Underwriting in On-chain RWA Protocols
Intro

Underwriting in On-chain RWA Protocols
Intro
Real-world asset (RWA) protocols have become one of the most important bridges between traditional finance and decentralized finance, enabling assets such as private credit, mortgages, treasury bills, and structured funds to be represented and traded on-chain. Yet despite rapid growth in tokenized finance, underwriting is still one of the least understood subjects in the ecosystem. Unlike traditional banks or credit funds, on-chain RWA platforms rarely publish a single standardized underwriting manual or fully transparent credit process. Instead, most protocols reveal only the outer structure of their onboarding and due diligence procedures, while much of the detailed analysis, legal negotiation, and financial modelling remains private or protected through NDA-gated processes.
This creates an important question for researchers and investors: who actually performs underwriting in on-chain finance, and how is risk evaluated before assets are tokenized? The answer differs significantly across protocols. Some systems rely on DAO-governed onboarding and community risk review, others delegate underwriting to specialized asset managers or junior-capital providers, while treasury-focused products emphasize legal wrappers, custody, and counterparty selection rather than borrower credit analysis.
What protocols tend to publish is the shell of the process: eligibility gates, information requests, governance stages, legal structure, investor gating, and the risk dimensions reviewers look at. What they usually do not publish in full are the complete data rooms, detailed loan tapes, negotiated covenants, private models, and parts of the diligence process that sit behind NDAs or bilateral legal documents. You can see that pattern clearly in Centrifuge’s older POP process, which explicitly contemplated an NDA-protected assessment stage; in Goldfinch’s borrower pools, where deeper diligence is commonly accessed through NDA-gated data rooms; and in Credix, where underwriters may receive direct deal documentation such as promissory notes and security agreements.
Across the ecosystem, the public material points to three broad underwriting models. First, there is community-governed pool onboarding, where the protocol or DAO screens the issuer, asset class, legal structure, capital stack, and reporting framework before a pool can go live; Centrifuge is the clearest example. Second, there is delegated or investor-led underwriting, where the protocol supplies rails and structuring, but the real credit judgement is made by specialists, junior-tranche providers, delegates, or portfolio managers on a deal-by-deal basis; Goldfinch’s legacy borrower pools and Credix fit this model. Third, there is the treasury/fund-wrapper model, where the “underwriting” is less about borrower credit and more about selecting high-quality underlying instruments, service providers, custody arrangements, legal wrappers, and redemption mechanics; Ondo’s OUSG is the clearest example.
The shared pattern the ecosystem actually follows
When you strip away branding differences, most published RWA onboarding processes follow a similar sequence. They begin with a fit and eligibility screen: does the issuer have enough operating history, relevant expertise, and a credible strategy; is the asset class appropriate for the protocol; and can the applicant support the proposed structure with first-loss capital, legal documentation, and servicing capacity? Centrifuge’s current POP guidance is unusually explicit here: it asks applicants to explain team expertise, the asset class, the process to onboard and manage assets, the process to onboard and manage borrowers, fund-management operations, legal framework, junior and senior capital sources, and target pool scale. Earlier Centrifuge criteria also set more numerical expectations around time in operation, loan tape, origination volume, junior capital, and asset maturity.
The next layer is originator and asset due diligence. In Centrifuge’s own description of how the Credit Group works, the group first gathers additional information not already covered in the issuer’s materials, then identifies asset- and industry-specific risk factors, and then analyses the opportunity through a generic credit framework: structural integrity, collateral quality, cash-flow analysis, stress testing, and the tranche waterfall. Credix describes a very similar flow in more compact terms, saying its underwriting process has three phases: screening, due diligence, and structuring. Maple’s published institutional underwriting materials, while aimed mainly at secured lending rather than classic offchain private credit, show the same shape: KYC/AML, financial review, management interviews, operational assessment, collateral analysis, internal approval, term setting, and then ongoing monitoring.
