How to regulate decentralized finance: FATF's position

How to regulate decentralized finance: FATF's position

FATF has, for the first time, released a standalone report on DeFi and proposed determining the degree of regulation not by a protocol's claims but by real control and influence.

Aug 12, 2026

What FATF thinks about the DeFi market

Decentralized finance (DeFi) has long posed problems for regulators. DeFi projects, also called protocols, can offer significant operational advantages: automatic settlement, programmable financial services and the ability to operate around the clock. However, the diversity of governance models for such projects makes it difficult to determine when and how existing anti-money laundering and counter-terrorist financing (AML/CFT) requirements should apply to them.

These DeFi «regulatory challenges» are the subject of a new 49-page report by the Financial Action Task Force (FATF), the international organization that sets global standards for anti-money laundering and counter-terrorist financing. FATF acknowledges that financial institutions are interested in tapping the benefits of DeFi and believes jurisdictions should create the conditions for such engagement. Yet the same properties that make DeFi attractive to legitimate users also attract criminals.

One of the central questions the report addresses concerns the scope of regulation. How is a jurisdiction to determine whether a DeFi protocol should be regulated under the same rules FATF sets for virtual asset service providers (VASPs), such as crypto exchanges and stablecoin issuers?

Although FATF proposes a framework jurisdictions can use to assess the presence of control or sufficient influence, it does not establish a single step-by-step algorithm for such an assessment. It does, however, point to one crucial capability: blockchain analytics. This provides data on what is happening directly on-chain, thanks to which the framework can work in practice: supervisors gain the ability to apply the COSI test, regulated entities can engage with DeFi more safely, and DeFi protocols themselves can implement controls without sacrificing efficiency and innovation.

The control or sufficient influence (COSI) test

FATF's proposed framework recognizes that DeFi exists in a wide range of forms. Rather than placing all protocols in a single category, it distinguishes three groups depending on whether anyone exercises control or holds sufficient influence:

  • Centralized: protocols in which individuals or organizations exercise obvious control or hold sufficient influence. They fall within the scope of FATF standards and should be treated as VASPs.
  • Centralized but with controlling parties not yet identified: protocols under the control or significant influence of persons whose identities have not yet been established. They also fall within the scope of FATF standards. FATF recommends that supervisors work with national government agencies, foreign counterparts and blockchain analytics providers to establish who is behind such protocols.
  • Truly decentralized: protocols that are not controlled by, or under the sufficient influence of, any specific person or organization. They fall outside FATF standards but still carry certain risks, which should be mitigated through other, risk-based measures.

To determine the presence of «control or sufficient influence» and, accordingly, which of the three groups a protocol belongs to, FATF suggests taking a number of indicators into account.

Indicators identified directly on-chain:

  • Governance concentration: a small number of individuals or organizations holds enough governance tokens to materially influence the protocol's financial activity. Several wallets — or several outwardly unrelated wallets — may hold significant control over financial operations. FATF urges supervisors to consider possible clustering of wallets and to analyze on-chain voting in order to detect hidden patterns of control. At the same time, a high concentration of tokens alone does not yet prove centralization.
  • Administrative privileges: certain individuals or organizations hold private keys that allow them to upgrade smart contracts, change their parameters, pause the protocol or manage access.
  • Fees and treasury funds: receiving protocol fees, controlling treasury funds or being able to direct economic value within the protocol.

Blockchain analytics can help supervisors apply FATF's proposed framework in practice. It can be used to cluster related wallets, trace the movement of fees and treasury funds across DeFi protocols, bridges and decentralized exchanges, and link on-chain activity to the real parties behind transactions across more than 27 blockchains and more than 40 million assets. This allows supervisors to assess, on the basis of factual data, who actually exercises control or holds sufficient influence over a protocol, instead of relying solely on its name, claims of decentralization or public statements.

FATF also identifies off-chain indicators, in particular control over the interfaces through which users interact with the protocol, source-code repositories and public statements about the ability to modify the protocol. These also matter when conducting a COSI assessment.

The purpose of the COSI test is to identify who exercises overall control over the protocol, not to establish whether the protocol has voluntarily chosen to implement responsible security and compliance measures. Notably, FATF actively encourages the use of security features such as circuit breakers and pause mechanisms, as well as AML risk-mitigation tools, for example user checks via the protocol interface and sanctions-list screening, across all categories of DeFi. This distinction matters: protocols should have an incentive to implement robust safeguards, because the regulatory framework is designed to assess control or sufficient influence over the financial services provided, not to penalize the use of effective protective measures.

What this means for jurisdictions and supervisors

So far, jurisdictions have been fairly slow to respond to the challenges posed by DeFi, which has created gaps in the effectiveness of existing controls and enforcement.

This underscores the importance of the framework proposed in the new report.

The DeFi report calls on jurisdictions to cooperate with DeFi protocols, virtual asset service providers and blockchain analytics firms in order to counter emerging risks more effectively. This public-private partnership model was also emphasized in FATF's seventh targeted update. A similar approach has already been used in joint operations between government investigators and the private sector to disrupt crypto fraud. Extending this model to the DeFi ecosystem could be the next step.

