FATF Warns ‘DeFi’ Leaves Centralized Platforms Out of AML Rules

The Financial Action Task Force is urging governments to bring decentralized finance platforms under anti-money laundering rules when developers, token holders or other identifiable parties retain meaningful control. It warned that many purportedly decentralized platforms are not as decentralized as they claim.

In a report published Tuesday (July 21), new report, the Paris-based global anti-money laundering (AML) standard-setter said its existing rules apply to DeFi arrangements whenever an identifiable person or entity exercises “control or sufficient influence,” regardless of whether the project describes itself as decentralized.

FATF divides DeFi arrangements into three broad categories: platforms with identifiable controllers; platforms that are effectively centralized but whose operators remain hidden; and a smaller group of genuinely leaderless protocols. Only the last category falls outside FATF’s standards, according to the report.

According to Decrypt, that distinction matters because features commonly associated with DeFi do not necessarily make a platform decentralized for regulatory purposes. FATF identified concentrated holdings of governance tokens, administrative privileges, control over protocol upgrades and the distribution of fees and rewards as indicators that centralized control may remain.

Other signs include upgrade keys or “kill switches,” authority to set fees or risk parameters, concentrated voting power, control of a public-facing website or app, and corporate entities that employ core developers or control a project treasury. Developers, major token holders, funders and front-end operators could therefore qualify for licensing and supervision as financial businesses. Simply operating an interface that channels users into a protocol may be sufficient.

Yet implementation has been sparse. Nearly 93% of jurisdictions responding to a recent FATF survey have never applied the standards to a qualifying DeFi arrangement. Only 26 of 142 jurisdictions have assessed DeFi-related risks, only four have established licensing requirements and just two have actually registered or licensed a platform.

The figures expose a potentially significant gap between FATF’s existing regulatory framework and national enforcement. Although FATF standards are not themselves law, more than 200 jurisdictions use them as a benchmark, and countries can face increased scrutiny, including placement on FATF’s “grey list,” for persistent deficiencies.

In a statement accompanying the report, FATF President Giles Thomson said the objective is to prevent criminals from exploiting emerging technologies to “launder dirty money” while “supporting responsible financial innovation.”

To close the compliance gap, FATF recommends that jurisdictions require or encourage DeFi projects to incorporate AML safeguards directly into smart contracts or user interfaces. Those controls could include sanctions screening and proof-of-know-your-customer checks before certain transactions or functions can occur.

Where protocols are genuinely decentralized, regulators should focus on surrounding “choke points,” including stablecoin issuers capable of freezing tokens, exchanges providing fiat on- and off-ramps and front-end operators, the report said. Banks and crypto exchanges should conduct due diligence on DeFi platforms they interact with and stop doing business with platforms presenting unacceptable risks.

FATF tied the regulatory urgency to DeFi’s growing use in illicit finance. The report cites ransomware groups, professional money-laundering networks and investment fraud operations using mixers, bridges and swaps. It also points to more than $570 million allegedly stolen in two April attacks attributed to North Korean state-linked hackers, representing roughly 76% of crypto hacking losses for the year covered by the report.

The potential exposure is growing with the sector itself. DeFi’s total value locked has reached $86.6 billion, about 85% above 2023 levels, while the 12 largest protocols account for more than 60% of that value.

FATF’s core message is that regulators should examine how a platform actually operates rather than accept decentralization claims at face value. Where identifiable parties retain the ability to control code, governance, interfaces or economic benefits, the watchdog says existing AML obligations should follow that control.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *