









Decentralized finance (DeFi) has long posed a regulatory challenge. DeFi arrangements, also known as protocols, can offer significant operational benefits: automated settlement, programmable financial services, and round-the-clock availability. But their varied governance structures make it difficult to determine when and how existing anti-money laundering and counter-terrorist financing (AML/CFT) obligations should apply. The central question: who, if anyone, exercises enough control over an arrangement to be held responsible for compliance?
DeFi’s “regulatory challenges” are the focus of a new 49-page report by the Financial Action Task Force (FATF), the global standard-setter for Anti-Money Laundering/ Combating the Financing of Terrorism AML/CFT. The FATF acknowledges in its report that institutions are eager to utilize DeFi’s benefits, and that jurisdictions should enable these interactions. But the same properties that make DeFi attractive to legitimate users also appeal to illicit actors. Our 2026 Crypto Crime Report found that illicit flows into DeFi protocols rose 343% year-on-year, making effective risk mitigation — not restriction — essential to ensuring DeFi can continue to grow safely.
One big question at the center of the report is coverage. How can a jurisdiction know if a DeFi protocol should be regulated under the same rules the FATF sets for Virtual Asset Service Providers (VASPs) such as crypto exchanges and stablecoin issuers? The FATF’s answer is the “control or sufficient influence” (COSI) test. It determines whether a protocol should be within regulators’ scope.
While the FATF offers a framework through which jurisdictions can consider COSI, it does not lay out a single playbook for doing so. But it does point to one essential capability: blockchain analytics. Blockchain analytics provides the on-chain intelligence that makes this framework operational — helping supervisors apply the COSI test, enabling regulated entities to engage with DeFi safely, and giving DeFi protocols the tools to embed compliance without sacrificing efficiency and innovation.
The FATF’s framework recognises that DeFi exists on a spectrum. Rather than treating all protocols the same, it distinguishes three categories based on who, if anyone, exercises control or sufficient influence:
To measure “control or sufficient influence,” and therefore establish which group a protocol falls into, the FATF points to a series of indicators:
On-chain indicators:
Chainalysis can help supervisors make the FATF’s framework operational. With Reactor, investigators can cluster related wallets, trace fee and treasury flows through DeFi protocols, bridges, and DEXs, and connect on-chain activity to real-world counterparties across 27+ blockchains and 40 million+ assets. That gives supervisors an evidence-based way to assess who actually exercises control or sufficient influence over a protocol, rather than relying on labels or public claims alone.
The FATF also identifies off-chain indicators — including control over front-end interfaces, development repositories, and public communications about the ability to modify the protocol — as relevant factors in the COSI assessment.
The COSI test aims to assess who has overall control over a protocol, not whether a protocol has chosen to adopt responsible security and compliance practices. Notably, the FATF actively encourages security features like kill switches and pause mechanisms, and AML risk mitigation controls such as front-end screening and sanctions checks, across all categories of DeFi. This distinction matters: protocols should feel encouraged to implement robust safeguards, knowing that the regulatory framework is designed to assess control or sufficient influence over financial services provided, not to penalise good practice.
Jurisdictions have so far been slow to address the challenges of DeFi, which has created a gap in the efficacy of their enforcement frameworks. According to the FATF’s 7th Targeted Update published the same week as the DeFi report, 93% of jurisdictions have not identified qualifying DeFi protocols in their territory. Only four have imposed licensing requirements, and just one has taken enforcement action. This underscores the importance of the framework the report establishes.
The FATF sets out clear priorities for jurisdictions to speed up their efforts:
The DeFi report calls on jurisdictions to collaborate with DeFi protocols, VASPs, and blockchain analytics firms in order to better combat emerging risks — a public-private partnership model emphasized in the 7th Targeted Update. Chainalysis has supported these partnerships through initiatives like Operation Spincaster, in which public investigators and private sector partners collaborated to disrupt crypto scams. We welcome the extension of this model to the DeFi ecosystem.
The report expects financial institutions to take a risk-based approach to DeFi. All financial institutions, be they in traditional finance or in crypto, should evaluate their DeFi counterparties based on their governance structures, their effective implementation of AML/CFT controls, and their ability to mitigate risks — including hacks. These steps complement the measures such financial institutions already follow to mitigate on-chain risk, like transaction-monitoring and wallet screening tools.
