Policy & Regulation

Understanding the FATF’s DeFi Report: A Functional Approach to Decentralized Finance Regulation

Summary

  • The FATF just released its first DeFi-specific report: Acknowledging DeFi’s operational benefits, the global AML/CFT standard-setter explains how jurisdictions, supervisors, VASPs, and financial institutions can engage with DeFi responsibly, applying existing AML/CFT standards proportionately.
  • Putting the framework into practice: The report provides detailed guidance on how jurisdictions should evaluate each DeFi arrangement based on concrete indicators to determine whether existing AML/CFT obligations apply. Put simply: calling oneself “decentralized” is not enough to avoid oversight.
  • Blockchain intelligence is a key to the puzzle: On-chain tracing tools provide the insights for builders and regulators to effectively apply the FATF’s recommendations.

 

The FATF Weighs in on DeFi

Decentralized finance (DeFi) has long posed a regulatory challenge. DeFi arrangements, also known as protocols, can offer significant operational benefits: automated settlement, programmable financial services, and round-the-clock availability. But their varied governance structures make it difficult to determine when and how existing anti-money laundering and counter-terrorist financing (AML/CFT) obligations should apply. The central question: who, if anyone, exercises enough control over an arrangement to be held responsible for compliance?

DeFi’s “regulatory challenges” are the focus of a new 49-page report by the Financial Action Task Force (FATF), the global standard-setter for Anti-Money Laundering/ Combating the Financing of Terrorism AML/CFT. The FATF acknowledges in its report that institutions are eager to utilize DeFi’s benefits, and that jurisdictions should enable these interactions. But the same properties that make DeFi attractive to legitimate users also appeal to illicit actors. Our 2026 Crypto Crime Report found that illicit flows into DeFi protocols rose 343% year-on-year, making effective risk mitigation — not restriction — essential to ensuring DeFi can continue to grow safely.

One big question at the center of the report is coverage. How can a jurisdiction know if a DeFi protocol should be regulated under the same rules the FATF sets for Virtual Asset Service Providers (VASPs) such as crypto exchanges and stablecoin issuers? The FATF’s answer is the “control or sufficient influence” (COSI) test. It determines whether a protocol should be within regulators’ scope.

While the FATF offers a framework through which jurisdictions can consider COSI, it does not lay out a single playbook for doing so. But it does point to one essential capability: blockchain analytics. Blockchain analytics provides the on-chain intelligence that makes this framework operational — helping supervisors apply the COSI test, enabling regulated entities to engage with DeFi safely, and giving DeFi protocols the tools to embed compliance without sacrificing efficiency and innovation.

Testing for control and influence

The FATF’s framework recognises that DeFi exists on a spectrum. Rather than treating all protocols the same, it distinguishes three categories based on who, if anyone, exercises control or sufficient influence:

  1. Centralized: where persons or entities exercise clear control or sufficient influence. These fall within scope of the FATF Standards and should be treated as VASPs.
  2. Centralized, but with unidentified controllers: A protocol subject to the control or sufficient influence of persons as-yet-unknown. These also fall within scope of the FATF Standards. The FATF recommends that supervisors work with domestic authorities, foreign counterparts, and blockchain analytics providers to identify who is behind them.
  3. Truly decentralized: a protocol that is not controlled or sufficiently influenced by anyone. These fall outside the scope of the FATF Standards, but still present risks that require alternative, risk-based mitigation measures.

To measure “control or sufficient influence,” and therefore establish which group a protocol falls into, the FATF points to a series of indicators:

On-chain indicators:

  • Governance concentration: A handful of individuals or entities hold enough governance tokens to meaningfully direct the protocol’s financial operations. A few wallets (or multiple seemingly unrelated wallets) may wield significant control over financial operations. The FATF calls on supervisors to consider “potential wallet clustering” and on-chain voting behavior to identify hidden patterns of control. Importantly, concentration is not in and of itself evidence of centralization.
  • Administrative privileges: Possession of private keys allowing smart contract upgrades, parameter changes, protocol pauses, or access controls
  • Fee and treasury flows: Receiving protocol fees, controlling treasury funds, or directing economic value

Chainalysis can help supervisors make the FATF’s framework operational. With Reactor, investigators can cluster related wallets, trace fee and treasury flows through DeFi protocols, bridges, and DEXs, and connect on-chain activity to real-world counterparties across 27+ blockchains and 40 million+ assets. That gives supervisors an evidence-based way to assess who actually exercises control or sufficient influence over a protocol, rather than relying on labels or public claims alone.

