The same data, read as a bank
How a DeFi finding translates into a bank's own risk categories — and where the translation has no equivalent.
This lesson has had no expert review. It was written for this platform and against the evidence it cites; nobody has gone through it independently.
Learning objectives
- You can map a DeFi finding onto a bank's risk categories.
- You can name the findings for which no established equivalent exists.
Check your prior knowledge
Answer these for yourself before reading on. Wherever you hesitate is where this lesson pays off.
- Which risk categories does your institution distinguish?
- Where would a smart contract failure be booked today?
- Who owns a risk that fits no category?
Core concept
Most findings have an equivalent
A collateral price move is market risk. Bad debt is credit risk. Constrained withdrawals at high utilization are liquidity risk. Key management and signing processes are operational risk. Those four cover most of what a DeFi position carries, and every institution already defines, measures and reports them.
Three findings with no equivalent
First, smart contract risk: not market risk, not credit risk, and operational risk fits only with reservations because the failing process is not one's own. Second, governance risk: a change of terms by third parties with no contractual relationship. Third, oracle risk: a data source that directly decides whether collateral is liquidated. Forcing these three into an existing category loses exactly the information that makes them distinctive.
Concentration arises across the categories
The real institutional question is not which category a single finding falls into, but how much of the book hangs on the same dependency. A shared stablecoin or oracle provider creates a concentration that appears in none of the classic risk categories, because it lies across all of them — and for exactly that reason needs a listing of its own.
Definitions
- Concentration risk
- Risk from an accumulation of similar or jointly dependent positions.
- Risk category
- One of the established categories a bank measures and reports risk under.
Model
Observation from the data
Map to an existing risk category where one fits
Otherwise: a finding of its own, with reasons why none fits
Across all of it: a listing by shared dependency
Worked example
One finding, four sub-findings
- Finding
- lending market, 96 % utilization, oracle from a tradable pool
- Market risk
- collateral price move
- Liquidity risk
- 4 % free capital
- Credit risk
- possible bad debt
- No equivalent
- oracle manipulability
Three of the four sub-findings map cleanly and can be measured with existing procedures. The fourth can be described but not booked into an existing category.
Three booked, one carried as a finding of its own.
Reading: The fourth is the one carrying the decision. A mapping that makes it disappear under “operational” makes the report complete and the decision worse.
Retrieval
Exercise on real data
Go through the twelve dimensions and mark, for each, which of your institution's risk categories it feeds — and where you find none.
Institutional impact in the framework →Application
Which additional listing do you recommend alongside the existing risk report — and what is its one decisive row?
Related case studies
- CASE-13 — Classification under the Basel standard
- CASE-04 — A dependency chain across four protocols
- CASE-02 — Stablecoin under stress
Institutional reading
- Bank
- Who inside the institution owns a finding that falls into no risk category?
- Insurance
- Which of the three findings with no equivalent would be insurable at all?
Metrics in this lesson
Key takeaways
- Most DeFi findings have an established equivalent — three do not.
- A finding forced into a nearby category disappears from the decision.
- Concentration through shared dependencies lies across all risk categories.