Think DeFi is Exempt from AML/CFT? Think Again
- Todd Phillips

- 5 hours ago
- 6 min read
It has become something close to common wisdom in the digital asset industry that the labs and protocol teams building decentralized finance (DeFi) protocols sit outside the anti-money laundering and countering the financing of terrorism (AML/CFT) perimeter. The reasoning is familiar: Although labs write software, the software runs itself, users hold their own keys, and no one takes custody of anyone’s assets. Under this argument, there is no “financial institution” with the obligations to know its customers, monitor transactions, or file suspicious activity reports.
A new report from the Financial Action Task Force (FATF), an international intergovernmental body that develops and promotes policies to combat money laundering and terrorist financing that counts the United States as a member, contradicts this theory. In Targeted Report on Regulatory Challenges from Decentralised Finance, FATF explains that most DeFi protocols are subject to its standards, with only genuinely decentralized arrangements falling outside them.(1) And even where protocols are truly leaderless, FATF warns that the banks, exchanges, stablecoin issuers, and other virtual asset service providers (VASPs) interacting with them must satisfy their own AML/CFT obligations or stop interacting altogether.
This report should cause labs to question whether they have really escaped AML/CFT requirements or whether it is only a matter of time before U.S. regulators come knocking.
How DeFi Can Facilitate Financial Crimes
DeFi protocols offer compelling value propositions. Permissionless access allows any digital wallet to interface with and use the protocol without onboarding limitations. Automation moves value in seconds. Sophisticated trades can be orchestrated through a series of protocols with a single prompt.
Yet the features that make DeFi compelling are the same ones that make it useful to illicit actors. Because most DeFi protocols never collect traditional Customer Identification Program elements (e.g., name, address, date of birth, government-issued identification number or identity document) from the wallets that interact with them, they function as an unregulated venue where criminal actors can convert, swap, or move value, routing stolen or illicit funds directly through permissionless smart contracts. The clearest illustration is the mixing service Tornado Cash, which was sanctioned by the Office of Foreign Assets Control (OFAC) in August 2022 for allegedly helping North Korean hackers launder billions of dollars of user funds.(2) Since Tornado Cash’s 2019 launch, an estimated $7 billion or more in value had flowed through the service, none of it gated by identity checks.
Although Tornado Cash is perhaps the most notorious DeFi protocol used for illicit activities, it is not the only one. Even mainstream, non-custodial exchanges are used as liquidity-conversion layers within larger illicit fund flow because they impose no Know Your Customer requirements at the protocol level.(3) Criminals use these protocols to swap stolen or sanctioned assets into more liquid, harder-to-trace tokens without ever presenting an ID.
What FATF’s Report Says
FATF has long explained that DeFi protocols are obligated to engage in AML/CFT measures when natural or legal persons exercise “control or sufficient influence” over them.(4) This report takes that assessment further, articulating an operationalizable test to determine whether control or influence exists.
The report sorts DeFi into three buckets: arrangements with identifiable controllers; arrangements that are centralized in practice but whose operators remain hidden; and a genuinely leaderless minority FATF calls “truly decentralized.” Only the third bucket escapes AML/CFT obligations, and FATF’s assessment is that the number of institutions in this bucket is small. Although many projects present themselves as fully decentralized, a whitepaper describing a protocol as autonomous is evidence of nothing. FATF’s report finds that centralized elements frequently persist in practice through various methods, including:
Concentration of governance tokens in a handful of wallets;
Retention of administrative privileges and controlling protocol upgrades by projects’ initial developers; and
Significant and continuing influence by insiders over protocols’ development and infrastructure.
To help jurisdictions apply this test in a risk-based way, FATF sets out on-chain and off-chain indicators of control. On-chain markers include the existence of upgrade keys and administrative functions in individuals; a wallet’s ability to set or change fees and risk parameters, including control over the oracles upon which DeFi protocols rely; and concentrated voting power in governance. Off-chain markers include the existence of persons that control a protocol’s public website, app, or front-end interface; persons that hold or direct the treasury; and legal entities that employ core developers and control protocol development. Where those indicators are present, FATF says, the persons behind them — developers, large token holders, front-end operators, or funders — should be licensed, registered, and supervised like any other financial firm. Notably, FATF explains that operating a front-end that routes users into a protocol can be sufficient on its own.
