FATF DeFi report says control should trigger AML oversight
FATF says DeFi projects with controllers should face AML oversight, citing sparse national enforcement and illicit finance risks.
By Rafael Ortiz · Fintech Correspondent
· 3 min read
The Financial Action Task Force said in a FATF DeFi report that governments should apply anti-money laundering standards to crypto platforms when developers, token holders or other identifiable parties retain meaningful control. The Paris-based standard-setter warned that many projects using the decentralised finance label still have centralised features that can bring them within existing rules.
In the report published July 21, FATF said its standards apply when a person or entity has “control or sufficient influence” over a DeFi arrangement, regardless of how the project describes itself. FATF standards are not statutes, but more than 200 jurisdictions use them as a benchmark, and countries with persistent weaknesses can face additional scrutiny, including placement on the group’s grey list.
When do FATF DeFi AML rules apply?
FATF divides DeFi arrangements into three groups: projects with identifiable controllers, projects that function as centralised platforms while their operators remain obscured, and a smaller set of protocols that are genuinely leaderless. The watchdog said only the last group sits outside its standards.
The report treats decentralisation as a question of operational control rather than branding. FATF listed several indicators that a project may still have a responsible party, including concentrated governance-token ownership, administrative powers, control over software upgrades and the ability to direct fees or rewards.
Other signals include upgrade keys, emergency shutdown mechanisms, authority to set fees or risk limits, concentrated voting rights, control of a website or app used by customers, and corporate entities that employ core developers or manage a project treasury. Under that analysis, FATF said developers, major token holders, funders and front-end operators could fall within licensing and supervisory requirements for financial businesses. Operating an interface that sends users into a protocol may also be enough to create obligations.
National implementation remains limited, according to FATF’s survey. Nearly 93% of responding jurisdictions said they had not applied the standards to a qualifying DeFi arrangement. Out of 142 jurisdictions, 26 had assessed DeFi-related risks, four had created licensing requirements and two had registered or licensed a platform.
FATF President Giles Thomson said in a statement accompanying the report that the aim is to stop criminals from using emerging technologies to “launder dirty money” while “supporting responsible financial innovation.”
How FATF wants regulators to close the gap
FATF recommended that governments require or encourage DeFi projects to build anti-money laundering controls into smart contracts or user interfaces. The report said such measures could include sanctions screening and proof-of-know-your-customer checks before users can carry out certain transactions or use particular functions.
For protocols that are genuinely decentralised, FATF said regulators should concentrate on surrounding choke points. Those include stablecoin issuers that can freeze tokens, exchanges that provide fiat entry and exit points, and front-end operators that connect users to protocols. The report also said banks and crypto exchanges should conduct due diligence on DeFi platforms they interact with and cease relationships where risks are unacceptable.
FATF linked the issue to illicit finance activity across DeFi tools, including mixers, bridges and swaps. The report cited use by ransomware groups, professional laundering networks and investment fraud operations. It also pointed to more than $570 million allegedly stolen in two April attacks attributed to North Korean state-linked hackers, equal to about 76% of crypto hacking losses for the year covered by the report.
The market exposure has grown alongside the sector. FATF said DeFi total value locked has reached $86.6 billion, about 85% higher than 2023 levels, while the 12 largest protocols account for more than 60% of that value.
FATF’s central position is that regulators should examine who can change code, direct governance, manage interfaces or benefit economically from a platform. Where identifiable parties hold that kind of influence, the watchdog said existing AML obligations should follow the control.
This story draws on original reporting from PYMNTS.