# NAV Committee — Terms of Reference, seat criteria, code of conduct > **SUPERSEDED — not in force.** This document is superseded by [ETP Foundry Methodology v1.0](/documents/methodology-v1.0.md) (28 Sep 2026) and by [Committee terms v1.3](/documents/committee-terms-v1.3.md). It is kept for the record only. Where it differs from Methodology v1.0, Methodology v1.0 governs. **Version 1.2 — 28 September 2026** (v1.0, 24 September 2026; v1.1, 28 September 2026, moved the committee to Signer Protocol v3; v1.2 moves it to Signer Protocol v4 and ETP Foundry Methodology v1.0). Published alongside the rulebook. Precedents: IBA PMOC Terms of Reference (Jul 2026), WMR Terms of Reference (Sep 2026), CF Benchmarks Charter v13.8 and Constituent Exchange Criteria v8.5, and the FTSE appointment-letter template, all read 24 Sep 2026. Methodology v1.0 governs the determination; the Rulebook v0.2 governs process; where they differ, the Methodology prevails until the Rulebook is reissued. This document governs the *people*. What each seat is asked is the **Signer Protocol v4** (28 September 2026; served at etpfoundry.com/api/signer-protocol once the v4 desk is deployed), which implements **ETP Foundry Methodology v1.0** §4: one numeric submission per seat, from the member's own systems, signed and timestamped. A venue submits its trades in the observation window (`window-trades`); a lender its own independent mark (`independent-mark`); an issuer a reserves/supply snapshot with its evidence reference and redemption and mint/burn status (`reserve-snapshot`); a custodian and a transfer agent a reconciliation with both numbers (`custody-reconciliation`, `register-reconciliation`). The administrator computes the fixing from the venues' submissions (the volume-weighted median of eligible venue VWAPs) and gates it on the lender's mark and the issuer's snapshot; it never attests. Members send aggregates and statements, never their trade tapes, books, client identities or keys. What the ledger enforces since Daml package 3.0.0: the administrator signs every proposal; `K ≥ 2` and `K ≤ N`; the administrator is never a member; a venue's confirmation carries the window's low and high and is refused if the price lies outside them; one fixing per instrument, session and as-of date. Everything else below is a rule of the committee, kept by people and by the records, and it says so. ## Context: why ETP Foundry exists (not part of the terms) **Our mission: put every asset worth owning into a fund people can trust — and make launching one take days, not months.** **The problem today.** A traditional exchange-traded fund (ETF) is a chain of separate firms. Before the first share exists it needs an index provider for the price, a fund administrator for the net asset value (NAV), a transfer agent for the share register, a custodian, authorised participants (APs) to create and redeem shares, and a clearing agency: **five or more firms**, each with its own contract, its own system and its own daily reconciliation. Launching one takes **months**. Creations and redemptions settle **T+1**, the next business day. And for tokenised assets on Canton we know of no administrator publishing a fixing (for CBTC, for example), so **every new asset starts the paperwork again**. **How we fix it: four steps on one ledger** (the Canton Network). 1. **Onboard a tokenised asset.** Any Canton token built on the CIP-56 token standard is added by configuration, not code: four facts from its issuer. 2. **The committee supplies the data; the administrator computes the price.** Once a day, firms that already hold a position in the asset each submit numbers only they hold. **Venues** submit their own trades in the observation window (VWAP, volume, trade count, low and high), and the fixing is the volume-weighted median of those VWAPs. A **lender** submits its own independent mark, and the value publishes only inside its declared tolerance. The **issuer** submits a signed, timestamped reserves-and-supply snapshot, and nothing publishes while the peg is in doubt. With **K of N** signatures and every gate passed, the day's official price, the *fixing*, exists. Otherwise a labelled fallback or a gap is published. (ETP Foundry Methodology v1.0, Signer Protocol v4.) 3. **Create and redeem in one transaction.** An AP delivers the basket and receives fund shares at the signed NAV, or the reverse, all or nothing. No T+1 and no failed leg; custodian and register reconciliations still gate the NAV. 4. **Shares go out on many chains.** Fund shares are carried to other chains through *vaults*, so investors hold them where they already are. **Why each next fund is faster.** A committee is seated once per asset and serves every fund that holds that asset. A second fund holding CBTC settles against the same signed CBTC price: no new committee, no new contracts with its members. A new fund adds only what is its own (any asset nobody covers yet, and its share register), so the more assets are covered, the less each new fund has to set up. ## Context: where we are today (not part of the terms) | | | |---|---| | Ledger | Our own Canton **DevNet** validator (Canton's public test network), live since 24 September 2026. It holds DevNet registry assets (BitSafe CBTC, Canton Coin), which have no monetary value. Not on MainNet. | | Other chains | Vaults on **10 public EVM testnets**. On Solana the program is deployed on devnet (28 September 2026), but **no Solana vault** exists yet. Nothing on any mainnet. | | Prices | **Tier 0, indicative only**: live market observations, signed by nobody. No fixing has been published for commercial use. | | Committee | **No third-party seat yet.