The Conventional Wisdom
Many believe that if a protocol runs on smart contracts, operates without intermediaries, and labels itself decentralized, it's beyond the reach of AML/CFT regulation. This view has been prevalent since DeFi's rise. The logic seemed simple: no central party means no one to regulate. Code is law, governance is distributed, and traditional compliance frameworks don't apply.
Protocols have built their market strategies around this idea, structuring governance tokens and distributing development tasks to appear maximally decentralized. The assumption: decentralization equals regulatory immunity.
Why We Disagree
The FATF report on DeFi challenges this assumption with the control or sufficient influence (COSI) test. The focus isn't on eliminating intermediaries or widely distributing governance tokens. It's about whether specific individuals or entities can direct the protocol's financial operations.
Here's what the COSI test examines:
On-chain indicators:
- Governance concentration: Do a few wallets hold enough tokens to direct operations? The FATF recommends wallet clustering analysis to identify hidden control patterns.
- Administrative privileges: Who holds private keys that allow smart contract upgrades, parameter changes, or protocol pauses?
- Fee and treasury flows: Who receives protocol fees, controls treasury funds, or directs economic value?
Off-chain indicators:
- Control over front-end interfaces
- Control over development repositories
- Public communications about the ability to modify the protocol
Notice what's missing: the word "decentralized" in your documentation. Self-labeling doesn't determine regulatory scope. Actual control does.
The Evidence
The numbers show why this matters. Illicit flows into DeFi protocols rose 343% year-on-year. Meanwhile, 93% of jurisdictions haven't identified qualifying DeFi protocols in their territory. This isn't because DeFi is genuinely beyond reach. It's because regulators lacked a framework for determining when their authority applies.
The FATF now provides that framework, and it's more nuanced than many expected. The report identifies three categories:
Centralized protocols with identifiable controllers fall within scope and should be treated as VASPs. Full licensing, Customer Due Diligence, transaction monitoring, sanctions compliance, and Travel Rule obligations apply.
Centralized protocols with unidentified controllers also fall within scope. The FATF recommends supervisors work with blockchain analytics providers to identify who's behind them. You can't avoid regulation by hiding control.
Truly decentralized protocols where no person or entity exercises control or sufficient influence fall outside the FATF Standards. But the report is explicit: being out of scope doesn't mean being risk-free.
What to Do Instead
If you're a compliance officer evaluating DeFi counterparties, stop accepting "we're decentralized" as due diligence. Start with these steps:
For protocol assessment: Use blockchain analytics to trace governance token concentration. Don't just count unique wallet addresses. Look for wallet clustering patterns that reveal coordinated control. Examine fee flows and treasury movements. Who actually receives economic value from the protocol?
Review administrative key holders. Who can upgrade smart contracts? Who can pause the protocol? These capabilities indicate control regardless of governance token distribution.
Check front-end control. A protocol might have distributed governance, but if one entity controls the primary interface users access, that's influence over financial services delivery.
For risk-based due diligence: Protocols with exposure to bridges, mixers, or cross-chain tools require enhanced due diligence. Trace fund flows deeper. Set lower thresholds for flagging suspicious activity.
Evaluate what compliance controls the protocol has actually implemented. Automated screening? Risk-scoring? Sanctions checks? The FATF encourages these features and distinguishes them from the COSI assessment. A protocol can implement robust safeguards without that indicating centralized control.
For ongoing monitoring: Don't treat DeFi assessment as a one-time exercise. Governance structures change. Treasury control shifts. Administrative keys get transferred. Your risk profile for a protocol should update as these factors evolve.
If you're building or operating a DeFi protocol, understand where you actually sit on the spectrum. If you've got multisig control over smart contract upgrades, if your team receives protocol fees, if you can pause operations during a security incident, you likely have control or sufficient influence. That means VASP obligations apply to you.
The FATF encourages security features like kill switches and pause mechanisms. It encourages AML risk mitigation controls like front-end screening and sanctions checks. Implementing these doesn't automatically make you centralized under COSI. The test assesses who has overall control, not whether you've adopted responsible security practices.
Consider embedding compliance controls at the design phase: automated freezing capabilities, on-chain risk-scoring, transaction blocking for high-risk addresses. Institutional capital is already flowing preferentially to protocols with these controls in place. Compliance is becoming a market differentiator.
When the Conventional Wisdom IS Right
Some protocols genuinely have no identifiable controller. No person or entity can upgrade the smart contracts. No one receives protocol fees. Governance is sufficiently distributed that no coalition can meaningfully direct financial operations. These arrangements exist, and the FATF acknowledges they fall outside its Standards.
But even truly decentralized protocols face indirect compliance pressure. Stablecoin issuers with freeze and burn capabilities can block addresses interacting with your protocol. Regulated entities at the touchpoints (exchanges, on-ramps) will apply enhanced due diligence to flows from your protocol if you've got no compliance controls. Front-end providers serving your protocol in certain jurisdictions may be required to implement screening and geo-blocking.
The practical reality: even if you're genuinely decentralized under COSI, compliance controls make you more usable, more accessible, and more attractive to legitimate users and institutional capital. The choice isn't between decentralization and compliance. It's between thoughtful implementation of both or getting cut off from regulated financial infrastructure.
The FATF's framework is functional and proportionate. It doesn't assume all DeFi is centralized. It provides clear indicators for making that determination based on actual control, not marketing claims. For compliance professionals, that's the clarity you need to engage with DeFi responsibly.



