Global Regulatory Standards for Decentralized Finance Take Shape as FATF Introduces Control and Influence Test for Protocols

The Financial Action Task Force (FATF), the preeminent global watchdog for anti-money laundering and counter-terrorist financing (AML/CFT), has released a comprehensive 49-page report outlining a new framework for the regulation of decentralized finance (DeFi). This landmark publication marks a pivotal shift in how international regulators approach the "regulatory headache" of decentralized protocols, moving away from…

 Avatar

by

8 minutes

Read Time

The Financial Action Task Force (FATF), the preeminent global watchdog for anti-money laundering and counter-terrorist financing (AML/CFT), has released a comprehensive 49-page report outlining a new framework for the regulation of decentralized finance (DeFi). This landmark publication marks a pivotal shift in how international regulators approach the "regulatory headache" of decentralized protocols, moving away from broad generalizations and toward a nuanced "Control or Sufficient Influence" (COSI) test. As DeFi continues to mature, offering benefits such as automated settlement and 24/7 availability, it has also become a focal point for illicit financial activity. According to data from the 2026 Crypto Crime Report, illicit flows into DeFi protocols surged by 343% year-on-year, underscoring the urgency for a standardized global oversight mechanism that can mitigate risk without stifling the underlying technological innovation.

The Evolution of DeFi and the Regulatory Challenge

Decentralized finance has long existed in a perceived legal gray area. Unlike traditional financial institutions or centralized Virtual Asset Service Providers (VASPs) such as Coinbase or Binance, DeFi protocols operate through smart contracts on public blockchains. These arrangements often lack a central headquarters or a clear management team, complicating the application of existing AML/CFT obligations. The core of the FATF’s investigation centers on a fundamental question: who, if anyone, exercises enough control over a protocol to be held legally responsible for compliance?

The rise of DeFi has been rapid. Since the "DeFi Summer" of 2020, the total value locked (TVL) in these protocols has fluctuated but generally trended toward institutional adoption. However, the same features that attract legitimate institutional capital—programmability and transparency—also appeal to bad actors. The FATF acknowledges that while jurisdictions should enable the benefits of DeFi, the current enforcement gap is significant. Data indicates that 93% of jurisdictions have yet to even identify qualifying DeFi protocols within their borders, and only a handful have moved toward licensing or enforcement.

Chronology of Global Crypto Regulation (2019–2026)

The 2026 DeFi report is the culmination of a multi-year effort by the FATF to bring the digital asset ecosystem into alignment with global financial standards.

  • June 2019: The FATF first extended its AML/CFT standards to virtual assets and VASPs, introducing the "Travel Rule" which requires the collection and transmission of sender and recipient information for transactions.
  • October 2021: Updated guidance was issued specifically addressing DeFi, suggesting that entities with "control or sufficient influence" over DeFi arrangements could be classified as VASPs.
  • 2023–2025: A period of "monitoring and observation" followed, during which the FATF tracked the emergence of Decentralized Autonomous Organizations (DAOs) and the increasing use of bridges and mixers.
  • July 2026: The release of the "7th Targeted Update" and the dedicated DeFi report. These documents highlight a persistent "enforcement gap," noting that while the framework exists, implementation at the national level remains sluggish.

The COSI Test: Defining the Spectrum of Control

The centerpiece of the FATF’s new report is the "Control or Sufficient Influence" (COSI) test. This framework rejects a binary view of DeFi, instead recognizing that protocols exist on a spectrum of decentralization. The FATF distinguishes between three primary categories of DeFi arrangements:

  1. Centralized DeFi: Protocols where a specific person or legal entity maintains clear control. These are treated as traditional VASPs and must comply with all standard AML/CFT regulations, including customer due diligence (CDD) and suspicious activity reporting (SAR).
  2. DeFi with Sufficient Influence: Protocols where control is dispersed but still identifiable through specific indicators. This might include governance token holders who can vote on protocol changes or developers who maintain the administrative keys (admin keys).
  3. Truly Decentralized DeFi: Protocols where no single entity or group exercises control. While these fall outside the current VASP definition, the FATF recommends that supervisors monitor them closely using blockchain analytics to ensure they do not become havens for money laundering.

To operationalize the COSI test, the FATF points to several on-chain indicators. These include the ability to modify smart contracts, the power to freeze or unfreeze assets, and the receipt of fees generated by the protocol. Off-chain indicators are also considered, such as who controls the front-end website interface, who manages the development repositories (e.g., GitHub), and who communicates publicly on behalf of the protocol.