** Every seat today is operated by ETP Foundry, and every value says so. | | Methodology | **ETP Foundry Methodology v1.0** and **Signer Protocol v4** (28 September 2026) are implemented and unit-tested in the desk. No venue, lender or issuer has submitted real data yet. | | Regulation | **Not a regulated benchmark administrator.** Not authorised or registered in any jurisdiction. | | Governing text | Methodology v1.0 governs the determination; the Rulebook v0.2 governs process; where they differ, the Methodology prevails until the Rulebook is reissued. | | Audit | The Daml contracts and the vault contracts have **not yet been independently audited**. | --- ## 1. Purpose The NAV Committee exists so that a published fixing is **attested by parties who lose money if it is wrong**, and so that no single interest can set it. It is not an advisory board. Each member submits numbers only its firm holds, from its own systems, and confirms or refuses the proposed fixing on the strength of them. Members act **for their firm on the data they submit**. This is a deliberate difference from IBA and WMR oversight committees, whose members act as individuals. Ours are contributors in the IOSCO sense (Principle 14) and the contributor obligations apply to us, not the "no contributed data" exemption CF and WMR use. ## 2. Composition | Seat | Submits (Signer Protocol v4) | Bias, stated | Minimum | |---|---|---|---| | Issuer (peg-integrity gate) | `reserve-snapshot`: reserves, supply, as-of time, evidence reference, redemptions open, mint/burn paused. Gates publication; never sets the price | high | exactly one per instrument | | Lender (independent validator) | `independent-mark`: its own mark and time, collateral eligibility, haircut. The value publishes only within its declared tolerance (default 25 bp) | low | ≥ 1 lender **or** venue in every `K` | | Venue (price contributor) | `window-trades`: trade count, volume, VWAP, low, high, halt seconds (or time-weighted quotes if nothing traded). Its VWAP feeds the volume-weighted median | where its book is | pilot: 1, flagged single-source on every value (`minVenues` = 1); 2 independent operators recommended before any official fixing | | Custodian / reserve holder | `custody-reconciliation`: holdings, ledger holdings, encumbered units, statement time | neutral, liable | mandatory when the native network is not the settlement ledger (rulebook §4.8) | | Transfer agent | `register-reconciliation`: register shares, ledger shares, register time | neutral | fund products only | | Administrator (ETP Foundry) | proposes, computes, publishes | — | **not a member** (enforced on-ledger) | `N` and `K` per committee are declared in the committee's on-ledger record and printed on every value. Pilot minimum is `N=3, K=2` with three seats whose interests differ (rulebook §6); the pilot label is printed on every value and sunsets when a fourth seat is filled. **Independence tests** (from CF "independent = different operators", IBA PMOC §6): - parties the issuer controls or is affiliated with may never reach `K` together; - the issuer may not also hold the custodian or venue seat for its own instrument; - a venue owned by the issuer or the administrator is disclosed and does not count toward the independent venues; - a lender that is an issuer affiliate counts as issuer-controlled. ## 3. Eligibility — entity, individual, arrangements Every seat, before a credential is issued: 1. **Entity**: a named legal entity, disclosed principals, disclosed licence or regulatory status, balance sheet at risk on the data submitted. No oracles, no data vendors, no "neutral attestors for a fee" (rulebook §6). 2. **Individuals**: the people who will confirm are named, have "appropriate experience, skill and training" (WMR ToR wording) in the function they attest, and have completed the protocol walkthrough (signer portal "Your seat" panel or a 30-minute call). 3. **Arrangements**: a written data/attestation agreement; a named alternate; an escalation contact reachable at the strike; declared tolerance in basis points (default 25 bp, rulebook §6) and, for issuers and custodians, declared attestation cadence (default freshness 24 h). 4. **Signed appointment letter and code of conduct** (§6 and §7 below). 5. **Public disclosure** in the roster table (§5). Seat-specific entity tests, taken from the closest TradFi analogue: | Seat | Must show at onboarding | Re-checked | |---|---|---| | Issuer | the four on-ledger facts of rulebook §4.1; declared **reserve model** (`attested` / `onchain-verifiable` / `custodial`) — which decides what its `evidenceRef` points to; attestation cadence; redemption window terms | annually, and on any change of reserve model | | Lender | actually holds the instrument as collateral (position evidence); a liquidation engine or risk book that consumes a mark; declared tolerance | quarterly position re-confirmation | | Venue | all six rulebook §4.0 tests plus CF's four: executed data-sharing agreement, API exposing trade **and order** data, KYC/AML programme, cooperation with inquiries; volume share ≥ 5 % of observed 30-day volume trending to 3 % over 90–180 days | annual conformance review, presented to the committee and minuted | | Custodian | regulated custodian (or protocol-controlled