← All blockchain use cases

Policy-as-Code Smart Contract Compliance

Sector: Quaternary sector · Industry: Risk management and corporate governance · Organisation: Europäische Investitionsbank (EIB) mit Société Générale Forge, Santander, Goldman Sachs · Maturity level: Pilot

Policy-as-Code embeds regulatory logic directly into smart contracts: KYC checks, holding periods and investor accreditation are automatically enforced in real-time. Chainlink develops the standards, MiCA accelerates adoption.

Documentation status

Description

Policy-as-Code embeds regulatory logic directly into smart contracts. Instead of retrospective audits, KYC checks, holding periods and accreditation are enforced in real time. Chainlink develops the oracle infrastructure for on-chain compliance. MiCA (EU) has provided the legal framework since 2024.

Policy-as-Code transforms compliance from a reactive cost centre into a proactive security feature. Regulation is not audited but enforced.

Perspectives

B2B — organisations perspective

Issuers of tokenised securities use Policy-as-Code for automated regulatory compliance — from investor accreditation to geographic restrictions.

B2C — consumers perspective

Investors benefit from more secure tokenised markets, as non-compliant transactions become technically impossible.

Employees perspective

Compliance teams are relieved from manual checks. Lawyers codify regulation as smart contract logic.

Benefits

General

B2B — organisations

B2C — consumers

Employees

Challenges

General

B2B — organisations

B2C — consumers

Employees

Technology foundation

ERC-20/ERC-721 token standards with embedded compliance logic, Chainlink Oracles for off-chain data, allowlist-based transfer restrictions.

Implementation examples

Chainlink / MiCA Framework

Manual compliance does not scale for tokenised securities markets with thousands of transactions per second. Automation is the only option.

Chainlink is developing oracle infrastructure for on-chain compliance, embedded within the regulatory framework of the EU MiCA regulation.

Policy-as-Code describes an approach where regulatory logic is embedded directly into smart contracts. Token standards for regulated securities automatically check allowlists of verified wallet addresses — if the KYC check fails, the transaction is rejected. Chainlink is working on oracle infrastructure that makes off-chain compliance data available on-chain. The EU regulation MiCA (Markets in Crypto-Assets, effective since 2024) provides the legal framework.

Real-time enforcement of regulatory requirements. Automatic KYC/AML checks on transactions. Cross-jurisdictional compliance.

Tags

Policy-as-Code, Smart Contract Compliance, MiCA, Tokenised Securities, Automated Regulation

Sources

  1. Chainlink – Oracle Infrastructure
  2. MiCA – Markets in Crypto-Assets Regulation
  3. EIB: European Investment Bank issues its first ever digital bond on a public blockchain (April 2021, 100 Mio. EUR auf Ethereum, mit Goldman Sachs, Santander, Société Générale)
  4. EIB: Project Venus – erste auf Euro lautende digitale Anleihe auf einer privaten Blockchain (2022, GS DAP, T+0-Settlement, DvP gegen Zentralbankgeld)
  5. CoinDesk: European Investment Bank Issues $121M Digital Notes Using Ethereum