Risk Stewards: Cap and IRM Changes on Aave V3: When Delegated Risk Management Becomes Centralized Discretion
The proposal appeared on the Aave governance forum in August 2026 with the bureaucratic precision of a risk committee asking for broader powers. The Risk Stewards—Gauntlet, Chaos Labs, and LlamaRisk—were requesting authority to adjust interest rate m

The proposal appeared on the Aave governance forum in August 2026 with the bureaucratic precision of a risk committee asking for broader powers. The Risk Stewards—Gauntlet, Chaos Labs, and LlamaRisk—were requesting authority to adjust interest rate models and supply caps on Aave V3 markets without going through the full governance process each time. The pitch was speed: in volatile markets, waiting two weeks for a governance vote could mean liquidation cascades and protocol insolvency. The fine print raised a question about whether giving three external firms the power to move millions in protocol parameters is risk management or just governance outsourcing with a risk-management label.
That was the proposal. Then came the question of whether the risk stewards who were supposed to protect depositors from liquidation cascades had become the arbiters of who gets liquidated and when, and whether the speed they promised was for depositors' protection or for the protocols' quarterly revenue targets.
What the Risk Stewards Actually Propose
The proposal describes a delegated risk management framework with specific mechanics:
The Core Components:
- Cap adjustments: Risk Stewards can raise or lower supply and borrow caps within predefined bounds
- IRM modifications: Interest rate model parameters can be adjusted to respond to market conditions
- Timelock bypass: Changes can be executed in hours rather than the standard governance cycle
- Revenue optimization: Interest rate adjustments can increase protocol revenue during high-demand periods
The Current System:
- Full governance votes: Every parameter change requires Aave token holder approval
- Two-week cycle: Proposals go through discussion, voting, and execution delays
- Community oversight: All changes are transparent and subject to token holder veto
- Slower response: Market conditions may change before governance can act
The Proposed Changes:
- Delegated authority: Risk Stewards get limited autonomy to adjust parameters
- Speed: Responses to market stress can be immediate rather than delayed
- Predefined bounds: Steward discretion is constrained by protocol-defined limits
- Accountability reporting: Stewards must report all changes and their rationale
The proposal frames these as operational necessities. They are also a transfer of power from token holders to external risk management firms.

Key Metrics at a Glance
| Dimension | Current (Full Governance) | Proposed (Risk Stewards) | Impact |
|---|---|---|---|
| Response Time | 10-14 days | 2-48 hours | Much faster |
| Governance Participation | High (token holders vote) | Low (stewards decide) | Reduced |
| Parameter Change Frequency | ~2-4 per month | ~10-20 per month | Much higher |
| Revenue Optimization | Limited | Significant | Increased |
| Liquidation Risk | Higher (slower response) | Lower (faster response) | Reduced |
| Centralization Risk | Low | Medium-High | Increased |
| Steward Compensation | Fixed retainers | Performance-linked | Incentive alignment |
The Proprietary Risk Delegation Accountability Score (RDAS)
I've developed a framework to evaluate whether delegated risk management strengthens or weakens Aave governance:
Formula: RDAS = (Speed Benefit × 0.25) + (Governance Preservation × 0.25) + (Conflict Mitigation × 0.2) + (Transparency × 0.15) + (Decentralization Impact × 0.15)
Risk Stewards Assessment:
| Factor | Score | Analysis |
|---|---|---|
| Speed Benefit | 8/10 | The proposal genuinely reduces response time from weeks to hours; liquidation cascades can be mitigated faster; market stress can be addressed before it compounds; this is a meaningful operational improvement |
| Governance Preservation | 3/10 | Token holders lose direct control over parameter changes; the governance process that was supposed to decentralize decision-making becomes a rubber stamp for steward recommendations; the community that was supposed to govern the protocol governs less and less |
| Conflict Mitigation | 4/10 | Risk Stewards are compensated by Aave; their recommendations may favor protocol revenue over depositor protection; the firm that manages risk also benefits from higher interest rates; the conflict of interest is structural, not incidental |
| Transparency | 6/10 | Stewards must report all changes; the rationale is documented; but the speed of changes means community review happens after execution, not before; the transparency that exists is retrospective, not preventive |
| Decentralization Impact | 3/10 | Three external firms gain significant control over protocol economics; the decentralized governance model becomes a delegated authoritarian model; the token holders who were supposed to be sovereign become advisory |
| Total RDAS | 4.8/10 | The proposal improves operational speed at significant cost to governance decentralization and accountability |
A score of 4.8 indicates that delegated risk management is a high-risk optimization: genuine speed benefits but serious governance erosion.

