The Riffle
The Financial Services Regulatory Authority (FSRA) of Abu Dhabi Global Market (ADGM) has published Consultation Paper No. 5 of 2026 (CP5/2026), seeking feedback on proposed DeFi Risk Management Guidance. Published on 6 October 2026, the consultation addresses how regulated entities should manage risks arising from interaction with decentralised finance protocols and infrastructure. Comments close on 30 November 2026. ADGM public consultation
As outlined in the accompanying executive briefing, the proposal focuses on Authorised Persons and Recognised Bodies whose regulated activities or functions involve, depend on, or are materially affected by DeFi protocols and infrastructure.
The central message is straightforward: using decentralised technology does not remove institutional responsibility. Firms engaging with DeFi would need to demonstrate that their activities fall within existing permissions and that their controls address the risks of the underlying technology.

Key highlights
Existing permissions remain the starting point: The proposed guidance would not create a new DeFi licence or expand a firm’s Financial Services Permission.
Accountability stays with the regulated entity: Interaction with a protocol would not amount to regulatory recognition of that protocol or its external providers.
Client asset safeguards continue: DeFi engagement would not relax existing custody, segregation or client money obligations.
Risk assessment should cover each layer: Firms would need to consider smart contracts, keys, governance, price feeds, bridges and infrastructure dependencies.
Monitoring should reflect continuous markets: DeFi risks can develop outside business hours, requiring appropriate monitoring, escalation and operational coverage.
Automated execution needs defined limits: Routing software and AI agents would need controls over permitted protocols, exposure, slippage and human intervention.
Exit plans cannot carry the whole risk strategy: Exposure limits and protocol selection matter before funds are committed, particularly where stressed markets could obstruct withdrawals.
What is proposed, and what should firms consider next?
Boards and senior management: make DeFi accountability explicit
The briefing describes an approach built around governing body oversight of DeFi strategy, risk appetite and material exposures. Senior management would translate that oversight into approval procedures, monitoring arrangements and incident response plans.
For firms considering DeFi engagement, a practical starting point is to identify who owns each risk and who can act when limits are breached. Technical specialists, compliance teams and risk functions need a shared understanding of how the activity operates.
Protocol automation and external service providers do not remove the need for named individuals to oversee decisions and controls.
Compliance teams: establish permissibility before protocol suitability
The proposed approval sequence begins with whether an activity is permissible under the firm’s existing permissions. Alignment with risk appetite and detailed due diligence follow.
This ordering matters. Strong technical controls cannot make an activity permissible if it falls outside the firm’s authorised scope.
The briefing also highlights early FSRA engagement where an activity is novel or its regulatory classification is uncertain, alongside consultation before placing Client Assets into a DeFi structure. Firms should assess proposed arrangements against the applicable rules and the original consultation text before proceeding.
Risk and technology teams: look beyond the protocol itself
A smart contract audit is one part of due diligence. A fuller assessment considers who can upgrade the protocol, how administrative keys are controlled, what emergency powers exist and which external systems the protocol relies on.
Oracles supply external information, such as prices, to smart contracts. Bridges move assets or messages between networks. Failures in either can affect a position even where the main protocol operates as designed.
Shared dependencies also complicate diversification. Positions across several protocols may still depend on the same price feed, bridge or blockchain infrastructure. Firms should therefore assess concentration across common failure points as well as individual exposures.
Stress testing should explore scenarios such as stablecoin depegs, manipulated prices, bridge failures, governance capture and sudden liquidity withdrawal.
Operations teams: prepare for incidents outside business hours
DeFi operates continuously, and exploits can spread within seconds or minutes. Monitoring is useful only when alerts reach people with the authority and tools to respond.
The briefing emphasises tested escalation procedures and response actions, including pausing activity, revoking contract permissions and isolating exposures where feasible.
Exit planning also needs realistic assumptions. Congestion, limited liquidity or technical restrictions may prevent a timely withdrawal during stress. Position sizing and exposure caps therefore remain essential preventive controls.
Automated trading teams: build policy into execution
Automated routers and AI agents can interact with several contracts in a single execution path. Controls should account for the protocols, pools and intermediate assets encountered along that route.
The proposed approach described in the briefing includes permitted venues, prohibited intermediate tokens, exposure limits, slippage thresholds and mechanisms for human intervention.
Recordkeeping should also explain the decision behind a transaction. Firms need sufficient information to reconstruct routing, approvals, screening and exceptions, alongside the onchain transaction record.
Financial crime and custody teams: retain visibility and control
Public transaction records do not, by themselves, establish the identity or risk profile of participants. Wallet screening, transaction monitoring and assessment of exposure through liquidity pools remain relevant.
The briefing also highlights traceability concerns where privacy features prevent effective screening. Custody assessments should address signing authority, key recovery and persistent token approvals that allow contracts to move assets.
These suggested preparation steps are practical considerations drawn from the briefing. The proposed guidance remains subject to consultation, while existing regulatory obligations continue to apply.
Conclusion
The proposal described in the briefing would bring greater specificity to how ADGM-regulated entities assess and oversee DeFi engagement. Its emphasis spans permissions, governance, custody, infrastructure dependencies, automated execution and incident readiness.
Firms considering DeFi should use the consultation period to assess whether their existing controls can support the proposed activity and identify areas where further regulatory clarification is needed.
The Riffle takeaway
DeFi participation requires clear institutional accountability. Confirm permissions first, understand the dependencies behind each exposure, and ensure people and controls can respond when markets and protocols are under stress.
Consultation deadline: 30 November 2026.