The FATF also identifies off-chain indicators — including control over front-end interfaces, development repositories, and public communications about the ability to modify the protocol — as relevant factors in the COSI assessment.

The COSI test aims to assess who has overall control over a protocol, not whether a protocol has chosen to adopt responsible security and compliance practices. Notably, the FATF actively encourages security features like kill switches and pause mechanisms, and AML risk mitigation controls such as front-end screening and sanctions checks, across all categories of DeFi. This distinction matters: protocols should feel encouraged to implement robust safeguards, knowing that the regulatory framework is designed to assess control or sufficient influence over financial services provided, not to penalise good practice.

What this means for jurisdictions and supervisors

Jurisdictions have so far been slow to address the challenges of DeFi, which has created a gap in the efficacy of their enforcement frameworks. According to the FATF’s 7th Targeted Update published the same week as the DeFi report, 93% of jurisdictions have not identified qualifying DeFi protocols in their territory. Only four have imposed licensing requirements, and just one has taken enforcement action. This underscores the importance of the framework the report establishes.

The FATF sets out clear priorities for jurisdictions to speed up their efforts:

  • Conduct DeFi-specific risk assessments: considering the complex governance structures, cross-border nature, and concentration of activity.
  • Deploy blockchain analytics for ongoing DeFi supervision: the report recommends “conducting continuous blockchain analytics, including transaction tracing, wallet clustering, and network analysis” to identify controllers and monitor high-risk protocols.
  • Utilize with blockchain analytics tools: supervisors are told to work with “blockchain analytics companies, who may have additional identifiers” when trying to identify controllers of centralized DeFi protocols where controllers cannot be readily identified.
  • Enhance oversight of front-end providers and oracle operators: requiring automated screening, risk-scoring, and geo-blocking.
  • Encourage smart-contract audits alongside embedded controls and ongoing monitoring: the report recommends that jurisdictions consider all three as complementary measures for effective DeFi oversight.

The DeFi report calls on jurisdictions to collaborate with DeFi protocols, VASPs, and blockchain analytics firms in order to better combat emerging risks — a public-private partnership model emphasized in the 7th Targeted Update. Chainalysis has supported these partnerships through initiatives like Operation Spincaster, in which public investigators and private sector partners collaborated to disrupt crypto scams. We welcome the extension of this model to the DeFi ecosystem.

What this means for financial institutions

The report expects financial institutions to take a risk-based approach to DeFi. All financial institutions, be they in traditional finance or in crypto, should evaluate their DeFi counterparties based on their governance structures, their effective implementation of AML/CFT controls, and their ability to mitigate risks — including hacks. These steps complement the measures such financial institutions already follow to mitigate on-chain risk, like transaction-monitoring and wallet screening tools.

Where higher risks are identified — for example, exposure to bridges, mixers, or cross-chain tools, or interaction with protocols that have limited compliance controls — regulated entities are expected to apply enhanced due diligence, such as deeper analysis of fund flows, tracing exposure to high-risk services, or setting lower thresholds for flagging suspicious activity.

Stablecoin issuers carry a distinct responsibility within the DeFi ecosystem. The attributes that make stablecoins the primary form of collateral in DeFi — 24/7 value transfer globally and instantly — also attract illicit actors who seek to exploit them. As documented in our 2026 Crypto Crime Report, stablecoins now account for 84% of all illicit transaction volume. With the growth of stablecoins in DeFi in particular, issuers have a unique opportunity to make a material difference in preventing and fighting financial crime. The FATF expects freeze and burn capabilities as a baseline — and as the 7th Targeted Update flagged, criminal networks are now designing stablecoins specifically to resist freezing.

What this means for DeFi protocols

Where a DeFi protocol lands on the COSI test determines how the FATF’s recommendations apply to it.

Centralized DeFi

If a protocol has identifiable controllers —or has controllers that simply haven’t been identified yet — it is subject to the same AML/CFT obligations as any other VASP: licensing, customer due diligence, transaction monitoring, sanctions compliance, and Travel Rule compliance where applicable. The FATF also recommends embedding controls directly into protocol infrastructure: automated freezing, on-chain risk-scoring, and transaction blocking. Smart-contract audits are necessary, ongoing monitoring should be standard practice.

The message is clear: if you have control, you also have obligations.

Truly Decentralized DeFi

Protocols where no person or entity exercises control or sufficient influence fall outside the FATF’s regime. But being out of scope does not mean being risk-free. The FATF encourages supervisors to monitor these protocols using blockchain analytics, expects regulated entities at the touchpoints to apply appropriate due diligence, and relies on stablecoin issuer controls as an indirect safeguard.

