FATF says “DeFi” labels do not exempt centralized crypto platforms from AML rules
The Financial Action Task Force is telling governments to stop taking “decentralized” at face value. If developers, token holders or other identifiable parties still exercise “control or sufficient influence,” FATF says anti-money laundering rules should apply — which is the sort of distinction that matters when a platform looks decentralized on the front end and centralized everywhere else.
- In a report published Tuesday (July 21), the Paris-based AML standard-setter said its existing rules already cover DeFi arrangements whenever an identifiable person or entity has “control or sufficient influence,” even if the project markets itself as decentralized. In other words, the label is not the test; the control structure is.
- FATF splits DeFi arrangements into three buckets: platforms with identifiable controllers, platforms that are effectively centralized but whose operators stay hidden, and a smaller group of genuinely leaderless protocols. According to the report, only that last category falls outside FATF’s standards.
- The report says a number of common DeFi features can point to ongoing centralized control: concentrated holdings of governance tokens, administrative privileges, control over protocol upgrades, and control over the distribution of fees and rewards. FATF also flags upgrade keys or “kill switches,” authority to set fees or risk parameters, concentrated voting power, control of a public-facing website or app, and corporate entities that employ core developers or control a project treasury.
- For PSPs, the practical takeaway is that developers, major token holders, funders and front-end operators could qualify for licensing and supervision as financial businesses. FATF says even operating an interface that channels users into a protocol may be enough.
- Implementation, however, is still thin on the ground. Nearly 93% of jurisdictions responding to a recent FATF survey have never applied the standards to a qualifying DeFi arrangement. Only 26 of 142 jurisdictions have assessed DeFi-related risks, only four have established licensing requirements, and just two have actually registered or licensed a platform.
The gap matters because FATF standards are not law, but more than 200 jurisdictions use them as a benchmark. Countries can also face increased scrutiny, including placement on FATF’s “grey list,” for persistent deficiencies. FATF President Giles Thomson said the goal is to prevent criminals from exploiting emerging technology.
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!