Recaps

Where Onchain Risk Controls Belong: Notes From a Roundtable With WisdomTree, Plume, and OpenZeppelin

August 19, 2026

On August 12 Forta hosted Institutional Finance Goes Onchain: Risk, Compliance and the Road Ahead, with Rohan Ranadive (Head of Risk, Digital Assets, WisdomTree), Alex Palmer (Plume), John Neufeld (General Counsel, OpenZeppelin) and Laeeq Shabir (Partner, HT Digital). Andy Beal, Forta's Head of Institutional Strategy, hosted. Five ideas stood out.

Two universes are colliding. Rohan opened with the framing that anchored the hour. One universe is institutional: tokenized real world assets in the tens of billions, stablecoins past $300 billion and a regulatory stack spanning GENIUS, MiCA, Hong Kong and Singapore. The other was born onchain: always on, permissionless, composable. Universe one needs the liquidity of universe two. Universe two needs the assets of universe one. The collision is a question of pace, not of whether.

The line between financial and non-financial risk is dissolving. Onchain, a single misconfiguration can trigger a cyber event, a collateral event, a liquidity event and a compliance event at once, from the same root cause. Rohan was careful here: the taxonomy is not wrong, and regulators still think in those categories. What changes is where risk originates and how fast it propagates. His conclusion: risk architecture has to operate in real time, and not by committee on Thursday.

Controls are moving from detective to preventive. Laeeq identified this as the foundational shift from an assurance perspective. Frameworks were built to detect and remediate after the fact and the center of gravity has moved to prevention, both in how firms build and in what regulators are asking for. Where those controls belong was the session's real disagreement. Many issuers embed them in the token itself. Alex argued they belong as deep in the stack as possible, so issuers inherit them without having to think about it. Rohan's position was complementary: regulated funds still carry off-chain components, so controls have to span both.

Regulation is asking for outcomes, not methods. John noted that most digital asset regulation taking shape is principle-based, leaving the method open. On why that matters: the current intermediated approach to financial crime produces filings nobody meaningfully reviews, which is a paperwork problem dressed as a control. That puts the burden on builders to show something better actually works.

Utility is where the risk footprint expands. Andy closed on the trend he sees from talking with issuers. First-generation tokenized assets were largely experimentation. The next step is collateral and genuine 24/7 liquidity, which means integrating with lending markets and AMMs, turning a contained instrument into a web of protocol dependencies the issuer does not control.

Laeeq had the closing thought. Everyone is somewhere on the tokenization spectrum, some well ahead and some just beginning, but almost nobody is walking away. The convergence is happening. 

The open question is which risk architecture is standing when it does.

Big thanks to Rohan, Alex, John and Laeeq. A second roundtable is planned for September with new voices at the table. If you would like an invitation, get in touch.

Share