The Financial Action Task Force has released its first report focused specifically on decentralized finance, setting out how existing anti-money laundering and counter-terrorist financing standards should be applied to DeFi arrangements. The 49-page document says the key question is not whether a project describes itself as decentralized, but whether any person or group exercises “control or sufficient influence” over the financial service.

The framework is aimed at jurisdictions, supervisors, virtual asset service providers and financial institutions. It outlines a functional test for deciding when a DeFi protocol falls within FATF standards, while also stressing that blockchain analytics and certain off-chain signals are central to making that assessment in practice.

A spectrum rather than a label

The FATF describes DeFi as existing on a spectrum rather than in a simple regulated-or-unregulated category. Under its approach, arrangements with identifiable controllers fall within scope as VASPs, while projects that appear centralized but have hidden or unclear controllers should still be treated as potentially covered, with supervisors encouraged to work to identify the parties behind them.

At the other end are arrangements the report characterizes as truly decentralized, where no one exercises control. Those may fall outside FATF scope, but the report says they would still warrant risk-based mitigation. The central test is whether there is meaningful control over the financial service itself, not whether the protocol uses decentralized branding or governance language.

How supervisors are expected to assess control

The report points to both on-chain and off-chain indicators. On-chain factors include governance concentration, such as whether a small set of wallets can shape protocol decisions, as well as administrative privileges that allow upgrades, parameter changes, pauses or access controls. It also highlights fee distribution and treasury management as evidence that may help show who benefits from and directs a protocol.

The FATF notes that no single indicator is decisive. Governance concentration alone does not automatically prove centralization, and the indicators are not presented as an exhaustive checklist. Off-chain evidence can also matter, including control of front-end interfaces, software repositories and public statements about who has the power to modify a protocol.

The report also makes clear that security mechanisms should not automatically count against a project. It says features such as kill switches, pause tools and other safeguards can be legitimate risk controls, and that the purpose of the test is to measure control over financial services rather than punish good security practice.

Expectations for regulators and institutions

For national authorities, the FATF says DeFi-specific risk assessments are needed, especially where governance is complex, activity is cross-border or power is concentrated. It calls for ongoing use of blockchain analytics, including transaction tracing, wallet clustering and network analysis, to identify controllers and monitor higher-risk protocols.

The report also urges cooperation with analytics providers when responsible parties are not readily identifiable, and points to stronger oversight of front-end providers and oracle operators. Smart-contract audits, embedded controls and continuous monitoring are presented as complementary parts of a broader supervisory approach.

Financial institutions, meanwhile, are told to apply a risk-based framework when dealing with DeFi exposure. That includes assessing governance structures, the existence of AML and CFT controls, and a protocol’s broader risk-mitigation capabilities. The report says enhanced due diligence is appropriate for higher-risk exposure such as bridges, mixers, cross-chain tools or protocols with limited compliance controls.

Stablecoins, implementation challenges and next steps

The FATF gives stablecoin issuers particular weight because stablecoins are widely used as collateral and for continuous global value transfer. According to the report, stablecoins now account for a large share of illicit volume, and issuers should have freeze and burn capabilities as a baseline, even as some criminals are trying to create stablecoins that resist freezing.

The document also leaves several implementation questions open. These include how to avoid mechanically classifying a protocol as centralized based on partial indicators, how to treat progressive decentralization over time, and how to coordinate across jurisdictions when different parts of a protocol are spread internationally. It also ties cybersecurity more closely to AML and CFT supervision, arguing that security incidents can generate illicit proceeds and should be treated as part of the compliance picture.

The immediate next step is likely to be jurisdiction-level interpretation and enforcement using the FATF’s functional framework. For now, the report’s clearest message is that DeFi arrangements will be judged by who can actually direct or influence them, with on-chain analysis and off-chain evidence used together to make that determination.

Source: www.chainalysis.com