FATF DeFi Report: When Control Brings a DeFi Arrangement Within the FATF Standards

On 21 July 2026 the Financial Action Task Force published its Targeted Report on Regulatory Challenges from Decentralised Finance, and the message for anti-money laundering teams is blunt: decentralised is a claim to be tested, not a label that lifts a service out of scope. Where an identifiable natural or legal person controls or sufficiently influences a DeFi arrangement, the FATF says the arrangement falls within the scope of the Standards. The person, rather than the software, is a VASP only where that person is not covered elsewhere under the Recommendations and, as a business, conducts a listed virtual-asset activity for or on behalf of another person.

The FATF DeFi report updates and complements the DeFi analysis contained in its 2021 Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers; it does not formally replace that guidance. Since 2021, the DeFi ecosystem has expanded and regulated entities have increased their interaction with DeFi arrangements, raising the relevance of associated money laundering, terrorist financing and proliferation financing risks. The report creates no new Recommendation and provides non-binding analysis and recommendations on applying the existing Standards.

The practical takeaway for a compliance function is that financial institutions and VASPs interacting with DeFi arrangements should risk-assess the products involved and take proportionate measures under Recommendation 15. Recommendation 10 applies when the DeFi arrangement is seeking to become, or is already, a client. Recommendation 13 applies when it is seeking to establish a correspondent banking relationship. The report does not impose a generic customer-due-diligence or transfer-information requirement merely because a firm swaps, custodies or bridges value involving DeFi.

Related reading: FATF on stablecoins and unhosted wallets: peer-to-peer transaction risk

Why the FATF returned to DeFi five years on

The 2021 guidance already said that a DeFi arrangement could fall within Recommendation 15 where a person controlled or sufficiently influenced it. The 2026 report responds to the sector’s expansion and increasing participation by institutional investors, VASPs and other regulated entities. That growth increases supervisory and financial-crime relevance, but it does not itself determine regulatory scope; scope depends on control, the relevant person and the activities performed.

The market it describes is concentrated. A small number of protocols account for the majority of activity, and usage clusters heavily in North America and Europe, with much thinner volumes across other regions. Concentration matters for supervision because the report says authorities should take market asymmetries into account and prioritise engagement with the largest and most systemically relevant DeFi protocols and associated stakeholders. The report also situates DeFi’s illicit finance exposure against a run of large protocol exploits and state linked thefts, where a handful of incidents can drive most of a year’s losses. The precise figures sit in the report itself, and a reporting officer building a risk assessment should read them from that source.

None of this rewrites the rulebook. The FATF Standards operate through national legislation and are tested through the mutual evaluation process; they reach firms only once a jurisdiction has transposed them into domestic law. The report therefore changes what supervisors will look for before it changes any statute on your desk, which is the reason to act on it now instead of filing it as a future consultation.

The control test: when a DeFi arrangement is a VASP

The FATF glossary defines a VASP by the activities of a natural or legal person, not by the legal form or marketing label of software. A VASP is a natural or legal person not covered elsewhere under the Recommendations that, as a business, conducts one or more of five activities for or on behalf of another person: exchanging virtual assets for fiat, exchanging one virtual asset for another, transferring virtual assets, safekeeping or administering virtual assets or instruments that enable control over them, and participating in and providing financial services related to an issuer’s offer and/or sale of a virtual asset. A smart contract may deliver the functionality, but the DeFi application itself is not a VASP; the relevant question is whether a person behind or facilitating it meets that definition.

The report’s central instruction is to look for control or sufficient influence. It divides DeFi arrangements into three groups. The first has identifiable controllers and is centralised in substance. The second is centralised in practice, but the controllers are not readily identified. The third is genuinely decentralised, with no person able to control or sufficiently influence it. The FATF Standards apply to the first two categories. The third falls outside the scope of the FATF Standards because no person controls or sufficiently influences it. The software itself is not a VASP in any of the three categories; any relevant natural or legal person must be tested separately against the VASP definition.

