Institutions hesitate because direct DeFi participation introduces smart contract risk, uncertain insurance coverage, and weaker regulatory clarity than traditional custody models. They also face greater accountability when managing other people’s money, which raises the bar for due diligence. For that reason, many institutions start with asset holding and only expand into DeFi once controls, oversight, and risk transfer mechanisms are stronger.
Why institutions stop at custody instead of touching DeFi directly
For an institution, “using DeFi” is not just a trade decision, it is an operating model decision. Direct protocol participation exposes the institution to smart contract failure, oracle and bridge dependency, and fast-moving governance or parameter changes that are harder to bound than a custody-only posture. It also creates a higher evidentiary burden for approvals, monitoring, and client accountability when the capital belongs to others.
The custody-first approach preserves optionality. Institutions can hold digital assets, then decide whether any protocol interaction is justified after they have mapped the contract risk, the operational controls, and the legal basis for acting on behalf of clients. That is why the debate is often less about “can we use DeFi?” and more about “can we justify the control and accountability model that direct use requires?”
That distinction matters because direct participation changes the risk surface in ways custody alone does not. A custody model concentrates risk in storage, segregation, and key management, while protocol use adds execution risk, on-chain failure modes, and dependence on code that may be difficult to unwind once deployed. For institutions, the practical question is whether those extra dependencies are material enough to outweigh the yield, access, or product-design benefit.
What actually changes when an institution goes on-chain
Direct DeFi use adds three material layers on top of simple asset holding. First, there is contract and protocol risk, including logic bugs, upgradeability surprises, governance capture, and integration assumptions that can fail under stress. Second, there is accountability risk, because asset managers, trustees, and fiduciaries need to explain why a particular protocol, pool, or routing path was acceptable at the time of use. Third, there is regulatory and legal uncertainty, especially where asset classification, custody obligations, disclosures, and client suitability vary by jurisdiction.
Institutions also face a control mismatch. Traditional custody models are built around segregated accounts, established counterparties, and documented recovery paths. DeFi execution can require wallet signing, real-time transaction approval, and dependency on external infrastructure such as RPC endpoints, bridges, oracles, and third-party front ends. Each of those adds a possible point of failure that can affect both losses and auditability.
For practitioners comparing protocol access with holding only, the operational issue is not whether one control is “better,” but whether the institution can bound blast radius. If the institution cannot reliably limit exposure per strategy, venue, or client mandate, direct participation tends to be treated as a premium-risk activity rather than a default operating posture. The broader the mandate, the more conservative the initial entry point usually becomes.
Risk and Threat Considerations
Direct DeFi exposure can fail in ways that custody-only holdings do not. Smart contract defects, oracle manipulation, bridge compromise, and governance attacks can convert an ordinary transaction into an irreversible loss event. For an institution, the issue is amplified by fiduciary duty and the need to show that the selected protocol, controls, and permissions were reasonable before the loss occurred.
Failure mechanism: A protocol dependency breaks, a contract behaves unexpectedly, or a connected service is compromised, and the institution has limited ability to reverse or contain the position once funds have been moved on-chain.
Impact: Losses can include direct asset loss, forced impairment, client claims, reporting complications, and a higher threshold for future approval of on-chain strategies.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.2 — Risk Management Strategy | DeFi entry changes enterprise risk strategy and tolerance. |
| GV.4 — Cybersecurity Risk Management Strategy | Direct protocol use introduces contract and operational risk needing formal treatment. | |
| ID.RA — Risk Assessment | The question centers on assessing contract, regulatory, and accountability risk. | |
| Recommendation — Define DeFi participation limits through explicit risk appetite and governance approval. Align DeFi exposure decisions to documented cyber risk management criteria. Assess protocol, governance, and legal risks before direct on-chain use. | ||
| CIS Controls v8 | 6 — Access Control Management | Protocol interaction depends on tightly bounded transaction and wallet access. |
| 3 — Data Protection | Institutions need to protect signing material, transaction data, and client records. | |
| Recommendation — Restrict DeFi transaction authority to approved users and use cases. Protect wallet secrets, signing workflows, and sensitive transaction artifacts. | ||
| NIST AI RMF | GOVERN — Govern | Institutions need governance for AI-like autonomous or algorithmic decision workflows in DeFi operations. |
| MAP — Map | Protocol use requires mapping business purpose, stakeholders, and risk context. | |
| Recommendation — Establish governance for any automated or model-assisted DeFi decision process. Map DeFi use cases, dependencies, and accountability before deployment. | ||
Practitioner Guidance
What to verify: Before any direct DeFi use, verify whether the institution can evidence protocol due diligence, pre-trade approval, transaction-level controls, and post-trade monitoring. The minimum bar is not just “did we understand the protocol,” but “can we prove who approved the risk, what limits applied, and how exceptions are handled.”
Decision rule: If the activity cannot be bounded by mandate, liquidity profile, and counterparty analysis, treat it as an experimental or restricted strategy rather than a routine treasury function. If the institution is managing client money, require a stronger review standard than would be used for proprietary capital.
Practitioner takeaway: Institutions usually hesitate because direct DeFi use converts a holding decision into an execution, governance, and accountability problem, so adoption should follow control maturity, not precede it.
Related resources from NHI Mgmt Group
- Who should use digital certificates instead of simpler MFA methods?
- When should organisations use a digital signature instead of a basic electronic signature?
- What fails when DeFi protocols allow broad standing access to assets and contract controls?
- When should organisations use digital credentials instead of document capture and selfie checks?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 17, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org