Where higher risks are identified — for example, exposure to bridges, mixers, or cross-chain tools, or interaction with protocols that have limited compliance controls — regulated entities are expected to apply enhanced due diligence, such as deeper analysis of fund flows, tracing exposure to high-risk services, or setting lower thresholds for flagging suspicious activity.
Stablecoin issuers carry a distinct responsibility within the DeFi ecosystem. The attributes that make stablecoins the primary form of collateral in DeFi — 24/7 value transfer globally and instantly — also attract illicit actors who seek to exploit them. As documented in our 2026 Crypto Crime Report, stablecoins now account for 84% of all illicit transaction volume. With the growth of stablecoins in DeFi in particular, issuers have a unique opportunity to make a material difference in preventing and fighting financial crime. The FATF expects freeze and burn capabilities as a baseline — and as the 7th Targeted Update flagged, criminal networks are now designing stablecoins specifically to resist freezing.
Where a DeFi protocol lands on the COSI test determines how the FATF’s recommendations apply to it.
Centralized DeFi
If a protocol has identifiable controllers —or has controllers that simply haven’t been identified yet — it is subject to the same AML/CFT obligations as any other VASP: licensing, customer due diligence, transaction monitoring, sanctions compliance, and Travel Rule compliance where applicable. The FATF also recommends embedding controls directly into protocol infrastructure: automated freezing, on-chain risk-scoring, and transaction blocking. Smart-contract audits are necessary, ongoing monitoring should be standard practice.
The message is clear: if you have control, you also have obligations.
Truly Decentralized DeFi
Protocols where no person or entity exercises control or sufficient influence fall outside the FATF’s regime. But being out of scope does not mean being risk-free. The FATF encourages supervisors to monitor these protocols using blockchain analytics, expects regulated entities at the touchpoints to apply appropriate due diligence, and relies on stablecoin issuer controls as an indirect safeguard.
The practical implication: even truly decentralized protocols benefit from adopting compliance controls voluntarily at the design and pre-deployment phase. Early signs suggest institutional capital is already flowing preferentially to protocols with screening, monitoring, and governance controls in place — compliance is becoming a market differentiator, not just a regulatory obligation.
The FATF’s DeFi report establishes a framework that is functional, tech-neutral, and proportionate. For an industry seeking regulatory clarity, this is a constructive outcome. But the framework is only as good as how it is applied. Several open questions will shape DeFi’s next phase.
The FATF explicitly encourages both public and private sectors to strengthen their technical expertise in blockchain analytics tools to support DeFi-related investigations. Many of the implementation challenges outlined above are ones Chainalysis is uniquely positioned to address; Chainalysis accurately attributed 145 million smart contract transactions representing $15.8 trillion in value in 2026.
Applying the COSI test proportionately requires the ability to analyse governance token distribution, map wallet clusters, trace fee flows, and assess the real-world control picture behind a protocol — exactly what our clustering and attribution capabilities are built for. Cross-border coordination becomes practical when supervisors share a common analytical infrastructure that provides visibility across jurisdictions and chains. And as the Venus Protocol case above demonstrated, the cybersecurity-compliance convergence is already a reality in our product suite.
More broadly, we help regulated entities assess their DeFi exposure, enable DeFi protocols to embed the AML/CFT controls the FATF recommends, and work with supervisors in over 100 countries to make on-chain intelligence operational. With the vast majority of jurisdictions yet to identify qualifying DeFi protocols, the gap between framework and practice needs to close quickly. We’re ready to help bridge it.
To learn more about how Chainalysis supports DeFi compliance and supervision, get in touch with our team.
This website contains links to third-party sites that are not under the control of Chainalysis, Inc. or its affiliates (collectively “Chainalysis”). Access to such information does not imply association with, endorsement of, approval of, or recommendation by Chainalysis of the site or its operators, and Chainalysis is not responsible for the products, services, or other content hosted therein.
This material is for informational purposes only, and is not intended to provide legal, tax, financial, or investment advice. Recipients should consult their own advisors before making these types of decisions. Chainalysis has no responsibility or liability for any decision made or any other acts or omissions in connection with Recipient’s use of this material.
Chainalysis does not guarantee or warrant the accuracy, completeness, timeliness, suitability or validity of the information in this report and will not be responsible for any claim attributable to errors, omissions, or other inaccuracies of any part of such material.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。