contracts under `onchain-verifiable`); client assets segregated; independent control report (SOC 1 / ISAE 3402) or on-chain proof; statement age ≤ freshness | annually; immediately on any lien or rehypothecation | | Transfer agent | appointed under the fund's governing documents; maintains the register; daily reconciliation; SLA with the administrator | annually | ## 4. Terms of office Copied from IBA's selection document, because indefinite seats are the thing to avoid: - initial term **six months** from appointment (the pilot's shadow run of about 90 days, under the pilot letter, comes before appointment), auto-extended to **three years** on the committee's first annual review if the seat has met its obligations; - maximum **nine consecutive years**, then a minimum one-year gap; - **annual membership review** at the fourth quarterly meeting: obligations met, conflicts re-declared, tolerance re-declared, trust level reviewed; - alternates act only with the administrator's prior written agreement and are disclosed in the fixing record like any other signer. ## 5. Public roster and conflicts disclosure No seat is real until it is on the public roster page. The table follows IBA's "Composition and Disclosure of Conflicts of Interest" format, with two columns of ours: | First name | Surname | Company | Market position | Seat & instruments | Voting | Directorships & interests | Date of COI declaration | **Trust level** | **Declared tolerance** | |---|---|---|---|---|---|---|---|---|---| Printed under the table, verbatim in spirit from IBA: *members may themselves use the benchmark, may provide input data to it, and may hold a commercial interest in the assets it prices. That is the design: differing interests, disclosed.* The administrator's own conflicts are disclosed on the same page (the way CF discloses Kraken): any position in a priced asset, any commercial relationship with a member, and the impersonation capability of rulebook §6.7. **The administrator's own conflicts, disclosed.** The fund and ETP issuer licence includes a component linked to the assets under management of funds that reference ETP Foundry fixings. AUM rises with the fixing level, so this is a conflict of interest for the administrator. It is disclosed; the controls are that the administrator computes but never attests, cannot sign (the ledger refuses it as a member), and does not trade the instruments. The administrator also operates the settlement desk and creation/redemption, and today operates every committee seat on DevNet; both are disclosed conflicts. ## 6. Ongoing obligations (all seats) 1. Confirm or refuse **every** fixing for the instruments the seat covers, within the confirmation window; silence is recorded as silence, not as consent. 2. **Send the seat's required submission, from the firm's own systems.** Under Signer Protocol v4 each seat sends one numeric submission per strike (Methodology v1.0 §4). A malformed submission, or a confirmation that omits the seat's required submission, is refused (422) naming the field, and nothing is recorded. A well-formed submission that fails its gate is recorded as the seat's refusal, with the numbers. A figure the firm's systems cannot produce is not estimated: the checker halts and nothing is sent. 3. **Tolerances are declared, not adjusted per fixing.** Widening a tolerance is a change to the seat's record, dated and disclosed. 4. **Declare conflicts** before any fixing they touch; **annual re-attestation** of fitness and propriety, conflicts and confidentiality (WMR ToR §2.3). 5. **Notify** any change of control, licence status, role, reserve model, custodian or material position within five business days. 6. **Cooperate with inquiries** into any fixing, complaint or surveillance alert. 7. **Confidentiality** of other members' submissions and of unpublished proposals. The public record shows who signed, under which protocol, and the determination (input level, method, venues used and excluded); per-venue figures are published only with that venue's consent. 8. **Key custody at the declared trust level** (L1 pilot, L2/L3 official). A seat at L1 is told, in writing, that the administrator could technically act as its party. ## 7. Suspension and removal | Trigger | Consequence | Who decides | |---|---|---| | Missed attestation for one full cadence (issuer, custodian) | seat suspended; fixing moves to `EXCEPTIONAL`, then `NO FIXING` (chain-event policy §2.1) | administrator, immediately; committee at next meeting | | Three consecutive unexplained silences | membership review (IBA "three consecutive meetings") | committee | | Refusal three times without stated cause (rulebook §7.3) | membership review | committee | | Lender position falls to zero | seat lapses at next quarterly review | committee | | Venue volume below threshold | takes effect at next review; anyone may nominate removal | committee, decision published | | Any regulatory or court sanction for market manipulation | **mandatory resignation** (IBA PMOC §6) | automatic | | A knowingly false submission | removal; the fixing is reviewed under the restatement policy | committee; published | | Insolvency or loss of licence | immediate suspension (chain-event policy §2.3) | administrator | | Disagreeing with a fixing | **never a ground** (operations runbook, §6) | — | The administrator may **suspend** ad hoc; only the committee makes a removal permanent; every suspension and removal is published with its reason (CF