For DeFi arrangements that are truly decentralized or leaderless, FATF does not simply concede that AML/CFT obligations do not apply. Rather, it advises that the chokepoints surrounding DeFi (e.g., stablecoin issuers with the technical ability to freeze tokens, VASPs that provide fiat on- and off-ramps, interface operators) are subject to such requirements. Regulated entities that interact with or provide services to DeFi arrangements must comply with relevant AML/CFT obligations, including those related to customer due diligence and correspondent banking. Where these entities cannot ensure compliance, FATF recommends that they refrain from interacting with the arrangement altogether.
Moreover, where DeFi protocols cannot ensure that their operations comply with AML/CFT requirements, FATF advises that the arrangements may be sanctioned directly.
How Klaros Can Help
In practice, FATF’s identification of most DeFi protocols as centralized and its recommendation that VASPs only interact with or provide services to DeFi protocols that can ensure AML/CFT compliance create significant incentives for labs to build AML controls directly into smart contracts and interfaces. Without proof-of-KYC gating and sanctions screening before certain functions execute, projects risk being left behind as blockchain-based activity moves into the regulated sector.
Klaros Group works at the intersection of financial innovation, regulation, and risk management, and Bank Secrecy Act (“BSA”) and financial crimes compliance is a core part of our practice. For labs working through what this report means, we can help in several concrete ways:
Controller analysis. Rather than assuming the answer, we build a documented, evidence-based assessment that maps FATF’s on-chain and off-chain indicators (e.g., admin keys, multisig composition, upgrade authority, governance token distribution, fee and revenue flows, front-end ownership, developer employment, treasury control) against the actual facts of your arrangement, and identifies which levers create exposure and which can be relinquished.
Building the program. Where a lab, front-end operator, or affiliated entity is in scope, we draft the full stack: an AML/CFT risk assessment, policies and procedures, customer due diligence and sanctions screening at the interface layer, transaction monitoring, suspicious activity reporting workflows, Travel Rule handling, and escalation structures sized to the business rather than copied from a bank.
Auditing what exists. For teams that already have policies, we conduct independent gap analyses and program audits against FinCEN expectations, FATF standards, and comparable international regimes – the review a prospective bank partner, acquirer, or examiner will run anyway.
The counterparty side. We also help banks, stablecoin issuers, payment firms, and VASPs build DeFi risk appetite statements, counterparty due diligence frameworks, and monitoring programs so they can engage with the sector without tripping their own obligations.
Our team includes former regulators and senior compliance executives. We support licensing and registration applications, examination readiness, responses to supervisory findings, enforcement action remediation, and fractional or interim compliance leadership. We also provide training so the people making protocol decisions understand which of those decisions create regulatory status.
Conclusion
FATF’s recent report raises questions that regulated entities should ask before using DeFi protocols. This report explicitly tells them to conduct due diligence on the protocols they touch.
The practical takeaway for labs is that the exemption many teams assumed they had is narrower than advertised and no longer self-executing. Whether you sit inside or outside the regulatory perimeter turns on a specific, enumerated set of facts about keys, governance, fees, interfaces, and corporate structure — facts largely within your control today and much harder to change once someone else is asking about them. Better to run that analysis deliberately, on your own timeline, with documentation, than in response to a subpoena, an examination request, or an offboarding notice from your banking partner.
Facing a challenge? Reach the Klaros team at hello@klaros.com.
Financial Action Task Force, Targeted Report on Regulatory Challenges from Decentralised Finance (DeFi) (July 2026), https://www.fatf-gafi.org/content/dam/fatf-gafi/reports/targeted-report-decentralised-finance-2026.pdf.coredownload.pdf.
Ryan McNamara, US Sanctions Ethereum Mixer Tornado Cash Citing Ties With North Korea-Backed Web3 Hacks, Benzinga (Aug. 8, 2022), https://www.benzinga.com/markets/cryptocurrency/22/08/28404250/north-korea-involved-in-web3-hacks-u-s-sanctions-ethereum-application-tornado-cash.
DeFi, Chainalysis (n.d.), https://www.chainalysis.com/glossary/defi/.
Financial Action Task Force, Virtual Assets and Virtual Asset Service Providers (Oct. 2021), https://www.fatf-gafi.org/content/dam/fatf-gafi/guidance/Updated-Guidance-VA-VASP.pdf.