This is the point teams most often get wrong. A protocol can market itself as community owned, publish a token, and still have a controller under the FATF test. The report finds that centralised elements frequently persist even where governance looks distributed, through governance token concentration, administrative privileges, control over protocol upgrades, significant economic benefits flowing to a founding team, and influence over the development roadmap and the hosting infrastructure. The answer lies in how power is actually distributed, and the label on the website counts for little.

Reading the signals: on-chain and off-chain indicators of control

To make the control test operational, the report sets out a non-exhaustive list of on-chain and off-chain indicators that supervisors and firms can use to decide whether a controller exists. On-chain indicators include upgradeability and back-door privileges, unilateral parameter setting, oracle control, control over protocol-critical smart-contract infrastructure, fee flows and profits, administration or gatekeeping rights, and governance concentration. Off-chain indicators include custody and operational roles such as multisignature signatories, operation of public front-ends, relevant corporate entities, control over development or essential off-chain infrastructure, and control over branding or user communications.

Read together, those indicators help determine whether a person can materially influence protocol operations, governance or economic benefits. They are non-exhaustive and do not operate as a scoring test. Evidence of control or sufficient influence brings the arrangement within the FATF assessment, but the assessor must still identify the relevant natural or legal person and determine whether that person satisfies the VASP definition, including the business, covered-activity and on-behalf-of-another elements.

The indicators are deliberately not a checklist that produces a score. The report frames the exercise as functional and risk-based, requiring the substance of control or influence to be assessed rather than boxes to be counted. As a firm-level control recommendation, document the indicators examined, the evidence obtained and the classification reached, and establish review triggers where governance, administrative rights or economic arrangements materially change. The report does not prescribe a fixed reassessment frequency.

What the report asks jurisdictions to do

The recommendations aimed at countries are about closing the gap between the Standards and their enforcement. The report calls for a proportionate regulatory framework for DeFi arrangements, and it floats tools such as smart contract certification as a way to bring assurance into a market that ships code faster than it ships disclosures. It presses for stronger domestic cooperation between financial regulators and law enforcement, because deciding that a protocol has a controller often depends on investigative work that no filing will surface.

Beyond the framework itself, the report points to practical supervisory capacity. It encourages regulatory thematic workshops and public-private partnerships so that supervisors and industry build a shared understanding of how these arrangements actually operate. It cites the value of dedicated cryptocurrency investigation teams that can analyse how illicit actors abuse DeFi protocols. And it calls for information sharing between financial intelligence units to catch cross-border DeFi risk, including through established channels such as the Egmont Secure Web and FIU.net.

For a firm, the jurisdiction-facing recommendations identify areas that may influence future national policy and supervisory work. The report does not state that adoption of smart-contract certification or a cryptocurrency investigation unit automatically creates a firm-level counterparty-classification requirement. Separately, its private-sector recommendations support maintaining a documented risk assessment of the DeFi products and arrangements with which the firm interacts.

What it means for VASPs and banks that touch DeFi

The report is explicit that financial institutions and VASPs interacting with DeFi arrangements should risk-assess the relevant products under Recommendation 15. Recommendation 10 applies when the DeFi arrangement is seeking to become, or is already, a client. Recommendation 13 applies when the DeFi arrangement is seeking to establish a correspondent banking relationship; it is not triggered merely because a regulated firm provides services to or through an arrangement.

The DeFi report does not separately restate Recommendation 16. Travel-rule obligations arise under the current Interpretive Note to Recommendation 15 and Recommendation 16 where the relevant person qualifies as a VASP and acts as an originating or beneficiary VASP in a virtual-asset transfer; the same obligations apply to financial institutions sending or receiving such transfers for a customer. Interaction with a DeFi protocol alone does not establish those roles. Our explainer on the FATF travel rule and Recommendation 16 sets out that separate framework.