Supporting Data: The Rising Stakes of Illicit Finance

The FATF’s move toward stricter DeFi oversight is driven by alarming trends in crypto-related crime. The 343% increase in illicit flows into DeFi protocols is a record high, reflecting a shift away from centralized exchanges as criminals seek out less regulated avenues.

Stablecoins have emerged as a particular point of concern. Once used primarily as a "safe haven" from crypto volatility, stablecoins now account for an estimated 84% of all illicit transaction volume. Because stablecoins are the primary form of collateral in DeFi, they serve as the bridge between legitimate finance and criminal networks. The FATF report emphasizes that stablecoin issuers have a unique responsibility to implement "freeze and burn" capabilities, allowing them to invalidate tokens held by sanctioned entities or those linked to major hacks.

However, the report also notes a counter-trend: criminal networks are increasingly designing their own stablecoins specifically to resist these freezing mechanisms. This "arms race" between regulators and illicit actors has made the use of advanced blockchain analytics an essential requirement for any effective supervisory regime.

Official Responses and Industry Reactions

While the FATF does not set laws itself, its "Recommendations" are followed by over 200 countries and jurisdictions. The reaction to the DeFi report from the global financial community has been one of cautious approval, though industry advocates have raised concerns about the feasibility of compliance for smaller protocols.

A spokesperson for a major European regulatory body noted, "The COSI test provides the clarity we have been seeking. It allows us to move past the ‘theatre of decentralization’ and hold accountable those who are actually pulling the levers of these financial machines."

Conversely, DeFi advocacy groups have argued that the FATF’s focus on "administrative keys" and "governance tokens" might discourage developers from building in safeguards. They argue that if implementing a "kill switch" for security purposes leads to a protocol being labeled as "controlled," developers might choose to omit these features to avoid regulatory burdens. The FATF addressed this in the report, stating that security features and AML risk mitigation controls should be encouraged and not necessarily used as a "penalty" to prove control.

Implications for Financial Institutions and Protocols

The FATF report carries significant implications for both traditional financial institutions (TradFi) and native crypto entities.

For Financial Institutions: Banks and asset managers looking to engage with DeFi are now expected to adopt a "risk-based approach." This involves performing deep due diligence on DeFi counterparties. If a bank interacts with a protocol that lacks AML controls or uses high-risk tools like mixers and cross-chain bridges, they are expected to apply "enhanced due diligence." This includes tracing the origin of funds and setting lower thresholds for flagging suspicious activity.

For DeFi Protocols: The era of "regulatory arbitrage" appears to be closing. For protocols categorized as centralized or having "sufficient influence," the requirements are clear: they must implement licensing, KYC (Know Your Customer) procedures, and transaction monitoring. The FATF explicitly recommends embedding these controls directly into the protocol’s infrastructure—a concept known as "compliance by design."

For Truly Decentralized Protocols: While these may be "out of scope" for direct VASP regulation, they are not invisible. The FATF encourages supervisors to use blockchain analytics to monitor these protocols. Furthermore, institutional capital is already showing a preference for "permissioned DeFi"—protocols that include screening and governance controls—suggesting that compliance is becoming a market differentiator rather than just a legal hurdle.

Future Outlook: Bridging the Implementation Gap

The challenge ahead lies in the global implementation of these standards. The FATF’s "7th Targeted Update" revealed a stark reality: despite the existence of guidelines, the majority of the world has yet to take meaningful action against DeFi-related financial crime. Only four jurisdictions have imposed licensing requirements, and only one has taken a formal enforcement action against a DeFi protocol.

The FATF calls for a "public-private partnership" model to bridge this gap. By collaborating with blockchain analytics firms, regulators can gain the technical expertise needed to map wallet clusters, trace fee flows, and identify the real-world entities behind decentralized "fronts."

As the boundary between cybersecurity and financial compliance continues to blur, the COSI test will serve as the benchmark for the next generation of financial regulation. The goal is a functional, tech-neutral, and proportionate framework that ensures the DeFi ecosystem can grow safely without sacrificing the transparency and efficiency that made it revolutionary in the first place. For an industry seeking legitimacy and institutional scale, the FATF’s DeFi report provides a long-awaited, albeit demanding, roadmap for the future.

About the Author

About the Author

Easy WordPress Websites Builder: Versatile Demos for Blogs, News, eCommerce and More – One-Click Import, No Coding! 1000+ Ready-made Templates for Stunning Newspaper, Magazine, Blog, and Publishing Websites.

BlockSpare — News, Magazine and Blog Addons for (Gutenberg) Block Editor

Search the Archives

Access over the years of investigative journalism and breaking reports