RIA·DeFi
Due diligence

DeFi due-diligence checklist for financial advisors

A protocol audit is one input. Advisor diligence has to connect the client’s legal and economic exposure to every technical and operational dependency.

By 10 min read

Educational analysis for financial professionals. Not legal, tax, compliance, or investment advice. Regulatory statements are source-linked and time-stamped.

Reader objective

Build a repeatable pre-approval and monitoring process.

1. Define the position

  • Name the exact token, contract, chain, protocol, market, and strategy.
  • State the economic exposure and source of expected return.
  • Identify the legal claim, issuer, counterparty, or lack of one.
  • Record eligible investor and jurisdiction restrictions.

2. Map the dependency stack

  • Asset issuer, collateral, redemption, and freeze authority
  • Protocol contracts, upgrades, pauses, governance, and audits
  • Oracles, bridges, curators, keepers, relayers, and front ends
  • Chain liveness, transaction ordering, validators, and upgrade control
  • Wallet, custodian, signer, recovery, and transaction-approval workflow

3. Test loss and exit

  • Historical exploits, bad debt, depegs, halts, and governance failures
  • Observable liquidity at client size—not only TVL
  • Redemption gates, queues, market depth, fees, and settlement delay
  • Failure scenarios for oracle, bridge, collateral, issuer, and keys
  • Expected recovery path and responsible party

4. Make the decision monitorable

  • Written verdict and reasons
  • Position or sleeve limit
  • Observable kill criteria set before investment
  • Named owner, next review date, and evidence archive
  • Client-language risk statement and suitability rationale
  • Version history for corrections and changed decisions
Evidence standardIf a fact can revoke the recommendation, record its source and monitoring method when the position is approved.

Primary and reference sources