Two operational habits follow. First, determine and document the regulatory status and risk profile of the relevant persons and arrangement before routing value. Second, where an arrangement is unregulated or truly decentralised, the DeFi report says the firm should ensure that the interaction does not undermine its own AML/CFT framework, assess safeguards incorporated by the arrangement and apply proportionate measures relating to underlying users. The report does not state that every interaction with a truly decentralised arrangement is equivalent to a transaction with an unhosted wallet.

The implementation gap the survey exposes

The report draws on the FATF’s 2026 Recommendation 15 implementation survey. Of 142 responding jurisdictions, 26 had assessed risks associated with DeFi arrangements, while 93 percent, or 132 of 143, had not identified DeFi arrangements operating in their territory that qualified as VASPs under the FATF Standards. Four jurisdictions had imposed licensing or registration requirements, and two had actually licensed or registered such arrangements in practice.

It would be a mistake to treat limited DeFi-specific implementation as a general exemption from obligations already imposed by applicable law. Those obligations must nevertheless be tested against their own triggers: customer due diligence depends on the customer relationship or relevant occasional-transaction rules; Recommendation 13 depends on a correspondent relationship; Recommendation 16 depends on the firm’s role in a qualifying virtual-asset transfer; and suspicious transaction reporting depends on the applicable national law and the existence of suspicion.

Recommendation 15 implementation can be considered through FATF mutual evaluations, which separately assess technical compliance and the effectiveness of a jurisdiction’s AML/CFT framework. Weak DeFi risk assessment, regulation or supervision may contribute to adverse findings depending on the jurisdiction’s risks and evidence, but the DeFi report does not state that weak DeFi supervision automatically produces a particular effectiveness rating.

How this lands in the EU, the UK and beyond

Because the FATF operates at the level of international standards, legal obligations in the European Union arise from the applicable EU and national framework. MiCAR governs the crypto-asset-service authorisation perimeter, while Regulation (EU) 2023/1113 has applied since 30 December 2024 to information accompanying crypto-asset transfers, including transfers involving self-hosted addresses where a crypto-asset service provider is involved. Existing AML rules continue to apply until Regulation (EU) 2024/1624 generally applies from 10 July 2027. A FATF classification does not by itself determine whether an arrangement or person is a crypto-asset service provider under MiCAR; the EU definitions and activities must be tested separately. Our guide to MiCAR token classification and reporting obligations explains those boundaries for EU firms.

In the United Kingdom, relevant cryptoasset businesses remain subject to the FCA registration regime under the Money Laundering Regulations. The new FSMA authorisation gateway opens on 30 September 2026, and the new regulated-activities regime starts on 25 October 2027. Firms must therefore distinguish the current AML registration perimeter from the future FSMA authorisation perimeter and test the domestic definitions rather than assume that the FATF control concept produces an equivalent UK classification. The FCA cryptoasset regime and authorisation gateway is the relevant domestic reference point.

Legal obligations arise through national laws, regulations and other enforceable measures implementing or reflecting the Standards, or through directly applicable supranational instruments such as EU regulations. Local rules can differ in scope, thresholds, timing and terminology, so a group must classify the relevant person and relationship separately under each applicable jurisdiction.

Frequently Asked Questions

Does the FATF DeFi report create new obligations or change the Standards?

The report interprets how the existing Standards, chiefly Recommendation 15, apply to DeFi arrangements, and gives supervisors indicators for deciding when control exists. The legal obligation on any firm flows from national law that implements the Standards; the report is interpretive guidance that imposes nothing on firms directly.

If a protocol is genuinely decentralised, is everything about it out of scope?

A truly decentralised arrangement falls outside the scope of the FATF Standards because no person controls or sufficiently influences it. The software itself is not a VASP. Virtual assets and regulated persons interacting with the arrangement remain subject to the Standards and applicable law on their own account; a natural or legal person may qualify as a VASP only where it meets the glossary definition and is not covered elsewhere under the Recommendations.

