." The proposal explicitly calls out gaps in the current rules around information security, cybersecurity, disaster recovery, and operational risk for connected, automated systems — the exact failure modes a distributed-ledger operating model introduces if nobody's watching it.
Who this actually touches
"Transfer agent" in this proposal isn't just the legacy back-office firms. It covers registered transfer agents, tokenization firms, and issuers that hold transfer agent status — anyone whose job is maintaining the authoritative shareholder record, however it's stored. If your onchain agent stack touches tokenized equity issuance, cap table management, or shareholder recordkeeping, this is the rulebook it now has to answer to, not a side document.
SEC Chair Paul Atkins framed it as modernization, not restriction: the goal is to "streamline and modernize the Commission's rules to reflect transfer agents' current processes and operations, including the use of electronic communications and blockchain technology." Commissioners Hester Peirce and Mark Uyeda also approved it.
The context that makes this land differently
This isn't the SEC's first word on the subject. Back in May 2025, the Division of Trading and Markets put out non-binding staff guidance saying registered transfer agents *could* use distributed ledger technology as their official master securityholder file — as long as records stayed secure, accurate, current, and readable by SEC staff for the required retention period. That guidance already sketched the split that shows up again here: transaction detail (wallet addresses, balances, transaction IDs) can live on-chain, while personally identifying information (names, tax IDs) stays off-chain.
This proposal is the rulemaking version of that guidance — turning "you're allowed to do this if you're careful" into an actual compliance checklist. Commissioner Peirce floated the next question worth watching: whether future rules should let identifiers like email addresses and wallet addresses stand in for names and physical addresses. That's a bigger identity question than it looks — it's asking whether a wallet address can be a legally sufficient identity for regulatory recordkeeping, which is exactly the terrain [ERC-8004](/standards/erc-8004) and onchain identity registries are built for.
What to watch
The public comment window opens 60 days after Federal Register publication — the date that starts the clock that actually matters here, not the announcement date. Watch for who comments: tokenization platforms and transfer agent incumbents will have very different takes on how strict Rule 17ad-12's risk-management bar should be. And watch whether Peirce's wallet-address-as-identifier question gets picked up in the comment period, because that's the piece that would actually change how onchain identity plugs into securities law — everything else here is compliance plumbing, necessary but not new ground.