2026-10-06
Added
The Financial Services Regulatory Authority proposes supervisory guidance requiring Authorised Persons and Recognised Bodies to maintain risk management arrangements proportionate to their engagement with decentralised finance. The guidance outlines expectations for identifying, assessing, and managing operational, governance, technology, and financial crime risks arising from interactions with DeFi infrastructure and exposures. Regulated firms must determine the applicable prudential, conduct, and asset safeguarding requirements for each exposure without assuming that DeFi usage alters underlying legal characteristics. The regulator seeks public comments on these proposals by 30 November 2026.
FSRA published 4 documents in the last 30 days — get each new one by email the day it lands.
CONSULTATION PAPER
NO. 5 OF 2026
DeFi Risk Management Guidance
6 October 2026
Table of Contents
Introduction .................................................................................................................. 3
Background................................................................................................................... 5
Proposed DeFi Risk Management Guidance ..................................................................... 6
Other Consultation Questions ........................................................................................ 8
Conclusion.................................................................................................................... 9
Attachments ................................................................................................................. 9
Why we are issuing this paper
The Financial Services Regulatory Authority (the “FSRA” or “we”), the financial services
regulator of Abu Dhabi Global Market (“ADGM”), is issuing this Consultation Paper (“CP”) to seek public comment on the proposed DeFi Risk Management Guidance (the “Guidance”).
The Guidance sets out the FSRA’s expectations for how Authorised Persons and
Recognised Bodies should identify, assess, monitor and manage risks arising from engagement with decentralised finance (“DeFi”) arrangements in connection with their Regulated Activities or Regulatory Functions.
The proposed Guidance has been developed in response to increasing market interest
in DeFi activity and the FSRA’s continuing engagement with digital asset markets. It follows the FSRA’s Discussion Paper No. 1 of 2022 on DeFi policy considerations which explored the opportunities, risks and possible future regulatory treatment of DeFi. This CP and the proposed Guidance advance that effort from policy discussion to practical supervisory expectations, without implementing the illustrative framework discussed in the 2022 paper.
DeFi can bring programmability, transparency, broader market access and new models
for financial intermediation. Those features may support more efficient financial services, but they can also compress the time in which risks emerge and spread. The FSRA’s focus is therefore on enabling regulated firms to engage with DeFi with robust risk governance and oversight in place.
The Guidance does not create a framework for regulating DeFi protocols or
decentralised activities, establish new types of digital assets, or determine whether a particular protocol, activity, token, receipt, claim or synthetic exposure falls within the FSRA’s regulatory perimeter. Those assessments will continue to be undertaken on a case-by-case basis with regard to the Financial Services and Markets Regulations 2015 (“FSMR”), the FSRA Rulebooks and any other applicable FSRA framework and guidance, having regard to the substance and operation of the relevant activity, instrument or arrangement. Introduction
Unless otherwise defined or the context otherwise requires, capitalised terms which
appear in this paper have the meanings attributed to them in FSMR, the FSRA’s Glossary Rulebook (“GLO”) or other relevant Rulebooks or guidance. How to provide comments
We welcome comments on the proposed Guidance and suggestions for alternative
approaches to address the regulatory considerations raised herein. Comments supported by reasoning and evidence will be given more weight.
All comments should be made in writing and via email. When submitting your
comments, please use the Consultation Paper number in the subject line. If relevant, please identify the organisation you represent when providing your comments. We reserve the right to publish any comments you provide, including on our website, unless you expressly request otherwise when submitting those comments. Email: fsra.consultation@adgm.com What happens next
The deadline for providing comments on these proposals is 30 November 2026. When
we receive your comments, we will consider whether any modifications to the Guidance are required. The FSRA will then proceed to publish the Guidance in its final form.
As the digital asset ecosystem develops in ADGM, regulated firms may increasingly
interact with smart contracts, automated market makers, liquidity pools, tokenised claims, bridges, oracles and other decentralised infrastructure. These arrangements can impact how financial services are designed, delivered and connected, while introducing dependencies that may be difficult to identify or control through conventional risk management approaches.
In 2022, the FSRA published Discussion Paper No. 1 of 2022 on “Policy
Considerations for Decentralised Finance” to foster dialogue with industry and other stakeholders on the potential opportunities and risks arising from DeFi, and on what a future regulatory framework for DeFi might resemble. The paper recognised the potential for DeFi to support efficiency and innovation, while also identifying risks to investors, financial institutions and the financial system where relevant activities, dependencies or exposures are not subject to effective controls, clear lines of accountability and oversight.
