Institutional DeFi is the use of public blockchain lending and yield protocols by regulated entities, under the controls those entities already answer to: custody with a party that can be held to an agreement, identity checks on counterparties, a documented approval behind every position, and accounting output an auditor will accept.
Ticket size is not the qualifier. One person moving a large allocation out of a hot wallet on a seed phrase is running a retail deployment at scale. A smaller position becomes institutional when it sits at a custodian under a written mandate, gets valued at a daily cut-off, and is exported into the fund's accounting system, and how allocators score those controls is set out in a risk framework for onchain allocation.
What makes a DeFi position institutional?
Four controls, all of which live around the position rather than inside the protocol.
Custody comes first. It asks who holds the private keys that can move the assets and whether that party carries an obligation if the keys are lost, and institutions usually go further by requiring those keys to sit behind a policy engine that restricts the addresses funds can reach, so that one compromised laptop cannot empty the account.
Compliance is the second control. In a pooled lending market, the party on the other side is a set of anonymous borrowers who each posted more collateral than they took, a legitimate answer and a different one from "a named bank", and the difference belongs in the documentation. Approval ties every position to a mandate naming the assets, the venues, the maximum exposure and the signatory. Onchain that usually means restricting the wallet to an approved list of contract addresses before anyone deploys. Reporting is the fourth control, and what it needs is a value at the cut-off, a cost basis, an income accrual and a counterparty label, in a file the administrator and the auditor can both read. A block explorer is not that file.
What are institutions actually doing onchain today?
Mostly the plain end of the market: stablecoins supplied to large lending protocols, and tokenized treasury and money market funds held in a wallet rather than at a broker.
Both share a property the rest of DeFi does not. A supply position in an overcollateralized lending market is a claim against borrowers who posted more than they took, with a public liquidation mechanism and a published rate. Wrapped inside a tokenized treasury fund token is a regulated product, with a named administrator and offering documents behind it, and either one can be valued at a cut-off and explained to an investment committee in a paragraph. Institutions are largely not deploying into strategies whose positions cannot be independently priced each day, into leveraged loops, or into allocations where redemption timing is unknown at entry. Approval depends on being able to report the position, and reporting in turn depends on being able to value it.
What is blocking wider adoption?
Custody mechanics, daily valuation, liability that nobody has written down, and the limits of what a contract audit covers.
Custody and deployment pull against each other to begin with. Supplying assets to a protocol means moving them to that protocol's contract, and under some custody arrangements that means leaving the perimeter the institution pays for. Policy-based signing permits transactions only to approved contracts. The question then moves from who holds the keys to who maintains the approved list.
Valuation is the second constraint. NAV requires a defensible price for every position at a fixed time, and some onchain positions have no independent price at all. Liability has no good public answer either. When a pooled position loses money because a risk parameter was set too loosely, the allocation of that loss is often not specified anywhere in the documentation. Ask during diligence and record the answer, including when the answer is that there isn't one.
Audit coverage has a similar gap, and the word is narrower than it sounds. An audit examines contract code and not the keys controlling upgrades, parameters and pause switches, and those keys are a separate failure surface with a separate owner.
Where to start
Start with the risk framework, not the venue selection. Write the mandate first, decide which controls are non-negotiable, then find venues that satisfy them, rather than picking a yield and reverse-engineering approval for it. A DeFi risk framework for institutions sets out the categories to score and the evidence to demand for each. Where the mandate requires every counterparty to be identified, the route is permissioned DeFi. Allocating through a manager rather than deploying directly is onchain asset management.
Common questions
Is institutional DeFi just DeFi with KYC? Identity checks are one part. Custody, mandate enforcement, daily valuation and an exportable audit trail matter as much, and a venue can be fully permissioned while failing every one of them. KYC answers who your counterparty is and nothing at all about whether you can value the position.
Does institutional DeFi have to be permissioned? No. Much institutional activity happens in permissionless lending markets, where control sits with the allocator: restricted signing, approved contract lists, position limits, independent monitoring. Permissioned venues move part of that work to the issuer, and that suits mandates requiring every counterparty to be identified.
What is the difference between holding crypto and deploying it? Holding is a balance sheet position with price risk. Deploying adds a counterparty, risk parameters someone else can change, and a settlement path that may not be instant, so each of those needs its own line in the risk register, and the settlement path is the one most often left out.