Then comes legal and structural underwriting, which is often just as important as the credit analysis itself. Protocols repeatedly stress SPVs, fund structures, investor rights, recourse, custody, security interests, counterparty quality, and documentation. Centrifuge’s risk framework explicitly starts with “structural integrity”. Ondo’s trust and compliance material focuses heavily on fund structure, regulatory exemptions, institutional partners, custody and exchange rails, and customer due diligence. Credix describes off-balance-sheet securitisation structures, Delaware series LLCs and deal SPVs, offchain collateral and default procedures, and direct documentation for underwriters in single-borrower deals.
Finally, these protocols all require some form of post-launch monitoring and investor gating. Centrifuge proposes ongoing public information for open pools and differentiates them from closed or portfolio pools. Ondo updates OUSG’s NAV daily and restricts access through accredited-investor, qualified-purchaser, AML and sanctions checks. Goldfinch’s borrower-pool model relies on continuing borrower communications and reporting channels after investment. Credix and Maple both describe ongoing collateral and/or facility monitoring after origination. So the usual ecosystem procedure is not “underwrite once, tokenise forever”; it is screen, structure, gate, monitor, and only then scale.
Centrifuge is the clearest published pool-onboarding workflow
Centrifuge is the closest thing in the current ecosystem to a documented, protocol-level pool underwriting framework. For open pools, the official POP process is community-owned and CFG-governed. In the current process, the issuer submits a POP as an RFC, there is at least a week of public discussion, the Credit Group may publish an assessment at its discretion, and the pool then proceeds to an onchain vote if the issuer wants to launch. The POP exists specifically to curate asset quality and give CFG holders enough information to vote. CP5 also makes clear that the newer process was designed to be “more subjective” and descriptive rather than a rigid scoring exercise, which is one reason you do not see a neat public scorecard that mechanically determines “pass/fail” on every asset.
What is especially useful in Centrifuge is that the protocol publishes both the information the issuer must provide and the framework the Credit Group uses to think about it. The proposal guidance asks the applicant to explain, among other things, the exact process to onboard an asset and manage its lifecycle, including defaults and liquidations; the exact process to onboard borrowers and manage their lifecycle; the legal framework and liabilities; and the junior and senior capital sources expected to support the pool. Separately, the Credit Group’s own blog explains that its analysis usually proceeds by requesting more information, identifying industry-specific risk factors, and testing the transaction through a framework centred on structural integrity, collateral quality, cash-flow analysis, stress testing, and tranche waterfall design. In other words, the public procedure is not just “submit a forum post”; it is a mixture of issuer disclosure, credit-group risk review, and governance approval.
Centrifuge’s public examples also show how the framework changes by asset class. In the Anemoy Liquid Treasury Fund credit report, the analysis focuses on the investment mandate, the fact that assets are cash and U.S. Treasury bills, the BVI fund wrapper, fees, redemption period, investor eligibility, and key counterparties such as the custodian and exchange agent. There is no classic borrower-level underwriting because the underlying assets are sovereign bills; the real diligence sits in the fund structure and counterparties. In the **New Silver NS3** mortgage-oriented case, the review instead highlights New Silver’s risk-management practices, the 20% junior tranche funded by the issuer, the issuer’s willingness to support pool performance, and the historical performance and track record of the originator. That is much closer to conventional private-credit underwriting.
An important nuance is that Centrifuge does not apply the same underwriting path to every kind of pool. The governance discussion that introduced pool types says open pools require the full POP, but closed pools can be launched with the relevant fee/deposit, and portfolio pools for single owners such as DAOs using Centrifuge Prime do not fit a one-size-fits-all onboarding process. The rationale is explicit: it does not make sense to force pools that are not offered to other Centrifuge users through the same public governance and credit-assessment process. That means that, even inside Centrifuge, the “exact underwriting procedure” depends on whether you are launching a public/open pool or a dedicated/private portfolio structure.
Ondo shows how treasury wrappers are underwritten very differently
Ondo’s public material is useful precisely because it shows that tokenised treasuries are not underwritten like mortgage pools or private-credit facilities. OUSG is structured as a traditional GP/LP private fund. The public documentation says the investment manager uses OUSG proceeds to invest in U.S. Treasury products; the portfolio is currently invested in funds from large asset managers such as BlackRock, Franklin Templeton, WisdomTree and Fidelity, together with bank deposits and USDC for liquidity management. Ondo also emphasises that its risk management is “compliance-oriented”, rooted in legal, tax and regulatory advice, and supported by established institutional partners across exchange, custody, asset management and administration.
That means Ondo’s public “underwriting procedure” is really a wrapper-selection and counterparty-selection process, not a loan-by-loan credit memo. The published ingredients are investor eligibility rules, legal exemptions, AML/sanctions checks, partner quality, transparency, audits, and NAV mechanics. The docs say OUSG is only available to verified accredited investors who are also qualified purchasers, and investors must pass customer due diligence for AML, CTF and sanctions compliance. The overview then explains how stable coins are routed to a Coinbase account, used to purchase underlying holdings, and repriced through a daily NAV update. Publicly, that is the procedure you can see: not a line-by-line sovereign credit model, but a product design built around regulated access, reputable underlying funds, strong service providers, and operational transparency.
This is why, for treasury products, the right question is usually not “how did the protocol underwrite each bond?” U.S. Treasury bills are already standardised, short-duration sovereign instruments. The more important questions are: what exactly owns them, who manages them, who custodies them, how are subscriptions and redemptions processed, what legal rights do token holders have, and how is pricing updated on-chain? Ondo’s public materials answer those questions much more directly than they answer a classical credit-underwriting question, because that is where the real residual risk sits in a treasury wrapper.
Goldfinch Prime, though it is a private-credit product rather than a treasury product, now publishes a similarly curated-manager approach. Its current public materials say Prime invests through a single on-chain pool into selected institutional private-credit funds and discloses the high-level manager-selection criteria: multi-billion-dollar institutional funds, more than 10 years of private-credit track record, portfolios with more than 90% senior secured loans, less than 5% PIK income, and target non-accrual rates below 0.75%. Goldfinch’s current docs also say the product has already “vetted managers”. So here again, the public underwriting is manager and fund selection rather than a public release of every underlying loan-level memo.
Delegated-underwriter models make the p2p case much clearer
When it comes to the p2p or deal-specific case, Credix is one of the best documented examples. The protocol says its underwriting process has three phases: screening, due diligence, and structuring. During screening, Credix and/or an asset manager checks eligibility criteria and financial metrics. During due diligence, underwriters and asset managers review the borrower’s financials and historical performance in detail. During structuring, the facility is set up with regulatory compliance, FX hedging where relevant, collateral management, and reporting standards. Credix’s FAQ then makes the division of labour even clearer: Credix performs the initial due diligence to get borrowers onto the platform, but the underwriting itself is done by underwriters such as hedge funds and credit funds, while Credix supplies the due-diligence information.
The capital structure in Credix is designed to make that underwriting economically meaningful. Its docs say the junior tranches are supplied by institutional underwriters such as asset managers, credit funds and hedge funds, while liquidity providers fund the senior tranche through the pool. The protocol’s terms explain why: the underwriter is first-loss capital, so it is incentivised to perform strong diligence before approving a deal. Once the underwriter diligences and approves a deal and the junior tranche is filled, the senior pool fills the rest. For direct, single-borrower deals, the terms go further and say the underwriter may sign additional documents such as a promissory note and security agreement and may not benefit from diversification, because it is participating directly in that specific borrower facility through a deal SPV. That is about as close as you get, publicly, to a true on-chain p2p underwriting workflow.
