FATF Introduces DeFi Control Test to Strengthen Global AML Regulation

FATF Introduces DeFi Control Test to Strengthen Global AML Regulation

The Financial Action Task Force (FATF) has issued a targeted report setting out how anti-money laundering and counter-terrorist financing standards should apply to decentralised finance (DeFi), placing the concept of “control or sufficient influence” at the centre of its regulatory approach.

Published on July 21, 2026, the report updates and expands the FATF’s 2021 guidance on virtual assets and virtual asset service providers (VASPs). It seeks to help national authorities identify which DeFi arrangements fall within Recommendation 15, even when platforms describe themselves as decentralised or rely heavily on automated smart contracts.

The FATF’s approach is functional rather than technology-based. Under the framework, the existence of blockchain infrastructure, open-source software or smart contracts does not by itself determine whether AML and counter-terrorist financing requirements apply. Instead, regulators are expected to examine the people, entities and governance structures that operate, influence or benefit from a DeFi arrangement.

Control, Influence and VASP Status

The report confirms that the FATF Standards apply when an identifiable natural or legal person exercises control or sufficient influence over a DeFi arrangement. Such a person may then fall within the FATF definition of a VASP if they conduct or actively facilitate activities such as exchanging virtual assets, transferring assets, providing custody or administering instruments that enable control over virtual assets.

The FATF stressed that a DeFi application or smart contract itself is not a VASP. The software may execute transactions automatically, but the individuals or entities controlling the protocol, its governance or its access points may be subject to regulatory obligations.

The report also warns that a platform’s marketing language should not determine its regulatory status. A project may present itself as decentralised while retaining centralised features through its developers, investors, administrators, governance-token holders or other participants.

Among the factors that may indicate control or sufficient influence are:

  • The ability to set or change protocol parameters.
  • Authority to upgrade or modify smart-contract code.
  • Administrative or back-door privileges.
  • Concentrated ownership of governance tokens.
  • Control over voting blocs, proposal rights or veto powers.
  • The ability to manage access to permissioned pools or functions.
  • The receipt of protocol fees, rewards, liquidation penalties or maximal extractable value.
  • Influence over development teams, infrastructure, front-end applications or key service providers.

The FATF said these indicators are not exhaustive and should not be applied as a rigid checklist. Authorities should assess the specific governance, operational and economic structure of each arrangement.

Three Categories of DeFi

The report divides DeFi arrangements into three broad categories.

The first consists of centralised arrangements with identifiable controllers. These may include protocols where administrators, developers, funders or governance-token holders retain meaningful decision-making authority. The FATF states that arrangements in this category fall within the FATF Standards and should be regulated.

The second category covers arrangements that are centralised in practice but where the individuals exercising control cannot readily be identified. Pseudonymity, complex ownership structures or distributed governance may make it difficult for authorities to establish who controls the protocol. These arrangements nevertheless remain within the scope of the FATF Standards, although enforcement may be difficult.

Where regulatory measures cannot be effectively applied, jurisdictions are encouraged to treat these arrangements, for practical purposes, as unregulated and apply risk-mitigation measures similar to those used for truly decentralised systems.

The third category consists of genuinely decentralised arrangements in which no person maintains control or exercises sufficient influence. These arrangements fall outside the direct scope of the FATF Standards because there is no identifiable party to which the obligations can be applied. However, the FATF said they may still present significant financial crime risks and should be subject to alternative, risk-based safeguards where appropriate.

Global Implementation Gap

The report identifies a substantial gap between the FATF’s standards and their implementation by national authorities. Almost 93% of reporting jurisdictions—132 of 143—had not implemented Recommendation 15 for DeFi arrangements falling within the regulatory perimeter.

Only two of 142 jurisdictions reported having licensed or registered a DeFi arrangement in practice. The figures indicate that many countries have yet to establish a practical method for identifying qualifying DeFi operators, determining jurisdictional responsibility or supervising protocols that operate across multiple countries.

The FATF attributed the implementation difficulties to DeFi’s global reach, the absence of clear jurisdictional anchors, limited technical expertise among supervisors and the difficulty of distinguishing decentralised technology from centralised governance.

It also noted that regulatory fragmentation could encourage arbitrage. Protocols and operators may structure activities across jurisdictions with weaker or less clearly defined virtual asset rules, while users and assets move rapidly between blockchains, platforms and service providers.

Financial Crime Risks

The FATF said DeFi’s growth has increased its relevance to the global financial system. Total value locked in DeFi reached approximately USD 86.644 billion in 2026, an increase of about 85% from 2023, according to data cited in the report.

The report identifies several features that may increase exposure to money laundering, terrorist financing and proliferation financing. These include pseudonymous transactions, permissionless access, smart-contract automation, composability, cross-border reach and the use of unhosted wallets.

Criminal actors may exploit decentralised exchanges, liquidity pools, cross-chain bridges, mixers and governance mechanisms to layer and combine illicit funds with legitimate assets. The FATF also identified chain-hopping, governance manipulation, cyberattacks and the use of offshore or unregulated service providers as continuing risks.

Smart-contract vulnerabilities and weaknesses in oracle systems may create additional opportunities for fraud, market manipulation and theft. The report noted that the speed and complexity of DeFi transactions can make traditional supervisory and investigative methods less effective.

Expectations for Regulators and Industry

The FATF recommends that jurisdictions conduct risk assessments covering DeFi’s domestic exposure, cross-border activity, governance models and financial crime vulnerabilities. Authorities should establish methods for identifying controllers, require licensing or registration for centralised DeFi arrangements and develop supervisory expertise in blockchain technology and on-chain investigation.

Regulators are also encouraged to use blockchain analytics, cooperate with law enforcement and financial intelligence units, and establish mechanisms for tracing, freezing and recovering illicit virtual assets.

Financial institutions and VASPs that interact with DeFi arrangements will also face heightened expectations. They should conduct risk assessments of the protocols and services they use, examine whether AML and counter-terrorist financing safeguards are in place and apply customer due diligence where required.

Where an arrangement is regulated, banks and VASPs should assess its AML framework and conduct appropriate due diligence. Where it is unregulated, firms should ensure that their activities do not weaken their own compliance systems. The FATF points to measures such as real-time blockchain monitoring, customer due diligence on underlying users and the use of third-party compliance providers.

The report is non-binding and does not impose a single global licensing model. However, it is likely to influence national legislation, supervisory decisions and FATF mutual evaluations. Its central message is that decentralisation will be assessed by examining how a DeFi arrangement actually operates—not simply by accepting the label used by its developers.