This Consultation Paper and the proposed Guidance build on that earlier policy
discussion, but they do not implement the illustrative framework discussed in the 2022 DeFi Discussion Paper. The FSRA is not at this stage creating a framework for regulating DeFi protocols, introducing a new set of regulated DeFi activities, or determining the regulatory treatment of DeFi governance tokens or other DeFi-related instruments. Instead, the proposed Guidance focuses on how Authorised Persons and Recognised Bodies should manage the risks arising from their own engagement with DeFi within the existing FSRA framework.
Such engagement may create operational, governance, technology, financial crime,
conduct, custody and prudential risks. These risks may crystallise rapidly and may transmit across protocols, infrastructure providers and markets through interconnected or composable arrangements. DeFi arrangements may also involve dependencies on smart contracts, cryptographic keys, external data sources, offchain governance arrangements, bridges, validators, sequencers, wallet infrastructure or other technology and service providers.
Existing regulatory requirements continue to apply to regulated firms engaging with
DeFi. The purpose of the proposed Guidance is to explain the FSRA’s supervisory Background
expectations in that context, without creating a separate protocol approval framework, altering the regulatory perimeter, waiving existing obligations, or changing the classification or treatment of any digital asset or exposure.
6. The proposed Guidance organises the FSRA’s DeFi risk management expectations
into three main sections covering the firm’s risk management arrangements, the infrastructure on which its engagement depends and the nature of the resulting exposures. Effective DeFi risk management
7. Section 2 of the Guidance proposes that a regulated firm should maintain risk
management arrangements proportionate to the nature, scale and complexity of its DeFi engagement. Those arrangements should address:
Question 2
Do you consider the proposed Guidance to be actionable regarding the governance, risk management and control arrangements that regulated firms should maintain when engaging with DeFi arrangements? DeFi infrastructure risks
8. The proposed Guidance identifies infrastructure risks that may arise from the
technology, governance and dependencies supporting a DeFi engagement. These include risks associated with custody and asset access, wallet and signing arrangements, privacy, traceability, financial crime controls, smart contracts, protocol governance, oracles, bridges and interoperability, composability, transaction execution, mechanism design and emerging infrastructure.
9. The identified risk categories are illustrative and non-exhaustive. Firms are expected
to assess the particular risk profile and dependencies of each material DeFi engagement rather than treating DeFi as a single composite risk. This assessment should include whether the:
DeFi exposure risks
10. The proposed Guidance also addresses risks associated with particular forms of DeFi
exposure, including Fiat-Referenced Tokens, synthetic and derivative-like exposures, receipt tokens and tokenised claims, and wrapped, bridged or cross-chain assets.
11. The Guidance does not classify these instruments or alter their treatment under
existing FSRA frameworks. A regulated firm must determine the nature of each exposure and the applicable prudential, conduct, market integrity, asset safeguarding and AML requirements. Where an exposure involves or may involve a Virtual Asset, Fiat-Referenced Token, Digital Security, derivative, derivative-like, tokenised claim, staking-related exposure or other digital asset arrangement, the firm must consider the relevant FSRA framework and should not assume that the use of DeFi changes the underlying legal or regulatory characteristics of the asset or activity. Question 5 Does the proposed Guidance appropriately identify and address the principal risks associated with DeFi exposures, including Fiat-Referenced Tokens, synthetic exposures, tokenised claims and wrapped or bridged assets?
12. The FSRA invites comments on all aspects of the proposed Guidance. In particular,
respondents are invited to address the questions set out below, alongside those above. Respondents are encouraged to provide reasons and supporting evidence for their views. Other Consultation Questions
Question 6 – Unsuitable engagements
Should any specific categories of DeFi engagement be regarded as unsuitable for regulated firms? If so, please detail them, explain the basis and suggest objective criteria. Question 7 – Implementation Would implementation of the proposed Guidance give rise to significant operational, compliance, technology or supervisory challenges? Question 8 – Other matters Are there any other matters that the FSRA should consider before finalising the proposed Guidance?
13. The proposed Guidance is intended to support the safe, sound and orderly
engagement with DeFi by Authorised Persons and Recognised Bodies. It reflects the FSRA’s view that the potential benefits of DeFi can be responsibly pursued through informed risk treatment, clear accountability and controls proportionate to the nature of each engagement. The FSRA encourages stakeholders to provide written feedback on the questions set out in this CP and on any other aspects of the proposed Guidance that may require clarification, amendment or further consideration before finalisation. Attachment 1 – Draft DeFi Risk Management Guidance Attachments Conclusion
Read the rest free
Source: Financial Services Regulatory Authority — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from FSRA
FSRA published 4 documents in the last 30 days. We email you each new one the day it's published.