The practical implication: even truly decentralized protocols benefit from adopting compliance controls voluntarily at the design and pre-deployment phase. Early signs suggest institutional capital is already flowing preferentially to protocols with screening, monitoring, and governance controls in place — compliance is becoming a market differentiator, not just a regulatory obligation.

The challenge of implementation

The FATF’s DeFi report establishes a framework that is functional, tech-neutral, and proportionate. For an industry seeking regulatory clarity, this is a constructive outcome. But the framework is only as good as how it is applied. Several open questions will shape DeFi’s next phase.

  • From framework to practice: The COSI test provides multiple indicators, but applying them will raise practical questions. The most immediate risk is that jurisdictions unfamiliar with DeFi might assume that all DeFi is centralized once there is an element of centralized control or influence. The FATF’s three-category distinction exists precisely to prevent this. It will be important that jurisdictions implement it proportionately, recognising that concentrated governance over insignificant operational details, or retaining limited technical functions for security purposes, should not on its own lead to classification as a centralized protocol. The FATF’s indicators are non-exhaustive and indicative; jurisdictions will need to weigh them carefully rather than apply them mechanically. The central question should be whether the control or influence identified is material to the provision of a financial service, not simply whether a technical capability exists.
    Other questions remain: how to treat immutable protocols where controls can’t be retrofitted, how to assess governance concentration when on-chain voting doesn’t reflect real-world influence, and how to establish jurisdiction over protocols with no geographic anchor. These are implementation questions, not flaws in the framework, but they’ll need answers as jurisdictions begin applying the COSI test.
  • Progressive decentralization: Many protocols start centralized and progressively hand over control. At what point does a protocol move from in-scope to out-of-scope? While the report doesn’t address this transition, it does make clear that implementing robust risk mitigation, both AML/CFT controls and cybersecurity measures, is always sound practice.
  • Cross-border coordination: When a protocol’s smart contracts, frontend operator, governance token holders, and foundation are all in different jurisdictions, who regulates it? On-chain data doesn’t stop at borders but regulatory mandates do. International cooperation, combined with shared analytical infrastructure, will be essential.
  • Cybersecurity and AML/CFT convergence: Cybersecurity is not traditionally central to AML/CFT — but in DeFi, the two are inseparable. A smart-contract exploit generates illicit proceeds that must be laundered; for state actors like the DPRK, those proceeds fund weapons programs. The Venus Protocol case demonstrates this in practice: a security response (detecting an attack, pausing the protocol) was simultaneously an AML/CFT response (preventing the theft and enabling $13M in recovery before funds could be moved). As more traditional financial institutions engage with DeFi, treating cybersecurity as a first-class component of the supervisory framework will only become more important.

How Chainalysis can help

The FATF explicitly encourages both public and private sectors to strengthen their technical expertise in blockchain analytics tools to support DeFi-related investigations. Many of the implementation challenges outlined above are ones Chainalysis is uniquely positioned to address; Chainalysis accurately attributed 145 million smart contract transactions representing $15.8 trillion in value in 2026.

Applying the COSI test proportionately requires the ability to analyse governance token distribution, map wallet clusters, trace fee flows, and assess the real-world control picture behind a protocol — exactly what our clustering and attribution capabilities are built for. Cross-border coordination becomes practical when supervisors share a common analytical infrastructure that provides visibility across jurisdictions and chains. And as the Venus Protocol case above demonstrated, the cybersecurity-compliance convergence is already a reality in our product suite.

More broadly, we help regulated entities assess their DeFi exposure, enable DeFi protocols to embed the AML/CFT controls the FATF recommends, and work with supervisors in over 100 countries to make on-chain intelligence operational. With the vast majority of jurisdictions yet to identify qualifying DeFi protocols, the gap between framework and practice needs to close quickly. We’re ready to help bridge it.

To learn more about how Chainalysis supports DeFi compliance and supervision, get in touch with our team.

 

This website contains links to third-party sites that are not under the control of Chainalysis, Inc. or its affiliates (collectively “Chainalysis”). Access to such information does not imply association with, endorsement of, approval of, or recommendation by Chainalysis of the site or its operators, and Chainalysis is not responsible for the products, services, or other content hosted therein.

This material is for informational purposes only, and is not intended to provide legal, tax, financial, or investment advice. Recipients should consult their own advisors before making these types of decisions. Chainalysis has no responsibility or liability for any decision made or any other acts or omissions in connection with Recipient’s use of this material.

Chainalysis does not guarantee or warrant the accuracy, completeness, timeliness, suitability or validity of the information in this report and will not be responsible for any claim attributable to errors, omissions, or other inaccuracies of any part of such material.