How should we evidence the decision that a DeFi arrangement is or is not a VASP?

Keep the reasoning behind the classification alongside the evidence for each indicator you examined. Record which on-chain and off-chain signals you looked at, what they showed, and why you reached the conclusion. Because control can shift as tokens concentrate or admin keys are handed over, schedule a periodic re-assessment instead of treating the first classification as permanent.

Does the travel rule apply to transactions with DeFi protocols?

Under the Interpretive Note to Recommendation 15, Recommendation 16 applies to originating and beneficiary VASPs and to financial institutions sending or receiving virtual-asset transfers for customers. Where the relevant person behind a controlled DeFi arrangement qualifies as a VASP and performs one of those transfer roles, the required originator and beneficiary information applies. A transfer involving a truly decentralised arrangement or a self-hosted address is not thereby converted into a VASP-to-VASP transfer; the regulated firm must apply the risk-based measures required by its applicable law.

Our jurisdiction has no DeFi licensing regime yet. Can we wait?

The absence of a bespoke DeFi regime does not remove obligations already imposed by applicable AML law, but those duties are not triggered merely by any interaction with a DeFi arrangement. The firm must test the relevant customer-due-diligence, correspondent-relationship, transfer-information and suspicious-transaction-reporting conditions under the law governing the firm and the transaction.

How will supervisors actually test this?

Domestic supervisors test firms through the supervisory and enforcement powers available under applicable national law. FATF mutual evaluations instead assess a jurisdiction’s technical compliance with the Recommendations and the effectiveness of its AML/CFT framework; they do not directly inspect or determine the compliance of an individual firm. DeFi-related weaknesses may contribute to country findings depending on the jurisdiction’s risk profile and the evidence available.

Does institutional or tokenised DeFi change the analysis?

It increases the need for a documented assessment. The report identifies growing interaction between regulated entities and DeFi arrangements as increasing the sector’s relevance to the regulated financial system. A bank or asset manager providing services connected to a DeFi arrangement should assess the arrangement’s governance, administrative rights, economic benefits and infrastructure, but institutional participation does not itself establish that a controller exists.

Key Takeaways

  • The FATF DeFi report, published 21 July 2026, updates and complements the 2021 virtual assets guidance and interprets how the existing Standards apply to DeFi. It creates no new Recommendation.
  • Control or sufficient influence brings a DeFi arrangement within the FATF assessment, but the software is not itself a VASP. The relevant natural or legal person is a VASP only where that person also satisfies the glossary’s business, covered-activity and on-behalf-of-another tests and is not covered elsewhere under the Recommendations.
  • The report sorts arrangements into three groups. Those with identifiable controllers and those centralised in practice fall within the scope of the FATF Standards. Truly decentralised arrangements fall outside the Standards; in every category, the software itself is not a VASP, and any natural or legal person must separately satisfy the VASP definition.
  • Control is judged on substance through on-chain and off-chain indicators such as governance token concentration, admin keys, multi-signature control, fee redirection and front-end ownership. The decentralisation label does not settle it.
  • Financial institutions and VASPs interacting with DeFi should risk-assess the products under Recommendation 15. Recommendation 10 applies where the arrangement is seeking to become, or is already, a client; Recommendation 13 applies where it seeks a correspondent banking relationship; and Recommendation 16 applies separately where the firm or qualifying VASP performs the relevant virtual-asset-transfer role.
  • Of 143 jurisdictions that responded to the survey, almost 93 percent, or 132, had not identified a qualifying DeFi arrangement operating in their territory. Four had imposed licensing or registration requirements and two had actually licensed or registered an arrangement in practice.
  • The Standards reach firms through national law and directly applicable instruments such as EU regulations; the same DeFi counterparty can be regulated in one jurisdiction and unregulated in another.

