Regulation & Policy
Share
FATF has issued its first dedicated DeFi report, establishing a 'control or sufficient influence' test to determine when DeFi arrangements fall under existing AML/CFT standards, replacing reliance on a protocol's self-described decentralization label.
The global AML watchdog says regulators should look beyond DeFi’s labels and assess who can actually influence protocols, while truly decentralized arrangements remain outside its standards.
The Financial Action Task Force (FATF) has issued its first report dedicated to decentralized finance, giving regulators a framework to determine when DeFi arrangements should fall under existing anti-money laundering and counter-terrorist financing rules.
The 49-page report, published in July, does not create a separate AML regime for DeFi. Instead, it applies the FATF’s existing technology-neutral approach and puts a more specific question at the center of regulatory assessments: who exercises “control or sufficient influence” over a DeFi arrangement?
The distinction is important because the FATF does not treat the underlying smart contracts as regulated entities simply because they provide financial functionality. Rather, its standards can apply to identifiable people or entities that control or sufficiently influence an arrangement providing financial services.
That means a protocol’s claim to be decentralized will not, by itself, determine whether it falls within the regulatory perimeter.
The FATF's report distinguishes between the decentralized technology underpinning DeFi and the governance structures surrounding it.
Smart contracts can automate transactions without an intermediary, but the people or entities governing those contracts may retain significant powers over upgrades, treasury assets, fees, users or other critical functions.
The report therefore divides DeFi arrangements into three broad categories.
The first is centralized DeFi, where identifiable individuals or entities exercise control or sufficient influence. These arrangements fall within the FATF Standards when they provide activities covered by the framework.
The second is effectively centralized DeFi with unidentified controllers. In these cases, control exists but regulators cannot readily determine who is exercising it. The FATF says these arrangements also fall within scope and encourages authorities to use additional sources of information to identify the relevant actors.
The third is truly decentralized DeFi, where no person or entity exercises control or sufficient influence. These arrangements fall outside the FATF Standards, but the FATF says they can still present significant money-laundering, terrorist-financing and proliferation-financing risks that require alternative mitigation measures.
The approach gives regulators a way to distinguish genuine decentralization from arrangements in which decentralization exists mainly at the technical or marketing level.
Rather than establishing a rigid checklist, the FATF provides a non-exhaustive set of indicators that supervisors can use flexibly depending on a protocol's structure.
Among the on-chain indicators are:
Upgrade and administrative powers, including control of upgrade keys, proxy contracts and emergency functions.
Parameter-setting authority, such as the ability to change fees, risk limits, collateral factors or rewards.
Control over oracles or the ability to alter critical data feeds.
Control over critical smart-contract infrastructure.
Fee flows and economic benefits, including protocol fees, liquidation penalties, MEV-related payments and token emissions.
Permissioning and gatekeeping, including control over whitelists or access rights.
Governance concentration, where a small group can determine voting outcomes, upgrades or treasury decisions.
The FATF also looks beyond the blockchain.
Control over a protocol's front end, corporate entities, development roadmap, essential off-chain infrastructure, branding and communications can all provide evidence of influence.
Developers, governance-token holders, core maintainers, front-end operators, investors, oracle providers, foundations and corporate entities could therefore become relevant to a control assessment depending on what they actually do. The FATF stresses that the list is not exhaustive and that jurisdictions should take a functional approach.
Importantly, not every technical capability automatically establishes control.
The report notes, for example, that emergency functions retained for legitimate security purposes may not by themselves indicate control. Authorities are expected to consider the nature and materiality of the power rather than mechanically treating every administrative function as evidence of centralization.
The need for the framework is underscored by how little progress jurisdictions have made in applying existing FATF standards to DeFi.
According to the FATF's 2026 survey, only 26 of 142 jurisdictions that responded have assessed DeFi-related risks. A further 132 jurisdictions have not identified any qualifying DeFi arrangements operating in their territory.
Only four jurisdictions have implemented licensing or registration requirements for qualifying DeFi arrangements, while just two have actually licensed or registered such arrangements in practice.
The FATF identifies several reasons for the gap, including DeFi's cross-border structure, unclear jurisdictional anchors, complex governance models and the difficulty of identifying the people behind ostensibly decentralized arrangements.
The report consequently calls on jurisdictions to conduct DeFi-specific risk assessments and devote supervisory resources according to the materiality of DeFi activity in their markets.