process). ## 8. Meetings, quorum, minutes - **Quarterly**, fixed agenda (the operations runbook, §4); the administrator attends without a vote. - **Quorum**: `K` of `N` present, including at least one lender or venue. - **Minutes** within eight working days; a **public summary** within fifteen; the full minutes to members and licensees. Where the administrator acts against a committee decision, the minutes record it and the reason. - **Annual self-review** of these terms at the fourth meeting. ## 9. Responsibilities (the standing list) The committee of seats is **not** an oversight function (Methodology v1.0 §9.1): its members hold positions. The list below is review by interested parties. No independent oversight function exists yet; once constituted it takes the methodology, cessation and complaints decisions (items 7–9), and until then the administrator performs those reviews, publishes them and says that it does. Complaints are acknowledged within 2 business days and answered within 20, with reasons. 1. Review every `NO FIXING`, carry-forward and restatement of the quarter. 2. Authorise a response after **three consecutive carry-forwards** on any instrument (CF charter duty). 3. Review the constituent venue list; decide additions, suspensions, removals (policies document, §4). 4. Admit and remove members (§3, §7); decide whether `K` moves when `N` changes. 5. Review the conflicts register and the administrator's impersonation log. 6. Review surveillance alerts and venue conformance reports. 7. Review complaints escalated under the policies document, §1. 8. Approve methodology consultations and their feedback statements (policies document, §2). 9. Approve cessation or transfer of any benchmark (rulebook §9). 10. Oversee third parties involved in calculation or dissemination, including the transfer agent and any data provider. 11. Report suspicious input data to the administrator, and where required, to the relevant authority. 12. Review the quarterly error table (policies document, §3). 13. Review tolerances in aggregate and the trust-level mix of the quarter's fixings. 14. Review these terms annually. ## 10. Appointment letter (template) > **Appointment to the ETP Foundry NAV Committee — [Instrument(s)] — [Seat]** > > [Firm] is appointed to the [Seat] seat of the NAV Committee for [instrument(s)] from > [date], for an initial term of six months under the Terms of Reference v1.2, the > Signer Protocol v4 and ETP Foundry Methodology v1.0, all attached. > > Named signers: [name, role, e-mail], alternate [name]. Trust level at appointment: [L1/L2/L3]. > Declared tolerance: [n] bp. Reserve model (issuers): [attested / onchain-verifiable / custodial]. > Attestation cadence (issuers, custodians): [n] hours. > > Nothing is paid or charged for this seat, now or later. [Firm] may resign on thirty days' > written notice (during the pilot, before this appointment, either side may stop at any time); the > administrator may suspend under ToR §7. > > [Firm] confirms that the conflicts declared in the attached schedule are complete and > agrees to the code of conduct in ToR §11. > > Signed for [Firm] ______ Signed for ETP Foundry ______ Date ______ ## 11. Signer code of conduct Modelled on IOSCO Principle 14 and BMR Art. 15, and identical in substance to Methodology v1.0 §9.3; signed before the first credential is issued. 1. I submit only data my firm's own systems produced for the stated window or time: executed trades, our own mark, our own reserve, custody or register records. I never submit an estimate or someone else's number as our own; if a figure cannot be produced, the checker halts and nothing is sent. 2. I keep my declared tolerances and cadence. They are set in advance in the seat settings; I never widen one at submission time to make a check pass, and any change goes through the administrator, dated and disclosed. 3. I declare every conflict before a fixing it touches, and re-declare annually. Where my firm also trades the instrument, those who submit are not those who trade it, or the conflict is declared and managed. 4. I keep unpublished proposals and other members' submissions confidential. 5. Each submission is produced by an automated checker or a documented manual procedure, by named people and credentials under my firm's control; changes to the checker's data sources are recorded. I rotate a credential on any suspicion of exposure, and I do not share a seat. 6. I will resign the seat if my firm or I are sanctioned for market manipulation. 7. I understand that a knowingly false submission is grounds for removal and public disclosure. 8. I understand that at trust level L1 the administrator could technically act as my party, that every such act is logged and disclosed, and that L2 or L3 is required before any OFFICIAL fixing settles a third party's product. 9. I keep the data behind each submission for five years and produce it to the oversight function or an authority on request; I cooperate with inquiries into any fixing I confirmed or refused; and I report to the administrator any attempt to influence a submission, and any trading I believe was intended to move a window's prints. 10. I understand refusing a fixing is the mechanism working and is never held against me. --- *Status: v1.2, drafted from verified precedents; not yet adopted by a committee because none has met. It becomes effective on adoption at the first quarterly meeting and is printed with that date on the public roster page.*