Sources and References

  • FATF, Targeted Report on Regulatory Challenges from Decentralised Finance, 21 July 2026: fatf-gafi.org publication page (verified against the deterministic loop-start snapshot; see note).
  • FATF news release, FATF urges action to respond to emerging risks from Decentralised Finance: fatf-gafi.org news page.
  • FATF, Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers (2021): fatf-gafi.org guidance. FATF states that this document does not reflect revisions to the Standards made after its publication and should be read with the current FATF Recommendations and more recent guidance.
  • FATF Recommendations (Recommendation 15 on new technologies, Recommendation 10 on customer due diligence, Recommendation 13 on correspondent banking, Recommendation 16 on wire transfers): The FATF Recommendations.
  • FATF, Seventh Targeted Update on Implementation of the FATF Standards on Virtual Assets and VASPs (2026): fatf-gafi.org publication.

Testing the decentralisation claim before it is tested for you

The instruction a compliance function should carry away from this FATF DeFi report is procedural. When a DeFi arrangement appears in a payment flow, custody arrangement or product proposal, determine whether an identifiable person controls or sufficiently influences it and then test whether that person qualifies as a VASP, a financial institution or neither under the applicable definitions. For the firm’s own controls, apply the Recommendation 15 product-risk assessment and the separate Recommendation 10 client, Recommendation 13 correspondent-relationship and Recommendation 16 transfer-role triggers as applicable under domestic law. Where an arrangement is unregulated or truly decentralised, apply proportionate measures to protect the integrity of the firm’s own AML/CFT framework and address risks relating to underlying users.

Last updated: July 2026

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • AML Reporting in Luxembourg: STRs, GoAML, and Your Obligations

    Last updated: March 2026In this guideIntroductionThe Legal Basis for AML Reporting in LuxembourgWho Must Report? Obliged Entities and ScopeSuspicious Transaction Reports: What Triggers Reporting?Filing Suspicious Transaction Reports: The ProcessOther AML Reporting Obligations Beyond STRsThe CRF: Luxembourg’s Financial Intelligence UnitHow AML Reporting Works in PracticeCommon AML Reporting MistakesRecent Developments: AMLA, the AMLR, and the Single RulebookComing…

  • PRA Cryptoasset Exposures: The 100% Capital Expectation for UK Banks

    On 18 May 2026, the Prudential Regulation Authority published a Dear CEO letter addressed to the chief executives of all banks and designated investment firms, signed by David Bailey, Charlotte Gerken and Rebecca Jackson. The PRA continues to expect a 100 per cent own-funds requirement under the market-risk framework for unbacked cryptoassets. Separately, where a…

  • FCA Cryptoasset Regime: What UK Crypto Firms Must Do Before the Authorisation Gateway Closes

    Last updated: July 2026In this guideWhat the FCA cryptoasset regime package published on 30 June 2026Which cryptoasset activities now need FCA authorisationThe authorisation gateway is a window, not a queueWhy an MLR 2017 registration does not carry you acrossThe prudential regime: COREPRU and CRYPTOPRUStablecoins and safeguarding: CASS 16 and CASS 17Conduct, the Consumer Duty and…

  • FATF Travel Rule Consultation: What EU Payment Firms and CASPs Should Consider

    Last updated: June 2026In this guideWhat the FATF travel rule consultation opened, and what the response deadline isWhat has changed in the revised Recommendation 16Where the EU already stands: the recast Transfer of Funds RegulationThe de minimis trap: EUR 1,000 for funds, nothing for cryptoThe real change for EU firms: the gap between today’s TFR…

  • EBA-NYDFS Stablecoin MoU: What EU EMT Issuers Should Know

    Last updated: June 2026In this guideWhat the EBA-NYDFS stablecoin MoU actually coversThe legal basis: MiCA Article 126 and EBA agreements with third countriesWhy this lands on EMT issuers specificallyWhat the MoU changes, and what it does notThe US side: GENIUS Act and why New YorkWhat reporting and supervision teams should do nowFrequently Asked QuestionsRelated ArticlesKey…