The FATF also notes that DeFi activity is highly concentrated. North America and Europe account for roughly 60% of global activity, while the Middle East and Africa together account for less than 10%. The report says the 12 largest protocols account for more than 60% of global total value locked.
One of the report's more practical implications is the role it gives blockchain analytics in identifying control and investigating illicit activity.
The FATF says authorities can combine publicly available blockchain data with governance proposals, voting records, protocol documentation and other sources. It also points to third-party blockchain analytics and forensic analysis, transaction-flow mapping, service-provider disclosures and information from financial intelligence units and law enforcement agencies.
That is particularly relevant where governance concentration or financial flows are difficult to understand from protocol documentation alone.
For example, a supervisor may need to determine whether several wallets are linked, whether a small group effectively controls voting power, who receives protocol-level fees, or who has authority over treasury and upgrade functions.
The FATF also recommends the use of real-time blockchain analytics as part of risk mitigation for financial institutions and VASPs interacting with DeFi. In investigations, it calls for public-private cooperation to integrate blockchain analytics and tracing tools into enforcement operations, particularly where funds move across chains or through complex transaction paths.
This does not mean blockchain analytics becomes a substitute for traditional evidence. Rather, the report treats on-chain intelligence as one component of a broader assessment that can include corporate records, communications, governance data and law-enforcement intelligence.
The FATF is also addressing the other side of the DeFi relationship: regulated institutions that interact with protocols.
Financial institutions and VASPs remain responsible for ensuring that their DeFi interactions comply with applicable AML/CFT requirements.
The report recommends that they assess a DeFi arrangement's governance structure, AML/CFT controls and risk profile before engaging with it. Higher-risk exposure may require additional measures, including enhanced due diligence and real-time blockchain monitoring.
The FATF also recognizes that truly decentralized protocols can implement controls without necessarily becoming centralized.
It points to measures such as third-party or embedded KYC/CDD solutions, allowlists and blocklists at the smart-contract or front-end level. Where such controls effectively reduce residual risk, supervisors may consider a more tailored approach when regulated institutions interact with truly decentralized arrangements.
That creates an important distinction between control and compliance.
A protocol can adopt security or AML safeguards without those safeguards necessarily proving that someone controls the protocol. Conversely, a protocol can appear decentralized while retaining concentrated control over economically significant functions.
The FATF's report does not settle every question surrounding DeFi regulation. Instead, it gives jurisdictions a framework that they will now have to apply to increasingly complicated structures.
One unresolved issue is how regulators will assess protocols that are progressively decentralizing. A project may begin under the control of a company or development team before transferring governance to a DAO. The FATF's indicators suggest that regulators will need to examine whether that transfer represents a genuine shift in control or merely a change in formal governance.
Cross-border enforcement is another challenge. A protocol can have developers, governance participants, front-end operators, foundations and infrastructure providers spread across multiple jurisdictions, while users and transactions are global.
The FATF therefore emphasizes international cooperation and public-private information sharing, including collaboration among authorities, DeFi projects, VASPs, financial institutions and blockchain analytics firms.
The broader message is less about bringing all DeFi under regulation than about making “decentralized” an assessment rather than an assumption.
For protocols with identifiable control, the existing FATF framework can apply. For protocols where no one exercises sufficient influence, the standards may not apply directly, but financial-crime risks remain.
The dividing line, increasingly, is not whether a protocol runs on smart contracts or calls itself a DAO.
It is who can actually make the decisions, move the money, change the code or materially influence the financial service being provided.
Disclaimer of Warranty
The information provided in this article is for general informational purposes only. We make no warranties about the completeness, reliability, and accuracy of this information. Read full disclaimer
Editor's Picks

Exclusive: Flipster GM Benjamin Grolimund Discusses Full VARA License and UAE Growth
Anna K.
Aug 4, 2026
4 min

Digital Euro: Europe’s Sovereignty Project Has a Demand Problem
Walid Abou Zaki
Jul 10, 2026
9 min

In Digital Finance, the Product Is the Regulation
Walid Abou Zaki
Jul 9, 2026
7 min
Read More Articles
In the Same Space

Russia Introduces First Comprehensive Framework for Crypto Market Regulation
News Desk
Aug 5, 2026
3 min

Exclusive: Flipster GM Benjamin Grolimund Discusses Full VARA License and UAE Growth
Anna K.
Aug 4, 2026
4 min

Kalshi Faces New York Lawsuit Seeking Up to $36B in Damages
News Desk
Jul 31, 2026
5 min

Schumer Targets Trump’s $1.4B Crypto-Related Income With New Bill
News Desk
Jul 31, 2026
5 min