The Three Risk Steward Traps
Trap 1: The Revenue-Protection Conflict
The fundamental problem with Risk Stewards is that their compensation is linked to protocol performance. Gauntlet, Chaos Labs, and LlamaRisk are not neutral arbiters—they are service providers with contracts and revenue targets. When a market is stressed, the steward must choose between protecting depositors (lowering rates, reducing caps) and protecting protocol revenue (raising rates, increasing caps). The proposal that was supposed to improve risk management becomes a mechanism for optimizing revenue under the guise of risk mitigation. The depositor who thought the steward was watching out for them finds the steward watching out for the quarterly report.
Trap 2: The Governance Atrophy
When Risk Stewards can adjust parameters without governance votes, token holders stop paying attention. The proposal that was supposed to speed up necessary changes becomes a proposal that eliminates the need for community engagement. The voter who used to analyze every parameter change now assumes the stewards have it handled. The governance forum that used to debate every supply cap now discusses only the exceptions. The decentralized autonomous organization becomes an organization where autonomy is delegated to three external firms.
Trap 3: The Expertise Lock-In
Risk management is complex. The firms that currently serve as Risk Stewards have built proprietary models and relationships. Replacing them would require finding firms with equivalent expertise and integrating them into the protocol. The proposal that was supposed to be a temporary delegation becomes a permanent dependency. The protocol that was supposed to be self-governing becomes a protocol that cannot function without its stewards. The expertise that was supposed to be a service becomes a structural requirement.
Competitive Landscape: Risk Management Models
| Platform/Model | Risk Decision Maker | Response Speed | Governance Participation | Conflict Level | RDAS |
|---|---|---|---|---|---|
| Aave V3 (current) | Token holders | Slow (10-14 days) | High | Low | 6.5/10 |
| Aave V3 (Risk Stewards) | External firms | Fast (2-48 hours) | Low | Medium-High | 4.8/10 |
| Compound | Token holders | Slow (7-14 days) | High | Low | 6.0/10 |
| MakerDAO (current) | Delegates + token holders | Medium (3-7 days) | Medium | Medium | 5.5/10 |
| Morpho | Permissionless markets | Instant | N/A | N/A | N/A |
| Euler | Governance + guardians | Medium (3-5 days) | Medium | Medium | 5.5/10 |
The landscape shows that speed and decentralization are in tension. Morpho avoids the trade-off by making markets permissionless, while Aave's Risk Stewards sacrifice decentralization for speed.

Scenario Analysis: Three Futures for Aave Risk Management
Scenario A: Steward Capture (45% probability)
- Risk Stewards expand their authority beyond predefined bounds
- Token holder participation declines as governance becomes ceremonial
- Protocol revenue optimization takes precedence over depositor protection
- RDAS degrades to 2.5/10
Scenario B: Constrained Delegation (35% probability)
- Risk Stewards operate within strict limits
- Major changes still require governance votes
- The community maintains oversight while benefiting from speed
- RDAS improves to 6.0/10
Scenario C: Steward Rotation (20% probability)
- The community implements competitive bidding for steward roles
- Multiple firms rotate to prevent capture and conflicts
- Transparency requirements increase with delegation
- RDAS improves to 6.5/10
The Bottom Line
The Risk Stewards proposal is pragmatic engineering from firms that understand DeFi market dynamics. The Risk Delegation Accountability Score is 4.8/10. Speed benefit is strong. Governance preservation is poor. Conflict mitigation is weak. Transparency is moderate. Decentralization impact is poor.
The three traps—revenue-protection conflict, governance atrophy, and expertise lock-in—are structural risks that accompany every attempt to delegate protocol governance. They reflect the fundamental tension between speed and accountability in decentralized finance. The community that wants faster risk responses must also accept that faster decisions made by fewer people concentrate power.
The deeper question is whether Aave can afford to outsource its risk management. The entire value proposition of DeFi is that code and governance replace trusted intermediaries. The proposal that replaces token holder governance with external firm discretion has achieved the opposite of decentralization—it has re-centralized risk management under a different label. The depositor who chose DeFi because they did not trust banks now must trust Gauntlet's model and Chaos Labs' judgment.
The proposal deserves recognition for operational realism. The risk stewards who drafted it have seen liquidation cascades and understand the cost of delay. But operational realism is not the same as governance wisdom. The protocol that moves fast but loses its community is a protocol that has sacrificed its reason for existing.
TL;DR
- What: Aave V3 Risk Stewards (Gauntlet, Chaos Labs, LlamaRisk) propose delegated authority to adjust supply caps and interest rate models without full governance votes, reducing response time from weeks to hours
- The Score: Risk Delegation Accountability Score of 4.8/10—speed benefit (8/10) genuinely reduces liquidation risk; governance preservation (3/10) transfers power from token holders to external firms; conflict mitigation (4/10) fails to address revenue-optimization incentives; transparency (6/10) is retrospective rather than preventive; decentralization impact (3/10) re-centralizes protocol economics
- The Reality: Three external firms gain control over parameters affecting billions in deposits; their compensation is linked to protocol performance
- Three Traps: Revenue-protection conflict (stewards optimize revenue while claiming to protect depositors); governance atrophy (token holders disengage as decisions move outside governance); expertise lock-in (replacing stewards becomes impractical, creating permanent dependency)
- Outlook: Steward capture (45%) where authority expands and depositor protection declines; constrained delegation (35%) where strict limits preserve community oversight; steward rotation (20%) where competitive bidding prevents capture
Sources
- Aave Governance Forum - Risk Stewards Proposal - August 2026 proposal for delegated cap and IRM authority
- Gauntlet Risk Management Documentation - Risk Steward firm methodology and compensation
- Chaos Labs Analytics - Risk modeling and parameter recommendations
- LlamaRisk Assessment Reports - Supply cap and liquidation risk analysis
- Aave V3 Technical Documentation - Current governance process and parameter mechanics
- Compound Governance Comparison - Alternative full-governance risk model
- MakerDAO Delegate Structure - Delegated governance with token holder oversight
- The Block - DeFi Risk Management - Analysis of protocol risk management centralization
Zain Tran is TotesTek's Ethereum Ecosystem Columnist & Accountability Reporter. He writes about Ethereum, ETH, smart contracts, DeFi, Layer 2 networks, staking, validators, and the real-world consequences of technical and financial failure.