How the work of financial institutions will change

The report expects financial institutions to take a risk-based approach to DeFi. All financial institutions — both traditional and crypto-focused — must assess their DeFi counterparties in light of governance structure, the actual application of AML/CFT mechanisms and the ability to mitigate risks, including the risk of hacks. These measures complement the tools financial institutions already use to reduce risks associated with on-chain transactions, such as transaction-monitoring systems and crypto-wallet screening.

Where elevated risks are identified — for example, those linked to the use of bridges, mixers or cross-chain tools, or to interaction with protocols that have limited compliance mechanisms — regulated entities are expected to apply enhanced due diligence. This may include deeper analysis of the movement of funds, tracing contacts with high-risk services, or lowering the thresholds at which transactions are flagged as suspicious.

Stablecoin issuers bear special responsibility within the DeFi ecosystem. The very properties that have made stablecoins the primary form of collateral in DeFi — the ability to transfer value instantly and around the clock worldwide — also make them attractive to criminals seeking to exploit these capabilities.

As the direct use of stablecoins in DeFi grows, their issuers have a unique opportunity to significantly influence the prevention and disruption of financial crime.

How the new rules will affect DeFi protocols

Which COSI category a DeFi protocol falls into determines how FATF's recommendations apply to it.

Centralized DeFi

If a protocol has established controlling parties — or such parties simply have not yet been identified — it is subject to the same AML/CFT requirements as any other VASP: licensing, customer due diligence, transaction monitoring, sanctions compliance and compliance with the Travel Rule where it applies. FATF also recommends building controls directly into the protocol's infrastructure: automatic freezing of funds, on-chain risk assessment and transaction blocking. Smart-contract audits are essential, and continuous monitoring should become standard practice.

Truly decentralized DeFi

Protocols in which no person or organization exercises control or holds sufficient influence do not fall under the FATF regime. But the absence of regulation does not mean the absence of risk. FATF recommends that supervisors track such protocols using blockchain analytics, expects regulated entities at the points of interaction with them to carry out appropriate due diligence, and counts on controls by stablecoin issuers as an additional layer of protection.

The practical takeaway is that even truly decentralized protocols benefit from voluntarily building in compliance mechanisms at the design stage and before launch. Early signs show that institutional capital is already beginning to favor protocols that have checks, monitoring and governance mechanisms in place from the outset. Compliance is thus gradually becoming not only a regulatory obligation but also a competitive advantage in the market.

Challenges in applying the new rules in practice

FATF's DeFi report creates a functional, technology-neutral and proportionate regulatory framework. For an industry that has long sought greater certainty from regulators, this is a constructive outcome. However, the effectiveness of this framework will depend on exactly how it is applied in practice. Several unresolved questions will shape the further development of DeFi.

From framework to practice: the COSI test sets out many indicators, but their application in practice will inevitably raise questions. The most obvious risk is that jurisdictions insufficiently familiar with DeFi may start treating any protocol as centralized as soon as they detect some element of centralized control or influence in it. It is precisely to prevent this approach that FATF divided protocols into three categories.

It is important for jurisdictions to apply this classification proportionately to the risks, understanding that concentrated control over minor operational details, or the retention of limited technical functions for security purposes, should not in itself automatically lead to a protocol being deemed centralized.

FATF's list of indicators is not exhaustive and serves as a reference point; jurisdictions will have to assess them in the aggregate rather than apply them mechanically. The main question should be whether the identified control or influence is material to the provision of a financial service, not simply whether there is a technical ability to change something.

Other questions also remain: how to deal with immutable protocols into which the necessary controls cannot be built afterward; how to assess governance concentration when on-chain voting does not reflect real-world influence; and how to establish jurisdiction over protocols that have no geographic anchor. These are questions of practical application rather than flaws in the framework itself, but they will have to be answered as jurisdictions begin to use the COSI test.

Progressive decentralization: many protocols start out in a centralized form and then gradually hand control to other participants. At what point does such a protocol move from the category of those subject to regulation into the category of those outside it? Although the report does not answer this question directly, it makes clear that implementing robust risk-mitigation mechanisms — both AML/CFT controls and cybersecurity measures — always remains sound practice.

Cross-border coordination: when a protocol's smart contracts, interface operator, governance-token holders and foundation are located in different jurisdictions, who should regulate it? On-chain data does not stop at national borders, whereas regulators' powers are limited to national jurisdictions.

International cooperation, combined with shared analytical infrastructure, will be critically important.

The convergence of cybersecurity and AML/CFT: cybersecurity has traditionally not been a central element of the anti-money laundering and counter-terrorist financing framework. In DeFi, however, these two areas are inseparable. A smart-contract hack produces illicitly obtained funds that then need to be laundered; for state actors such as the DPRK, such funds can be used to finance military programs.

As traditional financial institutions engage with DeFi ever more actively, treating cybersecurity as a full-fledged element of the supervisory framework will become increasingly important.

#AML
DeFi regulation: FATF's new approach to controlling protocols