Goldfinch’s legacy borrower-pool architecture shows a similar logic from a different angle. Public docs describe Borrower Pools as term sheets that borrowers propose to the network. The borrower sets terms such as rate, limit, payment frequency, term and late fee, but the terms are not automatically accepted. Instead, backers supply the junior tranche after doing their own diligence, and the Senior Pool then allocates senior capital according to the leverage model. Goldfinch’s diligence resources make that explicit: backers are told to review the NDA-gated data room, join private discussion channels with the borrower, and decide for themselves whether the opportunity is attractive. The borrower’s historical case study for Almavest describes a week-long due-diligence period, a dataroom, and live Q&A before the pool opened for funding.
So the common p2p pattern is this: the protocol is not the sole underwriter. Instead, the protocol creates the legal and technical envelope; a delegate, junior-tranche investor, backer, or manager performs the actual deal-level underwriting; and the senior capital often follows that first-loss signal. That is why these ecosystems frequently talk about underwriters, backers, asset managers, or portfolio managers rather than presenting themselves as if the smart contract alone “underwrites” an RWA.
What this means for pool cases and p2p cases
If you are trying to map the actual market convention, the most accurate summary is this. In a public pool case, the protocol usually underwrites the issuer/manager and the structure first, not every individual future asset in perfect public detail. The onboarding questions are: who is the originator, what is their track record, what do historical tapes show, how are assets onboarded and serviced, who holds first-loss capital, what are the default and liquidation procedures, how is the SPV or fund documented, who are the key counterparties, and what ongoing reporting will investors receive? Centrifuge’s POP is the clearest version of that model.
In a direct or p2p case, underwriting tends to move closer to the edge of the network. The protocol provides the facility format, SPVs, whitelisting, waterfall logic and distribution rails, but a designated underwriter, junior-tranche buyer, backer or PM does the decisive credit work. Credix is explicit that the underwriter does the underwriting and takes first-loss; Goldfinch is explicit that each backer should do their own due diligence with the borrower’s data room; TrueFi’s manager-onboarding docs show a related idea at the portfolio-manager level, where governance approves the manager and the manager then launches and runs the vault.
The biggest practical takeaway is that “tokenisation platform” does not tell you who is underwriting. Sometimes it is the protocol community and a credit group; sometimes it is a regulated fund issuer selecting underlying instruments and counterparties; sometimes it is a specialist underwriter or junior-capital provider; and sometimes, for closed or portfolio pools, there may be no broad public underwriting layer at all beyond governance approval and structural controls. In other words, when you evaluate an RWA product, you should ask two separate questions: who underwrites the assets, and who underwrites the wrapper? The answer is often different for each.
Open questions and limitations
The biggest limitation is visibility. Several protocols deliberately keep parts of the process private. Centrifuge’s older POP process expressly noted an NDA-protected assessment stage, Goldfinch commonly gates the fuller borrower materials behind NDAs, and Credix indicates that direct underwriters may receive additional transaction documents not visible to the public. That means the public record is strong on workflow, scope, and risk categories, but weaker on the complete internal checklists, modelling assumptions, and negotiated legal covenants actually used in live deals.
A second limitation is that public documentation is unevenly current across protocols. Centrifuge’s POP and Ondo’s OUSG materials are current enough to describe present operating logic. Goldfinch’s clearest borrower-pool underwriting materials live in its legacy V1 docs, while Goldfinch Prime’s current public materials focus on manager-selection criteria rather than loan-level underwriting. Credix’s underwriting docs are concise and useful, but the most explicit process descriptions in its public docs date from earlier versions of the product. So the report above is best read as a high-confidence map of published practice, not a claim that every live internal underwriting committee at every protocol still uses exactly the same template today.
메타데이터
- post_id
- 83ff91f6b2ce
- slug
- underwriting-in-on-chain-rwa-protocols-83ff91f6b2ce
- url
- https://medium.com/@amin.mohazab/underwriting-in-on-chain-rwa-protocols-83ff91f6b2ce
- canonical_url
- https://medium.com/@amin.mohazab/underwriting-in-on-chain-rwa-protocols-83ff91f6b2ce
- author_url
- https://medium.com/@amin.mohazab
- status
- ok
- fetched_at
- 2026-08-10 08:07:49