Standing up a trust company, end to end
A stage-by-stage map for institutions that do not yet have a trust company — what has to happen, in what order, and which parts a platform can supply.
Start the custody conversation
Charter-to-custody engagements start with one conversation, not an RFP.
Last updated 23 July 2026
1. Why this path exists
Most infrastructure is sold to institutions that already exist. A chartered trust company already has an operating model, a policy library, an examiner relationship and a book of accounts, and it is buying a component to replace or extend something it already runs.
A growing number of the organisations we speak with are not in that position. They have identified a market — self-directed retirement, alternative-asset custody, private-market settlement, digital assets held in trust — and they need to stand up the whole thing: the entity, the charter application, the policies, the account core, the authorization model, the custody operation and the investor-facing experience. They are not comparing authorization layers. They are asking what Monday looks like.
This page is the answer to that question. It is a map of the work, in order, with an honest division between what a platform can supply and what only the institution and its counsel can do.
2. The seven stages
The sequence below is deliberately not a product diagram. It is the order in which the work has to happen, because several stages are prerequisites for the ones that follow — an examiner will ask to see policy before configuration, and configuration before a live account.
- Charter and organisation — entity, capital, application, business plan.
- Policy, governance and controls — the written record an examiner reads first.
- The account core — parties, accounts, positions, ledger, reporting.
- Authorization and evidence — who may act on which record, for which purpose, and how that is proven afterwards.
- Custody and administration — asset onboarding, titling, valuation, distributions, tax reporting.
- Distribution and access — how investors, advisers and sponsors reach the institution.
- Examination readiness and go-live — evidence, reconciliation, and the first real account.
3. Stage 1 — Charter and organisation
This stage belongs to the institution, its counsel and its chosen jurisdiction. It is named here because the stages that follow depend on decisions made in it, and because sequencing it wrongly is the most common and most expensive mistake we see.
The decisions that propagate furthest into later stages are the permitted-activity list, whether the institution will act in a fiduciary capacity or as a directed non-fiduciary custodian, the asset classes it intends to hold, and whether it will serve retail investors, employer plans, institutions or all three. Each of those changes the policy library, the account types, the reporting obligations and the authorization model.
We do not provide legal, regulatory or chartering advice, and nothing on this page is such advice. Charter strategy, capital adequacy, application drafting and regulator engagement are matters for the institution, its counsel and its regulator. What we can do is tell you which of your charter decisions will drive configuration later, so you make them with that in view.
4. Stage 2 — Policy, governance and controls
An examination is a documentary exercise before it is a technical one. The written record — board charters, delegation of authority, conflicts policy, AML and sanctions programme, information-security policy, vendor management, business continuity, complaint handling, records retention — is what an examiner reads first, and it is what your technology has to be demonstrably consistent with.
The practical point is that policy and configuration are two expressions of the same decisions. If your delegation-of-authority policy says a second approver is required above a threshold, the platform has to enforce that and produce evidence of it. Writing the policy first and configuring to match is far cheaper than reconciling the two after an examiner finds the gap.
5. Stage 3 — The account core
A8 Core™ is the account operating system: the authoritative record of parties, accounts, positions and movements, and the workflows that open, fund, title and administer an account. It spans the account spectrum — demand-deposit, retirement, taxable, trust, entity and private-fund — on one multi-tenant, white-label integration, with the controls and reporting for each account type treated as a feature of the core rather than a separate compliance product.
For a de novo institution the relevant property is that account types are configuration, not custom development. The permitted-activity list from Stage 1 becomes a set of enabled account types and a set of workflows, which is also the artefact you can show an examiner when they ask how a Roth conversion or a prohibited-transaction check is actually performed.
6. Stage 4 — Authorization and evidence
B5 Secure™ governs every data element, purpose, delegation and decision. Authentication establishes who is calling; authorization establishes whether that caller may touch this record, for this purpose, right now — and produces the evidence trail afterwards.
This is the stage most often deferred and most often regretted. An authenticated caller reaching a record they should not have reached is not an authentication failure, and it is not something a perimeter control catches. For an institution that will be examined on segregation of duties and on who approved what, data-element authorization is the difference between asserting a control and evidencing it.
7. Stage 5 — Custody and administration
Investor Services is the customer-facing custody and administration experience: account opening, funding, titling, directed transactions, asset administration, statements, tax reporting and distributions, across traditional and alternative assets and across retirement, taxable, trust, institutional and private-fund structures.
The Stage 1 fiduciary decision lands here in visible form. A directed, non-discretionary custodian does not evaluate, recommend or approve an investment — the account holder directs, and the custodian executes and records. A trustee, by contrast, is a fiduciary. Those are different operating models, different disclosures and different staffing, and the platform has to express whichever one the charter permits.
8. Stage 6 — Distribution and access
InvestNow™ is the private-market discovery and subscription experience, and the Investor Passport is the reusable identity and eligibility layer that connects it to the account. Verified identity, entity and ownership data, accreditation status, tax and banking details, authority and consent are captured once and reused across eligible offerings and accounts.
The Passport is hierarchical. An authorised person may hold a Passport under an entity, an authorised person above may terminate one below, and an approval gate can be configured so that a principal approves transactions before they are final. That is the same delegation structure B5 Secure™ enforces at the record level — which is why the commercial unit and the technical control are one object rather than two systems that have to be reconciled.
The concrete case worth picturing: an account holder authorises their financial adviser to act, retains approval rights over every transaction, and can revoke that authority unilaterally without involving anyone else — and every one of those events is an evidenced decision.
9. Stage 7 — Examination readiness and go-live
Readiness is a demonstrable state, not an assertion. In practice it means: every control in the policy library maps to an enforced configuration; every enforced configuration produces evidence; reconciliation runs and breaks are worked; reporting for each account type has been produced end to end at least once against test data; and the people who will operate the institution have done so in a rehearsal before a real account exists.
10. Who does what
| Work | Owner |
|---|---|
| Charter strategy, application, capital, regulator engagement | Institution and its counsel |
| Policy library and board governance | Institution; we map policies to enforceable configuration |
| Account core, ledger, account-type workflows, reporting | A8 Core™ |
| Data-element authorization, delegation, decision evidence | B5 Secure™ |
| Custody and administration experience | Investor Services |
| Private-market discovery, qualification, subscription | InvestNow™ and the Investor Passport |
| Investment decisions and suitability | The investor, and their adviser where one is appointed |
11. Where to start
The most useful first conversation is not a demonstration. It is a ninety-minute review of your intended permitted-activity list and your fiduciary posture, because those two decisions determine most of what follows. Bring the draft business plan if you have one.
Request a readiness review See the Trust Center
A8 Core™ is a technology platform operated by Financial Infrastructure, Inc.. It is not a bank, trust company, broker-dealer, investment adviser or law firm, and it does not provide legal, regulatory, tax, accounting or chartering advice. Institutional Trust Company is a proposed trust entity that is seeking a South Dakota non-depository trust charter; it is not yet chartered and is not accepting accounts. Nothing on this page is an offer or solicitation of any security, nor a representation that any regulator has approved or will approve any application.
Questions about this document? Contact hello@a8core.com or write to Financial Infrastructure, Inc., PO Box 1410, Menlo Park, California 94026-1410.